This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis log included

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello eveyone! my dad gave me a computer he got for free from a friend but it seems to have some virus or something. a friend offered to look at it and help but it seems he didn't help at all!!! it just seems slower now and lags a lot and freezes when loading and loggin in. i saw about his site on a search and thought why not i have no idea what else to do.so i downloaded hijackthis and ran it and here's what it gave me. so much thanks to anyone willin to help!! :) Logfile of HijackThis v1.99.1 Scan saved at 12:08, on 06-12-02 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Documents and Settings\Administrator.USER-DN1AO2BERU\Desktop\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [lsass] C:\windows\system32\eliteveu32.exe O4 - HKLM\..\Run: [urnncvua] C:\WINDOWS\System32\urnncvua.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1153190093\EE\AOLHostManager.exe O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [e7d6512a.exe] C:\WINDOWS\System32\e7d6512a.exe O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe O4 - HKLM\..\Run: [SiS Mpc Service] C:\WINDOWS\System32\mpcsvc.exe O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_28.dll (file missing) O21 - SSODL: jQvPPRUelxB - {2F9AA011-8530-0ABB-E50D-6FF2616352DA} - C:\WINDOWS\System32\bcz.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\aolserv.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!




You are running HJT directly from the desktop.
Create a folder called HJT either in C: or My documents and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .



___________________

I see no signs of an anti virus program.. I suggest you get one in asap.
I will list 2 free anti virus programs just choose 1.

AVG FREE

Avast

Download and install one of these and run a full scan.



________________

Please download LQfix.exe from one of the following locations:
http://www.downloads.subratam.org/LQfix.exe
http://miekiemoes.geekstogo.com/tools/LQfix.exe

Save it to your desktop and Double-Click LQfix.exe and click Next > Next > Install.
Leave the default settings, if you change them, the fix will Fail!
You need an active Internet Connection, so make sure your you're not blocking any connection now.
Now make sure the "Launch LQfix" box is checked.
Click the Finish button, after clicking the Finish button the fix will start.
Follow the on-screen prompts and Your system will reboot afterwards
Please be patient after the reboot, there is a script running in the background that needs to complete.



In your next reply I would like to see:
  • A new HJT log
Alright, thanks for your help! Sorry it took so long for me to respond as i still have dialup and it kept booting me while i was trying to download the antivirus program. out of curiousity, what does LQfix do? here is my new hijackThis log: Logfile of HijackThis v1.99.1 Scan saved at 2:25:11 PM, on 12/4/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\HJT\HijackThis.exe O2 - BHO: (no name) - {1E33120B-0518-B3DD-6EDF-0AA358C58F9F} - C:\WINDOWS\System32\lcsilx.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {69C52FBF-228C-C2FB-FDCF-0858B28307D8} - C:\WINDOWS\System32\vyqfwzg.dll O2 - BHO: (no name) - {75CAD05A-D6CF-A048-FF10-015C28A5D9AB} - C:\WINDOWS\System32\qwvmrgk.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [urnncvua] C:\WINDOWS\System32\urnncvua.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe O4 - HKLM\..\Run: [hfvqlug.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\hfvqlug.dll,lxfaoe O4 - HKLM\..\Run: [lbitnjb.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\lbitnjb.dll,xkmjtr O4 - HKLM\..\Run: [amqdajn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\amqdajn.dll,pvtbded O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll (file missing) O21 - SSODL: jQvPPRUelxB - {2F9AA011-8530-0ABB-E50D-6FF2616352DA} - C:\WINDOWS\System32\bcz.dll (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe thanks so much for your help! :)
Didn't realize your were on dial up.

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked



O2 - BHO: (no name) - {1E33120B-0518-B3DD-6EDF-0AA358C58F9F} - C:\WINDOWS\System32\lcsilx.dll
O2 - BHO: (no name) - {69C52FBF-228C-C2FB-FDCF-0858B28307D8} - C:\WINDOWS\System32\vyqfwzg.dll
O2 - BHO: (no name) - {75CAD05A-D6CF-A048-FF10-015C28A5D9AB} - C:\WINDOWS\System32\qwvmrgk.dll


O4 - HKLM\..\Run: [urnncvua] C:\WINDOWS\System32\urnncvua.exe
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [hfvqlug.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\hfvqlug.dll,lxfaoe
O4 - HKLM\..\Run: [lbitnjb.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\lbitnjb.dll,xkmjtr
O4 - HKLM\..\Run: [amqdajn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\amqdajn.dll,pvtbded
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll (file missing)
O21 - SSODL: jQvPPRUelxB - {2F9AA011-8530-0ABB-E50D-6FF2616352DA} - C:\WINDOWS\System32\bcz.dll (file missing)




Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
____________________________
Please download the Killbox by Option^Explicit

Note: In the event you already have Killbox, this is a new version that I need you to download.
Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll
C:\WINDOWS\System32\bcz.dll
C:\WINDOWS\System32\amqdajn.dll
C:\WINDOWS\System32\lbitnjb.dll
C:\WINDOWS\System32\urnncvua.exe
C:\WINDOWS\System32\qwvmrgk.dll
C:\WINDOWS\System32\vyqfwzg.dll
C:\WINDOWS\System32\lcsilx.dll



Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.



In your next reply I would like to see:
  • A new HJT log
  • The report from S&D fix ( Report.txt )
All steps completed ! Here's the reports: Logfile of HijackThis v1.99.1 Scan saved at 5:22:13 PM, on 12/4/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\wuauclt.exe C:\HJT\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe SDFix: Version 1.44 **************** Mon 12/04/2006 - 17:08:15.20 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Stage One - Safe Mode Checking Services… Service Name: File Path: Starting Registry Repairs… Restoring Default Hosts File… Stage One Complete Rebooting… Stage Two - Normal Mode Checking For Malware: ——————– C:\DOCUME~1\work\LOCALS~1\Temp\Wing.pal Backing Up and Removing any Files Found… Final Check: Services: ——— Authorized Applications Export: Files: —— Backups Folder: - C:\SDFix\backups\backups.zip Checking for files with Hidden Attributes: C:\Program Files\Accessories\mspcx32.dll C:\Program Files\Accessories\HyperTerminal\hticons.dll C:\Program Files\Accessories\HyperTerminal\hypertrm.dll C:\WINDOWS\SYSTEM32\.exe C:\WINDOWS\SYSTEM32\cdplayer.exe.manifest C:\WINDOWS\SYSTEM32\logonui.exe.manifest C:\MSDOS.SYS C:\IO.SYS C:\hiberfil.sys C:\CONFIG.SYS C:\pagefile.sys FINISHED! thanks again
Looking much better.



1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Post that and 1 more HJT log.
Okay, did those things. Don't know if its important but last time i connected online i got a winservices had an error and had to close message. here's the logs. work - 06-12-04 19:32:30.00 Service Pack 1 ComboFix 06.11.27W - Running from: "C:\Documents and Settings\work\Desktop" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\vxgamet2.exe C:\WINDOWS\system32\vxgamet4.exe C:\WINDOWS\system32\vxgame3.exe C:\WINDOWS\system32\vxgame4.exe C:\WINDOWS\system32\vxgamet1.exe C:\WINDOWS\system32\vxgamet3.exe C:\WINDOWS\system32\vxgame1.exe C:\WINDOWS\xpupdate.exe C:\WINDOWS\system32\bszip.dll C:\WINDOWS\system32\cmd.com C:\WINDOWS\system32\kernels8.exe C:\WINDOWS\system32\maxd641.exe C:\WINDOWS\system32\netstat.com C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\regedit.com C:\WINDOWS\system32\taskkill.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\tracert.com C:\Program Files\winupdates C:\WINDOWS\system32\2236_28.dll C:\WINDOWS\system32\2236_28.dll C:\Documents and Settings\All Users\Documents\Settings C:\WINDOWS\system32\2236_28.dll C:\Documents and Settings\All Users\Documents\Settings C:\Documents and Settings\All Users\Documents\Settings ((((((((((((((((((((((((((((((( Files Created from 2006-11-02 to 2006-12-02 )))))))))))))))))))))))))))))))))) 2006-12-04 19:12 d——– C:\Documents and Settings\work\Application Data\Canon 2006-12-04 18:55 d——– C:\Documents and Settings\All Users\Application Data\Adobe Systems 2006-12-04 18:39 5,632 –a—— C:\WINDOWS\SYSTEM32\ptpusb.dll 2006-12-04 18:39 150,528 –a—— C:\WINDOWS\SYSTEM32\ptpusd.dll 2006-12-04 18:39 14,208 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbscan.sys 2006-12-04 17:13 d——– C:\!KillBox 2006-12-04 17:04 d——– C:\SDFix 2006-12-04 16:28 d——– C:\Program Files\InstallShield Installation Information 2006-12-04 16:28 d——– C:\Program Files\Canon 2006-12-04 16:21 d——– C:\Program Files\Common Files\Adobe Systems Shared 2006-12-04 16:20 d——– C:\Documents and Settings\All Users\Application Data\Adobe 2006-12-04 16:14 d——– C:\Program Files\PHOTO 2006-12-03 17:34 dr-h—– C:\$VAULT$.AVG 2006-12-03 16:54 4,960 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgtdi.sys 2006-12-03 16:54 4,224 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsw.sys 2006-12-03 16:54 3,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys 2006-12-03 16:54 28,416 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsxp.sys 2006-12-03 16:54 18,240 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys 2006-12-03 16:54 d——– C:\Documents and Settings\work\Application Data\AVG7 2006-12-03 16:53 816,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys 2006-12-03 16:53 d——– C:\Program Files\Grisoft 2006-12-03 16:53 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-12-03 16:53 d——– C:\Documents and Settings\All Users\Application Data\avg7 2006-12-03 12:57 d——– C:\Documents and Settings\work\.housecall6.6 2006-12-03 11:46 d——– C:\Documents and Settings\work\Application Data\Lavasoft 2006-12-03 11:33 d——– C:\WINDOWS\SoftwareDistribution 2006-12-03 11:19 420,632 –a—— C:\WINDOWS\SYSTEM32\wuapi.dll 2006-12-03 11:19 39,704 –a—— C:\WINDOWS\SYSTEM32\wups.dll 2006-12-03 11:19 186,136 –a—— C:\WINDOWS\SYSTEM32\wuaueng1.dll 2006-12-03 11:19 167,704 –a—— C:\WINDOWS\SYSTEM32\wuauclt1.exe 2006-12-03 11:19 120,288 –a—— C:\WINDOWS\SYSTEM32\wuweb.dll 2006-12-03 11:19 118,552 –a—— C:\WINDOWS\SYSTEM32\wucltui.dll 2006-12-03 10:51 d——– C:\HJT 2006-12-03 09:52 d——– C:\WINDOWS\LQfix 2006-12-03 09:38 94,720 –a—— C:\WINDOWS\SYSTEM32\hfvqlug.dll 2006-12-03 09:38 107,520 –a—— C:\Documents and Settings\work\loaded.exe 2006-12-02 13:27 d——– C:\Program Files\Spybot - Search & Destroy 2006-12-02 13:27 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2006-12-02 13:05 d——– C:\Program Files\Lavasoft 2006-12-02 11:16 360 –a—— C:\Combo.bat (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "AOL Fast Start"="\"C:\\Program Files\\America Online 9.0\\AOL.EXE\" -b" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "NoActiveDesktop"=dword:00000000 "ForceActiveDesktopOn"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: 06-12-04 19:37:30.09 C:\ComboFix.txt … 06-12-04 19:37 Logfile of HijackThis v1.99.1 Scan saved at 7:38:50 PM, on 12/4/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\HJT\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
recently got a rectangular error message saying lsass.exe had terminated unexpectedly and the machine had to shut down… it had a countdown and an red and white x icon.
I see you have AVG installed. Lets update it and set it up the way I ask and do a scan.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates
Do not use it yet.


________________________________________
Safe mode:
Please reboot to safe mode:
After the very first black screen start tapping the
F8 key untill prompted with a list choose safe
mode.




_________________________________________
AVG Part 2
AVG
Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
Click on scanner
Click on Settings
Under How to act
Choose quarintine

Under Reports check automatically create report after every scan.
Now back to the scan tab andClick on Complete system scan

Let the program scan the machine .
When finished click apply all actions.


Exit AVG.
It will save a log in C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Reboot normaly.

Post the log from AVG and a new Hijackthis log.

Reboot Normaly

______________________


Please go HERE and do a online scan.
Let me know what is found.

______________________

In your next reply I would like to see:
  • A new HJT log
  • The report from the online scan
  • The report from AVG.
  • Let me know if the lsass.exe error continuesThe
Okay… I didn't have the scanning options in AVG that you described. I ran a full scan but it came back clean. I have gotten the lsass.exe error once again. Here's the other two reports.

Scanning Report Tuesday, December 05, 2006 17:34:31 - 18:33:13 Computer name: USER-DN1AO2BERU Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ ———————————————————————— Result: 1 malware found W32/Malware (virus) * C:\DOCUMENTS AND SETTINGS\WORK\LOADED.EXE (Submitted) ———————————————————————— Statistics Scanned: * Files: 12135 * System: 3253 * Not scanned: 4 Actions: * Disinfected: 0 * Renamed: 0 * Deleted: 0 * None: 1 * Submitted: 1 Files not scanned: * C:\HIBERFIL.SYS * C:\PAGEFILE.SYS * C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{C851EA67-B2FA-4D31-9371-A83C7B8C928C}.BIN * C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT ———————————————————————— Options Scanning engines: * F-Secure Libra: 2.4.2, 2006-12-05 * F-Secure AVP: 7.0.171, 2006-12-05 * F-Secure Orion: 1.2.37, 2006-12-04 * F-Secure Blacklight: 1.0.31, 0000-00-00 * F-Secure Draco: 1.0.35, 0260-02-44 * F-Secure Pegasus: 1.19.0, 2006-11-03 Scanning options: * Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX * Use Advanced heuristics ———————————————————————— Copyright © 1998-2006 Product support |Send virus sample to F-Secure F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.



Logfile of HijackThis v1.99.1
Scan saved at 6:40:29 PM, on 12/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Download this tool and run it. Let me know if it finds anything.

Sasser removal



_____________________

Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\SYSTEM32\hfvqlug.dll
C:\Documents and Settings\work\loaded.exe


Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.



____________________


Please download WinPFind2.
  • Extract the files to a folder(eg: C:\WinPFind2).
  • Double click WinPFind2.exe to start the program.
  • Click the Select All button in the File Options box of the Configuration tab(this is the tab the program opens up to by default).
  • Click the Run all Scans button.
  • When its finished scanning you will see Scans Complete! at the bottom left of the program.
  • Click the Export to Text button.
  • Notepad will open with the results of the scan and the log will be saved to the folder that you extracted the program to(C:\WinPFind2\WinPFind2.txt)
  • Post the log in your next reply please. You may need to split the log over a couple posts so that it doesn't get cut off. If so please use the [Start Post #1] and [Start Post #2] deliminators in the log to split the log up.
In your next reply I would like to see:
  • A new HJT log
  • The report from winp2 log
  • If sasser removal tool found anything
  • Let me know if the lsass error continues
Haven't gotten the lsass error since last night.
Killbox did not need me to run missingfiles.exe

Here's the reports:

Logfile of HijackThis v1.99.1
Scan saved at 5:37:21 PM, on 12/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
[Start Post #1] Processes Image Name—————ProcessID–Thread Count–Parent ID–Base Priority– #Full Path ##(Version Info) avgamsvr.exe————-001140—–0007———-000472—–Normal——— #c:\progra~1\grisoft\avgfre~1\avgamsvr.exe ##(GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 343552 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) avgcc.exe—————-001356—–0008———-001024—–Normal——— #c:\progra~1\grisoft\avgfre~1\avgcc.exe ##(GRISOFT, s.r.o. [Ver = 7.5.0.418 | Size = 406016 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) avgemc.exe—————001228—–0008———-000472—–Normal——— #c:\progra~1\grisoft\avgfre~1\avgemc.exe ##(GRISOFT, s.r.o. [Ver = 7.5.0.432 | Size = 323072 bytes | Date = 12/5/2006 10:35:02 AM | Attr = ]) avgupsvc.exe————-001180—–0003———-000472—–Normal——— #c:\progra~1\grisoft\avgfre~1\avgupsvc.exe ##(GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) ipodservice.exe———-001584—–0008———-000472—–Normal——— #c:\program files\ipod\bin\ipodservice.exe ##(Apple Computer, Inc. [Ver = 4.7.0.42 | Size = 327680 bytes | Date = 10/13/2004 4:03:54 PM | Attr = ]) ituneshelper.exe———001208—–0006———-001024—–Normal——— #c:\program files\itunes\ituneshelper.exe ##(Apple Computer, Inc. [Ver = 4.7.0.42 | Size = 278528 bytes | Date = 10/13/2004 4:04:14 PM | Attr = ]) jusched.exe————–001304—–0001———-001024—–Normal——— #c:\program files\java\jre1.5.0_06\bin\jusched.exe ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Date = 11/10/2005 1:03:52 PM | Attr = ]) winpfind2.exe————000216—–0002———-001024—–Normal——— #c:\winpfind2\winpfind2\winpfind2.exe ##(OldTimer Tools [Ver = 1.0.15.0 | Size = 397312 bytes | Date = 11/16/2006 6:07:22 AM | Attr = ]) Registry Entries #Value ##(Version Info) <<< >> Internet Explorer Settings << >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page #http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page #http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL #http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_URL #http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page #%SystemRoot%\system32\blank.htm ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page #http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page #http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ## HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Local Page #C:\WINDOWS\System32\blank.htm ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomizeSearch #http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ## HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant #http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ## HKCU\Software\Microsoft\Internet Explorer\urlSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} #Microsoft Url Search Hook = %SystemRoot%\System32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1341440 bytes | Date = 7/16/2003 3:44:36 PM | Attr = ]) HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable #0 ## <<< >> BHO's << >>> HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F} #Reg Data - Value does not exist = C:\Program Files\Spybot - Search & Destroy\SDHelper.dll ##(Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Date = 5/31/2005 1:04:00 AM | Attr = ]) <<< >> Internet Explorer Bars, Toolbars and Extensions << >>> <<< HKLM-> Internet Explorer Bars >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376} #&Tip of the Day = %SystemRoot%\System32\shdocvw.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1341440 bytes | Date = 7/16/2003 3:44:36 PM | Attr = ]) <<< HKCU-> Internet Explorer Bars >>> HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478} #Media Band = %SystemRoot%\System32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1021952 bytes | Date = 7/16/2003 3:24:56 PM | Attr = ]) <<< HKLM-> Internet Explorer ToolBars >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{8E718888-423F-11D2-876E-00A0C9082467} #&Radio = C:\WINDOWS\System32\msdxm.ocx ##( [Ver = | Size = 842268 bytes | Date = 7/16/2003 3:35:34 PM | Attr = ]) <<< HKCU-> Internet Explorer ToolBars >>> HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} #&Address = %SystemRoot%\System32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1021952 bytes | Date = 7/16/2003 3:24:56 PM | Attr = ]) HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} #&Links = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 8336384 bytes | Date = 7/16/2003 3:44:38 PM | Attr = ]) HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} #AOL Toolbar = C:\Program Files\AOL Toolbar\toolbar.dll ##(File not found) <<< HKCU-> Internet Explorer CmdMapping >>> HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} #8196 - Sun Java Console ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} #8195 - Reg Data - Key not found ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} #8192 - Reg Data - Value does not exist ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} #8194 - Reg Data - Key not found ## HKCU\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\NextId #8197 ## <<< HKLM-> Internet Explorer Extensions >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} #MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Date = 11/10/2005 1:22:12 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} #ButtonText: AIM = C:\PROGRA~1\AIM\aim.exe ##(America Online, Inc. [Ver = 5.9.3702 | Size = 67160 bytes | Date = 12/8/2004 3:50:04 PM | Attr = ]) <<< HKCU-> Internet Explorer Menu Extensions >>> HKCU\Software\Microsoft\Internet Explorer\MenuExt\&AOL Toolbar search #res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML ##(File not found) <<< HKLM-> Internet Explorer Plugins >>> HKLM\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension\.pdf #Adobe Acrobat = C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll ##(Adobe Systems Inc. [Ver = 6.0.0.2003051500 | Size = 133376 bytes | Date = 5/15/2003 12:01:48 AM | Attr = ]) <<< >> Approved Shell Extensions (Non-Microsoft only) << >>> <<< HKLM-> Approved Shell Extensions >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} #Taskbar and Start Menu = Reg Data - Key not found ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{42071714-76d4-11d1-8b24-00a0c9068ff3} #Display Panning CPL Extension = deskpan.dll ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{764BF0E1-F219-11ce-972D-00AA00A14F56} #Shell extensions for file compression = Reg Data - Key not found ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{7A9D77BD-5403-11d2-8785-2E0420524153} #User Accounts = Reg Data - Key not found ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} #Encryption Context Menu = Reg Data - Key not found ##(File not found) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{88895560-9AA2-1069-930E-00AA0030EBC8} #HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll ##(Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Date = 7/16/2003 3:29:42 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} #AVG7 Shell Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7.5.0.409 | Size = 50688 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} #AVG7 Find Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7.5.0.409 | Size = 50688 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\\{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} #iTunes = C:\Program Files\iTunes\iTunesMiniPlayer.dll ##(Apple Computer, Inc. [Ver = 4.7.0.42 | Size = 102400 bytes | Date = 10/13/2004 4:03:06 PM | Attr = ]) <<< >> ContextMenuHandlers (Non-Microsoft only) << >>> <<< HKLM-> ContextMenuHandlers >>> HKLM\Software\Classes\*\shellex\ContextMenuHandlers\AVG7 Shell Extension #{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7.5.0.409 | Size = 50688 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\AVG7 Shell Extension #{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll ##(GRISOFT, s.r.o. [Ver = 7.5.0.409 | Size = 50688 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) <<< >> ColumnHandlers (Non-Microsoft only) << >>> <<< HKLM-> ColumnHandlers >>> <<< >> File Associations Keys << >>> HKLM\SOFTWARE\Classes\.bat\\'' #batfile ## HKLM\SOFTWARE\Classes\batfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.cmd\\'' #cmdfile ## HKLM\SOFTWARE\Classes\cmdfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.com\\'' #comfile ## HKLM\SOFTWARE\Classes\comfile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.exe\\'' #exefile ## HKLM\SOFTWARE\Classes\exefile\shell\open\command\\'' #"%1" %* ## HKLM\SOFTWARE\Classes\.hta\\'' #htafile ## HKLM\SOFTWARE\Classes\htafile\shell\open\command\\'' #C:\WINDOWS\System32\mshta.exe "%1" %* ## HKLM\SOFTWARE\Classes\.js\\'' #JSFile ## HKLM\SOFTWARE\Classes\jsfile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.jse\\'' #JSEFile ## HKLM\SOFTWARE\Classes\jsefile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.scr\\'' #scrfile ## HKLM\SOFTWARE\Classes\scrfile\shell\open\command\\'' #"%1" /S ## HKLM\SOFTWARE\Classes\.vbe\\'' #VBEFile ## HKLM\SOFTWARE\Classes\vbefile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.vbs\\'' #VBSFile ## HKLM\SOFTWARE\Classes\vbsfile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.wsf\\'' #WSFFile ## HKLM\SOFTWARE\Classes\wsffile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.wsh\\'' #WSHFile ## HKLM\SOFTWARE\Classes\wshfile\shell\open\command\\'' #%SystemRoot%\System32\WScript.exe "%1" %* ## HKLM\SOFTWARE\Classes\.txt\\'' #txtfile ## HKLM\SOFTWARE\Classes\txtfile\shell\open\command\\'' #%SystemRoot%\system32\NOTEPAD.EXE %1 ## <<< >> Registry Run Keys << >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AVG7_CC #C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP ##(GRISOFT, s.r.o. [Ver = 7.5.0.418 | Size = 406016 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper #C:\Program Files\iTunes\iTunesHelper.exe ##(Apple Computer, Inc. [Ver = 4.7.0.42 | Size = 278528 bytes | Date = 10/13/2004 4:04:14 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task #"C:\Program Files\QuickTime\qttask.exe" -atboottime ##(Apple Computer, Inc. [Ver = 6.5.1 | Size = 98304 bytes | Date = 5/13/2005 6:51:32 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched #C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe ##(Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Date = 11/10/2005 1:03:52 PM | Attr = ]) HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AOL Fast Start #"C:\Program Files\America Online 9.0\AOL.EXE" -b ##(File not found) <<< >> Miscellaneous Startup Keys << >>> <<< AppInit DLLs >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs # ##(File not found) <<< Image File Execution Options >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path #Debugger = ntsd -d ## <<< Shell Service Object Delay Load >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn #{fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 8336384 bytes | Date = 7/16/2003 3:44:38 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\PostBootReminder #{7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 8336384 bytes | Date = 7/16/2003 3:44:38 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SysTray #{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 117760 bytes | Date = 7/16/2003 3:46:54 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck #{E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 258048 bytes | Date = 7/16/2003 3:51:06 PM | Attr = ]) <<< Shell Execute Hooks >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} #URL Exec Hook = shell32.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 8336384 bytes | Date = 7/16/2003 3:44:38 PM | Attr = ]) <<< Shared Task Scheduler >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{438755C2-A8BA-11D1-B96B-00A0C90312E1} #Browseui preloader = %SystemRoot%\System32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1021952 bytes | Date = 7/16/2003 3:24:56 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{8C7461EF-2B13-11d2-BE35-3078302C2030} #Component Categories cache daemon = %SystemRoot%\System32\browseui.dll ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1021952 bytes | Date = 7/16/2003 3:24:56 PM | Attr = ]) <<< SafeBoot Option >>> <<< HKLM Command Processor AutoRun >>> HKLM\SOFTWARE\Microsoft\Command Processor\\AutoRun # ## <<< HKCU Command Processor AutoRun >>> <<< Security Providers >>> HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders #msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll ## <<< BootExecute >>> HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\\BootExecute #autocheck autochk *; ## <<< PendingFileRenameOperations >>> <<< FileRenameOperations >>> <<< ExcludeFromKnownDlls >>> HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\\ExcludeFromKnownDlls # ## <<< >> Disabled MSConfig Items << >>> <<< >> User Agent Post Platform << >>> HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\() # ## HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\(none) # ## HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\acc=none # ## <<< >> Winlogon << >>> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\AltDefaultDomainName #USER-DN1AO2BERU ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\AltDefaultUserName #work ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\AutoAdminLogon #Reg Data - Value does not exist ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\DefaultDomainName #USER-DN1AO2BERU ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\DefaultUserName #work ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell #Explorer.exe ##(Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 1004032 bytes | Date = 7/16/2003 3:28:10 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System # ##(File not found) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit #C:\WINDOWS\system32\userinit.exe, ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 22016 bytes | Date = 7/16/2003 3:49:24 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet #rundll32 shell32,Control_RunDLL "sysdm.cpl" ## HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain #crypt32.dll ##(Microsoft Corporation [Ver = 5.131.2600.1106 (xpsp1.020828-1920) | Size = 557568 bytes | Date = 7/16/2003 3:25:58 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet #cryptnet.dll ##(Microsoft Corporation [Ver = 5.131.2600.0 (xpclient.010817-1148) | Size = 53248 bytes | Date = 7/16/2003 3:26:00 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll #cscdll.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 89600 bytes | Date = 7/16/2003 3:26:00 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 86528 bytes | Date = 7/16/2003 3:52:02 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 86528 bytes | Date = 7/16/2003 3:52:02 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy #sclgntfy.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 18432 bytes | Date = 7/16/2003 3:43:58 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn #WlNotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 86528 bytes | Date = 7/16/2003 3:52:02 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 86528 bytes | Date = 7/16/2003 3:52:02 PM | Attr = ]) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon #wlnotify.dll ##(Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 86528 bytes | Date = 7/16/2003 3:52:02 PM | Attr = ]) <<< >> DNS Name Servers << >>> HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1F36D2BB-1079-4861-BBFE-4503A3F37246} # (D-Link DFE-530TX PCI Fast Ethernet Adapter (rev.A)) ## <<< >> All Winsock2 Catalogs << >>> HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001 #%SystemRoot%\System32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002 #%SystemRoot%\System32\winrnr.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 14848 bytes | Date = 7/16/2003 3:51:50 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003 #%SystemRoot%\System32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004 #%SystemRoot%\system32\rsvpsp.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 7/16/2003 3:43:32 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005 #%SystemRoot%\system32\rsvpsp.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 7/16/2003 3:43:32 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015 #%SystemRoot%\system32\mswsock.dll ##(Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 228352 bytes | Date = 7/16/2003 3:37:00 PM | Attr = ]) <<< >> Protocol Handlers (Non-Microsoft only) << >>> HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\ipp # ##(File not found) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp # ##(File not found) HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\vnd.ms.radio #C:\WINDOWS\System32\msdxm.ocx ##( [Ver = | Size = 842268 bytes | Date = 7/16/2003 3:35:34 PM | Attr = ]) <<< >> Protocol Filters (Non-Microsoft only) << >>>
[Start Post #2]

Services
Name–Internal Name–Startup Type–State–Service Type–
#Path
##(Version Info)

AVG7 Alert Manager Server–Avg7Alrt–Automatic–Running–Win32, running in it's own process–
#C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
##(GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 343552 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ])

AVG7 Update Service–Avg7UpdSvc–Automatic–Running–Win32, running in it's own process–
#C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
##(GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Date = 12/3/2006 4:53:58 PM | Attr = ])

AVG E-mail Scanner–AVGEMS–Automatic–Running–Win32, running in it's own process–
#C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
##(GRISOFT, s.r.o. [Ver = 7.5.0.432 | Size = 323072 bytes | Date = 12/5/2006 10:35:02 AM | Attr = ])

iPod Service–iPodService–On Demand–Running–Win32, running in it's own process–
#C:\Program Files\iPod\bin\iPodService.exe
##(Apple Computer, Inc. [Ver = 4.7.0.42 | Size = 327680 bytes | Date = 10/13/2004 4:03:54 PM | Attr = ])


Files
Full Path
#Details

%SystemDrive%
#

%ProgramFilesDir%
#

%WinDir%
#

%System%
#

C:\WINDOWS\SYSTEM32\dfrg.msc
#PEC2 ( [Ver = | Size = 41397 bytes | Date = 7/16/2003 3:26:44 PM | Attr = ])

C:\WINDOWS\SYSTEM32\nusrmgr.cpl
#WSUD (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 7/16/2003 3:40:02 PM | Attr = ])

C:\WINDOWS\SYSTEM32\wbdbase.deu
#winsync ( [Ver = | Size = 1309184 bytes | Date = 7/16/2003 3:50:38 PM | Attr = ])

C:\WINDOWS\SYSTEM32\rasdlg.dll
#Umonitor (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 631808 bytes | Date = 7/16/2003 3:42:40 PM | Attr = ])

C:\WINDOWS\SYSTEM32\MRT.exe
#PECompact2 (Microsoft Corporation [Ver = 1.19.1567.0 | Size = 8325544 bytes | Date = 8/9/2006 12:03:06 PM | Attr = ])

C:\WINDOWS\SYSTEM32\MRT.exe
#aspack (Microsoft Corporation [Ver = 1.19.1567.0 | Size = 8325544 bytes | Date = 8/9/2006 12:03:06 PM | Attr = ])

%System%\Drivers folder and sub-folders
#

C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
#UPX! (GRISOFT, s.r.o. [Ver = 7.5.0.429 | Size = 816672 bytes | Date = 12/3/2006 4:54:00 PM | Attr = ])

C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
#FSG! (GRISOFT, s.r.o. [Ver = 7.5.0.429 | Size = 816672 bytes | Date = 12/3/2006 4:54:00 PM | Attr = ])

C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
#PEC2 (GRISOFT, s.r.o. [Ver = 7.5.0.429 | Size = 816672 bytes | Date = 12/3/2006 4:54:00 PM | Attr = ])

C:\WINDOWS\SYSTEM32\drivers\avg7core.sys
#aspack (GRISOFT, s.r.o. [Ver = 7.5.0.429 | Size = 816672 bytes | Date = 12/3/2006 4:54:00 PM | Attr = ])

%windir% + sub-dirs for System or Hidden files less than 60 days old
#

C:\WINDOWS\bootstat.dat
# ( [Ver = | Size = 2048 bytes | Date = 12/6/2006 4:46:32 PM | Attr = S])

C:\WINDOWS\QTFont.qfn
# ( [Ver = | Size = 54156 bytes | Date = 12/6/2006 7:44:34 AM | Attr = H ])

C:\WINDOWS\INF\oem3.inf
# ( [Ver = | Size = 0 bytes | Date = 12/3/2006 11:19:06 AM | Attr = H ])

C:\WINDOWS\SYSTEM32\.exe
# ( [Ver = | Size = 50176 bytes | Date = 12/5/2006 8:01:06 PM | Attr = HS])

C:\WINDOWS\SYSTEM32\config\SECURITY.LOG
# ( [Ver = | Size = 1024 bytes | Date = 12/6/2006 4:56:44 PM | Attr = H ])

C:\WINDOWS\SYSTEM32\config\SOFTWARE.LOG
# ( [Ver = | Size = 1024 bytes | Date = 12/6/2006 4:48:04 PM | Attr = H ])

C:\WINDOWS\SYSTEM32\config\SYSTEM.LOG
# ( [Ver = | Size = 1024 bytes | Date = 12/6/2006 4:47:36 PM | Attr = H ])

C:\WINDOWS\SYSTEM32\config\DEFAULT.LOG
# ( [Ver = | Size = 1024 bytes | Date = 12/6/2006 4:47:12 PM | Attr = H ])

C:\WINDOWS\SYSTEM32\config\SAM.LOG
# ( [Ver = | Size = 1024 bytes | Date = 12/6/2006 4:46:36 PM | Attr = H ])

C:\WINDOWS\TASKS\SA.DAT
# ( [Ver = | Size = 6 bytes | Date = 12/6/2006 4:46:38 PM | Attr = H ])

CPL files
#

C:\WINDOWS\SYSTEM32\hdwwiz.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 150016 bytes | Date = 7/16/2003 3:29:16 PM | Attr = ])

C:\WINDOWS\SYSTEM32\main.cpl
# (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 7/16/2003 3:32:24 PM | Attr = ])

C:\WINDOWS\SYSTEM32\mmsys.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 559616 bytes | Date = 7/16/2003 3:33:56 PM | Attr = ])

C:\WINDOWS\SYSTEM32\ncpa.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 7/16/2003 3:37:18 PM | Attr = ])

C:\WINDOWS\SYSTEM32\nusrmgr.cpl
# (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 7/16/2003 3:40:02 PM | Attr = ])

C:\WINDOWS\SYSTEM32\odbccp32.cpl
# (Microsoft Corporation [Ver = 3.520.7713.0 | Size = 36864 bytes | Date = 7/16/2003 3:40:18 PM | Attr = ])

C:\WINDOWS\SYSTEM32\powercfg.cpl
# (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 109056 bytes | Date = 7/16/2003 3:41:58 PM | Attr = ])

C:\WINDOWS\SYSTEM32\telephon.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 7/16/2003 3:47:58 PM | Attr = ])

C:\WINDOWS\SYSTEM32\timedate.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 7/16/2003 3:48:06 PM | Attr = ])

C:\WINDOWS\SYSTEM32\desk.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 129024 bytes | Date = 7/16/2003 3:26:40 PM | Attr = ])

C:\WINDOWS\SYSTEM32\appwiz.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 578560 bytes | Date = 7/16/2003 3:24:16 PM | Attr = ])

C:\WINDOWS\SYSTEM32\inetcpl.cpl
# (Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 292352 bytes | Date = 7/16/2003 3:30:20 PM | Attr = ])

C:\WINDOWS\SYSTEM32\intl.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 121856 bytes | Date = 7/16/2003 3:30:30 PM | Attr = ])

C:\WINDOWS\SYSTEM32\joy.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 65536 bytes | Date = 7/16/2003 3:31:04 PM | Attr = ])

C:\WINDOWS\SYSTEM32\sysdm.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 268288 bytes | Date = 7/16/2003 3:47:12 PM | Attr = ])

C:\WINDOWS\SYSTEM32\access.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 66048 bytes | Date = 7/16/2003 3:23:44 PM | Attr = ])

C:\WINDOWS\SYSTEM32\QuickTime.cpl
# (Apple Computer, Inc. [Ver = 6.5.1 | Size = 323072 bytes | Date = 9/23/2004 6:57:40 PM | Attr = ])

C:\WINDOWS\SYSTEM32\jpicpl32.cpl
# (Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 49265 bytes | Date = 11/10/2005 1:03:50 PM | Attr = ])

C:\WINDOWS\SYSTEM32\wuaucpl.cpl
# (Microsoft Corporation [Ver = 5.4.3790.2182 built by: srv03_rtm(ntvbl04) | Size = 167704 bytes | Date = 8/3/2004 2:03:24 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
# (Microsoft Corporation [Ver = 3.520.7713.0 | Size = 36864 bytes | Date = 7/16/2003 3:40:18 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\access.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 66048 bytes | Date = 7/16/2003 3:23:44 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 578560 bytes | Date = 7/16/2003 3:24:16 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 129024 bytes | Date = 7/16/2003 8:26:40 AM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 150016 bytes | Date = 7/16/2003 3:29:16 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 121856 bytes | Date = 7/16/2003 3:30:30 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
# (Microsoft Corporation [Ver = 6.00.2800.1106 (xpsp1.020828-1920) | Size = 292352 bytes | Date = 7/16/2003 3:30:20 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 65536 bytes | Date = 7/16/2003 3:31:04 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 559616 bytes | Date = 7/16/2003 3:33:56 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\main.cpl
# (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 7/16/2003 3:32:24 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 7/16/2003 3:37:18 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
# (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 256000 bytes | Date = 7/16/2003 3:40:02 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
# (Microsoft Corporation [Ver = 6.00.2600.0000 (xpclient.010817-1148) | Size = 109056 bytes | Date = 7/16/2003 3:41:58 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
# (Microsoft Corporation [Ver = 5.1.4111.00 (xpsp1.020828-1920) | Size = 147456 bytes | Date = 7/16/2003 3:43:50 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
# (Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 268288 bytes | Date = 7/16/2003 3:47:12 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 7/16/2003 3:47:58 PM | Attr = ])

C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
# (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 90112 bytes | Date = 7/16/2003 3:48:06 PM | Attr = ])

Auto-Start Folders
#

HKLM->Explorer\Shell Folders\\Common Startup
# = C:\Documents and Settings\All Users\Start Menu\Programs\Startup

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
#( [Ver = | Size = 84 bytes | Date = 5/13/2005 9:03:24 PM | Attr = HS])

HKLM->Explorer\User Shell Folders\\Common Startup
# = %ALLUSERSPROFILE%\Start Menu\Programs\Startup

HKLM->Explorer\Shell Folders\\Startup
# = C:\Documents and Settings\work\Start Menu\Programs\Startup

C:\Documents and Settings\work\Start Menu\Programs\Startup\desktop.ini
#( [Ver = | Size = 84 bytes | Date = 5/13/2005 9:03:24 PM | Attr = HS])

HKCU->Explorer\User Shell Folders\\Startup
# = %USERPROFILE%\Start Menu\Programs\Startup

Miscellaneous Auto-Start Files
#

System.ini->[Boot]\\Shell
#Explorer.exe

Config.nt: Line 54
#dos=high, umb

Config.nt: Line 55
#device=%SystemRoot%\system32\himem.sys

Config.nt: Line 56
#files=40

AutoExec.nt: Line 1
#@echo off

AutoExec.nt: Line 8
#lh %SystemRoot%\system32\mscdexnt.exe

AutoExec.nt: Line 11
#lh %SystemRoot%\system32\redir

AutoExec.nt: Line 14
#lh %SystemRoot%\system32\dosx

AutoExec.nt: Line 36
#SET BLASTER=A220 I5 D1 P330 T3

Miscellaneous Folders
#

AllUsers ApplicationData Folder
#

C:\Documents and Settings\All Users\Application Data\desktop.ini
# ( [Ver = | Size = 62 bytes | Date = 5/13/2005 8:49:36 PM | Attr = HS])

CurrentUser ApplicationData Folder
#

C:\Documents and Settings\work\Application Data\desktop.ini
# ( [Ver = | Size = 62 bytes | Date = 5/13/2005 8:49:36 PM | Attr = HS])

Program Files Folder
#

C:\Program Files\folder.htt
# ( [Ver = | Size = 23357 bytes | Date = 12/27/2003 5:16:14 PM | Attr = H ])

C:\Program Files\desktop.ini
# ( [Ver = | Size = 271 bytes | Date = 12/27/2003 5:16:16 PM | Attr = HS])

C:\Program Files\WINZIP80.EXE
# ( [Ver = | Size = 1259448 bytes | Date = 9/27/2000 9:21:24 PM | Attr = ])

Common Files Folder
#

C:\Program Files\Common Files\MSCREATE.DIR
# ( [Ver = | Size = 0 bytes | Date = 12/27/2003 3:05:10 PM | Attr = RH ])

C:\Program Files\Common Files\IRAABOUT.DLL
# (Symantec Corp. [Ver = 1.0.0.52 | Size = 99840 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

C:\Program Files\Common Files\IRALPTTR.DLL
# (Symantec Corp., Peter Norton Computing Group [Ver = 1.0.0.110 | Size = 48640 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

C:\Program Files\Common Files\IRAMDMTR.DLL
# (Symantec Corp., Peter Norton Computing Group [Ver = 1.0.0.69 | Size = 70144 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

C:\Program Files\Common Files\IRAREG.DLL
# (Symantec Corp., Peter Norton Computing Group [Ver = 1.0.0.112 | Size = 186368 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

C:\Program Files\Common Files\IRASRIAL.DLL
# (Symantec Corp. [Ver = 1.0.0.58 | Size = 17920 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

C:\Program Files\Common Files\IRAWEBTR.DLL
# (Symantec Corp., Peter Norton Computing Group [Ver = 1.0.0.112 | Size = 31744 bytes | Date = 12/9/1998 2:53:54 AM | Attr = ])

DPF files
#

{33564D57-0000-0010-8000-00AA00389B71}
# - CodeBase = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

{8AD9C840-044E-11D1-B3E9-00805F499D93}
#Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab

{9D190AE6-C81E-4039-8061-978EBAD10073}
#F-Secure Online Scanner 3.0 - CodeBase = http://support.f-secure.com/ols/fscax.cab

{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
#Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
#Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab

Microsoft XML Parser for Java
# - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab

Hosts file = 686 bytes. Reading all entries.
#C:\WINDOWS\System32\drivers\etc\Hosts

# Copyright © 1993-1999 Microsoft Corp.
#

#
#

# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#

#
#

# This file contains the mappings of IP addresses to host names. Each
#

# entry should be kept on an individual line. The IP address should
#

# be placed in the first column followed by the corresponding host name.
#

# The IP address and the host name should be separated by at least one
#

# space.
#

#
#

# Additionally, comments (such as these) may be inserted on individual
#

# lines or following the machine name denoted by a "#" symbol.
#

#
#

# For example:
#

#
#

# 102.54.94.97 rhino.acme.com # source server
#

# 38.25.63.10 x.acme.com # x client host

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI