Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

XP really really slow


  • This topic is locked This topic is locked

#16
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
The computer doesn't have an Antivirus on it. What is the best free one I could put on it now. I was going to put Windows Defender on it.
  • 0

Advertisements


#17
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :D

The computer doesn't have an Antivirus on it. What is the best free one I could put on it now. I was going to put Windows Defender on it.

We will address this in due course. I would not bother with Windows Defender as it is not partiauclary effective and Malwarebytes' Anti-Malware is by far the better solution.

You will also need to update to XP Service Pack Three but please do not do so untill I advise so, thank you.

Next:

Now please go to Start >> Control Panel >> Add/Remove Programs and remove the following (if present):

Antivirus 2010
Java™ 6 Update 18 <-- We will update this in due course.
Viewpoint Media Player

To do so, click once on each of the above in turn to highlight and then click on the Remove button.

Note: Take extra care in answering questions posed by any Uninstaller. Some questions may be worded to deceive you into keeping the program.

Backup the Registry:

Modifying the Registry can create unforeseen problems, so it always wise to create a backup before doing so.

  • Please go here and download ERUNT.
  • ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.
  • Double-click on erunt-setup.exe to Install ERUNT by following the prompts.
  • Use the default install settings but say No to the portion that asks you to add ERUNT to the Start-Up folder.
  • Start ERUNT either by double clicking on the desktop icon or choosing to start the program at the end of the setup process.
  • Choose a location for the backup. Note: the default location is C:\WINDOWS\ERDNT which is acceptable.
  • Make sure that at least the first two check boxes are selected.
  • Click on OK
  • Then click on YES to create the folder.
Note: If it is necessary to restore the registry, open the backup folder and start ERDNT.exe

Custom OTL Script:

  • Double-click OTL.exe to start the program.
  • Copy the lines from the codebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:OTL
IE - HKCU\..\URLSearchHook: {b67fa914-5d1d-4bea-97f0-87798333ad72} - File not found
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
FF - prefs.js..browser.search.selectedEngine: "search"
FF - HKLM\software\mozilla\Firefox\extensions\\{B75BE0FB-85FF-4909-9B16-70184D6BA4BA}: C:\Documents and Settings\amelungv\Local Settings\Application Data\{B75BE0FB-85FF-4909-9B16-70184D6BA4BA}\ [2010/07/16 15:16:16 | 000,000,000 | ---D | M]
[2009/10/11 16:23:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/10/12 18:42:24 | 000,001,210 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\search.xml
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (SparkleBox KS2 Toolbar) - {b67fa914-5d1d-4bea-97f0-87798333ad72} - File not found
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - File not found
O3 - HKLM\..\Toolbar: (SparkleBox KS2 Toolbar) - {b67fa914-5d1d-4bea-97f0-87798333ad72} - File not found
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (SparkleBox KS2 Toolbar) - {B67FA914-5D1D-4BEA-97F0-87798333AD72} - File not found
O4 - HKCU..\Run: [AROReminder] File not found
O15 - HKCU\..Trusted Domains: wustl.edu ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: wustl.edu ([*.itccitrix] * in Trusted sites)
O15 - HKCU\..Trusted Domains: wustl.edu ([*.wudosis] * in Trusted sites)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupd...7849.4791435185 (Reg Error: Key error.)
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} http://us.dl1.yimg.c...ropper1_1us.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2011/04/21 09:15:20 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2011/04/21 09:15:20 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
2010/07/16 15:17:01 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Yyibikiki.bin
[2010/07/16 15:16:56 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Fyudozavuyu.dat
[2008/04/13 19:12:38 | 000,128,512 | ---- | M] ()(C:\WINDOWS\System32\us?rinit_exe_1302483541.arl) -- C:\WINDOWS\System32\us?rinit_exe_1302483541.arl
 [2001/08/18 07:00:00 | 000,128,512 | ---- | C] ()(C:\WINDOWS\System32\us?rinit_exe_1302483541.arl) -- C:\WINDOWS\System32\us?rinit_exe_1302483541.arl
@Alternate Data Stream - 60 bytes -> C:\QWS3270:AFP_AfpInfo
 
 :Files 
ipconfig /flushdns /c 
%systemroot%\prefetch\*.* 

:Reg
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 "1900:UDP"=-
 "2869:TCP"=-
 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 "C:\Program Files\Real\RealPlayer\realplay.exe"=-
 "C:\Program Files\Real\RealPlayer\realplayer.exe"=-
 "C:\Program Files\Real\RealPlayer\trueplay.exe"=-
 "C:\Program Files\AVG\AVG9\avgnsx.exe"=-

:Commands
[Purity]
[ResetHosts]
[EmptyFlash]
[EmptyTemp]
[CreateRestorePoint]
[Reboot]
  • Return to OTL, right-click in the Custom Scans/Fixes window (under the cyan bar) and choose Paste.
  • Then click the red Run Fix button.
  • Let the program run unhindered.
  • If OTL asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
Note: The logfile can also be located C: >> _OTL >> MovedFiles >> DD/DD/DD TT/TT.txt <-- denotes date/time log created.

Download/Install a AV:

Download just one only of the three free anti-virus programs listed below please and then:

Install >> Update >> Carry Out a Complete Scan. Have it fix anything it finds.

Note: If anything was removed by the AV you chose to install, please save a copy of the report created and post the contents in your next reply, thank you.

When completed the above, please post back the following in the order asked for:

  • How is the computer performing now, any further symptoms and or problems encountered?
  • OTL Log from the Custom Script.

  • 0

#18
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
How long should it take OTL to run the fix?
  • 0

#19
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
All would depend on the vagaries of any one machine, this particular script should pose no problems. How longs has OTL been processing the script for now then?
  • 0

#20
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
Right now about 15 minutes. But, I let it from for about 3 hours last night and it seemed like it locked the computer up. When I went to task manager it said it was unresponsive. So I restarted the computer and tried again this morning. Ill let it run for a while now and see what happens.
  • 0

#21
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
OK, it may be possible OTL is corrupted somehow so if the need redownload a fresh copy and try again, failing that try the script in Safe Mode. If still no joy we will merely take a different approach.

Out of interest how did the machine become so badly infected again if you performed a full reformat and reinstallation of the Windows Operating System?
  • 0

#22
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
I didn't perform a full reformat. I just reinstalled windows. I never reformatted.
  • 0

#23
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
Can't get OTL to run the fix. In safe mode either.
  • 0

#24
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :D

I didn't perform a full reformat. I just reinstalled windows. I never reformatted.

Fair play, actually this may have worsened the situation, not to worry lets see what can be done.

Can't get OTL to run the fix. In safe mode either.

OK let try a different approach as follows...

Download/Run ComboFix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs <-- Click on this link.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: If ComboFix detects Rootkit activitity and asks to reboot the system, please allow this to be done.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use. ComboFix Should Not be used unless requested by a forum helper


Download/Install a AV:

Download just one only of the three free anti-virus programs listed below please and then:

Install >> Update >> Carry Out a Complete Scan. Have it fix anything it finds.

Note: If anything was removed by the AV you chose to install, please save a copy of the report created and post the contents in your next reply, thank you.

When completed the above, please post back the following in the order asked for:

  • How is the computer performing now, any other symptoms and or problems encountered?
  • ComboFix Log.

  • 0

#25
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
The computer seems to be running fine. No problems so far..

ComboFix 11-04-22.03 - amelungv 04/23/2011 2:50.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.296 [GMT -5:00]
Running from: c:\documents and settings\amelungv\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\.wtav
c:\documents and settings\amelungv\WINDOWS
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\driVERs\qkswx.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_USERINIT
-------\Legacy_qkswx
-------\Service_qkswx
.
.
((((((((((((((((((((((((( Files Created from 2011-03-23 to 2011-04-23 )))))))))))))))))))))))))))))))
.
.
2011-04-23 08:01 . 2011-04-23 08:01 -------- d-----w- c:\windows\LastGood
2011-04-23 08:01 . 2008-10-15 16:57 332800 ----a-w- c:\windows\system32\SET9.tmp
2011-04-21 05:17 . 2004-08-04 12:00 8704 -c--a-w- c:\windows\system32\dllcache\snmptrap.exe
2011-04-21 05:16 . 2004-08-04 12:00 7680 -c--a-w- c:\windows\system32\dllcache\migregdb.exe
2011-04-21 05:15 . 2004-08-04 12:00 7680 -c--a-w- c:\windows\system32\dllcache\ftpctrs2.dll
2011-04-21 05:14 . 2004-08-04 12:00 7168 -c--a-w- c:\windows\system32\dllcache\wamregps.dll
2011-04-21 05:11 . 2004-08-04 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2011-04-21 05:11 . 2004-08-04 12:00 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2011-04-21 04:52 . 2004-08-04 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-04-21 04:52 . 2004-08-04 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-04-21 04:52 . 2004-08-04 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-04-21 04:52 . 2004-08-04 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-04-19 16:49 . 2011-04-19 16:49 -------- d-----w- C:\VIPRERESCUE
2011-04-11 16:57 . 2011-04-21 06:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-07 14:49 . 2011-04-07 14:49 -------- d-----w- c:\documents and settings\amelungv\Application Data\SUPERAntiSpyware.com
2011-04-07 14:49 . 2011-04-07 14:49 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-07 14:43 . 2010-11-09 19:56 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-07 14:43 . 2010-11-09 19:56 27984 ----a-w- c:\windows\system32\sbbd.exe
2011-04-07 06:16 . 2011-04-07 06:16 -------- d-----w- C:\drvrtmp
2011-04-07 06:15 . 2011-04-16 23:17 -------- d-----w- C:\dell
2011-04-06 17:04 . 2004-08-04 12:00 10752 -c--a-w- c:\windows\system32\dllcache\smtpapi.dll
2011-04-06 17:04 . 2004-08-04 12:00 10752 ----a-w- c:\windows\system32\smtpapi.dll
2011-04-06 17:04 . 2004-08-04 12:00 9728 -c--a-w- c:\windows\system32\dllcache\rwnh.dll
2011-04-06 17:04 . 2004-08-04 12:00 9728 ----a-w- c:\windows\system32\rwnh.dll
2011-04-06 17:04 . 2004-08-04 12:00 221696 -c--a-w- c:\windows\system32\dllcache\seo.dll
2011-04-06 17:04 . 2004-08-04 12:00 189440 -c--a-w- c:\windows\system32\dllcache\smtpadm.dll
2011-04-06 17:00 . 2011-04-16 23:01 -------- d-----w- c:\documents and settings\amelungv\Application Data\Sammsoft
2011-04-03 21:18 . 2011-04-03 21:18 -------- d-----w- c:\program files\MSXML 6.0
2011-04-03 19:23 . 2011-04-03 19:23 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-04-01 21:27 . 2004-08-04 12:00 32768 -c--a-w- c:\windows\system32\dllcache\icwdl.dll
2011-04-01 21:27 . 2004-08-04 12:00 32768 ----a-w- c:\program files\Internet Explorer\Connection Wizard\icwdl.dll
2011-04-01 21:27 . 2004-08-04 12:00 86016 -c--a-w- c:\windows\system32\dllcache\icwconn2.exe
2011-04-01 21:27 . 2004-08-04 12:00 86016 ----a-w- c:\program files\Internet Explorer\Connection Wizard\icwconn2.exe
2011-04-01 21:27 . 2004-08-04 12:00 214528 -c--a-w- c:\windows\system32\dllcache\icwconn1.exe
2011-04-01 21:27 . 2004-08-04 12:00 214528 ----a-w- c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe
2011-04-01 21:27 . 2004-08-04 12:00 20480 -c--a-w- c:\windows\system32\dllcache\inetwiz.exe
2011-04-01 21:27 . 2004-08-04 12:00 20480 ----a-w- c:\program files\Internet Explorer\Connection Wizard\inetwiz.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 23:45 . 2008-10-16 23:53 556480 ----a-w- c:\program files\HughesNetToolsInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-08-04 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-22 47904]
"nwiz"="nwiz.exe" [2003-10-06 741376]
"TraySantaCruz"="c:\windows\System32\tbctray.exe" [2002-04-03 290816]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2003-10-06 49152]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microtek Scanner Finder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
backup=c:\windows\pss\Microtek Scanner Finder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=c:\windows\pss\Quicken Startup.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-09-22 04:28 47904 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 12:00 15360 ----a-w- c:\windows\SYSTEM32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 07:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2001-08-17 03:41 28738 ----a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2003-10-06 19:16 5058560 ----a-w- c:\windows\SYSTEM32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2003-10-06 19:16 741376 ----a-w- c:\windows\SYSTEM32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2008-05-23 19:06 128296 ----a-w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoExplosionCalCheck]
2006-05-10 17:32 69632 ----a-w- c:\program files\Nova Development\Photo Explosion Deluxe 3.0\CalCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2006-05-27 02:30 1003520 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
2010-10-05 04:52 304448 ----a-w- c:\documents and settings\amelungv\Application Data\Smilebox\SmileboxTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2003-12-25 18:59 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 nsslq;nsslq;c:\windows\SYSTEM32\DRIVERS\nsslq.sys [7/16/2010 3:17 PM 96256]
R3 tbcspud;Santa Cruz Driver;c:\windows\SYSTEM32\DRIVERS\tbcspud.sys [1/1/1980 144768]
R3 tbcwdm;Santa Cruz WDM Driver;c:\windows\SYSTEM32\DRIVERS\tbcwdm.sys [1/1/1980 545088]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/3/2010 9:25 PM 135664]
S3 FDE6C4AB;FDE6C4AB; [x]
S3 vbma20ef;Virtual Bus for Microsoft ACPI-Compliant System; [x]
.
Contents of the 'Scheduled Tasks' folder
.
2010-10-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-04-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-04 02:25]
.
2011-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-04 02:25]
.
2011-04-23 c:\windows\Tasks\User_Feed_Synchronization-{FBBB2170-175B-473A-B7A5-0F65C911E6A0}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-AdaptecDirectCD - c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
MSConfigStartUp-cxsfvtai - c:\documents and settings\amelungv\Local Settings\Application Data\jrmxfprqk\bpbpmcxtssd.exe
MSConfigStartUp-hsehf98u34i9tjioaugy987iuegdsg - c:\docume~1\amelungv\LOCALS~1\Temp\user.exe
MSConfigStartUp-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
MSConfigStartUp-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
MSConfigStartUp-jdknywyorv - c:\documents and settings\amelungv\local settings\application data\qqnrpxs\umqcgcu.exe
MSConfigStartUp-M5T8QL3YW3 - c:\docume~1\amelungv\LOCALS~1\Temp\Crr.exe
MSConfigStartUp-mcexecwin - c:\docume~1\amelungv\LOCALS~1\Temp\xachf8vh7.dll
MSConfigStartUp-MChk - c:\windows\system32\hbngp.exe
MSConfigStartUp-Microsoft Forefront Client Security Antimalware Service - c:\program files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe
MSConfigStartUp-PhotoShow Deluxe Media Manager - c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
MSConfigStartUp-Pvawecavalega - c:\windows\ndmdbieA.dll
MSConfigStartUp-Sgevuce - c:\windows\uwidiwoxew.dll
MSConfigStartUp-sta - qbngp.dll
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Common Files\Java\Java Update\jusched.exe
MSConfigStartUp-uiha98uiohf873yuiadnhgjesgregas - c:\docume~1\amelungv\LOCALS~1\Temp\xcrry41p.exe
AddRemove-conduitEngine - c:\program files\ConduitEngine\ConduitEngineUninstall.exe
AddRemove-SparkleBox_KS2 Toolbar - c:\program files\SparkleBox_KS2\uninstall.exe
AddRemove-Works2002Setup - c:\program files\Microsoft Works Suite 2002\Setup\Launcher.exe
AddRemove-Poingo Content Manager - c:\windows\system32\javaws.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-23 03:04
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\TelnetServer\1.0\ReadConfig]
@DACL=(02 0000)
"Defaults"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3900)
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-04-23 03:15:34 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-23 08:15
.
Pre-Run: 29,990,383,616 bytes free
Post-Run: 30,065,958,912 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin
.
- - End Of File - - 896C286A3A8EEF1743E0492DC8AECE8A
  • 0

Advertisements


#26
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
Avira AntiVir Personal
Report file date: Saturday, April 23, 2011 09:00

Scanning for 2595150 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : AMELUNG01

Version information:
BUILD.DAT : 10.0.0.635 31822 Bytes 3/7/2011 12:15:00
AVSCAN.EXE : 10.0.3.5 435368 Bytes 3/4/2011 19:36:52
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 17:57:04
LUKE.DLL : 10.0.3.2 104296 Bytes 3/4/2011 19:36:59
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 04:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 14:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 19:37:07
VBASE002.VDF : 7.11.3.0 1950720 Bytes 2/9/2011 19:37:08
VBASE003.VDF : 7.11.5.225 1980416 Bytes 4/7/2011 13:56:40
VBASE004.VDF : 7.11.5.226 2048 Bytes 4/7/2011 13:56:40
VBASE005.VDF : 7.11.5.227 2048 Bytes 4/7/2011 13:56:40
VBASE006.VDF : 7.11.5.228 2048 Bytes 4/7/2011 13:56:41
VBASE007.VDF : 7.11.5.229 2048 Bytes 4/7/2011 13:56:41
VBASE008.VDF : 7.11.5.230 2048 Bytes 4/7/2011 13:56:41
VBASE009.VDF : 7.11.5.231 2048 Bytes 4/7/2011 13:56:41
VBASE010.VDF : 7.11.5.232 2048 Bytes 4/7/2011 13:56:42
VBASE011.VDF : 7.11.5.233 2048 Bytes 4/7/2011 13:56:42
VBASE012.VDF : 7.11.5.234 2048 Bytes 4/7/2011 13:56:42
VBASE013.VDF : 7.11.6.28 158208 Bytes 4/11/2011 13:56:43
VBASE014.VDF : 7.11.6.74 116224 Bytes 4/13/2011 13:56:44
VBASE015.VDF : 7.11.6.113 137728 Bytes 4/14/2011 13:56:46
VBASE016.VDF : 7.11.6.150 146944 Bytes 4/18/2011 13:56:47
VBASE017.VDF : 7.11.6.192 138240 Bytes 4/20/2011 13:56:49
VBASE018.VDF : 7.11.6.237 156160 Bytes 4/22/2011 13:56:51
VBASE019.VDF : 7.11.6.238 2048 Bytes 4/22/2011 13:56:51
VBASE020.VDF : 7.11.6.239 2048 Bytes 4/22/2011 13:56:51
VBASE021.VDF : 7.11.6.240 2048 Bytes 4/22/2011 13:56:51
VBASE022.VDF : 7.11.6.241 2048 Bytes 4/22/2011 13:56:52
VBASE023.VDF : 7.11.6.242 2048 Bytes 4/22/2011 13:56:52
VBASE024.VDF : 7.11.6.243 2048 Bytes 4/22/2011 13:56:52
VBASE025.VDF : 7.11.6.244 2048 Bytes 4/22/2011 13:56:52
VBASE026.VDF : 7.11.6.245 2048 Bytes 4/22/2011 13:56:52
VBASE027.VDF : 7.11.6.246 2048 Bytes 4/22/2011 13:56:53
VBASE028.VDF : 7.11.6.247 2048 Bytes 4/22/2011 13:56:53
VBASE029.VDF : 7.11.6.248 2048 Bytes 4/22/2011 13:56:53
VBASE030.VDF : 7.11.6.249 2048 Bytes 4/22/2011 13:56:53
VBASE031.VDF : 7.11.6.252 17920 Bytes 4/23/2011 13:56:54
Engineversion : 8.2.4.214
AEVDF.DLL : 8.1.2.1 106868 Bytes 3/4/2011 19:36:49
AESCRIPT.DLL : 8.1.3.59 1261947 Bytes 4/23/2011 13:57:21
AESCN.DLL : 8.1.7.2 127349 Bytes 3/4/2011 19:36:48
AESBX.DLL : 8.1.3.2 254324 Bytes 3/4/2011 19:36:48
AERDL.DLL : 8.1.9.9 639347 Bytes 4/23/2011 13:57:18
AEPACK.DLL : 8.2.6.0 549237 Bytes 4/23/2011 13:57:15
AEOFFICE.DLL : 8.1.1.20 205177 Bytes 4/23/2011 13:57:13
AEHEUR.DLL : 8.1.2.105 3453303 Bytes 4/23/2011 13:57:12
AEHELP.DLL : 8.1.16.1 246134 Bytes 3/4/2011 19:36:41
AEGEN.DLL : 8.1.5.4 397684 Bytes 4/23/2011 13:57:03
AEEMU.DLL : 8.1.3.0 393589 Bytes 3/4/2011 19:36:40
AECORE.DLL : 8.1.20.2 196982 Bytes 4/23/2011 13:57:01
AEBB.DLL : 8.1.1.0 53618 Bytes 3/4/2011 19:36:39
AVWINLL.DLL : 10.0.0.0 19304 Bytes 3/4/2011 19:36:53
AVPREF.DLL : 10.0.0.0 44904 Bytes 3/4/2011 19:36:52
AVREP.DLL : 10.0.0.8 62209 Bytes 6/17/2010 19:27:13
AVREG.DLL : 10.0.3.2 53096 Bytes 3/4/2011 19:36:52
AVSCPLR.DLL : 10.0.3.2 84328 Bytes 3/4/2011 19:36:53
AVARKT.DLL : 10.0.22.6 231784 Bytes 3/4/2011 19:36:50
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 3/4/2011 19:36:51
SQLITE3.DLL : 3.6.19.0 355688 Bytes 6/17/2010 19:27:22
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/4/2011 19:36:53
NETNT.DLL : 10.0.0.0 11624 Bytes 6/17/2010 19:27:21
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 3/4/2011 19:37:12
RCTEXT.DLL : 10.0.58.0 97128 Bytes 3/4/2011 19:37:12

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Saturday, April 23, 2011 09:00

Starting search for hidden objects.

The scan of running processes will be started
Scan process 'msdtc.exe' - '42' Module(s) have been scanned
Scan process 'dllhost.exe' - '62' Module(s) have been scanned
Scan process 'dllhost.exe' - '47' Module(s) have been scanned
Scan process 'vssvc.exe' - '50' Module(s) have been scanned
Scan process 'avscan.exe' - '71' Module(s) have been scanned
Scan process 'ctfmon.exe' - '26' Module(s) have been scanned
Scan process 'avcenter.exe' - '61' Module(s) have been scanned
Scan process 'wuauclt.exe' - '43' Module(s) have been scanned
Scan process 'avgnt.exe' - '49' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'avguard.exe' - '55' Module(s) have been scanned
Scan process 'wuauclt.exe' - '34' Module(s) have been scanned
Scan process 'iPodService.exe' - '29' Module(s) have been scanned
Scan process 'tbctray.exe' - '29' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '68' Module(s) have been scanned
Scan process 'Explorer.EXE' - '104' Module(s) have been scanned
Scan process 'alg.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '35' Module(s) have been scanned
Scan process 'SeaPort.exe' - '44' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '26' Module(s) have been scanned
Scan process 'mdm.exe' - '20' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '32' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '32' Module(s) have been scanned
Scan process 'spoolsv.exe' - '63' Module(s) have been scanned
Scan process 'svchost.exe' - '46' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'svchost.exe' - '160' Module(s) have been scanned
Scan process 'svchost.exe' - '41' Module(s) have been scanned
Scan process 'svchost.exe' - '54' Module(s) have been scanned
Scan process 'lsass.exe' - '60' Module(s) have been scanned
Scan process 'services.exe' - '45' Module(s) have been scanned
Scan process 'winlogon.exe' - '74' Module(s) have been scanned
Scan process 'csrss.exe' - '13' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1770' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\WINDOWS\SYSTEM32\usеrinit_exe_1302483541.arl
[DETECTION] Is the TR/Agent.128512.4 Trojan

Beginning disinfection:
C:\WINDOWS\SYSTEM32\usеrinit_exe_1302483541.arl
[DETECTION] Is the TR/Agent.128512.4 Trojan
[NOTE] The file was moved to the quarantine directory under the name '5700bbad.qua'.


End of the scan: Saturday, April 23, 2011 13:47
Used time: 2:07:34 Hour(s)

The scan has been done completely.

12818 Scanned directories
439492 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
439491 Files not concerned
4025 Archives were scanned
0 Warnings
1 Notes
430864 Objects were scanned with rootkit scan
0 Hidden objects were found
  • 0

#27
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :D

The computer seems to be running fine. No problems so far..

Good, we are making some headway now.

FixPolicies:

Please download to your Desktop FixPolicies.exe, a self-extracting ZIP archive from here.

  • Double-click FixPolicies.exe.
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box should briefly appear and then close.
  • Leave FixPolicies on your desktop please until I otherwsie advise, thank you.
Malwarebytes Anti-Malware:

  • Launch the application, Check for Updates >> Perform a Quick Scan
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
  • 0

#28
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6429

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

4/23/2011 9:22:39 PM
mbam-log-2011-04-23 (21-22-39).txt

Scan type: Quick scan
Objects scanned: 178721
Time elapsed: 6 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#29
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Hi. :D

Check Hard Disk For Errors:

Press Start >> Run.., then copy/paste the following command into the box and press OK:

cmd /c chkdsk c: |find /v "percent" >> "%userprofile%\desktop\checkhd.txt"

A blank command window will open on your desktop, then close in a few minutes. This is normal.

A file icon named checkhd.txt should appear on your Desktop. Please post the contents of this file.
  • 0

#30
civiccrazy

civiccrazy

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 244 posts
The type of the file system is NTFS.

WARNING! F parameter not specified.
Running CHKDSK in read-only mode.

CHKDSK is verifying files (stage 1 of 3)...
CHKDSK is verifying indexes (stage 2 of 3)...
CHKDSK is recovering lost files.
Recovering orphaned file PERFST~1.TMP (374) into directory file 5061.
Recovering orphaned file PerfStringBackup.TMP (374) into directory file 5061.
CHKDSK is verifying security descriptors (stage 3 of 3)...
CHKDSK is verifying Usn Journal...
Usn Journal verification completed.
Correcting errors in the master file table's (MFT) BITMAP attribute.
Correcting errors in the Volume Bitmap.
Windows found problems with the file system.
Run CHKDSK with the /F (fix) option to correct these.

78140159 KB total disk space.
48837576 KB in 97780 files.
38720 KB in 12970 indexes.
4 KB in bad sectors.
216507 KB in use by the system.
65536 KB occupied by the log file.
29047352 KB available on disk.

4096 bytes in each allocation unit.
19535039 total allocation units on disk.
7261838 allocation units available on disk.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP