No start bar or desktop icons [Solved] |
![]() ![]() |
No start bar or desktop icons [Solved] |
Jun 27 2009, 06:34 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Hello,
Upon turning on my computer recently, my wallpaper loaded up but I had no start bar or icons on the desktop. The only operation I can perform is to press ctrl,alt,del and bring up the task manager and from here browse files via the 'run new task' option. We tried reboots and restore points and ran antivirus, hijackthis etc before i was advised to visit this site. I have followed the instructions in the cleaning guide thread, by downloading the tools from my partners computer and transferring by usb, as i can't connect to the internet on my computer. Here are the results... MBAM Malwarebytes' Anti-Malware 1.38 Database version: 2297 Windows 5.1.2600 Service Pack 3 27/06/2009 9:56:34 PM mbam-log-2009-06-27 (21-56-34).txt Scan type: Quick Scan Objects scanned: 86802 Time elapsed: 6 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{386a771c-e96a-421f-8ba7-32f1b706892f} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c559105-9ecf-42b8-b3f7-832e75edd959} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\Microsoft Common (Trojan.Agent) -> Quarantined and deleted successfully. Rooter Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows XP Home Edition (5.1.2600) Service Pack 3 [32_bits] - x86 Family 15 Model 2 Stepping 9, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) . Internet Explorer 8.0.6001.18702 . A:\ [Removable] C:\ [Fixed-NTFS] .. ( Total:37 Go - Free:10 Go ) D:\ [CD_Rom] E:\ [CD_Rom] F:\ [CD_Rom] H:\ [Removable] . Scan : 22:01.31 Path : H:\Rooter.exe User : Vaughan Moutrie ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (644) ______ \??\C:\WINDOWS\system32\csrss.exe (932) ______ \??\C:\WINDOWS\system32\winlogon.exe (1096) ______ C:\WINDOWS\system32\services.exe (1252) ______ C:\WINDOWS\system32\lsass.exe (1312) ______ C:\WINDOWS\system32\svchost.exe (1952) ______ C:\WINDOWS\system32\svchost.exe (324) ______ C:\WINDOWS\System32\svchost.exe (620) ______ C:\WINDOWS\system32\svchost.exe (784) ______ C:\WINDOWS\System32\svchost.exe (1420) ______ C:\WINDOWS\System32\svchost.exe (1608) ______ C:\WINDOWS\system32\spoolsv.exe (96) ______ C:\WINDOWS\System32\svchost.exe (372) ______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (564) ______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (664) ______ C:\WINDOWS\System32\svchost.exe (900) ______ C:\Program Files\Java\jre6\bin\jqs.exe (1076) ______ C:\WINDOWS\System32\svchost.exe (1588) ______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (184) ______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (436) ______ C:\Program Files\Windows Media Player\WMPNetwk.exe (1376) ______ C:\WINDOWS\System32\alg.exe (1756) ______ C:\WINDOWS\system32\wscntfy.exe (160) ______ C:\WINDOWS\system32\wbem\wmiprvse.exe (2672) ______ C:\WINDOWS\system32\wuauclt.exe (3672) ______ C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (1728) ______ C:\WINDOWS\system32\taskmgr.exe (2484) ______ H:\Rooter.exe (3080) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:40007729664) . ----------------------\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1097200139.job C:\WINDOWS\Tasks\SA.DAT . ----------------------\\ Registry . . ----------------------\\ Files & Folders . C:\DOCUME~1\VAUGHA~1\My Documents\Unzipped\Macromedia Studio MX - (ColdFusion MX, Dreamweaver MX, Fireworks MX, Flash MX, Fireworks 10) - Trade Only\Flash MX\keygen.exe ==> Cracks & Keygens <== . ----------------------\\ Scan completed at 22:01.58 . C:\Rooter$\Rooter_3.txt - (27/06/2009 | 22:01.58).c OTL OTL logfile created on: 27/06/2009 10:03:39 PM - Run 2 OTL by OldTimer - Version 3.0.5.3 Folder = H:\ Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 503.48 Mb Total Physical Memory | 206.17 Mb Available Physical Memory | 40.95% Memory free 1.20 Gb Paging File | 0.97 Gb Available in Paging File | 80.67% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.26 Gb Total Space | 10.15 Gb Free Space | 27.25% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS G: Drive not present or media not loaded Drive H: | 971.51 Mb Total Space | 92.13 Mb Free Space | 9.48% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: AUSTIN Current User Name: Vaughan Moutrie Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Processes (SafeList) ========== PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.) PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.) PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.) PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation) PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation) PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation) PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation) PRC - H:\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.) SRV - (CaCCProvSP [On_Demand | Stopped]) -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.) SRV - (CAISafe [Auto | Running]) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.) SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation) SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation) SRV - (iPodService [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.) SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.) SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation) SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\HPZipm12.exe (HP) SRV - (VETMSGNT [Auto | Running]) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.) SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation) SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (AFS2K [System | Running]) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.) DRV - (ALCXSENS [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ALCXSENS.SYS (Sensaura Ltd) DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.) DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation) DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation) DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP) DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP) DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP) DRV - (hwdatacard [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation) DRV - (IdeBusDr [Boot | Stopped]) -- C:\WINDOWS\System32\DRIVERS\IdeBusDr.sys (Intel Corporation) DRV - (IdeChnDr [Boot | Stopped]) -- C:\WINDOWS\System32\DRIVERS\IdeChnDr.sys (Intel Corporation) DRV - (LwAdiHid [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LwAdiHid.sys (Logitech Inc.) DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\msmpu401.sys (Microsoft Corporation) DRV - (Pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software) DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.) DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.) DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions) DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (tmod [System | Stopped]) -- C:\WINDOWS\System32\tmod.sys () DRV - (TVICHW32 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS (EnTech Taiwan) DRV - (VET-FILT [System | Running]) -- C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.) DRV - (VET-REC [System | Running]) -- C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.) DRV - (VETEBOOT [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.) DRV - (VETEFILE [System | Running]) -- C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.) DRV - (VETFDDNT [System | Running]) -- C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.) DRV - (VETMONNT [System | Running]) -- C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.) DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation) DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://au.search.yahoo.com [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com/?fr=fp-yie8 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://home.microsoft.com/access/allinone.asp IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/?fr=fp-yie8 IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local> FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/11 09:15:32 | 00,000,000 | ---D | M] O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc) O3 - HKLM\..\Toolbar: (Yahoo!7 Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll () O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.) O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.) O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe File not found O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe File not found O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Computer, Inc.) O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh) O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation) O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.) O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.) O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG) O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] .Trashes [2007/09/24 12:23:12 | 00,000,000 | -H-D | M] O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UDisk Assistant.lnk = C:\Program Files\UDisk utility 1.00.12\UDisk.exe () O4 - Startup: C:\Documents and Settings\Vaughan Moutrie\Start Menu\Programs\Startup\Shortcut to autodown.exe.lnk = C:\Program Files\CA\eTrust Vet Antivirus\autodown.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0 O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.) O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone. O15 - HKCU\..Trusted Domains: ([]msn in My Computer) O15 - HKCU\..Trusted Domains: 103 domain(s) and sub-domain(s) not assigned to a zone. O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} http://housecall-beta.trendmicro.com/housecall/xscan60.cab (HouseCall Control) O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (MessengerStatsClient Class) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab (Minesweeper Flags Class) O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} http://www.cult3d.com/download/cult.cab (Cult3D ActiveX Player) O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://vorn86.spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool) O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control) O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control) O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} http://instantsupport.asiapac.hp.com/awebu...SWebManager.CAB (Hewlett-Packard Printer Diagnostics) O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} http://a1540.g.akamai.net/7/1540/52/200404...meInstaller.exe (Reg Error: Key error.) O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://vorn86.spaces.live.com/PhotoUpload/MsnPUpld.cab (Windows Live Photo Upload Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (MessengerStatsClient Class) O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.) O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8044.7952546296 (Reg Error: Key error.) O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} http://fdl.msn.com/zone/datafiles/heartbeat.cab (HeartbeatCtl Class) O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab (ZoneIntro Class) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object) O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control) O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class) O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab (Solitaire Showdown Class) O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class) O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.) O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\ipp - No CLSID value found O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\tmodkm: DllName - tmodkm.dll - .Trashes [2007/09/24 12:23:12 | 00,000,000 | -H-D | M] O24 - Desktop Components:0 (My Current Home Page) - About:Home O27 - HKLM IFEO\explorer.exe: Debugger - C:\Program Files\Microsoft Common\svchost.exe File not found O29 - HKLM SecurityProviders - (zwebauth.dll) - C:\WINDOWS\System32\zwebauth.dll () O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004/02/28 12:49:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2006/05/12 08:13:39 | 00,000,279 | R--- | M] () - F:\autorun.inf -- [ CDFS ] O32 - Unable to obtain root file information for disk H:\ O33 - MountPoints2\{ad62a951-43ec-11dd-aa99-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{ad62a951-43ec-11dd-aa99-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{ec74dd5f-da55-11db-b20a-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{ec74dd5f-da55-11db-b20a-000d6135b3f1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- [2006/04/19 08:33:36 | 00,950,272 | R--- | M] () O33 - MountPoints2\{f6d558fa-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f6d558fa-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\{f6d558fd-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f6d558fd-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - File not found ========== Files/Folders - Created Within 30 Days ========== [2028/02/28 23:35:26 | 00,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\splitter.sys [2028/02/28 23:35:25 | 00,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aec.sys [2028/02/28 23:35:24 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmkaud.sys [2028/02/28 23:35:23 | 00,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\swmidi.sys [2028/02/28 23:35:22 | 00,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dmusic.sys [2028/02/28 23:35:20 | 00,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wdmaud.sys [2028/02/28 23:35:17 | 00,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kmixer.sys [2028/02/28 23:35:14 | 00,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sysaudio.sys [2028/02/28 23:35:11 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\audstub.sys [2028/02/28 23:34:52 | 00,057,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\redbook.sys [2028/02/28 23:34:35 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msmpu401.sys [2028/02/28 23:34:33 | 00,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gameenum.sys [2028/02/28 23:34:16 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\intelide.sys [2028/02/28 23:33:17 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC [2028/02/28 23:33:15 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd [2028/02/28 23:33:15 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcommon.dll [2028/02/28 23:33:15 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcplui.dll [2028/02/28 23:33:15 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf [2028/02/28 23:33:14 | 00,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spttseng.dll [2028/02/28 23:33:14 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa [2028/02/28 23:33:14 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa [2028/02/28 23:33:14 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapisvr.exe [2028/02/28 23:33:14 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines [2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared [2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files [2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files [2028/02/28 23:33:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls [2028/02/28 23:33:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls [2028/02/28 23:33:11 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls [2028/02/28 23:33:11 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls [2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls [2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls [2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls [2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls [2028/02/28 23:33:11 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll [2028/02/28 23:33:11 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll [2028/02/28 23:33:11 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuq.dll [2028/02/28 23:33:11 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuf.dll [2028/02/28 23:33:11 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll [2028/02/28 23:33:11 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdazel.dll [2028/02/28 23:33:10 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll [2028/02/28 23:33:10 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkyr.dll [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls [2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll [2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycc.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbduzb.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdur.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtat.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru1.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdmon.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkaz.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdbu.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdblr.dll [2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdaze.dll [2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls [2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls [2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls [2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS [2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls [2028/02/28 23:33:07 | 00,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll [2028/02/28 23:33:07 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhept.dll [2028/02/28 23:33:07 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll [2028/02/28 23:33:07 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela3.dll [2028/02/28 23:33:07 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll [2028/02/28 23:33:07 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll [2028/02/28 23:33:07 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela2.dll [2028/02/28 23:33:07 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgkl.dll [2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll [2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll [2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll [2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe319.dll [2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe220.dll [2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe.dll [2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls [2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls [2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls [2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls [2028/02/28 23:33:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls [2028/02/28 23:33:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS [2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll [2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll [2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll [2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv1.dll [2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv.dll [2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdest.dll [2028/02/28 23:33:06 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll [2028/02/28 23:33:06 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll [2028/02/28 23:33:06 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt1.dll [2028/02/28 23:33:06 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt.dll [2028/02/28 23:33:04 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls [2028/02/28 23:33:04 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls [2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls [2028/02/28 23:33:04 | 00,007,168 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz.dll [2028/02/28 23:33:04 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz2.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz1.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll [2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycl.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl1.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz2.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz1.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcr.dll [2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdal.dll [2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll [2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll [2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll [2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdro.dll [2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl1.dll [2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu1.dll [2028/02/28 23:33:02 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls [2028/02/28 23:33:02 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll [2028/02/28 23:33:02 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll [2028/02/28 23:33:02 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irenum.sys [2028/02/28 23:33:01 | 00,126,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL [2028/02/28 23:33:01 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL [2028/02/28 23:33:01 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL [2028/02/28 23:33:01 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL [2028/02/28 23:33:01 | 00,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV [2028/02/28 23:33:01 | 00,009,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL [2028/02/28 23:33:01 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL [2028/02/28 23:33:01 | 00,004,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV [2028/02/28 23:33:01 | 00,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV [2028/02/28 23:33:01 | 00,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV [2028/02/28 23:33:01 | 00,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV [2028/02/28 23:33:00 | 00,109,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL [2028/02/28 23:33:00 | 00,073,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV [2028/02/28 23:33:00 | 00,069,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL [2028/02/28 23:33:00 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe [2028/02/28 23:33:00 | 00,068,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\mmsystem.dll [2028/02/28 23:33:00 | 00,032,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL [2028/02/28 23:33:00 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV [2028/02/28 23:33:00 | 00,025,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV [2028/02/28 23:33:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE [2028/02/28 23:33:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\taskman.exe [2028/02/28 23:33:00 | 00,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL [2028/02/28 23:33:00 | 00,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV [2028/02/28 23:33:00 | 00,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV [2028/02/28 23:33:00 | 00,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK [2028/02/28 23:32:59 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\winspool.drv [2028/02/28 23:32:59 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll [2028/02/28 23:32:59 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll [2028/02/28 23:32:59 | 00,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT [2028/02/28 23:32:50 | 00,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT [2028/02/28 23:32:50 | 00,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT [2028/02/28 23:32:50 | 00,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT [2028/02/28 23:32:50 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT [2028/02/28 23:32:49 | 00,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT [2028/02/28 23:32:49 | 00,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT [2028/02/28 23:32:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2 [2028/02/28 23:32:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot [2028/02/28 23:32:32 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft [2028/02/28 23:31:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings [2028/02/28 23:31:50 | 00,138,056 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2028/02/28 23:31:09 | 00,000,211 | RHS- | C] () -- C:\boot.ini [2028/02/28 23:31:06 | 00,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf [2028/02/28 23:27:39 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts [2028/02/28 23:27:39 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache [2028/02/28 23:27:39 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web [2028/02/28 23:27:39 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32 [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\system [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\security [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\java [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins [2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS [2009/06/27 21:58:54 | 00,000,000 | ---D | C] -- C:\Avenger [2009/06/27 21:47:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vaughan Moutrie\Application Data\Malwarebytes [2009/06/27 21:47:42 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/27 21:47:39 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/06/27 21:47:35 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/06/27 21:47:35 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/06/27 21:47:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009/06/27 21:46:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/06/27 21:45:23 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\NTREGOPT.lnk [2009/06/27 21:45:23 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\ERUNT.lnk [2009/06/27 21:45:22 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/06/27 20:58:22 | 00,000,000 | ---D | C] -- C:\Rooter$ [2009/04/21 21:27:17 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini [2009/03/09 14:29:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\tmod.sys [2008/11/05 11:29:13 | 00,000,140 | ---- | C] () -- C:\WINDOWS\NSFASTKY.INI [2008/11/05 10:53:30 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\W32mkrc.dll [2008/11/05 10:53:27 | 00,054,272 | ---- | C] () -- C:\WINDOWS\System32\P2IRDAO.DLL [2008/11/05 10:53:26 | 00,050,176 | ---- | C] () -- C:\WINDOWS\System32\CTDAO.DLL [2008/11/05 10:53:25 | 00,036,352 | ---- | C] () -- C:\WINDOWS\System32\P2BBND.DLL [2008/11/05 10:53:24 | 00,748,160 | ---- | C] () -- C:\WINDOWS\System32\CO2C40EN.DLL [2008/11/05 10:53:24 | 00,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\IMPLODE.DLL [2008/11/05 10:53:16 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\OC25JPN.DLL [2008/11/05 10:53:16 | 00,014,256 | ---- | C] () -- C:\WINDOWS\System32\VAJP2.DLL [2008/11/05 10:53:12 | 00,001,736 | ---- | C] () -- C:\WINDOWS\NSFASTW.INI [2007/04/12 11:08:52 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini [2007/04/12 11:08:36 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll [2007/01/24 10:06:35 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini [2006/06/07 08:56:04 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hpqemlsz.INI [2005/04/04 11:08:49 | 00,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI [2005/03/08 17:39:07 | 00,000,156 | ---- | C] () -- C:\WINDOWS\GetServer.ini [2005/02/17 02:12:54 | 00,025,157 | ---- | C] () -- C:\WINDOWS\RMAgentOutput.dll [2005/02/17 02:12:00 | 00,126,976 | ---- | C] () -- C:\WINDOWS\dllTSCLIBMT.dll [2005/02/01 20:43:10 | 00,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI [2004/11/10 10:37:44 | 00,000,115 | ---- | C] () -- C:\WINDOWS\WININIT.INI [2004/10/31 17:21:16 | 00,000,125 | ---- | C] () -- C:\WINDOWS\cdplayer.ini [2004/10/01 16:33:46 | 00,000,679 | ---- | C] () -- C:\WINDOWS\TSC.ini [2004/07/23 21:30:43 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\tvqenc.dll [2004/07/23 21:30:41 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll [2004/07/18 16:36:41 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI [2004/07/01 09:23:29 | 00,016,973 | ---- | C] () -- C:\WINDOWS\System32\ZWebAuth.dll [2004/06/30 16:48:05 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll [2004/06/29 16:59:27 | 00,108,992 | ---- | C] () -- C:\WINDOWS\System32\SH34W32.DLL [2004/06/29 16:59:27 | 00,075,264 | ---- | C] () -- C:\WINDOWS\System32\IFORCE2.dll [2004/04/03 16:04:32 | 00,000,562 | ---- | C] () -- C:\WINDOWS\SIERRA.INI [2004/03/30 09:16:59 | 00,000,225 | ---- | C] () -- C:\WINDOWS\QTW.INI [2004/02/29 09:00:00 | 00,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini [2004/02/28 18:45:55 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2004/02/28 15:31:04 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll [2004/02/28 14:41:34 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini [2004/02/28 13:28:57 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll [2004/02/28 13:01:17 | 00,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll [2003/03/31 22:00:00 | 00,000,763 | ---- | C] () -- C:\WINDOWS\win.ini [2003/03/31 22:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI [2002/11/27 21:30:32 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll [2002/11/01 15:17:50 | 00,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini [2002/07/04 14:05:34 | 00,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini [2001/12/14 12:34:46 | 00,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll [1999/07/23 12:46:48 | 00,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini [1999/07/23 09:53:20 | 00,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll ========== Files - Modified Within 30 Days ========== [2028/02/28 23:33:14 | 00,000,231 | ---- | M] () -- C:\WINDOWS\System.vet [2009/06/27 21:59:48 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/06/27 21:59:25 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT [2009/06/27 21:59:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/06/27 21:47:42 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/27 21:45:23 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\NTREGOPT.lnk [2009/06/27 21:45:23 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\ERUNT.lnk [2009/06/21 12:15:07 | 00,138,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/06/14 07:31:44 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK < End of report > Extras OTL Extras logfile created on: 27/06/2009 9:00:25 PM - Run 1 OTL by OldTimer - Version 3.0.5.3 Folder = H:\ Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy 503.48 Mb Total Physical Memory | 169.55 Mb Available Physical Memory | 33.68% Memory free 1.20 Gb Paging File | 0.93 Gb Available in Paging File | 77.59% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 37.26 Gb Total Space | 6.74 Gb Free Space | 18.08% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS G: Drive not present or media not loaded Drive H: | 971.51 Mb Total Space | 96.69 Mb Free Space | 9.95% Space Free | Partition Type: FAT32 I: Drive not present or media not loaded Computer Name: AUSTIN Current User Name: Vaughan Moutrie Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: On Skip Microsoft Files: Off File Age = 30 Days Output = Standard ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 "AntiVirusOverride" = 0 "FirewallOverride" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service "10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [2006/01/25 05:37:02 | 07,094,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 [2008/04/14 04:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] File not found -- C:\Program Files\KaZaA Lite\Kazaa.exe:*:Enabled:Kazaa Lite [1999/04/05 15:29:50 | 01,065,984 | ---- | M] (Valve, L.L.C.) -- C:\Program Files\Sierra\hl.exe:*:Enabled:Half-Life Launcher [2001/12/06 13:08:18 | 02,511,445 | ---- | M] (Electronic Arts Inc.) -- C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault [2008/04/14 10:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\messenger\msmsgs.exe:*:Enabled:Windows Messenger File not found -- C:\Documents and Settings\All Users\Documents\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing File not found -- C:\Program Files\Kazaa\kazaa.exe:*:Enabled:Kazaa [2005/10/18 11:50:24 | 12,116,480 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes [2006/01/25 05:37:02 | 07,094,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5 [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer File not found -- C:\Documents and Settings\Vaughan Moutrie\My Documents\utorrent.exe:*:Enabled:µTorrent [2008/04/14 04:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 [2008/01/01 10:09:50 | 08,594,880 | ---- | M] (Discordia, LTD) -- C:\Program Files\Shareaza Applications\Shareaza\Shareaza.exe:*:Disabled:Shareaza ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "@BIOS" = @BIOS "{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium "{07295ABF-1245-415A-BE06-863271753443}" = ShowBiz "{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3 "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java 6 Update 7 "{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX "{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth "{3EBD3749-304E-4A4C-9575-C00E5F015217}" = Apple Mobile Device Support "{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver "{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Premium "{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0 "{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD "{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0 "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers "{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes "{896D642C-7125-44F0-AC49-A23ABF82209C}" = CDBurnerXP Pro 3 "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver "{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet "{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional "{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1 "{B10D4952-97EA-401D-AF22-930BA7BE2A9B}" = UDISK Accessory "{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc "{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update "{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series "{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5 "{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio "{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard "Ad-Aware SE Personal" = Ad-Aware SE Personal "Adobe AIR" = Adobe AIR "Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Photoshop 7.0" = Adobe Photoshop 7.0 "Adobe Shockwave Player" = Adobe Shockwave Player "cciss_av" = CA Anti-Virus "CD to MP3 Ripper" = CD to MP3 Ripper "DivX Codec" = DivX Codec "DivX Player" = DivX Player "DropToCD (DataCD/DVD)_is1" = DropToCD (DataCD/DVD) v3.31 "DVD Shrink_is1" = DVD Shrink 3.2 "DVD-TO-MPEG V1.9_is1" = DVD-TO-MPEG V1.9 "eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook! "Enable S3 for USB Device" = Enable S3 for USB Device "e-tax 2006" = e-tax 2006 "e-tax 2007" = e-tax 2007 "e-tax 2008" = e-tax 2008 "GameSpy Arcade" = GameSpy Arcade "Half-Life" = Half-Life "HijackThis" = HijackThis 1.99.1 "HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series "IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs "ie7" = Windows Internet Explorer 7 "ie8" = Windows Internet Explorer 8 "InstallShield_{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver "InstallShield_{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes "InterActual Player" = InterActual Player "Microsoft Internet Gaming Zone" = MSN Gaming Zone "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "MusicBrainz Picard" = MusicBrainz Picard 0.7.2 "MusicIP Mixer_is1" = MusicIP Mixer 1.8.1 "Nissan FAST For Windows" = Nissan FAST For Windows "NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs "PROSet" = Intel® PRO Network Adapters and Drivers "RealPlayer 6.0" = RealPlayer "Rogue Spear" = Rogue Spear "Shareaza" = Shareaza "Sierra Utilities" = Sierra Utilities "Snap 'n Burn_is1" = Snap 'n Burn 1.2 "Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4 "SpyBotSnD" = SpyBot - Search & Destroy 1.1 "SpywareBlaster_is1" = SpywareBlaster 4.1 "VETWIN32Vp5" = CA Anti-Virus "Viewpoint Manager" = Viewpoint Manager (Remove Only) "VIRGIN BROADBAND" = VIRGIN BROADBAND "Winamp" = Winamp "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "Windows XP Service Pack" = Windows XP Service Pack 3 "WinRAR archiver" = WinRAR archiver "WinZip" = WinZip "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "Yahoo! Companion" = Yahoo!7 Toolbar "Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 22/03/2009 9:24:08 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000 Description = Faulting application wmplayer.exe, version 11.0.5721.5145, faulting module , version 0.0.0.0, fault address 0x00000000. Error - 25/03/2009 1:41:42 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000 Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting module unknown, version 0.0.0.0, fault address 0x08cd45d0. Error - 26/03/2009 8:22:46 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 27/03/2009 7:47:00 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 19/04/2009 10:28:54 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002 Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 21/04/2009 4:00:21 AM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002 Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 23/04/2009 3:20:03 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000 Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting module unknown, version 0.0.0.0, fault address 0x20007e6b. Error - 26/04/2009 7:32:49 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000 Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting module unknown, version 0.0.0.0, fault address 0x20007e6b. Error - 20/05/2009 7:59:07 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002 Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error - 3/06/2009 5:58:05 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000 Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting module unknown, version 0.0.0.0, fault address 0x20007e6b. [ System Events ] Error - 20/06/2009 9:53:48 PM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 20/06/2009 10:15:30 PM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 20/06/2009 10:16:30 PM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error - 21/06/2009 3:36:56 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 21/06/2009 4:50:01 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 25/06/2009 3:32:40 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 25/06/2009 3:33:31 AM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. Error - 25/06/2009 3:36:49 AM | Computer Name = AUSTIN | Source = DCOM | ID = 10010 Description = The server {601AC3DC-786A-4EB0-BF40-EE3521E70BFB} did not register with DCOM within the required timeout. Error - 27/06/2009 6:56:32 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000 Description = The Parallel port driver service failed to start due to the following error: %%1058 Error - 27/06/2009 6:57:28 AM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16 Description = Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection. < End of report > Thank you to anyone who can help |
|
|
Jun 27 2009, 04:20 PM
Post
#2
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
I should also add, i can't run explorer.exe from the task manager, even if i browse into the windows folder and select it i get an error message saying it cant find it.
|
|
|
Jul 3 2009, 03:20 PM
Post
#3
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Hi vmoutrie and welcome to Geeks to Go! I'm Dave and I'll be helping you out.
Let's get down to business, ComboFix is an excellent tool that will help us to deal with your explorer.exe problems in one of several ways. On your other computer, please download, rename, and save a copy of ComboFix as per these instructions: Please click on any of the links below to download Combofix. When you are asked to select the location of the file, please change the name of the file from ComboFix.exe to Combo-Fix.exe, and then save it to your desktop. Link 1 Link 2 Link 3 ![]() ![]() Once you have the file on your USB drive, plug the drive into the infected computer, and transfer the Combo-Fix.exe file to your desktop on the infected PC. You should be able to do this by opening 2 windows explorer windows from Task Manager > New Task as you have been doing and then drag and dropping the file on to your desktop. It's very important that the file run directly from your desktop. Once it's there, please run it according to these instructions: Notes:
![]() Once the Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning. The program will then scan for malware and perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else. When it's finished, the program's log will appear in notepad as well as saving itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply. Cheers, Dave |
|
|
Jul 4 2009, 05:22 AM
Post
#4
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Hi Dave, thanks alot for your reply!
I successfully got ComboFix onto the infected computer, but it can't connect to the internet to download the windows recovery console. I have a mobile internet service which requires the ISP software to be opened and a connection made like the old dial-up way, and when I try to open the software nothing happens. Is there somewhere I can download the windows recovery console and transfer via USB? PS, I have CA anti virus software. I opened the program via task manager and disabled the real-time scanning, will this suffice for disabling the antivirus? Thanks again for your help, Vaughan |
|
|
Jul 4 2009, 07:08 AM
Post
#5
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Now we have to go really old school
On a clean computer, visit this page: http://www.microsoft.com/downloads/details...;displaylang=en. Download the boot disk file (this is what we will need to install the recovery console) and save it to your USB drive. Once that's done, transfer it to your desktop on the infected computer like you did with the Combo-Fix.exe file. Then, in order to start ComboFix, instead of double-clicking on Combo-Fix.exe, in a Windows Explorer window, drag and drop the recovery console package into the Combo-Fix.exe file like such (except you won't be doing it your desktop but this is the general idea): ![]() You should see prompts similar or identical to the ones I described for the automatic RC install previously, follow those and go ahead with running ComboFix as detailed above. QUOTE PS, I have CA anti virus software. I opened the program via task manager and disabled the real-time scanning, will this suffice for disabling the antivirus? That's probably sufficient it would be worth looking through the task manager process list for any processes that belong to it and killing those before you start CF. Not a huge deal but something to try. Just need the CF log if you can get it for me in your next reply. Cheers, Dave |
|
|
Jul 5 2009, 03:56 AM
Post
#6
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
OK I just downloaded the file, put it on USB, turned on my infected PC aaaand.... the icons and start bar are back like normal!
All I did the other day was put Combo-Fix on there, disable the anti virus and run ComboFix until the point where it tried to download the recovery console. At that point I said No to the download and exited out of the program and shut down. Should I continue to follow the above process, or is there something different you would like me to try given this development? I can access the internet now as well so, provided the situation is the same next time I turn it on, I should be able to run ComboFix the normal way instead of transferring the file I just put on the USB. Thanks |
|
|
Jul 5 2009, 09:46 AM
Post
#7
|
|
![]() Unofficial Music Guru Posts: 2,354 From: Massachusetts, USA OS: Vista |
Okay assuming you can access the internet and your icons start bar etc. are back please continue with running ComboFix per these instructions:
Please click on any of the links below to download Combofix. When you are asked to select the location of the file, please change the name of the file from ComboFix.exe to Combo-Fix.exe, and then save it to your desktop. Link 1 Link 2 Link 3 ![]() ![]() Notes:
![]() Once the Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning. The program will then scan for malware and perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else. When it's finished, the program's log will appear in notepad as well as saving itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply. Just need the CF log in your next post Cheers, Dave |
|
|
Jul 6 2009, 12:21 AM
Post
#8
|
|
![]() Trusted Helper Posts: 9,208 OS: Windows XP |
Hello, my name is fenzodahl512 and welcome to Geekstogo..
Transience will be unavailable for a while.. Please complete Transience's last instruction and post the log here for my review |
|
|
Jul 6 2009, 05:09 AM
Post
#9
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Thanks guys, here is the report:
ComboFix 09-07-05.03 - Vaughan Moutrie 06/07/2009 20:53.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.503.164 [GMT 10:00] Running from: c:\documents and settings\Vaughan Moutrie\Desktop\Combo-Fix.exe AV: CA Anti-Virus *On-access scanning disabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\16982.msp c:\windows\Installer\1b1a1c.msp c:\windows\Installer\254235.msp c:\windows\Installer\2be713.msp c:\windows\Installer\2e0e0.msp c:\windows\Installer\3b96f1.msp c:\windows\Installer\4eb18.msp c:\windows\Installer\5f23d5.msp c:\windows\Installer\bb20a9.msp c:\windows\patch.exe c:\windows\system\GZSnb77896.drv c:\windows\system32\DBCS2016.DLL . ((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\Vaughan Moutrie\Application Data\Malwarebytes 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-27 11:45 . 2009-06-27 11:45 -------- d-----w- c:\program files\ERUNT 2009-06-17 01:27 . 2009-06-27 11:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 01:27 . 2009-06-27 11:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-13 07:09 . 2004-11-06 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink 2009-05-24 08:04 . 2008-03-24 23:47 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys 2009-05-24 08:04 . 2008-03-24 23:47 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys 2009-05-24 08:04 . 2008-03-24 23:47 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys 2009-05-24 08:04 . 2008-03-24 23:47 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys 2009-05-13 08:52 . 2004-02-28 23:06 -------- d-----w- c:\program files\Winamp 2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\program files\NOS 2009-05-09 07:55 . 2009-05-09 07:55 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-05-09 07:54 . 2004-02-28 05:18 -------- d-----w- c:\program files\Common Files\Adobe 2007-11-24 04:11 . 2007-11-24 04:10 2083211 -c--a-w- c:\program files\SnapNBurn.exe 2007-11-24 04:07 . 2007-11-24 04:03 4436563 -c--a-w- c:\program files\burn4free_setup.exe 2007-10-22 13:28 . 2007-10-22 13:28 6316925 -c--a-w- c:\program files\picard-setup-0.7.2-2.exe 2007-10-22 13:02 . 2007-10-22 13:02 4089084 -c--a-w- c:\program files\libofa-0.9.3-win32.zip 2005-03-12 00:28 . 2005-03-12 00:27 3304944 -c--a-w- c:\program files\Shareaza_2.1.0.0.exe 2004-11-15 01:30 . 2004-11-15 01:30 1164112 -c--a-w- c:\program files\wrar341.exe 2004-11-15 01:27 . 2004-11-15 01:26 2421920 -c--a-w- c:\program files\winzip90.exe 2004-11-06 11:46 . 2004-11-06 11:46 1094021 -c--a-w- c:\program files\dvdshrink32setup.zip 2004-11-06 11:29 . 2004-11-06 11:28 3987626 -c--a-w- c:\program files\1clickdvdcopysetup.exe 2004-07-23 11:30 . 2004-07-23 11:30 9059382 -c--a-w- c:\program files\mp3ripper.exe 2004-07-22 09:08 . 2004-07-22 09:08 839576 -c--a-w- c:\program files\dvdtm.exe 2004-02-28 04:26 . 2004-02-28 04:26 6207624 -c--a-w- c:\program files\vet-win32-full-10.61.0.03.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-18 278528] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-10 286720] "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-27 181488] "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-12 234736] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-02 577536] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-5 113664] hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-2 147456] hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-2 40960] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-18 65588] UDisk Assistant.lnk - c:\program files\UDisk utility 1.00.12\UDisk.exe [2009-1-29 532480] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tmod.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Sierra\\hl.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\messenger\\msmsgs.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [29/09/2008 1:01 PM 24652] S1 tmod;DRAM Cash Driver;c:\windows\system32\tmod.sys [9/03/2009 2:29 PM 0] S3 LwAdiHid;Logitech WingMan Digital Devices(Auto-Detect);c:\windows\system32\drivers\LwAdiHid.sys [29/06/2004 5:03 PM 20864] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . Contents of the 'Scheduled Tasks' folder 2005-01-17 c:\windows\Tasks\FRU Task 2002-12-03 04:38ewlett-Packard2002-12-03 04:38p psc 1200 series84887B468ABA3F57D76752217D5938688025EB21097200139.job - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 10:38] . - - - - ORPHANS REMOVED - - - - HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe Notify-tmodkm - tmodkm.dll . ------- Supplementary Scan ------- . uStart Page = hxxp://au.yahoo.com/?fr=fp-yie8 LSP: c:\windows\system32\VetRedir.dll TCP: {B1063B76-C024-4A97-B58B-1EE36F4D9EFD} = 123.200.191.17 123.200.191.18 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-06 20:59 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-06 21:03 ComboFix-quarantined-files.txt 2009-07-06 11:03 Pre-Run: 10,783,977,472 bytes free Post-Run: 10,774,642,688 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 143 --- E O F --- 2009-05-13 11:48 |
|
|
Jul 7 2009, 12:44 AM
Post
#10
|
|
![]() Trusted Helper Posts: 9,208 OS: Windows XP |
Please do an online scan with Kaspersky WebScanner
Click on Accept You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
How's the computer now? |
|
|
Jul 8 2009, 02:26 AM
Post
#11
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Hi Fenzodahl512,
I had a bit of trouble at first, I left it to go overnight and in the morning it looks like the computer had had an auto windows update and restarted itself ([bleep] those things!). I put it on to go again this morning, a balloon came up saying low virtual memory, but it was still scanning when I left for work. It seems to have gone OK, but hasn't picked up anything. In the Scan tab the Threat Names etc all have 0 results, and the Scan Report page has an empty table. The prompts it gave me throughout were a bit different to what you have said - I cant see a Save as Text button but there is a Save Report As button which I clicked, changed the file type from webpage to text and saved: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Wednesday, July 8, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Tuesday, July 07, 2009 21:00:04 Records in database: 2438441 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 79556 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 06:05:54 No malware has been detected. The scan area is clean. The selected area was scanned. Also, my mother is trying to learn all this stuff and is following the thread. She asks: "In the first OTL scan a lot of files dated 2028. Obviously they had to be infected files, and I'm assuming they have been deleted since by MBAM and Combofix, but I was surprised to see no files listed in the Combofix log for files created in the last month - surely there should be some genuine entries there....are they being hidden by malware or something?" Thanks |
|
|
Jul 8 2009, 02:40 AM
Post
#12
|
|
![]() Trusted Helper Posts: 9,208 OS: Windows XP |
Uh, you are absolutely right about the date.. Please don't delete it yet.. Currently I'm asking the developer of OTL regarding the case
anyhow, the computer only has 503mb of RAM.. Its quite low comparing with today's programs.. I strongly suggesting you to upgrade to 1gb of RAM at least.. When it comes to RAM, the more RAM, the better it is.. But for general usage, 1gb of RAM should be enough.. Now, since Kaspersky did not detect anything, can you tell me in details about your computer problem if any? Since not all computer problems related with malware.. It could be caused by something else |
|
|
Jul 10 2009, 02:54 AM
Post
#13
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Since the icons and start bar returned, it seems to be running normally...
|
|
|
Jul 10 2009, 02:55 AM
Post
#14
|
|
![]() Trusted Helper Posts: 9,208 OS: Windows XP |
Hello.. sorry for my late reply.. Please pm me if you didn't receive any response after 36 hours..
Anyhow, I've sent a pm to you.. Run it and post the log here |
|
|
Jul 10 2009, 04:10 AM
Post
#15
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Hey thats OK, no rush
Here is the log: ComboFix 09-07-09.07 - Vaughan Moutrie 10/07/2009 19:10.2.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.503.169 [GMT 10:00] Running from: c:\documents and settings\Vaughan Moutrie\Desktop\Combo-Fix.exe AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\Vaughan Moutrie\Application Data\Malwarebytes 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-27 11:45 . 2009-06-27 11:45 -------- d-----w- c:\program files\ERUNT 2009-06-17 01:27 . 2009-06-27 11:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-17 01:27 . 2009-06-27 11:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-13 07:09 . 2004-11-06 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink 2009-05-24 08:04 . 2008-03-24 23:47 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys 2009-05-24 08:04 . 2008-03-24 23:47 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys 2009-05-24 08:04 . 2008-03-24 23:47 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys 2009-05-24 08:04 . 2008-03-24 23:47 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys 2009-05-13 08:52 . 2004-02-28 23:06 -------- d-----w- c:\program files\Winamp 2009-05-13 05:15 . 2004-02-06 08:05 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\program files\NOS 2009-05-07 15:32 . 2003-03-31 12:00 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-17 12:26 . 2003-03-31 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-04-14 04:37 585216 ----a-w- c:\windows\system32\rpcrt4.dll 2007-11-24 04:11 . 2007-11-24 04:10 2083211 -c--a-w- c:\program files\SnapNBurn.exe 2007-11-24 04:07 . 2007-11-24 04:03 4436563 -c--a-w- c:\program files\burn4free_setup.exe 2007-10-22 13:28 . 2007-10-22 13:28 6316925 -c--a-w- c:\program files\picard-setup-0.7.2-2.exe 2007-10-22 13:02 . 2007-10-22 13:02 4089084 -c--a-w- c:\program files\libofa-0.9.3-win32.zip 2005-03-12 00:28 . 2005-03-12 00:27 3304944 -c--a-w- c:\program files\Shareaza_2.1.0.0.exe 2004-11-15 01:30 . 2004-11-15 01:30 1164112 -c--a-w- c:\program files\wrar341.exe 2004-11-15 01:27 . 2004-11-15 01:26 2421920 -c--a-w- c:\program files\winzip90.exe 2004-11-06 11:46 . 2004-11-06 11:46 1094021 -c--a-w- c:\program files\dvdshrink32setup.zip 2004-11-06 11:29 . 2004-11-06 11:28 3987626 -c--a-w- c:\program files\1clickdvdcopysetup.exe 2004-07-23 11:30 . 2004-07-23 11:30 9059382 -c--a-w- c:\program files\mp3ripper.exe 2004-07-22 09:08 . 2004-07-22 09:08 839576 -c--a-w- c:\program files\dvdtm.exe 2004-02-28 04:26 . 2004-02-28 04:26 6207624 -c--a-w- c:\program files\vet-win32-full-10.61.0.03.exe . ((((((((((((((((((((((((((((( SnapShot@2009-07-06_10.59.54 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-10 08:42 . 2009-07-10 08:42 16384 c:\windows\Temp\Perflib_Perfdata_5dc.dat + 2003-03-31 12:00 . 2009-04-30 21:22 25600 c:\windows\system32\jsproxy.dll - 2003-03-31 12:00 . 2009-03-07 18:33 25600 c:\windows\system32\jsproxy.dll + 2009-07-07 10:36 . 2009-04-30 21:22 12800 c:\windows\system32\dllcache\xpshims.dll - 2006-05-10 05:22 . 2009-03-07 18:33 25600 c:\windows\system32\dllcache\jsproxy.dll + 2006-05-10 05:22 . 2009-04-30 21:22 25600 c:\windows\system32\dllcache\jsproxy.dll + 2009-07-07 17:06 . 2009-03-07 18:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll + 2009-07-07 17:06 . 2009-03-07 18:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll + 2003-03-31 12:00 . 2009-04-30 21:22 385536 c:\windows\system32\iedkcs32.dll - 2003-03-31 12:00 . 2009-03-07 18:32 173056 c:\windows\system32\ie4uinit.exe + 2003-03-31 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe - 2028-02-28 13:31 . 2009-06-21 02:15 138056 c:\windows\system32\FNTCACHE.DAT + 2028-02-28 13:31 . 2009-07-07 17:13 138056 c:\windows\system32\FNTCACHE.DAT + 2006-05-10 05:23 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\wininet.dll + 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll + 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll + 2009-07-07 10:36 . 2009-04-30 21:22 246272 c:\windows\system32\dllcache\ieproxy.dll + 2006-10-26 15:44 . 2009-04-30 21:22 385536 c:\windows\system32\dllcache\iedkcs32.dll + 2006-10-26 15:44 . 2009-04-30 11:21 173056 c:\windows\system32\dllcache\ie4uinit.exe - 2006-10-26 15:44 . 2009-03-07 18:32 173056 c:\windows\system32\dllcache\ie4uinit.exe + 2009-07-07 17:06 . 2009-03-07 18:34 914944 c:\windows\ie8updates\KB969897-IE8\wininet.dll + 2009-07-07 17:06 . 2008-07-09 07:38 382840 c:\windows\ie8updates\KB969897-IE8\spuninst\updspapi.dll + 2009-07-07 17:06 . 2007-11-30 12:39 231288 c:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe + 2009-07-07 17:06 . 2009-03-07 18:33 246784 c:\windows\ie8updates\KB969897-IE8\ieproxy.dll + 2009-07-07 17:06 . 2009-03-08 04:09 391536 c:\windows\ie8updates\KB969897-IE8\iedkcs32.dll + 2009-07-07 17:06 . 2009-03-07 18:32 173056 c:\windows\ie8updates\KB969897-IE8\ie4uinit.exe + 2004-01-21 05:20 . 2009-04-30 21:22 1207808 c:\windows\system32\urlmon.dll + 2004-07-07 08:37 . 2009-05-13 05:15 5936128 c:\windows\system32\mshtml.dll - 2006-10-17 01:57 . 2009-03-07 18:32 1985024 c:\windows\system32\iertutil.dll + 2006-10-17 01:57 . 2009-04-30 21:22 1985024 c:\windows\system32\iertutil.dll + 2008-10-15 22:21 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys + 2006-05-10 05:23 . 2009-04-30 21:22 1207808 c:\windows\system32\dllcache\urlmon.dll + 2006-05-19 15:08 . 2009-05-13 05:15 5936128 c:\windows\system32\dllcache\mshtml.dll - 2007-05-08 22:44 . 2009-03-07 18:32 1985024 c:\windows\system32\dllcache\iertutil.dll + 2007-05-08 22:44 . 2009-04-30 21:22 1985024 c:\windows\system32\dllcache\iertutil.dll + 2009-07-07 17:06 . 2009-03-07 18:34 1206784 c:\windows\ie8updates\KB969897-IE8\urlmon.dll + 2009-07-07 17:06 . 2009-03-07 18:41 5937152 c:\windows\ie8updates\KB969897-IE8\mshtml.dll + 2009-07-07 17:06 . 2009-03-07 18:32 1985024 c:\windows\ie8updates\KB969897-IE8\iertutil.dll + 2005-05-12 04:41 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe + 2006-10-27 04:09 . 2009-04-30 21:22 11064832 c:\windows\system32\ieframe.dll + 2007-05-08 22:44 . 2009-04-30 21:22 11064832 c:\windows\system32\dllcache\ieframe.dll + 2009-07-07 17:06 . 2009-03-07 18:39 11063808 c:\windows\ie8updates\KB969897-IE8\ieframe.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-18 278528] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-10 286720] "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-27 181488] "CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-12 234736] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-02 577536] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193] Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-5 113664] hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-2 147456] hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-2 40960] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-18 65588] UDisk Assistant.lnk - c:\program files\UDisk utility 1.00.12\UDisk.exe [2009-1-29 532480] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tmod.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Sierra\\hl.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\messenger\\msmsgs.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [29/09/2008 1:01 PM 24652] S1 tmod;DRAM Cash Driver;c:\windows\system32\tmod.sys [9/03/2009 2:29 PM 0] S3 LwAdiHid;Logitech WingMan Digital Devices(Auto-Detect);c:\windows\system32\drivers\LwAdiHid.sys [29/06/2004 5:03 PM 20864] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12 . Contents of the 'Scheduled Tasks' folder 2005-01-17 c:\windows\Tasks\FRU Task 2002-12-03 04:38ewlett-Packard2002-12-03 04:38p psc 1200 series84887B468ABA3F57D76752217D5938688025EB21097200139.job - c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 10:38] . . ------- Supplementary Scan ------- . uStart Page = hxxp://au.yahoo.com/?fr=fp-yie8 LSP: c:\windows\system32\VetRedir.dll TCP: {B1063B76-C024-4A97-B58B-1EE36F4D9EFD} = 123.200.191.17 123.200.191.18 DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-10 19:19 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(412) c:\windows\system32\WININET.dll c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\VetRedir.dll c:\windows\system32\ISafeIf.dll . Completion time: 2009-07-10 19:23 ComboFix-quarantined-files.txt 2009-07-10 09:23 ComboFix2.txt 2009-07-06 11:04 Pre-Run: 10,584,485,888 bytes free Post-Run: 10,631,172,096 bytes free 177 --- E O F --- 2009-07-07 17:06 |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
1 / 687 | 27th April 2005 - 12:58 PM Hot_Reezy started - last by TonyKlein |
|||||
![]() |
4 / 462 | 26th April 2007 - 12:12 PM Otieno started - last by Retired Tech |
|||||
![]() |
6 / 454 | 1st July 2008 - 02:05 AM ChicagosOnlyPunk started - last by mirjel |
|||||
![]() |
7 / 637 | 22nd August 2008 - 04:21 PM Panther6730 started - last by Rorschach112 |
|||||
|
Time is now: 7th November 2009 - 10:28 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising