Hi LT,
Hope all are well with you now.
I recently removed the Windows 98 and installed a Windows XP with its IExplorer, and the internet connection is now working.
However, the computer seems to run weirdly. It does not seem the 98 has removed completely .... all my old Program Files are still there, but do not shown on XP Add/Remove command. When download from Internet .... the Explorer STALLED sometime (ie .... when installing McAfee ... it just could not be done).
Anyway, here are the logs u requested with the latest HijackThis.
Thanks.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:25:50 AM, on 8/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (file missing)
--
End of file - 2335 bytes
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
Deckard's System Scanner v20071014.68
Run by Terry on 2008-08-07 09:07:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
6: 2008-08-07 16:07:49 UTC - RP6 - Deckard's System Scanner Restore Point
5: 2008-08-07 03:56:06 UTC - RP5 - Software Distribution Service 3.0
4: 2008-08-07 00:54:04 UTC - RP4 - Software Distribution Service 3.0
3: 2008-08-06 06:00:42 UTC - RP3 - Software Distribution Service 3.0
2: 2008-08-06 05:52:47 UTC - RP2 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-08-06 03:38:27 UTC - RP1 - ?????
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 320 MiB (512 MiB recommended).-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-07 09:08:40
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\SYSTEM32\wscntfy.exe
C:\WINDOWS\SYSTEM32\ctfmon.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\EWXXDNCO\dss[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ??
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () -
http://fpdownload.ma...t/ultrashim.cabO23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
--
End of file - 2524 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 McNASvc (McAfee Network Agent) - "c:\progra~1\common~1\mcafee\mna\mcnasvc.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {D45B1C18-C8FA-11D1-9F77-0000F805F530}
Description: NT Apm/Legacy Interface Node
Device ID: ROOT\NTAPM\0000
Manufacturer: Microsoft
Name: NT Apm/Legacy Interface Node
PNP Device ID: ROOT\NTAPM\0000
Service: NtApm
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI ???????
Device ID: PCI\VEN_1057&DEV_5600&SUBSYS_03001436&REV_00\2&EBB567F&0&58
Manufacturer:
Name: PCI ???????
PNP Device ID: PCI\VEN_1057&DEV_5600&SUBSYS_03001436&REV_00\2&EBB567F&0&58
Service:
-- Files created between 2008-07-07 and 2008-08-07 -----------------------------
2008-08-07 09:03:10 0 dr-h----- C:\Documents and Settings\Terry\Recent
2008-08-06 23:29:12 0 d--hs---- C:\FOUND.002
2008-08-06 23:25:44 0 d-------- C:\Program Files\McAfee.com
2008-08-06 23:25:35 0 d-------- C:\Program Files\Common Files\McAfee
2008-08-06 23:25:16 0 d-------- C:\Program Files\McAfee
2008-08-06 22:56:13 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-06 22:24:06 0 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-06 18:14:05 0 d-------- C:\WINDOWS\system32\appmgmt
2008-08-06 17:55:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-06 17:47:40 0 d---s---- C:\Documents and Settings\Terry\UserData
2008-08-06 17:42:51 0 d---s---- C:\Documents and Settings\Ethan C\UserData
2008-08-05 22:53:01 0 d-------- C:\WINDOWS\system32\PreInstall
2008-08-05 22:52:58 0 d--h----- C:\WINDOWS\$hf_mig$
2008-08-05 22:48:14 0 d-------- C:\Documents and Settings\Ethan C\Application Data\Mozilla
2008-08-05 22:44:49 0 d-------- C:\Documents and Settings\Ethan C\Application Data\Macromedia
2008-08-05 22:44:49 0 d-------- C:\Documents and Settings\Ethan C\Application Data\Adobe
2008-08-05 21:26:53 0 d-------- C:\Documents and Settings\Terry\Application Data\Macromedia
2008-08-05 21:26:53 0 d-------- C:\Documents and Settings\Terry\Application Data\Adobe
2008-08-05 21:21:42 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-05 21:21:36 0 d-------- C:\Documents and Settings\Terry\Application Data\Mozilla
2008-08-05 21:15:20 0 d-------- C:\Documents and Settings\Ethan C\Application Data\Identities
2008-08-05 21:15:12 0 d-------- C:\Documents and Settings\Ethan C\Desktop
2008-08-05 21:15:05 0 d-------- C:\Documents and Settings\Ethan C\??
2008-08-05 21:15:05 0 d--h----- C:\Documents and Settings\Ethan C\Templates
2008-08-05 21:15:05 0 dr-h----- C:\Documents and Settings\Ethan C\SendTo
2008-08-05 21:15:05 0 dr-h----- C:\Documents and Settings\Ethan C\Recent
2008-08-05 21:15:05 0 d--h----- C:\Documents and Settings\Ethan C\PrintHood
2008-08-05 21:15:05 0 d--h----- C:\Documents and Settings\Ethan C\NetHood
2008-08-05 21:15:05 0 dr------- C:\Documents and Settings\Ethan C\My Documents
2008-08-05 21:15:05 0 dr------- C:\Documents and Settings\Ethan C\Favorites
2008-08-05 21:15:05 0 d---s---- C:\Documents and Settings\Ethan C\Cookies
2008-08-05 21:15:05 0 dr-h----- C:\Documents and Settings\Ethan C\Application Data
2008-08-05 21:15:05 0 d---s---- C:\Documents and Settings\Ethan C\Application Data\Microsoft
2008-08-05 21:15:05 0 dr------- C:\Documents and Settings\Ethan C\???????
2008-08-05 21:15:04 786432 --ah----- C:\Documents and Settings\Ethan C\NTUSER.DAT
2008-08-05 21:15:04 0 d--h----- C:\Documents and Settings\Ethan C\Local Settings
2008-08-05 20:37:49 0 d-------- C:\Documents and Settings\Terry\Application Data\Identities
2008-08-05 20:37:28 0 d-------- C:\Documents and Settings\Terry\Desktop
2008-08-05 20:37:19 0 d-------- C:\Documents and Settings\Terry\??
2008-08-05 20:37:19 0 dr-h----- C:\Documents and Settings\Terry\SendTo
2008-08-05 20:37:19 0 d--h----- C:\Documents and Settings\Terry\PrintHood
2008-08-05 20:37:19 0 d--h----- C:\Documents and Settings\Terry\NetHood
2008-08-05 20:37:19 0 dr------- C:\Documents and Settings\Terry\My Documents
2008-08-05 20:37:19 0 dr------- C:\Documents and Settings\Terry\Favorites
2008-08-05 20:37:19 0 d---s---- C:\Documents and Settings\Terry\Cookies
2008-08-05 20:37:19 0 dr-h----- C:\Documents and Settings\Terry\Application Data
2008-08-05 20:37:19 0 dr------- C:\Documents and Settings\Terry\???????
2008-08-05 20:37:18 0 d--h----- C:\Documents and Settings\Terry\Templates
2008-08-05 20:37:17 0 d--h----- C:\Documents and Settings\Terry\Local Settings
2008-08-05 20:37:16 1048576 --ah----- C:\Documents and Settings\Terry\NTUSER.DAT
2008-08-05 20:35:52 0 d--hs---- C:\FOUND.001
2008-08-05 20:30:24 0 d--hs---- C:\FOUND.000
2008-08-05 20:24:03 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-08-05 20:10:57 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-08-05 20:10:56 0 d--hs---- C:\System Volume Information
2008-08-05 20:10:46 0 d-------- C:\WINDOWS\Prefetch
2008-08-05 20:10:45 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-08-05 20:10:43 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-08-05 20:10:43 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-08-05 20:10:43 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-08-05 20:10:43 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-08-05 20:10:43 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-08-05 20:10:26 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-08-05 20:10:26 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-08-05 20:10:26 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-08-05 20:10:26 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-08-05 20:10:26 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-08-05 19:56:03 0 d-------- C:\WINDOWS\system32\xircom
2008-08-05 19:54:47 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-08-05 19:51:24 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-08-05 19:49:28 0 d-------- C:\WINDOWS\system32\DirectX
2008-08-05 19:49:00 0 d-------- C:\Program Files\Common Files\MSSoap
2008-08-05 19:48:56 0 d-------- C:\WINDOWS\system32\Macromed
2008-08-05 19:48:56 0 d-------- C:\WINDOWS\srchasst
2008-08-05 19:48:48 0 d-------- C:\Program Files\Movie Maker
2008-08-05 19:48:42 0 d-------- C:\WINDOWS\system32\Restore
2008-08-05 19:46:18 21456 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-08-05 19:45:38 0 d-------- C:\WINDOWS\Registration
2008-08-05 19:45:07 0 d-------- C:\Program Files\Messenger
2008-08-05 19:45:03 0 d-------- C:\Program Files\MSN Gaming Zone
2008-08-05 19:44:38 0 d-------- C:\Program Files\Windows NT
2008-08-05 19:44:36 0 d-------- C:\WINDOWS\system32\MsDtc
2008-08-05 19:44:35 0 d-------- C:\WINDOWS\system32\Com
2008-08-05 19:26:03 0 d-------- C:\Program Files\Common Files\ODBC
2008-08-05 19:25:57 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-08-05 19:21:45 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-08-05 19:21:45 0 d-------- C:\Documents and Settings\All Users\??
2008-08-05 19:21:45 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-08-05 19:21:45 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-08-05 19:21:45 0 dr------- C:\Documents and Settings\All Users\Documents
2008-08-05 19:21:45 0 dr------- C:\Documents and Settings\All Users\???????
2008-08-05 19:21:44 0 d-------- C:\Documents and Settings\Default User\??
2008-08-05 19:21:44 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-08-05 19:21:44 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-08-05 19:21:44 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-08-05 19:21:44 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-08-05 19:21:44 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-08-05 19:21:44 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-08-05 19:21:44 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-08-05 19:21:44 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-08-05 19:21:44 0 dr------- C:\Documents and Settings\Default User\???????
2008-08-05 19:21:19 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-08-05 19:21:19 0 d-------- C:\WINDOWS\system32\CatRoot
2008-08-05 19:21:12 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-08-05 19:21:12 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-08-05 19:21:11 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-08-05 19:21:11 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-05 19:20:49 0 d-------- C:\Documents and Settings
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\WinSxS
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\wins
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\wbem
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\usmt
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\spool
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\ShellExt
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\Setup
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\ras
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\oobe
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\npp
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\mui
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\inetsrv
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\IME
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\icsxml
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\ias
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\export
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-08-05 19:02:13 0 dr-hs---- C:\WINDOWS\system32\dllcache
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\dhcp
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\config
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\3076
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\2052
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1054
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1042
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1041
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1037
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1033
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1031
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1028
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\system32\1025
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\security
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\Resources
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\repair
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\Provisioning
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\PeerNet
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\pchealth
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\mui
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\ime
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\ehome
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\Driver Cache
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\Debug
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\Connection Wizard
2008-08-05 19:02:13 0 d-------- C:\WINDOWS\addins
2008-08-05 18:55:35 451 --a------ C:\AUTOEXEC.BAT
2008-08-05 18:51:25 127924 --a------ C:\WINDOWS\system32\prfh0404.dat
2008-08-05 18:51:25 39976 --a------ C:\WINDOWS\system32\prfc0404.dat
2008-08-05 18:41:53 0 d-------- C:\WINDOWS\setup
2008-08-05 18:40:25 0 d--h----- C:\WINDOWS\Recent
2008-08-05 15:21:14 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-08-04 18:14:26 5166 ---hs---- C:\SUHDLOG.DAT
2008-08-03 12:18:26 0 d-------- C:\Program Files\CCleaner
2008-08-03 12:11:00 0 d-------- C:\Program Files\Trend Micro
-- Find3M Report ---------------------------------------------------------------
2008-08-05 19:21:46 62 --ahs---- C:\Documents and Settings\Terry\Application Data\desktop.ini
2008-08-04 18:21:06 11079 ---h----- C:\Program Files\folder.htt
2008-08-04 18:21:06 266 ---hs---- C:\Program Files\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/12/2004 12:00 PM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/12/2004 12:00 PM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/12/2004 12:00 PM]
"Pop-Up Stopper"="C:\Program Files\Panicware\Pop-Up Stopper\dpps2.exe" []
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/12/2004 12:00 PM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
-- End of Deckard's System Scanner: finished at 2008-08-07 09:22:01 ------------
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: Chinese
CPU 0: Intel Pentium III ???
Percentage of Memory in Use: 47%
Physical Memory (total/avail): 319.49 MiB / 168.02 MiB
Pagefile Memory (total/avail): 774.8 MiB / 642.04 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1918.72 MiB
A: is Removable (No Media)
C: is Fixed (FAT32) - 8.09 GiB total, 3.08 GiB free.
D: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - Maxtor 90871U2 - 8.1 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 8.1 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Terry\Application Data
BLASTER=A220 I7 D1 T2
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=ETHAN
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Terry
LOGONSERVER=\\ETHAN
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 7 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0703
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SNDSCAPE=C:\WINDOWS
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Terry\LOCALS~1\Temp
TMP=C:\DOCUME~1\Terry\LOCALS~1\Temp
USERDOMAIN=ETHAN
USERNAME=Terry
USERPROFILE=C:\Documents and Settings\Terry
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Terry
(admin)Ethan C
-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Windows XP ¦w₯ώ©Κ§σ·s (KB901190) --> "C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB950749) --> "C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB950759) --> "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB950760) --> "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB950762) --> "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB951376-v2) --> "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB951698) --> "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Windows XP ¦w₯ώ©Κ§σ·s (KB951748) --> "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Windows XP §σ·s (KB898461) --> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Windows XP §σ·s (KB942763) --> "C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
-- Application Event Log -------------------------------------------------------
Event Record #/Type62 / Error
Event Submitted/Written: 08/07/2008 08:54:28 AM
Event ID/Source: 1000 / Application Error
Event Description:
??????? install.exe,?? 2.1.106.0,????? compat.dll,?? 2.1.106.0,???? 0x0002cdf9?
??? [install.exe!ws!] ?????????
Event Record #/Type61 / Error
Event Submitted/Written: 08/07/2008 08:47:38 AM
Event ID/Source: 1000 / Application Error
Event Description:
??????? install.exe,?? 2.1.106.0,????? compat.dll,?? 2.1.106.0,???? 0x0002cdf9?
??? [install.exe!ws!] ?????????
Event Record #/Type40 / Error
Event Submitted/Written: 08/05/2008 08:31:55 PM
Event ID/Source: 1010 / Windows Product Activation
Event Description:
Windows ?????,???????????????????? Windows ???
Event Record #/Type20 / Warning
Event Submitted/Written: 08/05/2008 07:53:27 PM
Event ID/Source: 5603 / WinMgmt
Event Description:
??? Rsop Planning Mode Provider ?? WMI ???? root\RSOP ???,???? HostingModel ??,???? LocalSystem ???????????????????????????????????????,?????????????????????????,????????? HostingModel ?????????????????????
Event Record #/Type19 / Warning
Event Submitted/Written: 08/05/2008 07:53:27 PM
Event ID/Source: 5603 / WinMgmt
Event Description:
??? Rsop Planning Mode Provider ?? WMI ???? root\RSOP ???,???? HostingModel ??,???? LocalSystem ???????????????????????????????????????,?????????????????????????,????????? HostingModel ?????????????????????
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type193 / Error
Event Submitted/Written: 08/07/2008 08:24:54 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
McAfee Network Agent ??????,????????:
%%3
Event Record #/Type189 / Warning
Event Submitted/Written: 08/06/2008 11:41:34 PM
Event ID/Source: 20 / Print
Event Description:
?????? Windows NT x86 Version-3 ???????? Brother MFC-8220???:- UNIDRV.DLL, UNIDRVUI.DLL, BRMF8220.GPD, UNIDRV.HLP, UNIRES.DLL, STDNAMES.GPD, BRMZRD03.DLL, BRMZUI03.DLL, BRHBP03.GPD, BRMZ03.INI, BRMFCRES.DLL, BRMZ03.HLP?
Event Record #/Type186 / Error
Event Submitted/Written: 08/06/2008 11:31:32 PM
Event ID/Source: 1003 / System Error
Event Description:
??? 1000000a,parameter1 0000001c,parameter2 00000002,parameter3 00000001,parameter4 8053cee9?
Event Record #/Type176 / Error
Event Submitted/Written: 08/06/2008 11:31:27 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
McAfee Network Agent ??????,????????:
%%3
Event Record #/Type96 / Error
Event Submitted/Written: 08/05/2008 10:17:07 PM
Event ID/Source: 8032 / BROWSER
Event Description:
???????????? \Device\NetBT_Tcpip_{886B7B1C-9917-42CC-8801-350344180DDB} ??????????
??????????
-- End of Deckard's System Scanner: finished at 2008-08-07 09:22:01 ------------