2010-02-19 21:15:57 . 2010-02-19 21:15:57 105 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TPSMain.reg.dat
2010-02-19 21:15:57 . 2010-02-19 21:15:57 109 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TPSODDCtl.reg.dat
2010-02-19 21:15:57 . 2010-02-19 21:15:57 103 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TOSDCR.reg.dat
2010-02-19 21:15:57 . 2010-02-19 21:15:57 107 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-000StTHK.reg.dat
2010-02-19 21:15:57 . 2010-02-19 21:15:57 101 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-TFNF5.reg.dat
2010-02-13 17:21:40 . 2010-02-19 21:14:18 0 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2010-02-13 15:20:24 . 2010-02-13 17:23:48 10,577 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2010-02-13 15:11:09 . 2010-02-19 21:13:30 153 —-a-w- C:\Qoobox\Quarantine\catchme.log
2010-02-09 02:46:47 . 2010-02-09 02:46:47 8 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\mswintmp.dat.vir
2010-02-09 02:46:43 . 2010-02-09 02:46:43 1 —-a-w- C:\Qoobox\Quarantine\C\s.vir
2009-10-02 13:07:18 . 2009-10-02 13:07:18 74 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Favorites\Translator.url.vir
2009-09-24 02:44:23 . 2009-09-24 02:44:23 14 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Application Data\iniasd.txt.vir
2009-01-31 16:28:57 . 2009-01-31 16:28:57 3,321 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\c.js.vir
2009-01-31 16:28:57 . 2009-01-31 16:28:57 5,708 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\overlay.xul.vir
2009-01-31 16:28:57 . 2009-01-31 16:28:57 120 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome.manifest.vir
2009-01-31 16:28:57 . 2009-01-31 16:28:57 770 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\install.rdf.vir
2009-01-31 16:28:57 . 2009-01-31 16:28:57 2,129 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Tracie Borror\Local Settings\Application Data\{2DE85B80-910D-471B-85D3-748CA975C6DC}\chrome\content\_cfg.js.vir
2008-04-25 01:06:47 . 2008-04-25 01:06:47 13,864 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\AegisP.inf.vir
2008-04-25 01:00:00 . 2008-05-27 23:04:04 150,040 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxtray .exe.vir
2008-04-25 01:00:00 . 2008-05-27 23:03:58 141,848 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxpers .exe.vir
2008-04-25 01:00:00 . 2008-05-27 23:03:48 170,520 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\hkcmd .exe.vir
2008-04-14 00:11:51 . 2008-04-14 00:11:51 792,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\SET68C.tmp.vir
2008-01-10 20:04:54 . 2006-07-05 20:14:30 258,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\00thotkey .exe.vir
2008-01-10 20:04:54 . 2001-06-23 12:28:00 24,576 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\000stthk .exe.vir
2008-01-10 19:24:34 . 2004-08-03 21:00:00 382,464 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003109_.tmp.dll.vir
2008-01-10 17:53:33 . 2004-08-03 21:00:00 2,897,920 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003108_.tmp.dll.vir
2008-01-10 17:53:16 . 2006-08-17 12:28:27 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003048_.tmp.dll.vir
2008-01-10 17:53:16 . 2004-08-03 21:00:00 146,432 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003049_.tmp.dll.vir
2008-01-10 17:53:16 . 2004-08-03 21:00:00 101,888 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003050_.tmp.dll.vir
2008-01-10 17:53:15 . 2005-10-06 00:05:59 1,839,488 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003051_.tmp.dll.vir
2008-01-10 17:53:12 . 2005-03-02 18:09:30 577,024 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dll.vir
2008-01-10 17:53:08 . 2005-07-08 16:27:56 249,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\tapisrv.dll.vir
2008-01-10 17:53:06 . 2004-12-07 19:32:34 96,768 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003058_.tmp.dll.vir
2008-01-10 17:53:05 . 2005-06-10 23:53:32 57,856 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\spoolsv.exe.vir
2008-01-10 17:53:02 . 2004-08-03 21:00:00 22,040 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003059_.tmp.dll.vir
2008-01-10 17:53:01 . 2004-08-03 21:00:00 50,688 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003060_.tmp.dll.vir
2008-01-10 17:52:59 . 2004-08-03 21:00:00 983,552 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003061_.tmp.dll.vir
2008-01-10 17:52:59 . 2004-08-03 21:00:00 108,032 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003063_.tmp.dll.vir
2008-01-10 17:52:58 . 2004-08-03 21:00:00 144,896 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003064_.tmp.dll.vir
2008-01-10 17:52:57 . 2004-08-03 21:00:00 95,744 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003065_.tmp.dll.vir
2008-01-10 17:52:57 . 2004-08-03 21:00:00 415,744 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003067_.tmp.dll.vir
2008-01-10 17:52:57 . 2004-08-03 21:00:00 64,000 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003068_.tmp.dll.vir
2008-01-10 17:52:56 . 2008-04-14 00:12:33 33,280 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\rundll32 .exe.vir
2008-01-10 17:52:56 . 2005-07-26 04:20:40 398,336 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\rpcss.dll.vir
2008-01-10 17:52:54 . 2004-08-03 21:00:00 58,880 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003070_.tmp.dll.vir
2008-01-10 17:52:54 . 2004-08-03 21:00:00 61,440 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003071_.tmp.dll.vir
2008-01-10 17:52:54 . 2004-08-03 21:00:00 657,920 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003072_.tmp.dll.vir
2008-01-10 17:52:54 . 2004-08-03 21:00:00 236,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003074_.tmp.dll.vir
2008-01-10 17:52:50 . 2005-07-26 04:20:40 37,376 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003077_.tmp.dll.vir
2008-01-10 17:52:50 . 2004-08-03 21:00:00 553,472 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003078_.tmp.dll.vir
2008-01-10 17:52:46 . 2004-08-03 21:00:00 8,192 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003082_.tmp.dll.vir
2008-01-10 17:52:46 . 2004-08-03 21:00:00 708,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003083_.tmp.dll.vir
2008-01-10 17:52:41 . 2004-08-03 21:00:00 129,536 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003085_.tmp.dll.vir
2008-01-10 17:52:31 . 2006-08-17 12:28:27 721,920 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003088_.tmp.dll.vir
2008-01-10 17:52:30 . 2004-08-03 21:00:00 341,504 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003090_.tmp.dll.vir
2008-01-10 17:52:30 . 2004-08-03 21:00:00 249,270 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003091_.tmp.dll.vir
2008-01-10 17:52:30 . 2004-08-03 21:00:00 13,824 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003092_.tmp.dll.vir
2008-01-10 17:52:30 . 2005-09-01 01:41:53 19,968 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\linkinfo.dll.vir
2008-01-10 17:52:29 . 2006-07-05 10:55:01 984,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003093_.tmp.dll.vir
2008-01-10 17:52:25 . 2004-08-03 21:00:00 144,384 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003094_.tmp.dll.vir
2008-01-10 17:52:17 . 2005-07-26 04:20:28 243,200 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\es.dll.vir
2008-01-10 17:52:06 . 2006-05-19 12:59:41 111,616 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003097_.tmp.dll.vir
2008-01-10 17:52:05 . 2004-08-03 21:00:00 135,168 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003098_.tmp.dll.vir
2008-01-10 17:52:04 . 2004-08-03 21:00:00 32,768 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003099_.tmp.dll.vir
2008-01-10 17:52:01 . 2004-08-03 21:00:00 276,992 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003100_.tmp.dll.vir
2008-01-10 17:52:01 . 2006-08-25 15:45:58 617,472 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003101_.tmp.dll.vir
2008-01-10 17:51:51 . 2004-08-03 21:00:00 616,960 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_003106_.tmp.dll.vir
2007-02-02 23:39:34 . 2007-02-02 23:39:34 110,592 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\tpsoddctl .exe.vir
2006-07-27 00:03:28 . 2006-07-27 00:03:28 315,392 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\tpsmain .exe.vir
2006-04-11 01:14:52 . 2006-04-11 01:14:52 622,592 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\tfnf5 .exe.vir
2005-12-13 18:54:44 . 2005-12-13 18:54:44 57,344 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\tosdcr .exe.vir
Hi Snowflake343,
I have some more files to rsearch. Please be patient.
In the meantime please run SystemLook with this script
:filefind
igfxtray*igfxpers*
*hkcmd*
*user32.dll*
*tapisrv.dll*
*spoolsv.exe*
*rundll32*
*linkinfo*
*es*
Thanks
The output text file is 3.25 MB. How do you want me to post it?
Hi Snowflake343,
Sorry about that, that script had a parameter that would make it very long. Use this one instead. It will only take a few seconds.
Use this instead
:file
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\user32.dll
C:\WINDOWS\system32\tapisrv.dll
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rpcss.dll
C:\WINDOWS\system32\es.dll
C:\WINDOWS\system32\linkinfo.dll
Well that's much smaller.
Here's the log.
My Power Saver program is back. I don't see the Pointer program in the task bar, but I was able to turn off the knob-like mouse from the control panel "mouse" menu, which I couldn't do before, which is good. Yay!
Still no sound, though. The wheel on the front of the computer changes the sound, but it doesn't display it on the screen (to be able to tell you have to be in one of the other sound menus). Function keys are still not working either.
Hi Snowflake343,
Well we made some progress. We'll see if these copies are good.
We need some file informantion
Make sure to use Internet Explorer for this Please go to VirSCAN.org FREE on-line scan service Copy and paste the following file path, one at a time if more than file is listed, into the "Suspicious files to scan" box on the top of the page:
C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxtray .exe.vir
C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxpers .exe.vir
C:\Qoobox\Quarantine\C\WINDOWS\system32\hkcmd .exe.vir
Click on the Upload button Please ensure the scan is complete and the results saved before submitting the next. If a pop-up appears saying the file has been scanned already, please select the ReScan button. Once the Scan is completed, click on the "Copy to Clipboard " button. This will copy the link of the report into the Clipboard. Paste the contents of the Clipboard in your next reply.
Thanks
Hi Snowflake343,
I don't see the Pointer program in the task bar
This used to be located near the clock? Are there any other missing tray icons?
Right click the taskbar near the clock
Click Properties Click the customize button. Are there any items listed as Always Hide ? Is/are the missing icon(s) listed?
Please create this batch file
Open a new Notepad session
Click the Start button, click run in the run box type notepad click ok In the notepad, Click "Format" and be certain that Word Wrap is not checked .
Copy and paste all the text in the code box below into the Notepad. Do Not copy the word
CODE
copy "C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxtray .exe.vir" "C:\WINDOWS\system32\igfxtray.exe"
copy "C:\Qoobox\Quarantine\C\WINDOWS\system32\igfxpers .exe.vir" "c:\windows\system32\igfxpers.exe"
copy "C:\Qoobox\Quarantine\C\WINDOWS\system32\hkcmd .exe.vir" "c:\windows\system32\hkcmd.exe"
In the notepad
Click File , Save as …, and set the Save in to your Desktop In the filename box, type (including quotation marks) as the filename: "copy.bat" Click save
Double click
copy.bat to run it.
I'll check these logs again to see what we may be missing.
Thanks
Am I supposed to name it "myfix.bat" or "copy.bat"?
As far as I know, all of the icons are there. Though right now the arrow is gone and hiding some of the icons. It seems to randomly disappear sometimes. And I think the Pointer one also disappeared randomly even before I had all of these problems. Sometimes it was there and sometimes it wasn't. I'm not too worried about that one, though, since I got it to do what I wanted it to from the other menu.
Also, I don't know if it has any relevance to anything, but for some reason when I click on the IE tab thing in the explorer bar it doesn't minimize, it makes me click the button in the top corner. If it's a bother to fix, it's not too big of a deal, it's just annoying.
Something else that I had not thought of… (I know, I'm a pain, I apologize.) When I put a blank CD in my drive and go to click on it to open it in windows explorer, it tells me that it's an incorrect function and won't let me open or explore it. If I go into a program that writes on CDs, then it works just fine, but it won't let me access it via My Computer.
In My Computer, there's "CD Drive (D:)", and when I click on that, it gives me an error message saying: "D:\ Is not accessible. Incorrect function."
Hi
Sorry. Please use copy.bat for the name. I've fixed my previous instructions.
I'll have a look at the other problems.
Here's the log from OTL. If this is the wrong scan, let me know.
Hi Snowflake343,
Also, I don't know if it has any relevance to anything, but for some reason when I click on the IE tab thing in the explorer bar it doesn't minimize, it makes me click the button in the top corner. If it's a bother to fix, it's not too big of a deal, it's just annoying.
Not sure if it's relevent to the other problems but there may to a little fix to help. Any other programs with the same behavior?
Something else that I had not thought of… (I know, I'm a pain, I apologize.) When I put a blank CD in my drive and go to click on it to open it in windows explorer, it tells me that it's an incorrect function and won't let me open or explore it. If I go into a program that writes on CDs, then it works just fine, but it won't let me access it via My Computer.
In My Computer, there's "CD Drive (D:)", and when I click on that, it gives me an error message saying: "D:\ Is not accessible. Incorrect function."
No problem. Try this:
Right click on the drive and select properties and then the recording tab. Make sure the "Enable CD recording on this drive" box is checked.
Right click the taskbar near the clock
Click Properties
Click the customize button.
Are there any items listed as Always Hide ?
Is/are the missing icon(s) listed?
Did you check this?
I'm still looking into why the Fkeys are not functioning.
Thanks
The only other program with which I've noticed the minimizing problem is SuperAntiSpyware, but it's always done that. The only recently changed one that I've noticed is IE.
Yay! That fixed the CD Drive. You're magic. Thank you.
Take your time. I really appreciate all that you're doing.
Hi Snowflake343,
but for some reason when I click on the IE tab thing in the explorer bar it doesn't minimize
Instead of clicking it with your left mouse button, please right click on it and tell me what the menu says.
Thanks