ExTS Admin Starbuck Posted June 15, 2011 ExTS Admin Posted June 15, 2011 Ok, sorry, was that to speed things up or the boot partition thing? The information was to help speed up the system Running the System File Checker was to correct the Boot partition. We can check if it's worked or not by running Combofix again ( let it update if it asks) and see if it will install the recovery console. Quote Member of:UNITE
Slumdog Posted June 15, 2011 Author Posted June 15, 2011 No, it won't install, it said the same thing again. Do you want the combofix report when it's done? (replying on my own laptop). Quote
Slumdog Posted June 15, 2011 Author Posted June 15, 2011 Here it is anyway. (It re-booted while I was away). ComboFix 11-06-15.02 - Alan Smith 15/06/2011 19:54:04.3.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.758.283 [GMT 1:00] Running from: c:\documents and settings\Alan Smith\Desktop\Combo-fix.exe * Created a new restore point . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((( Files Created from 2011-05-15 to 2011-06-15 ))))))))))))))))))))))))))))))) . . 2011-06-13 20:52 . 2008-04-14 00:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2011-06-13 20:52 . 2001-08-17 21:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2011-06-13 20:52 . 2008-04-14 00:12 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll 2011-06-13 20:51 . 2001-08-17 21:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe 2011-06-13 20:51 . 2001-08-17 21:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe 2011-06-13 20:49 . 2001-08-17 21:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe 2011-06-13 20:49 . 2001-08-17 11:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys 2011-06-13 20:49 . 2004-08-03 21:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys 2011-06-13 20:48 . 2004-08-03 21:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys 2011-06-13 20:47 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys 2011-06-13 20:47 . 2004-08-03 21:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys 2011-06-13 20:47 . 2001-08-17 11:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys 2011-06-13 20:46 . 2001-08-17 12:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys 2011-06-13 20:45 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll 2011-06-13 20:45 . 2001-08-17 21:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll 2011-06-13 20:45 . 2001-08-17 12:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys 2011-06-13 20:45 . 2004-08-03 21:29 23615 -c--a-w- c:\windows\system32\dllcache\wch7xxnt.sys 2011-06-13 20:45 . 2008-04-13 18:45 31744 -c--a-w- c:\windows\system32\dllcache\wceusbsh.sys 2011-06-13 20:44 . 2001-08-17 11:10 35871 -c--a-w- c:\windows\system32\dllcache\wbfirdma.sys 2011-06-13 20:44 . 2004-08-03 21:29 33599 -c--a-w- c:\windows\system32\dllcache\watv04nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 19551 -c--a-w- c:\windows\system32\dllcache\watv02nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 29311 -c--a-w- c:\windows\system32\dllcache\watv01nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 11775 -c--a-w- c:\windows\system32\dllcache\wadv05nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 12127 -c--a-w- c:\windows\system32\dllcache\wadv02nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 12415 -c--a-w- c:\windows\system32\dllcache\wadv01nt.sys 2011-06-13 20:43 . 2001-08-17 11:13 16925 -c--a-w- c:\windows\system32\dllcache\w940nd.sys 2011-06-13 20:43 . 2001-08-17 11:13 19016 -c--a-w- c:\windows\system32\dllcache\w926nd.sys 2011-06-13 20:43 . 2001-08-17 11:13 19528 -c--a-w- c:\windows\system32\dllcache\w840nd.sys 2011-06-13 20:42 . 2001-08-17 12:28 64605 -c--a-w- c:\windows\system32\dllcache\vvoice.sys 2011-06-13 20:42 . 2001-08-17 12:28 397502 -c--a-w- c:\windows\system32\dllcache\vpctcom.sys 2011-06-13 20:42 . 2001-08-17 12:28 604253 -c--a-w- c:\windows\system32\dllcache\vmodem.sys 2011-06-13 20:42 . 2001-08-17 11:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys 2011-06-13 20:41 . 2001-08-17 12:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys 2011-06-13 20:41 . 2008-04-13 18:40 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys 2011-06-13 20:41 . 2001-08-17 12:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys 2011-06-13 20:41 . 2001-08-17 12:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys 2011-06-13 20:40 . 2001-08-17 12:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys 2011-06-13 20:40 . 2001-08-17 12:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys 2011-06-13 20:40 . 2001-08-17 12:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys 2011-06-13 20:40 . 2001-08-17 12:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys 2011-06-13 20:39 . 2001-08-17 12:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys 2011-06-13 20:39 . 2001-08-17 12:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys 2011-06-13 20:39 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2011-06-13 20:39 . 2008-04-13 18:45 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys 2011-06-13 20:39 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys 2011-06-13 20:39 . 2004-08-03 21:31 32384 -c--a-w- c:\windows\system32\dllcache\usb101et.sys 2011-06-13 20:38 . 2001-08-17 21:36 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll 2011-06-13 20:38 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll 2011-06-13 20:38 . 2001-08-17 21:36 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll 2011-06-13 20:38 . 2001-08-17 21:36 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll 2011-06-13 20:37 . 2001-08-17 21:36 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll 2011-06-13 20:37 . 2001-08-17 12:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys 2011-06-13 20:37 . 2001-08-17 21:36 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll 2011-06-13 20:37 . 2001-08-17 21:36 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll 2011-06-13 20:37 . 2001-08-17 21:36 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll 2011-06-13 20:36 . 2001-08-17 21:36 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll 2011-06-13 20:36 . 2001-08-17 12:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys 2011-06-13 20:36 . 2001-08-17 12:48 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys 2011-06-13 20:35 . 2001-08-17 11:51 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys 2011-06-13 20:35 . 2001-08-17 21:36 525568 -c--a-w- c:\windows\system32\dllcache\tridxp.dll 2011-06-13 20:35 . 2001-08-17 11:51 159232 -c--a-w- c:\windows\system32\dllcache\tridkbm.sys 2011-06-13 20:35 . 2001-08-17 13:56 440576 -c--a-w- c:\windows\system32\dllcache\tridkb.dll 2011-06-13 20:35 . 2001-08-17 11:51 222336 -c--a-w- c:\windows\system32\dllcache\trid3dm.sys 2011-06-13 20:34 . 2001-08-17 13:56 315520 -c--a-w- c:\windows\system32\dllcache\trid3d.dll 2011-06-13 20:34 . 2001-08-17 11:12 34375 -c--a-w- c:\windows\system32\dllcache\tpro4.sys 2011-06-13 20:34 . 2001-08-17 21:35 42496 -c--a-w- c:\windows\system32\dllcache\tp4res.dll 2011-06-13 20:34 . 2008-04-14 00:12 82944 -c--a-w- c:\windows\system32\dllcache\tp4mon.exe 2011-06-13 20:34 . 2001-08-17 21:36 31744 -c--a-w- c:\windows\system32\dllcache\tp4.dll 2011-06-13 20:33 . 2001-08-17 12:51 4992 -c--a-w- c:\windows\system32\dllcache\toside.sys 2011-06-13 20:33 . 2001-08-17 13:02 230912 -c--a-w- c:\windows\system32\dllcache\tosdvd03.sys 2011-06-13 20:33 . 2001-08-17 13:01 241664 -c--a-w- c:\windows\system32\dllcache\tosdvd02.sys 2011-06-13 20:33 . 2001-08-17 11:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys 2011-06-13 20:33 . 2001-08-17 11:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys 2011-06-13 20:32 . 2001-08-17 11:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys 2011-06-13 20:32 . 2001-08-17 13:56 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll 2011-06-13 20:32 . 2008-04-13 18:40 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys 2011-06-13 20:32 . 2001-08-17 11:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys 2011-06-13 20:31 . 2001-08-17 11:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys 2011-06-13 20:31 . 2001-08-17 12:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys 2011-06-13 20:31 . 2001-08-17 12:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys 2011-06-13 20:30 . 2001-08-17 11:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys 2011-06-13 20:30 . 2001-08-17 13:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll 2011-06-13 20:30 . 2001-08-17 13:07 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys 2011-06-13 20:30 . 2001-08-17 13:07 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys 2011-06-13 20:29 . 2001-08-17 13:07 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys 2011-06-13 20:29 . 2001-08-17 13:07 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys 2011-06-13 20:29 . 2001-08-17 21:36 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll 2011-06-13 20:29 . 2001-08-17 12:50 103936 -c--a-w- c:\windows\system32\dllcache\sx.sys 2011-06-13 20:29 . 2001-08-17 13:02 3968 -c--a-w- c:\windows\system32\dllcache\swusbflt.sys 2011-06-13 20:29 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpidflt.dll 2011-06-13 20:28 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpdflt2.dll 2011-06-13 20:28 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll 2011-06-13 20:28 . 2001-08-17 21:36 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll 2011-06-13 20:28 . 2001-08-17 21:36 155648 -c--a-w- c:\windows\system32\dllcache\stlnprop.dll 2011-06-13 20:27 . 2001-08-17 21:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll 2011-06-13 20:27 . 2001-08-17 11:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys 2011-06-13 20:27 . 2001-08-17 12:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys 2011-06-13 20:27 . 2001-08-17 11:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys 2011-06-13 20:26 . 2001-08-17 21:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll 2011-06-13 20:26 . 2001-08-17 21:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll 2011-06-13 20:25 . 2001-08-17 12:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys 2011-06-13 20:25 . 2001-08-17 21:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll 2011-06-13 20:25 . 2001-08-17 13:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys 2011-06-13 20:25 . 2001-08-17 12:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys 2011-06-13 20:25 . 2001-08-17 11:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys 2011-06-13 20:24 . 2001-08-17 21:36 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll 2011-06-13 20:24 . 2001-08-17 11:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys 2011-06-13 20:24 . 2001-08-17 12:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys 2011-06-13 20:24 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys 2011-06-13 20:24 . 2004-08-04 12:00 143422 -c--a-w- c:\windows\system32\dllcache\softkey.dll 2011-06-13 20:24 . 2001-08-17 12:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys 2011-06-13 20:23 . 2001-08-17 11:51 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys 2011-06-13 20:23 . 2001-08-17 13:56 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll 2011-06-13 20:23 . 2001-08-17 11:12 25034 -c--a-w- c:\windows\system32\dllcache\smcpwr2n.sys 2011-06-13 20:22 . 2001-08-17 11:12 24576 -c--a-w- c:\windows\system32\dllcache\smc8000n.sys 2011-06-13 20:22 . 2001-08-17 12:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys 2011-06-13 20:22 . 2008-04-13 18:36 6912 -c--a-w- c:\windows\system32\dllcache\smbclass.sys 2011-06-13 20:22 . 2008-04-13 18:36 16000 -c--a-w- c:\windows\system32\dllcache\smbbatt.sys 2011-06-13 20:22 . 2001-08-17 21:36 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll 2011-06-13 20:22 . 2001-08-17 21:36 33792 -c--a-w- c:\windows\system32\dllcache\smb0w.dll 2011-06-13 20:21 . 2001-08-17 21:36 28672 -c--a-w- c:\windows\system32\dllcache\sma0w.dll 2011-06-13 20:21 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\sm91w.dll 2011-06-13 20:21 . 2004-08-03 21:31 63547 -c--a-w- c:\windows\system32\dllcache\sla30nd5.sys 2011-06-13 20:20 . 2001-08-17 11:12 91294 -c--a-w- c:\windows\system32\dllcache\skfpwin.sys 2011-06-13 20:20 . 2001-08-17 11:12 94698 -c--a-w- c:\windows\system32\dllcache\sk98xwin.sys . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TabletWizard"="c:\windows\help\SplshWrp.exe" [2008-04-14 16384] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-29 126976] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840] "AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363] "FjDspMon"="c:\program files\Fujitsu\Utils\FjDspMon.exe" [2004-10-14 20480] "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-09-13 172032] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Alan Smith\Start Menu\Programs\Startup\ Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-11-6 368640] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ AntSwitch.lnk - c:\windows\AntSwitch.exe [2005-11-2 28748] BTTray.lnk - c:\program files\Fujitsu Siemens\Bluetooth Software\BTTray.exe [2004-9-21 557123] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey] 2008-04-14 00:11 47104 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\loginkey.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL] 2002-08-29 10:41 11776 ----a-w- c:\windows\system32\tabbtnwl.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify] 2008-04-14 00:12 32256 ----a-w- c:\windows\system32\tpgwlnot.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FjEvents] 2004-12-16 14:08 20480 ----a-w- c:\program files\Fujitsu\Utils\FjEvents.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fujitsu Menu] 2004-12-16 14:10 32768 ----a-w- c:\program files\Fujitsu\Utils\FjMnuIco.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-05-08 15:24 54840 ----a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager] 2006-06-26 08:46 497200 ----a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon] 2006-06-26 09:34 614960 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX] 2006-06-26 09:33 243248 ----a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor] 2006-05-16 17:50 40960 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TabletTip] 2008-04-14 00:12 271872 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\tabtip.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "gusvc"=2 (0x2) "gupdate1c9d31333ce2850"=2 (0x2) . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4635:TCP"= 4635:TCP:ppLive "6329:UDP"= 6329:UDP:ppLive . R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [09/06/2010 17:43 11352] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [28/09/2005 21:35 192608] R3 Fjbtndrv;Fujitsu LIFEBOOK T3000 Button Driver;c:\windows\system32\drivers\FjBtndrv.sys [20/06/2003 14:30 11392] R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [28/09/2005 21:35 6000] R3 hidpen;Wacom Serial Pen HID MiniDriver;c:\windows\system32\drivers\hidpen.sys [28/09/2005 21:35 31104] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [07/05/2010 12:06 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472] R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [28/09/2005 21:35 92550] S2 gupdate1c9d31333ce2850;Google Update Service (gupdate1c9d31333ce2850);c:\program files\Google\Update\GoogleUpdate.exe [12/05/2009 16:06 133104] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/05/2009 16:06 133104] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [25/05/2011 11:53 39984] S3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [28/09/2005 21:35 6324] S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [13/08/2004 09:54 14208] S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [10/06/2011 21:50 229376] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder . 2011-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05] . 2011-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05] . 2011-06-15 c:\windows\Tasks\User_Feed_Synchronization-{52548EC2-B4D7-439B-9623-1232966E9D66}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 03:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s TCP: DhcpNameServer = 192.168.0.1 . . ------- File Associations ------- . JSEFile=NOTEPAD.EXE %1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-15 20:20 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(6928) c:\windows\system32\WININET.dll c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll c:\program files\windows journal\nbmaptip.dll c:\windows\IME\SPGRMR.DLL c:\windows\system32\ieframe.dll c:\windows\system32\BTNEIG~1.DLL c:\windows\system32\wbtapi.dll c:\windows\system32\btwpimif.dll c:\windows\system32\btosif.dll c:\windows\system32\btrez.dll c:\windows\system32\CSH.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\btncopy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe c:\windows\SYSTEM32\WISPTIS.EXE c:\windows\System32\tabbtnu.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe c:\windows\System32\SCardSvr.exe c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe c:\program files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe c:\windows\System32\digtizer.exe c:\windows\system32\igfxext.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Common Files\Microsoft Shared\Ink\TCServer.exe c:\windows\system32\HPZipm12.exe c:\windows\AGRSMMSG.exe c:\windows\system32\rundll32.exe c:\windows\system32\igfxext.exe c:\windows\system32\wscntfy.exe c:\program files\Apoint2K\HidFind.exe c:\program files\Apoint2K\Apntex.exe . ************************************************************************** . Completion time: 2011-06-15 20:28:28 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-15 19:28 ComboFix2.txt 2011-06-09 18:06 . Pre-Run: 6,465,757,184 bytes free Post-Run: 6,472,966,144 bytes free . - - End Of File - - 48E22F4D29EC1997795E4F50761E6D3C Quote
ExTS Admin Starbuck Posted June 15, 2011 ExTS Admin Posted June 15, 2011 No, it won't install, it said the same thing again. Ok, seems we can't do it the easy way. :( Open windows explorer (right click the Start button and click Explore) At the top of windows explorer, click tools >> folder options >> click the view tab check Display the contents of system folders check Show hidden files and folders uncheck "Hide extensions for known file types" box uncheck "Hide protecting operating system files" box Click apply, click ok Now Navigate to the C:\ folder and click on it. In the right hand panel locate a file named boot.ini right click it and click open or Open with if prompted with Open with choose notepad Please post the contents of the file in your next reply. Thanks Quote Member of:UNITE
Slumdog Posted June 15, 2011 Author Posted June 15, 2011 "Now Navigate to the C:\ folder and click on it" Again sorry, where is this? Quote
ExTS Admin Starbuck Posted June 15, 2011 ExTS Admin Posted June 15, 2011 If you click on Start >> My Computer you will see Local Disc © ( under the Hard Disc Drives section) this is the C:\ folder. Quote Member of:UNITE
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 I had a strange feeling you was going to tell me that! Oh Well, we now know why the Boot partition cannot be enumerated correctly. :o As the boot.ini doesn't exist.... open Notepad copy/paste the following text in the Code box below, into Notepad: Do Not copy the word CODE [boot loader] timeout=30 [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=1 /fastdetect multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=2 /fastdetect scsi(0)disk(0)rdisk(0)partition(1)\WINDOWS=3 /fastdetect scsi(0)disk(0)rdisk(0)partition(2)\WINDOWS=4 /fastdetect scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=5 /fastdetect scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=6 /fastdetect C:\WINDOWS=7 /fastdetect Save the file you just created. Name it boot.ini & save it directly to C:\ drive Do Not reboot yet! Next Go to start >> Run and type the following line in the run box and click OK. notepad c:\boot.ini note the space after notepad. Please post the contents of the notepad that opens. Thanks Quote Member of:UNITE
Slumdog Posted June 16, 2011 Author Posted June 16, 2011 Same as you gave me-- [boot loader] timeout=30 [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=1 /fastdetect multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=2 /fastdetect scsi(0)disk(0)rdisk(0)partition(1)\WINDOWS=3 /fastdetect scsi(0)disk(0)rdisk(0)partition(2)\WINDOWS=4 /fastdetect scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=5 /fastdetect scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=6 /fastdetect C:\WINDOWS=7 /fastdetect Quote
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 That's ok .... i just needed to check before we continue. Please print or write down these instructions then reboot the computer. You will only need to do this until you find the option that will boot to Windows. Once Windows has loaded please stop there and post back which option started the computer. After the reboot, you'll have 30 seconds to choose from the boot menu. Use your arrow key and select 1 /fastdetect in the list and press Enter Wait for it to boot Windows. If you receive an error, click OK to restart the system. If you need to restart because of Windows failing to load you will see the boot menu again. Arrow up to 2 /fastdetect and press Enter. Wait for Windows to boot. If you receive an error message, same as before, click OK to restart. Continue using the arrow key, going in succession from 3 /fastdetect, etc., one at a time, until Windows boots up. Who said life was dull? :) Quote Member of:UNITE
Slumdog Posted June 16, 2011 Author Posted June 16, 2011 Just before I do that, I don't know if this has any bearing on the matter but every time the laptop starts or re-boots, on the first page-Fujitsu etc. it says 02F9: Thermal sensor error Enter F1 To resume or F2 to set up. It does this every time and will not proceed until F1 is pushed. Quote
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 sounds like an over heating problem, but this isn't in my field. Once we get this boot problem sorted i'll get some more experienced in this to assist you. Quote Member of:UNITE
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 So that is: 1 /fastdetect Quote Member of:UNITE
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 Ok thanks, i needed to be sure which option worked. If we got it wrong!!! mmm doesn't bare thinking about. OK good. Now that we know which partition Windows is located in, we need to set it one more time. Right click the C:\boot.ini (you created earlier) & rename it to boot.old Open Notepad then copy/paste the text in the Code box below, into that empty Notepad: [boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect Save this as boot.ini directly on the C:\ drive. (replacing the earlier one) Let me know how you make out. It should be ok now. Quote Member of:UNITE
Slumdog Posted June 16, 2011 Author Posted June 16, 2011 Okay, that is on C:\ notepad report the same again-- [boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect Quote
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 Reboot the system. It should reboot ok now. Quote Member of:UNITE
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 If the system reboots ok, you can edit the boot.ini we just created. You can change: timeout=30 to timeout=3 it'll reboot a bit faster, it'll cut down the wait time from 30 seconds to 3 seconds. Quote Member of:UNITE
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 Re-booted fine but slow. Yes, that was my mistake Sorry. i should have altered the new boot.ini script to say: timeout=3 that's why i added the previous post. Now to see if everything works....... Run Combofix again and see if it will install the recovery console now. if no deletions are found, you need not post the report. Quote Member of:UNITE
Slumdog Posted June 16, 2011 Author Posted June 16, 2011 One deletion: ComboFix 11-06-15.02 - Alan Smith 16/06/2011 21:27:53.4.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.758.403 [GMT 1:00] Running from: c:\documents and settings\Alan Smith\Desktop\Combo-fix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\struct~.ini . . ((((((((((((((((((((((((( Files Created from 2011-05-16 to 2011-06-16 ))))))))))))))))))))))))))))))) . . 2011-06-15 23:14 . 2011-06-16 14:04 -------- d-----w- c:\windows\SxsCaPendDel 2011-06-13 20:52 . 2008-04-14 00:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2011-06-13 20:52 . 2001-08-17 21:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2011-06-13 20:52 . 2008-04-14 00:12 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll 2011-06-13 20:51 . 2001-08-17 21:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe 2011-06-13 20:51 . 2001-08-17 21:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe 2011-06-13 20:49 . 2001-08-17 21:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe 2011-06-13 20:49 . 2001-08-17 11:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys 2011-06-13 20:49 . 2004-08-03 21:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys 2011-06-13 20:48 . 2004-08-03 21:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys 2011-06-13 20:47 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys 2011-06-13 20:47 . 2004-08-03 21:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys 2011-06-13 20:47 . 2001-08-17 11:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys 2011-06-13 20:46 . 2001-08-17 12:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys 2011-06-13 20:45 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll 2011-06-13 20:45 . 2001-08-17 21:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll 2011-06-13 20:45 . 2001-08-17 12:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys 2011-06-13 20:45 . 2004-08-03 21:29 23615 -c--a-w- c:\windows\system32\dllcache\wch7xxnt.sys 2011-06-13 20:45 . 2008-04-13 18:45 31744 -c--a-w- c:\windows\system32\dllcache\wceusbsh.sys 2011-06-13 20:44 . 2001-08-17 11:10 35871 -c--a-w- c:\windows\system32\dllcache\wbfirdma.sys 2011-06-13 20:44 . 2004-08-03 21:29 33599 -c--a-w- c:\windows\system32\dllcache\watv04nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 19551 -c--a-w- c:\windows\system32\dllcache\watv02nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 29311 -c--a-w- c:\windows\system32\dllcache\watv01nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 11775 -c--a-w- c:\windows\system32\dllcache\wadv05nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 12127 -c--a-w- c:\windows\system32\dllcache\wadv02nt.sys 2011-06-13 20:44 . 2004-08-03 21:29 12415 -c--a-w- c:\windows\system32\dllcache\wadv01nt.sys 2011-06-13 20:43 . 2001-08-17 11:13 16925 -c--a-w- c:\windows\system32\dllcache\w940nd.sys 2011-06-13 20:43 . 2001-08-17 11:13 19016 -c--a-w- c:\windows\system32\dllcache\w926nd.sys 2011-06-13 20:43 . 2001-08-17 11:13 19528 -c--a-w- c:\windows\system32\dllcache\w840nd.sys 2011-06-13 20:42 . 2001-08-17 12:28 64605 -c--a-w- c:\windows\system32\dllcache\vvoice.sys 2011-06-13 20:42 . 2001-08-17 12:28 397502 -c--a-w- c:\windows\system32\dllcache\vpctcom.sys 2011-06-13 20:42 . 2001-08-17 12:28 604253 -c--a-w- c:\windows\system32\dllcache\vmodem.sys 2011-06-13 20:42 . 2001-08-17 11:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys 2011-06-13 20:41 . 2001-08-17 12:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys 2011-06-13 20:41 . 2008-04-13 18:40 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys 2011-06-13 20:41 . 2001-08-17 12:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys 2011-06-13 20:41 . 2001-08-17 12:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys 2011-06-13 20:40 . 2001-08-17 12:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys 2011-06-13 20:40 . 2001-08-17 12:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys 2011-06-13 20:40 . 2001-08-17 12:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys 2011-06-13 20:40 . 2001-08-17 12:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys 2011-06-13 20:39 . 2001-08-17 12:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys 2011-06-13 20:39 . 2001-08-17 12:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys 2011-06-13 20:39 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys 2011-06-13 20:39 . 2008-04-13 18:45 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys 2011-06-13 20:39 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys 2011-06-13 20:39 . 2004-08-03 21:31 32384 -c--a-w- c:\windows\system32\dllcache\usb101et.sys 2011-06-13 20:38 . 2001-08-17 21:36 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll 2011-06-13 20:38 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll 2011-06-13 20:38 . 2001-08-17 21:36 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll 2011-06-13 20:38 . 2001-08-17 21:36 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll 2011-06-13 20:37 . 2001-08-17 21:36 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll 2011-06-13 20:37 . 2001-08-17 12:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys 2011-06-13 20:37 . 2001-08-17 21:36 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll 2011-06-13 20:37 . 2001-08-17 21:36 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll 2011-06-13 20:37 . 2001-08-17 21:36 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll 2011-06-13 20:36 . 2001-08-17 21:36 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll 2011-06-13 20:36 . 2001-08-17 12:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys 2011-06-13 20:36 . 2001-08-17 12:48 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys 2011-06-13 20:35 . 2001-08-17 11:51 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys 2011-06-13 20:35 . 2001-08-17 21:36 525568 -c--a-w- c:\windows\system32\dllcache\tridxp.dll 2011-06-13 20:35 . 2001-08-17 11:51 159232 -c--a-w- c:\windows\system32\dllcache\tridkbm.sys 2011-06-13 20:35 . 2001-08-17 13:56 440576 -c--a-w- c:\windows\system32\dllcache\tridkb.dll 2011-06-13 20:35 . 2001-08-17 11:51 222336 -c--a-w- c:\windows\system32\dllcache\trid3dm.sys 2011-06-13 20:34 . 2001-08-17 13:56 315520 -c--a-w- c:\windows\system32\dllcache\trid3d.dll 2011-06-13 20:34 . 2001-08-17 11:12 34375 -c--a-w- c:\windows\system32\dllcache\tpro4.sys 2011-06-13 20:34 . 2001-08-17 21:35 42496 -c--a-w- c:\windows\system32\dllcache\tp4res.dll 2011-06-13 20:34 . 2008-04-14 00:12 82944 -c--a-w- c:\windows\system32\dllcache\tp4mon.exe 2011-06-13 20:34 . 2001-08-17 21:36 31744 -c--a-w- c:\windows\system32\dllcache\tp4.dll 2011-06-13 20:33 . 2001-08-17 12:51 4992 -c--a-w- c:\windows\system32\dllcache\toside.sys 2011-06-13 20:33 . 2001-08-17 13:02 230912 -c--a-w- c:\windows\system32\dllcache\tosdvd03.sys 2011-06-13 20:33 . 2001-08-17 13:01 241664 -c--a-w- c:\windows\system32\dllcache\tosdvd02.sys 2011-06-13 20:33 . 2001-08-17 11:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys 2011-06-13 20:33 . 2001-08-17 11:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys 2011-06-13 20:32 . 2001-08-17 11:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys 2011-06-13 20:32 . 2001-08-17 13:56 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll 2011-06-13 20:32 . 2008-04-13 18:40 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys 2011-06-13 20:32 . 2001-08-17 11:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys 2011-06-13 20:31 . 2001-08-17 11:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys 2011-06-13 20:31 . 2001-08-17 12:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys 2011-06-13 20:31 . 2001-08-17 12:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys 2011-06-13 20:30 . 2001-08-17 11:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys 2011-06-13 20:30 . 2001-08-17 13:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll 2011-06-13 20:30 . 2001-08-17 13:07 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys 2011-06-13 20:30 . 2001-08-17 13:07 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys 2011-06-13 20:29 . 2001-08-17 13:07 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys 2011-06-13 20:29 . 2001-08-17 13:07 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys 2011-06-13 20:29 . 2001-08-17 21:36 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll 2011-06-13 20:29 . 2001-08-17 12:50 103936 -c--a-w- c:\windows\system32\dllcache\sx.sys 2011-06-13 20:29 . 2001-08-17 13:02 3968 -c--a-w- c:\windows\system32\dllcache\swusbflt.sys 2011-06-13 20:29 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpidflt.dll 2011-06-13 20:28 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpdflt2.dll 2011-06-13 20:28 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll 2011-06-13 20:28 . 2001-08-17 21:36 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll 2011-06-13 20:28 . 2001-08-17 21:36 155648 -c--a-w- c:\windows\system32\dllcache\stlnprop.dll 2011-06-13 20:27 . 2001-08-17 21:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll 2011-06-13 20:27 . 2001-08-17 11:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys 2011-06-13 20:27 . 2001-08-17 12:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys 2011-06-13 20:27 . 2001-08-17 11:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys 2011-06-13 20:26 . 2001-08-17 21:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll 2011-06-13 20:26 . 2001-08-17 21:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll 2011-06-13 20:25 . 2001-08-17 12:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys 2011-06-13 20:25 . 2001-08-17 21:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll 2011-06-13 20:25 . 2001-08-17 13:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys 2011-06-13 20:25 . 2001-08-17 12:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys 2011-06-13 20:25 . 2001-08-17 11:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys 2011-06-13 20:24 . 2001-08-17 21:36 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll 2011-06-13 20:24 . 2001-08-17 11:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys 2011-06-13 20:24 . 2001-08-17 12:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys 2011-06-13 20:24 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys 2011-06-13 20:24 . 2004-08-04 12:00 143422 -c--a-w- c:\windows\system32\dllcache\softkey.dll 2011-06-13 20:24 . 2001-08-17 12:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys 2011-06-13 20:23 . 2001-08-17 11:51 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys 2011-06-13 20:23 . 2001-08-17 13:56 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll 2011-06-13 20:23 . 2001-08-17 11:12 25034 -c--a-w- c:\windows\system32\dllcache\smcpwr2n.sys 2011-06-13 20:22 . 2001-08-17 11:12 24576 -c--a-w- c:\windows\system32\dllcache\smc8000n.sys 2011-06-13 20:22 . 2001-08-17 12:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys 2011-06-13 20:22 . 2008-04-13 18:36 6912 -c--a-w- c:\windows\system32\dllcache\smbclass.sys 2011-06-13 20:22 . 2008-04-13 18:36 16000 -c--a-w- c:\windows\system32\dllcache\smbbatt.sys 2011-06-13 20:22 . 2001-08-17 21:36 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll 2011-06-13 20:22 . 2001-08-17 21:36 33792 -c--a-w- c:\windows\system32\dllcache\smb0w.dll 2011-06-13 20:21 . 2001-08-17 21:36 28672 -c--a-w- c:\windows\system32\dllcache\sma0w.dll 2011-06-13 20:21 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\sm91w.dll 2011-06-13 20:21 . 2004-08-03 21:31 63547 -c--a-w- c:\windows\system32\dllcache\sla30nd5.sys 2011-06-13 20:20 . 2001-08-17 11:12 91294 -c--a-w- c:\windows\system32\dllcache\skfpwin.sys . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-02 15:31 . 2004-08-13 16:00 692736 ----a-w- c:\windows\system32\inetcomm.dll 2011-04-29 16:19 . 2004-08-12 11:27 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-25 16:11 . 2004-08-12 11:28 916480 ----a-w- c:\windows\system32\wininet.dll 2011-04-25 16:11 . 2004-08-12 11:27 43520 ----a-w- c:\windows\system32\licmgr10.dll 2011-04-25 16:11 . 2004-08-12 11:27 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2011-04-25 12:01 . 2004-08-12 11:27 385024 ----a-w- c:\windows\system32\html.iec 2011-04-21 13:37 . 2004-08-12 11:28 105472 ----a-w- c:\windows\system32\drivers\mup.sys . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TabletWizard"="c:\windows\help\SplshWrp.exe" [2008-04-14 16384] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-29 126976] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840] "AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363] "FjDspMon"="c:\program files\Fujitsu\Utils\FjDspMon.exe" [2004-10-14 20480] "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-09-13 172032] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] "avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-10-14 352976] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] . c:\documents and settings\Alan Smith\Start Menu\Programs\Startup\ Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-11-6 368640] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ AntSwitch.lnk - c:\windows\AntSwitch.exe [2005-11-2 28748] BTTray.lnk - c:\program files\Fujitsu Siemens\Bluetooth Software\BTTray.exe [2004-9-21 557123] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey] 2008-04-14 00:11 47104 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\loginkey.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL] 2002-08-29 10:41 11776 ----a-w- c:\windows\system32\tabbtnwl.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify] 2008-04-14 00:12 32256 ----a-w- c:\windows\system32\tpgwlnot.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FjEvents] 2004-12-16 14:08 20480 ----a-w- c:\program files\Fujitsu\Utils\FjEvents.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fujitsu Menu] 2004-12-16 14:10 32768 ----a-w- c:\program files\Fujitsu\Utils\FjMnuIco.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-05-08 15:24 54840 ----a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager] 2006-06-26 08:46 497200 ----a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon] 2006-06-26 09:34 614960 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX] 2006-06-26 09:33 243248 ----a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] 2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor] 2006-05-16 17:50 40960 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TabletTip] 2008-04-14 00:12 271872 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\tabtip.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "gusvc"=2 (0x2) "gupdate1c9d31333ce2850"=2 (0x2) . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4635:TCP"= 4635:TCP:ppLive "6329:UDP"= 6329:UDP:ppLive . R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [09/06/2010 17:43 11352] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [28/09/2005 21:35 192608] R3 Fjbtndrv;Fujitsu LIFEBOOK T3000 Button Driver;c:\windows\system32\drivers\FjBtndrv.sys [20/06/2003 14:30 11392] R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [28/09/2005 21:35 6000] R3 hidpen;Wacom Serial Pen HID MiniDriver;c:\windows\system32\drivers\hidpen.sys [28/09/2005 21:35 31104] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [07/05/2010 12:06 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472] R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [28/09/2005 21:35 92550] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [25/05/2011 11:53 39984] S3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [28/09/2005 21:35 6324] S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [13/08/2004 09:54 14208] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] vvdsvc REG_MULTI_SZ vvdsvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder . 2011-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05] . 2011-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05] . 2011-06-16 c:\windows\Tasks\User_Feed_Synchronization-{52548EC2-B4D7-439B-9623-1232966E9D66}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 03:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm TCP: DhcpNameServer = 192.168.0.1 . . ------- File Associations ------- . JSEFile=NOTEPAD.EXE %1 . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-16 21:44 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Completion time: 2011-06-16 21:52:10 ComboFix-quarantined-files.txt 2011-06-16 20:52 ComboFix2.txt 2011-06-15 19:28 ComboFix3.txt 2011-06-09 18:06 . Pre-Run: 6,179,082,240 bytes free Post-Run: 6,176,911,360 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - BDD4FE5CA20FDB3B4E4E6CE576DA5738 Quote
ExTS Admin Starbuck Posted June 16, 2011 ExTS Admin Posted June 16, 2011 Ok thanks. and the recovery console installed i see: WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect seems the boot problem is sorted. http://fc07.deviantart.net/images3/i/2004/146/9/1/Two_thumbs_up.gif Let me have one last OTL report before we finish off the cleaning ( just so that i can double check everything) Once we've finished i'll get some one to take a look at that 'Thermal sensor error' for you. Double click on OTL to run it. Under Extra Registry section, select Use SafeList. Don't check the boxes beside 'LOP Check' and 'Purity Check' this time. Click on Run Scan at the top left hand corner. When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply. Thanks Quote Member of:UNITE
Slumdog Posted June 17, 2011 Author Posted June 17, 2011 It's too long will have to post in three parts! OTL logfile created on: 16/06/2011 22:29:49 - Run 3 OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Alan Smith\Desktop Windows XP Tablet PC Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 758.48 Mb Total Physical Memory | 307.06 Mb Available Physical Memory | 40.48% Memory free 1.43 Gb Paging File | 1.03 Gb Available in Paging File | 71.90% Paging File free Paging file location(s): C:\pagefile.sys 756 1512 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 39.02 Gb Total Space | 5.77 Gb Free Space | 14.79% Space Free | Partition Type: NTFS Drive D: | 16.85 Gb Total Space | 16.79 Gb Free Space | 99.62% Space Free | Partition Type: NTFS Computer Name: NFRNTABLET11 | User Name: Alan Smith | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Alan Smith\Desktop\OTL.scr (OldTimer Tools) PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) PRC - C:\WINDOWS\system32\HPZipm12.exe (HP) PRC - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation) PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions) PRC - C:\WINDOWS\system32\digtizer.exe (WACOM) PRC - C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Fujitsu PC Corporation) PRC - C:\Program Files\Fujitsu Siemens\Bluetooth Software\BTTray.exe (WIDCOMM, Inc.) PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP) PRC - C:\Program Files\Apoint2K\Hidfind.exe (Alps Electric Co., Ltd.) PRC - C:\Program Files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Alan Smith\Desktop\OTL.scr (OldTimer Tools) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP) SRV - (LVSrvLauncher) -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe (Logitech Inc.) SRV - (LVPrcSrv) -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.) SRV - (Digitizer) -- C:\WINDOWS\system32\digtizer.exe (WACOM) SRV - (HP Port Resolver) -- C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company) SRV - (HP Status Server) -- C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company) SRV - (btwdins) -- C:\Program Files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.) ========== Driver Services (SafeList) ========== DRV - (catchme) -- File not found DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation) DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab) DRV - (kl2) -- C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO) DRV - (KL1) -- C:\WINDOWS\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO) DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO) DRV - (klmouflt) -- C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab) DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia) DRV - (n558) -- C:\WINDOWS\system32\drivers\n558.sys () DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys () DRV - (LVMVDrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.) DRV - (LVcKap) -- C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.) DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.) DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.) DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions) DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions) DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions) DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions) DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions) DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions) DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions) DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions) DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions) DRV - (hidpen) -- C:\WINDOWS\system32\drivers\hidpen.sys (Wacom Co., Ltd) DRV - (STAC97) -- C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.) DRV - (OZSCR) -- C:\WINDOWS\system32\drivers\ozscr.sys (O2Micro) DRV - (CONAN) -- C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro ) DRV - (MbxStby) -- C:\WINDOWS\system32\drivers\MbxStby.sys (O2 Micro) DRV - (k750obex) -- C:\WINDOWS\system32\drivers\k750obex.sys (MCCI) DRV - (k750mdm) -- C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI) DRV - (k750mdfl) -- C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI) DRV - (k750bus) Sony Ericsson 750 driver (WDM) -- C:\WINDOWS\system32\drivers\k750bus.sys (MCCI) DRV - (w29n51) Intel® -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation) DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation) DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation) DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.) DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems) DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (WIDCOMM, Inc.) DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (WIDCOMM, Inc.) DRV - (BTSLBCSP) -- C:\WINDOWS\system32\drivers\btslbcsp.sys (WIDCOMM, Inc.) DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (WIDCOMM, Inc.) DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (WIDCOMM, Inc.) DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (WIDCOMM, Inc.) DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (WIDCOMM, Inc.) DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation) DRV - (Fjbtndrv) -- C:\WINDOWS\system32\drivers\FjBtndrv.sys (Fujitsu PC Corporation) DRV - (FUJ02E1) -- C:\WINDOWS\system32\drivers\FUJ02E1.sys (Fujitsu Limited) DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC) DRV - (FUJ02B1) -- C:\WINDOWS\system32\drivers\fuj02b1.sys (FUJITSU LIMITED) DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 04 EB 0C 2A F9 CA 01 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" FF - prefs.js..browser.search.selectedEngine: "Google" FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010/10/14 14:31:46 | 000,000,000 | ---D | M] [2009/05/07 11:06:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alan Smith\Application Data\Mozilla\Firefox\Profiles\cibkoitq.default\extensions [2008/06/10 16:09:27 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Alan Smith\Application Data\Mozilla\Firefox\Profiles\cibkoitq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/11/24 15:09:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2008/05/04 12:06:42 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2011/06/08 23:25:46 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{422112EB-BC81-4FF3-A751-D14968EB3BC3} File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\REAL-NETWORKS@PARTNERS.MOZILLA.COM File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\TALKBACK@MOZILLA.ORG File not found (No name found) -- C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD O1 HOSTS File: ([2011/06/16 21:44:19 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O4 - HKLM..\Run: [avp] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO) O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation) O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions) O4 - HKLM..\Run: [FjDspMon] C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Fujitsu PC Corporation) O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP) O4 - Startup: C:\Documents and Settings\Alan Smith\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AntSwitch.lnk = C:\WINDOWS\AntSwitch.exe (Fujitsu Siemens Computers) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\Fujitsu Siemens\Bluetooth Software\BTTray.exe (WIDCOMM, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm () O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.) O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Fujitsu Siemens\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Fujitsu Siemens\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool) O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object) O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool) O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://194.168.163.96/activex/AxisCamControl.cab (CamImage Class) O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.tvucricket.com/player/vjocx-en-black.cab (VodClient Control Class) O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\widimg {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\BTXPPanel.dll (WIDCOMM, Inc.) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation) O20 - Winlogon\Notify\klogon: DllName - C:\windows\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO) O24 - Desktop WallPaper: C:\Documents and Settings\Alan Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Alan Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = ComFile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== Quote
Slumdog Posted June 17, 2011 Author Posted June 17, 2011 So now it wont let me post the rest? But I can do short posts. (Obviously!). Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.