Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Aurora pop-ups - AGAIN![RESOLVED]


  • This topic is locked This topic is locked

#1
dtrouble

dtrouble

    New Member

  • Member
  • Pip
  • 8 posts
Hi guys,

Please help, had a look at instructions given to others so have tried a few things but still no joy....

As such heres my log...

Logfile of HijackThis v1.99.1
Scan saved at 01:49:19, on 29/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
F:\Hijak\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\system32\winb2s32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [Microsoft Windows Updata] scvhost.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\system32\ap9h4qmo.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [Microsoft Windows Updata] scvhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1113245309452
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\IcePack.exe
O23 - Service: Intel Alert Handler - Intel® Corporation - C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel® Corporation - C:\WINDOWS\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\Program Files\Symantec\Quarantine\Server\qserver.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\ScanExplicit.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Many Thanks :tazz:
  • 0

Advertisements


#2
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi there,

* Please download ewido security suite here: http://www.ewido.net/en/download/
Install and update it. Don't let it scan yet!!

* Reboot into Safe Mode`:
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\system32\winb2s32.dll
O4 - HKLM\..\Run: [Microsoft Windows Updata] scvhost.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\system32\ap9h4qmo.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Updata] scvhost.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


* Click on Fix Checked when finished and exit HijackThis.

*Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.

* Go to start > run and type sc delete SvcProc

* Perform a full scan with ewido.
Let it delete everything it is finding.
When finished, you'll get the option to make a log.
Save this log, because I'll need that later.

Reboot back to normal mode.

Download Findit
Unzip it to your desktop. Make sure the FindIt's.bat and XFind.com are together in the same UNZIPPED folder!

Doubleclick FindIt's.bat. Let it scan and it will produce a log afterwards.

Post a new hijackthislog + the ewido-log + the log from findit's.

If you had any problems with deleting files or noticed any other problems during your fix, let me also know in your next reply.
  • 0

#3
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi miekiemoes,

Sorry about the delay in my reply and many thanks for looking into my issues so fast.

My PC kept crashing whilst I tried to follow your instructions but I finally managed to run all the scans producing each report. Please find attached each report. I await your next instruction.

Yours gratefully,

dtrouble. :tazz:

Attached Files


  • 0

#4
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hello,



* Download Killbox.
Click killbox.exe.
Select the option "Delete on reboot".

Now copy the next bold:

C:\WINDOWS\IIJYCR.EXE
C:\WINDOWS\JQEHWQ~1.EXE
C:\WINDOWS\NAIL.EXE
C:\WINDOWS\SVCPROC.EXE
C:\WINDOWS\System32\70TOVMTO.INI
C:\WINDOWS\System32\AP9H4QMO.INI
C:\WINDOWS\System32\Q17I9A4J.INI
C:\WINDOWS\System32\dice21.ico
C:\WINDOWS\System32\greenmovie2311.ico
C:\WINDOWS\System32\hotbod.ico
C:\WINDOWS\System32\ico_bikini49_gif_32x32.ico
C:\WINDOWS\System32\kill all spyware4.ico
C:\WINDOWS\System32\poker11212.ico
C:\WINDOWS\System32\virushunter1231.ico


Open 'file' in the killboxmenu on top and choose Paste from clipboard

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines must be there together if the files are present!

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

Your computer must reboot now.
Ignore the errors you'll get.

Open hijackthis, check and fix next line again:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Reboot again.

Post back a new hijackthislog and new findit's-log in your next reply.
Could you please copy and paste them in your reply instead of adding as an attachement?
Also, it is important I get a hijackthislog made in normal mode, not from safe mode. :tazz:
Thx.
  • 0

#5
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hello again,

Ok, I managed to run Killbox. But my pc keeps crashing so again it took me some time to get back online to post this.

By the way I took the liberty of running a disk defrag, I hope that was ok. I noticed I have some unmovemable files which I guess is a bad thing, I hope that isnt causing all the crashes. :tazz:

In any event, heres my new HIjackthis log....

Logfile of HijackThis v1.99.1
Scan saved at 21:46:36, on 02/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\cba\pds.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Symantec\Quarantine\Server\qserver.exe
C:\Program Files\Symantec\Quarantine\Server\ScanExplicit.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Symantec\Quarantine\Server\IcePack.exe
C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
C:\WINDOWS\system32\ams_ii\iao.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Norton Personal Firewall\ATRACK.EXE
C:\Program Files\Messenger\msmsgs.exe
F:\Hijak\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Windows Updata] scvhost.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1113245309452
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\IcePack.exe
O23 - Service: Intel Alert Handler - Intel® Corporation - C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel® Corporation - C:\WINDOWS\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\Program Files\Symantec\Quarantine\Server\qserver.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\ScanExplicit.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Many Thanks.

D.
  • 0

#6
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O4 - HKCU\..\Run: [Microsoft Windows Updata] scvhost.exe


* Click on Fix Checked when finished and exit HijackThis.

Perform a full scan with an updated Adaware SE and/or Spybot S&D to get rid of the leftovers.
If you don't have those programs yet, you can find the downloadlocations in my sig.

* Perform an onlinescan with housecall and/or Etrust and let it delete everything it is finding.

Reply in your next post which files couldnt get deleted.
Also tell me in which folder they are in.

I'm starting to have doubts that symantec/norton can also be responsible for those crashes. I've seen it a lot lately.
  • 0

#7
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hello again,

its been really difficult to try and run any type of program, I managed to run a full scan with adaware SE and it picked up 80 items which it deleted.
I cant however scan with Housecall as my system just keeps crashing.

At least the good news is the Aurora pop-ups have stopped.

Do you reckon symantec/norton is maybe the issue?

This PC is driving me up the wall!! ;)

Oh well...i'll keep following your instruction...whats next dude.

D. :tazz:

Edited by dtrouble, 03 May 2005 - 04:18 PM.

  • 0

#8
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Post another hijackthislog.. and if it still looks clean.. Then I really think Norton and the whole symantecpacket is causing those crashes.
I had today another 2 cases where after an update of norton the system kept crashing again and again.

There are better antivirus and firewalls which are free and doesn't take so many resources as symantec does!!

AVG, Bitdefender OR Avast are good FREE antivirus.
Never install more than one antivirusscanner or firewall on your system! Several together can give problems and decreases the reliability of it seriously!
Zonealarm OR Sygate are FREE firewalls.
  • 0

#9
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Ok, here you go....

Logfile of HijackThis v1.99.1
Scan saved at 23:34:43, on 03/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\cba\pds.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Symantec\Quarantine\Server\qserver.exe
C:\Program Files\Symantec\Quarantine\Server\ScanExplicit.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Symantec\Quarantine\Server\IcePack.exe
C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
C:\WINDOWS\system32\ams_ii\iao.exe
C:\WINDOWS\system32\cba\xfr.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Norton Personal Firewall\ATRACK.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Hijak\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1113245309452
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Symantec Quarantine Agent (IcePack) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\IcePack.exe
O23 - Service: Intel Alert Handler - Intel® Corporation - C:\WINDOWS\system32\ams_ii\hndlrsvc.exe
O23 - Service: Intel Alert Originator - Intel® Corporation - C:\WINDOWS\system32\ams_ii\iao.exe
O23 - Service: Intel File Transfer - Intel® Corporation - C:\WINDOWS\system32\cba\xfr.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINDOWS\system32\cba\pds.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Central Quarantine (qserver) - Symantec Corporation - C:\Program Files\Symantec\Quarantine\Server\qserver.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Quarantine Scanner (ScanExplicit) - IBM Corp. - C:\Program Files\Symantec\Quarantine\Server\ScanExplicit.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#10
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Clean log, so this is not malwarerelated, because I can't see any malware active in your running processes.

Ok.. If we wont try, we wont know, so Uninstall Norton antivirus AND norton firewall and everything else Symantec related, because if I look in your log, it's all symantec and Norton I see in here... really overdone.
Reboot afterwards and post a new log to see if the uninstalls worked, because Norton/symantec is known for improper uninstallations.

Don't install another antivirus/firewall for the time beeing.

Edited by miekiemoes, 03 May 2005 - 04:57 PM.

  • 0

Advertisements


#11
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi again,

I tried to delete all the Norton/Symantec stuff I could find, you were right there was loads.

I partially took your advice though. I installed Avast antivirus instead of connecting with zero protection, previous experience has shown me that its possible to get a virus on broadband in 2mins.

Anyhow after removing all the Norton stuff the pc still crashed a couple of times but seems to be stabalising. Ive now got an Avast scan running in the background as I right this reply, (something not previously possible.

My latest log file....

Logfile of HijackThis v1.99.1
Scan saved at 21:23:28, on 04/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Hijak\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1113245309452
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Cheers for your great help dude.
  • 0

#12
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP

but seems to be stabalising


That is good news! I'm pretty sure your system is running faster now too.. especially when starting up and shutting down.

The crashes that you are experiencing, however much less than before, could it be possible you installed new drivers or also anything else lately before the crashes started? Maybe try to search in that direction too.
Did you also perform a full scan with avast? Did it find anything?

Edited by miekiemoes, 04 May 2005 - 03:13 PM.

  • 0

#13
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi miekiemoes,

been trying loads of stuff since we last talked, tried to update 99% of my drivers however there are no newer updates available. I uninstalled Avast and Zonelabs which I later installed as I was without a firewall too after uninstalling Nortons etc. Now running Bitdefender8 Pro plus and my system now seems to be running better / faster although keeps crashing. I must say since ive restarted is hasnt done so yet...touch wood.

Avast didnt seem much good, was hard to get it to give a good scan report and when it finally did produce one it said there were 244 errors of some sort? Unfortunately it would not produce a word log of the results and it would not allow me to copy and paste what was being shown.

I managed to get a log from the Bitdefender scan...please take a look...


//-----------------------------------------------------------------
//
// Product: BitDefender 8 Professional Plus
// Version: (no ver)
//
// Created on: 05/05/2005 22:57:14
//
//-----------------------------------------------------------------


Statistics

Scan path : C:\WINDOWS\system32\
Folders : 200
Files : 5144
Archives : 16
Packed files : 284
Identified viruses : 0
Infected files : 0
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 0
Renamed files : 0
I/O errors : 10
Scan time : 00:02:49
Scan speed (files/sec) : 30

Virus definitions : 71509
Scan plugins : 12
Archive plugins : 36
Unpack plugins : 4
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[X] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report

Scanned files

C:\=>Master Boot Record 80 OK
C:\=>Partition Boot 1 (primary) (active) OK
C:\=>Partition Boot 2 OK
C:\WINDOWS\system32\$winnt$.inf OK
C:\WINDOWS\system32\1033\dwintl.dll OK
C:\WINDOWS\system32\12520437.cpx OK
C:\WINDOWS\system32\12520850.cpx OK
C:\WINDOWS\system32\5pg6797f.html OK
C:\WINDOWS\system32\6to4svc.dll OK
C:\WINDOWS\system32\a3d.dll OK
C:\WINDOWS\system32\aaaamon.dll OK
C:\WINDOWS\system32\access.cpl OK
C:\WINDOWS\system32\acctres.dll OK
C:\WINDOWS\system32\accwiz.exe OK
C:\WINDOWS\system32\acelpdec.ax OK
C:\WINDOWS\system32\acledit.dll OK
C:\WINDOWS\system32\aclui.dll OK
C:\WINDOWS\system32\activeds.dll OK
C:\WINDOWS\system32\activeds.tlb OK
C:\WINDOWS\system32\actmovie.exe OK
C:\WINDOWS\system32\actskin4.ocx OK
C:\WINDOWS\system32\actxprxy.dll OK
C:\WINDOWS\system32\admparse.dll OK
C:\WINDOWS\system32\adptif.dll OK
C:\WINDOWS\system32\adsldp.dll OK
C:\WINDOWS\system32\adsldpc.dll OK
C:\WINDOWS\system32\adsmsext.dll OK
C:\WINDOWS\system32\adsnds.dll OK
C:\WINDOWS\system32\adsnt.dll OK
C:\WINDOWS\system32\adsnw.dll OK
C:\WINDOWS\system32\advapi32.dll OK
C:\WINDOWS\system32\advpack.dll OK
C:\WINDOWS\system32\ahui.exe OK
C:\WINDOWS\system32\alg.exe OK
C:\WINDOWS\system32\alrsvc.dll OK
C:\WINDOWS\system32\amcompat.tlb OK
C:\WINDOWS\system32\amstream.dll OK
C:\WINDOWS\system32\AMS_II\IAOBIND.DAT OK
C:\WINDOWS\system32\AMS_II\IAOBINDNAME.DAT OK
C:\WINDOWS\system32\AMS_II\IAOLOG.DAT OK
C:\WINDOWS\system32\AMS_II\Norton_AntiVirus_Corporate_Edition.atd OK
C:\WINDOWS\system32\AMS_II\reorig.atd OK
C:\WINDOWS\system32\ansi.sys OK
C:\WINDOWS\system32\ap2nqrd4.dat OK
C:\WINDOWS\system32\apcups.dll OK
C:\WINDOWS\system32\append.exe OK
C:\WINDOWS\system32\apphelp.dll OK
C:\WINDOWS\system32\appmgmts.dll OK
C:\WINDOWS\system32\appmgr.dll OK
C:\WINDOWS\system32\appwiz.cpl OK
C:\WINDOWS\system32\arp.exe OK
C:\WINDOWS\system32\asctrls.ocx OK
C:\WINDOWS\system32\asferror.dll OK
C:\WINDOWS\system32\asr_fmt.exe OK
C:\WINDOWS\system32\asr_ldm.exe OK
C:\WINDOWS\system32\asr_pfu.exe OK
C:\WINDOWS\system32\aswBoot.exe OK
C:\WINDOWS\system32\asycfilt.dll OK
C:\WINDOWS\system32\at.exe OK
C:\WINDOWS\system32\ati2cqag.dll OK
C:\WINDOWS\system32\ati2dvaa.dll OK
C:\WINDOWS\system32\ati2dvag.dll OK
C:\WINDOWS\system32\ati3d1ag.dll OK
C:\WINDOWS\system32\ati3duag.dll OK
C:\WINDOWS\system32\ativdaxx.ax OK
C:\WINDOWS\system32\ativmvxx.ax OK
C:\WINDOWS\system32\ativtmxx.dll OK
C:\WINDOWS\system32\ativvaxx.dll OK
C:\WINDOWS\system32\atkctrs.dll OK
C:\WINDOWS\system32\atl.dll OK
C:\WINDOWS\system32\atl71.dll OK
C:\WINDOWS\system32\atmadm.exe OK
C:\WINDOWS\system32\atmfd.dll OK
C:\WINDOWS\system32\atmlib.dll OK
C:\WINDOWS\system32\atmpvcno.dll OK
C:\WINDOWS\system32\atrace.dll OK
C:\WINDOWS\system32\attrib.exe OK
C:\WINDOWS\system32\Audiodev.dll OK
C:\WINDOWS\system32\audiosrv.dll OK
C:\WINDOWS\system32\auditusr.exe OK
C:\WINDOWS\system32\authz.dll OK
C:\WINDOWS\system32\autochk.exe OK
C:\WINDOWS\system32\autoconv.exe OK
C:\WINDOWS\system32\autodisc.dll OK
C:\WINDOWS\system32\AUTOEXEC.NT OK
C:\WINDOWS\system32\autofmt.exe OK
C:\WINDOWS\system32\autolfn.exe OK
C:\WINDOWS\system32\AVASTSS.scr OK
C:\WINDOWS\system32\avicap.dll OK
C:\WINDOWS\system32\avicap32.dll OK
C:\WINDOWS\system32\avifil32.dll OK
C:\WINDOWS\system32\avifile.dll OK
C:\WINDOWS\system32\avisynth.dll OK
C:\WINDOWS\system32\avmeter.dll OK
C:\WINDOWS\system32\avtapi.dll OK
C:\WINDOWS\system32\avwav.dll OK
C:\WINDOWS\system32\basesrv.dll OK
C:\WINDOWS\system32\batmeter.dll OK
C:\WINDOWS\system32\batt.dll OK
C:\WINDOWS\system32\baur5s9q.dat OK
C:\WINDOWS\system32\bidispl.dll OK
C:\WINDOWS\system32\bios1.rom OK
C:\WINDOWS\system32\bios4.rom OK
C:\WINDOWS\system32\bits\qmgr.dll OK
C:\WINDOWS\system32\bitsprx2.dll OK
C:\WINDOWS\system32\bitsprx3.dll OK
C:\WINDOWS\system32\blackbox.dll OK
C:\WINDOWS\system32\blastcln.exe OK
C:\WINDOWS\system32\bootcfg.exe OK
C:\WINDOWS\system32\bootok.exe OK
C:\WINDOWS\system32\bootvid.dll OK
C:\WINDOWS\system32\bootvrfy.exe OK
C:\WINDOWS\system32\bopomofo.uce OK
C:\WINDOWS\system32\bqrufs5f.dat OK
C:\WINDOWS\system32\bqrufs5f.dat=>(JAVASCRIPT 1) OK
C:\WINDOWS\system32\browselc.dll OK
C:\WINDOWS\system32\browser.dll OK
C:\WINDOWS\system32\browseui.dll OK
C:\WINDOWS\system32\browsewm.dll OK
C:\WINDOWS\system32\bthci.dll OK
C:\WINDOWS\system32\bthprops.cpl OK
C:\WINDOWS\system32\bthserv.dll OK
C:\WINDOWS\system32\btpanui.dll OK
C:\WINDOWS\system32\cabinet.dll OK
C:\WINDOWS\system32\cabview.dll OK
C:\WINDOWS\system32\cacls.exe OK
C:\WINDOWS\system32\calc.exe OK
C:\WINDOWS\system32\camocx.dll OK
C:\WINDOWS\system32\capesnpn.dll OK
C:\WINDOWS\system32\capicom.dll OK
C:\WINDOWS\system32\cards.dll OK
C:\WINDOWS\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\TimeStamp OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\codecs10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\DRM10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\fp4.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\HPCRDP.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\IASNT4.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ims.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB867282.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB873333.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB873339.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB885250.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB885835.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB885836.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB886185.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB887472.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB887742.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB888113.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB888302.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB890047.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB890175.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB890859.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB890923.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB891781.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893066.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893086.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893803_wxp.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MAPIMIG.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\mediactr.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MPCD10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MPPRE10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MPSTUB10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\msmsgs.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\msn7.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\msn9.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\mstsweb.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\MW770.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\netfx.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\NT5IIS.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\nt5inf.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\ntprint.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem0.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem1.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem11.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem2.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem3.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem4.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem6.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem7.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem8.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\oem9.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\OEMBIOS.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\sp2.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\tabletpc.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\viamach.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WMDM10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\wmerrenu.cat OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WMFSDK10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WMP10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WMSET10.CAT OK
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WPD10.CAT OK
C:\WINDOWS\system32\CatRoot2\dberr.txt OK
C:\WINDOWS\system32\CatRoot2\edb.chk OK
C:\WINDOWS\system32\CatRoot2\edb.log OK
C:\WINDOWS\system32\CatRoot2\edb00004.log OK
C:\WINDOWS\system32\CatRoot2\res1.log OK
C:\WINDOWS\system32\CatRoot2\res2.log OK
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb OK
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\TimeStamp OK
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb OK
C:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\TimeStamp OK
C:\WINDOWS\system32\catsrv.dll OK
C:\WINDOWS\system32\catsrvps.dll OK
C:\WINDOWS\system32\catsrvut.dll OK
C:\WINDOWS\system32\ccfgnt.dll OK
C:\WINDOWS\system32\cdfview.dll OK
C:\WINDOWS\system32\cdm.dll OK
C:\WINDOWS\system32\cdmodem.dll OK
C:\WINDOWS\system32\cdosys.dll OK
C:\WINDOWS\system32\cdplayer.exe.manifest OK
C:\WINDOWS\system32\certcli.dll OK
C:\WINDOWS\system32\certmgr.dll OK
C:\WINDOWS\system32\certmgr.msc OK
C:\WINDOWS\system32\cewmdm.dll OK
C:\WINDOWS\system32\cfgbkend.dll OK
C:\WINDOWS\system32\cfgmgr32.dll OK
C:\WINDOWS\system32\charmap.exe OK
C:\WINDOWS\system32\chcp.com OK
C:\WINDOWS\system32\chkdsk.exe OK
C:\WINDOWS\system32\chkntfs.exe OK
C:\WINDOWS\system32\ciadmin.dll OK
C:\WINDOWS\system32\ciadv.msc OK
C:\WINDOWS\system32\cic.dll OK
C:\WINDOWS\system32\cidaemon.exe OK
C:\WINDOWS\system32\ciodm.dll OK
C:\WINDOWS\system32\cipher.exe OK
C:\WINDOWS\system32\cisvc.exe OK
C:\WINDOWS\system32\ckcnv.exe OK
C:\WINDOWS\system32\clb.dll OK
C:\WINDOWS\system32\clbcatex.dll OK
C:\WINDOWS\system32\clbcatq.dll OK
C:\WINDOWS\system32\cleanmgr.exe OK
C:\WINDOWS\system32\cliconf.chm OK
C:\WINDOWS\system32\cliconf.chm=>/#SYSTEM OK
C:\WINDOWS\system32\cliconf.chm=>/_what_is_microsoft_sql_server_client_configurationy.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_what_is_microsoft_sql_server_client_configurationy.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_general.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_general.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_named_pipes_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_named_pipes_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_tcp!ip_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_tcp!ip_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_multiprotocol_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_multiprotocol_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_nwlink_ipx!spx_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_nwlink_ipx!spx_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_appletalk_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_appletalk_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_banyan_vines_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_banyan_vines_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_via_protocol_default_value_setup.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_via_protocol_default_value_setup.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_alias.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_alias.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_namedpipes.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_namedpipes.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_tcpip.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_tcpip.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_multi.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_multi.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_ipxspx1.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_ipxspx1.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_ipxspx2.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_ipxspx2.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_apple.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_apple.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_vines.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_vines.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_add_(or_edit)_via_library_configuration.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_add_(or_edit)_via_library_configuration.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_others.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_add_others.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_dblib.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_dblib.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/idh_netlib.htm OK
C:\WINDOWS\system32\cliconf.chm=>/idh_netlib.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_managing_clients.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_managing_clients.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_start_the_sql_client_configuration_utility_.28.windows_nt.2d_.or_windows_95.2d_.based_client.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_start_the_sql_client_configuration_utility_.28.windows_nt.2d_.or_windows_95.2d_.based_client.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_check_the_library_version_numbers.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_check_the_library_version_numbers.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_set_db.2d.library_conversion_preference.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_set_db.2d.library_conversion_preference.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_add_a_network_protocol_configuration_.28.client_configuration_utility.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_add_a_network_protocol_configuration_.28.client_configuration_utility.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_edit_a_network_protocol_configuration_.28.client_configuration_utility.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_edit_a_network_protocol_configuration_.28.client_configuration_utility.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_delete_a_network_protocol_configuration_.28.client_configuration_utility.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_delete_a_network_protocol_configuration_.28.client_configuration_utility.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_alias_a_client_to_an_alternate_pipe.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_alias_a_client_to_an_alternate_pipe.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_create_an_alias_for_a_specific_server_name_to_use_the_multi.2d.protocol_net.2d.library.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_create_an_alias_for_a_specific_server_name_to_use_the_multi.2d.protocol_net.2d.library.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_use_the_windows_sockets_net.2d.library_.28.windows.2d_.or_windows_nt.2d.based_clients.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_use_the_windows_sockets_net.2d.library_.28.windows.2d_.or_windows_nt.2d.based_clients.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_nwlink_ipx.2f.spx_network_protocol.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_nwlink_ipx.2f.spx_network_protocol.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_appletalk_network_protocol.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_appletalk_network_protocol.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_banyan_vines_network_protocol.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_banyan_vines_network_protocol.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_via_network_library_(client_network_utility).htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_use_the_via_network_library_(client_network_utility).htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_a_nonstandard_network_protocol.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_configure_a_client_to_a_nonstandard_network_protocol.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_verify_that_sql_server_is_listening_on_appletalk_and_can_accept_a_client_connection.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_helphow_to_verify_that_sql_server_is_listening_on_appletalk_and_can_accept_a_client_connection.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_check_the_odbc_sql_server_driver_version_.28.windows_95.2d.based_clients.29.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_how_to_check_the_odbc_sql_server_driver_version_.28.windows_95.2d.based_clients.29.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_topic_unavailable_in_help.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_topic_unavailable_in_help.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/_sql_server_2000_copyright_and_disclaimer.htm OK
C:\WINDOWS\system32\cliconf.chm=>/_sql_server_2000_copyright_and_disclaimer.htm=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coUA.css OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coUA_Ex.css OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coUA_Print.css OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/vs70_5.css OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.css OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/shared.js OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/vs70link.js OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/vs70link.js=>(JAVASCRIPT 1) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/vs70link.js=>(JAVASCRIPT 4) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/vs70.js OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.js OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.js=>(JAVASCRIPT 1) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.js=>(JAVASCRIPT 2) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.js=>(JAVASCRIPT 3) OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/banner.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/banner2.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/banner_.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/banner_2.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/caution.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coC.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coCb.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coE.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/coEb.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/elle.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/important.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/note.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/relglyph.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/relglyph_.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/relglyph_c.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/shortcutclick.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/shortcutcold.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/shortcuthot.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/spacer.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/warning.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/keybrd.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/keybrd_c.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/keybrd_.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto_.gif OK
C:\WINDOWS\system32\cliconf.chm=>/Basics/mailto_c.gif OK
C:\WINDOWS\system32\cliconf.chm=>/cliconf.hhc OK
C:\WINDOWS\system32\cliconf.chm=>/#WINDOWS OK
C:\WINDOWS\system32\cliconf.chm=>/#IVB OK
C:\WINDOWS\system32\cliconf.chm=>/$WWKeywordLinks/Property OK
C:\WINDOWS\system32\cliconf.chm=>/$WWAssociativeLinks/Property OK
C:\WINDOWS\system32\cliconf.chm=>/$OBJINST OK
C:\WINDOWS\system32\cliconf.chm=>/$FIftiMain OK
C:\WINDOWS\system32\cliconf.chm=>/#IDXHDR OK
C:\WINDOWS\system32\cliconf.chm=>/#TOCIDX OK
C:\WINDOWS\system32\cliconf.chm=>/#TOPICS OK
C:\WINDOWS\system32\cliconf.chm=>/#URLTBL OK
C:\WINDOWS\system32\cliconf.chm=>/#URLSTR OK
C:\WINDOWS\system32\cliconf.chm=>/#STRINGS OK
C:\WINDOWS\system32\cliconfg.dll OK
C:\WINDOWS\system32\cliconfg.exe OK
C:\WINDOWS\system32\cliconfg.rll OK
C:\WINDOWS\system32\clipbrd.exe OK
C:\WINDOWS\system32\clipsrv.exe OK
C:\WINDOWS\system32\clusapi.dll OK
C:\WINDOWS\system32\cmcfg32.dll OK
C:\WINDOWS\system32\cmd.exe OK
C:\WINDOWS\system32\cmdial32.dll OK
C:\WINDOWS\system32\cmdl32.exe OK
C:\WINDOWS\system32\cmdlib.wsc OK
C:\WINDOWS\system32\cmdlib.wsc=>(VBSCRIPT 1) OK
C:\WINDOWS\system32\cmmgr32.hlp OK
C:\WINDOWS\system32\cmmon32.exe OK
C:\WINDOWS\system32\cmos.ram OK
C:\WINDOWS\system32\cmpbk32.dll OK
C:\WINDOWS\system32\cmprops.dll OK
C:\WINDOWS\system32\cmsetacl.dll OK
C:\WINDOWS\system32\cmstp.exe OK
C:\WINDOWS\system32\cmutil.dll OK
C:\WINDOWS\system32\cnbjmon.dll OK
C:\WINDOWS\system32\cnetcfg.dll OK
C:\WINDOWS\system32\cnvfat.dll OK
C:\WINDOWS\system32\colbact.dll OK
C:\WINDOWS\system32\Com\comadmin.dll OK
C:\WINDOWS\system32\Com\comempty.dat OK
C:\WINDOWS\system32\Com\comexp.msc OK
C:\WINDOWS\system32\Com\comrepl.exe OK
C:\WINDOWS\system32\Com\comrereg.exe OK
C:\WINDOWS\system32\Com\mtsadmin.tlb OK
C:\WINDOWS\system32\comaddin.dll OK
C:\WINDOWS\system32\comcat.dll OK
C:\WINDOWS\system32\comctl32.dll OK
C:\WINDOWS\system32\comctl32.ocx OK
C:\WINDOWS\system32\comdlg32.dll OK
C:\WINDOWS\system32\comm.drv OK
C:\WINDOWS\system32\command.com OK
C:\WINDOWS\system32\commdlg.dll OK
C:\WINDOWS\system32\comp.exe OK
C:\WINDOWS\system32\compact.exe OK
C:\WINDOWS\system32\compatui.dll OK
C:\WINDOWS\system32\compmgmt.msc OK
C:\WINDOWS\system32\compobj.dll OK
C:\WINDOWS\system32\compstui.dll OK
C:\WINDOWS\system32\comrepl.dll OK
C:\WINDOWS\system32\comres.dll OK
C:\WINDOWS\system32\comsdupd.exe OK
C:\WINDOWS\system32\comsnap.dll OK
C:\WINDOWS\system32\comsvcs.dll OK
C:\WINDOWS\system32\comuid.dll OK
C:\WINDOWS\system32\config\Antiviru.evt OK
C:\WINDOWS\system32\config\Antivirus.Evt OK
C:\WINDOWS\system32\config\AppEvent.Evt OK
C:\WINDOWS\system32\config\default OK
C:\WINDOWS\system32\config\default.LOG OK
C:\WINDOWS\system32\config\default.sav OK
C:\WINDOWS\system32\config\SAM OK
C:\WINDOWS\system32\config\SAM.LOG OK
C:\WINDOWS\system32\config\SecEvent.Evt OK
C:\WINDOWS\system32\config\SECURITY OK
C:\WINDOWS\system32\config\SECURITY.LOG OK
C:\WINDOWS\system32\config\software OK
C:\WINDOWS\system32\config\software.LOG OK
C:\WINDOWS\system32\config\software.sav OK
C:\WINDOWS\system32\config\SysEvent.Evt OK
C:\WINDOWS\system32\config\system OK
C:\WINDOWS\system32\config\system.LOG OK
C:\WINDOWS\system32\config\system.sav OK
C:\WINDOWS\system32\config\systemprofile\Application Data\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\E891C648621A40AC7F773694A17FE76C OK
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\E891C648621A40AC7F773694A17FE76C OK
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.bak OK
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\brndlog.txt OK
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012005041120050412\index.dat OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2RSZE1OD\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CXID41EJ\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M7MB4N6N\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S9S3WNCF\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\ntuser.dat OK
C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG OK
C:\WINDOWS\system32\config\systemprofile\SendTo\Compressed (zipped) Folder.ZFSendToTarget OK
C:\WINDOWS\system32\config\systemprofile\SendTo\Desktop (create shortcut).DeskLink OK
C:\WINDOWS\system32\config\systemprofile\SendTo\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\SendTo\Mail Recipient.MAPIMail OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk=>C:\WINDOWS\system32\magnify.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk=>C:\WINDOWS\system32\narrator.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk=>C:\WINDOWS\system32\osk.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk=>C:\WINDOWS\system32\utilman.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Command Prompt.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Command Prompt.lnk=>C:\WINDOWS\system32\cmd.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Entertainment\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Notepad.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Synchronize.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Synchronize.lnk=>C:\WINDOWS\system32\mobsync.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Tour Windows XP.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Tour Windows XP.lnk=>C:\WINDOWS\system32\tourstart.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Windows Explorer.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Windows Explorer.lnk=>C:\WINDOWS\explorer.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Remote Assistance.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Remote Assistance.lnk=>C:\WINDOWS\system32\rcimlby.exe OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Windows Media Player.lnk OK
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Windows Media Player.lnk=>C:\Program Files\Windows Media Player\wmplayer.exe OK
C:\WINDOWS\system32\config\systemprofile\Templates\amipro.sam OK
C:\WINDOWS\system32\config\systemprofile\Templates\excel.xls OK
C:\WINDOWS\system32\config\systemprofile\Templates\excel4.xls OK
C:\WINDOWS\system32\config\systemprofile\Templates\lotus.wk4 OK
C:\WINDOWS\system32\config\systemprofile\Templates\powerpnt.ppt OK
C:\WINDOWS\system32\config\systemprofile\Templates\presenta.shw OK
C:\WINDOWS\system32\config\systemprofile\Templates\quattro.wb2 OK
C:\WINDOWS\system32\config\systemprofile\Templates\sndrec.wav OK
C:\WINDOWS\system32\config\systemprofile\Templates\winword.doc OK
C:\WINDOWS\system32\config\systemprofile\Templates\winword2.doc OK
C:\WINDOWS\system32\config\systemprofile\Templates\wordpfct.wpd OK
C:\WINDOWS\system32\config\systemprofile\Templates\wordpfct.wpg OK
C:\WINDOWS\system32\config\TempKey.LOG OK
C:\WINDOWS\system32\config\userdiff OK
C:\WINDOWS\system32\config\userdiff.LOG OK
C:\WINDOWS\system32\CONFIG.NT OK
C:\WINDOWS\system32\CONFIG.TMP OK
C:\WINDOWS\system32\confmsp.dll OK
C:\WINDOWS\system32\conime.exe OK
C:\WINDOWS\system32\ConnAPI.dll OK
C:\WINDOWS\system32\console.dll OK
C:\WINDOWS\system32\control.exe OK
C:\WINDOWS\system32\convert.exe OK
C:\WINDOWS\system32\corpol.dll OK
C:\WINDOWS\system32\country.sys OK
C:\WINDOWS\system32\credui.dll OK
C:\WINDOWS\system32\crtdll.dll OK
C:\WINDOWS\system32\crypt32.dll OK
C:\WINDOWS\system32\cryptdlg.dll OK
C:\WINDOWS\system32\cryptdll.dll OK
C:\WINDOWS\system32\cryptext.dll OK
C:\WINDOWS\system32\cryptnet.dll OK
C:\WINDOWS\system32\cryptsvc.dll OK
C:\WINDOWS\system32\cryptui.dll OK
C:\WINDOWS\system32\cscdll.dll OK
C:\WINDOWS\system32\cscript.exe OK
C:\WINDOWS\system32\cscui.dll OK
C:\WINDOWS\system32\csrsrv.dll OK
C:\WINDOWS\system32\csrss.exe OK
C:\WINDOWS\system32\csseqchk.dll OK
C:\WINDOWS\system32\ctfmon.exe OK
C:\WINDOWS\system32\ctl3d32.dll OK
C:\WINDOWS\system32\ctl3dv2.dll OK
C:\WINDOWS\system32\ctype.nls OK
C:\WINDOWS\system32\c_037.nls OK
C:\WINDOWS\system32\c_10000.nls OK
C:\WINDOWS\system32\c_10006.nls OK
C:\WINDOWS\system32\c_10007.nls OK
C:\WINDOWS\system32\c_10010.nls OK
C:\WINDOWS\system32\c_10017.nls OK
C:\WINDOWS\system32\c_10029.nls OK
C:\WINDOWS\system32\c_10079.nls OK
C:\WINDOWS\system32\c_10081.nls OK
C:\WINDOWS\system32\c_10082.nls OK
C:\WINDOWS\system32\c_1026.nls OK
C:\WINDOWS\system32\c_1250.nls OK
C:\WINDOWS\system32\c_1251.nls OK
C:\WINDOWS\system32\c_1252.nls OK
C:\WINDOWS\system32\c_1253.nls OK
C:\WINDOWS\system32\c_1254.nls OK
C:\WINDOWS\system32\c_1255.nls OK
C:\WINDOWS\system32\c_1256.nls OK
C:\WINDOWS\system32\c_1257.nls OK
C:\WINDOWS\system32\c_1258.nls OK
C:\WINDOWS\system32\c_20127.nls OK
C:\WINDOWS\system32\c_20261.nls OK
C:\WINDOWS\system32\c_20866.nls OK
C:\WINDOWS\system32\c_20905.nls OK
C:\WINDOWS\system32\c_21866.nls OK
C:\WINDOWS\system32\c_28591.nls OK
C:\WINDOWS\system32\c_28592.nls OK
C:\WINDOWS\system32\c_28593.nls OK
C:\WINDOWS\system32\C_28594.NLS OK
C:\WINDOWS\system32\C_28595.NLS OK
C:\WINDOWS\system32\C_28597.NLS OK
C:\WINDOWS\system32\c_28598.nls OK
C:\WINDOWS\system32\c_28599.nls OK
C:\WINDOWS\system32\c_28603.nls OK
C:\WINDOWS\system32\c_28605.nls OK
C:\WINDOWS\system32\c_437.nls OK
C:\WINDOWS\system32\c_500.nls OK
C:\WINDOWS\system32\c_737.nls OK
C:\WINDOWS\system32\c_775.nls OK
C:\WINDOWS\system32\c_850.nls OK
C:\WINDOWS\system32\c_852.nls OK
C:\WINDOWS\system32\c_855.nls OK
C:\WINDOWS\system32\c_857.nls OK
C:\WINDOWS\system32\c_860.nls OK
C:\WINDOWS\system32\c_861.nls OK
C:\WINDOWS\system32\c_863.nls OK
C:\WINDOWS\system32\c_865.nls OK
C:\WINDOWS\system32\c_866.nls OK
C:\WINDOWS\system32\c_869.nls OK
C:\WINDOWS\system32\c_874.nls OK
C:\WINDOWS\system32\c_875.nls OK
C:\WINDOWS\system32\c_932.nls OK
C:\WINDOWS\system32\c_936.nls OK
C:\WINDOWS\system32\c_949.nls OK
C:\WINDOWS\system32\c_950.nls OK
C:\WINDOWS\system32\d3d8.dll OK
C:\WINDOWS\system32\d3d8thk.dll OK
C:\WINDOWS\system32\d3d9.dll OK
C:\WINDOWS\system32\d3d9caps.dat OK
C:\WINDOWS\system32\d3dim.dll OK
C:\WINDOWS\system32\d3dim700.dll OK
C:\WINDOWS\system32\d3dpmesh.dll OK
C:\WINDOWS\system32\d3dramp.dll OK
C:\WINDOWS\system32\d3drm.dll OK
C:\WINDOWS\system32\d3dxof.dll OK
C:\WINDOWS\system32\danim.dll OK
C:\WINDOWS\system32\dataclen.dll OK
C:\WINDOWS\system32\datime.dll OK
C:\WINDOWS\system32\davclnt.dll OK
C:\WINDOWS\system32\daxctle.ocx OK
C:\WINDOWS\system32\dbgeng.dll OK
C:\WINDOWS\system32\dbghelp.dll OK
C:\WINDOWS\system32\dbmsadsn.dll OK
C:\WINDOWS\system32\dbmsrpcn.dll OK
C:\WINDOWS\system32\dbmsvinn.dLL OK
C:\WINDOWS\system32\dbnetlib.dll OK
C:\WINDOWS\system32\dbnmpntw.dll OK
C:\WINDOWS\system32\dcache.bin OK
C:\WINDOWS\system32\dciman32.dll OK
C:\WINDOWS\system32\dcomcnfg.exe OK
C:\WINDOWS\system32\ddeml.dll OK
C:\WINDOWS\system32\ddeshare.exe OK
C:\WINDOWS\system32\ddraw.dll OK
C:\WINDOWS\system32\ddrawex.dll OK
C:\WINDOWS\system32\debug.exe OK
C:\WINDOWS\system32\debug.exe=>(ExePack 3.69) OK
C:\WINDOWS\system32\defrag.exe OK
C:\WINDOWS\system32\desk.cpl OK
C:\WINDOWS\system32\deskadp.dll OK
C:\WINDOWS\system32\deskmon.dll OK
C:\WINDOWS\system32\deskperf.dll OK
C:\WINDOWS\system32\desktop.ini OK
C:\WINDOWS\system32\devenum.dll OK
C:\WINDOWS\system32\devmgmt.msc OK
C:\WINDOWS\system32\devmgr.dll OK
C:\WINDOWS\system32\dfrg.msc OK
C:\WINDOWS\system32\dfrgfat.exe OK
C:\WINDOWS\system32\dfrgntfs.exe OK
C:\WINDOWS\system32\dfrgres.dll OK
C:\WINDOWS\system32\dfrgsnap.dll OK
C:\WINDOWS\system32\dfrgui.dll OK
C:\WINDOWS\system32\dfsshlex.dll OK
C:\WINDOWS\system32\dgnet.dll OK
C:\WINDOWS\system32\dgrpsetu.dll OK
C:\WINDOWS\system32\dgsetup.dll OK
C:\WINDOWS\system32\dhcpcsvc.dll OK
C:\WINDOWS\system32\dhcpmon.dll OK
C:\WINDOWS\system32\dhcpsapi.dll OK
C:\WINDOWS\system32\diactfrm.dll OK
C:\WINDOWS\system32\diantz.exe OK
C:\WINDOWS\system32\digest.dll OK
C:\WINDOWS\system32\dimap.dll OK
C:\WINDOWS\system32\dinput.dll OK
C:\WINDOWS\system32\dinput8.dll OK
C:\WINDOWS\system32\DirectX\Dinput\actc094.ini OK
C:\WINDOWS\system32\DirectX\Dinput\act_rs.png OK
C:\WINDOWS\system32\DirectX\Dinput\glmda.ini OK
C:\WINDOWS\system32\DirectX\Dinput\glmda.png OK
C:\WINDOWS\system32\DirectX\Dinput\glmdiggp.ini OK
C:\WINDOWS\system32\DirectX\Dinput\glmdiggp.png OK
C:\WINDOWS\system32\DirectX\Dinput\gr3001.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr3001.png OK
C:\WINDOWS\system32\DirectX\Dinput\gr3001_g.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr4001.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr4001.png OK
C:\WINDOWS\system32\DirectX\Dinput\gr4001_g.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr4001_g.png OK
C:\WINDOWS\system32\DirectX\Dinput\gr4003.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr4003.png OK
C:\WINDOWS\system32\DirectX\Dinput\gr4005.ini OK
C:\WINDOWS\system32\DirectX\Dinput\gr4005.png OK
C:\WINDOWS\system32\DirectX\Dinput\hammer.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ia3002.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ia3002_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ia3002_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\lgc202.ini OK
C:\WINDOWS\system32\DirectX\Dinput\lgc202.png OK
C:\WINDOWS\system32\DirectX\Dinput\lgc207.ini OK
C:\WINDOWS\system32\DirectX\Dinput\lgc207.png OK
C:\WINDOWS\system32\DirectX\Dinput\lgc209.ini OK
C:\WINDOWS\system32\DirectX\Dinput\lgc209.png OK
C:\WINDOWS\system32\DirectX\Dinput\lgc20a.ini OK
C:\WINDOWS\system32\DirectX\Dinput\lgc20a.png OK
C:\WINDOWS\system32\DirectX\Dinput\lgc291.ini OK
C:\WINDOWS\system32\DirectX\Dinput\lgc291.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_01.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_02.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_03.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_04.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_05.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_06.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_07.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_08.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_09.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms1b_10.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms26.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_01.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_02.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_03.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_04.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_05.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_06.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_07.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms26_08.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms27.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms27_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms28.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms28_8.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms34.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_01.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_02.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_03.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_04.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_05.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_06.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_07.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms34_08.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_a.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_c.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_m.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms3b_t.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms56.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_10.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_8.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms56_9.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_10.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_8.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms6_9.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_8.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_9.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms7_g.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms8.ini OK
C:\WINDOWS\system32\DirectX\Dinput\ms8.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_1.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_10.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_2.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_3.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_4.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_5.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_6.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_7.png OK
C:\WINDOWS\system32\DirectX\Dinput\ms8_8.pn
  • 0

#14
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi, you don't need to send me the whole report... those are huge.
As long bitdefender says your system is clean, it's good.
Glad you like bitdefender (I also use it) and your system is running better/faster
Actually, i think your system instability (crashes) are more a hardware-issue and I'm not familiar with that unfortunately.
So maybe better to start a new thread here:
http://www.geekstogo...pherals-f9.html

I'm sure someone can help you further there.
We fixed the crap on your system, so now hope someone else can help you with those crashes.
  • 0

#15
dtrouble

dtrouble

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Hi miekiemoes,

can I just say you have been a real great help, had my system running untill 1am yesterday simply to check stability and it seems real good. Got the all in one Bitdefender going now and you definately know your stuff. My system is running fast and stable.

It seems there are a number if anti virus programs which are just not compatible with XP and service pack two.

After further research the unmovemable files I mentioned in a previous thread look to be standard parts of XP and really nothing to worry about.

Once again, thanks for your help dude...

Oh and I know what you're thinkin...dont worry I will be making a donation as soon as.

Keep up the amazing work.

D.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP