Jump to content

el02139

Honorary Members
  • Posts

    60
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Gringo I greatly appreciate your help in this matter! I have completed everything that you have asked for and have MSE and WinPatrol installed and running. I believe it is safe to close this thread and thank you for your work!
  2. I performed the first task, restarted the computer and ran the ESET scan. 10 threats were found: C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\TelevisionFanatic\bar\1.bin\64ieovr.dll probably a variant of Win32/Toolbar.MyWebSearch.P application C:\System Volume Information\SystemRestore\FRStaging\Users\HP\AppData\Local\Temp\MyBabylonTB_I.exe a variant of Win32/Toolbar.Babylon.C application C:\System Volume Information\SystemRestore\FRStaging\Users\HP\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\6038886A.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\System Volume Information\SystemRestore\FRStaging\Users\HP\Downloads\AltastGreeting_downloader_by_Fonts101.exe a variant of Win32/Somoto.A application C:\System Volume Information\SystemRestore\FRStaging\Users\HP\Downloads\freefileviewer_2_1283.exe a variant of Win32/InstallIQ application C:\Users\HP\Downloads\7zip_bimo_d3280787.exe probably a variant of Win32/InstallIQ application C:\Users\HP\Downloads\Adobe_Reader_setup.exe a variant of Win32/InstallCore.BH application C:\Users\HP\Downloads\AltastGreeting_downloader_by_Fonts101.exe a variant of Win32/Somoto.A application C:\Users\HP\Downloads\freefileviewer_2_1283.exe a variant of Win32/InstallIQ application C:\_OTL\MovedFiles\04252013_205901\C_Windows\SysWOW64\choifpmp.dll Win32/PSW.Papras.CD trojan
  3. Gringo, Near as I can tell, there seem to be no more issues with the computer - a huge thank you to you! One question I have left is how to prevent this in the future. In your opinion, does Microsoft Security Essentials provide enough protection, or should I be augmenting it with something? Does the professional version of Malewarebytes make sense? Just asking your opinion. Thanks!
  4. Also, just tried to run Malwarebytes and it is running successfully. I will dig into the computer deeper to see if all the issues have been addressed tonight. Thanks a lot!
  5. Ran the script to fix, attached are the results: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 26-05-2013 04 Ran by HP at 2013-05-27 17:29:47 Run:2 Running from C:\Users\HP\Desktop\Secure\Post12 Boot Mode: Normal ============================================== ========= Dir /b /a:l "C:\Program Files" /s ========= File Not Found ========= End of CMD: ========= HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. HKLM => Group Policy Restriction on software restored successfully. ==== End of Fixlog ====
  6. and here is the addtion.txt file: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-05-2013 04 Ran by HP at 2013-05-27 06:58:28 Run: Running from C:\Users\HP\Desktop\Secure\Post12 Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 64 Bit HP CIO Components Installer (Version: 7.2.8) ActiveCheck component for HP Active Support Library (Version: 3.0.0.2) Adobe AIR (Version: 3.5.0.1060) Adobe Community Help (Version: 3.5.23) Adobe Flash Player 11 ActiveX (Version: 11.7.700.202) Adobe Photoshop Elements 10 (Version: 10.0) Adobe Photoshop.com Inspiration Browser (Version: 3.07) Adobe Reader X (10.1.7) (Version: 10.1.7) Adobe Shockwave Player 11.5 (Version: 11.5.1.601) Amazon Music Importer (Version: 2.0.1) AnswerWorks 5.0 English Runtime (Version: 5.0.7) AOL Toolbar Apple Application Support (Version: 2.3.4) Apple Mobile Device Support (Version: 6.1.0.13) Apple Software Update (Version: 2.1.3.127) AVG Security Toolbar (Version: 15.2.0.5) Bing Bar (Version: 7.0.609.0) Bing Rewards Client Installer (Version: 16.0.345.0) Bonjour (Version: 3.0.0.10) BufferChm (Version: 130.0.331.000) Cakewalk Sound Center 1.1.0 (Version: 1.1.0) Canon Camera TWAIN Driver (Version: 5.2) Canon EOS Kiss REBEL 300D TWAIN Driver (Version: 5.2) Canon PhotoRecord (Version: 02.00.00029) Canon RAW Codec (Version: 1.7.0.56) Canon RAW Image Task for ZoomBrowser EX (Version: 0.9.0) Canon RemoteCapture Task for ZoomBrowser EX (Version: 0.9.0) Canon Utilities CameraWindow (Version: 7.1.0.2) Canon Utilities CameraWindow DC (Version: 7.3.0.4) Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (Version: 6.4.2.16) Canon Utilities Digital Photo Professional 3.7 (Version: 3.7.2.0) Canon Utilities File Viewer Utility 1.3 (Version: 1.3.2) Canon Utilities MyCamera (Version: 7.1.0.1) Canon Utilities MyCamera DC (Version: 7.1.0.4) Canon Utilities PhotoStitch 3.1 (Version: 3.1.10) Canon Utilities RemoteCapture 2.7 (Version: 2.7.5) Canon Utilities RemoteCapture DC (Version: 3.1.0.5) Canon Utilities RemoteCapture Task for ZoomBrowser EX (Version: 1.7.1.9) Canon Utilities ZoomBrowser EX (Version: 6.2.1.31) Canon ZoomBrowser EX Memory Card Utility (Version: 1.2.0.9) Cards_Calendar_OrderGift_DoMorePlugout (Version: 2.03.0000) CCleaner (Version: 4.01) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) Copy (Version: 130.0.366.000) Corel Paint Shop Pro Photo X2 (Version: 12.50.0000) CyberLink DVD Suite Deluxe (Version: .1707) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Destinations (Version: 140.0.77.000) DeviceDiscovery (Version: 130.0.372.000) DJ_AIO_05_F4400_Software_Min (Version: 140.0.690.000) Download Updater (AOL Inc.) Elements 10 Organizer (Version: 10.0) F4400 (Version: 130.0.448.000) File Type Assistant File Viewer Utility 1.3.2 (Version: 1.3.2) Free File Viewer 2011 Garmin Communicator Plugin (Version: 4.0.4) Garmin Communicator Plugin x64 (Version: 4.0.4) Garmin Trip and Waypoint Manager v5 (Version: 5.0.0.0) Garmin USB Drivers (Version: 2.3.0.0) Google Earth (Version: 7.0.3.8542) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.4.3607.2246) Google Update Helper (Version: 1.3.21.145) GoToMeeting 4.1.0.366 GPBaseService2 (Version: 130.0.371.000) Hardware Diagnostic Tools (Version: 5.1.4976.17) HP Active Support Library (Version: 3.1.6.1) HP Advisor (Version: 3.3.12286.3436) HP Customer Experience Enhancements (Version: 5.6.0.2510) HP Customer Feedback (Version: 1.0.0) HP Customer Participation Program 13.0 (Version: 13.0) HP Demo (Version: 1.00.0000) HP Deskjet F4400 Printer Driver 14.0 Rel. 5 (Version: 14.0) HP Imaging Device Functions 13.0 (Version: 13.0) HP MediaSmart DVD (Version: 2.2.3309) HP Photo Creations (Version: 1.0.0.4042) HP Photosmart All-In-One Driver Software 10.0 Rel .2 (Version: 10.0) HP Photosmart Essential 2.5 (Version: 1.03.0000) HP Photosmart Essential 3.0 (Version: 3.0) HP Print Projects 1.0 (Version: 1.0) HP Recovery Manager RSS (Version: 84.0.0.7) HP Smart Web Printing 4.60 (Version: 4.60) HP Solution Center 13.0 (Version: 13.0) HP Update (Version: 5.002.005.003) HP_Network_UserGuide (Version: 1.00.0000) HPAsset component for HP Active Support Library (Version: 3.0.1.0) HPDiagnosticAlert (Version: 1.00.0000) HPPhotoGadget (Version: 130.0.282.000) HPPhotoSmartPhotobookWebPack1 (Version: 2.03.0000) hpPrintProjects (Version: 130.0.303.000) HPProductAssistant (Version: 130.0.371.000) HPSSupply (Version: 130.0.371.000) HPTCSSetup (Version: 1.0.964.2626) hpWLPGInstaller (Version: 130.0.303.000) iCloud (Version: 2.1.2.8) Intel® Matrix Storage Manager iPhone Configuration Utility (Version: 2.1.0.163) iTunes (Version: 11.0.3.42) Java 7 Update 21 (64-bit) (Version: 7.0.210) Java Auto Updater (Version: 2.0.6.1) LabelPrint (Version: 2.2.2913) LightScribe System Software (Version: 1.18.3.2) LightScribeTemplateLabeler (Version: 1.10.23.1) Lizardtech Express View Browser Plug-in Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300) MarketResearch (Version: 130.0.374.000) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Automated Troubleshooting Services Shim Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office 97, Professional Edition Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Home and Student 60 day trial Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 64-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 64-bit MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000) Microsoft Security Client (Version: 4.2.0223.1) Microsoft Security Essentials (Version: 4.2.223.1) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft UI Engine (Version: 6.3.2380.0) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219) Microsoft Works (Version: 9.7.0621) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) Music Creator LE 5.0.6 (Version: 17.0) muvee autoProducer 6.1 (Version: 6.10.050) My HP Games (Version: 1.0.0.52) MyFreeCodec Network64 (Version: 110.0.180.000) NVIDIA Drivers Panda Internet Security 2009 (Version: 14.00.00) PhotoShow Deluxe 4 (Version: 4.0) PhotoStitch (Version: 3.1.10) PlayReady PC runtime (Version: 1) Power2Go (Version: 5.6.4109) PowerDirector (Version: 6.5.3325) PS_AIO_02_Software_Min (Version: 100.0.206.000) PSE10 STI Installer (Version: 10.0) PSSWCORE (Version: 2.03.0000) Python 2.5.2 (Version: 2.5.2150) Quicken 2008 (Version: 17.1.1.24) QuickTime (Version: 7.74.80.86) RAW Image Task (Version: 0.9.0) Realtek High Definition Audio Driver (Version: 6.0.1.5789) RemoteCapture 2.7.5 (Version: 2.7.5) RemoteCapture Task (Version: 0.9.0) Revo Uninstaller 1.94 (Version: 1.94) Safari (Version: 5.34.57.2) Samsung Kies (Version: 2.0.2.11071_128) SAMSUNG USB Driver for Mobile Phones (Version: 1.4.2.2) Scan (Version: 140.0.80.000) Shop for HP Supplies (Version: 13.0) SmartWebPrinting (Version: 140.0.186.000) SolutionCenter (Version: 130.0.373.000) sp41119 Spelling Dictionaries Support For Adobe Reader 9 (Version: 9.0.0) Status (Version: 130.0.373.000) Toolbox (Version: 140.0.428.000) TrayApp (Version: 130.0.376.000) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Update Installer for WildTangent Games App VideoToolkit01 (Version: 110.0.171.000) Visual C++ 8.0 Runtime Setup Package (x64) (Version: 8.0.0.35) Visual Studio 2008 x64 Redistributables (Version: 10.0.0.2) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1) WebEx WebReg (Version: 130.0.132.017) WildTangent Games App (HP Games) (Version: 4.0.5.2) Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0) (Version: 06/03/2009 2.3.0.0) Yahoo! BrowserPlus 2.8.1 Yahoo! Toolbar ==================== Restore Points ========================= 28-04-2013 14:33:03 Windows Update 02-05-2013 07:42:22 Windows Update 04-05-2013 18:17:26 Revo Uninstaller's restore point - AVG Security Toolbar 04-05-2013 18:22:19 Revo Uninstaller's restore point - Google Chrome 04-05-2013 18:25:31 Revo Uninstaller's restore point - Adobe Reader X (10.1.6) 04-05-2013 18:39:17 Installed Adobe Reader X (10.1.0). 05-05-2013 21:12:02 Windows Update 07-05-2013 00:39:44 Scheduled Checkpoint 09-05-2013 07:15:52 Windows Update 12-05-2013 00:01:09 Scheduled Checkpoint 12-05-2013 21:12:22 Windows Update 16-05-2013 06:57:34 Windows Update 16-05-2013 08:00:21 Windows Update 17-05-2013 07:54:52 Scheduled Checkpoint 19-05-2013 08:46:00 Windows Update 21-05-2013 04:21:26 Scheduled Checkpoint 22-05-2013 05:00:01 Scheduled Checkpoint 22-05-2013 08:56:01 Windows Update 26-05-2013 06:45:40 Windows Update 27-05-2013 05:15:50 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============= Name: Microsoft 6to4 Adapter #2 Description: Microsoft 6to4 Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31) Resolution: Update the driver Name: HP Photosmart C7200 Description: HP Photosmart C7200 Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Hewlett-Packard Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Photosmart C7200 series Description: Photosmart C7200 series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: HP LaserJet 5100 Series Description: HP LaserJet 5100 Series Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: Hewlett-Packard Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (05/25/2013 09:25:30 AM) (Source: LoadPerf) (User: ) Description: WmiApRplWmiApRpl8 Error: (05/25/2013 09:25:30 AM) (Source: LoadPerf) (User: ) Description: Performance16 Error: (05/25/2013 09:19:21 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/23/2013 10:02:11 PM) (Source: Windows Search Service) (User: ) Description: The entry <C:\USERS\HP\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.OUTLOOK\KWHHU52Z\~WRD000.JPG> in the hash map cannot be updated. Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5007 Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5007 Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4009 Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4009 Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (05/25/2013 09:19:21 AM) (Source: Service Control Manager) (User: ) Description: Beep Error: (05/25/2013 09:19:21 AM) (Source: Service Control Manager) (User: ) Description: PskSvcRetailInst%%3 Error: (05/25/2013 09:18:09 AM) (Source: EventLog) (User: ) Description: The previous system shutdown at 9:15:47 AM on 5/25/2013 was unexpected. Error: (05/17/2013 09:03:16 PM) (Source: Service Control Manager) (User: ) Description: Windows Search%%1053 Error: (05/17/2013 09:03:16 PM) (Source: DCOM) (User: ) Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (05/17/2013 09:03:16 PM) (Source: Service Control Manager) (User: ) Description: 30000Windows Search Error: (05/16/2013 03:34:32 AM) (Source: Service Control Manager) (User: ) Description: Beep Error: (05/16/2013 03:34:32 AM) (Source: Service Control Manager) (User: ) Description: PskSvcRetailInst%%3 Error: (05/14/2013 06:28:29 AM) (Source: DCOM) (User: ) Description: {7F6316B4-4D69-4765-B0A3-B2598F2FA80A} Error: (05/14/2013 06:27:22 AM) (Source: Service Control Manager) (User: ) Description: Beep Microsoft Office Sessions: ========================= Error: (05/25/2013 09:25:30 AM) (Source: LoadPerf)(User: ) Description: WmiApRplWmiApRpl8 Error: (05/25/2013 09:25:30 AM) (Source: LoadPerf)(User: ) Description: Performance16 Error: (05/25/2013 09:19:21 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (05/23/2013 10:02:11 PM) (Source: Windows Search Service)(User: ) Description: Context: Application, SystemIndex Catalog Details: A device attached to the system is not functioning. (0x8007001f) C:\USERS\HP\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.OUTLOOK\KWHHU52Z\~WRD000.JPG Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5007 Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5007 Error: (05/21/2013 07:48:15 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4009 Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4009 Error: (05/21/2013 07:48:14 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2013-05-27 06:58:06.301 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 06:58:06.035 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 06:58:05.770 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-05-27 06:58:05.474 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-05-01 15:49:21.699 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-05-01 15:49:21.527 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2013-04-21 22:34:40.440 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-04-21 22:34:40.190 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-04-21 22:34:39.941 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. Date: 2013-04-21 22:34:39.644 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\NisDrvWFP.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Percentage of memory in use: 55% Total physical RAM: 4094.33 MB Available physical RAM: 1817.45 MB Total Pagefile: 8387.93 MB Available Pagefile: 6162.03 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (HP) (Fixed) (Total:684.81 GB) (Free:183.06 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)] Drive d: (FACTORY_IMAGE) (Fixed) (Total:13.83 GB) (Free:1.88 GB) NTFS (Disk=0 Partition=2) ==>[system with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: 1549F232) Partition 1: (Active) - (Size=685 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=14 GB) - (Type=07 NTFS) ==================== End Of Log ============================
  7. Alright - I'm back and attached is the frst.txt file: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-05-2013 04 Ran by HP (administrator) on 27-05-2013 06:57:26 Running from C:\Users\HP\Desktop\Secure\Post12 Windows Vista Home Premium Service Pack 2 (X64) OS Language: English(US) Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (Microsoft Corporation) C:\Windows\system32\SLsvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (Lexar Media, Inc.) C:\Windows\SysWOW64\LxrSII1s.exe (Panda Security, S.L.) C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\ehome\ehsched.exe (Microsoft Corporation) C:\Windows\ehome\ehRecvr.exe (Hewlett-Packard) c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 10 Organizer\ElementsOrganizerSyncAgent.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (AVG Secure Search) C:\Program Files (x86)\AVG Secure Search\vprot.exe (Hewlett-Packard Company) C:\hp\support\hpsysdrv.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (CyberLink Corp.) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (Corel, Inc.) C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe () C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Microsoft Corporation) C:\Windows\ehome\mcGlidHost.exe (Farbar) C:\Users\HP\Desktop\Secure\Post12\FRST64.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1281512 2013-01-27] (Microsoft Corporation) HKLM\...\Run: [iAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [182808 2008-11-03] (Intel Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [472992 2013-03-21] (Adobe Systems Incorporated) HKLM\...\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [82464 2008-10-16] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [15853088 2008-10-16] (NVIDIA Corporation) HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Malwarebytes <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Malwarebytes' Anti-Malware <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\Panda Security <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Panda Security <====== ATTENTION HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\avg8 <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files\Common Files\Symantec Shared <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKCU\...\Run: [PhotoshopElements8SyncAgent] C:\Program Files (x86)\Adobe\Elements 10 Organizer\ElementsOrganizerSyncAgent.exe [1954456 2011-09-01] (Adobe Systems Incorporated) HKCU\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [152064 2008-12-23] (Microsoft Corporation) HKLM-x32\...\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" [1226928 2013-05-20] (AVG Secure Search) HKLM-x32\...\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe [65536 2007-04-18] (Hewlett-Packard Company) HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard) HKLM-x32\...\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [75008 2008-06-02] (Hewlett-Packard) HKLM-x32\...\Run: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [1148200 2009-09-09] (CyberLink Corp.) HKLM-x32\...\Run: [Corel Photo Downloader] "C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup [532808 2008-08-08] (Corel, Inc.) HKLM-x32\...\Run: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe [16712 2008-08-08] () HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-15] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2013-05-01] (Apple Inc.) SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll (Microsoft Corporation) SSODL-x32: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt SearchScopes: HKLM - {2CB52562-425C-43DB-B31A-580670681992} URL = http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=hp-pvdt HKCU SearchScopes: DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {BE7F510C-A8B2-43CF-9DDE-E7519F754EED} URL = http://delicious.com/search?p={searchTerms} SearchScopes: HKCU - {CB914B9E-D70D-4948-A41E-A4C429750DD7} URL = http://www.flickr.com/search/?q={searchTerms} SearchScopes: HKCU - {DC995720-A70B-4696-8A0A-256D54529795} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie9 BHO: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: No Name - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO-x32: No Name - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) BHO-x32: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll No File BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) PDF: HKLM-x32 {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab PDF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - No File Handler: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - No File Handler-x32: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files (x86)\LizardTech\Express View\expressview.dll (Lizardtech Software) Handler-x32: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files (x86)\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler-x32: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files (x86)\LizardTech\Express View\expressview.dll (Lizardtech Software) Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search) Winsock: Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [19968] (Microsoft Corporation) Winsock: Catalog5-x64 07 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 216.51.173.2 216.51.173.1 Tcpip\..\Interfaces\{67899D8C-147F-49E2-ABE5-D064EEC25557}: [NameServer]216.51.173.2,216.51.173.1 ==================== Services (Whitelisted) ================= R2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-09-01] (Adobe Systems Incorporated) R2 LxrSII1s; C:\Windows\SysWow64\LxrSII1s.exe [65536 2009-12-30] (Lexar Media, Inc.) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation) R2 PavPrSrv; C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe [62768 2008-02-04] (Panda Security, S.L.) R2 vToolbarUpdater15.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [1015984 2013-05-20] (AVG Secure Search) R2 ezSharedSvc; C:\Windows\System32\ezsvc7.dll [x] S2 PskSvcRetailInst; C:\Users\HP\AppData\Local\Temp\ISSCAN\PskSvc.exe [x] ==================== Drivers (Whitelisted) ==================== R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [310728 2009-04-29] () R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-05-20] (AVG Technologies) R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2009-04-29] () R2 LxrSII1d; C:\Windows\System32\Drivers\LxrSII1d.sys [63064 2009-12-30] (Lexar Media, Inc.) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation) S1 Beep; No ImagePath S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] R0 pavboot; system32\Drivers\pavboot64.sys [x] S3 PcdrNdisuio; syswow64\drivers\pcdrndisuio.sys [x] S3 Prot6Flt; system32\DRIVERS\Prot6Flt.sys [x] R1 ShldFlt; System32\DRIVERS\ShldFlt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-05-27 06:41 - 2013-05-27 06:42 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-05-19 21:37 - 2013-05-19 21:37 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk 2013-05-19 21:36 - 2013-05-19 21:37 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-05-19 21:36 - 2013-05-19 21:37 - 00000000 ____D C:\Program Files\iTunes 2013-05-19 21:36 - 2013-05-19 21:36 - 00000000 ____D C:\Program Files\iPod 2013-05-16 03:13 - 2013-04-04 20:19 - 10926080 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-05-16 03:13 - 2013-04-04 20:08 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-05-16 03:13 - 2013-04-04 20:01 - 01346560 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-05-16 03:13 - 2013-04-04 20:00 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-05-16 03:13 - 2013-04-04 19:59 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-05-16 03:13 - 2013-04-04 19:58 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-05-16 03:13 - 2013-04-04 19:57 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-05-16 03:13 - 2013-04-04 19:56 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-05-16 03:13 - 2013-04-04 19:55 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-05-16 03:13 - 2013-04-04 19:55 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-05-16 03:13 - 2013-04-04 19:54 - 02147840 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-05-16 03:13 - 2013-04-04 19:54 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-05-16 03:13 - 2013-04-04 19:51 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-05-16 03:13 - 2013-04-04 19:46 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-05-16 03:13 - 2013-04-04 17:11 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-05-16 03:13 - 2013-04-04 17:09 - 09738752 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-05-16 03:13 - 2013-04-04 17:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-05-16 03:13 - 2013-04-04 17:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-05-16 03:13 - 2013-04-04 17:02 - 01104384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-05-16 03:13 - 2013-04-04 17:01 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-05-16 03:13 - 2013-04-04 16:59 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-05-16 03:13 - 2013-04-04 16:58 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-05-16 03:13 - 2013-04-04 16:58 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-05-16 03:13 - 2013-04-04 16:57 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-05-16 03:13 - 2013-04-04 16:56 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-05-16 03:13 - 2013-04-04 16:55 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-05-16 03:13 - 2013-04-04 16:54 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-05-16 03:13 - 2013-04-04 16:50 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-05-16 03:03 - 2013-05-05 16:36 - 17818624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-16 03:03 - 2013-05-05 16:16 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-16 03:03 - 2013-05-05 14:25 - 12324864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-16 03:03 - 2013-05-05 14:12 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-15 05:49 - 2013-04-15 09:17 - 00901496 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-05-15 05:49 - 2013-04-12 22:34 - 00047104 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-05-15 05:49 - 2013-04-08 20:55 - 02774016 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-05-14 06:25 - 2013-05-14 06:25 - 00001212 ____A C:\Windows\PFRO.log 2013-05-13 19:34 - 2013-05-13 19:34 - 03093171 ____A C:\Users\HP\Documents\Reasons the kids should go to Lauren’s Graduation.pptx 2013-05-11 14:00 - 2013-05-11 14:00 - 00000000 ____A C:\Windows\setuperr.log 2013-05-11 14:00 - 2013-05-11 14:00 - 00000000 ____A C:\Windows\setupact.log 2013-05-05 04:00 - 2013-05-20 20:35 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-05-04 13:43 - 2013-05-04 13:43 - 00000000 ____D C:\Program Files\CCleaner 2013-05-04 13:40 - 2013-05-04 13:40 - 00001924 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-05-03 14:39 - 2013-05-03 14:40 - 00255220 ____A C:\Users\HP\Downloads\made_with_b.zip 2013-05-03 14:36 - 2013-05-03 14:37 - 00164699 ____A C:\Users\HP\Downloads\blockography.zip 2013-05-01 15:53 - 2013-05-01 15:53 - 00019793 ____A C:\ComboFix.txt 2013-05-01 15:41 - 2011-06-26 01:45 - 00256000 ____A C:\Windows\PEV.exe 2013-05-01 15:41 - 2010-11-07 12:20 - 00208896 ____A C:\Windows\MBR.exe 2013-05-01 15:41 - 2009-04-19 23:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-05-01 15:41 - 2000-08-30 19:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-05-01 15:41 - 2000-08-30 19:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-05-01 15:41 - 2000-08-30 19:00 - 00098816 ____A C:\Windows\sed.exe 2013-05-01 15:41 - 2000-08-30 19:00 - 00080412 ____A C:\Windows\grep.exe 2013-05-01 15:41 - 2000-08-30 19:00 - 00068096 ____A C:\Windows\zip.exe 2013-05-01 15:38 - 2013-05-01 15:53 - 00000000 ____D C:\Qoobox 2013-05-01 15:37 - 2013-05-01 15:52 - 00000000 ____D C:\Windows\erdnt 2013-05-01 03:59 - 2013-05-01 03:59 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx 2013-05-01 03:59 - 2013-05-01 03:59 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts 2013-04-27 20:46 - 2013-04-27 20:46 - 00009484 ____A C:\Users\HP\Documents\Revised Corn Planting Plan '13.xlsx 2013-04-27 09:24 - 2013-04-27 09:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-04-27 09:24 - 2013-04-27 09:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-04-27 09:24 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys ==================== One Month Modified Files and Folders ======= 2013-05-27 06:57 - 2013-02-06 14:55 - 00000000 ____D C:\users\Lori 2013-05-27 06:54 - 2013-03-21 07:29 - 00000000 ____D C:\Users\HP\Desktop\Secure 2013-05-27 06:42 - 2013-05-27 06:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-05-27 06:15 - 2006-11-02 10:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-05-27 06:15 - 2006-11-02 10:22 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-05-27 05:59 - 2010-11-12 13:56 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-05-27 02:59 - 2010-11-12 13:56 - 00000886 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-05-27 02:22 - 2008-01-20 20:53 - 01142397 ____A C:\Windows\WindowsUpdate.log 2013-05-27 02:00 - 2009-01-03 13:00 - 00000000 ____D C:\Users\HP\AppData\Local\Adobe 2013-05-26 14:35 - 2011-12-16 21:28 - 00000000 ____D C:\Users\HP\Documents\Outlook Files 2013-05-26 14:03 - 2006-11-02 10:07 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-05-26 08:20 - 2011-12-03 09:20 - 00000396 ____A C:\Windows\Tasks\FreeFileViewerUpdateChecker.job 2013-05-25 11:14 - 2012-06-24 10:06 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-05-25 11:14 - 2011-06-10 07:22 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-05-25 09:25 - 2006-11-02 07:46 - 00005786 ____A C:\Windows\System32\PerfStringBackup.INI 2013-05-25 09:18 - 2006-11-02 10:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-05-21 09:30 - 2009-01-06 10:26 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log 2013-05-20 20:35 - 2013-05-05 04:00 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search 2013-05-20 20:35 - 2012-08-27 03:01 - 00045856 ____A (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys 2013-05-19 21:37 - 2013-05-19 21:37 - 00001696 ____A C:\Users\Public\Desktop\iTunes.lnk 2013-05-19 21:37 - 2013-05-19 21:36 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-05-19 21:37 - 2013-05-19 21:36 - 00000000 ____D C:\Program Files\iTunes 2013-05-19 21:37 - 2009-09-10 19:49 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-05-19 21:36 - 2013-05-19 21:36 - 00000000 ____D C:\Program Files\iPod 2013-05-19 17:39 - 2010-09-07 15:39 - 00150392 ____A (Sysinternals - www.sysinternals.com) C:\junction.exe 2013-05-16 03:34 - 2006-11-02 10:21 - 00453840 ____A C:\Windows\System32\FNTCACHE.DAT 2013-05-16 03:30 - 2006-11-02 10:42 - 00032648 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-05-16 03:13 - 2011-12-15 19:04 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-05-16 03:09 - 2006-11-02 07:35 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-05-14 06:25 - 2013-05-14 06:25 - 00001212 ____A C:\Windows\PFRO.log 2013-05-13 19:34 - 2013-05-13 19:34 - 03093171 ____A C:\Users\HP\Documents\Reasons the kids should go to Lauren’s Graduation.pptx 2013-05-11 22:03 - 2009-01-05 08:22 - 00000456 ____A C:\Windows\Tasks\PCDRScheduledMaintenance.job 2013-05-11 14:00 - 2013-05-11 14:00 - 00000000 ____A C:\Windows\setuperr.log 2013-05-11 14:00 - 2013-05-11 14:00 - 00000000 ____A C:\Windows\setupact.log 2013-05-05 19:43 - 2009-01-05 08:22 - 00000322 ____A C:\Windows\Tasks\HPCeeScheduleForHP.job 2013-05-05 16:36 - 2013-05-16 03:03 - 17818624 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-05-05 16:16 - 2013-05-16 03:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-05-05 14:25 - 2013-05-16 03:03 - 12324864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-05-05 14:12 - 2013-05-16 03:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-05-05 04:01 - 2013-02-18 22:30 - 00000000 ____D C:\ProgramData\AVG Secure Search 2013-05-05 04:01 - 2012-05-11 20:41 - 00000000 ____D C:\Users\HP\AppData\Local\AVG Secure Search 2013-05-04 13:50 - 2008-12-23 12:15 - 00000000 ____D C:\Windows\Panther 2013-05-04 13:43 - 2013-05-04 13:43 - 00000000 ____D C:\Program Files\CCleaner 2013-05-04 13:40 - 2013-05-04 13:40 - 00001924 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk 2013-05-04 13:39 - 2010-01-18 20:33 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-05-04 13:39 - 2009-01-03 13:00 - 00000000 ____D C:\ProgramData\Adobe 2013-05-04 13:22 - 2009-08-11 09:22 - 00000000 ____D C:\Users\HP\AppData\Local\Google 2013-05-04 13:22 - 2009-08-10 21:38 - 00000000 ____D C:\Program Files (x86)\Google 2013-05-04 13:16 - 2013-03-21 18:47 - 00000000 ____D C:\Program Files (x86)\VS Revo Group 2013-05-03 14:40 - 2013-05-03 14:39 - 00255220 ____A C:\Users\HP\Downloads\made_with_b.zip 2013-05-03 14:37 - 2013-05-03 14:36 - 00164699 ____A C:\Users\HP\Downloads\blockography.zip 2013-05-02 10:29 - 2009-10-02 16:59 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2013-05-01 15:53 - 2013-05-01 15:53 - 00019793 ____A C:\ComboFix.txt 2013-05-01 15:53 - 2013-05-01 15:38 - 00000000 ____D C:\Qoobox 2013-05-01 15:52 - 2013-05-01 15:37 - 00000000 ____D C:\Windows\erdnt 2013-05-01 15:50 - 2006-11-02 07:34 - 00000215 ____A C:\Windows\system.ini 2013-05-01 03:59 - 2013-05-01 03:59 - 00094208 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTimeVR.qtx 2013-05-01 03:59 - 2013-05-01 03:59 - 00069632 ____A (Apple Inc.) C:\Windows\SysWOW64\QuickTime.qts 2013-04-27 20:47 - 2013-04-13 08:12 - 00027210 ____A C:\Users\HP\Documents\Planting Plan 13.xlsx 2013-04-27 20:46 - 2013-04-27 20:46 - 00009484 ____A C:\Users\HP\Documents\Revised Corn Planting Plan '13.xlsx 2013-04-27 09:24 - 2013-04-27 09:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-04-27 09:24 - 2013-04-27 09:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware Other Malware: =========== C:\Users\HP\g2mdlhlpx.exe C:\Users\HP\hfp140807s10_r1.exe C:\Users\HP\IS09.exe C:\Users\HP\UNINSTALLER_08.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit Last Boot: 2013-05-26 09:32 ==================== End Of Log ============================
  8. Gringo, Sorry, I got your previous note from the airport the day I was travelling overseas. I just returned and will work on this today. Thanks!
  9. And here is the rest.... Failed to open \\?\c:\\Users\All Users\sentinel: Access is denied. \\?\c:\\Users\All Users\Start Menu: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Start Menu Substitute Name: C:\ProgramData\Microsoft\Windows\Start Menu \\?\c:\\Users\All Users\Templates: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Templates Substitute Name: C:\ProgramData\Microsoft\Windows\Templates Failed to open \\?\c:\\Users\All Users\{93E26451-CD9A-43A5 -A2FA-C42392EA4001}: Access is denied. . ... ... ... ... ... ... .. Failed to open \\?\c:\\Users\All Users\Hewlett-Packard\HP Print Settings\HP4orv63.cfg: Access is denied. . ... Failed to open \\?\c:\\Users\All Users\Microsoft\Microsoft Antimalware: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows Defender: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\S-1-5-18: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\01632489336ded7e6f07 82b274f8dae7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0344065c848389af1087 6d14913c01e2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\03bf2caf40a5c2db9bfa da378e67396e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\044196731b7b41087590 b26944d01d5b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\0c12c45ee466e5607464 285bb89e11a8_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\10c1fade14df8bbe7121 83fe55c81e02_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\10e6a32652b93ae16eb2 2e2292ff8150_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\112b2cc4f4df13b57c85 05a077f80dd6_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\13b83761793b8f99e306 94e9858d92a2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\184a284d6cdd70d596ff 6fb490051aee_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\190ee855f153c072b505 3111ae850a95_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1c7025640ade2c21f670 8aee40527292_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1dd7a627d49ca00341a3 f0024e8ea540_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\1f866c1674b80f1c9016 29c4956c9b43_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\20bef3731e4de3d0703d f1b6e9629d5f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\21736392af395f8cbf0b 0b303085b6f7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\222753a64ed8ae7df866 2ce713e5741c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\22c975d59ac3b5331684 ccdfb471ca3b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\22d81b2f95990d5b0763 a1b93d93d474_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2394e98577faef5e8503 ec3461aad388_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\258ae4c8f9ba0ef2db06 3954dfc9a744_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2660855ef783da37a172 1de38ca0f509_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\26902aae4790758f32de 9eeb3477a490_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2721e2409d0e34e6730a 360e1f299db0_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\27ac51a5e38972dc3082 94cf3a50262a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\29738da767aca837c592 0c408579b11a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\29c5fb05b9527cd25a78 f67d407a1096_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2ab2e0619af9a700e226 4ae003bde82f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2ac50d2544841f26e701 f7b84b73cead_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2b18b5387d89d4807afe 301e9125c547_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2c98a36920c601422fde 9ca87b38f46a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2cba9b28a02a7ee0b7bf 61564d9e1c70_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2eabc9858a9c72a46ed6 b8b995b78a6f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2ed93740e679d22976e9 e2a80e3565ff_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\2f1ffeec6c7cd834cf9b 2570929ca4bf_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\308a6c612a24634a5eee 5f9e11ba941e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\30d6a4ae21a69cd18c83 e94051e38bdf_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\30f7e7e6179ac3807966 a7b2c8a06c58_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\310c7e3c20fa6ba306b2 eed4fab0bcc9_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3315ab93fb13c140c1e4 6c64131b049a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\35c5395c210cc5b95e99 ed9ce8d9c043_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\36250df08e5dcb2ab0d6 fafac98901dd_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3847b6c77a4d225d4005 ae12c045bb83_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\394facc6873805f93a77 e936d337e215_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3a7a76a73eee511a25d7 d6449e1b754d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3ad8d90ad583c1a34507 7e74c4d84fb2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3c0aaaa4dacbf306516b f96dfc978a16_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3d59d8443073141766b9 1e062157887c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3e0982fdaa00c161df66 aae1b62e72a7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3e4032519e49459186b3 56ba8331c5d7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\3f5ee4cdb20084c06c3d 4a12e1a69cd6_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\401fb885b49553e88d17 729a546d33f1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\40e5865ca461f7ab4796 dc87dd3068e1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\40fb83ed9afd7797ba2e 73b74f2e4cbc_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\42b733d18311c3b1690f d23ae721f573_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\42fff0fb5e4c9663073d ee0e2600ef73_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\433fd8e5186d77817649 58f56cd9ac9b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\43c1a2b5c0d452e0c927 6cd5963b2187_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\444d5cdddc1338466b3b 7570a01d9da2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\44f99965b738d94488c4 1012c4329823_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\455833f7ef9005208b8d 1a5347fc0b88_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\45f8e9ab7ebe4498ec00 395155554f8d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4689ed430bb919ed0258 f67950b69fb4_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4858c03876bf9e203189 0ebba7aabf4b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\48ff11c44c01bc442652 e36849c7834c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\490fef58c1c5dcb6eaed ea8ee19147c9_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4a2584924ad9e2ae4769 c86b47bb2395_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4ae77574bce259622219 6437bb946558_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4c6a4e98de1878afcf00 144c57da751a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\4dfc5fb30c9a054aab77 af0d9a20bfa3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\50956834905a2efdb5c8 002ff5199ab3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\51597e6ecac7e38bde4f c5508ef88444_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\53227fca167a3a28812c 6203b36ee8f4_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5488a6aa81a598c3e2bd de2fb9b8ec94_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\55c4dfff16ba53490d6f 2ef9ad67d619_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\55f422205195dd23fc38 0e3438578c17_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\573aa406401fd4a0ae33 50a2e36b9778_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\577d2f6e2c1ed6f19c33 d02a74d11263_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5784c85626a8362cc2f4 3f8c6d071fe6_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5a83b4bc31e3fd4f3ff3 40097cd62949_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5ad38adfbd8983d259cd 158280656542_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5b87ffaf8790e74ffad1 419d78339bdc_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5b8bbe6cae3f5bd03c13 f1f0ecdf0e4b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5c12c97ac7a4708fb4d4 84bb19fdcc33_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5d620a1ce61623c6d475 c077d49de34f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\5f7bc3c64dbe9b5544ce 6af838efec0e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6186570bdea26caeec26 024a5ffe0365_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\61ab6958448e8158e43c 6a0d1de0a689_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\627eec19288bbfda4b3d e178ed7b67ed_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\65766b3305e92b392b4e caed3e364e18_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\65aca7f60d6f3fa52cc4 0836f64a5cbd_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6afb0875cb4c4c3e4772 658c2f5bb095_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6afc3d73c62b7e75721f bb7abfbd4e7f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\6f2272b6022c787dc289 d58ce42db221_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7137e2f03832831b48ea 293d6bb02bcc_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7158d419a34185ad9be4 68758e6acef1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7377fc822aca7e0cff3d 4ecf58236c7b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\770e0bb576a40d3de2cc 9f93791d8d5a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\79c599d4ee07db805b54 9237d881823b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7a63186dc2d915e84dcc e39f2eca016d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7dd270eb782a85a9db91 4d0e8a3ad3df_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7deb07ca420a9037f4d8 81bce8e2f54d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\7e8fff7f5ce5649b7f4f 46517d2ef05f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\806f8e2ec07f3bc5497f a4a443fe20f1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\80896dbe4e96840a3813 5602e37f90c5_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8153c606409a28550d12 c063e71e4823_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\83155faf742027e8e5ff 4fd78022a961_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8671199a9dcc6ff54925 d87786882a3a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\88df923f2597914ee313 2d25ed7f5d1f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\895f35f85a3a4f66b4a1 0d9112cbd7a8_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\89a4798572907d327b6a 6f62d149a65b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8a76f20517c38c846db2 c7064875012b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8b23e49ecbb575279a27 775ef14933ff_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\8f6e08cb4bf6de4fbef5 4bd190b55f54_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\90e84687048b8638a880 f31f738c1dcd_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\93734bc552f6c16951b2 7c97f730a02a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\943938cc4852a4e5beb8 55ddc656c1f4_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9bc5a593e165627aaf53 004f0938c2b0_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9bd5d182f58b862c700a bd3ff967eec0_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9c7530ba6e809e76a1d6 2aa2b8a5624d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9c8bc67177307b2722a4 aff38d421784_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\9e5650f451c335d2a54f ffb59ce488ea_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a0d362e48baf3fb83664 ae4038848044_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a0ecc159194dd82075a0 2fe21b1050e3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a18fa24df1b41c53e53b e36c0b104bed_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a447a46d09103149e7c3 35455be82074_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a48cacfac0d78767bb69 69ae8172f6b6_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a71d16a2ad9db8894948 159d1bb9653b_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a8332f150d52d0f3efee 5d6ae3943b72_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a86d809bb4fce01f3b14 a60c9ca3ef35_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\a8d553271c8d2f10b151 ffcbe03b8496_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aa15cf87a9fa78a1f09b 68df3f19b4d7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aa7b5990c05dbaf4b710 214973be0e0d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ab5e35aeda94da931eef 8bf96c4b2a49_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\abaf33b3afad287bc5b5 ac1afc97902a_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ac503547bd0e10abacb3 33b53b5a25f3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ac762e8c4d9b90a40f80 904524ccfa18_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\adf146f1cc86fb28fa9a b2dc9fc028eb_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\aea945771318b9bb5976 a97f23ff7ea4_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\af1ae7e63de744fd9397 98c62c39226e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b022f673cef6f7617187 19bff1d2fb47_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b0c8cd6cf1ebedd904dd 1ff90d0a3aea_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b0ddbb93713b5e35edf5 0942edc2ba6f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b4fffcfaa1730f76c38e aa109364939c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b595f4e03c66dca638a9 8249240d1495_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b81c8b806ec089b49f4d dbc1f043781f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b83c55c54e5eba057111 b4c3d344e443_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\b8c897e95bc5810ef05b b22c580059e6_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bb4c99d6e7076056e137 c2dedb8a642c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bd596b5b81262f3f746c b49c94bfb18e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\be5a0cb4b76812a4826c 13a3120eeeba_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\bf8ea0e8ea4c6ab871f4 b5ae14532776_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c30a12bf63e4d9ea1991 a637a789e15e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c6f7b270ebd6e89a8896 0783f4486f53_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\c7a7082ae9dc2dd6268f a342a9094b07_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ca19357ffd3997d1c9fb 296a22c29c8e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d375ab6d00a0e7fd9471 61c7ae2dd68f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d4196060fadcaeba5ae8 56306a062fda_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d4886f93c79698efdcba bd3c7472d768_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d79e015a1c9c566b6d85 a125a0769020_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d7b6e0a6f5004ea651ac 86728d67adb5_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d85224a7669a6377ecae f8ba1662948f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\d9c610e69cd8d483c91c a012ab51eb4f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\da04364d6b7396b3098a b1ee2f3991b5_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\dc2888aab134c4ca12e7 dbb2abdf73e1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\dc299bc1f94a5af8ecb6 6b83c305980e_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\dcb1838304127d55425a 08d63cd5b028_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\df2323260e2dad287f65 7e0353fb97a3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e13ffe01904f541933bb a65c773362f2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e15b26040c2469561709 4000fab0c9b3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e859c6b0f3d933359562 a4cbff6870d7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\e97e50fc16805c93daf5 8fa82a8fe32c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ea56a9d1116963032ade 760c28520a77_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\eaa130078da46ffad962 a56495d47a73_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\eb89a948d5cc4a4b613f 63fe1cd85210_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ebb3856608bdaa335f5a cb12f1ff3599_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f2114c0501ccd412ecb3 66dbaad54b67_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f46b0e4eea0326badf77 c43ba8bddca3_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f585949c44c5110efbf5 2bbb12e9b78d_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f6f54b32992d137651a4 3209d09a1b9c_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f7a9522581e7cb3bcc2d 515d78d96e79_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f7e1f01aed728769e701 6c530aa049b7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f8782d3f9d1698ec1330 78205e0868b7_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\f93751717ea9017df578 9c2196f1e834_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fab8018148753ab534c6 7ce9b62d20e5_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fb7ff82eb17af477fe33 f8f374b8f5e2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6f f1e01a5229f1_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fc8c0c43bfdfd0f5489c 136df9ac4628_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\fcf8d2a50d76fd1856ec 6831387be698_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ff21a30d058412c357f1 64b63ca3aa8f_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Crypto\RSA\MachineKeys\ffd21f18f65381dae16b 277802a84cc2_5393fbba-1086-4a5a-a206-b8dde46d31ed: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\eHome\Cache\S-1-5-20: Access is denied. ... ... . Failed to open \\?\c:\\Users\All Users\Microsoft\Network\Downloader: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\PlayReady\Cache\S-1-5-20: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Search\Data\Applications\Windows: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Search\Data\Temp\usgthrsvc: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\User Account Pictures\Lori.dat: Access is denied. .. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0141222f: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0156421d: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0156759b: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report02e550df: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report02e55523: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report02e555a0: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report02e5565b: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report03216586: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report03216660: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report032166fc: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report0b5a4059: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report35ddd54c: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report35dde3cd: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report35ddec07: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportArchive\Report79a2da37: Access is denied. Failed to open \\?\c:\\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0635d2f5: Access is denied. ..\\?\c:\\Users\Default\Application Data: JUNCTION Print Name : C:\Users\Default\AppData\Roaming Substitute Name: C:\Users\Default\AppData\Roaming \\?\c:\\Users\Default\Local Settings: JUNCTION Print Name : C:\Users\Default\AppData\Local Substitute Name: C:\Users\Default\AppData\Local \\?\c:\\Users\Default\My Documents: JUNCTION Print Name : C:\Users\Default\Documents Substitute Name: C:\Users\Default\Documents \\?\c:\\Users\Default\NetHood: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts \\?\c:\\Users\Default\PrintHood: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts \\?\c:\\Users\Default\Recent: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent \\?\c:\\Users\Default\SendTo: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo \\?\c:\\Users\Default\Start Menu: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu \\?\c:\\Users\Default\Templates: JUNCTION Print Name : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Template s Substitute Name: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Template s \\?\c:\\Users\Default\AppData\Local\Application Data: JUNCTION Print Name : C:\Users\Default\AppData\Local Substitute Name: C:\Users\Default\AppData\Local \\?\c:\\Users\Default\AppData\Local\History: JUNCTION Print Name : C:\Users\Default\AppData\Local\Microsoft\Windows\History Substitute Name: C:\Users\Default\AppData\Local\Microsoft\Windows\History \\?\c:\\Users\Default\AppData\Local\Temporary Internet Files: JUNCTION Print Name : C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files Substitute Name: C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files \\?\c:\\Users\Default\Documents\My Music: JUNCTION Print Name : C:\Users\Default\Music Substitute Name: C:\Users\Default\Music \\?\c:\\Users\Default\Documents\My Pictures: JUNCTION Print Name : C:\Users\Default\Pictures Substitute Name: C:\Users\Default\Pictures \\?\c:\\Users\Default\Documents\My Videos: JUNCTION Print Name : C:\Users\Default\Videos Substitute Name: C:\Users\Default\Videos \\?\c:\\Users\HP\Application Data: JUNCTION Print Name : C:\Users\HP\AppData\Roaming Substitute Name: C:\Users\HP\AppData\Roaming \\?\c:\\Users\HP\Cookies: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Cookies Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Cookies \\?\c:\\Users\HP\My Documents: JUNCTION Print Name : C:\Users\HP\Documents Substitute Name: C:\Users\HP\Documents \\?\c:\\Users\HP\NetHood: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Network Shortcuts Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Network Shortcuts \\?\c:\\Users\HP\PrintHood: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Printer Shortcuts Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Printer Shortcuts \\?\c:\\Users\HP\Recent: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Recent \\?\c:\\Users\HP\SendTo: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\SendTo Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\SendTo \\?\c:\\Users\HP\Start Menu: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Start Menu \\?\c:\\Users\HP\Templates: JUNCTION Print Name : C:\Users\HP\AppData\Roaming\Microsoft\Windows\Templates Substitute Name: C:\Users\HP\AppData\Roaming\Microsoft\Windows\Templates \\?\c:\\Users\HP\AppData\Local\Application Data: JUNCTION Print Name : C:\Users\HP\AppData\Local Substitute Name: C:\Users\HP\AppData\Local \\?\c:\\Users\HP\AppData\Local\History: JUNCTION Print Name : C:\Users\HP\AppData\Local\Microsoft\Windows\History Substitute Name: C:\Users\HP\AppData\Local\Microsoft\Windows\History \\?\c:\\Users\HP\AppData\Local\Temporary Internet Files: JUNCTION Print Name : C:\Users\HP\AppData\Local\Microsoft\Windows\Temporary Internet Files Substitute Name: C:\Users\HP\AppData\Local\Microsoft\Windows\Temporary Internet Files . ... ... ... ... ... ... ... ... ... ... ... ... ... ... . .. ... ... Failed to open \\? \c:\\Users\HP\AppData\LocalLow\AVG Security Toolbar\config.dat: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... ... ... . .\\?\c:\\Users\HP\Documents\My Music: JUNCTION Print Name : C:\Users\HP\Music Substitute Name: C:\Users\HP\Music \\?\c:\\Users\HP\Documents\My Pictures: JUNCTION Print Name : C:\Users\HP\Pictures Substitute Name: C:\Users\HP\Pictures \\?\c:\\Users\HP\Documents\My Videos: JUNCTION Print Name : C:\Users\HP\Videos Substitute Name: C:\Users\HP\Videos . ... ... ... ... ... ... ... ... ... ... ... ... ...\\? \c:\\Users\Lori\Application Data: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming Substitute Name: C:\Users\Lori\AppData\Roaming \\?\c:\\Users\Lori\Cookies: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Cookies Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Cookies \\?\c:\\Users\Lori\Local Settings: JUNCTION Print Name : C:\Users\Lori\AppData\Local Substitute Name: C:\Users\Lori\AppData\Local \\?\c:\\Users\Lori\My Documents: JUNCTION Print Name : C:\Users\Lori\Documents Substitute Name: C:\Users\Lori\Documents \\?\c:\\Users\Lori\NetHood: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Network Shortcuts Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Network Shortcuts \\?\c:\\Users\Lori\PrintHood: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Printer Shortcuts Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Printer Shortcuts \\?\c:\\Users\Lori\Recent: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Recent Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Recent \\?\c:\\Users\Lori\SendTo: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\SendTo Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\SendTo \\?\c:\\Users\Lori\Start Menu: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Start Menu Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Start Menu \\?\c:\\Users\Lori\Templates: JUNCTION Print Name : C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates Substitute Name: C:\Users\Lori\AppData\Roaming\Microsoft\Windows\Templates \\?\c:\\Users\Lori\AppData\Local\Application Data: JUNCTION Print Name : C:\Users\Lori\AppData\Local Substitute Name: C:\Users\Lori\AppData\Local \\?\c:\\Users\Lori\AppData\Local\History: JUNCTION Print Name : C:\Users\Lori\AppData\Local\Microsoft\Windows\History Substitute Name: C:\Users\Lori\AppData\Local\Microsoft\Windows\History \\?\c:\\Users\Lori\AppData\Local\Temporary Internet Files: JUNCTION Print Name : C:\Users\Lori\AppData\Local\Microsoft\Windows\Temporary Internet Files Substitute Name: C:\Users\Lori\AppData\Local\Microsoft\Windows\Temporary Internet Files ... Failed to open \\? \c:\\Users\Lori\AppData\Local\Microsoft\Windows\WER\ReportA rchive: Access is denied. Failed to open \\? \c:\\Users\Lori\AppData\Local\Microsoft\Windows\WER\ReportQ ueue: Access is denied. \\?\c:\\Users\Lori\Documents\My Music: JUNCTION Print Name : C:\Users\Lori\Music Substitute Name: C:\Users\Lori\Music \\?\c:\\Users\Lori\Documents\My Pictures: JUNCTION Print Name : C:\Users\Lori\Pictures Substitute Name: C:\Users\Lori\Pictures \\?\c:\\Users\Lori\Documents\My Videos: JUNCTION Print Name : C:\Users\Lori\Videos Substitute Name: C:\Users\Lori\Videos \\?\c:\\Users\Public\Documents\My Music: JUNCTION Print Name : C:\Users\Public\Music Substitute Name: C:\Users\Public\Music \\?\c:\\Users\Public\Documents\My Pictures: JUNCTION Print Name : C:\Users\Public\Pictures Substitute Name: C:\Users\Public\Pictures \\?\c:\\Users\Public\Documents\My Videos: JUNCTION Print Name : C:\Users\Public\Videos Substitute Name: C:\Users\Public\Videos Failed to open \\?\c:\\Windows\LiveKernelReports: Access is denied. Failed to open \\?\c:\\Windows\Minidump: Access is denied. Failed to open \\?\c:\\Windows\ModemLogs: Access is denied. Failed to open \\?\c:\\Windows\Prefetch: Access is denied. ... ... ... ... ... . Failed to open \\?\c:\\Windows\Logs\SystemRestore: Access is denied. Failed to open \\?\c:\\Windows\Logs\WindowsBackup: Access is denied. Failed to open \\?\c:\\Windows\Logs\CBS\CBS.log: Access is denied. Failed to open \\?\c:\\Windows\Logs\DPX\setupact.log: Access is denied. Failed to open \\?\c:\\Windows\Logs\DPX\setuperr.log: Access is denied. .. Failed to open \\? \c:\\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config: Access is denied. . Failed to open \\? \c:\\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe.config: Access is denied. . Failed to open \\? \c:\\Windows\Panther\UnattendGC\diagerr.xml: Access is denied. Failed to open \\? \c:\\Windows\Panther\UnattendGC\diagwrn.xml: Access is denied. Failed to open \\? \c:\\Windows\security\database\secedit.sdb: Access is denied. Failed to open \\? \c:\\Windows\ServiceProfiles\LocalService: Access is denied. Failed to open \\? \c:\\Windows\ServiceProfiles\NetworkService: Access is denied. . ... ... ... .. Failed to open \\? \c:\\Windows\System32\config: Access is denied. . Failed to open \\?\c:\\Windows\System32\ias: Access is denied. Failed to open \\?\c:\\Windows\System32\Msdtc: Access is denied. Failed to open \\?\c:\\Windows\System32\networklist: Access is denied. . Failed to open \\?\c:\\Windows\System32\WDI: Access is denied. Failed to open \\?\c:\\Windows\System32\wfp: Access is denied. .. ... ... ... ... ... ... ... ... .. Failed to open \\?\c:\\Windows\System32 \LogFiles\HTTPERR: Access is denied. Failed to open \\?\c:\\Windows\System32\LogFiles\WMI: Access is denied. Failed to open \\?\c:\\Windows\System32 \LogFiles\Firewall\pfirewall.log: Access is denied. Failed to open \\?\c:\\Windows\System32 \LogFiles\Firewall\pfirewall.log.old: Access is denied. . Failed to open \\?\c:\\Windows\System32 \restore\MachineGuid.txt: Access is denied. . Failed to open \\?\c:\\Windows\System32 \sysprep\Panther\diagerr.xml: Access is denied. Failed to open \\?\c:\\Windows\System32 \sysprep\Panther\diagwrn.xml: Access is denied. Failed to open \\?\c:\\Windows\System32 \sysprep\Panther\setupact.log: Access is denied. Failed to open \\?\c:\\Windows\System32 \sysprep\Panther\setuperr.log: Access is denied. Failed to open \\?\c:\\Windows\System32\wbem\MOF: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\0332A97878022BD4B34ECC098E57783A.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\040270F850D5C3C91057DDDA2DA294D8.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\073C87A5E65451B9C103BE54832C90C3.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\0FF162C67AD719BB7258CA5874D0E6EC.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\1328355F476A6C04BC174C8FEFED6030.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\14C5A2A3C41254184B007011E5565E5B.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\191095FB4864B1AE365957B3B2D28C4F.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\1A4E55E3BE96FF394FB5020C4D537AB1.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\1F260613E85F3D0BACEC07DCEF35396B.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\22A0F05220E6420CA3AA86E34805F752.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\241F1954DCD7B0310958D9540754CEC3.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\2CEA854D125A606E70A7CD04392A2AAE.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\394EF2A769C648E61B41BFAD23BACF0E.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\39EF661167099C8B2F81F813871BA3BC.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\3CF854648793305D1D2A7AC41F80E9D6.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\3DFD050CBBC8EA38EA5F1066285F0F4E.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\3E2EEA84B9C48DACD55F3E7EF12AC696.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\3EFE5AEBC6F1152375E7674497F7043F.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\3FC136B9AA8D71056333AF0137119E93.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\422F2CA2C538F8B8C6D7F7D2B92DC785.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\43AF8F4749656456F363ECA1D9B30B00.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\4461018BFFC22A809EBE8FA05567B686.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\451233ED13E097000776690B79D8D753.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\45D86E53E6ADF70035B0034F9D8C42FE.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\4B2660072B052959CB2A0C8B6A1E9B6A.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\4FFAA3E7CB3131376614E98F756EE7AD.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\542DC56D520FDDEDA279A0D2F398203D.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\58F6DC94AE063187572E906AE0B9DC24.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\5F8AAE81E6AA25DDECD426311EDC3CEA.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\6389D91E49CCAF02640B61214A97211F.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\63E48B1766A961491E55D10F8F08C0E7.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\66231762529A003735024004DCDE643C.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\68C49405800705A386C338BECA8D0719.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\6DD1779321E1C86B32D09A35DA5E4ED2.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\6F8564A71977AE6B940705DCC4847A8D.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\716FDC254E211F547A560E1A71D0E6CA.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\734834D588DA61453DEA4E0AF499ADCE.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\7424188A11F3D829BB76C98170DB45E5.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\79CD84A83C85E4F4FEED13F704AFD1A6.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\7A7E1B1832596F5C49CD70E9755EED39.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\7C45C8B7490D3AD44A961494C7FBFAFD.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\7DFE880F785D5AB82870BFC0C3F814A2.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\8608CDBF407B09DF27C3406379384843.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\86824C24FDE0A58E4EB1A7918FBEF0C5.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\8911086DE2019A3125DB34F979DF099B.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\89B278BD994A4232365F0E916C19916C.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\8E7C06671AFE3C491CA1A729ECB02971.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\902DBFF6F0C3BF7CE18405EF33C5B2C0.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\9202D7C90F498A9BFE4E12205CBE26F1.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\9B2AE30BDA2ED3E7E1378B8770C99C54.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\9FB731EA48C7701EB7978CEB7E0314AD.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\A02DB69DBBC4F298AD0CE59F677EBF22.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\A851D3BCFCE697C24E7112D24AFBE9E3.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\B7890DE53F3A6B3C277523E82A081C04.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\B88E8B639804BA063AC1D11AC4C196C1.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\BA991ACFF19ADCEED9AFD4DD6559F22A.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\BBF206490BAA431B592F9A13534F43F6.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\BF2ADAFC80AB82D412CD9F0B99A0AD2C.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\C3613D92FBA5F820823577D6FC2CE8A9.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\C599AFA5A6F053BAD70179501868318E.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\C5B3C3C921790F19FCDE9367A797A2EF.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\CF881EBD6F50B8BAA9BD57DC3DAC5CB2.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\CFD53C8456D58010BA580B1D5CFF68D3.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\D361F8B496FD6DAF7BEEF497E09C0DC1.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\D4CB64722F050ABEB5F8B6B143A19A6C.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\D5B60695D4528B9B368FC0C80DC5129F.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\D6149C45B68480CA184F2D9C7CB312A5.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\DED51090917AEE019629CE420A50F3C2.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\DF2FB1F3C8DCD25B01FDE5A4697177CB.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\E6195BA9E153534E5472835E2F29A5B0.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\EC4E4D2526C1F24E4D610677CF1EA0E7.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\EEDD6F5F4BEDFEA1C780FFC78DCDE051.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\F001D607C389EDBCFB1D1F3C9AE0FFC5.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\F1E5535EC8A153BF2EB4F202C2704228.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\FA01281653BC6D33CB10F9E5C36E4047.mof: Access is denied. Failed to open \\?\c:\\Windows\System32 \wbem\AutoRecover\FBD0E57ECE5A9402023443B148D93F98.mof: Access is denied. . Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Application.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32\winevt\Logs\DFS Replication.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\HardwareEvents.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Internet Explorer.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32\winevt\Logs\Key Management Service.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32\winevt\Logs\Media Center.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Bits-Client% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Bluetooth-MTPEnum% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-CodeIntegrity% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Diagnosis-DPS% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Diagnosis-PLA% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Diagnostics-Networking% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Diagnostics-Performance% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows- DiskDiagnosticDataCollector%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Forwarding% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-GroupPolicy% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Help%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-International% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Kernel-WDI% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-LanguagePackSetup% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-NetworkAccessProtection% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-ParentalControls% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-PowerShell% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-ReadyBoost% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows- ReliabilityAnalysisComponent%4Metrics.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows- ReliabilityAnalysisComponent%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-RemoteAssistance% 4Admin.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-RemoteAssistance% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Resource-Exhaustion- Detector%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Resource-Exhaustion- Resolver%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-RestartManager% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-TaskScheduler% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-UAC-FileVirtualization% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-WindowsUpdateClient% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-WinRM%4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-Winsock-WS2HELP% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-WLAN-AutoConfig% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-WPD-ClassInstaller% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Microsoft-Windows-WPD-MTPClassDriver% 4Operational.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\OAlerts.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Security.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\Setup.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32 \winevt\Logs\System.evtx: Access is denied. Failed to open \\?\c:\\Windows\System32\winevt\Logs\Windows PowerShell.evtx: Access is denied. Failed to open \\?\c:\\Windows\SysWOW64\config: Access is denied. . Failed to open \\?\c:\\Windows\SysWOW64\ias: Access is denied. Failed to open \\?\c:\\Windows\SysWOW64\Msdtc: Access is denied. Failed to open \\?\c:\\Windows\SysWOW64\networklist: Access is denied. ... ... Failed to open \\? \c:\\Windows\Tasks\FreeFileViewerUpdateChecker.job: Access is denied. Failed to open \\? \c:\\Windows\Tasks\GoogleUpdateTaskMachineCore.job: Access is denied. Failed to open \\? \c:\\Windows\Tasks\GoogleUpdateTaskMachineUA.job: Access is denied. Failed to open \\? \c:\\Windows\Tasks\HPCeeScheduleForHP.job: Access is denied. Failed to open \\? \c:\\Windows\Tasks\PCDRScheduledMaintenance.job: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... ... ... . .. ... ... ... ... Failed to open \\? \c:\\Windows\winsxs\amd64_microsoft-windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.18000_none _2d4d2c2fee5d2889\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\amd64_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.18226_none _2d3d91dfee67f2c3\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\amd64_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.22389_none _2d89500107b38638\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\amd64_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6002.18005_none _2f38a53beb7ef3d5\dnary.xsd: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... ... ... . .. ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... ... . Failed to open \\?\c:\\Windows\winsxs\x86_microsoft-windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.18000_none _d12e90ac35ffb753\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\x86_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.18226_none _d11ef65c360a818d\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\x86_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6001.22389_none _d16ab47d4f561502\dnary.xsd: Access is denied. Failed to open \\?\c:\\Windows\winsxs\x86_microsoft- windows- n..n_service_datastore_31bf3856ad364e35_6.0.6002.18005_none _d31a09b83321829f\dnary.xsd: Access is denied. .. ... ... ..
  10. Gringo - thanks for sticking with this. I've completed the above steps and have attached the log file below. I had to break it into two posts, as it was too long. Hope this can help. Thanks! Junction v1.06 - Windows junction creator and reparse point viewer Copyright © 2000-2010 Mark Russinovich Sysinternals - www.sysinternals.com Failed to open \\?\c:\\Config.Msi: Access is denied. \\?\c:\\Documents and Settings: JUNCTION Print Name : C:\Users Substitute Name: C:\Users Failed to open \\?\c:\\MSOCache: Access is denied. Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\PerfLogs: Access is denied. Failed to open \\?\c:\\System Volume Information: Access is denied. ... ... ... ... ... Failed to open \\? \c:\\Program Files\PC-Doctor for Windows\pcdroverrides.p5i: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... ... ... . .. ... ... ... ... ... ... ... ... Failed to open \\?\c:\\Program Files (x86) \Google\CrashReports: Access is denied. ... ... ... ... ... ... ... Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B- 0C564F9E8E79}\setup.ilg: Access is denied. Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5- 0009C5020658}\setup.ilg: Access is denied. Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA- 0121CCFC1243}\setup.ilg: Access is denied. ... ... ... ... ... ... ... . .. ... ... ... ... ...\\? \c:\\ProgramData\Application Data: JUNCTION Print Name : C:\ProgramData Substitute Name: C:\ProgramData \\?\c:\\ProgramData\Desktop: JUNCTION Print Name : C:\Users\Public\Desktop Substitute Name: C:\Users\Public\Desktop \\?\c:\\ProgramData\Documents: JUNCTION Print Name : C:\Users\Public\Documents Substitute Name: C:\Users\Public\Documents \\?\c:\\ProgramData\Favorites: JUNCTION Print Name : C:\Users\Public\Favorites Substitute Name: C:\Users\Public\Favorites Failed to open \\?\c:\\ProgramData\sentinel: Access is denied. \\?\c:\\ProgramData\Start Menu: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Start Menu Substitute Name: C:\ProgramData\Microsoft\Windows\Start Menu \\?\c:\\ProgramData\Templates: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Templates Substitute Name: C:\ProgramData\Microsoft\Windows\Templates Failed to open \\?\c:\\ProgramData\{93E26451-CD9A-43A5- A2FA-C42392EA4001}: Access is denied. ... ... ... ... ... ... ... Failed to open \\?\c:\\ProgramData\Hewlett-Packard\HP Print Settings\HP4orv63.cfg: Access is denied. ... Failed to open \\? \c:\\ProgramData\Microsoft\Microsoft Antimalware: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows Defender: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\S-1-5-18: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\016324893 36ded7e6f0782b274f8dae7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0344065c8 48389af10876d14913c01e2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\03bf2caf4 0a5c2db9bfada378e67396e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\044196731 b7b41087590b26944d01d5b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0c12c45ee 466e5607464285bb89e11a8_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10c1fade1 4df8bbe712183fe55c81e02_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10e6a3265 2b93ae16eb22e2292ff8150_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\112b2cc4f 4df13b57c8505a077f80dd6_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13b837617 93b8f99e30694e9858d92a2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\184a284d6 cdd70d596ff6fb490051aee_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\190ee855f 153c072b5053111ae850a95_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1c7025640 ade2c21f6708aee40527292_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1dd7a627d 49ca00341a3f0024e8ea540_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1f866c167 4b80f1c901629c4956c9b43_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\20bef3731 e4de3d0703df1b6e9629d5f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\21736392a f395f8cbf0b0b303085b6f7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\222753a64 ed8ae7df8662ce713e5741c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22c975d59 ac3b5331684ccdfb471ca3b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22d81b2f9 5990d5b0763a1b93d93d474_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2394e9857 7faef5e8503ec3461aad388_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\258ae4c8f 9ba0ef2db063954dfc9a744_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2660855ef 783da37a1721de38ca0f509_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\26902aae4 790758f32de9eeb3477a490_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2721e2409 d0e34e6730a360e1f299db0_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\27ac51a5e 38972dc308294cf3a50262a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29738da76 7aca837c5920c408579b11a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29c5fb05b 9527cd25a78f67d407a1096_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ab2e0619 af9a700e2264ae003bde82f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ac50d254 4841f26e701f7b84b73cead_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2b18b5387 d89d4807afe301e9125c547_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2c98a3692 0c601422fde9ca87b38f46a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2cba9b28a 02a7ee0b7bf61564d9e1c70_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2eabc9858 a9c72a46ed6b8b995b78a6f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ed93740e 679d22976e9e2a80e3565ff_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f1ffeec6 c7cd834cf9b2570929ca4bf_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\308a6c612 a24634a5eee5f9e11ba941e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30d6a4ae2 1a69cd18c83e94051e38bdf_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30f7e7e61 79ac3807966a7b2c8a06c58_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\310c7e3c2 0fa6ba306b2eed4fab0bcc9_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3315ab93f b13c140c1e46c64131b049a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\35c5395c2 10cc5b95e99ed9ce8d9c043_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\36250df08 e5dcb2ab0d6fafac98901dd_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3847b6c77 a4d225d4005ae12c045bb83_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\394facc68 73805f93a77e936d337e215_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3a7a76a73 eee511a25d7d6449e1b754d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3ad8d90ad 583c1a345077e74c4d84fb2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c0aaaa4d acbf306516bf96dfc978a16_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3d59d8443 073141766b91e062157887c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e0982fda a00c161df66aae1b62e72a7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e4032519 e49459186b356ba8331c5d7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f5ee4cdb 20084c06c3d4a12e1a69cd6_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\401fb885b 49553e88d17729a546d33f1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\40e5865ca 461f7ab4796dc87dd3068e1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\40fb83ed9 afd7797ba2e73b74f2e4cbc_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\42b733d18 311c3b1690fd23ae721f573_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\42fff0fb5 e4c9663073dee0e2600ef73_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\433fd8e51 86d7781764958f56cd9ac9b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\43c1a2b5c 0d452e0c9276cd5963b2187_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\444d5cddd c1338466b3b7570a01d9da2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\44f99965b 738d94488c41012c4329823_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\455833f7e f9005208b8d1a5347fc0b88_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\45f8e9ab7 ebe4498ec00395155554f8d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4689ed430 bb919ed0258f67950b69fb4_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4858c0387 6bf9e2031890ebba7aabf4b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48ff11c44 c01bc442652e36849c7834c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\490fef58c 1c5dcb6eaedea8ee19147c9_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a2584924 ad9e2ae4769c86b47bb2395_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4ae77574b ce2596222196437bb946558_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4c6a4e98d e1878afcf00144c57da751a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4dfc5fb30 c9a054aab77af0d9a20bfa3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\509568349 05a2efdb5c8002ff5199ab3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\51597e6ec ac7e38bde4fc5508ef88444_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\53227fca1 67a3a28812c6203b36ee8f4_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5488a6aa8 1a598c3e2bdde2fb9b8ec94_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\55c4dfff1 6ba53490d6f2ef9ad67d619_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\55f422205 195dd23fc380e3438578c17_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\573aa4064 01fd4a0ae3350a2e36b9778_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\577d2f6e2 c1ed6f19c33d02a74d11263_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5784c8562 6a8362cc2f43f8c6d071fe6_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a83b4bc3 1e3fd4f3ff340097cd62949_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5ad38adfb d8983d259cd158280656542_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5b87ffaf8 790e74ffad1419d78339bdc_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5b8bbe6ca e3f5bd03c13f1f0ecdf0e4b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5c12c97ac 7a4708fb4d484bb19fdcc33_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5d620a1ce 61623c6d475c077d49de34f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5f7bc3c64 dbe9b5544ce6af838efec0e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6186570bd ea26caeec26024a5ffe0365_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\61ab69584 48e8158e43c6a0d1de0a689_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\627eec192 88bbfda4b3de178ed7b67ed_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\65766b330 5e92b392b4ecaed3e364e18_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\65aca7f60 d6f3fa52cc40836f64a5cbd_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6afb0875c b4c4c3e4772658c2f5bb095_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6afc3d73c 62b7e75721fbb7abfbd4e7f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6f2272b60 22c787dc289d58ce42db221_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7137e2f03 832831b48ea293d6bb02bcc_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7158d419a 34185ad9be468758e6acef1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7377fc822 aca7e0cff3d4ecf58236c7b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\770e0bb57 6a40d3de2cc9f93791d8d5a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\79c599d4e e07db805b549237d881823b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a63186dc 2d915e84dcce39f2eca016d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7dd270eb7 82a85a9db914d0e8a3ad3df_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7deb07ca4 20a9037f4d881bce8e2f54d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7e8fff7f5 ce5649b7f4f46517d2ef05f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\806f8e2ec 07f3bc5497fa4a443fe20f1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80896dbe4 e96840a38135602e37f90c5_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8153c6064 09a28550d12c063e71e4823_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\83155faf7 42027e8e5ff4fd78022a961_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8671199a9 dcc6ff54925d87786882a3a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\88df923f2 597914ee3132d25ed7f5d1f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\895f35f85 a3a4f66b4a10d9112cbd7a8_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\89a479857 2907d327b6a6f62d149a65b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a76f2051 7c38c846db2c7064875012b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8b23e49ec bb575279a27775ef14933ff_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8f6e08cb4 bf6de4fbef54bd190b55f54_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\90e846870 48b8638a880f31f738c1dcd_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93734bc55 2f6c16951b27c97f730a02a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\943938cc4 852a4e5beb855ddc656c1f4_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9bc5a593e 165627aaf53004f0938c2b0_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9bd5d182f 58b862c700abd3ff967eec0_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c7530ba6 e809e76a1d62aa2b8a5624d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9c8bc6717 7307b2722a4aff38d421784_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9e5650f45 1c335d2a54fffb59ce488ea_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a0d362e48 baf3fb83664ae4038848044_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a0ecc1591 94dd82075a02fe21b1050e3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a18fa24df 1b41c53e53be36c0b104bed_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a447a46d0 9103149e7c335455be82074_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a48cacfac 0d78767bb6969ae8172f6b6_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a71d16a2a d9db8894948159d1bb9653b_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8332f150 d52d0f3efee5d6ae3943b72_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a86d809bb 4fce01f3b14a60c9ca3ef35_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8d553271 c8d2f10b151ffcbe03b8496_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa15cf87a 9fa78a1f09b68df3f19b4d7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa7b5990c 05dbaf4b710214973be0e0d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab5e35aed a94da931eef8bf96c4b2a49_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\abaf33b3a fad287bc5b5ac1afc97902a_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac503547b d0e10abacb333b53b5a25f3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ac762e8c4 d9b90a40f80904524ccfa18_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\adf146f1c c86fb28fa9ab2dc9fc028eb_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aea945771 318b9bb5976a97f23ff7ea4_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af1ae7e63 de744fd939798c62c39226e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b022f673c ef6f761718719bff1d2fb47_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0c8cd6cf 1ebedd904dd1ff90d0a3aea_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b0ddbb937 13b5e35edf50942edc2ba6f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b4fffcfaa 1730f76c38eaa109364939c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b595f4e03 c66dca638a98249240d1495_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b81c8b806 ec089b49f4ddbc1f043781f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b83c55c54 e5eba057111b4c3d344e443_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b8c897e95 bc5810ef05bb22c580059e6_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb4c99d6e 7076056e137c2dedb8a642c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bd596b5b8 1262f3f746cb49c94bfb18e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\be5a0cb4b 76812a4826c13a3120eeeba_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bf8ea0e8e a4c6ab871f4b5ae14532776_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c30a12bf6 3e4d9ea1991a637a789e15e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c6f7b270e bd6e89a88960783f4486f53_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c7a7082ae 9dc2dd6268fa342a9094b07_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ca19357ff d3997d1c9fb296a22c29c8e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d375ab6d0 0a0e7fd947161c7ae2dd68f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d4196060f adcaeba5ae856306a062fda_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d4886f93c 79698efdcbabd3c7472d768_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d79e015a1 c9c566b6d85a125a0769020_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d7b6e0a6f 5004ea651ac86728d67adb5_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d85224a76 69a6377ecaef8ba1662948f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d9c610e69 cd8d483c91ca012ab51eb4f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da04364d6 b7396b3098ab1ee2f3991b5_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dc2888aab 134c4ca12e7dbb2abdf73e1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dc299bc1f 94a5af8ecb66b83c305980e_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dcb183830 4127d55425a08d63cd5b028_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df2323260 e2dad287f657e0353fb97a3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e13ffe019 04f541933bba65c773362f2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e15b26040 c24695617094000fab0c9b3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e859c6b0f 3d933359562a4cbff6870d7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e97e50fc1 6805c93daf58fa82a8fe32c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ea56a9d11 16963032ade760c28520a77_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eaa130078 da46ffad962a56495d47a73_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb89a948d 5cc4a4b613f63fe1cd85210_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ebb385660 8bdaa335f5acb12f1ff3599_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2114c050 1ccd412ecb366dbaad54b67_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f46b0e4ee a0326badf77c43ba8bddca3_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f585949c4 4c5110efbf52bbb12e9b78d_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f6f54b329 92d137651a43209d09a1b9c_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f7a952258 1e7cb3bcc2d515d78d96e79_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f7e1f01ae d728769e7016c530aa049b7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f8782d3f9 d1698ec133078205e0868b7_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f93751717 ea9017df5789c2196f1e834_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fab801814 8753ab534c67ce9b62d20e5_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fb7ff82eb 17af477fe33f8f374b8f5e2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f 429ea606d6ff1e01a5229f1_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc8c0c43b fdfd0f5489c136df9ac4628_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fcf8d2a50 d76fd1856ec6831387be698_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff21a30d0 58412c357f164b63ca3aa8f_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ffd21f18f 65381dae16b277802a84cc2_5393fbba-1086-4a5a-a206- b8dde46d31ed: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\eHome\Cache\S -1-5-20: Access is denied. ... ... .. Failed to open \\? \c:\\ProgramData\Microsoft\Network\Downloader: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\PlayReady\Cache\S-1-5-20: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Search\Data\Applications\Windows : Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\User Account Pictures\Lori.dat: Access is denied. . Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 0141222f: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 0156421d: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 0156759b: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 02e550df: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 02e55523: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 02e555a0: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 02e5565b: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 03216586: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 03216660: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 032166fc: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 0b5a4059: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 35ddd54c: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 35dde3cd: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 35ddec07: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Report 79a2da37: Access is denied. Failed to open \\? \c:\\ProgramData\Microsoft\Windows\WER\ReportQueue\Report06 35d2f5: Access is denied. .. Failed to open \\?\c:\\Qoobox\BackEnv: Access is denied. \\?\c:\\Users\All Users: SYMBOLIC LINK Print Name : C:\ProgramData Substitute Name: \??\C:\ProgramData \\?\c:\\Users\Default User: JUNCTION Print Name : C:\Users\Default Substitute Name: C:\Users\Default \\?\c:\\Users\All Users\Application Data: JUNCTION Print Name : C:\ProgramData Substitute Name: C:\ProgramData \\?\c:\\Users\All Users\Desktop: JUNCTION Print Name : C:\Users\Public\Desktop Substitute Name: C:\Users\Public\Desktop \\?\c:\\Users\All Users\Documents: JUNCTION Print Name : C:\Users\Public\Documents Substitute Name: C:\Users\Public\Documents \\?\c:\\Users\All Users\Favorites: JUNCTION Print Name : C:\Users\Public\Favorites Substitute Name: C:\Users\Public\Favorites
  11. Gringo, I haven't heard back in a couple days and was just dropping a note to see if you are expecting something else from me at this time. Or perhaps that I am a lost cause... Let me know if there is something else that you need. Thanks!
  12. Gringo, I have performed the following: - Uninstalled Adobe Reader - no issues - Re-installed Adobe Reader - no issues - Ran CCleaner - no issues - Tried to run Malwarebytes - unable to run, same error: "This program is blocked by group policy. For more information, contact your system administrator." - Ran HijackThis program - no issues - the following is the log file: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 1:59:38 PM, on 5/4/2013 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v9.00 (9.00.8112.16476) Boot mode: Normal Running processes: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files (x86)\Adobe\Elements 10 Organizer\ElementsOrganizerSyncAgent.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\hp\support\hpsysdrv.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe C:\Users\HP\Desktop\Secure\Post10\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file) O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing) O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing) O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [DVDAgent] "c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" O4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup O4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKCU\..\Run: [PhotoshopElements8SyncAgent] C:\Program Files (x86)\Adobe\Elements 10 Organizer\ElementsOrganizerSyncAgent.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe -update activex O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{67899D8C-147F-49E2-ABE5-D064EEC25557}: NameServer = 216.51.173.2,216.51.173.1 O17 - HKLM\System\CS1\Services\Tcpip\..\{67899D8C-147F-49E2-ABE5-D064EEC25557}: NameServer = 216.51.173.2,216.51.173.1 O17 - HKLM\System\CS2\Services\Tcpip\..\{67899D8C-147F-49E2-ABE5-D064EEC25557}: NameServer = 216.51.173.2,216.51.173.1 O18 - Protocol: jpip - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files (x86)\LizardTech\Express View\expressview.dll O18 - Protocol: sidlet - {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files (x86)\LizardTech\Express View\expressview.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll O23 - Service: Adobe Active File Monitor V10 (AdobeActiveFileMonitor10.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: Lexar Secure II (LxrSII1s) - Lexar Media, Inc. - C:\Windows\system32\LxrSII1s.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe O23 - Service: PskSvcRetailInst - Unknown owner - C:\Users\HP\AppData\Local\Temp\ISSCAN\PskSvc.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: vToolbarUpdater14.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 11332 bytes
  13. Gringo - here is the report: ActiveCheck component for HP Active Support Library Adobe AIR Adobe Community Help Adobe Flash Player 11 ActiveX Adobe Photoshop Elements 10 Adobe Photoshop.com Inspiration Browser Adobe Reader X (10.1.6) Adobe Shockwave Player 11.5 Amazon Music Importer AnswerWorks 5.0 English Runtime AOL Toolbar Apple Application Support Apple Software Update AVG Security Toolbar Bing Bar Bing Rewards Client Installer BufferChm Cakewalk Sound Center 1.1.0 Canon Camera TWAIN Driver Canon EOS Kiss REBEL 300D TWAIN Driver Canon PhotoRecord Canon RAW Codec Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities Digital Photo Professional 3.7 Canon Utilities File Viewer Utility 1.3 Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch 3.1 Canon Utilities RemoteCapture 2.7 Canon Utilities RemoteCapture DC Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility Cards_Calendar_OrderGift_DoMorePlugout Compatibility Pack for the 2007 Office system Copy Corel Paint Shop Pro Photo X2 CyberLink DVD Suite Deluxe Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Destinations DeviceDiscovery DJ_AIO_05_F4400_Software_Min Download Updater (AOL Inc.) Elements 10 Organizer F4400 File Type Assistant File Viewer Utility 1.3.2 Free File Viewer 2011 Garmin Communicator Plugin Garmin Trip and Waypoint Manager v5 Garmin USB Drivers Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper GoToMeeting 4.1.0.366 GPBaseService2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Advisor HP Customer Experience Enhancements HP Customer Feedback HP Demo HP MediaSmart DVD HP Photo Creations HP Photosmart Essential 2.5 HP Recovery Manager RSS HP Update HP_Network_UserGuide HPAsset component for HP Active Support Library HPDiagnosticAlert HPPhotoGadget HPPhotoSmartPhotobookWebPack1 hpPrintProjects HPProductAssistant HPSSupply HPTCSSetup hpWLPGInstaller iPhone Configuration Utility Java Auto Updater LabelPrint LightScribe System Software LightScribeTemplateLabeler Lizardtech Express View Browser Plug-in Malwarebytes Anti-Malware version 1.75.0.1300 MarketResearch Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office 97, Professional Edition Microsoft Office Access MUI (English) 2010 Microsoft Office Access Setup Metadata MUI (English) 2010 Microsoft Office Excel MUI (English) 2010 Microsoft Office Groove MUI (English) 2010 Microsoft Office InfoPath MUI (English) 2010 Microsoft Office OneNote MUI (English) 2010 Microsoft Office Outlook MUI (English) 2010 Microsoft Office PowerPoint MUI (English) 2010 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Professional Plus 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (Spanish) 2010 Microsoft Office Proofing (English) 2010 Microsoft Office Publisher MUI (English) 2010 Microsoft Office Shared MUI (English) 2010 Microsoft Office Shared Setup Metadata MUI (English) 2010 Microsoft Office Word MUI (English) 2010 Microsoft Silverlight Microsoft UI Engine Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Works MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Music Creator LE 5.0.6 muvee autoProducer 6.1 My HP Games MyFreeCodec Panda Internet Security 2009 PhotoShow Deluxe 4 PhotoStitch Power2Go PowerDirector PS_AIO_02_Software_Min PSE10 STI Installer PSSWCORE Python 2.5.2 Quicken 2008 QuickTime RAW Image Task Realtek High Definition Audio Driver RemoteCapture 2.7.5 RemoteCapture Task Revo Uninstaller 1.94 Safari Samsung Kies Scan Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2687422) 32-Bit Edition Security Update for Microsoft InfoPath 2010 (KB2760406) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition Security Update for Microsoft Visio 2010 (KB2760762) 32-Bit Edition Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition SmartWebPrinting SolutionCenter sp41119 Spelling Dictionaries Support For Adobe Reader 9 Status Toolbox TrayApp Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Office 2010 (KB2494150) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition Update Installer for WildTangent Games App VideoToolkit01 Visual C++ 8.0 Runtime Setup Package (x64) Visual Studio 2008 x64 Redistributables WebEx WebReg WildTangent Games App (HP Games) Yahoo! BrowserPlus 2.8.1 Yahoo! Toolbar
  14. Internet Explorer has seemed to be rock solid, with no unanticipated shutdowns for several days. So, before we launch into trying to solve this final issue, THANK YOU! The only issue that we still have is when I try to start the newly installed Malwarebytes' Anti-Malware, I still get the error: "This program is blocked by group policy. For more information, contact your system administrator." Any ideas what might be driving this?
  15. Ok, Gringo, it looks as though ComboFix ran in safe mode, however, it gave a "reduced functionality mode" warning. It also warned me that the real time protection from Microsoft Security Essentials was on, when I had it disabled. Here is the log file: ComboFix 13-04-22.01 - HP 05/01/2013 15:45:43.1.4 - x64 MINIMAL Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.3366 [GMT -5:00] Running from: c:\users\HP\Desktop\Secure\Post4\ComboFix.exe AV: Microsoft Security Essentials *Enabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5} SP: Microsoft Security Essentials *Enabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . - REDUCED FUNCTIONALITY MODE - . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\HP\AppData\Roaming\completescan c:\users\HP\AppData\Roaming\install c:\windows\SysWow64\muzapp.exe . . ((((((((((((((((((((((((( Files Created from 2013-04-01 to 2013-05-01 ))))))))))))))))))))))))))))))) . . 2013-05-01 20:49 . 2013-05-01 20:49 -------- d-----w- c:\users\Lori\AppData\Local\temp 2013-05-01 20:49 . 2013-05-01 20:49 -------- d-----w- c:\users\HP\AppData\Local\temp 2013-05-01 20:49 . 2013-05-01 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-05-01 14:32 . 2013-04-10 03:46 9317456 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8E546ACF-15C5-4AD2-BEDC-9E37CC81746D}\mpengine.dll 2013-04-30 14:33 . 2013-04-10 03:46 9317456 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2013-04-27 14:24 . 2013-04-27 14:24 -------- d-----w- c:\programdata\Malwarebytes 2013-04-27 14:24 . 2013-04-27 14:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-04-27 14:24 . 2013-04-04 19:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-04-25 12:52 . 2013-04-25 12:50 905296 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A924FC93-A14C-41F3-B736-42E1E19FC6A7}\gapaengine.dll 2013-04-22 01:38 . 2013-04-22 01:37 971680 ----a-w- c:\windows\system32\deployJava1.dll 2013-04-22 01:38 . 2013-04-22 01:37 311200 ----a-w- c:\windows\system32\javaws.exe 2013-04-22 01:38 . 2013-04-22 01:37 1092512 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-04-22 01:37 . 2013-04-22 01:37 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll 2013-04-22 01:37 . 2013-04-22 01:37 188832 ----a-w- c:\windows\system32\javaw.exe 2013-04-22 01:37 . 2013-04-22 01:37 188320 ----a-w- c:\windows\system32\java.exe 2013-04-22 01:37 . 2013-04-22 01:37 -------- d-----w- c:\program files\Java 2013-04-18 01:30 . 2013-04-18 01:30 -------- d-----w- c:\program files\Microsoft ATS 2013-04-13 18:54 . 2013-04-13 18:54 -------- d-----w- c:\program files (x86)\Common Files\Software Update Utility 2013-04-10 17:14 . 2013-03-03 19:13 1513320 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 17:14 . 2013-03-11 13:33 4691304 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-04-10 17:14 . 2013-03-09 04:16 85504 ----a-w- c:\windows\system32\csrsrv.dll 2013-04-10 17:14 . 2013-03-09 01:48 75264 ----a-w- c:\windows\system32\smss.exe 2013-04-10 17:14 . 2013-03-05 01:57 2774016 ----a-w- c:\windows\system32\win32k.sys 2013-04-10 17:14 . 2013-03-08 04:18 451072 ----a-w- c:\windows\system32\winsrv.dll 2013-04-10 17:14 . 2013-03-08 04:17 2425344 ----a-w- c:\windows\system32\mstscax.dll 2013-04-10 17:14 . 2013-03-08 03:52 2067968 ----a-w- c:\windows\SysWow64\mstscax.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-04-11 08:05 . 2006-11-02 12:35 72702784 ----a-w- c:\windows\system32\mrt.exe 2013-04-02 10:34 . 2009-10-02 21:59 282744 ------w- c:\windows\system32\MpSigStub.exe 2013-03-16 22:11 . 2012-06-24 15:06 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-03-16 22:11 . 2011-06-10 12:22 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-03-07 20:49 . 2010-02-16 22:35 952 --sha-w- c:\programdata\KGyGaAvL.sys 2013-02-19 03:30 . 2012-08-27 08:01 39768 ----a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-02-12 02:18 . 2013-03-21 17:54 19456 ----a-w- c:\windows\system32\drivers\usb8023.sys 2013-02-05 19:36 . 2013-02-05 19:36 111104 ----a-w- c:\windows\system32\choifpmp64.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PhotoshopElements8SyncAgent"="c:\program files (x86)\Adobe\Elements 10 Organizer\ElementsOrganizerSyncAgent.exe" [2011-09-01 1954456] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-12-23 152064] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352] "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2013-03-24 1151152] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2013-02-20 152392] "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536] "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208] "HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008] "DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-09-09 1148200] "Corel Photo Downloader"="c:\program files (x86)\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2008-08-08 532808] "Corel File Shell Monitor"="c:\program files (x86)\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2008-08-08 16712] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\85285965.sys] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd] @="Driver" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc] @="Service" . R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-01 169624] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ECACHE . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs Themes ezSharedSvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-04-20 15:37 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-05-01 c:\windows\Tasks\FreeFileViewerUpdateChecker.job - c:\program files (x86)\FreeFileViewer\FFVCheckForUpdates.exe [2011-12-03 21:24] . 2013-04-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-12 18:55] . 2013-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-12 18:55] . 2013-04-06 c:\windows\Tasks\HPCeeScheduleForHP.job - c:\program files (x86)\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2008-12-23 04:03] . 2013-04-11 c:\windows\Tasks\PCDRScheduledMaintenance.job - c:\program files\PC-Doctor for Windows\pcdr5cuiw32.exe [2008-09-10 16:43] . 2013-04-21 c:\windows\Tasks\User_Feed_Synchronization-{31772478-CA3B-4282-A88C-AB588D195568}.job - c:\windows\system32\msfeedssync.exe [2013-04-21 23:25] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 1281512] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-11-03 182808] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-03-21 472992] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-16 82464] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-16 15853088] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.yahoo.com/?fr=fp-yie9 mStart Page = hxxp://www.google.com mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=84&bd=Pavilion&pf=cndt mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local TCP: DhcpNameServer = 216.51.173.2 216.51.173.1 TCP: Interfaces\{67899D8C-147F-49E2-ABE5-D064EEC25557}: NameServer = 216.51.173.2,216.51.173.1 DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run-Easy Dock - (no file) Wow6432Node-HKLM-Run-hpqSRMon - (no file) SafeBoot-PskSvcRetail AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-sp41119 - c:\hp\Softpaq\sp41119\sp41119.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions] @Denied: (2) (LocalSystem) "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"=hex:51,66,7a,6c,4c,1d,38,12,5c,be,8a, eb,c9,8f,bc,54,f6,39,43,d0,22,43,0b,9c "{8DCB7100-DF86-4384-8842-8FA844297B3F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,72,d8, 89,b4,91,ea,06,f7,54,cc,e8,41,77,3f,2b "{95B7759C-8C7F-4BF1-B163-73684A933233}"=hex:51,66,7a,6c,4c,1d,38,12,f2,76,a4, 91,4d,c2,9f,0e,ce,75,30,28,4f,cd,76,27 "{C98D5B61-B0EA-4D48-9839-1079D352D880}"=hex:51,66,7a,6c,4c,1d,38,12,0f,58,9e, cd,d8,fe,26,08,e7,2f,53,39,d6,0c,9c,94 "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b, 27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b "{02478D38-C3F9-4EFB-9B51-7695ECA05670}"=hex:51,66,7a,6c,4c,1d,38,12,56,8e,54, 06,cb,8d,95,0b,e4,47,35,d5,e9,fe,12,64 "{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54, 07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75 "{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc, 1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7 "{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}"=hex:51,66,7a,6c,4c,1d,38,12,7c,f0,b1, 38,5c,21,3d,0e,d9,78,0d,25,e1,c9,8c,d4 "{597A9974-8CB0-4F41-B61F-ED065738A397}"=hex:51,66,7a,6c,4c,1d,38,12,1a,9a,69, 5d,82,c2,2f,0a,c9,09,ae,46,52,66,e7,83 "{5D79F641-C168-40DF-A32F-BACEA7509E75}"=hex:51,66,7a,6c,4c,1d,38,12,2f,f5,6a, 59,5a,8f,b1,05,dc,39,f9,8e,a2,0e,da,61 "{6D53EC84-6AAE-4787-AEEE-F4628F01010C}"=hex:51,66,7a,6c,4c,1d,38,12,ea,ef,40, 69,9c,24,e9,02,d1,f8,b7,22,8a,5f,45,18 "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}"=hex:51,66,7a,6c,4c,1d,38,12,0f,32,96, 76,f7,7e,4c,08,c8,ef,48,fc,18,66,e7,6a "{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07, 72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57 "{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b, ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3 "{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0, b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb "{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}"=hex:51,66,7a,6c,4c,1d,38,12,fb,ff,52, cf,81,bf,f9,02,f4,a0,53,52,fa,3c,ef,ae "{D2CE3E00-F94A-4740-988E-03DC2F38C34F}"=hex:51,66,7a,6c,4c,1d,38,12,6e,3d,dd, d6,78,b7,2e,02,e7,98,40,9c,2a,66,87,5b "{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db, df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd "{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec, fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42 "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}"=hex:51,66,7a,6c,4c,1d,38,12,8f,19,47, 2e,c4,15,0b,03,d7,b5,8c,e9,62,70,06,85 "{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e, 51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11 . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration] @Denied: (2) (LocalSystem) "Timestamp"=hex:a0,85,49,90,24,26,cd,01 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2013-05-01 15:53:25 ComboFix-quarantined-files.txt 2013-05-01 20:53 . Pre-Run: 235,841,691,648 bytes free Post-Run: 239,233,859,584 bytes free . - - End Of File - - 532EB2DC43F005F28122509A692D9F5C
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.