Jump to content

joeyangel

Honorary Members
  • Posts

    57
  • Joined

  • Last visited

Everything posted by joeyangel

  1. Hello, I recently had a lengthy encounter with the Trojan.BHO which continually reinfected my registry; the original thread detailing this may be found here. After a great amount of involved assistance from forum guru LDTate, the TrojanBHO stopped recurring. There were some issues left over (from the Trojan or the remedies, I'm not sure which); these are described here. Everything was relatively back to normal until last night, when the TrojanBHO reappeared. I've upped all of my security precautions, I regularly update MBAM and my AV and run scans on at least a daily basis (often several times). Still, the TrojanBHO has reappeared. I suppose that what I'm wondering, along with how to proceed with getting rid of this iteration, is what else I could be doing proactively to stop this from becoming a regular part of my online experience. Also, I've noticed that a hidden TMP file (frqksodobw) always appears on my desktop in conjunction with this Trojan. As well, the Trojan only seems to appear when IE is started (this happened previously with Firefox, as well, but I haven't tested to see if that is the case this time). Is there a security issue I might not be addressing? Thanks in advance for any assistance which may be offered. In the meantime, I am following the steps outlined in the I'm infected - What do I do now? thread (yet again). As well, here are the results of my latest MBAM quick scan; every time I run this - even at intervals of two or three minutes - the results always show a reappearance of the TrojanBHO: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7941 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 10/13/2011 8:27:11 PM mbam-log-2011-10-13 (20-27-11).txt Scan type: Quick scan Objects scanned: 202955 Time elapsed: 3 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Here are the required logs from the I'm infected - What do I do now? thread: . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_18 Run by caparo at 1:21:12 on 2011-10-14 Microsoft Windows 7 Enterprise 6.1.7601.1.1252.1.1033.18.3054.1364 [GMT -4:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\ibmpmsvc.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\WUDFHost.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe C:\Program Files (x86)\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe C:\Program Files\Microsoft LifeCam\MSCamS64.exe C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe C:\Windows\system32\DRIVERS\xaudio64.exe C:\Windows\System32\alg.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Windows\system32\nvvsvc.exe C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Lenovo\System Update\SUService.exe C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k WbioSvcGroup C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\TpShocks.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe C:\Program Files\Lenovo\Client Security Solution\cssauth.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Windows\SysWOW64\rundll32.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\SearchProtocolHost.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://webmail.earthlink.net/wam/index.jsp?folder=INBOX&x=-33585947 uInternet Settings,ProxyServer = http=127.0.0.1:60646 uInternet Settings,ProxyOverride = <local> BHO: {0000d912-155c-404d-8d31-51fb95acd01a} - C:\Users\caparo\AppData\Local\NetworkCodec.dll BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: IePasswordManagerHelper Class: {bf468356-bb7e-42d7-9f15-4f3b9bcfced2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [soundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe uPolicies-explorer: RestrictWelcomeCenter = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll Trusted Zone: earthlink.net\webmail Trusted Zone: yougov.com\today DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 207.69.188.186 207.69.188.187 TCP: Interfaces\{10B9EAE8-0DE3-4F90-BCAC-74150DE80037} : DhcpNameServer = 207.69.188.186 207.69.188.187 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF} : DhcpNameServer = 207.69.188.186 207.69.188.187 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\2656374702775637475627E6 : DhcpNameServer = 207.69.188.186 207.69.188.187 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\4455B454 : DhcpNameServer = 152.3.250.12 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\55E434D213 : DhcpNameServer = 152.19.240.8 152.2.253.100 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\55E434D2355636572756 : DhcpNameServer = 152.19.240.8 152.2.253.100 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\D41484D41484 : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{10D4270F-F0E7-4997-90C0-A0ACD10F54AF}\E454353456E647 : DhcpNameServer = 10.0.5.1 TCP: Interfaces\{47783392-D2A8-4F1F-9829-99DA95EF0220} : DhcpNameServer = 207.69.188.186 207.69.188.187 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL LSA: Notification Packages = scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache C:\Users\caparo\AppData\Local\NetworkCodec.dll BHO-X64: Octh Class: {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll BHO-X64: btorbit.com - No File BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO-X64: URLRedirectionBHO - No File BHO-X64: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll BHO-X64: Password Manager Browser Helper Object - No File BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll TB-X64: Grab Pro: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll TB-X64: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun-x64: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [soundMAXPnP] C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8 FF - prefs.js: network.proxy.gopher - 127.0.0.1 FF - prefs.js: network.proxy.gopher_port - 60646 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 60646 FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll . ============= SERVICES / DRIVERS =============== . R0 DzHDD64;DzHDD64;C:\Windows\system32\DRIVERS\DzHDD64.sys --> C:\Windows\system32\DRIVERS\DzHDD64.sys [?] R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?] R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?] R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952] R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2010-10-29 93032] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-9-15 366152] R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2009-3-13 13840] R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?] R3 LenovoRd;LenovoRd;C:\Windows\system32\Drivers\LenovoRd.sys --> C:\Windows\system32\Drivers\LenovoRd.sys [?] R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?] R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?] R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272] R3 PCDSRVC{127174DC-C366ED8B-06020101}_0;PCDSRVC{127174DC-C366ED8B-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor\pcdsrvc_x64.pkms [2010-12-13 25072] R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys --> C:\Windows\system32\DRIVERS\Tvti2c.sys [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2010-10-29 45496] S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2010-7-27 164200] S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880] S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys --> C:\Windows\system32\Drivers\nx6000.sys [?] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?] S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?] S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S4 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-29 136176] S4 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-29 136176] . =============== Created Last 30 ================ . 2011-10-14 00:13:05 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-10-13 23:14:48 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E54D3B3-2E12-46C6-A7DA-1AAFAA41295F}\offreg.dll 2011-10-13 23:14:42 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E54D3B3-2E12-46C6-A7DA-1AAFAA41295F}\mpengine.dll 2011-10-13 14:39:32 3138048 ----a-w- C:\Windows\System32\win32k.sys 2011-10-13 14:39:31 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax 2011-10-13 14:39:31 613888 ----a-w- C:\Windows\System32\psisdecd.dll 2011-10-13 14:39:31 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll 2011-10-13 14:39:29 108032 ----a-w- C:\Windows\System32\psisrndr.ax 2011-10-13 14:38:56 331776 ----a-w- C:\Windows\System32\oleacc.dll 2011-10-13 14:38:56 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll 2011-10-13 14:38:55 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll 2011-10-13 14:38:54 861696 ----a-w- C:\Windows\System32\oleaut32.dll 2011-10-13 01:41:50 267776 ----a-w- C:\Users\caparo\AppData\Local\NetworkCodec.dll 2011-10-11 02:38:04 601424 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2011-10-11 02:37:42 917840 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{FF5DF996-93C5-4B7C-8773-66044981FD9C}\gapaengine.dll 2011-09-28 15:21:24 -------- d-----w- C:\Users\caparo\Local Setings 2011-09-27 01:50:31 -------- d-sh--w- C:\$RECYCLE.BIN 2011-09-24 23:26:47 9049936 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-09-24 20:14:05 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client 2011-09-24 20:13:59 -------- d-----w- C:\Program Files\Microsoft Security Client 2011-09-23 03:58:48 -------- d-----w- C:\Users\caparo\AppData\Local\{9ED73A25-1FAB-4BC6-8074-3E0BDFBC5AA2} 2011-09-23 03:57:10 -------- d-----w- C:\Users\caparo\AppData\Local\{D220C7D3-B43E-4768-8C80-D13FC7609B1D} 2011-09-23 01:09:58 -------- d-----w- C:\Users\caparo\AppData\Local\{EC1D16C9-C912-49FA-BBE7-D556DB9414A7} 2011-09-21 21:56:26 -------- d-----w- C:\Users\caparo\AppData\Local\{2273A7D6-2434-4A66-978F-59F1417BD59C} 2011-09-21 21:56:17 -------- d-----w- C:\Users\caparo\AppData\Local\{36AADB23-5572-4559-A7C6-8C98F0B2B385} 2011-09-21 21:54:42 -------- d-----w- C:\Users\caparo\AppData\Local\{45617192-FD46-4DE6-82B8-E77E637C1742} 2011-09-21 21:40:56 -------- d-----w- C:\Users\caparo\AppData\Local\{FC817D71-286D-40D1-9CF6-508371D2E1B8} 2011-09-20 18:20:02 6231376 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2011-09-20 18:19:57 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6813238C-071B-4706-A014-49A9DAEDC4B6}\mpengine.dll 2011-09-20 17:20:58 -------- d-----w- C:\Windows\desktop . ==================== Find3M ==================== . 2011-10-11 22:53:47 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2011-09-01 05:24:07 2309120 ----a-w- C:\Windows\System32\jscript9.dll 2011-09-01 05:17:57 1389056 ----a-w- C:\Windows\System32\wininet.dll 2011-09-01 05:12:04 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2011-09-01 02:35:59 1798144 ----a-w- C:\Windows\SysWow64\jscript9.dll 2011-09-01 02:28:15 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll 2011-09-01 02:22:54 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2011-08-31 21:00:50 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys 2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll 2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll 2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll 2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll 2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll . ============= FINISH: 1:23:39.62 =============== attach.zip
  2. Thank you, AdvancedSetup, I will happily follow your recommendations - again, many thanks.
  3. Thanks, Firefox, that makes sense; I appreciate your input. Last time around, the Trojan seemed to be associated with both IE and Firefox. When I first became aware of the TrojanBHO, several online references associated it with the Google toolbar; this was due in part to the redirect some users (myself included) experienced during Google searches which was associated with TrojanBHO. I uninstalled Google toolbar during the last infestation and have not reinstalled it (although I was considering it). I did have an instance of Bing taking over as my default search provider in Firefox several months ago, but that was resolved (as far as I can tell). Do you have any suggestions as to how I might proceed regarding the presence of a rootkit that might be the source of this?
  4. Hello, I recently had a lengthy encounter with the Trojan.BHO which continually reinfected my registry; the original thread detailing this may be found here. After a great amount of involved assistance from forum guru LDTate, the TrojanBHO stopped recurring. There were some issues left over (from the Trojan or the remedies, I'm not sure which); these are described here. Everything was relatively back to normal until last night, when the TrojanBHO reappeared. I've upped all of my security precautions, I regularly update MBAM and my AV and run scans on at least a daily basis (often several times). Still, the TrojanBHO has reappeared. I suppose that what I'm wondering, along with how to proceed with getting rid of this iteration, is what else I could be doing proactively to stop this from becoming a regular part of my online experience. Also, I've noticed that a hidden TMP file (frqksodobw) always appears on my desktop in conjunction with this Trojan. As well, the Trojan only seems to appear when IE is started (this happened previously with Firefox, as well, but I haven't tested to see if that is the case this time). Is there a security issue I might not be addressing? I'm sure there are other elements I'm forgetting and/or questions I should be asking, but I'll hold off for now. Thanks in advance for any assistance which may be offered.
  5. Hello, after recently contracting a virus (TrojanBHO, detailed here), several minor issues appeared following resolution. First, folders will not reset to default status; they continue to open in separate windows, resizing to restore-down. Also, default save locations are not adhered to. For example, image files will save to My Pictures until saved to another folder, at which point some files will save to the new location while others will save to the default, with no apparent pattern. Following the advice of a forum moderator, I have reverted to IE8 from IE9; this did not affect the issue, and I would be open to any insights regarding additional measures. Thanks in advance for your assistance.
  6. Thanks, that sounds like a good idea; I appreciate all of your help and remarkable patience in dealing with this. By the way, should I reference this thread and note the original issue, or should the topics remain separate? Thanks once again.
  7. Thanks, IE9 has been uninstalled and reverted to IE8.0.7601.17514. I tested a folder and reset to default, but the previous behavior (folders opening in separate windows) has not stopped. How do you recommend I proceed?
  8. Great - thanks; should I simply uninstall IE9 (which by default then reverts to IE8, I believe) or completely unintsall?
  9. Thanks; I've run Windows Update (all important updates have been installed; no relevant optional updates noted). I haven't tried reinstalling IE yet; is there an advisable procedure for this? As well, what is the best way to retain persinalized IE elements?
  10. Thannks; I ran the first command as you wrote it but came up with the following error warning: "The module "shdocvw.dll" was loaded but the entry-point DllRegisterServer was not found. Make sure that the "shdocvw.dll" is a valid DLL or OCX file and then try again."
  11. Yes, thanks; it appears in the C:\Windows\System32 file.
  12. Sorry, thanks, I think I see what I did wrong; my original formatting of the command was incorrect. Here are the results of the new log; by the way, I'll be "on the road" for the next few days and may not be back online again until the beginning of next week. Thanks as always for all your help. SystemLook 30.07.11 by jpshortstuff Log created at 07:17 on 29/09/2011 by caparo Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== filefind ========== Searching for "shdocvw.dll" C:\Windows\System32\shdocvw.dll --a---- 179712 bytes [14:09 01/04/2011] [12:21 20/11/2010] BE247AE996A9FDE007A27B51413A6C79 C:\Windows\SysWOW64\shdocvw.dll --a---- 179712 bytes [14:09 01/04/2011] [12:21 20/11/2010] BE247AE996A9FDE007A27B51413A6C79 C:\Windows\winsxs\amd64_microsoft-windows-shdocvw_31bf3856ad364e35_6.1.7600.16385_none_4369df2c25973477\shdocvw.dll --a---- 196096 bytes [23:55 13/07/2009] [01:41 14/07/2009] FBE8EBF528DC49B3DEB186CA9545D97E C:\Windows\winsxs\amd64_microsoft-windows-shdocvw_31bf3856ad364e35_6.1.7601.17514_none_459af2f42285b811\shdocvw.dll --a---- 196608 bytes [14:09 01/04/2011] [13:27 20/11/2010] C4F40F6CACD796A8E16671D0E9A2F319 C:\Windows\winsxs\x86_microsoft-windows-shdocvw_31bf3856ad364e35_6.1.7600.16385_none_e74b43a86d39c341\shdocvw.dll --a---- 179712 bytes [23:39 13/07/2009] [01:16 14/07/2009] E07B77C3BDC82A024E294FB67ABFEDA0 C:\Windows\winsxs\x86_microsoft-windows-shdocvw_31bf3856ad364e35_6.1.7601.17514_none_e97c57706a2846db\shdocvw.dll --a---- 179712 bytes [14:09 01/04/2011] [12:21 20/11/2010] BE247AE996A9FDE007A27B51413A6C79 -= EOF =-
  13. Thanks; I followed the instructions but this is all the log file contained. Please let me know if I may have done something in error - thanks again: SystemLook 30.07.11 by jpshortstuff Log created at 01:29 on 29/09/2011 by caparo Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. Invalid Context: filefindshdocvw.dll -= EOF =-
  14. Thanks, I merged the new with the current; that went off without a hitch. I restarted and opened a folder, then an internal folder; the internal folder came up in a new window. I went to control panel and reset all folder options to default; I opened a foolder again, with the same result. In case it was the single Shdocvw.dll, I opened a command prompt and ran as admin; I ran regsvr32 urlmon.dll, then regsvr32 Shdocvw.dll. Doing this, I received the following error message: The module "shdocvw.dll" failed to load. Make sure the binary is stored at the specific path or debug it to check for problems with the binary or dependent .DLL files. The specified module could not be found. I'm not sure what to do to change this; based on this latest function, does anything come to mind?
  15. Thanks, I'll definitely give this a try. What is the safest way to merge keyfiles?
  16. Thanks, that worked perfectly; the Office apps work as they were intended to again. I tried to solve the folder issue using one of the solutions I found previously: JavaScript Error: No Such Interface Supported Solved I had already successfully re-registered the actxprxy.dll, but when I have tried to re-register shdocvw.dll I receive the following error message: The module "shdocvw.dll" was loaded but the entry-point DllRegisterServer was not found. Make sure that the "shdocvw.dll" is a valid DLL or OCX file and then try again. Does any of this present an indication for an alternative solution?
  17. Thanks; no, as far as I can tell, the main issue seems to be the folders; the reset to default configuration doesn't work. The folders cannot be set to open in a single window - rather, they continue to open in separate windows, and seem to default to 'small' restore-down size. The only other issues I've come across involve MS Word and MS Outlook. Each app generates an error messages when started (e.g., "Outlook could not create work file. Check the temp environment variable"). Also, the "Email picture/Attach files" feature for online images that are right-clicked on seems to have changes configuration, if that makes sense. Does any of this seem related to the main virus issue(s), or are these perhaps separate matters?
  18. Yes, thanks, those are the controls I've be re-setting after each function in the hope that things might finally go back to normal - to no avail, I'm afriad. Is this a result of the virus or of one of the fixes we've tried?
  19. Great - thanks. Everything seems to be running normally, with the same exception of no overall folder control. Is there anything I can/should do next?
  20. Great, thanks - I'll reboot now. By the way, I have CCleaner; if you're familiar with that app, is there a setting I should run it on to ensure these files are being deleted, or am I safe already? Thanks again.
  21. Great - thanks; the scan just finished. I looked for the log file at C:\Program Files\EsetOnlineScanner\log.txt but couldn't find any location corresponding with that address. Upon completion, ESET gave the option of saving the List of Found Threats into a .txt file, which I'm including below. I was also give the following options: Manage Quarantine - only a 'restore' button appears after clicking the button for this option Uninstall Application on close - which I'm assuming I should do Delete quarantined files - which I'm also assuming I should do If there is another location I should check for the ESET log file, please let me know and I'll try to track it down - thanks again. C:\Documents and Settings\caparo\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\VirtualStore\Windows\Temporary Internet Files\Content.IE5\4G9I2S42\index4[1].htm HTML/Iframe.B.Gen virus deleted - quarantined C:\Documents and Settings\caparo\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\VirtualStore\Windows\Temporary Internet Files\Content.IE5\4G9I2S42\nadine-velazquez-photo-pic[1].htm HTML/Iframe.B.Gen virus deleted - quarantined C:\Documents and Settings\caparo\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\VirtualStore\Windows\Temporary Internet Files\Content.IE5\AQEK3ASL\amusingporno_blogspot_com[1].htm HTML/ScrInject.B.Gen virus deleted - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{18488b6f-3656-4ab0-baf8-fba73a5f7ed0}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{1a2980c0-8e8e-4dd3-95a0-91861e40747d}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{1b5c0e8e-c985-422f-971c-305fef2857b6}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{307da760-6bd4-4125-940f-eaf48c4dddce}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{3b481eab-1c9e-43b2-8550-f9bf628420b2}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{3d0148b0-716e-4e3f-af1b-0025af541691}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{49028c28-0462-4e7d-baa9-a99cb4892d8c}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{4ebf8d57-8473-4dc8-b77f-5b635bdb627e}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{55fccf83-97b0-421b-b266-318974889706}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{56d17287-bba6-405f-846c-33f0b1966a88}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{59907455-2d53-40a3-9d99-6464974f3654}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{62a52ff3-809b-4832-9dcc-244da7d6ac98}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{681a20b1-d761-4da4-9c6d-5498f81ef170}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{73128ca1-0368-4234-b6df-07140bbd18b2}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{732ae6c1-5e8d-4e4f-9b84-e2d208bfffde}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{89d63171-c288-4972-bc9a-c11f4771315b}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{8a5116e3-4f6b-4e05-a6ce-ea8d30ea6f42}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{a2f8c7be-7e5b-49a2-892d-49d2308b0976}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{ad704934-96ae-41ff-8530-85e6b823af31}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{adb5e36a-5ad3-454f-9ce4-3c11e13e8437}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{afe4d205-6897-4c47-9568-cf9fdf8ecff5}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{b9808ab5-0a3b-4a31-818b-72257ec3db43}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{bac6b8ab-3c12-4da5-8079-82c317d8e376}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{c184ea0c-e220-499e-b505-15cb862e2e02}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{c252ce39-cfcf-41b9-8213-e5c3b9555947}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{c391f316-8172-46fa-86c2-cb36cf8e76c0}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{c42bb762-39ef-4835-b40a-cdb7c102c712}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{c4a200eb-f2c6-4c18-b492-38afe461199e}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{cd783ab5-c5dd-40c6-8f16-0bde3c54e144}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{d28fff09-0f5c-4f3d-8ced-b621a711091c}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{d703bd62-285d-4d67-b2c0-330d5637c180}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{d79edafa-cd65-4c1c-934d-c1c246de17f4}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{ddb8b1d3-f289-41ad-9a01-906437b879fb}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{e293dc6b-42d7-4ed4-ae70-91026bcd7b8e}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{e2bbf93b-1d3c-4c83-8a05-11a907f3e090}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{e445a00b-8634-4d31-9e80-9e225138e7a7}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{ec907e04-d437-48e8-bf87-31f1edd1c95a}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Documents and Settings\caparo\Documents\Computer\GooredFix\GooredFix Backups\C\Users\caparo\Application Data\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{fa985a32-50ed-435b-a21a-df638679905f}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{06bf41c0-3c0f-4297-a96a-0471eb5d8113}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{08f23603-a37f-447e-84b3-2d7d204e756d}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{29f3b68f-aeb5-4135-b690-e7a9e3177608}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{86d361b5-a777-4ee1-81ed-b9fac8ccc0f5}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{8f923f1d-6d3f-4976-bd29-97d6750188d4}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{8fa96ac7-381c-4a96-bd73-b331e202c529}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{b19f0419-952f-40b8-b176-a58028edf6de}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{d716d8b8-cab7-4b12-8dd6-53d13dc5f781}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined C:\Qoobox\Quarantine\C\Users\caparo\AppData\Roaming\Mozilla\Firefox\Profiles\dwv589ee.default\extensions\{e8214435-ea31-4f77-9482-e92505efd925}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan cleaned by deleting - quarantined
  22. Thanks; what came up for the log (which appears to contain redundancies because I clicked the appropriate icon more than once before I noticed the 'log' file on the desktop). If I should delete these files and start again, just let me know - thanks. Junction v1.06 - Windows junction creator and reparse point viewer Copyright © 2000-2010 Mark Russinovich Sysinternals - www.sysinternals.com \\?\c:\\Documents and Settings: JUNCTION Print Name : C:\Users Substitute Name: C:\Users Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\MSOCache: Access is denied. Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\PerfLogs: Access is denied. Failed to open \\?\c:\\Recovery: Access is denied. Failed to open \\?\c:\\RRbackups: Access is denied. Failed to open \\?\c:\\System Volume Information: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... Failed to open \\?\c:\\Program Files (x86)\Google\CrashReports: Access is denied. Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.ilg: Access is denied. ... . Junction v1.06 - Windows junction creator and reparse point viewer Copyright © 2000-2010 Mark Russinovich Sysinternals - www.sysinternals.com \\?\c:\\Documents and Settings: JUNCTION Print Name : C:\Users Substitute Name: C:\Users Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\MSOCache: Access is denied. Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\PerfLogs: Access is denied. Failed to open \\?\c:\\Recovery: Access is denied. Failed to open \\?\c:\\RRbackups: Access is denied. Failed to open \\?\c:\\System Volume Information: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... Failed to open \\?\c:\\Program Files (x86)\Google\CrashReports: Access is denied. Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.ilg: Access is denied. ... ... ... ... ... ... ... ... ... .\\?\c:\\ProgramData\Application Data: JUNCTION Print Name : C:\ProgramData Substitute Name: C:\ProgramData \\?\c:\\ProgramData\Desktop: JUNCTION Print Name : C:\Users\Public\Desktop Substitute Name: C:\Users\Public\Desktop \\?\c:\\ProgramData\Documents: JUNCTION Print Name : C:\Users\Public\Documents Substitute Name: C:\Users\Public\Documents \\?\c:\\ProgramData\Favorites: JUNCTION Print Name : C:\Users\Public\Favorites Substitute Name: C:\Users\Public\Favorites \\?\c:\\ProgramData\Start Menu: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Start Menu Substitute Name: C:\ProgramData\Microsoft\Windows\Start Menu \\?\c:\\ProgramData\Templates: JUNCTION Print Name : C:\ProgramData\Microsoft\Windows\Templates Substitute Name: C:\ProgramData\Microsoft\Windows\Templates Failed to open \\?\c:\\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}: Access is denied. .. ... ... . Failed to open \\?\c:\\ProgramData\Microsoft\Microsoft Antimalware: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows Defender: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\S-1-5-18: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\00e6238f3be4f1723b08072f97ef633d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\01945b158787eb15eb1e469d2be90e3a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\01ae3c7e10f829340a085425c3a05279_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0320b04a2399ebdce2a08a7698d1550e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\03c1b0bc6491eb654d992ee085c16e80_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\04bccda0f71eb516a148fb6160ab0698_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\069034fecd792057058415c474a0043b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\07c4939bec14029b2d63b4995ba454f0_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\087ff7c4240a5a8bf4c6621ec9a4293f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\08a5b97518fccb7c259d38b5250b8ca4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\08cf84642df2c252c45a967cad1c034e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0a16107dcc3a2dd9f4c43e5c73feb1c7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0a41886896a7de0e3a962ba2e59770cd_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0a7df1aa0ae81cea95fd34f8574c20c7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0b057f1680aa81d4b090fdce0604f533_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0b24cdc48f0f45951662c5673520419b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0ccc79a5a95f5623462a38ab81c16560_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0ccf1651edda6c2dc7d17468b0116625_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0e6a44519f5da41571cb0c7e13a0effe_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f04ed2a22a8532cebe859e446642d6c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f75cf532d88c507fb8b216c8a18f732_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1196c3c94bb70c7e9cbb5e5c2554dd6f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13adca6116b9d40decb361f5755e22b9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\13e2e290756eb7c169634868bbfaa2f4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1570b59c705d5f2420b865c1c4374b99_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\179fbe725a6d9504ea873badb04a50f6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\19100b9fd43d121cdf1a298db620ed78_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bc9faddf8c9ed2e3b51bee3eb17ab8a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1beef8e236a7f7d5f71ccf1f344b511b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1c9a12a1fb76793fe1abd81cc0e53326_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1cfee0313e5c677318048c6e94c87d7d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1d356ebda58e075c5116d015bb897afe_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1d399e078f3a6aa0dcbdef9d03327d39_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\20ad89be34ec0678bfb15fa7cdc6d49e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\20b58e85828c73b7282679533896c066_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\213dc4f57c028f50094c7b8d6393c95c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22ef6dff631d39cdbde2e2d1926b4d34_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\261bf2f18f04773960525b9f3ca764bf_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\26a36eda4753a03f0ddefc432214cce8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2829f7a36b4e42f3837d4d43466a15f0_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28820405ee81655f35dfb784250be033_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28d162347aa59e749598c2ac5a11872e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29baeefa20e962e2c72e366de0c5dc0d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2aa025ce86bfdc1cb86d3c0bf9cf2b4d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ace82235369738abbd0f9f52f4d7f19_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2afa9be47d1c23e13d9d43144603bb8a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2dc861ede9dc1a67356b36fa23d86038_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2dcb58c72fe97c14d20e78eb72d24274_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f5547dc285729cf543ed87d73bf3fc2_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30a8f2f70a54a8af87a8a4019e18772c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3185e61d1add90cbae41c989abe4b2f1_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\350c23fb5562fe79aff8e29e3a07a88d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\351c4e21e4488d7e2d8f0712bd722ade_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\36f2638988f6b38a09cd7ce59a086730_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\37a25d8e083f9c49e9fb4d5ceb12b05b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\399300ba420ba0b9b432ec7e31742df3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3b1ce8d2f3f4006a9a524fcac0861088_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3d0deb0359d1274bae2cf0e732d6ee0f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3d4eeac61c2ba20d321708fef38bdc2a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3fa1801a8c6af2d9d873aa2072789164_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\407fb386986366f6c4f31808191c4a09_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46500de930e1e0d1e3f5db2e63d6b3f6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4741615ccd8a7a69ccbacb40cfa2fb28_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\47cfe6a8b3f916d9fe6a307bf6550fe2_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\49582293a50b07053ff3be16717494e5_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a922945eecfef981bbc56892ff2d9a9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4cfdbe4cf1eba7f50af0df573350ddc8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4d29c9c59577aa384a9122053871689c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5096bb67ca3befc95b7def316693cf94_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\50b121fe5691ba079ce133a199093b4c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5603598edebd459087242c07a0bddb7e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\57c7b117564ead3dfa3313131abc5e8d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\57d47323ac53ef18433ae9a52010b2de_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\58bc73e42f3a088f3fc703fe8dcd99c0_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\622cee07f413282a773244562d0fb8ad_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\625a674614f19b6be8df24ec29eb251c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\632c0f30e290846163dd061132b7208f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\656608b58ad125761d036b4715fefaaa_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\66d27c9491f0050ffa6a37a566dca384_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\676e750195081d26ef99380704483cf9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\678dd0053337804c67cd335b5a587f74_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6a5bfa3c1806b026d94cabcafd6c0b71_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6d9a70b74d3466f34394b4f56ceb9fd1_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6de4cbfbf790d79683c741a9451b5099_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6ed107dd59309b66e846e0722be56fd3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6efeb58e757bc0f1011070158031dcc4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\70a6a2a73dbd7937158c20f281bb1dc3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\71b962302f80673b01763f28f69ef343_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\737d4603c8d8f7ad40ef17a2e41e2b46_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\745f78d8d337a1c8a32351f0912b4500_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7580f9e95b48cbd6bace7dc29ca10724_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\75a2d3eb76ebbb40b1e5837bf7939284_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\778ab0015280fa0da12659f388d84f0b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78400b3bffdbb76e82fe68f9834d863a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\79ded13d36b7b2d9852394115e4b7e8b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a9e543470b8912178928d8dab000a93_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b0b95e9417812d12c64d63f8b49add7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7be5650bf44adb664c79e490299d463d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80ab0f3b75e680da4436f03f6d5deeb8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\81efd56b234079a3571efa88a6042bcb_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\83220b5b5ba42e8c319c87727aeaf22b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\84654386073019ff579d5d524c941f8d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\84972cf93d9bd478828ef0777ae15459_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\852b8ed45bf15f2f6c41f3fad03b2561_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\85b651836058888684dbfdfd965a43b9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\861b2016be07e0f43af6823e0636e8c7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\89132b7d5353203c04beeaaf320f14ca_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\898cd2e42db8ba30f1186317901b0387_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a9ec80dc16f503def8ff3abc2ebd09f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8ddb369d33746318dc4498a08776018c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8e3bc83e5bd6d1ff576d2fe18acf64c8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8fcde665fe75176d32d877647a49c64d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9168f0a4f8741332649374f7ac8e8cbe_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\94038c79d1393eeb49739c24fdf8f045_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9597aadedb6778f0ff7f2248f0e06402_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\99c1ba26997e115e34c2048e00504daa_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9bc87a64126c95fd8a97a1454320ca8b_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9d1a92cdc0324b0429d20c1a04949638_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9da076c887e2607da085d337adb89e55_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a12f5cf3b47e1ce6c36bb8ff1ee6c52f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a2dbf0dc632ed0f84a645219387f5ce3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a58880ca203bb98baf6c9ed8eeb104e0_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a5f011839834f3ca6530a6d0cc850b61_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a86dd880b2d2b21bbed8e5bf9ef9939f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a88382188e7decc9a99a8eaefccb614a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa67845e87143acb8a3a4d3938e9f16d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aab149d2a4c52b52076dbe573dab4abc_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aad78f65fe02e1d361ce656e36e65ff6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab534f16b4a97d71de40201c48bb330f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ade098070f12b69da818752ef8f5a596_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae59270a3db34c56d35aa0cb872e7a22_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b2667d082a21f70d51b28350d853ff7d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b35323723035938137061074ac8006a7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b46ffe5b9f8d30683e873087200b4e03_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b58b6acc3ec21af11a4b7dd958438aa2_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5dbfcc4b7aac59e7cd5d3928498473a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b6ca96cb3c6bc9c75cebf3d44aa544d4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b8708273423cc211dc6e47197170d938_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b8c8b056405fb4dedb848bbbdb3449f4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b982e07fd08c7ecd56816e2e82d3e944_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb1c81d0086364e12a0f38d2cec8a341_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb9bb2ea83fa4f01cc810fc7ba4e93be_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bbd90d894ec8599675ebbed88fcc6ac3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bbfff3f0647f83f62911345c62ffc3df_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c0286f1cdf9a771e997c735b6c32878c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c1e7b2b51ab91380d56da058a075481d_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c615de463c4f7da5523f8dc1e5ded1c2_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c6ab25de19ee5e0495d3b70264670007_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c6e95a491f9703cf175f2485fa88e10f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c9bf370e548bad95e59f8ffa30607117_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cc55a968b8e65fbd155133a323bd39b6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cf5e8dd62107614399b9572496bb072c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d1667a512872e43d3d7da0bee76d8f98_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d2302723eab581f7c4724e04e66b40fe_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d25f5be3a64cf8bb85aae66f6065f6ae_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d2944426f3d68694fb8fd368836aabbd_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d3441b581f3dfdaae6d6d3901d46fefe_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d56091ab6f238584714ae0e8d4aef680_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d605bf247463372e59f50bbd10827aa1_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d84a148e1dc8273cb936abf93b2bb84a_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\db7b0683fbb604f00b827c8eb4f43584_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dc983fe76262861fd92eebe8d391e732_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\deff25e02e3555e6e0d43369bf2c768e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dfbdf1e8bc98e5e5ef233a492fa12c4f_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e0e5329381674e279cbf24491d7db4ab_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e139d040f63cf803c5b4312d80d3c8fb_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e17cb6c55035961870d3b66e335a8a41_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e4a9d43e36bd89a78b8fdae0c7708f89_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e702e38af9531b9f833fe6496483f6e3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8c65fdac4ebfe454555ced3e356bae7_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8eea43ab93b1a9d962a9c8518a08766_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e933cad22e480963f00e26038f91b254_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e984fa6c4ead252b820efe67959a2878_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ebbfa33c562449b0fc1c8c2225f64d32_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec1dee82f479655332622b1fdd9c50d8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec45ed09b208b54c19d94d900ccace97_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ec63de080b767b8a54772dbfcde15663_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f108ed972707df146e376244ee40c0c6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1e83825d0623f768341a81811ffe0eb_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2fc652508a321f63a8a2dce55fdc952_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f7075e8da9baaa4e385a6149c269e1d9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f867c3a2fee677d54a7ecff49d0527a6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\faa7f7a862e3511750799515672c338e_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc384c7af609affb7f6f79400cf87da6_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc81fb4ff260e95b95ee3600333a12e8_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fcc273ea160148dd7d6053b63e1e73d3_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fdd858839885d3bc5e9377fa2d710163_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff5828fb03ea634769e547c9aa517ee4_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff61adf17b656be1e0e20108cbe9a5f9_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff63e995e1792b06ac8f3c17fa5bfd0c_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ffc3e11aaf42f79373a32c069c539ae1_60a24aa7-1866-4821-9952-ccc46e7b5529: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Network\Downloader: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Search\Data: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\User Account Pictures\UNC Support.dat: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics: Access is denied. . Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Smc.exe_7cc5dfb019e4522da4c5165e2ecd6de3ee881fd_cab_025dbb52: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Smc.exe_c961ad705a7ac62cc7e81963b8491442844a1f2_cab_08b13b0d: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01813b89: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_019e3e66: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01cc24cf: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01d31fa0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01d4337e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01d5756d: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01d5c4f3: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01e1d27b: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01f19990: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01f29a99: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_01f559f2: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_025545e5: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_03a8feaa: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_03e53b6a: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__874c9f971255cceaada81bb57fea3f443c55f79_08547a9f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__d33e4c7520a666e376fcd7393619e8765171b16_017f3745: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__d33e4c7520a666e376fcd7393619e8765171b16_019cd355: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__d33e4c7520a666e376fcd7393619e8765171b16_021a71d5: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__d33e4c7520a666e376fcd7393619e8765171b16_02414308: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_tvt_reg_monitor__d33e4c7520a666e376fcd7393619e8765171b16_10a4597f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_mbam.exe_375a273ccf293d26439c1cdf2a42a2e51ee71f3_02555b68: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_02e8142b: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_04de4d06: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_06031baa: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_07e2f22a: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_08f65f00: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_08fa32a3: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0ad2bc1d: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0b069710: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0b0bcdb9: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0b2640a7: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0b8ba331: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0b93b47f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0ba680a3: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0c12a12e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0e5a79e0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0e5b9e12: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0e7a7e72: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0e981708: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0ebb7251: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0ec29fe6: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0f5249cb: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0f8f1563: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0fb43774: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0fce5244: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0fcfa8cc: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0fda7425: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_0fe643e2: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_10b6e040: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\AppHang_MSCamSvc_ed35fe26451c4405a6d26eb3ea827d25dc3a3e_118b8361: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7600.16385_95b89e6f26b3581f6a8e1574ebbe30be4bb3a76_01ecdbdd: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7600.16385_ddea2ab56e762dc5e16dfc6f806e11cdf65feb82_025d1988: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_CanonDrivers.exe_c3aabd44d33ee470a8061296bacd27888ca927f_0291a218: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0199e07f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_01e26670: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_01e285a3: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_02ba111f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_02ba337e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_3072_a895f96b47a1694ff8e8dd7e1be9765c5bd9dfe_cab_010b6bc1: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_314dba050848b59681e9c7fb2de59bda0fea8f0_019ce8a9: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_314dba050848b59681e9c7fb2de59bda0fea8f0_0c4f4bde: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.3.7600.16385_f9fa1110e8b6978960cd571fd21736f2433dc3_1f272579: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_33fee1c16079435e4154e9e210b2642e1e27a34_0f9a19e6: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_b77d607dfdcb9190e1530bdc831f4158315287_0fdfa0e7: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_0506f1af: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_12e0ea57: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_139e1b79: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_13e1a7ea: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_1b89b82f: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_1e1954fc: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_63368637448857989ba1db62696b6689b0714019_219b7b23: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_030a8feb: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_0800ffb5: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_1099e773: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_155d410e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_15baed90: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_1808d6c7: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_1a1b2142: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_1bf73b71: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_1de71ed9: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_30fcb4b0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_316cb4b0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_34acabf0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_3f0a14e3: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_3f405428: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_680d91d1d4b161328a09ece3cdf2080dee85620_3f7c2a90: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_c0aac2bf3e66535480ab129dcfadc08c9f31b33_07e8caeb: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_d91013d1f8a67130ade1a4303788e899ae7b21_089d6cf0: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_d91013d1f8a67130ade1a4303788e899ae7b21_106dc5cd: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_d91013d1f8a67130ade1a4303788e899ae7b21_1668b536: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_d91013d1f8a67130ade1a4303788e899ae7b21_201869d4: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_d91013d1f8a67130ade1a4303788e899ae7b21_27370346: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_2954845664ae3bd3b88d99c4386f1e6644d75c0_cab_04ed7d92: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_431c794d4476261e43681313731ae8f2f046e_04ed8993: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_487e46e256196da9ca1edf788ad4995b70bd238a_002af22e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_487e46e256196da9ca1edf788ad4995b70bd238a_01f561be: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_56ecd3d9e4d408e4a40a619dc1e2577a55f652b_002afd26: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_56ecd3d9e4d408e4a40a619dc1e2577a55f652b_27ab410a: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_63c1bb18dfa147e362c374ac70bf3ba366e0bdd5_04ed967e: Access is denied. Failed to open \\?\c:\\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Microsoft_64b53246976c49c219495bda8134124f0a87395_002b080f: Access is denied. Failed to open \\?\c:\\ProgramData\Mi Junction v1.06 - Windows junction creator and reparse point viewer Copyright © 2000-2010 Mark Russinovich Sysinternals - www.sysinternals.com \\?\c:\\Documents and Settings: JUNCTION Print Name : C:\Users Substitute Name: C:\Users Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\MSOCache: Access is denied. Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process. Failed to open \\?\c:\\PerfLogs: Access is denied. Failed to open \\?\c:\\Recovery: Access is denied. Failed to open \\?\c:\\RRbackups: Access is denied. Failed to open \\?\c:\\System Volume Information: Access is denied. ... ... ... ... ... ... ... ... ... ... ... ... Failed to open \\?\c:\\Program Files (x86)\Google\CrashReports: Access is denied. Failed to open \\?\c:\\Program Files (x86)\InstallShield Installation Information\{DAC01CEE-5BAE-42D5-81FC-B687E84E8405}\setup.ilg: Access is denied. ... .
  23. Will do, thnaks; by the way, before I start this new procedure, is it possible that I clicked on the wrong icon? There are two 'junction' icons, one the Sysinternals Junction executable and the other the batch file with an icon similar to the one pictured in your previous post. I'd attach a screenshot, but I'm not sure whether that's possible.
  24. Thanks; I followed this procedure but I'm assuming I did something worng. When I attempted to run as admin I received the following error in the C:\ screen: 'junction' is not recognized as an internal or external command, operable or batch file.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.