Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Internet stopped working [Closed]


  • This topic is locked This topic is locked

#1
jan_jan64

jan_jan64

    Member

  • Member
  • PipPip
  • 44 posts
Hi all :)

I was on the internet on my PC (firefox) and the browser started acting funny - tabs kept opening themselves for no reason and directing me to pages for telephone and internet service providers. Assuming I had some kind of virus or browser hijack, I uninstalled Firefox and reinstalled it, but no luck. I ran my anti-virus program but it found nothing - it DID ask me to block a program later on, however, oxrohey.exe (which I cant find any info about on the web), and it was continually asking for permission to run, so i permanently blocked it (but i dont knwo if that is a piece of malware or a program my computer needs...). I also turned off all unnecessary processes on startup/services in MSCONFIG (there were many that needed turning off anyway, and i hoped if one was a virus it might help).

Now, however, my internet no longer works. When opening the browser i get an error message that reads:

'jqsnotify.exe - entry point not found'
'The procedure entry point RtlIpv4AddressToStringExA could not be located in the dynamic link library ntdll.dll'

So, im guessing either i have a [bleep] of a virus my program cant detect, or ive f-ed my system up a bit T_T As you can see theres nothing actually wrong with my internet connection as im currently using my notebook to post this message.

Heres my OTL file:

OTL logfile created on: 24/01/2012 20:37:42 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = E:\
Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.63 Gb Available Physical Memory | 87.87% Memory free
4.84 Gb Paging File | 4.63 Gb Available in Paging File | 95.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 596.16 Gb Total Space | 581.97 Gb Free Space | 97.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 444.37 Gb Free Space | 95.41% Space Free | Partition Type: NTFS

Computer Name: JAN | User Name: Janine | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/24 20:31:33 | 000,584,192 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
PRC - [2011/10/08 17:34:24 | 000,820,568 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/10/08 17:34:22 | 004,441,944 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Malware Fighter\IMF.exe
PRC - [2011/01/17 18:37:40 | 011,322,880 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 18:37:40 | 011,314,688 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2003/03/31 13:00:00 | 001,004,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/07 22:27:09 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2011/10/09 17:19:50 | 000,870,232 | ---- | M] () -- C:\Program Files\IObit\IObit Malware Fighter\Scan.dll
MOD - [2011/06/23 13:41:30 | 000,138,752 | ---- | M] () -- C:\Program Files\IObit\IObit Malware Fighter\zlibwapi.dll
MOD - [2010/11/26 12:18:08 | 000,175,616 | ---- | M] () -- C:\Program Files\IObit\IObit Malware Fighter\unrar.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/10/08 17:34:24 | 000,820,568 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/01/14 09:31:28 | 000,994,624 | ---- | M] (Packard Bell Services) [Auto | Stopped] -- C:\Program Files\Acer\Software Suite\PowerSave\HDPBSSS.exe -- (Service1)
SRV - [2003/03/31 13:00:00 | 000,047,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\mspmspsv.dll -- (WmdmPmSp)
SRV - [2003/03/31 13:00:00 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\WINDOWS\system32\atchksrv.dll -- (USBAAPL)


========== Driver Services (SafeList) ==========

DRV - [2011/12/06 18:59:42 | 007,067,752 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2011/09/20 14:29:32 | 000,016,208 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2011/09/20 14:29:30 | 000,030,368 | ---- | M] (IObit.com) [Kernel | On_Demand | Running] -- C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys -- (RegFilter)
DRV - [2009/06/26 20:15:50 | 000,142,336 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/23 22:44:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/23 22:44:35 | 000,000,000 | ---D | M]

[2012/01/23 22:44:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Janine\Application Data\Mozilla\Extensions
[2012/01/23 22:44:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Janine\Application Data\Mozilla\Firefox\Profiles\jq39vueg.default\extensions
[2012/01/23 22:44:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/07 22:26:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2012/01/07 22:26:45 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2003/03/31 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Janine\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Janine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Janine\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/12/29 16:59:21 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/01/23 22:44:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox
[2012/01/23 22:36:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/01/23 19:33:57 | 000,000,000 | -HSD | C] -- C:\WINDOWS\assembly
[2012/01/23 19:33:37 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\f06cada9
[2012/01/20 18:10:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Identities
[2012/01/20 18:10:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Ugi
[2012/01/19 19:11:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2012/01/19 14:07:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Temp
[2012/01/10 22:02:30 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Messenger
[2012/01/10 21:57:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\MSN6
[2012/01/10 21:57:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2012/01/08 23:35:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Acer
[2012/01/08 23:35:01 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Acer
[2012/01/08 23:34:57 | 000,000,000 | ---D | C] -- C:\Program Files\Acer
[2012/01/07 22:27:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\OpenOffice.org
[2012/01/07 22:27:08 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.3
[2012/01/07 22:26:54 | 000,000,000 | ---D | C] -- C:\Program Files\OpenOffice.org 3
[2012/01/07 22:26:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/01/07 22:26:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/01/07 22:26:44 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/01/07 22:26:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Sun
[2012/01/03 20:49:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2012/01/03 20:49:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Adobe
[2012/01/03 20:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/01/03 20:47:56 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/01/03 20:47:49 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
[2012/01/03 20:47:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/01/01 22:12:59 | 000,065,536 | ---- | C] (Khronos Group) -- C:\WINDOWS\System32\OpenCL.dll
[2012/01/01 22:00:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Desktop\DOTT
[2012/01/01 21:59:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ConeXware
[2012/01/01 21:58:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Caphyon
[2012/01/01 21:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\PowerArchiver
[2012/01/01 21:58:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\PowerArchiver
[2012/01/01 21:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Macromedia
[2012/01/01 21:02:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Adobe
[2012/01/01 19:58:37 | 000,000,000 | ---D | C] -- C:\Program Files\Steam
[2012/01/01 19:58:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Steam
[2012/01/01 19:58:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Steam
[2012/01/01 19:00:58 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2012/01/01 19:00:54 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2012/01/01 18:28:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\IceChat
[2012/01/01 18:28:51 | 000,000,000 | ---D | C] -- C:\Program Files\IceChat7
[2012/01/01 18:28:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IceChat7
[2012/01/01 18:26:39 | 000,000,000 | ---D | C] -- C:\Program Files\mIRC
[2012/01/01 18:26:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\mIRC
[2012/01/01 18:19:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Innovative Solutions
[2012/01/01 18:19:18 | 000,000,000 | ---D | C] -- C:\Program Files\Innovative Solutions
[2012/01/01 18:18:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\My Documents\Downloads
[2012/01/01 17:49:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Mozilla
[2012/01/01 17:49:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Mozilla
[2012/01/01 17:49:40 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/01/01 16:22:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\IObit Malware Fighter
[2012/01/01 16:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\IObit
[2012/01/01 16:22:20 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2012/01/01 16:20:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2012/01/01 16:18:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM
[2012/01/01 16:18:20 | 002,815,592 | ---- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\ALCWZRD.EXE
[2012/01/01 16:18:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2011/12/31 20:22:03 | 000,000,000 | ---D | C] -- C:\Intel
[2011/12/31 20:20:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2011/12/31 20:20:41 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2011/12/31 20:20:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Desktop\drivers
[2011/12/31 16:41:21 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/12/31 15:54:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Motherboard Drivers
[2011/12/30 19:07:37 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2011/12/30 19:07:37 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2011/12/30 15:27:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Desktop\PC
[2011/12/30 15:03:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavalys
[2011/12/30 15:03:09 | 000,000,000 | ---D | C] -- C:\Program Files\Lavalys
[2011/12/29 20:05:10 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2011/12/29 17:52:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2011/12/29 17:52:33 | 000,000,000 | R--D | C] -- C:\Program Files
[2011/12/29 17:52:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2011/12/29 17:52:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2011/12/29 17:52:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2011/12/29 17:51:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/12/29 17:51:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2011/12/29 17:51:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2011/12/29 17:51:59 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2011/12/29 17:51:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2011/12/29 17:51:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2011/12/29 17:51:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/12/29 17:51:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2011/12/29 17:51:44 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2011/12/29 17:51:44 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2011/12/29 17:51:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2011/12/29 17:44:14 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2011/12/29 17:44:14 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2011/12/29 17:44:14 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2011/12/29 17:44:14 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2011/12/29 17:44:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[2011/12/29 17:04:38 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2011/12/29 17:04:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Application Data\Identities
[2011/12/29 17:04:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\My Documents\My Pictures
[2011/12/29 17:04:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\My Documents\My Music
[2011/12/29 17:04:32 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2011/12/29 17:04:31 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Janine\Application Data\Microsoft
[2011/12/29 17:04:31 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Janine\Cookies
[2011/12/29 17:04:31 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Janine\SendTo
[2011/12/29 17:04:31 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Janine\Recent
[2011/12/29 17:04:31 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Janine\Application Data
[2011/12/29 17:04:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\Start Menu\Programs\Startup
[2011/12/29 17:04:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\Start Menu
[2011/12/29 17:04:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\My Documents
[2011/12/29 17:04:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\Favorites
[2011/12/29 17:04:31 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Janine\Start Menu\Programs\Accessories
[2011/12/29 17:04:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Janine\Templates
[2011/12/29 17:04:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Janine\PrintHood
[2011/12/29 17:04:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Janine\NetHood
[2011/12/29 17:04:31 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Janine\Local Settings
[2011/12/29 17:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\Microsoft
[2011/12/29 17:04:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Janine\Desktop
[2011/12/29 17:02:10 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2011/12/29 17:02:09 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2011/12/29 17:02:09 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2011/12/29 17:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2011/12/29 17:02:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2011/12/29 17:02:08 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2011/12/29 17:00:10 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia330.dll
[2011/12/29 17:00:10 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia001.dll
[2011/12/29 17:00:10 | 000,026,624 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw330ext.dll
[2011/12/29 16:59:34 | 000,054,528 | ---- | C] (Philips Semiconductors GmbH) -- C:\WINDOWS\System32\dllcache\cap7146.sys
[2011/12/29 16:59:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\xircom
[2011/12/29 16:59:23 | 000,000,000 | ---D | C] -- C:\Program Files\xerox
[2011/12/29 16:59:23 | 000,000,000 | ---D | C] -- C:\Program Files\microsoft frontpage
[2011/12/29 16:59:01 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2011/12/29 16:58:57 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2011/12/29 16:58:57 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2011/12/29 16:58:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2011/12/29 16:57:44 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2011/12/29 16:57:38 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2011/12/29 16:57:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2011/12/29 16:57:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2011/12/29 16:57:24 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2011/12/29 16:57:21 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2011/12/29 16:57:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\PCHealth
[2011/12/29 16:57:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2011/12/29 16:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2011/12/29 16:57:06 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2011/12/29 16:57:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2011/12/29 16:57:00 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2011/12/29 16:56:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2011/12/29 16:56:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2011/12/29 16:56:58 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2011/12/29 16:56:57 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2011/12/29 16:56:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2011/12/29 16:56:48 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2011/12/29 16:56:48 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2011/12/29 16:56:48 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2011/12/29 16:56:48 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2011/12/29 16:56:46 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2011/12/29 16:56:37 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2011/12/29 16:56:32 | 000,272,896 | ---- | C] (Cinematronics) -- C:\WINDOWS\System32\dllcache\pinball.exe
[2011/12/29 16:55:42 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2011/12/29 16:55:42 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2011/12/29 16:55:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2011/12/29 16:55:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2011/12/29 16:55:26 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/24 20:37:08 | 000,000,000 | -HS- | M] () -- C:\WINDOWS\System32\dds_log_trash.cmd
[2012/01/24 20:37:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/01/23 23:32:14 | 000,000,194 | -HS- | M] () -- C:\boot.ini
[2012/01/23 22:44:36 | 000,001,620 | ---- | M] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/23 22:44:36 | 000,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/01/23 18:13:43 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/01/08 23:35:43 | 000,048,640 | ---- | M] () -- C:\Documents and Settings\Janine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/08 10:06:46 | 000,122,928 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/01/07 22:27:43 | 000,000,864 | ---- | M] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2012/01/07 22:27:08 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2012/01/03 20:48:08 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/01 19:58:37 | 000,000,664 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2012/01/01 18:28:51 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\Janine\Desktop\IceChat.lnk
[2012/01/01 18:12:54 | 000,001,891 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/01/01 16:25:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2012/01/01 16:21:56 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/01/01 16:21:56 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/12/29 17:04:39 | 000,000,779 | ---- | M] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/29 17:04:39 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/29 17:04:37 | 000,000,804 | ---- | M] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/12/29 17:04:36 | 000,025,065 | ---- | M] () -- C:\WINDOWS\System32\wmpscheme.xml
[2011/12/29 17:00:57 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/29 17:00:22 | 000,000,261 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/29 16:59:21 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/29 16:59:21 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/12/29 16:59:21 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/12/29 16:59:21 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2011/12/29 16:59:21 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2011/12/29 16:59:20 | 000,299,552 | ---- | M] () -- C:\WINDOWS\WMSysPrx.prx
[2011/12/29 16:59:20 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/29 16:59:20 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/29 16:59:18 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/29 16:56:58 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/23 22:44:36 | 000,001,620 | ---- | C] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/23 22:44:36 | 000,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/01/23 19:33:56 | 000,000,000 | -HS- | C] () -- C:\WINDOWS\System32\dds_log_trash.cmd
[2012/01/10 22:02:30 | 000,002,329 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Messenger 7.5.lnk
[2012/01/08 23:35:19 | 000,048,640 | ---- | C] () -- C:\Documents and Settings\Janine\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/07 22:27:43 | 000,000,864 | ---- | C] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2012/01/07 22:27:08 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2012/01/03 20:48:08 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader X.lnk
[2012/01/03 20:48:07 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/01 22:13:00 | 002,130,002 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2012/01/01 19:58:37 | 000,000,664 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2012/01/01 19:00:54 | 000,003,250 | ---- | C] () -- C:\WINDOWS\System32\nvinfo.pb
[2012/01/01 18:28:51 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\Janine\Desktop\IceChat.lnk
[2012/01/01 18:13:53 | 000,001,486 | ---- | C] () -- C:\WINDOWS\System32\noise.kor
[2012/01/01 18:13:52 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\korwbrkr.lex
[2012/01/01 18:13:52 | 001,158,818 | ---- | C] () -- C:\WINDOWS\System32\dllcache\korwbrkr.lex
[2012/01/01 18:13:52 | 000,002,060 | ---- | C] () -- C:\WINDOWS\System32\noise.jpn
[2012/01/01 18:13:45 | 000,211,938 | ---- | C] () -- C:\WINDOWS\System32\lcphrase.tbl
[2012/01/01 18:13:45 | 000,146,126 | ---- | C] () -- C:\WINDOWS\System32\array30.tab
[2012/01/01 18:13:45 | 000,110,566 | ---- | C] () -- C:\WINDOWS\System32\arphr.tbl
[2012/01/01 18:13:45 | 000,043,242 | ---- | C] () -- C:\WINDOWS\System32\phoncode.tbl
[2012/01/01 18:13:45 | 000,024,114 | ---- | C] () -- C:\WINDOWS\System32\lcptr.tbl
[2012/01/01 18:13:45 | 000,018,600 | ---- | C] () -- C:\WINDOWS\System32\arrayhw.tab
[2012/01/01 18:13:45 | 000,016,312 | ---- | C] () -- C:\WINDOWS\System32\arptr.tbl
[2012/01/01 18:13:45 | 000,002,714 | ---- | C] () -- C:\WINDOWS\System32\phonptr.tbl
[2012/01/01 18:13:44 | 000,116,285 | ---- | C] () -- C:\WINDOWS\System32\msdayi.tbl
[2012/01/01 18:13:44 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\acode.tbl
[2012/01/01 18:13:44 | 000,044,370 | ---- | C] () -- C:\WINDOWS\System32\a234.tbl
[2012/01/01 18:13:44 | 000,004,071 | ---- | C] () -- C:\WINDOWS\System32\phon.tbl
[2012/01/01 18:13:44 | 000,001,460 | ---- | C] () -- C:\WINDOWS\System32\a15.tbl
[2012/01/01 18:13:44 | 000,000,700 | ---- | C] () -- C:\WINDOWS\System32\dayiptr.tbl
[2012/01/01 18:13:44 | 000,000,520 | ---- | C] () -- C:\WINDOWS\System32\dayiphr.tbl
[2012/01/01 18:13:39 | 001,783,864 | ---- | C] () -- C:\WINDOWS\System32\WINPY.MB
[2012/01/01 18:13:39 | 001,564,868 | ---- | C] () -- C:\WINDOWS\System32\WINSP.MB
[2012/01/01 18:13:39 | 001,223,500 | ---- | C] () -- C:\WINDOWS\System32\WINZM.MB
[2012/01/01 18:13:36 | 000,134,339 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imekr.lex
[2012/01/01 18:13:35 | 000,108,827 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hanja.lex
[2012/01/01 18:13:26 | 013,463,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hwxjpn.dll
[2012/01/01 18:13:12 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dllcache\chtskf.dll
[2012/01/01 18:13:10 | 000,175,104 | ---- | C] () -- C:\WINDOWS\System32\dllcache\pintlcsa.dll
[2012/01/01 18:13:07 | 000,059,392 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imscinst.exe
[2012/01/01 18:13:05 | 000,196,666 | ---- | C] () -- C:\WINDOWS\System32\dllcache\imjpinst.exe
[2012/01/01 16:25:09 | 000,013,646 | ---- | C] () -- C:\WINDOWS\System32\wpa.bak
[2012/01/01 16:18:20 | 000,021,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\RTAIODAT.DAT
[2012/01/01 15:11:58 | 000,073,728 | R--- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2011/12/29 17:52:39 | 000,001,891 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2011/12/29 17:52:37 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2011/12/29 17:52:35 | 001,685,606 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.spd
[2011/12/29 17:52:35 | 000,000,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sam.sdf
[2011/12/29 17:52:34 | 000,643,717 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ltts1033.lxa
[2011/12/29 17:52:34 | 000,605,050 | ---- | C] () -- C:\WINDOWS\System32\dllcache\r1033tts.lxa
[2011/12/29 17:52:02 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2011/12/29 17:51:59 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2011/12/29 17:51:59 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2011/12/29 17:51:59 | 000,031,405 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2011/12/29 17:51:59 | 000,013,608 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2011/12/29 17:51:59 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2011/12/29 17:51:59 | 000,010,881 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2011/12/29 17:51:59 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2011/12/29 17:51:59 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2011/12/29 17:51:59 | 000,007,369 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2011/12/29 17:51:58 | 002,049,999 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2011/12/29 17:51:58 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2011/12/29 17:51:58 | 000,344,390 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2011/12/29 17:51:19 | 000,122,928 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/29 17:50:34 | 000,000,261 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf
[2011/12/29 17:50:34 | 000,000,194 | -HS- | C] () -- C:\boot.ini
[2011/12/29 17:04:39 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/29 17:04:36 | 000,000,738 | ---- | C] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Outlook Express.lnk
[2011/12/29 17:04:35 | 000,000,804 | ---- | C] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2011/12/29 17:04:33 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Internet Explorer.lnk
[2011/12/29 17:04:32 | 000,000,779 | ---- | C] () -- C:\Documents and Settings\Janine\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/12/29 17:04:31 | 000,001,599 | ---- | C] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Remote Assistance.lnk
[2011/12/29 17:04:31 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\Janine\Start Menu\Programs\Windows Media Player.lnk
[2011/12/29 17:00:57 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2011/12/29 17:00:22 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2011/12/29 16:59:40 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\fpencode.dll
[2011/12/29 16:59:21 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/12/29 16:59:21 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2011/12/29 16:59:21 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2011/12/29 16:59:21 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2011/12/29 16:59:21 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2011/12/29 16:59:20 | 000,299,552 | ---- | C] () -- C:\WINDOWS\WMSysPrx.prx
[2011/12/29 16:59:20 | 000,025,065 | ---- | C] () -- C:\WINDOWS\System32\wmpscheme.xml
[2011/12/29 16:59:20 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2011/12/29 16:59:20 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2011/12/29 16:58:48 | 004,399,505 | ---- | C] () -- C:\WINDOWS\System32\dllcache\nls302en.lex
[2011/12/29 16:58:03 | 000,348,160 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msinfo.dll
[2011/12/29 16:58:00 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2011/12/29 16:58:00 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2011/12/29 16:57:49 | 000,000,984 | ---- | C] () -- C:\WINDOWS\System32\dllcache\srframe.mmf
[2011/12/29 16:57:13 | 000,004,639 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mplayer2.exe
[2011/12/29 16:56:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2011/12/29 16:56:49 | 000,000,829 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2011/12/29 16:56:48 | 000,001,846 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk
[2011/12/29 16:56:13 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2011/12/29 16:56:13 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2011/12/29 16:56:13 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2011/12/29 16:56:13 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2011/12/29 16:56:13 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2011/12/29 16:56:12 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2011/12/29 16:56:12 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2011/12/29 16:56:12 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2011/12/29 16:56:12 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2011/12/29 16:56:12 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2011/12/29 16:56:12 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2011/12/29 16:56:07 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2011/12/29 16:56:07 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2011/12/29 16:56:04 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2011/12/29 16:55:51 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2003/03/31 13:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/03/31 13:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/03/31 13:00:00 | 000,311,604 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/03/31 13:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/03/31 13:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/03/31 13:00:00 | 000,152,576 | ---- | C] () -- C:\WINDOWS\System32\qasf.dll
[2003/03/31 13:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/03/31 13:00:00 | 000,039,992 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/03/31 13:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/03/31 13:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2003/03/31 13:00:00 | 000,004,573 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2003/03/31 13:00:00 | 000,004,461 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/03/31 13:00:00 | 000,001,740 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2003/03/31 13:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2012/01/01 21:58:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Caphyon
[2012/01/01 21:59:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ConeXware
[2012/01/01 18:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Janine\Application Data\IceChat
[2012/01/01 16:22:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Janine\Application Data\IObit
[2012/01/07 22:27:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Janine\Application Data\OpenOffice.org
[2012/01/23 22:46:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Janine\Application Data\Ugi

========== Purity Check ==========



< End of report >


Also perhaps worth mentioning, I transferred this info via my external hard drive - i tried to safely remove the hard drive from my PC and in response the computer decided to reboot itself...

Well, any help would be fantastic, thank you :)
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi it is a new variant that you have - but I have just finished beating my head against a wall on them ... And now know where it is :lol:

Could you open taskmanager and check the services - is there one called Safety Settings Service


Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - [2003/03/31 13:00:00 | 000,005,120 | ---- | M] (Iomega) [Auto | Running] -- C:\WINDOWS\system32\atchksrv.dll -- (USBAAPL)
    [2012/01/23 19:33:37 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Janine\Local Settings\Application Data\f06cada9

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks
  • Allow the installation of the recovery console

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

FINALLY

Download aswMBR.exe ( 4.1mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#3
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP