Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Is the virus/malware gone? [RESOLVED]


  • This topic is locked This topic is locked

#1
tjrburgess

tjrburgess

    New Member

  • Member
  • Pip
  • 9 posts
Hello,

I have been noticing some strange things with my desktop computer and am seeking some help.

2 things I have noticed: 1. There is a red X icon in place of my hard drive icon 2. The windows/temp directory keeps filling up with (random) temporary files for no reason that I know of. It fills to +100 gigs until my hard drive is full with names such as PR287.tmp

I have run Kaspersky, Ad-Aware and Spybot. Is the infection removed?

Below is a copy of my Hyjackthis and Deckards System Scan log.

Thanks for the help and please advise
-Todd

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:23:26 PM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Documents and Settings\Todd\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F46D7EAA-901F-453B-9435-24A963B0FCEB} - F:\WINDOWS\System32\mljjh.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: Append to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1199563039476
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: ljjhhig - F:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe

--
End of file - 7450 bytes

*** DECKARD"S SYSTEM SCAN MAIN TEXT LOG***
Deckard's System Scanner v20071014.68
Run by Todd on 2008-02-24 21:46:01
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
17: 2008-02-25 02:46:03 UTC - RP185 - Deckard's System Scanner Restore Point
16: 2008-02-24 19:38:57 UTC - RP184 - Installed Ad-Aware 2007
15: 2008-02-23 21:04:33 UTC - RP183 - System Checkpoint
14: 2008-02-22 20:12:29 UTC - RP182 - System Checkpoint
13: 2008-02-21 19:12:30 UTC - RP181 - System Checkpoint


-- First Restore Point --
1: 2008-02-10 17:12:04 UTC - RP169 - Removed Ad-Aware 2007


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Todd.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:48:13 PM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Documents and Settings\Todd\Desktop\dss.exe
F:\DOCUME~1\Todd\Desktop\Todd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F46D7EAA-901F-453B-9435-24A963B0FCEB} - F:\WINDOWS\System32\mljjh.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: Append to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1199563039476
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: ljjhhig - F:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe

--
End of file - 7412 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SCDEmu - f:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 ForceWare Intelligent Application Manager (IAM) - f:\program files\nvidia corporation\networkaccessmanager\bin\nsvcappflt.exe <Not Verified; ; app_filter Module>
R2 ForcewareWebInterface (Forceware Web Interface) - "f:\program files\nvidia corporation\networkaccessmanager\apache group\apache2\bin\apache.exe" -k runservice <Not Verified; Apache Software Foundation; Apache HTTP Server>
R3 FLEXnet Licensing Service - "f:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID:
Description: Camera
Device ID: USB\VID_046D&PID_08F0\5&101D9493&0&3
Manufacturer:
Name: Camera
PNP Device ID: USB\VID_046D&PID_08F0\5&101D9493&0&3
Service:


-- Files created between 2008-01-24 and 2008-02-24 -----------------------------

2008-02-24 18:34:23 0 d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 14:38:45 0 d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-02-10 12:11:32 0 d-------- F:\WINDOWS\system32\NtmsData
2008-02-06 19:14:05 0 d-------- F:\Program Files\Windows Live Toolbar
2008-02-06 19:13:30 0 d-------- F:\Documents and Settings\Todd\Contacts
2008-02-06 19:13:15 0 d------c- F:\WINDOWS\system32\DRVSTORE
2008-02-06 19:08:54 0 d--hs--c- F:\Program Files\Common Files\WindowsLiveInstaller
2008-02-06 19:08:44 0 d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-06 09:17:42 0 d-------- F:\Program Files\MSECache


-- Find3M Report ---------------------------------------------------------------

2008-02-24 14:38:45 0 d-------- F:\Program Files\Common Files
2008-02-23 12:48:00 0 d-------- F:\Program Files\Common Files\Adobe
2008-02-23 12:40:56 0 d-------- F:\Documents and Settings\Todd\Application Data\uTorrent
2008-02-09 14:41:41 0 d-------- F:\Documents and Settings\Todd\Application Data\??crosoft.NET
2008-02-09 12:08:13 250767 --ahs---- F:\WINDOWS\system32\hjjlm.ini2
2008-01-31 10:24:53 0 d-------- F:\Program Files\Common Files\??sks
2008-01-18 09:19:49 0 d-------- F:\Documents and Settings\Todd\Application Data\Sun
2008-01-17 22:14:23 1279 --a------ F:\WINDOWS\mozver.dat
2008-01-17 22:06:10 0 d-------- F:\Program Files\Java
2008-01-17 21:58:55 0 d-------- F:\Program Files\Common Files\Java
2008-01-08 07:17:45 0 d-------- F:\Documents and Settings\Todd\Application Data\Help
2008-01-07 07:26:02 0 d--h----- F:\Program Files\InstallShield Installation Information
2008-01-07 07:26:02 0 d-------- F:\Program Files\Infinite Mind LC
2008-01-07 07:25:00 0 d-------- F:\Program Files\Common Files\InstallShield
2008-01-07 07:18:38 0 d-------- F:\Documents and Settings\Todd\Application Data\Adobe
2008-01-07 07:17:35 0 d-------- F:\Program Files\Common Files\Macrovision Shared
2008-01-06 16:37:03 0 d-------- F:\Program Files\Lavasoft
2008-01-06 15:44:02 0 d-------- F:\Program Files\Microsoft Works
2008-01-06 15:43:52 0 d-------- F:\Program Files\MSBuild
2008-01-06 13:55:12 0 d-------- F:\Documents and Settings\Todd\Application Data\Winamp
2008-01-06 01:32:30 0 d-------- F:\Program Files\Temporary
2008-01-06 01:32:19 0 d-------- F:\Program Files\PowerISO
2008-01-05 15:56:22 352256 --a------ F:\WINDOWS\system32\JMRaidTool .exe <Not Verified; JMicron Technology Corp.; JMB36X RAID Configurer>
2008-01-05 15:56:22 0 d-------- F:\Program Files\Messenger
2008-01-05 15:51:45 0 d-------- F:\Program Files\Kaspersky Lab
2008-01-05 15:45:04 0 d-------- F:\Documents and Settings\Todd\Application Data\WinRAR
2008-01-05 15:30:53 0 d-------- F:\Program Files\Movie Maker
2008-01-05 15:30:06 0 d-------- F:\Program Files\Windows NT
2008-01-05 15:16:17 0 d-------- F:\Program Files\Winamp
2008-01-05 15:13:12 0 d-------- F:\Documents and Settings\Todd\Application Data\Macromedia
2008-01-05 15:12:13 0 d-------- F:\Program Files\uTorrent
2008-01-05 15:08:39 0 d-------- F:\Program Files\Online Services
2008-01-05 15:00:41 0 --a------ F:\WINDOWS\nsreg.dat
2008-01-05 15:00:39 0 d-------- F:\Documents and Settings\Todd\Application Data\Mozilla
2008-01-05 14:57:43 0 d--h----- F:\Program Files\WindowsUpdate
2008-01-05 14:39:49 0 d-------- F:\Program Files\Analog Devices
2008-01-05 14:38:13 22 --a------ F:\WINDOWS\FileName
2008-01-05 14:38:08 0 d-------- F:\Program Files\NVIDIA Corporation
2008-01-05 14:31:00 0 d-------- F:\Documents and Settings\Todd\Application Data\Identities
2008-01-05 14:27:34 0 d-------- F:\Program Files\microsoft frontpage
2008-01-05 14:25:48 0 d-------- F:\Program Files\Common Files\MSSoap
2008-01-05 14:25:29 21640 --a------ F:\WINDOWS\system32\emptyregdb.dat
2008-01-05 14:24:45 0 d-------- F:\Program Files\MSN Gaming Zone
2008-01-05 09:16:02 0 d-------- F:\Program Files\Common Files\ODBC
2008-01-05 09:16:00 0 d-------- F:\Program Files\Common Files\SpeechEngines
2008-01-05 09:15:42 62 --ahs---- F:\Documents and Settings\Todd\Application Data\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F46D7EAA-901F-453B-9435-24A963B0FCEB}]
F:\WINDOWS\System32\mljjh.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="F:\WINDOWS\System32\NvCpl.dll" [04/17/2007 03:48 PM]
"nwiz"="nwiz.exe" [04/17/2007 03:48 PM F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\System32\NvMcTray.dll" [04/17/2007 03:48 PM]
"AVP"="F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [12/18/2007 12:43 AM]
"@"="" []
"Acrobat Assistant 8.0"="F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [10/22/2006 11:24 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhig]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 F:\WINDOWS\System32\mljjh

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\autorun.exe




-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

7966 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-02-24 21:51:20 ------------



*** DECKARD"S SYSTEM SCAN EXTRA TEXT LOG***
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 5000+
CPU 1: AMD Athlon™ 64 X2 Dual Core Processor 5000+
Percentage of Memory in Use: 17%
Physical Memory (total/avail): 2046.36 MiB / 1679.08 MiB
Pagefile Memory (total/avail): 3939.06 MiB / 3736.08 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1942.76 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 152.66 GiB total, 33.54 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is Fixed (NTFS) - 114.48 GiB total, 103.1 GiB free.

\\.\PHYSICALDRIVE1 - Maxtor 6L160M0 - 152.66 GiB - 1 partition
\PARTITION0 - Installable File System - 152.66 GiB - C:

\\.\PHYSICALDRIVE0 - Maxtor 6Y120M0 - 114.49 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 114.48 GiB - F:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AV: Kaspersky Anti-Virus v7.0.1.321 (Kaspersky Lab) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="F:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\\Program Files\\uTorrent\\uTorrent.exe"="F:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"F:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="F:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="F:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=F:\Documents and Settings\All Users
APPDATA=F:\Documents and Settings\Todd\Application Data
CLIENTNAME=Console
CommonProgramFiles=F:\Program Files\Common Files
COMPUTERNAME=DESKTOP
ComSpec=F:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=F:
HOMEPATH=\Documents and Settings\Todd
LOGONSERVER=\\DESKTOP
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=F:\WINDOWS\system32;F:\WINDOWS;F:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 67 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4302
ProgramFiles=F:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=F:
SystemRoot=F:\WINDOWS
TEMP=F:\DOCUME~1\Todd\LOCALS~1\Temp
TMP=F:\DOCUME~1\Todd\LOCALS~1\Temp
USERDOMAIN=DESKTOP
USERNAME=Todd
USERPROFILE=F:\Documents and Settings\Todd
windir=F:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Todd (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {926CC8AE-8414-43DF-8EB4-CF26D9C3C663}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 F:\WINDOWS\INF\PCHealth.inf
µTorrent --> "F:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 8.1.1 Professional --> msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Flash Player ActiveX --> F:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
eyeQ --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{B33CD700-6738-11D4-87FE-0080C6F974A2}\setup.exe" -l0x9 -uninst
High Definition Audio Driver Package - KB888111 --> F:\WINDOWS\$NtUninstallKB888111WXP$\spuninst\spuninst.exe
HijackThis 2.0.2 --> "F:\Documents and Settings\Todd\Desktop\HijackThis.exe" /uninstall
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
JMB36X Raid Configurer --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe" -l0x9 -removeonly
Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Kaspersky Anti-Virus 7.0 --> MsiExec.exe /I{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "F:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Save as XPS Add-in for 2007 Microsoft Office programs --> MsiExec.exe /X{90120000-00B1-0409-0000-0000000FF1CE}
Mozilla Firefox (2.0.0.12) --> F:\Program Files\Mozilla Firefox\uninstall\helper.exe
NVIDIA Drivers --> F:\WINDOWS\System32\nvuide.exe UninstallGUI
NVIDIA ForceWare Network Access Manager --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
PowerISO --> "F:\Program Files\PowerISO\uninstall.exe"
SoundMAX --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly
Spybot - Search & Destroy --> "F:\Program Files\Spybot - Search & Destroy\unins000.exe"
Update for Outlook 2007 Junk Email Filter (kb944965) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {EA8C80AA-31D6-43F0-8CD8-CA85479A34F1}
Winamp --> "F:\Program Files\Winamp\UninstWA.exe"
WinRAR archiver --> F:\Program Files\WinRAR\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type450 / Error
Event Submitted/Written: 02/24/2008 09:49:54 PM
Event ID/Source: 8 / crypt32
Event Description:
Failed auto update retrieval of third-party root list sequence number from: <http://www.download....uthrootseq.txt> with error: This operation returned because the timeout period expired.

Event Record #/Type437 / Error
Event Submitted/Written: 02/18/2008 11:09:46 AM
Event ID/Source: 11601 / MsiInstaller
Event Description:
Product: Sins of a Solar Empire -- Disk full: Out of disk space -- Volume: 'F:'; required space: 1,590,148 KB; available space: 1,351,152 KB. Free some disk space and retry.

Event Record #/Type429 / Error
Event Submitted/Written: 02/12/2008 01:19:56 PM
Event ID/Source: 2000 / Microsoft Office 12
Event Description:
Accepted Safe Mode action : Microsoft Office Outlook.

Event Record #/Type428 / Error
Event Submitted/Written: 02/12/2008 01:11:36 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application OUTLOOK.EXE, version 12.0.4518.1014, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type423 / Warning
Event Submitted/Written: 02/09/2008 03:54:27 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{AC76BA86-1033-F400-7760-000000000003}', feature 'PDFMaker' failed during request for component '{58F977F1-0B0D-44A5-BCDD-3B3E0238B430}'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type4427 / Error
Event Submitted/Written: 02/24/2008 06:34:19 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.

Event Record #/Type4426 / Error
Event Submitted/Written: 02/24/2008 06:34:19 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Event Record #/Type4424 / Error
Event Submitted/Written: 02/24/2008 05:59:54 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 59 minutes.
NtpClient has no source of accurate time.

Event Record #/Type4423 / Error
Event Submitted/Written: 02/24/2008 05:59:54 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)

Event Record #/Type4422 / Error
Event Submitted/Written: 02/24/2008 05:29:54 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 29 minutes.
NtpClient has no source of accurate time.



-- End of Deckard's System Scanner: finished at 2008-02-24 21:51:20 ------------

Attached Files


Edited by tjrburgess, 24 February 2008 - 10:36 PM.

  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Don't attach the reports

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
  • 0

#3
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello,

As instructed below are my combofix log and hyjackthis log

COMBOFIX

ComboFix 08-02-25.3 - Todd 2008-02-29 11:36:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1437 [GMT -5:00]
Running from: F:\Documents and Settings\Todd\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

F:\Documents and Settings\Todd\Application Data\CROSOF~1.NET
F:\Documents and Settings\Todd\My Documents\FNTS~1
F:\Documents and Settings\Todd\My Documents\FNTS~2
F:\Documents and Settings\Todd\My Documents\SSTEM~1
F:\Program Files\Common Files\sks~1
F:\Program Files\Temporary
F:\WINDOWS\system32\hjjlm.ini
F:\WINDOWS\system32\hjjlm.ini2
F:\WINDOWS\system32\mcrh.tmp
F:\WINDOWS\system32\ybqsrwqx.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-27 12:56 . 2008-02-27 12:56 54,156 --ah----- F:\WINDOWS\QTFont.qfn
2008-02-27 12:56 . 2008-02-27 12:56 1,409 --a------ F:\WINDOWS\QTFont.for
2008-02-27 12:55 . 2008-02-27 12:56 <DIR> d-------- F:\Program Files\QuickTime
2008-02-27 12:55 . 2008-02-27 12:55 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-27 12:54 . 2008-02-27 12:54 <DIR> d-------- F:\Program Files\Apple Software Update
2008-02-27 12:54 . 2008-02-27 12:54 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple
2008-02-27 11:44 . 2008-02-27 12:01 <DIR> d-------- F:\Documents and Settings\Todd\Application Data\gretl
2008-02-27 11:42 . 2008-02-27 11:42 <DIR> d-------- F:\Program Files\gretl
2008-02-26 10:22 . 2008-02-26 10:22 <DIR> d-------- F:\Program Files\Bonjour
2008-02-24 18:34 . 2008-02-24 18:34 <DIR> d-------- F:\Program Files\Spybot - Search & Destroy
2008-02-24 18:34 . 2008-02-24 18:36 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 14:38 . 2008-02-24 14:38 <DIR> d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-02-10 12:11 . 2008-02-10 12:11 <DIR> d-------- F:\WINDOWS\system32\NtmsData
2008-02-06 19:39 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2008-02-06 19:39 . 2007-07-30 19:19 207,736 --a------ F:\WINDOWS\system32\muweb.dll
2008-02-06 19:39 . 2007-07-30 19:19 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2008-02-06 19:14 . 2008-02-09 14:49 <DIR> d-------- F:\Program Files\Windows Live Toolbar
2008-02-06 19:13 . 2008-02-06 19:13 <DIR> d----c--- F:\WINDOWS\system32\DRVSTORE
2008-02-06 19:13 . 2008-02-06 19:13 <DIR> d-------- F:\Documents and Settings\Todd\Contacts
2008-02-06 19:08 . 2008-02-06 19:12 <DIR> d--hsc--- F:\Program Files\Common Files\WindowsLiveInstaller
2008-02-06 19:08 . 2008-02-06 19:08 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-06 09:17 . 2008-02-06 09:17 <DIR> d-------- F:\Program Files\MSECache
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ F:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ F:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 16:40 6,356,256 --sha-w F:\WINDOWS\system32\drivers\fidbox.dat
2008-02-29 16:39 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-29 16:38 88,244 --sha-w F:\WINDOWS\system32\drivers\fidbox.idx
2008-02-29 16:38 310,048 --sha-w F:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-29 16:38 31,160 --sha-w F:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-26 15:22 --------- d-----w F:\Program Files\Common Files\Adobe
2008-02-24 19:42 --------- d-----w F:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-23 17:40 --------- d-----w F:\Documents and Settings\Todd\Application Data\uTorrent
2008-02-14 08:00 --------- d-----w F:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-09 19:43 --------- d-----w F:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-02-09 17:07 91,700 ----a-w F:\WINDOWS\system32\drivers\klin.dat
2008-02-09 16:08 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-18 03:06 --------- d-----w F:\Program Files\Java
2008-01-18 02:58 --------- d-----w F:\Program Files\Common Files\Java
2008-01-12 04:16 --------- d-----w F:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-08 01:41 15,360 ----a-w F:\WINDOWS\system32\ctfmon .exe
2008-01-07 12:26 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-01-07 12:26 --------- d-----w F:\Program Files\Infinite Mind LC
2008-01-07 12:25 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-01-07 12:17 --------- d-----w F:\Program Files\Common Files\Macrovision Shared
2008-01-07 12:17 --------- d-----w F:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-06 21:37 --------- d-----w F:\Program Files\Lavasoft
2008-01-06 20:44 --------- d-----w F:\Program Files\Microsoft Works
2008-01-06 20:43 --------- d-----w F:\Program Files\MSBuild
2008-01-06 18:55 --------- d-----w F:\Documents and Settings\Todd\Application Data\Winamp
2008-01-06 06:32 --------- d-----w F:\Program Files\PowerISO
2008-01-05 21:05 85,860 ----a-w F:\WINDOWS\system32\drivers\klick.dat
2008-01-05 20:56 352,256 ----a-w F:\WINDOWS\system32\JMRaidTool .exe
2008-01-05 20:51 --------- d-----w F:\Program Files\Kaspersky Lab
2008-01-05 20:16 --------- d-----w F:\Program Files\Winamp
2008-01-05 20:12 --------- d-----w F:\Program Files\uTorrent
2008-01-05 19:39 --------- d-----w F:\Program Files\Analog Devices
2008-01-05 19:38 --------- d-----w F:\Program Files\NVIDIA Corporation
2008-01-05 19:27 --------- d-----w F:\Program Files\microsoft frontpage
2007-12-18 05:44 219,664 ----a-w F:\WINDOWS\system32\klogon.dll
2007-12-14 16:32 12,632 ----a-w F:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w F:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w F:\WINDOWS\system32\oleaut32.dll
.
<pre>
----a-w		   620,152 2008-02-08 14:18:20  F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
----a-w		   843,776 2008-01-05 20:56:22  F:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w		 1,667,584 2008-01-05 20:56:25  F:\Program Files\Messenger\MSMSGS .EXE
----a-w		   200,704 2008-01-05 20:49:46  F:\Program Files\PowerISO\PWRISOVM .EXE
----a-w			15,360 2008-01-08 01:41:09  F:\WINDOWS\system32\ctfmon .exe
----a-w		   352,256 2008-01-05 20:56:22  F:\WINDOWS\system32\JMRaidTool .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F46D7EAA-901F-453B-9435-24A963B0FCEB}]
F:\WINDOWS\System32\mljjh.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="F:\WINDOWS\System32\NvCpl.dll" [2007-04-17 15:48 8429568]
"nwiz"="nwiz.exe" [2007-04-17 15:48 1626112 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\System32\NvMcTray.dll" [2007-04-17 15:48 81920]
"AVP"="F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-12-18 00:43 227856]
"Acrobat Assistant 8.0"="F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhig]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\uTorrent\\uTorrent.exe"=
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"F:\\Program Files\\Bonjour\\mDNSResponder.exe"=

R3 klim5;Kaspersky Anti-Virus NDIS Filter;F:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\autorun.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 17:55:01 F:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- F:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 11:39:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************


Hyjackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:54 AM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\notepad.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Todd\Desktop\New Folder\Todd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F46D7EAA-901F-453B-9435-24A963B0FCEB} - F:\WINDOWS\System32\mljjh.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: Append to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1199563039476
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8B920F3-551F-4F4A-9E1F-EB7D495FF94A}: NameServer = 206.47.244.51 206.47.244.107
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: ljjhhig - F:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe

--
End of file - 7913 bytes

Thanks for the help

Todd
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {F46D7EAA-901F-453B-9435-24A963B0FCEB} - F:\WINDOWS\System32\mljjh.dll (file missing)
O20 - Winlogon Notify: ljjhhig - F:\WINDOWS\


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.


1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
F:\WINDOWS\System32\mljjh.dll
G:\autorun.exe

KillAll::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]

RenV::
----a-w		   620,152 2008-02-08 14:18:20  F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray .exe
----a-w		   843,776 2008-01-05 20:56:22  F:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w		 1,667,584 2008-01-05 20:56:25  F:\Program Files\Messenger\MSMSGS .EXE
----a-w		   200,704 2008-01-05 20:49:46  F:\Program Files\PowerISO\PWRISOVM .EXE
----a-w			15,360 2008-01-08 01:41:09  F:\WINDOWS\system32\ctfmon .exe
----a-w		   352,256 2008-01-05 20:56:22  F:\WINDOWS\system32\JMRaidTool .exe

Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Reboot and post a new HijackThis log
  • 0

#5
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello once again

I followed the directions (at least to the best of my ability) and below are the attached logs

**COMBOFIX***

ComboFix 08-02-25.3 - Todd 2008-02-29 13:23:15.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1684 [GMT -5:00]
Running from: F:\Documents and Settings\Todd\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-27 12:56 . 2008-02-27 12:56 54,156 --ah----- F:\WINDOWS\QTFont.qfn
2008-02-27 12:56 . 2008-02-27 12:56 1,409 --a------ F:\WINDOWS\QTFont.for
2008-02-27 12:55 . 2008-02-27 12:56 <DIR> d-------- F:\Program Files\QuickTime
2008-02-27 12:55 . 2008-02-27 12:55 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-27 12:54 . 2008-02-27 12:54 <DIR> d-------- F:\Program Files\Apple Software Update
2008-02-27 12:54 . 2008-02-27 12:54 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple
2008-02-27 11:44 . 2008-02-27 12:01 <DIR> d-------- F:\Documents and Settings\Todd\Application Data\gretl
2008-02-27 11:42 . 2008-02-27 11:42 <DIR> d-------- F:\Program Files\gretl
2008-02-26 10:22 . 2008-02-26 10:22 <DIR> d-------- F:\Program Files\Bonjour
2008-02-24 18:34 . 2008-02-24 18:34 <DIR> d-------- F:\Program Files\Spybot - Search & Destroy
2008-02-24 18:34 . 2008-02-24 18:36 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 14:38 . 2008-02-24 14:38 <DIR> d-------- F:\Program Files\Common Files\Wise Installation Wizard
2008-02-10 12:11 . 2008-02-10 12:11 <DIR> d-------- F:\WINDOWS\system32\NtmsData
2008-02-06 19:39 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2008-02-06 19:39 . 2007-07-30 19:19 207,736 --a------ F:\WINDOWS\system32\muweb.dll
2008-02-06 19:39 . 2007-07-30 19:19 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2008-02-06 19:14 . 2008-02-09 14:49 <DIR> d-------- F:\Program Files\Windows Live Toolbar
2008-02-06 19:13 . 2008-02-06 19:13 <DIR> d----c--- F:\WINDOWS\system32\DRVSTORE
2008-02-06 19:13 . 2008-02-06 19:13 <DIR> d-------- F:\Documents and Settings\Todd\Contacts
2008-02-06 19:08 . 2008-02-06 19:12 <DIR> d--hsc--- F:\Program Files\Common Files\WindowsLiveInstaller
2008-02-06 19:08 . 2008-02-06 19:08 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-06 09:17 . 2008-02-06 09:17 <DIR> d-------- F:\Program Files\MSECache
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ F:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ F:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 18:25 6,531,872 --sha-w F:\WINDOWS\system32\drivers\fidbox.dat
2008-02-29 18:25 316,704 --sha-w F:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-29 18:20 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-29 18:19 90,404 --sha-w F:\WINDOWS\system32\drivers\fidbox.idx
2008-02-29 18:19 31,640 --sha-w F:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-29 18:04 --------- d-----w F:\Program Files\PowerISO
2008-02-26 15:22 --------- d-----w F:\Program Files\Common Files\Adobe
2008-02-24 19:42 --------- d-----w F:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-23 17:40 --------- d-----w F:\Documents and Settings\Todd\Application Data\uTorrent
2008-02-14 08:00 --------- d-----w F:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-09 19:43 --------- d-----w F:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-02-09 17:07 91,700 ----a-w F:\WINDOWS\system32\drivers\klin.dat
2008-02-09 16:08 --------- d-----w F:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-18 03:06 --------- d-----w F:\Program Files\Java
2008-01-18 02:58 --------- d-----w F:\Program Files\Common Files\Java
2008-01-12 04:16 --------- d-----w F:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-08 01:41 15,360 ----a-w F:\WINDOWS\system32\ctfmon.exe
2008-01-07 12:26 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-01-07 12:26 --------- d-----w F:\Program Files\Infinite Mind LC
2008-01-07 12:25 --------- d-----w F:\Program Files\Common Files\InstallShield
2008-01-07 12:17 --------- d-----w F:\Program Files\Common Files\Macrovision Shared
2008-01-07 12:17 --------- d-----w F:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-06 21:37 --------- d-----w F:\Program Files\Lavasoft
2008-01-06 20:44 --------- d-----w F:\Program Files\Microsoft Works
2008-01-06 20:43 --------- d-----w F:\Program Files\MSBuild
2008-01-06 18:55 --------- d-----w F:\Documents and Settings\Todd\Application Data\Winamp
2008-01-05 21:05 85,860 ----a-w F:\WINDOWS\system32\drivers\klick.dat
2008-01-05 20:56 352,256 ----a-w F:\WINDOWS\system32\JMRaidTool.exe
2008-01-05 20:51 --------- d-----w F:\Program Files\Kaspersky Lab
2008-01-05 20:16 --------- d-----w F:\Program Files\Winamp
2008-01-05 20:12 --------- d-----w F:\Program Files\uTorrent
2008-01-05 19:39 --------- d-----w F:\Program Files\Analog Devices
2008-01-05 19:38 --------- d-----w F:\Program Files\NVIDIA Corporation
2008-01-05 19:27 --------- d-----w F:\Program Files\microsoft frontpage
2007-12-18 05:44 219,664 ----a-w F:\WINDOWS\system32\klogon.dll
2007-12-14 16:32 12,632 ----a-w F:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w F:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w F:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="F:\WINDOWS\System32\NvCpl.dll" [2007-04-17 15:48 8429568]
"nwiz"="nwiz.exe" [2007-04-17 15:48 1626112 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\System32\NvMcTray.dll" [2007-04-17 15:48 81920]
"AVP"="F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-12-18 00:43 227856]
"Acrobat Assistant 8.0"="F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-02-08 09:18 620152]
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\uTorrent\\uTorrent.exe"=
"F:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"F:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"F:\\Program Files\\Bonjour\\mDNSResponder.exe"=

R3 klim5;Kaspersky Anti-Virus NDIS Filter;F:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 17:55:01 F:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- F:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 13:25:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

***HYJACKTHIS***
.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:25:46 PM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\explorer.exe
F:\WINDOWS\system32\notepad.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Documents and Settings\Todd\Desktop\Todd.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - F:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "F:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: Append to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - F:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1199563039476
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8B920F3-551F-4F4A-9E1F-EB7D495FF94A}: NameServer = 206.47.244.51 206.47.244.107
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - F:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - F:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - F:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - F:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe

--
End of file - 7603 bytes

Thanks for the help
-Todd
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Looking good

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Also tell me how your PC is running
  • 0

#7
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Hello again,

As requested I ran the Kaspersky online. Below is the following log. As for problems with my desktop. I still have notices 2 reoccurring problems. The red X appears as my hard drive icon and 2. when you click on the drive icon (in my computer) it open the search function instead of the open (explore) function

Thanks again
-Todd

------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, February 29, 2008 6:08:27 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/02/2008
Kaspersky Anti-Virus database records: 590811
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 79251
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:14:31

Infected Object Name / Virus Name / Last Action
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{89348615-8377-4DB4-962D-A9BC0B8A6B2C}\RP191\change.log Object is locked skipped
F:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\cert8.db Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\history.dat Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\key3.db Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\parent.lock Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\search.sqlite Object is locked skipped
F:\Documents and Settings\Todd\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\urlclassifier2.sqlite Object is locked skipped
F:\Documents and Settings\Todd\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\Cache\_CACHE_001_ Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\Cache\_CACHE_002_ Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\Cache\_CACHE_003_ Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Application Data\Mozilla\Firefox\Profiles\xr8dyjt3.default\Cache\_CACHE_MAP_ Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
F:\Documents and Settings\Todd\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Todd\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\Todd\ntuser.dat.LOG Object is locked skipped
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\access_log Object is locked skipped
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error.log Object is locked skipped
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error_log Object is locked skipped
F:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\ssl_request_log Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{89348615-8377-4DB4-962D-A9BC0B8A6B2C}\RP191\change.log Object is locked skipped
F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
F:\WINDOWS\SchedLgU.Txt Object is locked skipped
F:\WINDOWS\SoftwareDistribution\EventCache\{09E8A566-2678-4075-AF51-B771645BDA4A}.bin Object is locked skipped
F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
F:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
F:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
F:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\default Object is locked skipped
F:\WINDOWS\system32\config\default.LOG Object is locked skipped
F:\WINDOWS\system32\config\Internet.evt Object is locked skipped
F:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
F:\WINDOWS\system32\config\OSession.evt Object is locked skipped
F:\WINDOWS\system32\config\SAM Object is locked skipped
F:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
F:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\SECURITY Object is locked skipped
F:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
F:\WINDOWS\system32\config\software Object is locked skipped
F:\WINDOWS\system32\config\software.LOG Object is locked skipped
F:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\system Object is locked skipped
F:\WINDOWS\system32\config\system.LOG Object is locked skipped
F:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
F:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
F:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
F:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
F:\WINDOWS\system32\h323log.txt Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
F:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Thats just a left over

Open Notepad and Copy (Control+C) and Paste (Control+V) the following code into the Notepad window.


@ECHO OFF
If exist DrvIconQuery.txt Del DrvIconQuery.txt
Echo Report>>DrvIconQuery.txt
Echo %date% %time% >>DrvIconQuery.txt
Echo.>>DrvIconQuery.txt
@ECHO Working.......
Reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /s >> DrvIconQuery.txt
start notepad DrvIconQuery.txt


Click on 'File' then 'Save As'
In the Save in drop down box select Desktop
In the File name box type in FixService.bat
In the Save as type drop down box select All Files
Close Notepad.

Now, find FixService.bat on your Desktop and Double click it
A window will open and close, do not be concerned this is normal.


Make sure you attach the report in your reply
  • 0

#9
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
The step as instructed has been completed.

Below is the log



Please Advice
-Todd

Report
Fri 02/29/2008 18:44:48.95


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
IconUnderline REG_NONE 03000000

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
TaskbarSizeMove REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder
Type REG_SZ group
Text REG_SZ @shell32.dll,-30498
Bitmap REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,4
HelpID REG_SZ shell.hlp#51140

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ClassicViewState
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30506
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ ClassicViewState
CheckedValue REG_DWORD 0x0
UncheckedValue REG_DWORD 0x1
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51076

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ControlPanelInMyComputer
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\HideMyComputerIcons
Text REG_SZ @shell32.dll,-30497
Type REG_SZ checkbox
ValueName REG_SZ {21EC2020-3AEA-1069-A2DD-08002B30309D}
CheckedValue REG_DWORD 0x0
UncheckedValue REG_DWORD 0x1
DefaultValue REG_DWORD 0x1
HKeyRoot REG_DWORD 0x80000001
HelpID REG_SZ shell.hlp#51150

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DesktopProcess
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30507
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ SeparateProcess
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51079

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DesktopProcess\Policy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DesktopProcess\Policy\SeparateProcess
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\DisableThumbCache
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30517
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ DisableThumbnailCache
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51155

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\FolderSizeTip
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30514
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ FolderContentsInfoTip
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\FriendlyTree
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30511
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ FriendlyTree
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51149
DefaultValue REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden
Text REG_SZ @shell32.dll,-30499
Type REG_SZ group
Bitmap REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,4
HelpID REG_SZ shell.hlp#51131

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Text REG_SZ @shell32.dll,-30501
Type REG_SZ radio
CheckedValue REG_DWORD 0x2
ValueName REG_SZ Hidden
DefaultValue REG_DWORD 0x2
HKeyRoot REG_DWORD 0x80000001
HelpID REG_SZ shell.hlp#51104

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Text REG_SZ @shell32.dll,-30500
Type REG_SZ radio
CheckedValue REG_DWORD 0x1
ValueName REG_SZ Hidden
DefaultValue REG_DWORD 0x2
HKeyRoot REG_DWORD 0x80000001
HelpID REG_SZ shell.hlp#51105

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30503
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ HideFileExt
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x1
HelpID REG_SZ shell.hlp#51101

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\NetCrawler
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30509
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ NoNetCrawling
CheckedValue REG_DWORD 0x0
UncheckedValue REG_DWORD 0x1
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51147

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\NetCrawler\Policy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\NetCrawler\Policy\NoNetCrawling
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\PersistBrowsers
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30513
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ PersistBrowsers
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51152
DefaultValue REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowCompColor
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30512
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ ShowCompColor
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x1
HelpID REG_SZ shell.hlp#51130

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowFullPath
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30504
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
ValueName REG_SZ FullPath
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51100

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowFullPathAddress
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30505
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState
ValueName REG_SZ FullPathAddress
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x1
HelpID REG_SZ shell.hlp#51107

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\ShowInfoTip
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30502
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ ShowInfoTip
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
DefaultValue REG_DWORD 0x1
HelpID REG_SZ shell.hlp#51102

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30508
WarningIfNotDefault REG_SZ @shell32.dll,-28964
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ ShowSuperHidden
CheckedValue REG_DWORD 0x0
UncheckedValue REG_DWORD 0x1
DefaultValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51103

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden\Policy\DontShowSuperHidden
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets
Bitmap REG_SZ F:\WINDOWS\system32\\SHELL32.DLL,4
Type REG_SZ group
Text REG_SZ Managing pairs of Web pages and folders
HelpID REG_SZ TBD

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\AUTO
DefaultValue REG_DWORD 0x0
CheckedValue REG_DWORD 0x0
HKeyRoot REG_DWORD 0x80000001
ValueName REG_SZ NoFileFolderConnection
Type REG_SZ radio
Text REG_SZ Show and manage the pair as a single file
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer
HelpID REG_SZ TBD

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\NOHIDE
DefaultValue REG_DWORD 0x0
CheckedValue REG_DWORD 0x2
HKeyRoot REG_DWORD 0x80000001
ValueName REG_SZ NoFileFolderConnection
Type REG_SZ radio
Text REG_SZ Show both parts but manage as a single file
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer
HelpID REG_SZ TBD

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Thickets\NONE
DefaultValue REG_DWORD 0x0
CheckedValue REG_DWORD 0x1
HKeyRoot REG_DWORD 0x80000001
ValueName REG_SZ NoFileFolderConnection
Type REG_SZ radio
Text REG_SZ Show both parts and manage them individually
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer
HelpID REG_SZ TBD

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\WebViewBarricade
Type REG_SZ checkbox
Text REG_SZ @shell32.dll,-30510
HKeyRoot REG_DWORD 0x80000001
RegPath REG_SZ Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ValueName REG_SZ WebViewBarricade
CheckedValue REG_DWORD 0x1
UncheckedValue REG_DWORD 0x0
HelpID REG_SZ shell.hlp#51148
DefaultValue REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey\15
RegisteredApp REG_SZ Mail

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey\16
Association REG_SZ .cda

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey\17
ShellExecute REG_SZ ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey\18
ShellExecute REG_SZ calc.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AppKey\7
Association REG_SZ http

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations
XMLLookup REG_SZ http://shell.windows...ass...x&Ext=%s
Application REG_SZ http://shell.windows...edir.asp?Ext=%s
intl REG_SZ http://shell.windows...ass...x&Ext=%s

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID
346617CD-E9F1-4891-B1D1-FA3694F368E7 REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\Files
*setup*.exe REG_SZ
*instal*.exe REG_SZ
*setup*.bat REG_SZ
*instal*.bat REG_SZ
*setup*.cmd REG_SZ
*instal*.cmd REG_SZ
*setup*.com REG_SZ
*instal*.com REG_SZ
Y?kle* REG_SZ
Felrak.exe REG_SZ
Imposta.exe REG_SZ
KUR.exe REG_SZ
Ayarla.exe REG_SZ
sfc2.ico REG_SZ
evanims REG_SZ
00000001.tmp REG_SZ
updmoney.exe REG_SZ
hs\media\y\11399\11399_cd_fp.jpg REG_SZ
hs\media\y\9953\9953_cd_fp.jpg REG_SZ
hs\media\y\9951\9951_cd_fp.jpg REG_SZ
hs\media\y\9964\9964_cd_fp.jpg REG_SZ
hs\media\y\9968\9968_cd_fp.jpg REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\MusicFilesContentHandler
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-225

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\MusicFilesContentHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\MusicFilesContentHandler\EventHandlers\MediaArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\MusicFilesContentHandler\FriendlyName
Content REG_SZ music files
IconLabel REG_SZ Music files (WMA/MP3)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\PicturesContentHandler
DefaultIcon REG_EXPAND_SZ shimgvw.dll,3

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\PicturesContentHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\PicturesContentHandler\EventHandlers\DeviceArrival
ShowPicturesOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\PicturesContentHandler\EventHandlers\MediaArrival
ShowPicturesOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\PicturesContentHandler\FriendlyName
Content REG_SZ picture files
IconLabel REG_SZ Pictures

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\VideoFilesContentHandler
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-224

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\VideoFilesContentHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\VideoFilesContentHandler\EventHandlers\MediaArrival

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeHandlers\VideoFilesContentHandler\FriendlyName
Content REG_SZ video files
IconLabel REG_SZ Video

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\MusicFilesContentSniffer
ContentTypeHandler REG_SZ MusicFilesContentHandler
RelPattern REG_MULTI_SZ *.wma\0HIFI\*\*.wma\0*.mp3\0HIFI\*\*.mp3\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\PicturesContentSniffer
ContentTypeHandler REG_SZ PicturesContentHandler
RelPattern REG_MULTI_SZ *.bmp\0DCIM\*\*.bmp\0*.jpg\0DCIM\*\*.jpg\0*.gif\0DCIM\*\*.gif\0DC*\*.jpg\0*.tif\0MSSONY\*\*.tif\0IM*\*.jpg\0CAMERA01\*.jpg\0DC*\BR*\*.jpg\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer
ContentTypeHandler REG_SZ VideoFilesContentHandler
RelPattern REG_MULTI_SZ *.mpg\0VIDEO\*.mpg\0*.mpeg\0VIDEO\*.mpeg\0*.asf\0VIDEO\*.asf\0MSSONY\*\*.mpg\0MSSONY\*\*.mpeg\0*.wmv\0VIDEO\*.wmv\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceClasses

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceClasses\{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceClasses\{CC7BFB41-F175-11D1-A392-00E0291F3959}
DeviceHandlers REG_SZ VideoCameraDeviceHandler
Label REG_SZ @F:\Program Files\Movie Maker\wmmres.dll,-61827
Icons REG_MULTI_SZ F:\WINDOWS\System32\shell32.dll,-317\0\0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\Camera
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-309\0\0
Label REG_SZ Digital Camera

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\CellPhone
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-310\0\0
Label REG_SZ Cell Phone

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\CFStorage
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-303\0\0
Label REG_SZ CompactFlash Reader/Writer

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\ClikDrive
Label REG_SZ Clik! Drive
NoSoftEject REG_SZ 0x00000001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\FaxDevice
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-196\0\0
Label REG_SZ Fax Machine

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\ImageMate
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-229\0\0
NoMediaIcons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-229\0\0
Label REG_SZ ImageMate
NoSoftEject REG_SZ 0x00000001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\JazDrive
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-312\0\0
Label REG_SZ Jaz Drive

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\MemoryStick
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-305\0\0
Label REG_SZ Memory Stick
NoSoftEject REG_SZ 0x00000001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\MemoryStick-MG
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-233\0\0
Label REG_SZ Memory Stick - MG
NoSoftEject REG_SZ 0x00000001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\OpticalDrive
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-301\0\0
Label REG_SZ Optical Drive

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\PCMCIAStorage
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-306\0\0
Label REG_SZ PCMCIA Storage Device

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\PocketPC
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-314\0\0
Label REG_SZ Pocket PC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\PortableAudioPlayer
Label REG_SZ Portable Audio Player
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-299\0\0
NoSoftEject REG_SZ 0x00000001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\Printer
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-17\0\0
Label REG_SZ Printer

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\Scanner
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-315\0\0
Label REG_SZ Scanner

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\SMStorage
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-308\0\0
Label REG_SZ SmartMedia Reader/Writer

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\TapeDrive
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-300\0\0
Label REG_SZ Tape Drive

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\VideoCamera
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-317\0\0
Label REG_SZ Digital Video Camera

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\ZipDrive100
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-230\0\0
Label REG_SZ Zip Drive 100

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceGroups\ZipDrive250
Icons REG_MULTI_SZ %SystemRoot%\system32\shell32.dll,-230\0\0
Label REG_SZ Zip Drive 250

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CompaqPA1Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CompaqPA1Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CompaqPA1Handler\EventHandlers\DeviceArrival
CompaqPA1Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIcHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIcHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIcHandler\EventHandlers\DeviceArrival
CreativeNomadIIcArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIHandler\EventHandlers\DeviceArrival
CreativeNomadIIArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIMGHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIMGHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadIIMGHandler\EventHandlers\DeviceArrival
CreativeNomadIIMGArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadJukeboxHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadJukeboxHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\CreativeNomadJukeboxHandler\EventHandlers\DeviceArrival
CreativeNomadJukeboxArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DigisetteDuo64Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DigisetteDuo64Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DigisetteDuo64Handler\EventHandlers\DeviceArrival
DigisetteDuo64Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DLinkDMP110Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DLinkDMP110Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\DLinkDMP110Handler\EventHandlers\DeviceArrival
DLinkDMP110Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\GenericVolumeHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\GenericVolumeHandler\ContentTypes
MusicFilesContentSniffer REG_SZ
PicturesContentSniffer REG_SZ
VideoFilesContentSniffer REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\GenericVolumeHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\GenericVolumeHandler\EventHandlers\DeviceArrival
GenericVolumeArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\GenericVolumeHandler\EventHandlers\MediaArrival
GenericVolumeArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Intel3000Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Intel3000Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Intel3000Handler\EventHandlers\DeviceArrival
Intel3000Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IntelPocketConcertHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IntelPocketConcertHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IntelPocketConcertHandler\EventHandlers\DeviceArrival
IntelPocketConcertArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IomegaHipZipHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IomegaHipZipHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\IomegaHipZipHandler\EventHandlers\DeviceArrival
IomegaHipZipArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\NikepsaplayHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\NikepsaplayHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\NikepsaplayHandler\EventHandlers\DeviceArrival
NikepsaplayArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Ravemp2300Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Ravemp2300Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Ravemp2300Handler\EventHandlers\DeviceArrival
Ravemp2300Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio600Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio600Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio600Handler\EventHandlers\DeviceArrival
Rio600Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio800Handler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio800Handler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\Rio800Handler\EventHandlers\DeviceArrival
Rio800Arrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\RioOneHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\RioOneHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\RioOneHandler\EventHandlers\DeviceArrival
RioOneArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\VideoCameraDeviceHandler

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\VideoCameraDeviceHandler\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\VideoCameraDeviceHandler\EventHandlers\DeviceArrival
VideoCameraArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\AutorunINFLegacyArrival
MSOpenFolder REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\CompaqPA1Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\CreativeNomadIIArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\CreativeNomadIIcArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\CreativeNomadIIMGArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\CreativeNomadJukeboxArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\DigisetteDuo64Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\DLinkDMP110Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\GenericVolumeArrival
MSGenericVolumeArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\HandleCDBurningOnArrival
MSCDBurningOnArrival REG_SZ
MSWMPBurnCDOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Intel3000Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\IntelPocketConcertArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\IomegaHipZipArrival
MSWMDMHandler REG_SZ
MSOpenFolder REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\MixedContentOnArrival
MSOpenFolder REG_SZ
BridgeCS3ImportMediaOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\MTPMediaPlayerArrival
WinampMTPHandler REG_SZ
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\NikepsaplayArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayCDAudioOnArrival
MSPlayCDAudioOnArrival REG_SZ
MSOpenFolder REG_SZ
WinampPlayMediaOnArrival REG_SZ
MSRipCDAudioOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayDVDMovieOnArrival
MSPlayDVDMovieOnArrival REG_SZ
MSOpenFolder REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayMusicFilesOnArrival
MSOpenFolder REG_SZ
MSPlayMediaOnArrival REG_SZ
WinampPlayMediaOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayVideoFilesOnArrival
MSOpenFolder REG_SZ
MSPlayMediaOnArrival REG_SZ
WinampPlayMediaOnArrival REG_SZ
BridgeCS3ImportMediaOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Ravemp2300Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Rio600Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\Rio800Arrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\RioOneArrival
MSWMDMHandler REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\ShowPicturesOnArrival
MSWiaEventHandler REG_SZ
MSShowPicturesOnArrival REG_SZ
MSPrintPicturesOnArrival REG_SZ
MSOpenFolder REG_SZ
BridgeCS3ImportMediaOnArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\VideoCameraArrival
MSVideoCameraArrival REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\BridgeCS3ImportMediaOnArrival
Provider REG_SZ Adobe Bridge CS3
InvokeVerb REG_SZ launch
InvokeProgID REG_SZ Adobe.adobebridge
DefaultIcon REG_SZ F:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe,0
Action REG_SZ Download images

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSCDBurningOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-5
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17169
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17170
InvokeProgID REG_SZ Folder
InvokeVerb REG_SZ open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolder
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-5
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17154
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17155
InvokeProgID REG_SZ Folder
InvokeVerb REG_SZ open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayCDAudioOnArrival
Action REG_SZ @wmploc.dll,-6503
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.AudioCD
InvokeVerb REG_SZ play
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayDVDMovieOnArrival
Action REG_SZ @wmploc.dll,-6504
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.DVD
InvokeVerb REG_SZ play
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPlayMediaOnArrival
Action REG_SZ @wmploc.dll,-1800
Provider REG_SZ @wmploc.dll,-6502
InvokeProgid REG_SZ WMP.PlayMedia
InvokeVerb REG_SZ play
DefaultIcon REG_SZ F:\Program Files\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPrintPicturesOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-17
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17158
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17159
InvokeProgID REG_SZ Applications\shimgvw.dll
InvokeVerb REG_SZ print

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTime
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-3
Action REG_SZ Prompt each time
Provider REG_SZ Windows Explorer
ProgID REG_SZ Shell.Autoplay
InitCmdLine REG_SZ PromptEachTime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSPromptEachTimeNoContent
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-3
Action REG_SZ Prompt each time - No Content
Provider REG_SZ Windows Explorer
ProgID REG_SZ Shell.Autoplay
InitCmdLine REG_SZ PromptEachTimeNoContent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSRipCDAudioOnArrival
Action REG_SZ @wmploc.dll,-6506
Provider REG_SZ @wmploc.dll,-6502
InvokeProgID REG_SZ WMP.RipCD
InvokeVerb REG_SZ Rip
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSShowPicturesOnArrival
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-249
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17156
Provider REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17157
InvokeProgID REG_SZ Shell.AutoplayForSlideShow.1
InvokeVerb REG_SZ open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSTakeNoAction
DefaultIcon REG_EXPAND_SZ %SystemRoot%\system32\SHELL32.dll,-338
Action REG_SZ @%SystemRoot%\system32\SHELL32.dll,-17168
Provider REG_SZ <TakeNoAction>
ProgID REG_SZ Shell.AutoplaySpecial

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSVideoCameraArrival
InitCmdLine REG_SZ "F:\Program Files\Movie Maker\moviemk.exe" /RECORD
ProgID REG_SZ Shell.HWEventHandlerShellExecute
DefaultIcon REG_SZ F:\Program Files\Movie Maker\moviemk.exe,0
CLSIDForCancel REG_SZ {AB007EC8-E2D4-4664-ACD9-1D059681F3DE}
Action REG_SZ @F:\Program Files\Movie Maker\wmmres.dll,-61826
Provider REG_SZ @F:\Program Files\Movie Maker\wmmres.dll,-61424

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWiaEventHandler
ProgID REG_SZ WiaDevMgr
Action REG_SZ @%systemroot%\System32\wiaacmgr.exe,-276
Provider REG_SZ @%systemroot%\System32\wiaacmgr.exe,-101
DefaultIcon REG_EXPAND_SZ %systemroot%\System32\wiaacmgr.exe,-2
InvokeProgID REG_SZ WIA.AutoplayDropHandler.1
InvokeVerb REG_SZ open

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMDMHandler
Action REG_SZ Transfer Files
CLSIDForCancel REG_SZ {91778246-9BE4-4713-A651-E833B853CC30}
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0
InitCmdLine REG_EXPAND_SZ "%ProgramFiles%\Windows Media Player\wmplayer.exe" /prefetch:3 /task:PortableDevice
ProgID REG_SZ Shell.HWEventHandlerShellExecute
Provider REG_SZ @wmploc.dll,-6502

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMPBurnCDOnArrival
Action REG_SZ @wmploc.dll,-6505
Provider REG_SZ @wmploc.dll,-6502
InvokeProgid REG_SZ WMP.BurnCD
InvokeVerb REG_SZ Burn
DefaultIcon REG_EXPAND_SZ %ProgramFiles%\Windows Media Player\wmplayer.exe,0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinampMTPHandler
Action REG_SZ Open with Winamp
DefaultIcon REG_SZ F:\Program Files\Winamp\winamp.exe,0
InitCmdLine REG_SZ F:\Program Files\Winamp\winamp.exe
ProgID REG_SZ Shell.HWEventHandlerShellExecute
Provider REG_SZ Winamp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinampPlayMediaOnArrival
Action REG_SZ Play with Winamp
DefaultIcon REG_SZ F:\Program Files\Winamp\winamp.exe,0
InvokeProgid REG_SZ Winamp.File
InvokeVerb REG_SZ Play
Provider REG_SZ Winamp

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket
UseGlobalSettings REG_DWORD 0x1
Percent REG_DWORD 0xa
NukeOnDelete REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\c
VolumeSerialNumber REG_DWORD 0x38250c72
IsUnicode REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\f
VolumeSerialNumber REG_DWORD 0x6ce3ddf0
IsUnicode REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
BrowseNewProcess REG_SZ yes

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
NoExplorer REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}
<NO NAME> REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CD Burning

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\AudioBurnHandlers
<NO NAME> REG_SZ {8dd448e6-c188-4aed-af92-44956194eb1f}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\AudioBurnHandlers\{8dd448e6-c188-4aed-af92-44956194eb1f}
verb REG_SZ WMPBurnAsAudioCD
SupportedFileTypes REG_SZ *.WMA;*.MP3;*.WAV

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\ExcludedFS
UDF REG_SZ
CDUDF REG_SZ
CDUDFRW REG_SZ
UDFREADR REG_SZ
UDF1.50 REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\Flags
desk.cpl REG_DWORD 0x1
access.cpl REG_DWORD 0x1
hdwwiz.cpl REG_DWORD 0x1
keymgr.cpl REG_DWORD 0x1
inetcpl.cpl REG_DWORD 0x1
joy.cpl REG_DWORD 0x1
main.cpl REG_DWORD 0x1
intl.cpl REG_DWORD 0x1
mmsys.cpl REG_DWORD 0x1
sapi.cpl REG_DWORD 0x1
sysdm.cpl REG_DWORD 0x1
telephon.cpl REG_DWORD 0x1
timedate.cpl REG_DWORD 0x1
powercfg.cpl REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Accessibility_Options
IconIndex REG_DWORD 0x6e
Info REG_SZ Customizes accessibility features for your computer.
Module REG_EXPAND_SZ %SystemRoot%\system32\access.cpl
Name REG_SZ Accessibility Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Add-Remove_Programs
IconIndex REG_DWORD 0x5dc
Info REG_SZ Installs and removes programs and Windows components.
Module REG_EXPAND_SZ %SystemRoot%\system32\appwiz.cpl
Name REG_SZ Add/Remove Programs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Date-Time
IconIndex REG_DWORD 0xc8
Info REG_SZ Changes date, time, and time-zone information.
Module REG_EXPAND_SZ %SystemRoot%\system32\timedate.cpl
Name REG_SZ Date/Time

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Dialing_Options
IconIndex REG_DWORD 0x64
Info REG_SZ Configures telephone dialing rules for your location.
Module REG_EXPAND_SZ %SystemRoot%\system32\telephon.cpl
Name REG_SZ Dialing Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Display_Properties
IconIndex REG_DWORD 0x64
Info REG_SZ Customizes your desktop display and screen saver.
Module REG_EXPAND_SZ %SystemRoot%\system32\desk.cpl
Name REG_SZ Display

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Internet_Options
IconIndex REG_DWORD 0x1187
Info REG_SZ Configures your Internet display and connections settings.
Module REG_EXPAND_SZ %SystemRoot%\system32\inetcpl.cpl
Name REG_SZ Internet Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\Printers
IconIndex REG_DWORD 0x12c
Info REG_SZ Adds, removes and changes settings for printers.
Module REG_EXPAND_SZ %SystemRoot%\system32\main.cpl
Name REG_SZ Printers and Faxes
<NO NAME> REG_SZ {2227A280-3AEA-1069-A2DE-08002B30309D}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
<NO NAME> REG_SZ Taskbar and Start Menu

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
<NO NAME> REG_SZ Folder Options

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{7007ACC7-3202-11D1-AAD2-00805FC1270E}
<NO NAME> REG_SZ Network Connections

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D20EA4E1-3957-11d2-A40B-0C5020524152}
<NO NAME> REG_SZ Fonts

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D20EA4E1-3957-11d2-A40B-0C5020524153}
<NO NAME> REG_SZ Administrative Tools

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
<NO NAME> REG_SZ Scheduled Tasks

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{E211B736-43FD-11D1-9EFB-0000F8757FCD}
<NO NAME> REG_SZ Scanners & Cameras

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CSSFilters
oavredirect REG_SZ {999937BC-30FE-11D4-BA52-00C04F6843FA}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{1f4de370-d627-11d1-ba4f-00a0c91eedba}
<NO NAME> REG_SZ Computer Search Results Folder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}
<NO NAME> REG_SZ
Removal Message REG_SZ @mydocs.dll,-900

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}
<NO NAME> REG_SZ Microsoft Office OneNote Namespace Extension for Windows Desktop Search

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}
<NO NAME> REG_SZ Recycle Bin

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}
<NO NAME> REG_SZ Search Results Folder

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DocFolderPaths
Todd REG_SZ F:\Documents and Settings\Todd\My Documents

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon
<NO NAME> REG_SZ %SystemRoot%\system32\shell32.dll,131

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation
KillList REG_SZ %1;explorer.exe;dvdplay.exe;mplay32.exe;msohtmed.exe;quikview.exe;rundll.exe;rund
ll32.exe;taskman.exe;bck32api.dll;
CutList REG_MULTI_SZ Application File\0MFC Application\0\0
AddRemoveApps REG_SZ SETUP.EXE;INSTALL.EXE;ISUNINST.EXE;UNWISE.EXE;UNWISE32.EXE;ST5UNST.EXE;RUNDLL32.<
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Driveicons]


Then double click on the fix.reg file, when it prompts to merge click "Yes".



Reboot your PC and tell me how it's running now
  • 0

#11
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Thanks again for all the help..... Were getting close

The red X icon is now gone, the last issue I have is that when I try to open a drive (say my C drive from my computer) it opens the search function in stead of opening (exploring) the drive

-Todd
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Not sure what is causing that, it's not malware anyway. You would be better off posting in the Windows XP forum about that

Few things to do before that though

Now lets uninstall Combofix:
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
The above procedure will do the following:
  • Delete ComboFix and its associated files and folders.
  • Delete VundoFix backups, if present
  • Delete the C:\Deckard folder, if present
  • Delete the C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.



You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
  • 0

#13
tjrburgess

tjrburgess

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Once again, thats for all the help
-Todd
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP