Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
   
3 Pages V   1 2 3 >  
Closed TopicStart new topic
No start bar or desktop icons [Solved]
vmoutrie
post Jun 27 2009, 06:34 AM
Post #1


Member
**
Posts: 20
OS: Windows XP



Hello,

Upon turning on my computer recently, my wallpaper loaded up but I had no start bar or icons on the desktop. The only operation I can perform is to press ctrl,alt,del and bring up the task manager and from here browse files via the 'run new task' option.

We tried reboots and restore points and ran antivirus, hijackthis etc before i was advised to visit this site. I have followed the instructions in the cleaning guide thread, by downloading the tools from my partners computer and transferring by usb, as i can't connect to the internet on my computer.

Here are the results...

MBAM

Malwarebytes' Anti-Malware 1.38
Database version: 2297
Windows 5.1.2600 Service Pack 3

27/06/2009 9:56:34 PM
mbam-log-2009-06-27 (21-56-34).txt

Scan type: Quick Scan
Objects scanned: 86802
Time elapsed: 6 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{386a771c-e96a-421f-8ba7-32f1b706892f} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c559105-9ecf-42b8-b3f7-832e75edd959} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Microsoft Common (Trojan.Agent) -> Quarantined and deleted successfully.




Rooter

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP Home Edition (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 2 Stepping 9, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
.
Internet Explorer 8.0.6001.18702
.
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:37 Go - Free:10 Go )
D:\ [CD_Rom]
E:\ [CD_Rom]
F:\ [CD_Rom]
H:\ [Removable]
.
Scan : 22:01.31
Path : H:\Rooter.exe
User : Vaughan Moutrie ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (644)
______ \??\C:\WINDOWS\system32\csrss.exe (932)
______ \??\C:\WINDOWS\system32\winlogon.exe (1096)
______ C:\WINDOWS\system32\services.exe (1252)
______ C:\WINDOWS\system32\lsass.exe (1312)
______ C:\WINDOWS\system32\svchost.exe (1952)
______ C:\WINDOWS\system32\svchost.exe (324)
______ C:\WINDOWS\System32\svchost.exe (620)
______ C:\WINDOWS\system32\svchost.exe (784)
______ C:\WINDOWS\System32\svchost.exe (1420)
______ C:\WINDOWS\System32\svchost.exe (1608)
______ C:\WINDOWS\system32\spoolsv.exe (96)
______ C:\WINDOWS\System32\svchost.exe (372)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (564)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (664)
______ C:\WINDOWS\System32\svchost.exe (900)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1076)
______ C:\WINDOWS\System32\svchost.exe (1588)
______ C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (184)
______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (436)
______ C:\Program Files\Windows Media Player\WMPNetwk.exe (1376)
______ C:\WINDOWS\System32\alg.exe (1756)
______ C:\WINDOWS\system32\wscntfy.exe (160)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (2672)
______ C:\WINDOWS\system32\wuauclt.exe (3672)
______ C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (1728)
______ C:\WINDOWS\system32\taskmgr.exe (2484)
______ H:\Rooter.exe (3080)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:40007729664)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1097200139.job
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
C:\DOCUME~1\VAUGHA~1\My Documents\Unzipped\Macromedia Studio MX - (ColdFusion MX, Dreamweaver MX, Fireworks MX, Flash MX, Fireworks 10) - Trade Only\Flash MX\keygen.exe
==> Cracks & Keygens <==
.
----------------------\\ Scan completed at 22:01.58
.
C:\Rooter$\Rooter_3.txt - (27/06/2009 | 22:01.58).c






OTL

OTL logfile created on: 27/06/2009 10:03:39 PM - Run 2
OTL by OldTimer - Version 3.0.5.3 Folder = H:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

503.48 Mb Total Physical Memory | 206.17 Mb Available Physical Memory | 40.95% Memory free
1.20 Gb Paging File | 0.97 Gb Available in Paging File | 80.67% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 10.15 Gb Free Space | 27.25% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
Drive H: | 971.51 Mb Total Space | 92.13 Mb Free Space | 9.48% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: AUSTIN
Current User Name: Vaughan Moutrie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - H:\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (CaCCProvSP [On_Demand | Stopped]) -- C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (CAISafe [Auto | Running]) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (Computer Associates International, Inc.)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPodService [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (VETMSGNT [Auto | Running]) -- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (CA, Inc.)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AFS2K [System | Running]) -- C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXSENS [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (ALCXWDM [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (hwdatacard [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IdeBusDr [Boot | Stopped]) -- C:\WINDOWS\System32\DRIVERS\IdeBusDr.sys (Intel Corporation)
DRV - (IdeChnDr [Boot | Stopped]) -- C:\WINDOWS\System32\DRIVERS\IdeChnDr.sys (Intel Corporation)
DRV - (LwAdiHid [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LwAdiHid.sys (Logitech Inc.)
DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (Pcouffin [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\Pcouffin.sys (VSO Software)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (tmod [System | Stopped]) -- C:\WINDOWS\System32\tmod.sys ()
DRV - (TVICHW32 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (VET-FILT [System | Running]) -- C:\WINDOWS\System32\drivers\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VET-REC [System | Running]) -- C:\WINDOWS\System32\drivers\vet-rec.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETEFILE [System | Running]) -- C:\WINDOWS\System32\drivers\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT [System | Running]) -- C:\WINDOWS\System32\drivers\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VETMONNT [System | Running]) -- C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://au.search.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://au.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://home.microsoft.com/access/allinone.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/?fr=fp-yie8
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/11 09:15:32 | 00,000,000 | ---D | M]


O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo!7 Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe File not found
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe File not found
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Computer, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [*Restore] C:\WINDOWS\System32\restore\rstrui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] .Trashes [2007/09/24 12:23:12 | 00,000,000 | -H-D | M]
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\UDisk Assistant.lnk = C:\Program Files\UDisk utility 1.00.12\UDisk.exe ()
O4 - Startup: C:\Documents and Settings\Vaughan Moutrie\Start Menu\Programs\Startup\Shortcut to autodown.exe.lnk = C:\Program Files\CA\eTrust Vet Antivirus\autodown.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: _NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 103 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxacm.CAB (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} http://housecall-beta.trendmicro.com/housecall/xscan60.cab (HouseCall Control)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} http://www.cult3d.com/download/cult.cab (Cult3D ActiveX Player)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://vorn86.spaces.msn.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/Facebo...toUploader3.cab (Facebook Photo Uploader 4 Control)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} http://upload.facebook.com/controls/Facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} http://instantsupport.asiapac.hp.com/awebu...SWebManager.CAB (Hewlett-Packard Printer Diagnostics)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} http://a1540.g.akamai.net/7/1540/52/200404...meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://vorn86.spaces.live.com/PhotoUpload/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...8044.7952546296 (Reg Error: Key error.)
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} http://fdl.msn.com/zone/datafiles/heartbeat.cab (HeartbeatCtl Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab (Solitaire Showdown Class)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\tmodkm: DllName - tmodkm.dll - .Trashes [2007/09/24 12:23:12 | 00,000,000 | -H-D | M]
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\explorer.exe: Debugger - C:\Program Files\Microsoft Common\svchost.exe File not found
O29 - HKLM SecurityProviders - (zwebauth.dll) - C:\WINDOWS\System32\zwebauth.dll ()
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/02/28 12:49:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2006/05/12 08:13:39 | 00,000,279 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O32 - Unable to obtain root file information for disk H:\
O33 - MountPoints2\{ad62a951-43ec-11dd-aa99-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ad62a951-43ec-11dd-aa99-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{ec74dd5f-da55-11db-b20a-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{ec74dd5f-da55-11db-b20a-000d6135b3f1}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- [2006/04/19 08:33:36 | 00,950,272 | R--- | M] ()
O33 - MountPoints2\{f6d558fa-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6d558fa-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\{f6d558fd-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f6d558fd-436d-11dd-aa98-000d6135b3f1}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2028/02/28 23:35:26 | 00,006,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\splitter.sys
[2028/02/28 23:35:25 | 00,142,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aec.sys
[2028/02/28 23:35:24 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmkaud.sys
[2028/02/28 23:35:23 | 00,056,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\swmidi.sys
[2028/02/28 23:35:22 | 00,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dmusic.sys
[2028/02/28 23:35:20 | 00,083,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wdmaud.sys
[2028/02/28 23:35:17 | 00,172,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kmixer.sys
[2028/02/28 23:35:14 | 00,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sysaudio.sys
[2028/02/28 23:35:11 | 00,003,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\audstub.sys
[2028/02/28 23:34:52 | 00,057,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\redbook.sys
[2028/02/28 23:34:35 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msmpu401.sys
[2028/02/28 23:34:33 | 00,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gameenum.sys
[2028/02/28 23:34:16 | 00,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\intelide.sys
[2028/02/28 23:33:17 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2028/02/28 23:33:15 | 01,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2028/02/28 23:33:15 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcommon.dll
[2028/02/28 23:33:15 | 00,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcplui.dll
[2028/02/28 23:33:15 | 00,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2028/02/28 23:33:14 | 00,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spttseng.dll
[2028/02/28 23:33:14 | 00,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2028/02/28 23:33:14 | 00,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2028/02/28 23:33:14 | 00,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapisvr.exe
[2028/02/28 23:33:14 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files
[2028/02/28 23:33:13 | 00,000,000 | ---D | C] -- C:\Program Files
[2028/02/28 23:33:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28603.nls
[2028/02/28 23:33:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28603.nls
[2028/02/28 23:33:11 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_857.nls
[2028/02/28 23:33:11 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_857.nls
[2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28599.nls
[2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10081.nls
[2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_28599.nls
[2028/02/28 23:33:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10081.nls
[2028/02/28 23:33:11 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll
[2028/02/28 23:33:11 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll
[2028/02/28 23:33:11 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuq.dll
[2028/02/28 23:33:11 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuf.dll
[2028/02/28 23:33:11 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll
[2028/02/28 23:33:11 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdazel.dll
[2028/02/28 23:33:10 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll
[2028/02/28 23:33:10 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkyr.dll
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28595.nls
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10017.nls
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10007.nls
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28595.NLS
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10017.nls
[2028/02/28 23:33:09 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10007.nls
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll
[2028/02/28 23:33:09 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycc.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbduzb.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdur.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtat.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru1.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdmon.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkaz.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdbu.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdblr.dll
[2028/02/28 23:33:09 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdaze.dll
[2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_869.nls
[2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_737.nls
[2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_869.nls
[2028/02/28 23:33:07 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_737.nls
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_875.nls
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28597.nls
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10006.nls
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_875.nls
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28597.NLS
[2028/02/28 23:33:07 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10006.nls
[2028/02/28 23:33:07 | 00,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll
[2028/02/28 23:33:07 | 00,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhept.dll
[2028/02/28 23:33:07 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll
[2028/02/28 23:33:07 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela3.dll
[2028/02/28 23:33:07 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll
[2028/02/28 23:33:07 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll
[2028/02/28 23:33:07 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela2.dll
[2028/02/28 23:33:07 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgkl.dll
[2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll
[2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll
[2028/02/28 23:33:07 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll
[2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe319.dll
[2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe220.dll
[2028/02/28 23:33:07 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe.dll
[2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_866.nls
[2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_855.nls
[2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_866.nls
[2028/02/28 23:33:06 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_855.nls
[2028/02/28 23:33:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_28594.nls
[2028/02/28 23:33:06 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\C_28594.NLS
[2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll
[2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll
[2028/02/28 23:33:06 | 00,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll
[2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv1.dll
[2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv.dll
[2028/02/28 23:33:06 | 00,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdest.dll
[2028/02/28 23:33:06 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll
[2028/02/28 23:33:06 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll
[2028/02/28 23:33:06 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt1.dll
[2028/02/28 23:33:06 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt.dll
[2028/02/28 23:33:04 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_852.nls
[2028/02/28 23:33:04 | 00,066,594 | ---- | C] () -- C:\WINDOWS\System32\c_852.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10082.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10029.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\dllcache\c_10010.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10082.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10029.nls
[2028/02/28 23:33:04 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_10010.nls
[2028/02/28 23:33:04 | 00,007,168 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz.dll
[2028/02/28 23:33:04 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz2.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz1.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll
[2028/02/28 23:33:04 | 00,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycl.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl1.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz2.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz1.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcr.dll
[2028/02/28 23:33:04 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdal.dll
[2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll
[2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll
[2028/02/28 23:33:04 | 00,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll
[2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdro.dll
[2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl1.dll
[2028/02/28 23:33:04 | 00,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu1.dll
[2028/02/28 23:33:02 | 00,066,082 | ---- | C] () -- C:\WINDOWS\System32\c_20127.nls
[2028/02/28 23:33:02 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2028/02/28 23:33:02 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll
[2028/02/28 23:33:02 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\irenum.sys
[2028/02/28 23:33:01 | 00,126,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL
[2028/02/28 23:33:01 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL
[2028/02/28 23:33:01 | 00,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL
[2028/02/28 23:33:01 | 00,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL
[2028/02/28 23:33:01 | 00,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV
[2028/02/28 23:33:01 | 00,009,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL
[2028/02/28 23:33:01 | 00,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL
[2028/02/28 23:33:01 | 00,004,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV
[2028/02/28 23:33:01 | 00,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV
[2028/02/28 23:33:01 | 00,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV
[2028/02/28 23:33:01 | 00,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV
[2028/02/28 23:33:00 | 00,109,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL
[2028/02/28 23:33:00 | 00,073,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV
[2028/02/28 23:33:00 | 00,069,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL
[2028/02/28 23:33:00 | 00,069,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2028/02/28 23:33:00 | 00,068,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\mmsystem.dll
[2028/02/28 23:33:00 | 00,032,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL
[2028/02/28 23:33:00 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV
[2028/02/28 23:33:00 | 00,025,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV
[2028/02/28 23:33:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2028/02/28 23:33:00 | 00,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\taskman.exe
[2028/02/28 23:33:00 | 00,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL
[2028/02/28 23:33:00 | 00,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV
[2028/02/28 23:33:00 | 00,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV
[2028/02/28 23:33:00 | 00,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK
[2028/02/28 23:32:59 | 00,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\winspool.drv
[2028/02/28 23:32:59 | 00,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll
[2028/02/28 23:32:59 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll
[2028/02/28 23:32:59 | 00,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2028/02/28 23:32:50 | 00,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2028/02/28 23:32:50 | 00,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2028/02/28 23:32:50 | 00,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2028/02/28 23:32:50 | 00,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2028/02/28 23:32:49 | 00,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2028/02/28 23:32:49 | 00,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2028/02/28 23:32:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2028/02/28 23:32:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2028/02/28 23:32:32 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2028/02/28 23:31:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings
[2028/02/28 23:31:50 | 00,138,056 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2028/02/28 23:31:09 | 00,000,211 | RHS- | C] () -- C:\boot.ini
[2028/02/28 23:31:06 | 00,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2028/02/28 23:27:39 | 00,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2028/02/28 23:27:39 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2028/02/28 23:27:39 | 00,000,000 | R--D | C] -- C:\WINDOWS\Web
[2028/02/28 23:27:39 | 00,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\system32
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\system
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\security
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\repair
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\mui
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Media
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\java
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\ime
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Help
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\Config
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS\addins
[2028/02/28 23:27:39 | 00,000,000 | ---D | C] -- C:\WINDOWS
[2009/06/27 21:58:54 | 00,000,000 | ---D | C] -- C:\Avenger
[2009/06/27 21:47:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Vaughan Moutrie\Application Data\Malwarebytes
[2009/06/27 21:47:42 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/27 21:47:39 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/27 21:47:35 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/27 21:47:35 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/27 21:47:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/27 21:46:25 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/27 21:45:23 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\NTREGOPT.lnk
[2009/06/27 21:45:23 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\ERUNT.lnk
[2009/06/27 21:45:22 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/27 20:58:22 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/21 21:27:17 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/03/09 14:29:10 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\tmod.sys
[2008/11/05 11:29:13 | 00,000,140 | ---- | C] () -- C:\WINDOWS\NSFASTKY.INI
[2008/11/05 10:53:30 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\W32mkrc.dll
[2008/11/05 10:53:27 | 00,054,272 | ---- | C] () -- C:\WINDOWS\System32\P2IRDAO.DLL
[2008/11/05 10:53:26 | 00,050,176 | ---- | C] () -- C:\WINDOWS\System32\CTDAO.DLL
[2008/11/05 10:53:25 | 00,036,352 | ---- | C] () -- C:\WINDOWS\System32\P2BBND.DLL
[2008/11/05 10:53:24 | 00,748,160 | ---- | C] () -- C:\WINDOWS\System32\CO2C40EN.DLL
[2008/11/05 10:53:24 | 00,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\IMPLODE.DLL
[2008/11/05 10:53:16 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\OC25JPN.DLL
[2008/11/05 10:53:16 | 00,014,256 | ---- | C] () -- C:\WINDOWS\System32\VAJP2.DLL
[2008/11/05 10:53:12 | 00,001,736 | ---- | C] () -- C:\WINDOWS\NSFASTW.INI
[2007/04/12 11:08:52 | 00,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2007/04/12 11:08:36 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2007/01/24 10:06:35 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/06/07 08:56:04 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hpqemlsz.INI
[2005/04/04 11:08:49 | 00,000,112 | ---- | C] () -- C:\WINDOWS\ActiveSkin.INI
[2005/03/08 17:39:07 | 00,000,156 | ---- | C] () -- C:\WINDOWS\GetServer.ini
[2005/02/17 02:12:54 | 00,025,157 | ---- | C] () -- C:\WINDOWS\RMAgentOutput.dll
[2005/02/17 02:12:00 | 00,126,976 | ---- | C] () -- C:\WINDOWS\dllTSCLIBMT.dll
[2005/02/01 20:43:10 | 00,000,019 | ---- | C] () -- C:\WINDOWS\SoundConverter.INI
[2004/11/10 10:37:44 | 00,000,115 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2004/10/31 17:21:16 | 00,000,125 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2004/10/01 16:33:46 | 00,000,679 | ---- | C] () -- C:\WINDOWS\TSC.ini
[2004/07/23 21:30:43 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\tvqenc.dll
[2004/07/23 21:30:41 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2004/07/18 16:36:41 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/07/01 09:23:29 | 00,016,973 | ---- | C] () -- C:\WINDOWS\System32\ZWebAuth.dll
[2004/06/30 16:48:05 | 00,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2004/06/29 16:59:27 | 00,108,992 | ---- | C] () -- C:\WINDOWS\System32\SH34W32.DLL
[2004/06/29 16:59:27 | 00,075,264 | ---- | C] () -- C:\WINDOWS\System32\IFORCE2.dll
[2004/04/03 16:04:32 | 00,000,562 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2004/03/30 09:16:59 | 00,000,225 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2004/02/29 09:00:00 | 00,001,125 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2004/02/28 18:45:55 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/02/28 15:31:04 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2004/02/28 14:41:34 | 00,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2004/02/28 13:28:57 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004/02/28 13:01:17 | 00,012,288 | R--- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2003/03/31 22:00:00 | 00,000,763 | ---- | C] () -- C:\WINDOWS\win.ini
[2003/03/31 22:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\SYSTEM.INI
[2002/11/27 21:30:32 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2002/11/01 15:17:50 | 00,000,256 | ---- | C] () -- C:\WINDOWS\aucfg.ini
[2002/07/04 14:05:34 | 00,000,269 | ---- | C] () -- C:\WINDOWS\tmupdate.ini
[2001/12/14 12:34:46 | 00,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[1999/07/23 12:46:48 | 00,000,116 | ---- | C] () -- C:\WINDOWS\AuHCcup1.ini
[1999/07/23 09:53:20 | 00,129,536 | ---- | C] () -- C:\WINDOWS\AuHCcup1.dll

========== Files - Modified Within 30 Days ==========

[2028/02/28 23:33:14 | 00,000,231 | ---- | M] () -- C:\WINDOWS\System.vet
[2009/06/27 21:59:48 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/27 21:59:25 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/27 21:59:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/27 21:47:42 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/27 21:45:23 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\NTREGOPT.lnk
[2009/06/27 21:45:23 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Vaughan Moutrie\Desktop\ERUNT.lnk
[2009/06/21 12:15:07 | 00,138,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/14 07:31:44 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
< End of report >





Extras

OTL Extras logfile created on: 27/06/2009 9:00:25 PM - Run 1
OTL by OldTimer - Version 3.0.5.3 Folder = H:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

503.48 Mb Total Physical Memory | 169.55 Mb Available Physical Memory | 33.68% Memory free
1.20 Gb Paging File | 0.93 Gb Available in Paging File | 77.59% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 6.74 Gb Free Space | 18.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 5.49 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
Drive H: | 971.51 Mb Total Space | 96.69 Mb Free Space | 9.95% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: AUSTIN
Current User Name: Vaughan Moutrie
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/01/25 05:37:02 | 07,094,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5
[2008/04/14 04:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found -- C:\Program Files\KaZaA Lite\Kazaa.exe:*:Enabled:Kazaa Lite
[1999/04/05 15:29:50 | 01,065,984 | ---- | M] (Valve, L.L.C.) -- C:\Program Files\Sierra\hl.exe:*:Enabled:Half-Life Launcher
[2001/12/06 13:08:18 | 02,511,445 | ---- | M] (Electronic Arts Inc.) -- C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault
[2008/04/14 10:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\messenger\msmsgs.exe:*:Enabled:Windows Messenger
File not found -- C:\Documents and Settings\All Users\Documents\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing
File not found -- C:\Program Files\Kazaa\kazaa.exe:*:Enabled:Kazaa
[2005/10/18 11:50:24 | 12,116,480 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2006/01/25 05:37:02 | 07,094,272 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5
[2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer
File not found -- C:\Documents and Settings\Vaughan Moutrie\My Documents\utorrent.exe:*:Enabled:µTorrent
[2008/04/14 04:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/01/01 10:09:50 | 08,594,880 | ---- | M] (Discordia, LTD) -- C:\Program Files\Shareaza Applications\Shareaza\Shareaza.exe:*:Disabled:Shareaza


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"@BIOS" = @BIOS
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{07295ABF-1245-415A-BE06-863271753443}" = ShowBiz
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}" = Macromedia Flash MX
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{3EBD3749-304E-4A4C-9575-C00E5F015217}" = Apple Mobile Device Support
"{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Premium
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = MyDVD
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}" = HP Photo and Imaging 2.0 - All-in-One Drivers
"{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes
"{896D642C-7125-44F0-AC49-A23ABF82209C}" = CDBurnerXP Pro 3
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{9867A917-5D17-40DE-83BA-BEA5293194B1}" = HP Photo and Imaging 2.0 - All-in-One
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B10D4952-97EA-401D-AF22-930BA7BE2A9B}" = UDISK Accessory
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{C900EF06-2E76-49C7-8DB0-41F629B21DC5}" = hp psc 1200 series
"{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{E0D51394-1D45-460A-B62D-383BC4F8B335}" = QuickTime
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe AIR" = Adobe AIR
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"cciss_av" = CA Anti-Virus
"CD to MP3 Ripper" = CD to MP3 Ripper
"DivX Codec" = DivX Codec
"DivX Player" = DivX Player
"DropToCD (DataCD/DVD)_is1" = DropToCD (DataCD/DVD) v3.31
"DVD Shrink_is1" = DVD Shrink 3.2
"DVD-TO-MPEG V1.9_is1" = DVD-TO-MPEG V1.9
"eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook!
"Enable S3 for USB Device" = Enable S3 for USB Device
"e-tax 2006" = e-tax 2006
"e-tax 2007" = e-tax 2007
"e-tax 2008" = e-tax 2008
"GameSpy Arcade" = GameSpy Arcade
"Half-Life" = Half-Life
"HijackThis" = HijackThis 1.99.1
"HP PSC 1200 Series" = HP Photo and Imaging 2.0 - hp psc 1200 series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{3ECED7D1-E469-4BC6-8A93-5CB0FFE5EBF5}" = Nokia Connectivity Cable Driver
"InstallShield_{872653C6-5DDC-488B-B7C2-CF9E4D9335E5}" = iTunes
"InterActual Player" = InterActual Player
"Microsoft Internet Gaming Zone" = MSN Gaming Zone
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MusicBrainz Picard" = MusicBrainz Picard 0.7.2
"MusicIP Mixer_is1" = MusicIP Mixer 1.8.1
"Nissan FAST For Windows" = Nissan FAST For Windows
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealPlayer
"Rogue Spear" = Rogue Spear
"Shareaza" = Shareaza
"Sierra Utilities" = Sierra Utilities
"Snap 'n Burn_is1" = Snap 'n Burn 1.2
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpyBotSnD" = SpyBot - Search & Destroy 1.1
"SpywareBlaster_is1" = SpywareBlaster 4.1
"VETWIN32Vp5" = CA Anti-Virus
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"VIRGIN BROADBAND" = VIRGIN BROADBAND
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo!7 Toolbar
"Yahoo! Photos Drag-Drop Uploader 1v7" = Yahoo! Photos Easy Upload Tool 1v7

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 22/03/2009 9:24:08 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000
Description = Faulting application wmplayer.exe, version 11.0.5721.5145, faulting
module , version 0.0.0.0, fault address 0x00000000.

Error - 25/03/2009 1:41:42 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module unknown, version 0.0.0.0, fault address 0x08cd45d0.

Error - 26/03/2009 8:22:46 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 27/03/2009 7:47:00 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 19/04/2009 10:28:54 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21/04/2009 4:00:21 AM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 23/04/2009 3:20:03 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000
Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting
module unknown, version 0.0.0.0, fault address 0x20007e6b.

Error - 26/04/2009 7:32:49 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000
Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting
module unknown, version 0.0.0.0, fault address 0x20007e6b.

Error - 20/05/2009 7:59:07 PM | Computer Name = AUSTIN | Source = Application Hang | ID = 1002
Description = Hanging application wmplayer.exe, version 11.0.5721.5145, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/06/2009 5:58:05 AM | Computer Name = AUSTIN | Source = Application Error | ID = 1000
Description = Faulting application dvd shrink 3.2.exe, version 3.2.0.15, faulting
module unknown, version 0.0.0.0, fault address 0x20007e6b.

[ System Events ]
Error - 20/06/2009 9:53:48 PM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 20/06/2009 10:15:30 PM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 20/06/2009 10:16:30 PM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 21/06/2009 3:36:56 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 21/06/2009 4:50:01 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 25/06/2009 3:32:40 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 25/06/2009 3:33:31 AM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 25/06/2009 3:36:49 AM | Computer Name = AUSTIN | Source = DCOM | ID = 10010
Description = The server {601AC3DC-786A-4EB0-BF40-EE3521E70BFB} did not register
with DCOM within the required timeout.

Error - 27/06/2009 6:56:32 AM | Computer Name = AUSTIN | Source = Service Control Manager | ID = 7000
Description = The Parallel port driver service failed to start due to the following
error: %%1058

Error - 27/06/2009 6:57:28 AM | Computer Name = AUSTIN | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.


< End of report >






Thank you to anyone who can help smile.gif
Go to the top of the page
 
+Quote Post
vmoutrie
post Jun 27 2009, 04:20 PM
Post #2


Member
**
Posts: 20
OS: Windows XP



I should also add, i can't run explorer.exe from the task manager, even if i browse into the windows folder and select it i get an error message saying it cant find it.
Go to the top of the page
 
+Quote Post
Transience
post Jul 3 2009, 03:20 PM
Post #3


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Hi vmoutrie and welcome to Geeks to Go! I'm Dave and I'll be helping you out.

Let's get down to business, ComboFix is an excellent tool that will help us to deal with your explorer.exe problems in one of several ways.

On your other computer, please download, rename, and save a copy of ComboFix as per these instructions:

Please click on any of the links below to download Combofix. When you are asked to select the location of the file, please change the name of the file from ComboFix.exe to Combo-Fix.exe, and then save it to your desktop.

Link 1
Link 2
Link 3





Once you have the file on your USB drive, plug the drive into the infected computer, and transfer the Combo-Fix.exe file to your desktop on the infected PC. You should be able to do this by opening 2 windows explorer windows from Task Manager > New Task as you have been doing and then drag and dropping the file on to your desktop. It's very important that the file run directly from your desktop. Once it's there, please run it according to these instructions:

Notes:
  • Before running ComboFix, you should disable all Antivirus, Anti-Spyware, and Firewall applications so they don't interfere with its running. You can often do this just by right-clicking on the system tray icon and clicking "Disable" or similar. If you need further instructions for how to disable your program specifically, look here.
  • ComboFix will temporarily disconnect your machine from the internet and change your clock settings, this is normal and both will be restored before the program terminates.
  • Do not attempt to run any programs or click on ComboFix's window while it is running, just allow it to proceed uninterrupted aside from okaying any prompts. It may appear to be doing nothing at times, this is normal, don't worry.
Next:
  • Double click on ComboFix.exe and follow the prompts.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Recovery Console, and when prompted, agree to the End-User License Agreement to install it.
* Note: If the Recovery Console is already installed on your computer, ComboFix will ignore the installation routines and continue its malware removal procedures.



Once the Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning. The program will then scan for malware and perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else.

When it's finished, the program's log will appear in notepad as well as saving itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 4 2009, 05:22 AM
Post #4


Member
**
Posts: 20
OS: Windows XP



Hi Dave, thanks alot for your reply!

I successfully got ComboFix onto the infected computer, but it can't connect to the internet to download the windows recovery console. I have a mobile internet service which requires the ISP software to be opened and a connection made like the old dial-up way, and when I try to open the software nothing happens. Is there somewhere I can download the windows recovery console and transfer via USB?

PS, I have CA anti virus software. I opened the program via task manager and disabled the real-time scanning, will this suffice for disabling the antivirus?

Thanks again for your help,
Vaughan
Go to the top of the page
 
+Quote Post
Transience
post Jul 4 2009, 07:08 AM
Post #5


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Now we have to go really old school tongue.gif. We used to do manual installs of the recovery console via ComboFix but its creator automated the process... however the old manual procedure should hopefully do the trick and is actually fairly simple.

On a clean computer, visit this page: http://www.microsoft.com/downloads/details...;displaylang=en. Download the boot disk file (this is what we will need to install the recovery console) and save it to your USB drive.

Once that's done, transfer it to your desktop on the infected computer like you did with the Combo-Fix.exe file. Then, in order to start ComboFix, instead of double-clicking on Combo-Fix.exe, in a Windows Explorer window, drag and drop the recovery console package into the Combo-Fix.exe file like such (except you won't be doing it your desktop but this is the general idea):



You should see prompts similar or identical to the ones I described for the automatic RC install previously, follow those and go ahead with running ComboFix as detailed above.

QUOTE
PS, I have CA anti virus software. I opened the program via task manager and disabled the real-time scanning, will this suffice for disabling the antivirus?

That's probably sufficient it would be worth looking through the task manager process list for any processes that belong to it and killing those before you start CF. Not a huge deal but something to try.

Just need the CF log if you can get it for me in your next reply.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 5 2009, 03:56 AM
Post #6


Member
**
Posts: 20
OS: Windows XP



OK I just downloaded the file, put it on USB, turned on my infected PC aaaand.... the icons and start bar are back like normal!

All I did the other day was put Combo-Fix on there, disable the anti virus and run ComboFix until the point where it tried to download the recovery console. At that point I said No to the download and exited out of the program and shut down.

Should I continue to follow the above process, or is there something different you would like me to try given this development? I can access the internet now as well so, provided the situation is the same next time I turn it on, I should be able to run ComboFix the normal way instead of transferring the file I just put on the USB.

Thanks smile.gif
Go to the top of the page
 
+Quote Post
Transience
post Jul 5 2009, 09:46 AM
Post #7


Unofficial Music Guru
Group Icon
Posts: 2,354
From: Massachusetts, USA
OS: Vista



Okay assuming you can access the internet and your icons start bar etc. are back please continue with running ComboFix per these instructions:

Please click on any of the links below to download Combofix. When you are asked to select the location of the file, please change the name of the file from ComboFix.exe to Combo-Fix.exe, and then save it to your desktop.

Link 1
Link 2
Link 3





Notes:
  • Before running ComboFix, you should disable all Antivirus, Anti-Spyware, and Firewall applications so they don't interfere with its running. You can often do this just by right-clicking on the system tray icon and clicking "Disable" or similar. If you need further instructions for how to disable your program specifically, look here.
  • ComboFix will temporarily disconnect your machine from the internet and change your clock settings, this is normal and both will be restored before the program terminates.
  • Do not attempt to run any programs or click on ComboFix's window while it is running, just allow it to proceed uninterrupted aside from okaying any prompts. It may appear to be doing nothing at times, this is normal, don't worry.
Next:
  • Double click on ComboFix.exe and follow the prompts.
  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Recovery Console, and when prompted, agree to the End-User License Agreement to install it.
* Note: If the Recovery Console is already installed on your computer, ComboFix will ignore the installation routines and continue its malware removal procedures.



Once the Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning. The program will then scan for malware and perform various fixes. You may be asked to reboot, okay the prompt and allow your computer to reboot. Log in as normal and allow ComboFix to complete its run without doing anything else.

When it's finished, the program's log will appear in notepad as well as saving itself to C:\ComboFix.txt. Please include the full contents of the log in your next reply.

Just need the CF log in your next post smile.gif.

Cheers,
Dave
Go to the top of the page
 
+Quote Post
fenzodahl512
post Jul 6 2009, 12:21 AM
Post #8


Trusted Helper
Group Icon
Posts: 9,208
OS: Windows XP



Hello, my name is fenzodahl512 and welcome to Geekstogo..

Transience will be unavailable for a while.. Please complete Transience's last instruction and post the log here for my review smile.gif
Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 6 2009, 05:09 AM
Post #9


Member
**
Posts: 20
OS: Windows XP



Thanks guys, here is the report:


ComboFix 09-07-05.03 - Vaughan Moutrie 06/07/2009 20:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.503.164 [GMT 10:00]
Running from: c:\documents and settings\Vaughan Moutrie\Desktop\Combo-Fix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Outdated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\16982.msp
c:\windows\Installer\1b1a1c.msp
c:\windows\Installer\254235.msp
c:\windows\Installer\2be713.msp
c:\windows\Installer\2e0e0.msp
c:\windows\Installer\3b96f1.msp
c:\windows\Installer\4eb18.msp
c:\windows\Installer\5f23d5.msp
c:\windows\Installer\bb20a9.msp
c:\windows\patch.exe
c:\windows\system\GZSnb77896.drv
c:\windows\system32\DBCS2016.DLL

.
((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\Vaughan Moutrie\Application Data\Malwarebytes
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-27 11:45 . 2009-06-27 11:45 -------- d-----w- c:\program files\ERUNT
2009-06-17 01:27 . 2009-06-27 11:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 01:27 . 2009-06-27 11:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-13 07:09 . 2004-11-06 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-05-24 08:04 . 2008-03-24 23:47 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-05-24 08:04 . 2008-03-24 23:47 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-05-24 08:04 . 2008-03-24 23:47 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-05-24 08:04 . 2008-03-24 23:47 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-05-13 08:52 . 2004-02-28 23:06 -------- d-----w- c:\program files\Winamp
2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\program files\NOS
2009-05-09 07:55 . 2009-05-09 07:55 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-09 07:54 . 2004-02-28 05:18 -------- d-----w- c:\program files\Common Files\Adobe
2007-11-24 04:11 . 2007-11-24 04:10 2083211 -c--a-w- c:\program files\SnapNBurn.exe
2007-11-24 04:07 . 2007-11-24 04:03 4436563 -c--a-w- c:\program files\burn4free_setup.exe
2007-10-22 13:28 . 2007-10-22 13:28 6316925 -c--a-w- c:\program files\picard-setup-0.7.2-2.exe
2007-10-22 13:02 . 2007-10-22 13:02 4089084 -c--a-w- c:\program files\libofa-0.9.3-win32.zip
2005-03-12 00:28 . 2005-03-12 00:27 3304944 -c--a-w- c:\program files\Shareaza_2.1.0.0.exe
2004-11-15 01:30 . 2004-11-15 01:30 1164112 -c--a-w- c:\program files\wrar341.exe
2004-11-15 01:27 . 2004-11-15 01:26 2421920 -c--a-w- c:\program files\winzip90.exe
2004-11-06 11:46 . 2004-11-06 11:46 1094021 -c--a-w- c:\program files\dvdshrink32setup.zip
2004-11-06 11:29 . 2004-11-06 11:28 3987626 -c--a-w- c:\program files\1clickdvdcopysetup.exe
2004-07-23 11:30 . 2004-07-23 11:30 9059382 -c--a-w- c:\program files\mp3ripper.exe
2004-07-22 09:08 . 2004-07-22 09:08 839576 -c--a-w- c:\program files\dvdtm.exe
2004-02-28 04:26 . 2004-02-28 04:26 6207624 -c--a-w- c:\program files\vet-win32-full-10.61.0.03.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-18 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-10 286720]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-27 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-12 234736]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-02 577536]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-5 113664]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-2 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-2 40960]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-18 65588]
UDisk Assistant.lnk - c:\program files\UDisk utility 1.00.12\UDisk.exe [2009-1-29 532480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tmod.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sierra\\hl.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [29/09/2008 1:01 PM 24652]
S1 tmod;DRAM Cash Driver;c:\windows\system32\tmod.sys [9/03/2009 2:29 PM 0]
S3 LwAdiHid;Logitech WingMan Digital Devices(Auto-Detect);c:\windows\system32\drivers\LwAdiHid.sys [29/06/2004 5:03 PM 20864]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2005-01-17 c:\windows\Tasks\FRU Task 2002-12-03 04:38ewlett-Packard2002-12-03 04:38p psc 1200 series84887B468ABA3F57D76752217D5938688025EB21097200139.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 10:38]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
Notify-tmodkm - tmodkm.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://au.yahoo.com/?fr=fp-yie8
LSP: c:\windows\system32\VetRedir.dll
TCP: {B1063B76-C024-4A97-B58B-1EE36F4D9EFD} = 123.200.191.17 123.200.191.18
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-06 20:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-06 21:03
ComboFix-quarantined-files.txt 2009-07-06 11:03

Pre-Run: 10,783,977,472 bytes free
Post-Run: 10,774,642,688 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

143 --- E O F --- 2009-05-13 11:48
Go to the top of the page
 
+Quote Post
fenzodahl512
post Jul 7 2009, 12:44 AM
Post #10


Trusted Helper
Group Icon
Posts: 9,208
OS: Windows XP



Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
      Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


How's the computer now? smile.gif
Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 8 2009, 02:26 AM
Post #11


Member
**
Posts: 20
OS: Windows XP



Hi Fenzodahl512,

I had a bit of trouble at first, I left it to go overnight and in the morning it looks like the computer had had an auto windows update and restarted itself ([bleep] those things!).

I put it on to go again this morning, a balloon came up saying low virtual memory, but it was still scanning when I left for work. It seems to have gone OK, but hasn't picked up anything. In the Scan tab the Threat Names etc all have 0 results, and the Scan Report page has an empty table. The prompts it gave me throughout were a bit different to what you have said - I cant see a Save as Text button but there is a Save Report As button which I clicked, changed the file type from webpage to text and saved:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, July 8, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, July 07, 2009 21:00:04
Records in database: 2438441
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 79556
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 06:05:54

No malware has been detected. The scan area is clean.

The selected area was scanned.




Also, my mother is trying to learn all this stuff and is following the thread. She asks:
"In the first OTL scan a lot of files dated 2028. Obviously they had to be infected files, and I'm assuming they have been deleted since by MBAM and Combofix, but I was surprised to see no files listed in the Combofix log for files created in the last month - surely there should be some genuine entries there....are they being hidden by malware or something?"

Thanks smile.gif
Go to the top of the page
 
+Quote Post
fenzodahl512
post Jul 8 2009, 02:40 AM
Post #12


Trusted Helper
Group Icon
Posts: 9,208
OS: Windows XP



Uh, you are absolutely right about the date.. Please don't delete it yet.. Currently I'm asking the developer of OTL regarding the case blushing.gif

anyhow, the computer only has 503mb of RAM.. Its quite low comparing with today's programs.. I strongly suggesting you to upgrade to 1gb of RAM at least.. When it comes to RAM, the more RAM, the better it is.. But for general usage, 1gb of RAM should be enough..

Now, since Kaspersky did not detect anything, can you tell me in details about your computer problem if any? Since not all computer problems related with malware.. It could be caused by something else smile.gif

Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 10 2009, 02:54 AM
Post #13


Member
**
Posts: 20
OS: Windows XP



Since the icons and start bar returned, it seems to be running normally...
Go to the top of the page
 
+Quote Post
fenzodahl512
post Jul 10 2009, 02:55 AM
Post #14


Trusted Helper
Group Icon
Posts: 9,208
OS: Windows XP



Hello.. sorry for my late reply.. Please pm me if you didn't receive any response after 36 hours..

Anyhow, I've sent a pm to you.. Run it and post the log here smile.gif
Go to the top of the page
 
+Quote Post
vmoutrie
post Jul 10 2009, 04:10 AM
Post #15


Member
**
Posts: 20
OS: Windows XP



Hey thats OK, no rush smile.gif

Here is the log:

ComboFix 09-07-09.07 - Vaughan Moutrie 10/07/2009 19:10.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.503.169 [GMT 10:00]
Running from: c:\documents and settings\Vaughan Moutrie\Desktop\Combo-Fix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\Vaughan Moutrie\Application Data\Malwarebytes
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-27 11:47 . 2009-06-27 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-27 11:45 . 2009-06-27 11:45 -------- d-----w- c:\program files\ERUNT
2009-06-17 01:27 . 2009-06-27 11:47 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 01:27 . 2009-06-27 11:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-13 07:09 . 2004-11-06 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-05-24 08:04 . 2008-03-24 23:47 26352 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-05-24 08:04 . 2008-03-24 23:47 21488 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-05-24 08:04 . 2008-03-24 23:47 21104 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-05-24 08:04 . 2008-03-24 23:47 161008 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-05-13 08:52 . 2004-02-28 23:06 -------- d-----w- c:\program files\Winamp
2009-05-13 05:15 . 2004-02-06 08:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-05-12 20:38 . 2009-05-09 07:08 -------- d-----w- c:\program files\NOS
2009-05-07 15:32 . 2003-03-31 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 2003-03-31 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-04-14 04:37 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2007-11-24 04:11 . 2007-11-24 04:10 2083211 -c--a-w- c:\program files\SnapNBurn.exe
2007-11-24 04:07 . 2007-11-24 04:03 4436563 -c--a-w- c:\program files\burn4free_setup.exe
2007-10-22 13:28 . 2007-10-22 13:28 6316925 -c--a-w- c:\program files\picard-setup-0.7.2-2.exe
2007-10-22 13:02 . 2007-10-22 13:02 4089084 -c--a-w- c:\program files\libofa-0.9.3-win32.zip
2005-03-12 00:28 . 2005-03-12 00:27 3304944 -c--a-w- c:\program files\Shareaza_2.1.0.0.exe
2004-11-15 01:30 . 2004-11-15 01:30 1164112 -c--a-w- c:\program files\wrar341.exe
2004-11-15 01:27 . 2004-11-15 01:26 2421920 -c--a-w- c:\program files\winzip90.exe
2004-11-06 11:46 . 2004-11-06 11:46 1094021 -c--a-w- c:\program files\dvdshrink32setup.zip
2004-11-06 11:29 . 2004-11-06 11:28 3987626 -c--a-w- c:\program files\1clickdvdcopysetup.exe
2004-07-23 11:30 . 2004-07-23 11:30 9059382 -c--a-w- c:\program files\mp3ripper.exe
2004-07-22 09:08 . 2004-07-22 09:08 839576 -c--a-w- c:\program files\dvdtm.exe
2004-02-28 04:26 . 2004-02-28 04:26 6207624 -c--a-w- c:\program files\vet-win32-full-10.61.0.03.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-07-06_10.59.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-10 08:42 . 2009-07-10 08:42 16384 c:\windows\Temp\Perflib_Perfdata_5dc.dat
+ 2003-03-31 12:00 . 2009-04-30 21:22 25600 c:\windows\system32\jsproxy.dll
- 2003-03-31 12:00 . 2009-03-07 18:33 25600 c:\windows\system32\jsproxy.dll
+ 2009-07-07 10:36 . 2009-04-30 21:22 12800 c:\windows\system32\dllcache\xpshims.dll
- 2006-05-10 05:22 . 2009-03-07 18:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2009-04-30 21:22 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-07-07 17:06 . 2009-03-07 18:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll
+ 2009-07-07 17:06 . 2009-03-07 18:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll
+ 2003-03-31 12:00 . 2009-04-30 21:22 385536 c:\windows\system32\iedkcs32.dll
- 2003-03-31 12:00 . 2009-03-07 18:32 173056 c:\windows\system32\ie4uinit.exe
+ 2003-03-31 12:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe
- 2028-02-28 13:31 . 2009-06-21 02:15 138056 c:\windows\system32\FNTCACHE.DAT
+ 2028-02-28 13:31 . 2009-07-07 17:13 138056 c:\windows\system32\FNTCACHE.DAT
+ 2006-05-10 05:23 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\wininet.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2009-07-07 10:36 . 2009-04-30 21:22 246272 c:\windows\system32\dllcache\ieproxy.dll
+ 2006-10-26 15:44 . 2009-04-30 21:22 385536 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-10-26 15:44 . 2009-04-30 11:21 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-10-26 15:44 . 2009-03-07 18:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-07-07 17:06 . 2009-03-07 18:34 914944 c:\windows\ie8updates\KB969897-IE8\wininet.dll
+ 2009-07-07 17:06 . 2008-07-09 07:38 382840 c:\windows\ie8updates\KB969897-IE8\spuninst\updspapi.dll
+ 2009-07-07 17:06 . 2007-11-30 12:39 231288 c:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe
+ 2009-07-07 17:06 . 2009-03-07 18:33 246784 c:\windows\ie8updates\KB969897-IE8\ieproxy.dll
+ 2009-07-07 17:06 . 2009-03-08 04:09 391536 c:\windows\ie8updates\KB969897-IE8\iedkcs32.dll
+ 2009-07-07 17:06 . 2009-03-07 18:32 173056 c:\windows\ie8updates\KB969897-IE8\ie4uinit.exe
+ 2004-01-21 05:20 . 2009-04-30 21:22 1207808 c:\windows\system32\urlmon.dll
+ 2004-07-07 08:37 . 2009-05-13 05:15 5936128 c:\windows\system32\mshtml.dll
- 2006-10-17 01:57 . 2009-03-07 18:32 1985024 c:\windows\system32\iertutil.dll
+ 2006-10-17 01:57 . 2009-04-30 21:22 1985024 c:\windows\system32\iertutil.dll
+ 2008-10-15 22:21 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2006-05-10 05:23 . 2009-04-30 21:22 1207808 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 15:08 . 2009-05-13 05:15 5936128 c:\windows\system32\dllcache\mshtml.dll
- 2007-05-08 22:44 . 2009-03-07 18:32 1985024 c:\windows\system32\dllcache\iertutil.dll
+ 2007-05-08 22:44 . 2009-04-30 21:22 1985024 c:\windows\system32\dllcache\iertutil.dll
+ 2009-07-07 17:06 . 2009-03-07 18:34 1206784 c:\windows\ie8updates\KB969897-IE8\urlmon.dll
+ 2009-07-07 17:06 . 2009-03-07 18:41 5937152 c:\windows\ie8updates\KB969897-IE8\mshtml.dll
+ 2009-07-07 17:06 . 2009-03-07 18:32 1985024 c:\windows\ie8updates\KB969897-IE8\iertutil.dll
+ 2005-05-12 04:41 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
+ 2006-10-27 04:09 . 2009-04-30 21:22 11064832 c:\windows\system32\ieframe.dll
+ 2007-05-08 22:44 . 2009-04-30 21:22 11064832 c:\windows\system32\dllcache\ieframe.dll
+ 2009-07-07 17:06 . 2009-03-07 18:39 11063808 c:\windows\ie8updates\KB969897-IE8\ieframe.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-01 118784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-10-18 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-10 286720]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-27 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-12 234736]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-02 577536]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-4-5 113664]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-2 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-2 40960]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-18 65588]
UDisk Assistant.lnk - c:\program files\UDisk utility 1.00.12\UDisk.exe [2009-1-29 532480]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tmod.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sierra\\hl.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [29/09/2008 1:01 PM 24652]
S1 tmod;DRAM Cash Driver;c:\windows\system32\tmod.sys [9/03/2009 2:29 PM 0]
S3 LwAdiHid;Logitech WingMan Digital Devices(Auto-Detect);c:\windows\system32\drivers\LwAdiHid.sys [29/06/2004 5:03 PM 20864]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2005-01-17 c:\windows\Tasks\FRU Task 2002-12-03 04:38ewlett-Packard2002-12-03 04:38p psc 1200 series84887B468ABA3F57D76752217D5938688025EB21097200139.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 10:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://au.yahoo.com/?fr=fp-yie8
LSP: c:\windows\system32\VetRedir.dll
TCP: {B1063B76-C024-4A97-B58B-1EE36F4D9EFD} = 123.200.191.17 123.200.191.18
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-10 19:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(412)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2009-07-10 19:23
ComboFix-quarantined-files.txt 2009-07-10 09:23
ComboFix2.txt 2009-07-06 11:04

Pre-Run: 10,584,485,888 bytes free
Post-Run: 10,631,172,096 bytes free

177 --- E O F --- 2009-07-07 17:06
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 7th November 2009 - 10:28 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising