Question

Windows xp blue screen

Asked by: dankyle67

Hi,
have a dell 600m laptop with windows xp sp3 and it keeps crashing with fatal error but when i go into safe mode its ok.  Triied using system restore but no restore points available.  If it works ok in safe mode, is it most likely a device driver?  I had installed avg v8.5 recently and this is around time it crashed.  Wanted to know best way to isolate which driver or program is causing the fatal error.  Also, i used diagnostic startup to load only basic drivers but still crashed.  Any ideas?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-03-08 at 16:53:06ID24210974
Topics

X-Windows Window Manager

,

Windows XP Operating System

Participating Experts
6
Points
500
Comments
104

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. BAD blue screen problem
    Hi, I have recently bought and put together a new computer and installed winXP onto it (about a month ago) recently i keep getting blue screens that pop up (usually jest after i select my user) that tell me there is an error and that it is doing a memory dump and that i need...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SaedSalmanPosted on 2009-03-08 at 17:24:23ID: 23832171

Hello, I just want to share this:
Think about recently add device, unplug it and uninstall its driver. Then, if your pc works properly, plug the device and re-install the the latest version of device driver.

at the end, I have a curiosity to know the solution :) and now I am monitoring it.

Best Regards,

 

by: debgaryPosted on 2009-03-08 at 17:35:02ID: 23832206

Blue screens are usually conflicts in memory access where a couple of different programs want the same area of memory at the same time.

Uninstall AVG. You can always put it back on again later if this doesn't help.

Make sure you run the PC for a couple of clean boots after the uninstall.

Hope this helps you.

Deb

 

by: SaedSalmanPosted on 2009-03-08 at 17:44:12ID: 23832246

Hello,
Does this mean 'Blue Screen' is the same as deadlock where race condition is achieved ?
if so, Is not the Operating System responsibility to take care of this ? at least to boot up.

 

by: dankyle67Posted on 2009-03-08 at 17:44:40ID: 23832249

Hi,

i uninstalled avg but still crashed.  I am  trying to do a repair now on xp system files using xp cd.  After that will try and see if i can log in normally.  Like i said, the fact that safe mode runs pretty well means there must be some driver or software conflict.  Noticed my wireless and embedded lan adapters are also not working.

 

by: venom96737Posted on 2009-03-08 at 17:59:09ID: 23832307

When are they not working in regular mode or in safe mode?  If its in safe mode they wont work unless you go into safemode with networking.  If its regular mode go into safe mode with networking and see if it still crashes.  Since it doesnt do it in safe mode I would look toward a video or lan driver if it is a driver but it really would help if you shared with us what the blue screen says on it.  If safe mode with networking crashes uninstall your ethernet driver and reinstall a new one if that doesnt fix it go for the wireless driver.  Once again if it would really help to know what the bluescreen is saying but thats where i would start with the symptoms you described.

 

by: dankyle67Posted on 2009-03-08 at 18:49:37ID: 23832533

Hi,

Just finished running the repair using xp home cd and it worked.  Only problem is that prior to repair when i couldn't get into windows normal mode, it was on xp sp3.  Now it is on sp2 since the cd i used is sp2.  Everything looks ok for now but would there be an issue you think with this situation.  I can just reapply the sp3.  Actually, this is not my laptop.  It is a friends and she uses it for work so probably her techs installed it for her but i will advise her to tell them to reapply.  I also had gone into safe mode prior to this repair using networking and both wireless and lan adapters had "status" selection grayed out under adapter properties so maybe it had corrupted system files and repair fixed it.  thanks for the help and let me know what you think about the sp3 issue.

 

by: nobusPosted on 2009-03-09 at 01:01:10ID: 23833730

in the future, post the minidump here, ; rename it to ***.txt
it may still be there, look in windows\minidumps.

 

by: JonveePosted on 2009-03-09 at 01:18:36ID: 23833787

If there's a Stop error, this article will help>
http://aumha.org/a/stop.htm

You could check to see if the Minidumps are enabled>
http://www.cakewalk.com/Support/ProblemReporter/minidump.asp

If the laptop is crashing before Windows has a chance to produce a crash dump, could conceivably be a Hard disk problem.

 

by: dankyle67Posted on 2009-03-09 at 13:02:07ID: 23840173

Hi,

after running avg free antivirus once, it discovered 12 trojans which it deleted and then i reran this morning and left laptop running but when i got back just now, the fatal error came up again.  It is stop: c000021a the windows logon process system process terminated unexpectedly with a status of f 0x00000000 (0x00000000 0x00000000).  Any ideas?  Also, not sure what you mean about the mini dump.  Thanks in advance.

 

by: JonveePosted on 2009-03-09 at 13:46:52ID: 23840678

Referring to the Minidumps, they are normally located in c:\windows\minidump\    
or  %systemroot%\minidump\

Can you paste the latest dump(s) in the "Attach Code Snippet" box.
You'll need to rename single minidumps first with a .txt extension.    If you have more than one you can zip them before attaching.

You may need to disable auto restart:
Right click My Computer > Properties > Advanced > Startup and Recovery Settings and uncheck Automatically Restart.

If you see no minidump this may help>
Enable Minidump's in Windows XP:
http://www.cakewalk.com/Support/ProblemReporter/minidump.asp

 

by: JonveePosted on 2009-03-09 at 13:49:51ID: 23840712

As you've already found a number of Trojans, suggest you run the following>

Download then update Malwarebytes' Anti-Malware:
http://www.malwarebytes.org/mbam.php
When updated, reboot into Safe Mode by selecting F8 at bootup & run a scan.
Full instructions are available, if you require.

Also ..
"Trend Micro's FREE online virus scanner":            
http://housecall.trendmicro.com/uk/
Ideal for scanning online, using "Safe Mode with networking".
     
Kaspersky free online virus scanner which is a good way to find out if you have any viruses or spyware without having to uninstall your existing antivirus software>
http://www.kaspersky.co.uk/virusscanner

 

by: dankyle67Posted on 2009-03-09 at 15:32:41ID: 23841794

Hi,

i had run avg in safe mode and when booting into normal mode got blue screen again.  Will try and get the minidump info and paste it here.  Since laptop works fine in safe mode, does this rule out bad hard drive?

 

by: SaedSalmanPosted on 2009-03-09 at 15:44:41ID: 23841906

Nope, it is not about hard drive. As I think.

Have you attached a new device recently ?
Have you updated, reinstalled, uninstalled any driver ?
Have you performed system restore from safe mode ?

 

by: JonveePosted on 2009-03-09 at 15:50:51ID: 23841978

Yes, assuming it's not your Hard drive at the moment, but it's worth trying those virus and Malware scanners, in Safe mode, particularly as AVG detected those Trojans.  
Recommend you start with Malwarebytes, it's excellent.

 

by: SaedSalmanPosted on 2009-03-09 at 15:54:51ID: 23842010

Again, did you upgrade windows ? (upgrade and not update, means change windows edtion e.g from XP SP2 to XP SP3 ...)
you might find the driver blue screen caused by here:
http://www.steveglendinning.com/2008/05/16/find-the-cause-of-a-vista-blue-screen/

 

by: dankyle67Posted on 2009-03-09 at 15:58:11ID: 23842043

HI,

as i mentioned, i had tried to correct the original problem by running a repair from xp home cd and noticed that it was sp2 afterwards when original was sp3 and that's why i had asked if this would be a problem.  Its possible that i had corrected the original blue screen and this is just a separate blue screen since after running the repair i was able to get in to windows normally for 1 day and then when running avg 2nd time it crashed.  

 

by: JonveePosted on 2009-03-09 at 16:09:16ID: 23842140

The repair procedure you used could be the problem.
Did you get the "Setup cannot continue because the version of Windows on your computer is newer than the version on the CD" message ?  
Scroll to this particular statement on the following link for detail.    You'll see that you need to create a slipstreamed copy of your XP CD by using the software and step by steps supplied in the links given here>

How to Perform a Windows XP Repair Install:
http://www.michaelstevenstech.com/XPrepairinstall.htm

 

by: SaedSalmanPosted on 2009-03-09 at 16:23:32ID: 23842260

Sorry, I just read your question and its seems to me as I never read it before.

the steps you performed when you tried to fix the problem lead to this situation.

I suggest you to perform CHKDSK which will perform in 3 stages.
- CHKDSK's activity is split into three major "stages" during which it examines all the "metadata" on the volume and an optional fourth stage. Metadata is "data about data." It is the file system overhead, so to speak, that is used to keep track of everything about all of the files on the volume. Metadata tells what allocation units make up the data for a given file, what allocation units are free, what allocation units contain bad sectors, and so on. The "contents" of a file, on the other hand, is termed "user data." NTFS protects its metadata through the use of a transaction log. User data is not so protected.
http://support.microsoft.com/kb/187941

this will gets your pc closer to the stable situation, if the issues still appear. the repair from XP SP3 CD will be much easer. with my wishes to you.

Best Regards
Saed Salman

 

by: dankyle67Posted on 2009-03-09 at 16:39:36ID: 23842363

Hi,

didnt get that message  when running repair.  Am running repair again and if i get in windows normally then it crashes later, must be service pack conflict

 

by: JonveePosted on 2009-03-09 at 16:55:54ID: 23842466

Ok, good luck this time.  Recommend you physically disconnect from the internet, but you were probably about to do that ... i still recommend you do a good virus & Malware scan, as soon as convenient.

Just logging off, it's about midnight over here .. will drop by tomorrow ...

 

by: dankyle67Posted on 2009-03-09 at 17:52:14ID: 23842708

ok hear from you tomorrow.  just to let you know i ran repair again fron xp cd home editiion and was able to get in again.  Rebooted 3 times and still able to get in.  Running Avg now so will see if that crashes.  

 

by: JonveePosted on 2009-03-10 at 00:48:07ID: 23844170

That's good.  If machine still running ok suggest looking for those illusive Minidumps .. then we'll have something more to go on, just in case it BSODs again.

Then perhaps next ..  update & run Malwarebytes' Anti-Malware, ~and~ one or two of the other scanners .. there's no single scanner that can guarantee removing all infections(that's assuming there may still be an infection!).

Once confirmed clean, we could take a look at your System Restore, which may well have corrupted file(s).

Not for one moment am i doubting your ability, but has it been enabled?  >>
http://www.pchell.com/virus/systemrestore.shtml

If ok, one option could be>
"The System Restore Utility May Be Suspended on a System Drive Even Though There Is Enough Disk Space":
http://support.microsoft.com/kb/299904/

Failing that, you could try this repair>
http://windowsxp.mvps.org/repairsr.htm

Reinstalling the System Restore program should not delete existing restore points which are stored in a hidden folder.
[Probably in C:\System Volume Information].
See >
"How to gain access to the System Volume Information folder":
http://support.microsoft.com/kb/309531

Until your laptop's is stable once more, perhaps it would be a good idea to hold off reinstalling avg v8.5.

 

by: JonveePosted on 2009-03-10 at 02:46:12ID: 23844706

Correction on one of my earlier System Restore comments ... your Restore functionality should be normal of course, after the XP repair.   If it's still inoperative you've got a few ideas there to check out.

 

by: dankyle67Posted on 2009-03-10 at 06:24:43ID: 23846309

Hi Jonvee,

thanks for all the advice.  I downloaded and installed the malwarebytes and updated then scanned whole machine and came up clean which was good and lapotp stayed on whole night but this morning when i rebooted it crashed again with same bsod message.  It references the logon process so wondering what that means but assume it is crashing right when it is about to bring up logon screen.  Anyway,my problem is that i didn't send you the minidump while the laptop was working since it was running scan of malware and i fell asleep.  Is there a way i can copy it from laptop in safemode so i don't have to run repair process again?  Unfortunately when it is in safemode after crashing, cannot access the internet to send to you since network adapters are not working.  Really curious what is causing the crash.  Thanks.

 

by: JonveePosted on 2009-03-10 at 06:32:29ID: 23846409

In addition to AVG 8 are you running an Acer eLock application ?

Apparantly one of Acer's dll's conflicts with AVG8, and causes a Page fault error.

If you are, from Safe mode you can uninstall the Acer eLock application.

 

by: JonveePosted on 2009-03-10 at 06:37:06ID: 23846462

Were you actually running AVG 8.5 at the time the laptop crashed?  If yes, there seems to be a connection, even if it's not an Acer eLock application that's running.

 

by: JonveePosted on 2009-03-10 at 06:53:55ID: 23846661

 >and i fell asleep<    << which is what i almost did at midnight last night!

Not aware of any method of reaching a Minidump from Safe mode.

Another option may be to try to run MSCONFIG from Safe mode.   Then from the SCU uncheck the Start up entries that are safe to 'disable', to see if some other application is causing the hang >>
http://netsquirrel.com/msconfig/msconfig_xp.html

Or if you prefer, you could try running the command "services.msc" (no quotes)>
http://www.blackviper.com/WinXP/service411.htm

 

by: dankyle67Posted on 2009-03-10 at 06:55:32ID: 23846682

Actually, laptop is a dellinspiron 600m.  Also, wasn't running avg when laptop crashed.  It was on all night and it crashed this morning when i went to do a reboot to test it.  Right now i am in safemode and wasnted to send you the minidump file but can't since internet not accessible due to network adapters not working.  Any ideas?  thanksl

 

by: dankyle67Posted on 2009-03-10 at 07:20:44ID: 23846966

Hi again,
was able to actually get to internet since both adapters are working now(don't know why they were disabled before).  Anyway, here is the minidump file.  Hope it makes sense to you.  I pasted to code snippet but doesn't seem right so i also included txt file.

MDMP§(Q	           ÑIµI           d       d  è     D  åv     ¨   Ü      8   R         Ä   
      Çv                             
      (
     L#     GenuineIntelÖ  ¿ùé¯<        S  ¬Ï´I        ´        À            Ý9|                          Üú	ñÿÿÿÿú	ñÿÿÿÿaxV¬ÿÿÿÿ,!âÿÿÿÿø%âÿÿÿÿÜû	ñÿÿÿÿ        ÿ     |      lú	ñÿÿÿÿ8HV¬ÿÿÿÿ,!âÿÿÿÿ        Ì  a7        ÿÿÿÿ         ðý    Dü     ¼  )z  Ì  f:  ´  ÿÿÿÿ         Ðý    <ú¥     Ä  å}  Ì  2=  ¸  ÿÿÿÿ         Àý    ,ÿ©     Ô   ©’  Ì  þ?  ¼  ÿÿÿÿ         °ý    @ÿ­     À   }  Ì  ÊB  <  ÿÿÿÿ          ý    Üÿ±     h   =&  Ì  E  D  ÿÿÿÿ         pý    èü¹       ¥&  Ì  bH  Ø  ÿÿÿÿ         @ý    $ÿÅ     Ü   ½Æ  Ì  .K  \  ÿÿÿÿ         ðú    hþÉ     Ü  "0  Ì  úM  ä  ÿÿÿÿ         àú    hþÍ     Ü  19  Ì  ÆP  `  ÿÿÿÿ         Ðú    ¤þÓ     \  ÉR  Ì  S    ÿÿÿÿ         Àú    Æÿ×     x   %}  Ì  ^V    ÿÿÿÿ         °ú    \ÿÛ     ¤   }  Ì  *Y  Ü  ÿÿÿÿ         ú    Èþã     8  A  Ì  ö[    ÿÿÿÿ         ¬ú    þç     è  y  Ì  Â^  t  ÿÿÿÿ         ý    lÿµ        a  Ì  }a  à  ÿÿÿÿ         àý    þ}     è  õ  Ì  Zd    ÿÿÿÿ         `ý    þ½     è  Ý  Ì  &g  P  ÿÿÿÿ         Pý    ¨þÁ     X  Å  Ì  òi  H           `  ÝS  Ö~An#  ½ïþ     (
  (
?                        $   ¾l                            |       ÷ò
 ´A´#  ½ïþ     (
  (
?                        "   âl                            ¬|     @ Hø ´Aö#  ½ïþ     (
  (
?                        %   m                            Ýw     °	 ä
 §A>$  ½ïþ     (
  (
?                        %   )m                            çw     	 Ä	 ®A $  ½ïþ     (
  (
?                        #   Nm                            ·\     ` & ºAÊ$  ½ïþ     (
  (
?                        $   qm                            Æo       ìP }A%  ½ïþ     (
  (
?                        %   "m                            Ôw      	 `Ê	 ¸AX%  ½ïþ     (
  (
?                        #   ºm                            ñw     ` ° AS%  ½ïþ     (
  (
?                        "   Ým                            ´v     Ð 
í ÖAÞ%  ½ïþ     (
  (
?                        "   ÿm                            Nw     À þA òA &  ½ïþ     (
  (
?                        "   !n                            Áw     ¬ Ó| RAb&  ½ïþ      (
  ¾!?                        #   Cn                            w     À Wi	 óA¦&  ½ïþ     (
  (
?                        %   fn                            ¾w     P Ö ÏAî&  ½ïþ     (
  (
?                       $   9n                            Àw     ¬  x ·A4'  ½ïþ     (
  (
?                        $   ¯n                            S|     @ ̬ ·Az'  ½ïþ      T   T?                        $   Ón                            öw     ` FY ¼AÀ'  ½ïþ      T   T?                        $   ÷n                            Sv     0 êg ¹A(  ½ïþ     (
  (
?                        $   o                            ×Z     ¬ 8æ »AL(  ½ïþ      T   T?                        $   ?o                            9v     Ð $  ®A(  ½ïþ     (
  (
?                        "   co                            Sb       ¶  ªAÔ(  ½ïþ     (
  (
?                            &o                            Ùt     ° ÉV ºA)  ½ïþ   ¤ (
¤ (
?                        "   ¥o                                       Ö#HT)                                                                                        ;v      ß± °AÜ)  ½ïþ      T   T?                        %   Ço                            	]     p	 &ð	 ¯Aà)  ½ïþ   R  T   T?                        %   ìo                            k      ¬     +W#H(*                                                                                        «q     p  òAp*  ½ïþ     (
  (
?                        #   p                            ªq     ¬  ö¯  óA´*  ½ïþ     (
  (
?                        $   4p                            =w     0 K2  Hú*  ½ïþ      ÆT   ÆT?                        S   Xp                            w     `
 ½$
 ÔAä+  ½ïþ      T   T?                        $   «p                            ¨w     @	 d	 A*,  ½ïþ   ’  (
’  (
?                        $   Ïp                            ²w       ­ ãAp,  ½ïþ     (
  (
?                        #   óp                            Év     ¬ 8â ©A´,  ½ïþ     (
  (
?                        %   q                            ¿v     °  :¢  ÊAü,  ½ïþ     (
  (
?                        "   ;q                            iw      ¿ÿ ÎA>-  ½ïþ     (
  (
?                        $   ]q                            öv     À  »A-  ½ïþ     (
  (
?                        $   q                            ¿q     0 QS ­AÊ-  ½ïþ     (
  (
?                        #   ¥q                            ¨v     0 Ûã ¯A.  ½ïþ     (
  (
?                        "   Èq                            þw      ¢ ÁAP.  ½ïþ     (
  (
?                        $   êq                                   P, D0- ¹A.  ½ïþ     (
  (
?                                                          v     0 r\ ½AÞ.  ½ïþ     (
  (
?                        $   r                            ÷t     `  ´~  "A$/  ½ïþ     (
  (
?                        #   2r                            w     0 kY °Ah/  ½ïþ     (
  (
?                        %   Ur                            Ãv     à ~ ¹A°/  ½ïþ   ’  (
’  (
?                        %   zr                            lw      Ð] ÑAø/  ½ïþ     (
  (
?                        "   xr                            u     ð m MA:0  ½ïþ     (
  (
?                        %   Ár                            Ìw       Ï~ A0  ½ïþ     (
  (
?                        %   ær                            áv     P c AÊ0  ½ïþ     (
  (
?                        $   s                             [     @ Ú ¬A1  ½ïþ     (
  (
?                        %   /s                            ²v       = ÇAX1  ½ïþ       ì  ì  ?                             Ts                            ¼v     ð  +¾ ¸A1  ½ïþ     (
  (
?                        #   ts                            ý     ¬ ܦ (]ë@Ú1  ½ïþ     q(
  q(
?                        #   s                            ýv     ð .ø ¢A2  ½ïþ    Ñ>   >  ?                         $   ºs                            w     P n ´Ad2  ½ïþ    Ñ>   >  ?                         #   Þs                            ´w       (c ´A¨2  ½ïþ     (
  (
?                        $   t                            &w     À	 xì	 µAî2  ½ïþ      T   T?                        #   %t                            ­q       1, ÿA23  ½ïþ     (
  (
?                        $   Ht                            îv     À V ©Ax3  ½ïþ     (
  (
?                        %   lt                            év       G§ ­AÀ3  ½ïþ     (
  (
?                        #   t                            ëv     ð ms ¶A4  ½ïþ     (
  (
?                        #   ´t                            èv     à  æ! ´AH4  ½ïþ     (
  (
?                        $   ×t                            +r     P  ef  ¬A}4  ½ïþ     (
  (
?                        $   ût                            ¥q     ð <z XAÔ4  ½ïþ     (
  (
?                        $   u                            +f     ¬ Ë  A5  ½ïþ     (
  (
?                        $   Cu                            ©q     ¬  " ýA`5  ½ïþ     (
  (
?                        %   gu                            üv     `  iÊ  ¨A¨5  ½ïþ     (
  (
?                        %   Ru                                 P Ë= .Fð5  ½ïþ                                      c   ±u                            Öv      Ìü aA>6  ½ïþ     (
  (
?                        %   v                            òv     p ú ½A 6  ½ïþ     (
  (
?                        #   9v                            õv     ¬  R  AÊ6  ½ïþ     (
  (
?                        %   \v                            6v       M ¸A7  ½ïþ     (
  (
?                        #   v                            Çw     0 ÙÀ OAV7  ½ïþ     (
  (
?                        #   ¤v                             S e r v i c e   P a c k   2   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s v c h o s t . e x e   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ n t d l l . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ k e r n e l 3 2 . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ a d v a p i 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r p c r t 4 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s h i m e n g . d l l   B   C : \ W I N D O W S 2 \ A p p P a t c h \ A c G e n r a l . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ u s e r 3 2 . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ g d i 3 2 . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w i n m m . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ o l e 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s v c r t . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ o l e a u t 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s a c m 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ v e r s i o n . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s h e l l 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s h l w a p i . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ u s e r e n v . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ u x t h e m e . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ i m m 3 2 . d l l   8   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ l p k . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ u s p 1 0 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ y d m v v o . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ c o m d l g 3 2 . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ c o m c t l 3 2 . d l l   B   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ f o z e m e v i . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w s 2 _ 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w s 2 h e l p . d l l   ä   C : \ W I N D O W S 2 \ W i n S x S \ x 8 6 _ M i c r o s o f t . W i n d o w s . C o m m o n - C o n t r o l s _ 6 5 9 5 b 6 4 1 4 4 c c f 1 d f _ 6 . 0 . 2 6 0 0 . 5 5 1 2 _ x - w w _ 3 5 d 4 c e 8 3 \ c o m c t l 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w i n i n e t . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ c r y p t 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s a s n 1 . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ i m a g e h l p . d l l   <   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ p s a p i . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ n t m a r t a . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w l d a p 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s a m l i b . d l l   <   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ r p c s s . d l l   @   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ s e c u r 3 2 . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ x p s p 2 r e s . d l l   @   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ t e r m s r v . d l l   >   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ i c a a p i . d l l   B   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ s e t u p a p i . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w i n t r u s t . d l l   <   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ a u t h z . d l l   B   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s t l s a p i . d l l   B   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ a c t i v e d s . d l l   @   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ a d s l d p c . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ n e t a p i 3 2 . d l l   8   c : \ W I N D O W S 2 \ s y s t e m 3 2 \ a t l . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r e g a p i . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r s a e n h . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ c l b c a t q . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ c o m r e s . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ a p p h e l p . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ u r l m o n . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w s o c k 3 2 . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r a s a p i 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r a s m a n . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ t a p i 3 2 . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r t u t i l s . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ s e n s a p i . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s w s o c k . d l l   @   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ h n e t c f g . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w s h t c p i p . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ r a s a d h l p . d l l   H   C : \ P r o g r a m   F i l e s \ B o n j o u r \ m d n s N S P . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ i p h l p a p i . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ d n s a p i . d l l   B   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w t s a p i 3 2 . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ w i n s t a . d l l   >   C : \ W I N D O W S 2 \ s y s t e m 3 2 \ m s v 1 _ 0 . d l l   ?                          ÿÿ  ÿÿÿÿÿÿ             ÿÿ´ü}     Ȭý} Q|ø<ý} B   øüDý} hRx B â֐|:=|¬ÿý}               _        <ý        ;   #   #   Äü¥ ú¥ s   ý¥ þÿÿ   ¨ü¥ Ý9|     @ú¥ #                      ÿÿ¬  ÿÿ  ´ü}     È      ¬ý} Q|ø      <ý} B   øü      Dý} hRx B       â֐|:=|¬ÿ      ý}                     _              <ý              Lý} @  hRx ¬ÿ} B Dý} \ r e g i s t r y \ m a c h i n e \ s o f t w a r e \ s e n e k a   \ s e n e k a   4 4 - 1 4 5 4 4 7 1 1 6 5 - 8 4 2 9 2 5 2 4 6 - 8 3 9 5 2 2 1 1 5   ¬9ÞwHþ} -9êw            Pý} x  ÿ} î|              \                  è          @bäw þ}   	 Üÿ} ó"’| "¬|ÿÿÿÿ:"¬|Ã+ '
 ¼ý} Ö6Þw«<Þw@bäw    ·<Þwm|Æ"¬|  	 ?                          ÿÿ @ÿÿÿÿÿÿan=w H=w# ÿÿöuV¬$`Üö           ¦ÎM¬ 
ÛºÔ0¸#â   ¨¬ö{ 8°T¬ S ¬À9Üöd       ¬ÿ?       ¬ÿ?        ;   #   #   ô           ë|Ps    À°ü ë|   F  Hü #    @  an=w   H=w# ÿÿ¬  ÿÿ  öuV¬$`Üö                       ¦ÎM¬ 
ÛºÔ0      ¸#â   ¨      ¬ö{ 8°T¬       S ¬À9Üöd             ¬ÿ?             ¬ÿ?      a}¿S ¬    9Üöa}¿S ¬    9Üö@Î â   9Üö¬       Ð9Üö]o¿    >  Ð9ÜöÜo¿@Î â$`Üöp¿   ø%â@Î â   9Üö8_Q        ¬ý@`ÜöÌù ¯¥|àø  pý|tø     Dù î|p	|Àä|o>|b>|  ü tü 6   r p   D r i v e Öù V o       6 8 øü ¬ü e r øü    6 E       Æû     <ù lû|qû|    Æû     ù utÝwþ î|xû|ÿÿÿÿqû|!uÝw            ,uÝw  ð¤u?                          ÿÿ  ÿÿÿÿÿÿ             ÿÿ´ü}     Ȭý} Q|ø<ý} B   øüDý} hRx B â֐|:=|¬ÿý}               _        <ý        ;   #   #   Äü¥ ú¥ s   ý¥ þÿÿ   ¨ü¥ Ý9|     @ú¥ #                      ÿÿ¬  ÿÿ  ´ü}     È      ¬ý} Q|ø      <ý} B   øü      Dý} hRx B       â֐|:=|¬ÿ      ý}                     _              <ý              Lý} @  hRx ¬ÿ} B Dý} \ r e g i s t r y \ m a c h i n e \ s o f t w a r e \ s e n e k a   \ s e n e k a   4 4 - 1 4 5 4 4 7 1 1 6 5 - 8 4 2 9 2 5 2 4 6 - 8 3 9 5 2 2 1 1 5   ¬9ÞwHþ} -9êw            Pý} x  ÿ} î|              \                  è          @bäw þ}   	 Üÿ} ó"’| "¬|ÿÿÿÿ:"¬|Ã+ '
 ¼ý} Ö6Þw«<Þw@bäw    ·<Þwm|Æ"¬|  	 ?                          ÿÿ  ÿÿÿÿÿÿ             ÿÿ´ü}     Ȭý} Q|ø<ý} B   øüDý} hRx B â֐|:=|¬ÿý}               _        <ý        ;   #   #   `ÿ©                À   Æÿ© ë|     0ÿ© #                      ÿÿ¬  ÿÿÿÿ´ü}     È      ¬ý} Q|ø      <ý} B   øü      Dý} hRx B       â֐|:=|¬ÿ      ý}                     _              <ý              Lý} @  hRx ¬ÿ} B Dý} \ r e g i s t r y \ m a c h i n e \ s o f t w a r e \ s e n e k a   \ s e n e k a   4 4 - 1 4 5 4 4 7 1 1 6 5 - 8 4 2 9 2 5 2 4 6 - 8 3 9 5 2 2 1 1 5   ¬9ÞwHþ} -9êw            Pý} x  ÿ} î|              \                  è          @bäw þ}   	 Üÿ} ó"’| "¬|ÿÿÿÿ:"¬|Ã+ '
 ¼ý} Ö6Þw«<Þw@bäw    ·<Þwm|Æ"¬|  	 ?                          ÿÿ  ÿÿÿÿÿÿ             ÿÿ´ü}     Ȭý} Q|ø<ý} B   øüDý} hRx B â֐|:=|¬ÿý}               _        <ý        ;   #   #   tÿ­         ë|Lÿ­     Sÿ­ ë|     Dÿ­ #                      ÿÿ¬  ÿÿÿÿ´ü}     È      ¬ý} Q|ø      <ý} B   øü      Dý} hRx B       â֐|:=|¬ÿ      ý}                     _              <ý              Lý} @  hRx ¬ÿ} B Dý} \ r e g i s t r y \ m a c h i n e \ s o f t w a r e \ s e n e k a   \ s e n e k a   4 4 - 1 4 5 4 4 7 1 1 6 5 - 8 4 2 9 2 5 2 4 6 - 8 3 9 5 2 2 1 1 5   ¬9ÞwHþ} -9êw            Pý} x  ÿ} î|              \                  è          @bäw þ}   	 Üÿ} ó"’| "¬|ÿÿÿÿ:"¬|Ã+ '
 ¼ý} Ö6Þw«<Þw@bäw    ·<Þwm|Æ"¬|  	 ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿØv
 lv
 
 È|A	 x`a
 ú} Púqû|x	 þá,ú} 
â|Üÿxû|ÿÿÿÿqû        Üûxû} H  pû        ;   #   #                   x	 À   ´ÿ± ë|   F  Sÿ± #                       ÿÿ¬  °
 Øv
 lv
 
       È|A	 x      `a
 ú} Pú      qû|x	 þá      ,ú} 
â|Üÿ      xû|ÿÿÿÿqû              Üû      xû} H  pû      ±   Üû} ú} ¸ú}   	 2|   x	   	     ú} È|Ôü} î|8|ÿÿÿÿ2||ë| Ä|        xû|ÿÿÿÿqû|û}   	 2|   x	 $û}   	 2|   è	   	     üú} 2|@ý} î|8|ÿÿÿÿ2||ë| Ä|            lý} î|8|ÿÿÿÿ    |°x
 @	   	 2|q   ¸	   	     hû} Æ"¬|¬ý} î|    À	 ||       ¨x
 0àþw    8àþw¾|ó"’|¸	        Àx
 @	 8àþwü}   	 ?                          ÿÿ  ÿÿÿÿÿÿ      	       ÿÿxû|ÿÿÿÿqû        Üûÿ¬|ÿÿÿÿ¤úSú} ÿ|    	 àx
     Ðú} Ôú2|   x    ¬ú} ë        ;   #   #                  È|À   ´ÿ¹ ë|   F  ìü¹ #       	               ÿÿ¬  x	 xû|ÿÿÿÿqû              Üû      ÿ¬|ÿÿÿÿ¤ú      Sú} ÿ|          	 àx
           Ðú} Ôú      2|   x          ¬ú} ë      î|ú   ý} 8||ë|ÀÃ|        x	 $û}   	 2|   è	   	     üú} 2|@ý} î|8|ÿÿÿÿ2||ë| Ä|            lý} î|8|ÿÿÿÿ    |°x
 @	   	 èx
 q         	     ¬û}   	 2|	   8	   	     û}    Èý} î|ñ  Øý} 8||ë|    @      Àx
 @	 8àþwü}   	  8    S  x	    x	      
     8|X  S  x	 ¸x
 8 
        ý} x	    ?                          ÿÿ  ÿÿÿÿÿÿ      Á       ÿÿ    ¸ûÁ     	 2|   	     xù¼ûÁ î|g8||ëÜ/v    0v-|  |ë|@~        ;   #   #       à      4ýÁ ØúÁ À   RÿÅ ë|   F  (ÿÅ #       Á               ÿÿ¬          ¸ûÁ           	 2|         	     xù      ¼ûÁ î|g      8||ë      Ü/v          0v-|        |ë|@~                      ø¿ßw0y
   v0úÁ úÁ     È|üÁ ÜúÁ     8	     üÁ  üÁ  ûÁ ,üÁ ðûÁ (üÁ     2|   @	 à          [ É@	 @	 x	                 x	 x	 È   D|    È´
 x	 ø5Æ|¡C|     ´
 P´
   	        ðûÁ (´
 x	    ¨´
 qû|0ûÁ x	 x	 x	 0´
 д
 î|x	 x	 x	 ¨´
 X´
     HüÁ x	 x	 0´
 üÁ üÁ à  x	 0ûÁ g          4  ÀØÀ|l  v  x	 ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿî|ï   Tû  	 2|   	 Ü& 4ùxûÁ î|82|«|ë         °ùÁ   	 2Ø	   	 0Å        ;   #   #   í| 0v    ë|øýÉ À   ´ÿÉ ë|     lþÉ #                       ÿÿ¬  DûÁ î|ï   Tû        	 2|         	 Ü& 4ù      xûÁ î|8      2|«|ë                     °ùÁ   	 2      Ø	   	 0Å      2|ÌûÁ î|8|ÿÿÿÿ2|«|ë|lüÁ tüÁ     2|«|ë|    4       (.vLüÁ x	 ðùÁ \ R e g     t r y \ M a c h i n Æ( S y s t e m \ C u r r e n t    n t r o l S x	 \ C À' t r o l \ T e r x	 n a ( S e r v e r x	 x HûÁ ¸' 8	 m|    ÐûÁ þá|ûÁ ÌúÁ lû|qû|ï   þá|ÐûÁ ¨úÁ 
â|ÜÿÁ î|x	 ÿÿÿÿqû|´oÝw        üÁ    ôûÁ À'  ¬             ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿ(   p Ìû(         ¸ûÉ üÉ îÌáv     ¸ûÉ    üÐávÿÿÿÿÌ  áv    ȼv  ¼v         ;   #   #   í| 0v     ~v àúÀ   ´ÿÍ ë|     lþÍ #                       ÿÿ¬  Æp (   p Ìû      (               ¸ûÉ üÉ î      Ìáv           ¸ûÉ    ü      ÐávÿÿÿÿÌ        áv          ȼv  ¼v           $üÉ  ¬ý0üÉ §|  ¼v        ¬ý     @ ¤üÉ  ðú¤üÉ }|TüÉ !| ðú ¬ý                                              ¬ý¬¼v¤ HüÉ     ýÉ î|Ð}|ÿÿÿÿt}|Äè|ú|0ýÉ î|                                                     ðú                    °üÉ     ÿÿÿÿî| }|ÿÿÿÿú|%֐|Ïê|0ýÉ                              8 j÷~~ZâV¥PÍ l÷¸~Zâ    ?                          ÿÿ  ÿÿÿÿÿÿ      Á       ÿÿ«|ë|@x@x                                                   r                     ;   #   #    ¬ý    ÐþÓ ë|°ÿÓ À   DÿÓ ë|   F  ¨þÓ #       Á               ÿÿ¬  2|«|ë|@x      @x                                                                                 r                                        X	 x	  r øq        X	                                                                                |                                       	|w øq             øq                        øu     ðq h	         ðq (   øq     x	 (         	 lùÁ     ÀûÁ î|ð|ÿÿÿÿë|æ|$|¬À|ú|w ¬w      ¬ý Pýøq ûÁ     ÜÿÁ ?                          ÿÿ  ÿÿÿÿÿÿ      Á       ÿÿ«|ë|@x@x                                                   r                     ;   #   #   |     ~vI N D O À   ´ÿ× ë|     Rÿ× #       Á               ÿÿ¬  2|«|ë|@x      @x                                                                                 r                                        X	 x	  r øq        X	                                                                                |                                       	|w øq             øq                        øu     ðq h	         ðq (   øq     x	 (         	 lùÁ     ÀûÁ î|ð|ÿÿÿÿë|æ|$|¬À|ú|w ¬w      ¬ý Pýøq ûÁ     ÜÿÁ ?                          ÿÿ  ÿÿÿÿÿÿ      Á       ÿÿ«|ë|@x@x                                                   r                     ;   #   #   À2v    ~vI N D O À   ´ÿÛ ë|     `ÿÛ #       Á               ÿÿ¬  2|«|ë|@x      @x                                                                                 r                                        X	 x	  r øq        X	                                                                                |                                       	|w øq             øq                        øu     ðq h	         ðq (   øq     x	 (         	 lùÁ     ÀûÁ î|ð|ÿÿÿÿë|æ|$|¬À|ú|w ¬w      ¬ý Pýøq ûÁ     ÜÿÁ ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿÐþÓ   ý¬HüÓ     ýÐ}|ÿÿÿÿt}ú|0ýÓ C                                Ðú              ;   #   #    ¬ý    ôþã ¤üÓ }|À   hÿã ë|   F  Ìþã #                       ÿÿ¬      ÐþÓ   ý¬      HüÓ     ý      Ð}|ÿÿÿÿt}      ú|0ýÓ C                                                        Ðú                    °üÓ     ÿÿÿÿî| }|(ýÓ     È|°Â
 ôýÓ Q|8	 m|RD	 vÃ
                                  0ÀE	|N	|         ¬ý¬A Àr’N¬ ¬ý|        ¬ýÈ   D|p	|Àä|D|ø5Æ|¡C|     þ2Àüþ2À  	 8       à\SvaþÓ <ZSv%   (þÓ Ó:|aþÓ 1     Sv\Svà\Sv       ÜþÓ          Svè Sv þÓ    8þÓ "|  Sv    ôþÓ Sa|  SvaþÓ þÓ þÓ aþÓ ?:|ØÀ|ëa|NÚv    ÿÿ  ?                          ÿÿ  ÿÿÿÿÿÿ      H       ÿÿ. \ p i p t x _ W i a t i o n I _ s e r e                                               ;   #   #   ds Àr     ë|þç À   ¬ÿç ë|   F  þç #       H               ÿÿ¬  \ \ . \ p i p       t x _ W i       a t i o n       I _ s e r       e                                                                                               ðûÁ   	 2|   è		   	     ÈûÁ     þÁ î|8|ÿÿÿÿ2||ë|øÍ     Ð
 H	   	     üÁ     HþÁ î|8|ÿÿÿÿ2||ë|ÐÉ (%ví|                    Ð	                                                 SüÁ °Î @	 Ü 	 hýÁ Q|x	 m|    =|                        øÍ        ¨Î                                ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿ        pù2|   è	    Rù¹      x	   dù¹ ë|¨ûç  ¸û¹ 8ë|                       ;   #   #    Ã|¬Ã|            À   ´ÿµ ë|      pÿµ #                       ÿÿ¬              pù      2|   è	          Rù¹            x	         dù¹ ë|¨û      ç  ¸û¹ 8      ë|                                                                                                           ú¹     ´ÿ¹ %֐|Ïê| ú¹                  dú¹   	 2|   	   	 Ü <ú¹     ¬ü¹ î|8|ÿÿÿÿ2|«|ë|   è                                                          ;   #   #                  È|À   ´ÿ¹ ë|   F  ìü¹ #   ë|   F  ìü¹     ë|   @	 ìü¹ 8ÌB ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿ              Sü½ Ðú@   Üú½ Üú    üú½   ø
 Èû½ Qm|ý½   è©
 h	  è©
    a¨        ;   #   #   c	 Èb	     ë|   À   ¬ÿ} ë|   F  þ} #                       ÿÿ¬  ÿÿ                      Sü½ Ðú      @   Üú½ Üú          üú½         ø
 Èû½ Q      m|ý½         è©
 h	        è©
    a¨       
         
 
 8   
    Rû½   	 2|   è		   	 ¸*
 dû½ È|¨ý½ î|8|ÿÿÿÿ2|«|ë|p§
     Ð
   ý    û½ ¿·¬| ü½ î|p|ÿÿÿÿm|Æ"¬|  	     :"¬|ý½            x   Dü½ S©vÜû½    ¤ý½ ó"’| "¬|ÿÿÿÿ  	   	  
                   û½ ¤ý½ ¤ý½ Pü½     È|  ý½ Q|È	 m|hý½ Ø¥
     à          (        à                  ?                          ÿÿ  ÿÿÿÿÿÿ              ÿÿÐúú `   Üú      øøL        ýdÿ          Dýú xpy
 2|«   x	 ¬lûú              ;   #   #   ds Àr             À   ¬ÿ½ ë|   F  þ½ #                       ÿÿ¬  ÿÿ  Ðúú `   Üú            øø      L        ý      dÿ                Dýú x      py
 2|«         x	 ¬      lûú            p	    &   i
      	 x	 ¨ûú   	 2|   è		   	 àÃ
 ¬ûú x	 Äýú î|8|ÿÿÿÿ2|«|ë| Ø     Ð
     È|Hó Üûú     È|X· ¨üú Q|x	 m|`· `·     @}
 Èüú Q|Ü	     È|Â àüú    x
	 m|Â Â   	 h#
     ýú \
|Püú     È|H 
 ýú Q|Ü	 m|hýú ð&
       ¬    Ü p#
 Øûú Üûú ¤ýú î    Ü	 m|   î|p|Ü	 m|      	 ?                          ÿÿ  ÿÿÿÿÿÿ      D      ÿÿ²Q       M $ü   Üûí à3k0j¿ ¬à60üí §        ¬M ¤üí  p}|Tüí !        ;   #   #       h
 ÿÿÿÿ    ¬|À   ØþÁ ë|   F  ¬þÁ #       D              ÿÿ¬  ÿÿ  ²Q             M $ü         Üûí       à3k0j¿ ¬      à60üí §              ¬      M ¤üí  p      }|Tüí !       ¬ý                          üí   	 2|   è		   	 Èõ xüí Hüí ¼þí î|8|ÿÿÿÿ2|«|ë|x:
     Ð
 `²
                                                  pú                    °üí     ÿÿÿÿî| }|ÿÿÿÿú|%֐|Ïê|0ýí                               0À|; Àâ                      +Ï÷ÁN¬ 0À+Ï÷ ¿N¬ ðí         ÿÿí ¨G gy     |; À
       RSDS:|z$8LaãåܰÆSI   svchost.pdb RSDSµ_Q6CÐäEörú.(xÀ   ntdll.pdb RSDS²O3û£(A½é"&¾L/   kernel32.pdb RSDS_l]EM»EµÅóQ   advapi32.pdb RSDSrZ¤¾¡ÚA£º ³¢S   rpcrt4.pdb RSDSåÃØª',ÖL `Iq¦LDr   ShimEng.pdb RSDS¨pª}_(F¿hÂ~ݼ   AcGenral.pdb RSDSzj\jÞC’Zçé   user32.pdb RSDSô MhúNxGä+R   gdi32.pdb RSDSyñÉOGÊE£Ço­ü(2   winmm.pdb RSDSbC/	cG¯eL*îà   ole32.pdb RSDSÃóx¦í
kB’2¹Ü~8   msvcrt.pdb RSDSȰx¼0
@º"r}ûX¡   oleaut32.pdb RSDSFÕïÔOLpÈ ø   msacm32.pdb RSDSĐ
>FÝÄ[,`·n   version.pdb RSDSß! ȼ?Mf&uUäÕ   shell32.pdb RSDSÀ ñ!¬O¶BVÙmÏë   shlwapi.pdb RSDSÎ"!Ç UÒL©eU|ñÙN   userenv.pdb RSDSþ¸¹9YC­<ÎÌÀÕx   uxtheme.pdb RSDSS¤,%}L¹â­×Ùê   imm32.pdb RSDSáàÈ«ìN¡ÑäB¯
Ð    lpk.pdb RSDSø×È<«¤H¹ZsºÉ¦°,   usp10.pdb RSDSÖêËOs="ERØÛ°Ü'   comdlg32.pdb RSDSaþ9sÊ®G20#SÜË   comctl32.pdb RSDS’¬@~Ϥ"¿   ws2_32.pdb RSDS0è|SéïãO©,";ÛqF   ws2help.pdb RSDSWPP@oA³xí9¾ÐW   MicrosoftWindowsCommon-Controls-6.0.2600.5512-comctl32.pdb RSDS	&'õ8uL’¡OߢüÊ<   wininet.pdb RSDSs¶!@;J©ÅE!wF¸0   crypt32.pdb RSDSwLuh¨J"&x ó^   msasn1.pdb RSDSUÀeD|ÑI³tTÜQ'   imagehlp.pdb RSDSù¡Ã¥xhØC­"`	)80p   psapi.pdb RSDS d¢ÒȵK£);"©p   ntmarta.pdb RSDS^!°D§n]k¨¦¥   wldap32.pdb RSDSäÖ²ù¹-sEÆÖ"s³¹S   samlib.pdb RSDSfÄÈqÙ¾D´÷Blxs_   rpcss.pdb RSDS¿rÝ&­LïB¹0ia9/   secur32.pdb RSDSãåòíQ#1H·DÁ£D|/^   termsrv.pdb RSDS&]þ’6àC«2[ãf`ØF   icaapi.pdb RSDS`¿Æ°v&C92òq_«   setupapi.pdb RSDS¥<5v&]NC­¶’ §9   wintrust.pdb RSDSìR"-w´L©0¦ tF   authz.pdb RSDSÒLÜ	½RG¶ßÚÃÈ7~   mstlsapi.pdb RSDS¾|axdOúE¯+8SUu	ï   activeds.pdb RSDSrçõvv"H:ßß=þM   adsldpc.pdb RSDSÑ <kª%£F¿¢a4û3   netapi32.pdb RSDSOt/f~N»V¡ÅL_   atl.pdb RSDS?=ý~ÅgD«3_aÞû±S   regapi.pdb RSDS¿Òû°ÚF¼"^"¹Zc¨   rsaenh.pdb RSDSrèýëkÙ#JÆ Uú¾é&   clbcatq.pdb RSDSÄDØ)Fª¼sýß
à   COMRes.pdb RSDSÛÎpD©¶"6f’\   apphelp.pdb RSDSý¶m¶WÉnOµò²Kªµd   urlmon.pdb RSDS~Á¶ç`C"H=;eI:l   wsock32.pdb RSDS¯bzqU&A¾ö Üt   rasapi32.pdb RSDS=ÚèH¸)é-cø7'   rasman.pdb RSDS’þcU|æÜG¹á¦dÁ   tapi32.pdb RSDSkûíØCÍI½\.s   rtutils.pdb RSDS ZêÙR×A¡Çu!¨®ïÖ   sensapi.pdb RSDSÆdöâi·C` TQê°   mswsock.pdb RSDSÓbötóI¼¸Û9ï   HNetCfg.pdb RSDSa
Þ5!ôECÙgèqÜ   wshtcpip.pdb RSDS²0©S0>NËt õ   rasadhlp.pdb RSDS³q!XH¶k;óZ8I   c:\bwa\BonjourWin-12\srcroot\mDNSWindows\mdnsNSP\Win32\Release\mdnsNSP.pdb RSDSy¨¶é¬g%C»ðG÷þñ"   iphlpapi.pdb RSDSí"§RC´	3Áz¢   dnsapi.pdb RSDS¸\Ó6:ÎÌMº)ô·N&D   wtsapi32.pdb RSDS÷:Ü*iE±ºy~}Ø=   winsta.pdb RSDS}"VlúIa{.:Ã}¸   msv1_0.pdb Dr. Watson generated MiniDump    ]9|       )x  ë|       )y  Dü     ¼  )z  <ú¥     Ä  å}  ,ÿ©     Ô   ©’  @ÿ­     À   }  Üÿ±     h   =&  èü¹       ¥&  $ÿÅ     Ü   ½Æ  hþÉ     Ü  "0  hþÍ     Ü  19  ¤þÓ     \  ÉR  Æÿ×     x   %}  \ÿÛ     ¤   }  Èþã     8  A  þç     è  y  lÿµ        a  þ}     è  õ  þ½     è  Ý  ¨þÁ     X  Å  ð|Y¬ûgu;÷u&ôýÿÿPÿ ð|Y¬½ôýÿÿ-u¬ñýÿÿ&õýÿÿ0&äýÿÿ9&äýÿÿP`@Éuù+ÂéK  If’8 t@@&Éuó+&äýÿÿÑøé1  &Àu¡äî|0&äýÿÿ9&äýÿÿëI¬8 t@&Éuõ+&äýÿÿé  Ç&èýÿÿ   0¼ýÿÿé.  `&¼ýÿÿQÆ&Øýÿÿ0Æ&ÙýÿÿÇ&Ðýÿÿ   é!  ö&ðýÿÿ¬Ç&àýÿÿ   
  ¬ñýÿÿéþ  ’&ìýÿÿö&ðýÿÿ 9ÿ’Äì0$ÇD$   0\$ÇD$    Tèw    U9ì’ìP0D$d¡   9¬¤  0$ÇD$    ÇD$    ÇD$    Tè8   9$9å]Ѝ¤$    I 9Ô4Ã¤$    d$ T$Í.ÃU9ìSìÐ  0&Üýÿÿ0Øýÿÿ9E9M0H&,ýÿÿ0Ƹ   0ܤ   0¨   0°    0¸S   M0ÆÄ   9M 0Æ´   9Mü0ÆÀ   RƼ   RÜÜ 4ü Æâ|u¬|ô               Æü |ý           ý ¬||ý     .|¬y
 <z
 |ý   tü     @ý ó"’|Ø:¬|ÿÿÿÿÜü ˳Þwô   |ý   Øü     ¬y
 <z
 |ý     Pý _²Þwô   |ý   ý ¸
      ¬ý          y´Þw¬y
 p e     <z
 Ô          ý o l     ôü 2    ÿ UVßw³Þwÿÿÿÿ°ÿ hµÞwô   |ý   ¸
 à0
  ¬ý        ô   0   P              T e r m S e r v i c e                                                                                                                                                                                 	 3
     4ÿ \
|  	 |	 m|¸
     Ü3
         3
     È|ø
 hÿ Ü3
 	 m|¸
      ¬ý 	     Ðþ     È|Ø0
 Sÿ Q|¸		 m|¸
 à0
  ¬ý                  	         @                xþ a÷  lÿ î|p|ÿÿÿÿm|Æ"¬|Æ       :"¬|¸
      ¬ý    àÿ î|p|  	 m|àÿ ó"’| "¬|ÿÿÿÿ:"    àþ à0
 àÿ î|Ps  dý m|àÿ UVßwܵÞwÿÿÿÿðÿ &% ¸
 8|ÿÿÿÿOm|8|ÿÿÿÿ ¬ý8°T¬Èÿ ¨ýF ÿÿÿÿó"’|Xm|            	%       	 |,ý¥  Oy                                    Äü¥         ½Vx     e   )      ÿÿÿÿý¥     0û¥ Ìú¥ Å­|pû Üýb   hû Æ>|       ôý¥ Ìý¥ pý¥ U­|p	|   0û¥ 8û¥     û¥ 41|ü¥     û¥ Tû¥    ü¥ S    Oy     `ü¥ 
)|8û¥        | )|  Tû¥  ¬ ü¥         (
     S e r v i c e   P a c k   2                                                     ´û¥     È|`û ¬ü¥ Q|X		 m|    =|                            ~ õ 0@xý¥ 9@x 2600|àNy ç   Dü¥ F|$ü¥ ]x Xü¥ |ÀNy ÎNy    ÀNy B   Dü¥ L0Æ|Î3|ç   ü¥ s#x ÀNy     ]x       (
         àNy S         (
     Service Pack 2                  ç   äü¥ F|Äü¥ ÆVx øü¥ |àNy ý¥ x   ,ý¥ B                   dþ¥ KAx ,ý¥   ÆVx   ! Qy       |Vx    ÀNy àNy 9Ry  Oy  ¬  :¬|  ! http://78.26.144.210/seneka/engine/engine.php?bot_id=2223964344-1454471165-842925246-839522115&affid=ÿÿÿ    =|þ¥ u|    ,                 ôý¥ @       Øý¥     Æâ|u¬|X              þ¥   ! ;       ܬ|  !     X  ôý¥ @       ;   ða¬|ÿÿÿÿüý¥ "a¬|Üÿ¥ ó"’|Ø:¬|ÿÿÿÿܬ|Ր|»:¬|X  `þ¥ Qx     Ù           ! ÿ¥ NBx  !    B$¬|,  ,  \\?\globalroot\systemroot\system32\senekauojbpjhi.dat                                                                                                                                                                                                               è½Û ;   ´ÿ¥ ´ÿ¥ àBx    !¨O¬~&x      ÿ¥     Üâ|ìÿ¥ µ¬|,        ,   Ðý  ÀÀÿ¥ dö¥ ÿÿÿÿó"’|µ¬|            RBx ,          \ؐ|í#¬|    `ÿ©                             æ}çýÿÿÿX  `ÿ© @ÿ© 4ÿ© Üÿ© ó"’|X$¬|    Üÿ© Q$¬| »
     ´ÿ© ¢?x  »
 ¬ÿ©     ¨'x     ìÿ© µ¬|               Àý æ{ Àÿ© M ÿÿÿÿó"’|µ¬|            U?x             \ؐ|í#¬|    tÿ­                            ¬igÿÿÿÿÿXXx tÿ­ Tÿ­ ^x Üÿ­ ó"’|X$¬|    ¬ÿ­ Q$¬|è      ìÿ­ o+x è  µ¬|               °ý æ{ Àÿ­ hSF ÿÿÿÿó"’|µ¬|            _+x             \ؐ|Ôy|   ¬ÿ±        ¬ìÿ± µ¬|                  ý æ{ Àÿ± èüB ÿÿÿÿó"’|µ¬|            y|           «é|Õ |   0ý¹               lv
     å|å|d  D           `  l     @                                                                                                                                                                                                                                                    è 
 ¬ 8 
 8                                                                                                                                                                                                                                             `                      Hÿ¹ Hÿ¹ Pÿ¹ Pÿ¹                                             n~                                       Øÿÿÿÿìÿ¹ µ¬|        lv
      pý æ{ Àÿ¹  ºB ÿÿÿÿó"’|µ¬|            ®x|            Àé|Û%¬|à          tÁ|                         jövÆ/v ¬ý @ý    Üöv<ÿÅ SÿÅ ÜÿÅ ó"’|&¬|     ÿÅ B%¬|à  ÿÿÿÿ    ìÿÅ *þvà  ÿÿÿÿx	 eþvµ¬|    tÁ|x	      @ý æ{ ÀÿÅ G0&ÿÿÿÿó"’|µ¬|            `þv         0vã|¸hv   þÉ     ¨þÉ øúÁ î|     ðú ðúä    Ñ     Ø ð         em             þÅ     (  ±           Æ      &¬|x  ÐþÅ     È|¨¬ SÿÅ Q|H	 m|tÁ|°¬     ÿÿÿÿ¨6ïw¬^ÞwXÞw²RÞwÿÅ <ÿÅ f^Þw}^ÞwtÁ|            XÞwÿÅ 4ÿÅ hÿÅ UVßw¬^ÞwÿÿÿÿÀé|w½v8      àv ~v@x     jövÆ/vtÁ|r  þÉ Ü,KòÜÿÉ >v°(vÿÿÿÿìÿÉ µ¬|    øúÁ î|     ðú æ{ ÀÿÉ p;7&ÿÿÿÿó"’|µ¬|            ^hv         0vã|¸hv   þÍ     ¨þÍ             àú àú      Ñ     Ø ð         m             Àý    (  ±           Æ             ÿÿª    ¯
  Ô"3&"3&à        « <+fò    ÿÿÿÿñ*N¬ ÀýÿÿÿÿV¬kðM¬ÿÿÿÿ¸,fò¼,fò ¬  DÏ*& ,fòF  jÈM¬Ï*&     @ýRÿÅ *&¬|HÿÅ  &¬|Àé|"½v8  S½v ~v ~v@x     jövÆ/vtÁ|r  þÍ Ü¼"òÜÿÍ >v°(vÿÿÿÿìÿÍ µ¬|                àú æ{ ÀÿÍ p;7&ÿÿÿÿó"’|µ¬|            ^hv        lû|«é|ò¬|   ÐþÓ                fÙÝw    x  |  T  ìI¼v  ¬                          ìI¼v,ÿÓ      ¬ý ÐúÚ¦¬|    ÐþÓ  Ü|   ÄþÓ |  ÜÿÓ ó"’|"¬|    `ÿÓ  S¬|   ÿÓ     ÿÿÿÿ    ÿÓ ÍI¼v   ÿÓ     ÿÿÿÿÌÆ T      x  |  T  ´ÿÓ Ýévt  T  ÌÆ C :     °ÿÓ°ÿÓìÿÓ µ¬|    ÌÆ C :      Ðú æ{ ÀÿÓ x:> ÿÿÿÿó"’|µ¬|            Sév        ÿÿÿÿÀé|év          ÌÆ C :  º<Üÿÿÿÿ    ìÿ× µ¬|    ÌÆ C :      Àú æ{ Àÿ× ¸",&ÿÿÿÿó"’|µ¬|            èv        î|«é|ܨv    t            ÌÆ C :      .¶ÿÿÿÿ                       ¸t  t ìÿÛ µ¬|    ÌÆ C :      °ú æ{ ÀÿÛ ¨`1&ÿÿÿÿó"’|µ¬|            .§v        ¼Çø~«é|ò¬|   ôþã                ¸¦vw:¬|`  d  ,   \þã lÿã lÿã î|p|                 ö¬| @ ¤üÓ  ¬ý ú8C	     ôþã        èþã     Üÿã ó"’|"¬|    ÿã  S¬|   ¦v    ÿÿÿÿ    ´ÿ㠍ÆSv   ¦v    ÿÿÿÿ @ ¤üÓ       Sv       ìÿã µ¬|     @ ¤üÓ      ú æ{ Àÿã x:> ÿÿÿÿó"’|µ¬|            1ÆSv        U&çw"ã|gçwÌ  pÿç     ðì Lÿç t R     (  Ü
  må     ¦¬|       ÿç `²
     Üþç       Lí    (  Ü
  Ð     |ÿÿÿÿ     0  ðkçw`²
     Øþç ã|Ùˬ|    h
 Øþç ̬|   ]îÿÿÿÿ    "  ÿç úrçw    ÿç  ÿç ÿç ¾sçw¬|h
                     h
 ¬ÿç +rçwähçw,vçw0
 h
 ¬ÿç ¬ÿç "fçwLÿç ©fçwí|øÍ  Î  ¢/Mÿÿÿÿ ]îÿÿÿÿ   8þç  Î  ¬Lÿç  ¬ðì         Æÿç "lçw¨ÿç ;jçwÀr         Î  Î  L ´ÿç 
lçwÐ
 ìÿç µ¬| Î         Î  ¬ú æ{ Àÿç ¨`1&ÿÿÿÿó"’|µ¬|            ðkçw Î     `ÿµ ã||\  ¬ÿµ °ÿµ Üÿµ  ÿµ                 8  |(èÿÿÿÿ    iu|Ø ìÿµ µ¬|                 ý æ{ Àÿµ üB ÿÿÿÿó"’|µ¬|            `|        U&çw"ã|gçwt  pÿ}      §
     |      \  ¤  SÁ      {&ò N¬@  Æl@  0úü0ÀRþÀ@  D  p              (|&òÁN¬ü0À(|&ò ¿N¬ 0ú        `ãÜ&j@ k@     RþÀ        ÿÿ<   Ï  \k@ j@           =<{&ò    ÿÿÿÿñ*N¬ 0úÿÿÿÿV¬kðM¬ÿÿÿÿ¸|&ò¼|&ò ¬  SÜ& |&òF  jÈM¬lÜ& Û&4Û&8°T¬¬ÿ} "fçwLÿ} ©fçwí|p§
 ¸*
  ¢/Mÿÿÿÿ ]îÿÿÿÿØO¬8þ} ¸*
   ¬      ¬ §
         Æÿ} "lçw¨ÿ} ;jçwÈb	 h   (R¨v¸*
 ¸*
 ¸*
 ´ÿ} 
lçwÐ
 ìÿ} µ¬|¸*
 h   (R¨v¸*
  àýj@ Àÿ} øÊ"&ÿÿÿÿó"’|µ¬|            ðkçw¸*
     (þ½ "ã|gçwÌ  pÿ½     Ü Lÿ½ |      S  ´  eå     \ÏD dS{Ö|!SEØJï{Yº3Ö«Û)|©        Èʹ=MRq"Êæ}´x§'¸?Î7xû°ý×óø'iÝ"¬_È"J¸ÃÛ
)O¬:|qëé/!¯ãÿ´ôÌ(t§ucÍ9³{ñfP­{K[pq×Ùº:Ï|@;Á×Ù "m~0ö>Æî$"à»Pºòòíín§æ8¨ cçàvNÙ[@,ÐÒÏûS¼!& S!ñF  jÈM¬R!& !&T!&wÆëÖ¬ÿ½ "fçwLÿ½ ©fçwí| Ø àÃ
  ¢/Mÿÿÿÿ ]îÿÿÿÿØO¬8þ½ àÃ
  ¬Lÿ½  ¬Ü         Æÿ½ "lçw¨ÿ½ ;jçwÀr     5vàÃ
 àÃ
 àÃ
 ´ÿ½ 
lçwÐ
 ìÿ½ µ¬|àÃ
     5vàÃ
  `ý æ{ Àÿ½ `]7 ÿÿÿÿó"’|µ¬|            ðkçwàÃ
     á¸V¬ã|Ùˬ|     ÿÁ ðþÁ ÐþÁ      ]îÿÿÿÿç4ã[ñÿÁ úrçw    ÿÁ  ÿÁ ÿÁ ÿÿÿÿ¬|h
 
  \ñ        P%5&¼&¬ÿÁ +rçwÿÿÿÿlÿÁ pÿÁ xÿÁ dÿÁ hÿÁ tÿÁ í|x:
 Èõ Èõ                       ÿÿÿÿ           &            ÆÿÁ ©sçw¨ÿÁ ;jçwh
 ½}©    Èõ Èõ Èõ ´ÿÁ 
lçwÐ
 ìÿÁ µ¬|Èõ ½}©    Èõ  Pý æ{ ÀÿÁ ÐwÔÿÿÿÿó"’|µ¬|            ðkçwÈõ     

                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:
75:
76:
77:
78:
79:
80:
81:
82:
83:
84:
85:
86:
87:
88:
89:
90:
91:
92:
93:
94:
95:
96:
97:
98:
99:
100:
101:
102:
103:
104:
105:
106:
107:
108:
109:
110:
111:
112:
113:
114:
115:
116:
117:
118:
119:
120:
121:
122:
123:
124:
125:
126:
127:
128:
129:
130:
131:
132:
133:
134:
135:
136:
137:
138:
139:
140:
141:
142:
143:
144:
145:
146:
147:
148:
149:
150:
151:
152:
153:
154:
155:
156:
157:
158:
159:
160:
161:
162:
163:
164:
165:
166:
167:
168:
169:
170:
171:
172:
173:
174:
175:
176:
177:
178:
179:
180:
181:
182:
183:
184:
185:
186:
187:
188:
189:
190:
191:
192:
193:
194:
195:
196:
197:
198:
199:
200:
201:
202:
203:
204:
205:
206:
207:
208:
209:
210:
211:
212:
213:
214:
215:
216:
217:
218:
219:
220:
221:
222:
223:
224:
225:
226:
227:
228:
229:
230:
231:
232:
233:
234:
235:
236:
237:
238:
239:
240:
241:
242:
243:
244:
245:
246:
247:
248:
249:
250:
251:
252:
253:
254:
255:
256:
257:
258:
259:
260:
261:
262:
263:
264:
265:
266:
267:
268:
269:
270:
271:
272:
273:
274:
275:
276:
277:
278:
279:
280:
281:

Select allOpen in new window

 

by: nobusPosted on 2009-03-10 at 09:02:56ID: 23848214

it looks not complete. can you attach it again ? do not reename it to anything else, just change the extension,.
this one seems a drWatsons file

 

by: JonveePosted on 2009-03-10 at 09:18:31ID: 23848448

From your Minidump & using WinDbg, obtained this >>
MODULE_NAME: ntdll
IMAGE_NAME:  ntdll.dll
FAILURE_BUCKET_ID:  STATUS_ACCESS_VIOLATION_c0000005_ntdll.dll!_output

Which refers to the file ntdll.dll

"What is ntdll.dll":
http://www.computerhope.com/issues/ch000960.htm

So ~conceivably~ it could still be an infection.

 

by: dankyle67Posted on 2009-03-10 at 10:26:15ID: 23849184

Hi,

i actually ran antimalware again but this time in safemode and it found 18 infections most of which were trojans.  It asked for reboot since some of the infections it could not delete until reboot.  Will run again to see if it got rid of everything.  You are probably right that the infection is causing the crashes.  I also uninstalled avg free and am going to run trial version of nod32 which i heard is good antivirus.  Do you still need me to send minidump file again or should i wait to see what happens after the 2 scans?

 

by: JonveePosted on 2009-03-10 at 10:31:40ID: 23849245

Ok, good.   Then try the infamous Kaspersky, the link's above ^    

Just about to post this suggestion .. >>>

.. a possible option (if you wish to try it) is to run Trend HijackThis 2.02:
http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html

You could download HJT to a memory stick, transfer it to the inspiron, then try to run it in Safe mode.  Even then there's no guarantee thet HijackThis will detect any possible infection(for example it doesn't necessarily see a rootkit).

Create a folder where you would like the HijackThis file to reside and run it from there, not from the Desktop or a temporary folder.
Run the scan & save the logfile.  Then click the "Attach Code Snippet" box, paste the logfile into the "Code Snippet" page and then it can be analysed.

You can rename hijackthis.exe to hijackthis.com or hijackthis.bat, in an attempt to prevent any nasties stopping your programs from running.

If you're unable to proceed much further you may want to consider the final option, a reformat.   Just in case you need this, further down the road>
 "Clean Install Windows XP":
http://www.michaelstevenstech.com/cleanxpinstall.html

 

by: JonveePosted on 2009-03-10 at 10:35:30ID: 23849282

But 18 more infections .. phew!

Hey, your best shot, try running Combofix & ignore HijackThis for the moment.
Download ComboFix and save to your Desktop >
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Before using ComboFix please disable any realtime Anti-virus, Anti-spyware, Shields, etc. that you may have running, and remember to re-enable them later, upon completion.

Before using ComboFix it may be necessary to rename it before saving it to your desktop.  If you have difficulties downloading it, try downloading to another machine, then into a USB memory stick (or equivalent).  Rename it and connect to the problematic machine.

Double click "combofix.exe" and follow the prompts.
When it's finished it will have produced a Logfile, probably at C:\ComboFix.txt.
You could post that log together with a HijackThis log, in a reply for us.
Please do not mouseclick Combofix's window while it is running, because it may stall.  It is absolutely normal for you to see a blue screen with flashing cursor, and this can last for up to 30 mins.  Just let it run.

It works well in normal mode or safe mode !

 

by: nobusPosted on 2009-03-10 at 10:38:28ID: 23849305

i have good experience wuth MBAM  :http://www.malwarebytes.org/mbam.php

 

by: JonveePosted on 2009-03-10 at 10:42:21ID: 23849336

You probably know this tutorial like the back of your hand, but just in case it's needed >
A guide and tutorial on using ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: dankyle67Posted on 2009-03-10 at 11:06:20ID: 23849516

Still wanna complete the nod32 scan and then rescan using malwarebytes again then if it comes up clean i will  run xp repair one more time and see if it works.  The other 3 times i ran repair, it still had infections so wasn't a good test.  I don't wanna have to do clean install since this person uses laptop for work and really wants to keep settings etc.  If i have to i can do a dual boot that way she can at least get her files if needed but don't know if i can do xp sp2 dual boot when original o/s is on sp3?  It should work i think as long as you don't go from xp to 2000 or something like that.  Will let you know and thanks again for all the good advice.

 

by: JonveePosted on 2009-03-10 at 11:38:53ID: 23849848

>don't wanna have to do clean install<     << no problem, i fully understand & we'll do all we can to fix this machine .. it's become a challenge now !
Basically i agree with your comments on nod32 & Malwarebytes, you can't have too many good scanners 'at the ready'.  
However, because of the apparant number of detected infections so far, ComboFix may well be the Tool for a final cleanup .. i'm also trying to save you another repair install.

 

by: JonveePosted on 2009-03-10 at 11:44:57ID: 23849901

i'm not sure at this time whether you can do an XP sp2 dual boot, when original OS is on sp3.  Instinct suggests it's preferable to concentrate on a total cleanup on an (almost) working machine.

 

by: dankyle67Posted on 2009-03-10 at 11:45:45ID: 23849910

Couldnlt run nod32 since doesn't perform install in safemode which i forgot so running trend micro housecall right now then will run the combofix as you instructed.  Also, when you mentioned about the ntdll.dll file does it make sense that if this file did get corrupted that safemode would still work or does this only affect normal mode login?

 

by: SaedSalmanPosted on 2009-03-10 at 11:51:04ID: 23849964

Nice job guys
doing very well
i am just watching and waiting the final solution ;-)

 

by: JonveePosted on 2009-03-10 at 11:54:46ID: 23850001

i would expect Housecall to find something ...

ntdll.dll file and your Safe mode enquiry?    .. short answer, i don't know  : /
... but i'll investigate further ..

@ SaedSalman .. it's good to have you with us.

 

by: JonveePosted on 2009-03-10 at 12:02:52ID: 23850066

When running Combo it really is important not to mouseclick Combofix's window,
it ~could ~ cause more trouble!
 
Incidently if after all this the issue is still unresolved, an alternative would be to remove the infected HD, connect it as 'slave' in another machine, then run ComboFix from the new machine.

 

by: dankyle67Posted on 2009-03-10 at 12:17:26ID: 23850235

Sounds lkie a good idea about running drive as slave and cleaning it with combofix from another machine.  I have actually done this before when someone really wanted to keep their data and settings intact. Hopefully we don't have to go this route.

 

by: dankyle67Posted on 2009-03-10 at 12:33:51ID: 23850405

Just to let you know, trendmicro will take antother 3 hours to complete since have big drive and of course remote scanning will take time as you know so will fill you in once its done and also, was thinking that even if trendmicro and combofix are able to completely clean the drive, since original infections probably already did damage to ntdll.dll file, will probably still have to do one more repair to get that file restored.  

 

by: JonveePosted on 2009-03-10 at 12:48:40ID: 23850550

Ok, good luck.
Agreed, maybe one more repair ... or, you may just be lucky & find that after scanning you can boot to a stable normal mode.

 

by: dankyle67Posted on 2009-03-10 at 15:05:04ID: 23852038

Hi,

after trendmicro cleaned the infected files(72 alttogether with spyware too), rebooted laptop and got into normal mode.  Updating to xp sp3 now since it prompted me to do that for security patches anyway that way it will return her system to correct service pack prior to running repair.  I will then run the nod32, reboot then run combofix, reboot then run malwarebytes then if good should be ok.  Looks like virus was the culprit since it probably affected the logon process which is why it worked in safemode.  Anyway, will let you know once i'm done and thanks so much again for all the help.  Its more satisfying to clean the system and preserve her settings then to have to resort to clean install.  But as you know i am not saying this is done till i get 3 successful reboots done and the antiviruses report 0 infections.

 

by: JonveePosted on 2009-03-10 at 15:59:34ID: 23852441

Ok, & good luck with the 3 reboots tonight.
Be interesting to see if the laptop starts creating new Restore points & whether System Restore is functioning again.   You may wish to create restore points periodically between scanning.

Hopefully SP3 will successful, and at least you should be able to remove it if there is a problem as it's ~not~ been installed using a slipstreamed CD.

 

by: dankyle67Posted on 2009-03-10 at 16:24:35ID: 23852618

Hi,
sp3 installed ok and rebooted and so far so good.  Running nod32 now and will see if that comes up clean.  I actually had turned off system restore earlier this morning after the crash since i wanted to make sure that the virus was not regenerating itself using system restore even though it wasn't working properly before anyway but will turn it on after next reboot then will see if it works and can make restore points.  Will try and get through the 3 reboots tonite then will turn it off and test few more times tomorrow before giving it back to my friend.  It was a corportate laptop so don't know how they allowed so many infections.  Its for a big well known company actually.

 

by: dankyle67Posted on 2009-03-10 at 18:31:56ID: 23853260

Just finished going through 5 reboots and looks good.  Just some minor issues still.  Turned on system restore but still couldn't create a restore point.  Then i tried running combofix but it warned that avg and nod32 realtime scanners were on so i uninstalled nod32 and don't know why avg is being detected since i ran the uninstall utility from the nod32 website and it isn't running in the services or in task manager under processes.  I decided not worth it to take a chance and run combofix since it might mess up system since i don't really need to run it coz i can already get into normal mode and infections have been cleaned with nod32 and malwarebytes.  I even tried installing avg free 8.5 again but it had problem and couldn't install so i installed avast free edition and am running now.  Will call it a day now and report tomorrow morning if everything still ok.  

 

by: SaedSalmanPosted on 2009-03-10 at 18:46:09ID: 23853323

Jonvee:
> i would expect Housecall to find something ...

He meant that you will send him a gift, So his family will inform him ?
He desired a gift, Indeed. post-up your address and I will send it my self :)

good luck dankyle67, you got closer

 

by: nobusPosted on 2009-03-11 at 00:15:35ID: 23854549

>>  Turned on system restore but still couldn't create a restore point.    <<   i suggest running  sfc /scannow from the run box

 

by: JonveePosted on 2009-03-11 at 00:27:45ID: 23854595

Thanks for the extensive report.   As far as System Restore is concerned it may well benefit from
a System Restore reinstall, as per http://windowsxp.mvps.org/repairsr.htm unless you've already tried.

i also understand how you feel about ComboFix .. it does present a *slight* risk to an o/s system, although it's worth running when a machine is quite heavily infected ..  whereas the laptop appears to be quite clean right now.

FYI here's Superantispyware, which can be considered as complimenting Malwarebytes:                        
http://www.superantispyware.com/

@ SaedSalman   ...    thanks, but what i meant by  "i would expect Housecall to find something" was >>   .....    that it would probably detect Malware and viruses, even though other scanners had actually found nothing   ; )

 

by: dankyle67Posted on 2009-03-11 at 04:35:30ID: 23855836

Hi,
just rebooted 3 times this morning and works so guess its ok.  I reinstalled system restore per your instructions but still couldn't create restore point.  Am gonna run the sfc /scannow but what is that anyway?  Thanks so much for all the help once again and glad we could solve it together.

 

by: nobusPosted on 2009-03-11 at 04:56:14ID: 23855962

 

by: gheistPosted on 2009-03-11 at 07:44:52ID: 23857845

Get into safe mode with network.
Then run autoruns obtained from www.sysinternals.com.
Now hide all the certified items from microsoft, refresh, and disable unsigned from the rest of the world.
That will let you boot.
Most likely cause is some copy=protection lowlevel driver which is not compatible with SP3

 

by: JonveePosted on 2009-03-11 at 10:10:37ID: 23859655

Reason for System Restore not functioning could conceivably be an infection in the _Restore folder although there shouldn't be anything in it because to my knowledge it was temporarily disabled.

If the problem still remains unresolved after using autoruns, maybe we'll have to consider running ComboFix after all.

 Your ref:        >glad we could solve it together<      <<--  Yep, 'Teamwork' is the word that comes to mind .. it was an intriguing period  : )

 

by: dankyle67Posted on 2009-03-11 at 10:22:28ID: 23859776

Hi,

just one more thing.  been trying to update the definitions files for malwarebytes and even the avast and all fail referencing that maybe firewall is blocking but i turned windows firewall off.  Also installed superantispyware and also fails on update.  Maybe there is still infection as you mentioned.  Wanna run combofix but my problem is it keeps warning about the avg scanner even though i uninstalled avg already.  Is there a way to find out if avg is still running in background?  I have looked at services and in processes in  task manager and not much going on.  Laptop is running fine though and at this point i won't even bother with system restore.  thanks.

 

by: JonveePosted on 2009-03-11 at 10:26:31ID: 23859825

Yes, looks like some infection still remains ..

You could run Process Explorer version 11.31 to search for AVG:
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx


Later, you could ensure that System Restore is enabled in the registry >
Scroll to sub-heading "To enable or disable System Restore .."

Go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore.
If a "DisableSR" value doesn't exist, go to the Edit menu, select New, DWORD value, and create the value.
Set the value to 0 to "enable" System Restore.

Ref:  http://www.kellys-korner-xp.com/xp_restore.htm

 

by: JonveePosted on 2009-03-11 at 10:29:58ID: 23859882

You could try running the 'Stinger' which is a utility that cleans the system of viruses, that block anti virus software.
http://vil.nai.com/vil/stinger/

Or see if HijackThis will run >
Trend HijackThis 2.02:
http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html

 

by: dankyle67Posted on 2009-03-11 at 10:49:56ID: 23860104

ok will try sysinternals to see if avg is running and will try stinger which i've used before and is good.  I checked value in registry for system restore and it exists and is 0 so this one is a real mystery.

 

by: gheistPosted on 2009-03-11 at 11:37:33ID: 23860671

You cannot check anything in normal running mode.
I suggest deinstalling all of security software in safe mode and then install some free antyspyware like Spybot S&D in networked safe mode and doing full scan and immunize while still in safe mode.
After that deinstall your avg and reinstall another AV like Antivir from free-av.com (since one failed you)

Can you post hijackthis report here for us to compare with working system (best from safe mode)?

Safe mode really is only mode when system is stable. Another way is to get some XP boot CD and do spyware scan when booted off the CD.

It is very simple API to replace normal filesystem calls with filtered ones and hide whatever spyware imaginable.

It might be useful to run specific tools for particular spyware if Spybot detects one. Ask here if it seems to be the case.

 

by: dankyle67Posted on 2009-03-11 at 11:45:13ID: 23860768

running superantispyware now in safemode.  Strange coz i was able to update files for both spyware softwares but doesn't work in regular windows mode.

 

by: gheistPosted on 2009-03-11 at 12:18:34ID: 23861156

Then it looks like way to go.

Give Spybot a try after one antispyware has cleaned - it is perfect in regard to cleaning dirt left by others like missing startup file dialogs etc.

Now update antivirus in safe mode as first effort... It may get fixed easily without changing to another.

 

by: JonveePosted on 2009-03-12 at 04:56:53ID: 23867161

Hi dankyle67  .. anything to report yet pse ?

If you do get an opportunity to run HijackThis 2.02 we'll get a better idea from it's logfile whether to run a more specialised tool, VundoFix to name but one.

 

by: dankyle67Posted on 2009-03-12 at 06:23:16ID: 23867916

Hi Jonvee,

Just to update you, i was able to run malwarebytes and superanntispware along with avast antivirus and all came up clean in safemode.  I still have problem in that i can  only do the updates of definition files in safemode but in normal mode it keeps saying the firewall is blocking.  Ran the sysinternals process module and doesn't show any firewall.  Doesn't make sense.  Any thoughts?  I will still run the hijack this and post it just in case but aftere running all 3 scans and nothing detected, should be ok right?  I think there is just somethin blocking the update process and my other idea is to disable startup items and see if it will allow update in diagnostic mode.

 

by: dankyle67Posted on 2009-03-12 at 06:33:31ID: 23868020

Ok here is output of hijack this which i ran in safemode.  Let me know if you find anything, thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:19 AM, on 3/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support
 
Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\experts\HiJackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS2\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS2\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS2\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS2\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS2\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [batuhomete] Rundll32.exe "C:\WINDOWS2\system32\hujobehe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [batuhomete] Rundll32.exe "C:\WINDOWS2\system32\hujobehe.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: VPN Client.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS2\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS2\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS2\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Client32 - NetSupport Ltd - C:\PROGRA~1\CrossTec\CROSST~1\client32.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS2\system32\HPZipm12.exe
 
--
End of file - 6460 bytes
                                              
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
47:
48:
49:
50:
51:
52:
53:
54:
55:
56:
57:
58:
59:
60:
61:
62:
63:
64:
65:
66:
67:
68:
69:
70:
71:
72:
73:
74:

Select allOpen in new window

 

by: JonveePosted on 2009-03-12 at 07:00:18ID: 23868320


Thanks for update .. yes, detecting nothing after running all 3 scans should be ok, but i'll take a close look at HJT log & report back later.

For your Startup items presume you're using MSCONFIG .. but if you prefer, take a look at this method ... of running the command "services.msc" (no quotes)>
http://www.blackviper.com/WinXP/service411.htm

Still contemplating why you're getting "the firewall is blocking" messages.

 

by: JonveePosted on 2009-03-12 at 07:09:44ID: 23868445

From your HijackThis log these two entries appear to be the problem!  
You'll find that the hujobehe.dll file is not recognised.  
Assuming you do not recognise them either, *both* should be Fixed although they may well regenerate >>

O4 - HKUS\S-1-5-19\..\Run: [batuhomete] Rundll32.exe "C:\WINDOWS2\system32\hujobehe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [batuhomete] Rundll32.exe "C:\WINDOWS2\system32\hujobehe.dll",s (User 'NETWORK SERVICE')

 

by: JonveePosted on 2009-03-12 at 07:21:02ID: 23868597

Yes you certainly need to get rid of those two O4 - HKUS entries  .. they seem to be Trojan or Trojan related files,can't identify closer than that.

If HJT doesn't permanently remove them, Combo quite probably will, *if* you can run it in Safe mode(after renaming Combo as explained earlier).

 

by: JonveePosted on 2009-03-12 at 07:30:19ID: 23868726

You can also Fix these three with HJT, their files are missing anyway>

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

Then the last entry which HJT describes as 'possibly nasty'.
<quote> according to our database this process runs normally in c:\windows\! Check if you know this process and arrange a viruscheck where required<unquote>

C:\WINDOWS2\Explorer.EXE

 

by: dankyle67Posted on 2009-03-12 at 07:43:38ID: 23868885

Ok sounds good.  I actually reran avast since i forgot i hadn't updated it since i had only done the other 2 in safemode but forgot avast and when i updated then ran again in safemode it found 4 trojans so far in restore folder which would make sense why system restore not working.  It is 64% done but i hope it will fix those other ones you mentioned as well.  Then i will run hijack this to try and get rid of them.  I didn't know hijack this could clean files, i thought it only prints logfile.  Good to know.  Will let you know when i finish up.

 

by: JonveePosted on 2009-03-12 at 07:59:12ID: 23869082


You're doing ok ... but it's a bit uncanny, reading your update is like hearing my own future thoughts reflected back!

But yes, that's why the Restore isn't functioning ... after removing those Trojans we may find the _Restore folder is corrupted .. then maybe you'd want to try that SR repair procedure again to put it right.

Confirming also that HijackThis will clean/remove files .. but not all, it usually becomes a bit unstuck when faced with a rootkit, so over to "Rootkit Reveiller" or equivalent to resolve it.

Logging off now for an hour or so .. will drop by later

 

by: gheistPosted on 2009-03-12 at 08:13:51ID: 23869283

You have two antiviruses - AVG and avast. Deinstall both in safemode and install one. This sinister combination definetly causes problems (make sure to use "autoruns" mentioned earlier to remove their trails).
Also remove both suspect components spotted by Jonvee - google says they are very bad.
Let me suggest uninstalling all the anti-spyware (it failed you, Sir!!!!) and go with Spybot S&D or adaware

 

by: dankyle67Posted on 2009-03-12 at 08:26:14ID: 23869469

Ok hear back from you later.  For now, what i did was deleted the 3 items found by avast then i removed all the items you listed in hijack this and rebooted.  System restore works now so those infections did in fact affect system restore since that's the folder they resided in.  Makes sense since virus doesn't want you to be able to use system restore to bring back good instance.  Now i still have to deal with the updating of definitions files since that still references firewall.  I will also run stinger and then finally combofix.  I also had already used the services.msc command other day to see what services were running that could possibly relate to firewall as well as avg since combofix still warns a bout avg scanner.  I even went through entire registry yesterday for any avg references and found a lot so deleted them and still gets identified by combofix.  Do you think it is ok to go ahead and run it despite the warning since avg is not really running?  Anyway i can use system restore now if it does something adverse to my system(ha ha).

 

by: dankyle67Posted on 2009-03-12 at 08:30:21ID: 23869533

One other thing i noticed jus now.  All this time i have been using firefox for all the internet stuff and so i tried bringing up internet explorer and it doesn't work.  Wondering if the updates are set to use internet explorere in normal mode and in safe mode it uses firefox which is why it works in one and not the other.  Wiill test it and let you know.

 

by: dankyle67Posted on 2009-03-12 at 08:37:35ID: 23869641

Hi again,  also just noticed that when i was trying to download stinger from a few different sites like cnet for instance, i would get redirected to another page so most likely have a hijacker infection correct?  I did not get rid of that last line item relating to internet exploer so will do that and will double check the hijack this again and will post again for you  to look at.  thanks.

 

by: gheistPosted on 2009-03-12 at 08:42:58ID: 23869719

Since it boots into normal mode I consider it somewhat fixed.
Can you post that firewall error you got - screenshot, or copy/paste from event log?
Does this firewall error appear in Networked Safemode?

 

by: gheistPosted on 2009-03-12 at 08:47:07ID: 23869781

It might be your superantispyware that poses as network firewall too - check security center...

 

by: JonveePosted on 2009-03-12 at 09:12:31ID: 23870119

You've probably started the Combo scan by now?  Just a thought, if those User documents are really valuable, we could consider removing the Harddisk & connecting as slave in a working computer .. take off the docs and THEN do a ComboFix scan in the same "working" machine .. but that's probably acedemic by now?

>internet explorer and it doesn't work<        << could be we'll need to run this script ~later~  to fix your connection.
It will reinstall winsock, the TCP/IP stack, and the HOSTS file.
http://downloads.subratam.org/WinsockFix.zip

>redirected to another page so most likely have a hijacker infection correct? <   Yes.

Incidently gheist is correct when he says two antiviruses make a sinister combination that causes problems.

 

by: nobusPosted on 2009-03-12 at 10:33:35ID: 23871184

with so many problems - i would just do a fresh install, after a backup.
then you're sure your system is ok, and it runs fast....

 

by: dankyle67Posted on 2009-03-12 at 12:01:53ID: 23872207

Hi,

away from the laptop right now and am using someone else's pc but will update you guys in about an hour when i get back.  We fixed all the problems so far except this inabllity to update in normal mode so definately don't wanna do a clean install since i would have done that long ago as it is easiest method but in this case, had to keep user data and settings intact so am glad it works this well.  I never had 2 antiviruses only avast since avg i had removed few days ago with avg uninstall utility from nod32 site.  Problem is it keeps getting recognized by combofix even though it is not running.  The system restore was still ok as well so just need to get the firewall issue fixed if indeed it is a correct message.  Stinger was running when i left so will be done when i get back and will let you know what it detects.  I actually downloaded it originally from cnet site but it was 2 years outdated so got latest and greatest now.  

 

by: gheistPosted on 2009-03-12 at 12:06:10ID: 23872253

AVG is product of grisoft, not nod32, so your uninstall was done wrong. You can install latest AVG from grisoft and uninstall it to clear all the trails of it.

Post the firewall error message exactly so we can sort it out.

 

by: dankyle67Posted on 2009-03-12 at 12:42:01ID: 23872652

I know avg is made by grisoft but if you look at nod32 site they are one of the few if any antivirus vendors that have all of the other antivirus uninstallers for you to use such as norton,macafee,sophos,avg etc.  I used this and then i also had installed avg couple of days ago the free version and used their uninstall as well and still it shows up on comboxfix warning after i even deleted all instances of it on the registry.  The stinger scan came up clean.  The firewall message when attempting to update the definitions files for avast, malwarebytes or superantispyware is:  "There was an error trying to retrieve the definitions.  Make sure your firewall is not blocking Superantispyware.exe from accessing the internet.  Just in case you might ask, the error reads the same for the other 2 except instead of  "Superantispyware" it reads "Malwarebytes" and "Avast" as well.  So question is why would this work in safemode and not in normal mode? I have also run spybot and adaware se and both came up clean in safemode.

 

by: gheistPosted on 2009-03-12 at 12:45:20ID: 23872683

Can you post screenshot of security center with all the software groups expanded?
Maybe remains of some ages old remains of some defunct firewall...
Windows firewall should suffice unless you are deep in warez usage.

 

by: JonveePosted on 2009-03-12 at 13:01:25ID: 23872841

"There was an error trying to retrieve the definitions. Make sure your firewall is not blocking Superantispyware.exe from accessing the internet"

You should be able to remove this error by running FixIEDef.exe

*These instructions are available thanks to rpggamergirl *

<quote>
Download FixIEDef by ShadowPuterDude to the Desktop.
http://downloads.malwareteks.com/FixIEDef.exe

Disable real-time protection that can interfer with FixIEDef:

*Disable Windows Defender until the computer is clean
Open Windows Defender
Select Tools and then General Settings
Under Real Time Protection Options uncheck Turn on real-time protection
Select Save
Don't forget to re-enable it, when your computer is clean.

*Disable SUPERAntiSpyware until the computer is clean
Right-click on the shortcut from the system tray
Choose View Control Center (preferences/options)
On the General and Startup tab, uncheck Start SUPERAntispyware when Windows starts.
Click Close to exit.
Don't forget to re-enable it, when your computer is clean.

*Disable Teatimer
First:
Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
Choose Exit Spybot S&D Resident
Second:
Open Spybot S&D
Click Mode, check Advanced Mode
Go To Left Panel, Click Tools, then also in left panel, click Resident
If your firewall raises a question, say OK
Uncheck the box labeled Resident Tea-Timer and OK any prompts.
Use File, Exit to terminate Spybot
Reboot your machine for the changes to take effect.
Don't forget to re-enable it, when your computer is clean.

Double-click FixIEDef
Click 'OK'
Click 'Scan'
Click 'OK' FixIEDef requires Adminstrator Privileges to run correctly. This box tells you that FixIEDef successfully elevated it's privileges to that of Administrator.

Wait for the scan to finish. It won't take very long.

WARNING: FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.

Everything will be restored to normal, once the malicious file is removed.

Click 'Exit' once FixIEDef displays the All Finished message.
<unquote>

 

by: JonveePosted on 2009-03-12 at 13:08:19ID: 23872900

As FixIEDef will kill all copies of Internet Explorer(which in your case is not functioning anyway)during it's operation, it will be interesting to see if IE is working ok when everything is restored to normal by FixIEDef.  You may not need the WinsockFix.

 

by: dankyle67Posted on 2009-03-12 at 13:15:22ID: 23872973

Hi,

i atually figured it out about 15min ago and it is related to admin.  All the time in safemode i am logged in as admin and updates worked.  Then in normal mode i am logged in as the person who i am fixing this for who has admin rights but it fails.  I then logged into safemode but as that same person in normal mode and it failed in safemode so i then switched users to admin and it worked.  I reinstalled 2 of the apps as that user in normal mode and the updates worked.  The FixIED would have worked but it is more work but based on same principle of admin rights as the cuplprit nothing to do with any firewalls which is why i mentioned in one of my prior posts that i i don't think it is firewall but a false message and something else.  Now i will just try and fix Internet explorer from your instructions and should be fully operational.  It was rewarding to finally find out what was causing the firewall error.  Thanks again for all the help and sorry i didn't tell you earlier and would have saved you all the verbage on the FixIED instructions.  

 

by: JonveePosted on 2009-03-12 at 13:28:05ID: 23873135

No problem .. anyway we all now have an excellent piece of FixIEDef
instruction, thanks to rpggamergirl.

As there's no Combo logfile, i'm not absolutely sure you ran it or not.  If you did, it would be wise to remove it when you're *absolutely sure* you've finished with it.

Uninstall ComboFix as follows >
Start > Run > then type "ComboFix /u" (with no quotes, and space between x and / )
Then hit enter.  This will uninstall ComboFix, reset your clock settings, re-hide system hidden files, re-hide the file extensions and reset System Restore.

 

by: gheistPosted on 2009-03-12 at 13:42:20ID: 23873271

Run spybot as admin to clean other profile. That is impossible if backdoor is active in current profile.
I have heard that bootvis out of softpedia fixes general slowness after change of antivirus...

 

by: dankyle67Posted on 2009-03-12 at 14:29:30ID: 23873798

I already ran spybot as admin but right now the laptop is running quite fast actually and updates are all working so only thing i have left to fix is internet explorer.  

 

by: JonveePosted on 2009-03-12 at 14:39:10ID: 23873927

For extra help on the IE repair this is a good site>
http://windowsxp.mvps.org/winsock.htm

If unsuccessful it could conceivably be router or externel DNS problem.
Try the google.com IP >>    http://64.233.187.99  
If you can access this IP ok, then it's likely to be a DNS issue.
Therefore try running ipconfig /flushdns to remove your cached DNS values.

 

by: gheistPosted on 2009-03-13 at 00:08:19ID: 23876696

For IE
use internet options as particular user and reset to defaults everywhere.
if no luck still:  use same autoruns, and use it to remove/disable IE extensions, then uninstall and reinstall legit ones - flash and java and silverlight at least.

If it does not work after all those attempts - you can remove user profile (save a copy in .zip before to get some documents)

What is your IE version btw?

 

by: dankyle67Posted on 2009-03-13 at 06:07:38ID: 23878744

Hi,
solved the ie problem finally.  It had to do with the user profile which was corriupted so i simply created a new one after deleting the other one and in fact there were 2 other user profiles on the machine that i never even tested and they both worked fine for internet explorer as did the new user and so that was the real cause of the updating issue because none of the apps updaters could get out to the internet using that corrupted user profille which is why admin always worked but i could never test admin in normal mode coz in xp it only allows admin in safemode or if there are no other users except guest account.  I've since then run several scans again with spybot and malwarebytes and avast and all reported clean.  I made sure to also run a manual restore point which went fine.  Thanks again guys for all the informative and intelligent advice.  Is there a way i can award additonal points since i had already divided it previously since i have never done it before?  Would really like to give more if possible.

 

by: gheistPosted on 2009-03-13 at 07:04:30ID: 23879289

You cannot give more than 500 per problem.

 

by: gheistPosted on 2009-03-13 at 07:05:45ID: 23879303

Just read through all the comments and award unique useful directions.

 

by: JonveePosted on 2009-03-13 at 14:23:48ID: 23883692

Glad to hear you've finally resolved all problems!

You asked about closing the question>
http://www.experts-exchange.com/help.jsp

If you click "Asking Questions"then click "How do i close a question".

Several sub-headings here including "Accept multiple solutions", the choice is yours ...

If you have difficulties and accept the wrong solution, just click the Request Attention button, and ask the Moderators to change the grade for you.

 

by: JonveePosted on 2009-03-19 at 00:21:11ID: 23927030


Hi dankyle67,
Is the BSOD problem still resolved or has there been a recurrance ?  

~If~  you are satisfied with the result and require no further assistance, we would be grateful if this thread could now be completed.    
Thanks.

 

by: dankyle67Posted on 2009-03-19 at 04:19:45ID: 23928253

Hi Jonvee,

yes problem is resolved and my friend said laptop works great now.  Ok to close thread.  Do i have to do anything else on my side or is that sufficient?  thanks again for all the help.

 

by: gheistPosted on 2009-03-19 at 04:35:24ID: 23928343

500 divides by 2 or by 5 - walk through the thread and award 2 or 5 most useful ideas as answers.

 

by: nobusPosted on 2009-03-19 at 05:09:53ID: 23928538

 

by: JonveePosted on 2009-03-19 at 06:28:32ID: 23929198

If you wish to split the points, here's another way of describing how to do it, and close a thread.  Each comment box has a button that says Accept Multiple Solutions.
Click it, and you will see a page that allows you to assign points to *any* of the comments in the thread.   There is also a "grade" box at the bottom of the page.

Also note that the total number of points of the "split points" must equal the amount you asked in the question, which in your case was 500.  Also, no comment can receive fewer than 20 points.

The 1st comment selected, of those that were posted first, is given the title "Accepted Solution", and any other(s) selected, automatically get the "Assisted Solutions" award.
Sounds a bit complicated  perhaps, but it appears to work well.

Hope that helps & thanks for your time.

 

by: dankyle67Posted on 2009-03-20 at 06:50:27ID: 23939257

Ok, split points as you instructed.  Hope it is correct.  Just let me know if it is ok and closed now, thanks.

 

by: JonveePosted on 2009-03-20 at 14:08:32ID: 23943981

Yes, the question is now closed, and all is ok.   Glad you were finally able to fix the laptop.  Thanks.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...