Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

help after limewire


  • Please log in to reply

#1
guestnomore

guestnomore

    New Member

  • Member
  • Pip
  • 8 posts
Hi

I have recently removed Limewire from my pc at work which someone had loaded up, I now seem to have a huge amount of problems - not sure if they are all related but I just want to get back to normal as my work pc is vital to my business.

If I start at the beginning .....

I removed Limewire by deleting the files as it was not appearing in the add / remove programs list which seemed to be all ok.

I then ran adaware and loaded zonealarm which identified a couple of problems
I also realized my antivirus was out of date so I removed Mcaffee (add/remove) and tried to load up Norton antivirus 2006
It was about this time I started getting a message "File or directory c:/$Mft is corrupt"
I have been unable to load up Norton, I have tried AVG and again the installation is failing very early on
I have also noticed the following:

- Ctrl + Alt + Del is not working when in normal start up mode (it does in safe mode)
- I cannot refragment my c drive as the system tells my chkdsk is due - it then scheduled it at start up but does nothing - still have the same message
- I cannot run "CMD" from the start menu
- I get a message at start up stating the paging file is too small
- I get another message at start up saying "Cannot load configuration"

The biggest problem is I do not have any AV not installed - which is worrying the [bleep] out of me,

I have gone through the process recommended before posting here - with limited success

Adaware cleaned a couple of problems
Spy bot found all clean
I couldn't run house call properly - but it did identify something along the lines of "PWstealer" (something like that)
Ewido found about 4900 files infected with dropper.vb.lu

Any help would really be appriciated........please find hijack this file attached

many thanks in advance

pls find my hijack this file

Logfile of HijackThis v1.99.1
Scan saved at 19:36:11, on 03/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\RAAGTAPP.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\keyhook.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\DOWNLO~1\MyWebEx\319\raagtx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Manager\LOCALS~1\Temp\Rar$EX0k.s20\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WebEx PCNow.LNK = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec....rl/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec....rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A89551E8-992E-48D0-A90C-3E78CF66B217} - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pc.mywebexpc.../ra/ieatgpc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  • 0

Advertisements


#2
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :whistling:

Limewire certainly didn't help and I'm sure it brought you some malware, but I don't think your most pressing issue is the result of malware. But we will clean up any that we find and make sure that you're clean. It's always best to rule out malware as the cause of problems.

Do you have your Windows XP disc?

That question usually scares people, so let me clarify that we won't be formatting your drive. That's not a solution, it's failure. But we may need to restore some corrupted files or access the recovery console from your disc.


Now let's run a tool that will give me a detailed report about your computer.
Download WinPFind2.zip and unzip it to your Desktop. It will create a folder named WinPFind2. Do NOT run the program directly from the zip file.
  • Open the folder and double-click on winpfind2.exe to start the program.
  • Keep the standard settings and then in the AddOn-Options box select all the checkboxes listed.
  • Under File Options click Select All
  • Under Other Options put a check to both Show All boxes
  • Please maximize the window in order to be able to view the Status Bar.
  • Now click the Run All Scans button on the toolbar.
  • When the scans are complete click the Simple Report button in the lower right-hand corner to create a report file. Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is, click on it to uncheck it and then please post that report into this topic. After posting please check if the whole report fit into the post. If it did fit, it should say <End of Report> at the end. If not, please post the section that was cut off in a second post.

  • 0

#3
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi Sam, many thanks for looking into this for me.

I have had a little trouble trying to complete the scans, loaded up ok but if I did anything whilst the scan was running it would freeze and stop responding.

I left it to run a couple of times without touching anything. After completing the initial scans it seemed not to give any staus of the "add ons" and do nothing, I un ticked all the add ons, and have managed to get a scan report which you can find below obviously this is without any of the "add ons" - I hope this helps and makes sense,

many thanks


Logfile created on: 09/09/2006 22:42
WinPFind2 by OldTimer - Version 1.0.8 Folder = C:\Documents and Settings\Manager\Desktop\winpfind2\WinPFind2\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)


< All Processes >
c:\program files\d-link\airplus g\airgcfg.exe - (D-Link )
c:\windows\system32\alg.exe - (Microsoft Corporation )
c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe - (Adobe Systems Incorporated )
c:\windows\downlo~1\mywebex\319\atnthost.exe - ( )
\??\c:\windows\system32\csrss.exe - (Microsoft Corporation )
c:\progra~1\common~1\pcsuite\datala~1\datala~1.exe - (Nokia Mobile Phones Ltd. )
c:\program files\dvd43\dvd43_tray.exe - ( )
c:\windows\explorer.exe - (Microsoft Corporation )
c:\windows\system32\ezsp_px.exe - (Easy Systems Japan Ltd. )
c:\program files\ewido anti-spyware 4.0\guard.exe - (Anti-Malware Development a.s. )
c:\program files\hewlett-packard\hp deskjet 1280\toolbox\hpwstbx.exe - (Hewlett-Packard Company )
c:\program files\ipod\bin\ipodservice.exe - (Apple Computer, Inc. )
c:\program files\itunes\ituneshelper.exe - (Apple Computer, Inc. )
c:\program files\java\jre1.5.0_03\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\windows\system32\keyhook.exe - (Silicon Integrated Systems Corporation )
c:\program files\nokia\nokia pc suite 6\launch application 2.exe - (Nokia )
c:\windows\system32\lsass.exe - (Microsoft Corporation )
c:\progra~1\common~1\nokia\mpapi\mpapi3s.exe - (Nokia Corporation )
c:\program files\messenger\msmsgs.exe - (Microsoft Corporation )
c:\program files\sony\md simple burner\netmdsb.exe - (Sony Corporation )
c:\program files\nokia\nokia pc suite 6\pcsync2.exe - (Time Information Services Ltd. )
c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe - (Intuit, Inc. )
c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\windows\downlo~1\mywebex\319\raagtapp.exe - ( )
c:\windows\downlo~1\mywebex\319\raagtx.exe - ( )
c:\windows\system32\services.exe - (Microsoft Corporation )
c:\progra~1\common~1\pcsuite\services\servic~1.exe - (Nokia. )
c:\windows\system32\sistray.exe - (Silicon Integrated Systems Corporation )
c:\windows\system32\slserv.exe - ( )
\systemroot\system32\smss.exe - (Microsoft Corporation )
c:\windows\soundman.exe - (Realtek Semiconductor Corp. )
c:\windows\system32\spoolsv.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\svchost.exe - (Microsoft Corporation )
c:\windows\system32\zonelabs\vsmon.exe - (Zone Labs, LLC )
c:\windows\system32\wdfmgr.exe - (Microsoft Corporation )
\??\c:\windows\system32\winlogon.exe - (Microsoft Corporation )
c:\documents and settings\manager\desktop\winpfind2\winpfind2\winpfind2.exe - (OldTimer Tools )
c:\windows\system32\wscntfy.exe - (Microsoft Corporation )
c:\program files\ani\aniwzcs2 service\wzcsldr2.exe - (Alpha Networks Inc. )
c:\program files\zone labs\zonealarm\zlclient.exe - (Zone Labs, LLC )

< Registry Entries >

[>> Internet Explorer Settings <<]
HKLM->Main\\Start Page - http://www.microsoft...p...ER}&ar=home
HKLM->Main\\Search Page - http://www.microsoft...amp;ar=iesearch
HKLM->Main\\Default_Page_URL - http://www.microsoft...p...&ar=msnhome
HKLM->Main\\Default_Search_URL - http://www.microsoft...amp;ar=iesearch
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page - http://www.bbc.co.uk...y.shtml?id=2340
HKCU->Main\\Search Bar - http://g.msn.com/0SEENUS/SAOS01
HKCU->Main\\Search Page - http://www.microsoft...amp;ar=iesearch
HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm
HKLM->Search\\CustomizeSearch - http://ie.search.msn...st/srchcust.htm
HKLM->Search\\SearchAssistant - http://www.google.com/ie
HKCU->Search\\SearchAssistant - http://ie.search.msn...st/srchasst.htm
HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 0
HKCU->Internet Settings\\ProxyOverride -

[>> BHO's <<]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated )
{53707962-6F74-2D53-2644-206D7942484F} - = C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited )
{AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper = c:\program files\google\googletoolbar2.dll (Google Inc. )

[>> Internet Explorer Bars, Toolbars and Extensions <<]

[HKLM-> Internet Explorer Bars]
{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )

[HKCU-> Internet Explorer Bars]
{21569614-B795-46B1-85F4-E737A8DC09AD} - Shell Search Band = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
{EFA24E62-B078-11D0-89E4-00C04FC9E26E} - History Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
{EFA24E64-B078-11D0-89E4-00C04FC9E26E} - Explorer Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )

[HKLM-> Internet Explorer ToolBars]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar2.dll (Google Inc. )

[HKCU-> Internet Explorer ToolBars]
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar2.dll (Google Inc. )
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar2.dll (Google Inc. )
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} - &Yahoo! Toolbar = Reg Data missing or invalid (File not found))

[HKCU-> Internet Explorer CmdMapping]
{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8192 - Windows Messenger
NextId - 8193

[HKLM-> Internet Explorer Extensions]
{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation )

[HKCU-> Internet Explorer Menu Extensions]
&Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html (Google Inc. )
&Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html (Google Inc. )
Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html (Google Inc. )
Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html (Google Inc. )
Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html (Google Inc. )
Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html (Google Inc. )

[>> Approved Shell Extensions (Non-Microsoft only) <<]

[HKLM-> Approved Shell Extensions]
{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - Autoplay for SlideShow = Reg Data missing or invalid (File not found))
{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = Reg Data missing or invalid (File not found))
{0E6C58A9-F592-4862-B35F-CA45E24003B3} - CloneCD = C:\Program Files\Elaborate Bytes\CloneCD\ElbyVCDShell.dll (Elaborate Bytes )
{40950107-FEA6-4d53-A65F-B2DCBA57DD58} - Nokia Phone Browser = C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll (Nokia )
{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = deskpan.dll (File not found))
{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data missing or invalid (File not found))
{7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = Reg Data missing or invalid (File not found))
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} - SampleView = C:\WINDOWS\system32\ShellvRTF.dll (XSS )
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data missing or invalid (File not found))
{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\system32\hticons.dll (Hilgraeve, Inc. )
{A5110426-177D-4e08-AB3F-785F10B4439C} - Sony Ericsson File Manager = C:\Program Files\Sony Ericsson\Mobile2\File Manager\fmgrgui.dll (Sony Ericsson Mobile Communications AB )
{B41DB860-8EE4-11D2-9906-E49FADC173CA} - WinRAR shell extension = C:\Program Files\WinRAR\rarext.dll ( )
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - iTunes = C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. )
{C0C4375A-5B72-4efe-929D-3B848C3A1E91} - Message View = C:\Program Files\Nokia\Nokia PC Suite 6\MessageView.dll (Nokia )
{FBFE7864-D495-41f0-B7DC-4BB601CC295E} - Contact View = C:\Program Files\Nokia\Nokia PC Suite 6\ContactView.dll (Nokia )

[>> ContextMenuHandlers (Non-Microsoft only) <<]

[HKLM-> ContextMenuHandlers]
* - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s. )
* - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( )
Directory - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s. )
Directory - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( )
Folder - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( )

[>> ColumnHandlers (Non-Microsoft only) <<]

[HKLM-> ColumnHandlers]
Folder - {F9DB5320-233E-11D1-9F84-707F02C10627} - PDF Shell Extension = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc. )

[>> Registry Run Keys <<]
HKLM->Run\\ - (File not found))
HKLM->Run\\Adobe Photo Downloader - "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated )
HKLM->Run\\ANIWZCS2Service - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Alpha Networks Inc. )
HKLM->Run\\CloneCDElbyCDFL - "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL (Elaborate Bytes AG )
HKLM->Run\\DataLayer - C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE (Nokia Mobile Phones Ltd. )
HKLM->Run\\D-Link AirPlus G - C:\Program Files\D-Link\AirPlus G\AirGCFG.exe (D-Link )
HKLM->Run\\dvd43 - C:\Program Files\dvd43\dvd43_tray.exe ( )
HKLM->Run\\ezShieldProtector for Px - C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd. )
HKLM->Run\\iTunesHelper - "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc. )
HKLM->Run\\NeroFilterCheck - C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh )
HKLM->Run\\PCSuiteTrayApplication - C:\Program Files\Nokia\Nokia PC Suite 6\Launch Application 2.exe -onlytray (Nokia )
HKLM->Run\\QuickTime Task - "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. )
HKLM->Run\\Recguard - C:\WINDOWS\SMINST\RECGUARD.EXE ( )
HKLM->Run\\SiS Windows KeyHook - C:\WINDOWS\system32\keyhook.exe (Silicon Integrated Systems Corporation )
HKLM->Run\\SiSUSBRG - C:\WINDOWS\SiSUSBrg.exe (Silicon Integrated Systems Corp. )
HKLM->Run\\Sony Ericsson PC Suite - "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions (Sony Ericsson Mobile Communications AB )
HKLM->Run\\SoundMan - SOUNDMAN.EXE (Realtek Semiconductor Corp. )
HKLM->Run\\SpeedTouch USB Diagnostics - "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon (THOMSON )
HKLM->Run\\SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe (Sun Microsystems, Inc. )
HKLM->Run\\Zone Labs Client - "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Zone Labs, LLC )
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\MSKAGENTEXE - C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe (File not found))
HKCU->Run\\MSMSGS - "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation )
HKCU->Run\\MsnMsgr - "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (File not found))
HKCU->Run\\PcSync - C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (Time Information Services Ltd. )
HKCU->Run\\QuickTime Task - "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. )

[>> Startup Lnks <<]
HKLM->Common Startup - Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated )
HKLM->Common Startup - desktop.ini - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ( )
HKLM->Common Startup - Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation )
HKLM->Common Startup - QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit, Inc. )
HKLM->Common Startup - Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation )
HKLM->Common Startup - WebEx PCNow.LNK - C:\WINDOWS\DOWNLO~1\MyWebEx\319\raagtx.exe ( )
HKCU->Startup - desktop.ini - C:\Documents and Settings\Manager\Start Menu\Programs\Startup\desktop.ini ( )

[>> Disabled MSConfig Items <<]

[>> User Agent Post Platform <<]
SV1 -

[>> AppInit DLLs <<]

[>> Image File Execution Options <<]
Your Image File Name Here without a path - Debugger = ntsd -d

[>> Shell Service Object Delay Load <<]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation )

[>> Shell Execute Hooks <<]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll (Anti-Malware Development a.s. )
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )

[>> Shared Task Scheduler <<]
{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )

[>> Winlogon <<]
UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation )
Shell - Explorer.exe (Microsoft Corporation )
System - (File not found))
Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
Notify\cscdll - cscdll.dll (Microsoft Corporation )
Notify\ScCertProp - wlnotify.dll (Microsoft Corporation )
Notify\Schedule - wlnotify.dll (Microsoft Corporation )
Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
Notify\termsrv - wlnotify.dll (Microsoft Corporation )
Notify\WgaLogon - WgaLogon.dll (Microsoft Corporation )
Notify\wlballoon - wlnotify.dll (Microsoft Corporation )

[>> DNS Name Servers <<]
{01F69B3B-A802-4387-A2DA-315C4D2C0499} - (Realtek RTL8139/810x Family Fast Ethernet NIC)
{07052203-5DA5-44C2-B738-9F79DFCBB119} - (1394 Net Adapter)
{969B6F32-A99C-43A9-AE37-6BE03C076514} - (1394 Net Adapter)
{C48FA0D4-FC70-4B91-BDF1-8277F5520338} - (1394 Net Adapter)

[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000003 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000004 - %SystemRoot%\System32\nwprovau.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )

[>> Protocol Handlers (Non-Microsoft only) <<]
ipp - (File not found))
msdaipp - (File not found))

[>> Protocol Filters (Non-Microsoft only) <<]

< All Services >
Application Layer Gateway Service (ALG) - C:\WINDOWS\System32\alg.exe (Microsoft Corporation ) [On Demand - Running - Win32, running in it's own process]
AT Host Service (atnthost) - "C:\WINDOWS\DOWNLO~1\MyWebEx\319\atnthost.exe" ( ) [Automatic - Running - Win32, running in it's own process]
Windows Audio (AudioSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Computer Browser (Browser) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Cryptographic Services (CryptSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
DCOM Server Process Launcher (DcomLaunch) - C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
DHCP Client (Dhcp) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
DNS Client (Dnscache) - C:\WINDOWS\system32\svchost.exe -k NetworkService (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Error Reporting Service (ERSvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Event Log (Eventlog) - C:\WINDOWS\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
COM+ Event System (EventSystem) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
ewido anti-spyware 4.0 guard (ewido anti-spyware 4.0 guard) - C:\Program Files\ewido anti-spyware 4.0\guard.exe (Anti-Malware Development a.s. ) [Automatic - Running - Win32, running in it's own process]
Fast User Switching Compatibility (FastUserSwitchingCompatibility) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Help and Support (helpsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
iPodService (iPodService) - C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc. ) [On Demand - Running - Win32, running in it's own process]
Server (lanmanserver) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Workstation (lanmanworkstation) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
TCP/IP NetBIOS Helper (LmHosts) - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Network Connections (Netman) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
MD Simple Burner Service (NetMDSB) - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe (Sony Corporation ) [Automatic - Running - Win32, running in it's own process]
Network Location Awareness (NLA) (Nla) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Plug and Play (PlugPlay) - C:\WINDOWS\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
IPSEC Services (PolicyAgent) - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Protected Storage (ProtectedStorage) - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Remote Access Connection Manager (RasMan) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Remote Procedure Call (RPC) (RpcSs) - C:\WINDOWS\system32\svchost -k rpcss (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Security Accounts Manager (SamSs) - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Task Scheduler (Schedule) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Secondary Logon (seclogon) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
System Event Notification (SENS) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Shell Hardware Detection (ShellHWDetection) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
SmartLinkService (SLService) - slserv.exe ( ) [Automatic - Running - Win32, running in it's own process]
Print Spooler (Spooler) - C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
System Restore Service (srservice) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
SSDP Discovery Service (SSDPSRV) - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Windows Image Acquisition (WIA) (stisvc) - C:\WINDOWS\system32\svchost.exe -k imgsvc (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Telephony (TapiSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Terminal Services (TermService) - C:\WINDOWS\System32\svchost -k DComLaunch (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Themes (Themes) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Distributed Link Tracking Client (TrkWks) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Windows User Mode Driver Framework (UMWdf) - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
TrueVector Internet Monitor (vsmon) - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (Zone Labs, LLC ) [Automatic - Running - Win32, running in it's own process]
Windows Time (W32Time) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
WebClient (WebClient) - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Windows Management Instrumentation (winmgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Security Center (wscsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Automatic Updates (wuauserv) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Wireless Zero Configuration (WZCSVC) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]

< Files >

%SystemDrive%

%ProgramFilesDir%

%WinDir%

%System%
C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL - WSUD (Realtek Semiconductor Corp. [Ver = 2.2.20 | Size = 14225408 bytes | Date = 02/09/2004 18:38 | Attr = ])
C:\WINDOWS\SYSTEM32\dfrg.msc - PEC2 ( [Ver = | Size = 41397 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\LegitCheckControl.dll - PTech (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 571184 bytes | Date = 06/19/2006 16:19 | Attr = ])
C:\WINDOWS\SYSTEM32\MRT.exe - PECompact2 (Microsoft Corporation [Ver = 1.19.1565.0 | Size = 8255912 bytes | Date = 08/03/2006 02:22 | Attr = ])
C:\WINDOWS\SYSTEM32\MRT.exe - aspack (Microsoft Corporation [Ver = 1.19.1565.0 | Size = 8255912 bytes | Date = 08/03/2006 02:22 | Attr = ])
C:\WINDOWS\SYSTEM32\ntdll.dll - aspack (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 708096 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - WSUD (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\oembios.bin - PEC2 ( [Ver = | Size = 13107200 bytes | Date = 09/10/2001 23:15 | Attr = ])
C:\WINDOWS\SYSTEM32\rasdlg.dll - Umonitor (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 657920 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wbdbase.deu - winsync ( [Ver = | Size = 1309184 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\WgaTray.exe - PTech (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 304944 bytes | Date = 06/19/2006 16:19 | Attr = ])

%System%\Drivers folder and sub-folders
C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys - PTech ( [Ver = 3.80.05RC | Size = 1300968 bytes | Date = 03/11/2004 22:14 | Attr = ])

%windir% + sub-dirs for System or Hidden files less than 60 days old
C:\WINDOWS\bootstat.dat - ( [Ver = | Size = 2048 bytes | Date = 09/09/2006 11:41 | Attr = S])
C:\WINDOWS\system32\vsconfig.xml - ( [Ver = | Size = 48882 bytes | Date = 09/09/2006 11:42 | Attr = H ])
C:\WINDOWS\system32\zllictbl.dat - ( [Ver = | Size = 4212 bytes | Date = 08/31/2006 14:09 | Attr = H ])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB918899.cat - ( [Ver = | Size = 23751 bytes | Date = 07/28/2006 13:16 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920214.cat - ( [Ver = | Size = 10337 bytes | Date = 07/27/2006 15:00 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920670.cat - ( [Ver = | Size = 10925 bytes | Date = 07/21/2006 10:03 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB921398.cat - ( [Ver = | Size = 13050 bytes | Date = 07/13/2006 15:24 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB921883.cat - ( [Ver = | Size = 10925 bytes | Date = 07/14/2006 17:13 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB922616.cat - ( [Ver = | Size = 10925 bytes | Date = 07/14/2006 16:53 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem100.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem101.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem102.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem103.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem104.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem105.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem106.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem107.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem108.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem109.CAT - ( [Ver = | Size = 9720 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem110.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem111.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem112.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem113.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem114.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem115.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem116.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem117.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem118.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem119.CAT - ( [Ver = | Size = 9851 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem120.CAT - ( [Ver = | Size = 13221 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem121.CAT - ( [Ver = | Size = 13221 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem122.CAT - ( [Ver = | Size = 13221 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem123.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem124.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem125.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem126.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem127.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem128.CAT - ( [Ver = | Size = 12796 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem129.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem130.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem131.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem132.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem133.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem134.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem135.CAT - ( [Ver = | Size = 9853 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem136.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem137.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem138.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem139.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem140.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem141.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem142.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem143.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem144.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem145.CAT - ( [Ver = | Size = 9853 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem146.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem147.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem148.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem149.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem150.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem151.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem152.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem153.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem154.CAT - ( [Ver = | Size = 12798 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem155.CAT - ( [Ver = | Size = 9720 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem156.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem157.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem158.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem159.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem160.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem161.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem162.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem163.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem164.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem165.CAT - ( [Ver = | Size = 9720 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem166.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem167.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem168.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem169.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem170.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem171.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem172.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem173.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem174.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem175.CAT - ( [Ver = | Size = 9845 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem176.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem177.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem178.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem179.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem180.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem181.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem182.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem183.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem37.CAT - ( [Ver = | Size = 9720 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem38.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem39.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem40.CAT - ( [Ver = | Size = 13090 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem41.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem42.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem43.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem44.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem45.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem46.CAT - ( [Ver = | Size = 12665 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem47.CAT - ( [Ver = | Size = 9845 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem48.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem49.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem50.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem51.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem52.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem53.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem54.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem55.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem56.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem57.CAT - ( [Ver = | Size = 9845 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem58.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem59.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem60.CAT - ( [Ver = | Size = 13215 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem61.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem62.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem63.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem64.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem65.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem66.CAT - ( [Ver = | Size = 12790 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem67.CAT - ( [Ver = | Size = 7417 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem68.CAT - ( [Ver = | Size = 7415 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem69.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem70.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem71.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem72.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem73.CAT - ( [Ver = | Size = 7417 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem74.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem75.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem76.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem77.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem78.CAT - ( [Ver = | Size = 7425 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5
  • 0

#4
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
and the 2nd part of the report - taken from where the 1st part finished


-00C04FC295EE}\oem79.CAT - ( [Ver = | Size = 9712 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem80.CAT - ( [Ver = | Size = 13082 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem81.CAT - ( [Ver = | Size = 13082 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem82.CAT - ( [Ver = | Size = 13082 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem83.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem84.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem85.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem86.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem87.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem88.CAT - ( [Ver = | Size = 12657 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem89.CAT - ( [Ver = | Size = 9853 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem90.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem91.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem92.CAT - ( [Ver = | Size = 13223 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem93.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem94.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem95.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem96.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem97.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem98.CAT - ( [Ver = | Size = 10695 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem99.CAT - ( [Ver = | Size = 9853 bytes | Date = 08/04/2006 23:18 | Attr = S])
C:\WINDOWS\system32\config\default.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/09/2006 22:41 | Attr = H ])
C:\WINDOWS\system32\config\SAM.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/09/2006 11:41 | Attr = H ])
C:\WINDOWS\system32\config\SECURITY.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/09/2006 18:42 | Attr = H ])
C:\WINDOWS\system32\config\software.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/09/2006 22:38 | Attr = H ])
C:\WINDOWS\system32\config\system.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/09/2006 11:44 | Attr = H ])
C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/09/2006 23:30 | Attr = H ])
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\7249c039-200c-499d-9f2a-9f7b193f9122 - ( [Ver = | Size = 388 bytes | Date = 08/15/2006 12:10 | Attr = HS])
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred - ( [Ver = | Size = 24 bytes | Date = 08/15/2006 12:10 | Attr = HS])
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\740297f5-fedc-4bd4-9301-b146a0451399 - ( [Ver = | Size = 388 bytes | Date = 08/02/2006 00:07 | Attr = HS])
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\de11f9fd-d494-41d6-8912-85b2bbe1e7dd - ( [Ver = | Size = 388 bytes | Date = 08/12/2006 23:14 | Attr = HS])
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred - ( [Ver = | Size = 24 bytes | Date = 08/02/2006 00:07 | Attr = HS])
C:\WINDOWS\Tasks\Lomac Bar and Dining Rooms 1106508680.job - ( [Ver = | Size = 532 bytes | Date = 09/03/2006 23:00 | Attr = H ])
C:\WINDOWS\Tasks\SA.DAT - ( [Ver = | Size = 6 bytes | Date = 09/09/2006 11:42 | Attr = H ])
CPL files -
C:\WINDOWS\SYSTEM32\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL - (Realtek Semiconductor Corp. [Ver = 2.2.20 | Size = 14225408 bytes | Date = 02/09/2004 18:38 | Attr = ])
C:\WINDOWS\SYSTEM32\appwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\bthprops.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 110592 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\desk.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 135168 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\firewall.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 80384 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 155136 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 358400 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\intl.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\irprops.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 380416 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\joy.cpl - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\jpicpl32.cpl - (Sun Microsystems, Inc. [Ver = 5.0.30.7 | Size = 49265 bytes | Date = 04/13/2005 03:48 | Attr = ])
C:\WINDOWS\SYSTEM32\main.cpl - (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\mmsys.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ncpa.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\odbccp32.cpl - (Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\powercfg.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 114688 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\slcpappl.cpl - ( [Ver = 2, 92, 0, 2 | Size = 454656 bytes | Date = 02/29/2004 15:12 | Attr = ])
C:\WINDOWS\SYSTEM32\sysdm.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\telephon.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\timedate.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 94208 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wscui.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 148480 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\desk.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 135168 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 80384 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 155136 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 358400 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\intl.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\joy.cpl - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\main.cpl - (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl - (Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 114688 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl - (Microsoft Corporation [Ver = 5.1.4111.00 (xpsp_sp2_rtm.040803-2158) | Size = 155648 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 94208 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\wscui.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 148480 bytes | Date = 08/04/2004 13:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])

AllUsers Startup Folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - ( [Ver = | Size = 1757 bytes | Date = 08/21/2006 10:07 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 10/02/2004 03:25 | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk - ( [Ver = | Size = 1725 bytes | Date = 01/13/2005 14:09 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk - ( [Ver = | Size = 1861 bytes | Date = 01/13/2005 18:20 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk - ( [Ver = | Size = 1513 bytes | Date = 11/01/1999 10:26 | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WebEx PCNow.LNK - ( [Ver = | Size = 1455 bytes | Date = 09/09/2006 11:42 | Attr = ])

AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 10/01/2004 20:19 | Attr = HS])
C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache - ( [Ver = | Size = 1751 bytes | Date = 10/14/2005 10:01 | Attr = ])

CurrentUser Startup Folder
C:\Documents and Settings\Manager\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 10/02/2004 03:25 | Attr = HS])

CurrentUser ApplicationData Folder
C:\Documents and Settings\Manager\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 10/01/2004 20:19 | Attr = HS])

DPF files
{1F2F4C9E-6F09-47BC-970D-3C54734667FE} - - CodeBase = http://www.symantec....rl/LSSupCtl.cab
{215B8138-A3CF-44C5-803F-8226143CFC0A} - Trend Micro ActiveX Scan Agent 6.5 - CodeBase = http://housecall65.t...ivex/hcImpl.cab
{3451DEDE-631F-421C-8127-FD793AFC6CC8} - ActiveDataInfo Class - CodeBase = http://www.symantec....rl/SymAData.cab
{44990200-3C9D-426D-81DF-AAB636FA4345} - Symantec SmartIssue - CodeBase = http://www.symantec....trl/tgctlsi.cab
{44990301-3C9D-426D-81DF-AAB636FA4345} - Symantec Script Runner Class - CodeBase = http://www.symantec....trl/tgctlsr.cab
{81025641-DE98-4F76-902A-44F48B3510BE} - - CodeBase = http://housecall65.t...ivex/hcImpl.cab
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - ActiveScan Installer Class - CodeBase = http://acs.pandasoft...free/asinst.cab
{A89551E8-992E-48D0-A90C-3E78CF66B217} - - CodeBase = http://housecall65.t...ivex/hcImpl.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} - Shockwave Flash Object - CodeBase = http://fpdownload.ma...ash/swflash.cab
{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - GpcContainer Class - CodeBase = https://pc.mywebexpc.../ra/ieatgpc.cab

Hosts file = 734 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
# Copyright © 1993-1999 Microsoft Corp. -
# -
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. -
# -
# This file contains the mappings of IP addresses to host names. Each -
# entry should be kept on an individual line. The IP address should -
# be placed in the first column followed by the corresponding host name. -
# The IP address and the host name should be separated by at least one -
# space. -
# -
# Additionally, comments (such as these) may be inserted on individual -
# lines or following the machine name denoted by a '#' symbol. -
# -
# For example: -
# -
# 102.54.94.97 rhino.acme.com # source server -
# 38.25.63.10 x.acme.com # x client host -
-
127.0.0.1 localhost -

< End of report >
  • 0

#5
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
That log is fine. It does show me just what I need to see.
I'm not seeing any malware, but there is on task that I'm curious about. Do you know what this task is for?

C:\WINDOWS\Tasks\Lomac Bar and Dining Rooms 1106508680.job

If not, go to the file and right click on it. Select Properties and tell me what's in the Run box.


Were you able to located your Windows XP disc?
  • 0

#6
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi Sam

thanks for last post, I do not have any great news to share....

I have tried to locate the file as requested but to no avail - I have tried various methods from searching to copy and pasting into the explorer bar but the system finds nothing, however the "Lomac Bar and Dining Rooms" is my business name - not sure if this is of use or if it could hide more sinister stuff.

With regards to the XP disk, my pc came with xp already loaded up so I did not have a specific xp disk per say, I can always go back to where I bought the machine -is there anything specific I should request?

I hope this is offers a degree of help

regards
  • 0

#7
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Chances are that it's fine, but I would like to rule it out. There's a little batch file that you can download that will give us the details of that task.

Download Findlop from this link.
http://www.geekstogo...a...ils&f_id=14

Double click on findlop.bat to run the tool. It will open up a log. Please copy that log and post it here.


===========


Let's see what we can do without the disc.
Click Start -> All Programs -> Accessories -> Command Prompt
Type in chkdsk and hit enter.

It should tell you when it finds errors and corrects them.


===========


We may end up needing a Windows XP installation disc if you need to restore some corrupted files. It would be a good idea to request the installation disc for Windows XP.
  • 0

#8
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi Sam

Please find log as requested from Findlop

- I am going to run the chkdsk now, I have run this on numerous occassions and it doesn't seem to fix anything, is there any specific file or log you require once this is complete?

I will also try and get hold of installation cd for XP tomorrow,

many thanks once again

Log form Findlop - (Just as a note I thought I had removed all Mcaffee components and same for Shareaza, they both seem to have entries here - would the Mcaffee entryprevent a new Anti virus from being installed??)

Volume in drive C has no label.
Volume Serial Number is 4431-4777

Directory of C:\Documents and Settings\Manager\Application Data

15/08/2006 12:16 <DIR> Adobe
25/07/2006 21:47 <DIR> AdobeAUM
21/08/2006 10:29 <DIR> AdobeUM
14/07/2006 21:00 <DIR> Ahead
14/10/2005 10:01 <DIR> APPLEC~1 Apple Computer
01/11/2004 18:54 <DIR> CYBERL~1 CyberLink
25/05/2005 16:00 <DIR> DATALA~1 Datalayer
27/01/2006 11:24 <DIR> Google
18/01/2005 19:29 <DIR> Help
01/11/2004 18:54 <DIR> IDENTI~1 Identities
02/09/2006 22:54 <DIR> Lavasoft
28/07/2006 23:23 <DIR> LEADER~1 Leadertech
22/01/2005 12:02 <DIR> MACROM~1 Macromedia
19/01/2005 12:12 <DIR> MCAFEE~1.COM McAfee.com Personal Firewall
25/05/2005 16:11 <DIR> Nokia
25/05/2005 16:10 <DIR> NOKIAM~1 Nokia Multimedia Player
25/05/2005 15:51 <DIR> PCSUIT~1 PC Suite
18/01/2005 22:39 <DIR> Roxio
01/11/2004 18:54 <DIR> SAMPLE~1 SampleView
08/11/2005 16:59 <DIR> Shareaza
17/06/2005 15:18 <DIR> SONYCO~1 Sony Corporation
19/01/2005 11:48 <DIR> spweng
04/08/2006 23:32 <DIR> Teleca
0 File(s) 0 bytes
23 Dir(s) 60,753,944,576 bytes free
Volume in drive C has no label.
Volume Serial Number is 4431-4777

Directory of C:\Documents and Settings\All Users\Application Data

21/08/2006 10:05 <DIR> Adobe
01/11/2004 18:54 <DIR> Ahead
10/10/2005 14:29 <DIR> APPLEC~1 Apple Computer
01/11/2004 18:54 <DIR> CYBERL~1 CyberLink
20/08/2006 19:12 <DIR> DRIVIN~1 Driving Test Success
21/02/2006 16:36 <DIR> HAZARD~1 Hazard Perception Training
29/08/2006 19:14 <DIR> McAfee.com
15/06/2005 09:18 <DIR> MCAFEE~1.COM McAfee.com Personal Firewall
13/07/2005 18:41 <DIR> Napster
14/10/2005 10:01 1,751 QTSBAN~1 QTSBandwidthCache
30/03/2005 23:45 <DIR> QUICKT~1 QuickTime
13/01/2005 14:17 <DIR> SBT
17/06/2005 15:10 <DIR> SONYCO~1 Sony Corporation
04/08/2006 23:25 <DIR> SONYER~1 Sony Ericsson
03/09/2006 00:05 <DIR> SPYBOT~1 Spybot - Search & Destroy
12/09/2006 13:35 <DIR> Symantec
04/08/2006 23:25 <DIR> Teleca
15/08/2006 12:10 <DIR> WINDOW~1 Windows Genuine Advantage
1 File(s) 1,751 bytes
17 Dir(s) 60,753,948,672 bytes free
Volume in drive C has no label.
Volume Serial Number is 4431-4777

Directory of C:\Program Files

12/09/2006 13:46 <DIR> .
12/09/2006 13:46 <DIR> ..
18/02/2006 16:17 <DIR> 321STU~1 321Studios
19/08/2006 14:44 <DIR> ACTIVE~1 activePDF
25/07/2006 22:27 <DIR> Adobe
01/11/2004 18:55 <DIR> Ahead
13/03/2006 17:20 <DIR> ANI
01/11/2004 18:55 <DIR> AvRack
29/08/2006 19:45 <DIR> COMMON~1 Common Files
01/11/2004 18:55 <DIR> COMPLU~1 ComPlus Applications
01/11/2004 18:56 <DIR> CYBERL~1 CyberLink
13/03/2006 17:20 <DIR> D-Link
08/09/2006 19:35 <DIR> DESIGN~1 DesignPro
25/07/2006 21:42 <DIR> DISC2P~1 Disc2Phone
07/09/2006 14:10 <DIR> dvd43
11/11/2003 21:19 <DIR> ELABOR~1 Elaborate Bytes
07/09/2006 14:10 <DIR> EWIDOA~1.0 ewido anti-spyware 4.0
12/09/2006 12:43 <DIR> FREERE~1 Free Registry Fix
07/09/2006 14:09 <DIR> Google
21/02/2006 16:32 <DIR> HAZARD~1 Hazard Perception 2003-2004
24/08/2006 09:48 <DIR> HEWLET~1 Hewlett-Packard
07/09/2006 14:09 <DIR> INTERN~1 Internet Explorer
23/10/2005 02:29 <DIR> Intuit
10/10/2005 14:30 <DIR> iPod
07/09/2006 14:10 <DIR> iTunes
16/07/2006 16:13 <DIR> Java
05/01/2006 13:47 <DIR> Kodak
02/09/2006 22:54 <DIR> Lavasoft
29/08/2006 19:30 <DIR> McAfee.com
07/09/2006 14:10 <DIR> MESSEN~1 Messenger
13/01/2005 14:17 <DIR> MICROS~1 microsoft frontpage
13/01/2005 14:18 <DIR> MICROS~2 Microsoft Office
20/07/2005 15:52 <DIR> MICROS~3 Microsoft Works
01/11/2004 18:56 <DIR> MOVIEM~1 Movie Maker
21/01/2005 00:31 <DIR> MSN
01/11/2004 18:56 <DIR> MSNGAM~1 MSN Gaming Zone
01/11/2004 18:56 <DIR> NETMEE~1 NetMeeting
25/05/2005 15:50 <DIR> Nokia
01/11/2004 18:56 <DIR> ONLINE~1 Online Services
16/08/2006 01:05 <DIR> OUTLOO~1 Outlook Express
07/09/2006 14:10 <DIR> QUICKT~1 QuickTime
01/11/2004 18:56 <DIR> REALTE~1 Realtek Sound Manager
21/03/2006 21:01 <DIR> SENSEL~1 Senselang
01/11/2004 18:56 <DIR> SILICO~1 Silicon Integrated Systems
01/11/2004 18:56 <DIR> SISVGA~1.59 SiS VGA Utilities V3.59
13/01/2005 14:17 <DIR> SNAPSH~1 Snapshot Viewer
17/06/2005 15:10 <DIR> Sony
17/06/2005 15:10 <DIR> SONYCO~1 Sony Corporation
04/08/2006 23:24 <DIR> SONYER~1 Sony Ericsson
07/09/2006 14:09 <DIR> SPYBOT~1 Spybot - Search & Destroy
12/09/2006 13:46 <DIR> Symantec
18/01/2005 18:45 <DIR> Thomson
01/11/2004 18:56 <DIR> Wanadoo
18/02/2006 18:30 <DIR> WINDOW~2 Windows Media Player
01/11/2004 18:56 <DIR> WINDOW~1 Windows NT
03/09/2006 12:02 <DIR> WinRAR
18/02/2006 18:16 <DIR> XSOFTW~1 X Software
01/11/2004 18:56 <DIR> xerox
29/08/2006 20:04 <DIR> Yahoo!
19/01/2005 11:52 6,655,600 ZLSSET~1.EXE zlsSetup_55_062_004.exe
19/01/2005 11:53 <DIR> ZONELA~1 Zone Labs
1 File(s) 6,655,600 bytes
60 Dir(s) 60,753,944,576 bytes free
  • 0

#9
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Sam
I have now run chkdsk, please find the log created

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Manager>chkdsk
The type of the file system is NTFS.

WARNING! F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
File verification completed.
CHKDSK is verifying indexes (stage 2 of 3)...
Index verification completed.
CHKDSK is recovering lost files.
Recovering orphaned file index[2].php (77913) into directory file 39613.
Recovering orphaned file INDEX_~2.PHP (77913) into directory file 39613.
Recovering orphaned file EARCHI~1 (90195) into directory file 39511.
Recovering orphaned file earchid%3D39954d3b6cefa829e9d832c210e033f7%26search_in%
3Dposts%26result_type%3Dposts&cc=100&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32
&u_tz=60&u_his=5&u_java=true (90195) into directory file 39511.
Recovering orphaned file X-CLIC~1.GIF (91764) into directory file 39613.
Recovering orphaned file x-click-but21[1].gif (91764) into directory file 39613.

CHKDSK is verifying security descriptors (stage 3 of 3)...
Security descriptor verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

75730409 KB total disk space.
16185908 KB in 87944 files.
28812 KB in 5304 indexes.
0 KB in bad sectors.
177365 KB in use by the system.
65536 KB occupied by the log file.
59338324 KB available on disk.

4096 bytes in each allocation unit.
18932602 total allocation units on disk.
14834581 allocation units available on disk.

C:\Documents and Settings\Manager>

End.............
  • 0

#10
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
It's possible, but unlikely, that Mcafee would be interferring with another installation. Regardless, if you've uninstalled the program you can delete those folders that still exist.

We'll run a registry cleaner later.

I need you to run chkdsk again, but this time use this command chkdsk /f
You may be prompted that chkdsk will run at next startup. If so, reboot your computer.

Let me know if you see any improvement.
Are you still getting error messages on startup?
  • 0

#11
guestnomore

guestnomore

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi, I have completed the chkdsk /f - it did require a restart, I have also run the chkdsk again once the system had restarted, please find the results below -


I did not get the c:$Mft error on this particular start up however I do not seems to get it every day, it seems to be every couple of days, not sure if this helps - but It has been displaying all day today so far....


Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Manager>chkdsk
The type of the file system is NTFS.

WARNING! F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
File verification completed.
CHKDSK is verifying indexes (stage 2 of 3)...
Index verification completed.
CHKDSK is verifying security descriptors (stage 3 of 3)...
Security descriptor verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

75730409 KB total disk space.
16197776 KB in 88324 files.
28932 KB in 5326 indexes.
0 KB in bad sectors.
177365 KB in use by the system.
65536 KB occupied by the log file.
59326336 KB available on disk.

4096 bytes in each allocation unit.
18932602 total allocation units on disk.
14831584 allocation units available on disk.

C:\Documents and Settings\Manager>

end
  • 0

#12
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
That sounds somewhat promising. :whistling:
Let me know if you get that error again.

Let's go ahead and clean up your registry now.
Download and install the trial version of Registry Tuneup.
http://www.acelogix.com/regtune.html

Once you run and fix all errors that it finds, reboot your computer and run it again.


Were you able to obtain a Windows disc yet?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP