Hi Excal,
Thanks for you help and patience.
Was able to get a boot disk made finally!
Here is the rk files log:
ECHO is off
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINDOWS\SYSTEM\IEAccess2.dll: UPX!
Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
C:\WINDOWS\Unwash5.exe: UPX!
Finished
bye
Here is the FindIt log:
------- System Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 0EC4-50EC
Directory of C:\WINDOWS\SYSTEM
IGM32 DLL 227,104 06-26-05 10:03p IGM32.DLL
MVISAM11 DLL 227,104 06-26-05 10:03p MVISAM11.DLL
IUMUI DLL 227,104 06-26-05 10:03p IUMUI.DLL
RIPILIB DLL 227,104 06-26-05 10:03p RIPILIB.DLL
RQX DLL 227,104 06-26-05 10:03p Rqx.dll
5 file(s) 1,135,520 bytes
0 dir(s) 20,237.84 MB free
------- Hidden Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 0EC4-50EC
Directory of C:\WINDOWS\SYSTEM
VSCONFIG XML 1,006 07-17-05 8:14p vsconfig.xml
ZLLICTBL DAT 4,212 05-30-05 7:01a zllictbl.dat
HPF72H06 GID 8,628 10-20-04 6:52p HPF72h06.GID
HPF72T06 GID 8,628 10-20-04 6:51p HPF72t06.GID
LOG0 TXT 5,709 04-06-04 9:03p log0.txt
LOGBAK~1 TXT 29,416 04-06-04 9:03p log.bak.txt
LOG1 TXT 10,365 04-06-04 9:27a log1.txt
FIZ0 218 04-06-04 9:01a fiz0
LOG2 TXT 13,407 04-06-04 9:01a log2.txt
RATINGS POL 8,192 12-22-03 7:56p RATINGS.POL
HPF72D06 GID 8,628 11-21-03 6:14a HPF72d06.GID
DESKTOP INI 271 06-21-00 10:21a desktop.ini
FOLDER HTT 23,155 06-21-00 10:21a folder.htt
13 file(s) 121,835 bytes
0 dir(s) 20,237.81 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{08FB80A6-F0D2-0BFA-15F8-D2966C2977FA}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
vsconfig.xml Sun Jul 17 2005 8:14:08p A..H. 1,006 0.98 K
zllictbl.dat Mon May 30 2005 7:01:08a ...H. 4,212 4.11 K
igm32.dll Sun Jun 26 2005 10:03:56p ..S.R 227,104 221.78 K
mvisam11.dll Sun Jun 26 2005 10:03:56p ..S.R 227,104 221.78 K
iumui.dll Sun Jun 26 2005 10:03:56p ..S.R 227,104 221.78 K
ripilib.dll Sun Jun 26 2005 10:03:56p ..S.R 227,104 221.78 K
rqx.dll Sun Jun 26 2005 10:03:56p ..S.R 227,104 221.78 K
7 items found: 7 files, 0 directories.
Total of file sizes: 1,140,738 bytes 1.09 M
------------ Strings.exe Qoologic Results ------------
C:\WINDOWS\hosts: 127.0.0.1 www.qoologic.com
-------------- Strings.exe Aspack Results -------------
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"PCHealth"="C:\\WINDOWS\\PCHealth\\Support\\PCHSchd.exe -s"
"SystemTray"="SysTray.Exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"OEMRUNONCE"="c:\\windows\\options\\cabs\\oemrun.exe"
"Promon.exe"="Promon.exe"
"GWMDMMSG"="GWMDMMSG.exe"
"GWMDMpi"="C:\\WINDOWS\\GWMDMpi.exe"
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE"
"Keyboard Preload Check"="C:\\OEMDRVRS\\KEYB\\Preload.exe /DEVID:*PNP0320 /CLASS:Keyboard /RunValue:\"Keyboard Preload Check\""
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Gateway Ink Monitor"="C:\\Program Files\\Gateway\\Gateway Ink Monitor\\InkMonitor.exe"
"Iomega Startup Options"="C:\\Program Files\\Iomega\\Common\\ImgStart.exe"
"Iomega Drive Icons"="C:\\Program Files\\Iomega\\DriveIcons\\ImgIcon.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"tgcmd"="\"C:\\Program Files\\Support.com\\bin\\tgcmd.exe\" /server"
"NvCplDaemon"="RUNDLL32.EXE NvQTwk,NvCplDaemon initialize"
"nwiz"="nwiz.exe /install"
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"CamMonitor"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\hpqcmon.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\SYSTEM\\hpztsb10.exe"
"HP Component Manager"="\"C:\\PROGRAM FILES\\HP\\HPCORETECH\\HPCMPMGR.EXE\""
"HP Software Update"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"SUNASDTSERV"="C:\\PROGRAM FILES\\SUNBELT SOFTWARE\\COUNTERSPY CLIENT\\SUNASDTSERV.exe"
@=""
"sunasServ"="C:\\Program Files\\Sunbelt Software\\CounterSpy Client\\sunasServ.exe"
"QuickTime Task"="\"C:\\WINDOWS\\SYSTEM\\QTTASK.EXE\" -atboottime"
"CreateCD50"="C:\\PROGRA~1\\COMMON~1\\ADAPTE~1\\CREATECD\\CREATE~1.EXE -r"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
Thanks