Jump to content

Recommended Posts

  • ExTS Admin
Posted
Ok, sorry, was that to speed things up or the boot partition thing?

The information was to help speed up the system

Running the System File Checker was to correct the Boot partition.

 

We can check if it's worked or not by running Combofix again ( let it update if it asks) and see if it will install the recovery console.

Member of:

UNITE

  • Replies 59
  • Created
  • Last Reply

Top Posters In This Topic

Posted
No, it won't install, it said the same thing again. Do you want the combofix report when it's done? (replying on my own laptop).
Posted

Here it is anyway. (It re-booted while I was away).

 

ComboFix 11-06-15.02 - Alan Smith 15/06/2011 19:54:04.3.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.758.283 [GMT 1:00]

Running from: c:\documents and settings\Alan Smith\Desktop\Combo-fix.exe

* Created a new restore point

.

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

.

((((((((((((((((((((((((( Files Created from 2011-05-15 to 2011-06-15 )))))))))))))))))))))))))))))))

.

.

2011-06-13 20:52 . 2008-04-14 00:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll

2011-06-13 20:52 . 2001-08-17 21:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll

2011-06-13 20:52 . 2008-04-14 00:12 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll

2011-06-13 20:51 . 2001-08-17 21:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe

2011-06-13 20:51 . 2001-08-17 21:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe

2011-06-13 20:49 . 2001-08-17 21:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe

2011-06-13 20:49 . 2001-08-17 11:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys

2011-06-13 20:49 . 2004-08-03 21:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys

2011-06-13 20:48 . 2004-08-03 21:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys

2011-06-13 20:47 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys

2011-06-13 20:47 . 2004-08-03 21:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys

2011-06-13 20:47 . 2001-08-17 11:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys

2011-06-13 20:46 . 2001-08-17 12:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys

2011-06-13 20:45 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll

2011-06-13 20:45 . 2001-08-17 21:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll

2011-06-13 20:45 . 2001-08-17 12:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys

2011-06-13 20:45 . 2004-08-03 21:29 23615 -c--a-w- c:\windows\system32\dllcache\wch7xxnt.sys

2011-06-13 20:45 . 2008-04-13 18:45 31744 -c--a-w- c:\windows\system32\dllcache\wceusbsh.sys

2011-06-13 20:44 . 2001-08-17 11:10 35871 -c--a-w- c:\windows\system32\dllcache\wbfirdma.sys

2011-06-13 20:44 . 2004-08-03 21:29 33599 -c--a-w- c:\windows\system32\dllcache\watv04nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 19551 -c--a-w- c:\windows\system32\dllcache\watv02nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 29311 -c--a-w- c:\windows\system32\dllcache\watv01nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 11775 -c--a-w- c:\windows\system32\dllcache\wadv05nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 12127 -c--a-w- c:\windows\system32\dllcache\wadv02nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 12415 -c--a-w- c:\windows\system32\dllcache\wadv01nt.sys

2011-06-13 20:43 . 2001-08-17 11:13 16925 -c--a-w- c:\windows\system32\dllcache\w940nd.sys

2011-06-13 20:43 . 2001-08-17 11:13 19016 -c--a-w- c:\windows\system32\dllcache\w926nd.sys

2011-06-13 20:43 . 2001-08-17 11:13 19528 -c--a-w- c:\windows\system32\dllcache\w840nd.sys

2011-06-13 20:42 . 2001-08-17 12:28 64605 -c--a-w- c:\windows\system32\dllcache\vvoice.sys

2011-06-13 20:42 . 2001-08-17 12:28 397502 -c--a-w- c:\windows\system32\dllcache\vpctcom.sys

2011-06-13 20:42 . 2001-08-17 12:28 604253 -c--a-w- c:\windows\system32\dllcache\vmodem.sys

2011-06-13 20:42 . 2001-08-17 11:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys

2011-06-13 20:41 . 2001-08-17 12:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys

2011-06-13 20:41 . 2008-04-13 18:40 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys

2011-06-13 20:41 . 2001-08-17 12:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys

2011-06-13 20:41 . 2001-08-17 12:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys

2011-06-13 20:40 . 2001-08-17 12:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys

2011-06-13 20:40 . 2001-08-17 12:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys

2011-06-13 20:40 . 2001-08-17 12:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys

2011-06-13 20:40 . 2001-08-17 12:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys

2011-06-13 20:39 . 2001-08-17 12:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys

2011-06-13 20:39 . 2001-08-17 12:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys

2011-06-13 20:39 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys

2011-06-13 20:39 . 2008-04-13 18:45 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys

2011-06-13 20:39 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys

2011-06-13 20:39 . 2004-08-03 21:31 32384 -c--a-w- c:\windows\system32\dllcache\usb101et.sys

2011-06-13 20:38 . 2001-08-17 21:36 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll

2011-06-13 20:38 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll

2011-06-13 20:38 . 2001-08-17 21:36 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll

2011-06-13 20:38 . 2001-08-17 21:36 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll

2011-06-13 20:37 . 2001-08-17 21:36 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll

2011-06-13 20:37 . 2001-08-17 12:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys

2011-06-13 20:37 . 2001-08-17 21:36 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll

2011-06-13 20:37 . 2001-08-17 21:36 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll

2011-06-13 20:37 . 2001-08-17 21:36 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll

2011-06-13 20:36 . 2001-08-17 21:36 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll

2011-06-13 20:36 . 2001-08-17 12:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys

2011-06-13 20:36 . 2001-08-17 12:48 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys

2011-06-13 20:35 . 2001-08-17 11:51 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys

2011-06-13 20:35 . 2001-08-17 21:36 525568 -c--a-w- c:\windows\system32\dllcache\tridxp.dll

2011-06-13 20:35 . 2001-08-17 11:51 159232 -c--a-w- c:\windows\system32\dllcache\tridkbm.sys

2011-06-13 20:35 . 2001-08-17 13:56 440576 -c--a-w- c:\windows\system32\dllcache\tridkb.dll

2011-06-13 20:35 . 2001-08-17 11:51 222336 -c--a-w- c:\windows\system32\dllcache\trid3dm.sys

2011-06-13 20:34 . 2001-08-17 13:56 315520 -c--a-w- c:\windows\system32\dllcache\trid3d.dll

2011-06-13 20:34 . 2001-08-17 11:12 34375 -c--a-w- c:\windows\system32\dllcache\tpro4.sys

2011-06-13 20:34 . 2001-08-17 21:35 42496 -c--a-w- c:\windows\system32\dllcache\tp4res.dll

2011-06-13 20:34 . 2008-04-14 00:12 82944 -c--a-w- c:\windows\system32\dllcache\tp4mon.exe

2011-06-13 20:34 . 2001-08-17 21:36 31744 -c--a-w- c:\windows\system32\dllcache\tp4.dll

2011-06-13 20:33 . 2001-08-17 12:51 4992 -c--a-w- c:\windows\system32\dllcache\toside.sys

2011-06-13 20:33 . 2001-08-17 13:02 230912 -c--a-w- c:\windows\system32\dllcache\tosdvd03.sys

2011-06-13 20:33 . 2001-08-17 13:01 241664 -c--a-w- c:\windows\system32\dllcache\tosdvd02.sys

2011-06-13 20:33 . 2001-08-17 11:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys

2011-06-13 20:33 . 2001-08-17 11:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys

2011-06-13 20:32 . 2001-08-17 11:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys

2011-06-13 20:32 . 2001-08-17 13:56 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll

2011-06-13 20:32 . 2008-04-13 18:40 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys

2011-06-13 20:32 . 2001-08-17 11:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys

2011-06-13 20:31 . 2001-08-17 11:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys

2011-06-13 20:31 . 2001-08-17 12:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys

2011-06-13 20:31 . 2001-08-17 12:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys

2011-06-13 20:30 . 2001-08-17 11:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys

2011-06-13 20:30 . 2001-08-17 13:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll

2011-06-13 20:30 . 2001-08-17 13:07 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys

2011-06-13 20:30 . 2001-08-17 13:07 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys

2011-06-13 20:29 . 2001-08-17 13:07 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys

2011-06-13 20:29 . 2001-08-17 13:07 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys

2011-06-13 20:29 . 2001-08-17 21:36 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll

2011-06-13 20:29 . 2001-08-17 12:50 103936 -c--a-w- c:\windows\system32\dllcache\sx.sys

2011-06-13 20:29 . 2001-08-17 13:02 3968 -c--a-w- c:\windows\system32\dllcache\swusbflt.sys

2011-06-13 20:29 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpidflt.dll

2011-06-13 20:28 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpdflt2.dll

2011-06-13 20:28 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll

2011-06-13 20:28 . 2001-08-17 21:36 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll

2011-06-13 20:28 . 2001-08-17 21:36 155648 -c--a-w- c:\windows\system32\dllcache\stlnprop.dll

2011-06-13 20:27 . 2001-08-17 21:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll

2011-06-13 20:27 . 2001-08-17 11:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys

2011-06-13 20:27 . 2001-08-17 12:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys

2011-06-13 20:27 . 2001-08-17 11:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys

2011-06-13 20:26 . 2001-08-17 21:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll

2011-06-13 20:26 . 2001-08-17 21:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll

2011-06-13 20:25 . 2001-08-17 12:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys

2011-06-13 20:25 . 2001-08-17 21:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll

2011-06-13 20:25 . 2001-08-17 13:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys

2011-06-13 20:25 . 2001-08-17 12:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys

2011-06-13 20:25 . 2001-08-17 11:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys

2011-06-13 20:24 . 2001-08-17 21:36 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll

2011-06-13 20:24 . 2001-08-17 11:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys

2011-06-13 20:24 . 2001-08-17 12:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys

2011-06-13 20:24 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys

2011-06-13 20:24 . 2004-08-04 12:00 143422 -c--a-w- c:\windows\system32\dllcache\softkey.dll

2011-06-13 20:24 . 2001-08-17 12:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys

2011-06-13 20:23 . 2001-08-17 11:51 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys

2011-06-13 20:23 . 2001-08-17 13:56 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll

2011-06-13 20:23 . 2001-08-17 11:12 25034 -c--a-w- c:\windows\system32\dllcache\smcpwr2n.sys

2011-06-13 20:22 . 2001-08-17 11:12 24576 -c--a-w- c:\windows\system32\dllcache\smc8000n.sys

2011-06-13 20:22 . 2001-08-17 12:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys

2011-06-13 20:22 . 2008-04-13 18:36 6912 -c--a-w- c:\windows\system32\dllcache\smbclass.sys

2011-06-13 20:22 . 2008-04-13 18:36 16000 -c--a-w- c:\windows\system32\dllcache\smbbatt.sys

2011-06-13 20:22 . 2001-08-17 21:36 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll

2011-06-13 20:22 . 2001-08-17 21:36 33792 -c--a-w- c:\windows\system32\dllcache\smb0w.dll

2011-06-13 20:21 . 2001-08-17 21:36 28672 -c--a-w- c:\windows\system32\dllcache\sma0w.dll

2011-06-13 20:21 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\sm91w.dll

2011-06-13 20:21 . 2004-08-03 21:31 63547 -c--a-w- c:\windows\system32\dllcache\sla30nd5.sys

2011-06-13 20:20 . 2001-08-17 11:12 91294 -c--a-w- c:\windows\system32\dllcache\skfpwin.sys

2011-06-13 20:20 . 2001-08-17 11:12 94698 -c--a-w- c:\windows\system32\dllcache\sk98xwin.sys

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TabletWizard"="c:\windows\help\SplshWrp.exe" [2008-04-14 16384]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-29 126976]

"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840]

"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363]

"FjDspMon"="c:\program files\Fujitsu\Utils\FjDspMon.exe" [2004-10-14 20480]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-09-13 172032]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\Alan Smith\Start Menu\Programs\Startup\

Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-11-6 368640]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

AntSwitch.lnk - c:\windows\AntSwitch.exe [2005-11-2 28748]

BTTray.lnk - c:\program files\Fujitsu Siemens\Bluetooth Software\BTTray.exe [2004-9-21 557123]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey]

2008-04-14 00:11 47104 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\loginkey.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL]

2002-08-29 10:41 11776 ----a-w- c:\windows\system32\tabbtnwl.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify]

2008-04-14 00:12 32256 ----a-w- c:\windows\system32\tpgwlnot.dll

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FjEvents]

2004-12-16 14:08 20480 ----a-w- c:\program files\Fujitsu\Utils\FjEvents.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fujitsu Menu]

2004-12-16 14:10 32768 ----a-w- c:\program files\Fujitsu\Utils\FjMnuIco.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

2007-05-08 15:24 54840 ----a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]

2006-06-26 08:46 497200 ----a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]

2006-06-26 09:34 614960 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]

2006-06-26 09:33 243248 ----a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]

2006-05-16 17:50 40960 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TabletTip]

2008-04-14 00:12 271872 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\tabtip.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WMPNetworkSvc"=3 (0x3)

"gusvc"=2 (0x2)

"gupdate1c9d31333ce2850"=2 (0x2)

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4635:TCP"= 4635:TCP:ppLive

"6329:UDP"= 6329:UDP:ppLive

.

R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [09/06/2010 17:43 11352]

R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [28/09/2005 21:35 192608]

R3 Fjbtndrv;Fujitsu LIFEBOOK T3000 Button Driver;c:\windows\system32\drivers\FjBtndrv.sys [20/06/2003 14:30 11392]

R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [28/09/2005 21:35 6000]

R3 hidpen;Wacom Serial Pen HID MiniDriver;c:\windows\system32\drivers\hidpen.sys [28/09/2005 21:35 31104]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [07/05/2010 12:06 32856]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]

R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [28/09/2005 21:35 92550]

S2 gupdate1c9d31333ce2850;Google Update Service (gupdate1c9d31333ce2850);c:\program files\Google\Update\GoogleUpdate.exe [12/05/2009 16:06 133104]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/05/2009 16:06 133104]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [25/05/2011 11:53 39984]

S3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [28/09/2005 21:35 6324]

S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [13/08/2004 09:54 14208]

S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [10/06/2011 21:50 229376]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

vvdsvc REG_MULTI_SZ vvdsvc

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]

2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll

.

Contents of the 'Scheduled Tasks' folder

.

2011-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05]

.

2011-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05]

.

2011-06-15 c:\windows\Tasks\User_Feed_Synchronization-{52548EC2-B4D7-439B-9623-1232966E9D66}.job

- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.co.uk/

uSearchURL,(Default) = hxxp://www.google.com/keyword/%s

TCP: DhcpNameServer = 192.168.0.1

.

.

------- File Associations -------

.

JSEFile=NOTEPAD.EXE %1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-06-15 20:20

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

.

- - - - - - - > 'explorer.exe'(6928)

c:\windows\system32\WININET.dll

c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll

c:\program files\windows journal\nbmaptip.dll

c:\windows\IME\SPGRMR.DLL

c:\windows\system32\ieframe.dll

c:\windows\system32\BTNEIG~1.DLL

c:\windows\system32\wbtapi.dll

c:\windows\system32\btwpimif.dll

c:\windows\system32\btosif.dll

c:\windows\system32\btrez.dll

c:\windows\system32\CSH.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\btncopy.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe

c:\windows\SYSTEM32\WISPTIS.EXE

c:\windows\System32\tabbtnu.exe

c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe

c:\windows\System32\SCardSvr.exe

c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe

c:\program files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe

c:\windows\System32\digtizer.exe

c:\windows\system32\igfxext.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\program files\Common Files\Microsoft Shared\Ink\TCServer.exe

c:\windows\system32\HPZipm12.exe

c:\windows\AGRSMMSG.exe

c:\windows\system32\rundll32.exe

c:\windows\system32\igfxext.exe

c:\windows\system32\wscntfy.exe

c:\program files\Apoint2K\HidFind.exe

c:\program files\Apoint2K\Apntex.exe

.

**************************************************************************

.

Completion time: 2011-06-15 20:28:28 - machine was rebooted

ComboFix-quarantined-files.txt 2011-06-15 19:28

ComboFix2.txt 2011-06-09 18:06

.

Pre-Run: 6,465,757,184 bytes free

Post-Run: 6,472,966,144 bytes free

.

- - End Of File - - 48E22F4D29EC1997795E4F50761E6D3C

  • ExTS Admin
Posted
No, it won't install, it said the same thing again.

Ok, seems we can't do it the easy way. :(

 

Open windows explorer (right click the Start button and click Explore)

 

At the top of windows explorer, click tools >> folder options >> click the

view tab

  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box

Click apply, click ok

 

Now Navigate to the C:\ folder and click on it.

  • In the right hand panel locate a file named boot.ini
  • right click it and click open or Open with
  • if prompted with Open with choose notepad

Please post the contents of the file in your next reply.

 

Thanks

Member of:

UNITE

  • ExTS Admin
Posted

I had a strange feeling you was going to tell me that!

Oh Well, we now know why the Boot partition cannot be enumerated correctly. :o

 

As the boot.ini doesn't exist.... open Notepad

copy/paste the following text in the Code box below, into Notepad:

Do Not copy the word CODE

 

[boot loader]
timeout=30
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=1 /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=2 /fastdetect
scsi(0)disk(0)rdisk(0)partition(1)\WINDOWS=3 /fastdetect
scsi(0)disk(0)rdisk(0)partition(2)\WINDOWS=4 /fastdetect
scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=5 /fastdetect
scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=6 /fastdetect
C:\WINDOWS=7 /fastdetect

 

Save the file you just created. Name it boot.ini & save it directly to C:\ drive

 

Do Not reboot yet!

 

Next

 

Go to start >> Run and type the following line in the run box and click OK.

 

notepad c:\boot.ini

 

note the space after notepad.

 

Please post the contents of the notepad that opens.

 

Thanks

Member of:

UNITE

Posted

Same as you gave me--

 

[boot loader]

timeout=30

[operating systems]

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=1 /fastdetect

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS=2 /fastdetect

scsi(0)disk(0)rdisk(0)partition(1)\WINDOWS=3 /fastdetect

scsi(0)disk(0)rdisk(0)partition(2)\WINDOWS=4 /fastdetect

scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=5 /fastdetect

scsi(0)disk(0)rdisk(1)partition(2)\WINDOWS=6 /fastdetect

C:\WINDOWS=7 /fastdetect

  • ExTS Admin
Posted

That's ok .... i just needed to check before we continue.

 

Please print or write down these instructions then reboot the computer.

 

You will only need to do this until you find the option that will boot to Windows. Once Windows has loaded please stop there and post back which option started the computer.

 

After the reboot, you'll have 30 seconds to choose from the boot menu.

  • Use your arrow key and select 1 /fastdetect in the list and press Enter
  • Wait for it to boot Windows.
  • If you receive an error, click OK to restart the system.

 

 

If you need to restart because of Windows failing to load you will see the boot menu again.

  • Arrow up to 2 /fastdetect and press Enter.
  • Wait for Windows to boot.
  • If you receive an error message, same as before, click OK to restart.
  • Continue using the arrow key, going in succession from 3 /fastdetect, etc., one at a time, until Windows boots up.

 

Who said life was dull? :)

Member of:

UNITE

Posted

Just before I do that,

I don't know if this has any bearing on the matter but every time the laptop starts or re-boots, on the first page-Fujitsu etc. it says

02F9: Thermal sensor error

Enter F1 To resume or F2 to set up.

 

It does this every time and will not proceed until F1 is pushed.

  • ExTS Admin
Posted

sounds like an over heating problem, but this isn't in my field.

Once we get this boot problem sorted i'll get some more experienced in this to assist you.

Member of:

UNITE

  • ExTS Admin
Posted

Ok thanks, i needed to be sure which option worked.

If we got it wrong!!! mmm doesn't bare thinking about.

 

OK good. Now that we know which partition Windows is located in, we need to set it one more time.

 

Right click the C:\boot.ini (you created earlier) & rename it to boot.old

 

Open Notepad then copy/paste the text in the Code box below, into that empty Notepad:

 

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Save this as boot.ini directly on the C:\ drive. (replacing the earlier one)

 

Let me know how you make out.

It should be ok now.

Member of:

UNITE

Posted

Okay, that is on C:\

notepad report the same again--

[boot loader]

timeout=30

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

  • ExTS Admin
Posted

If the system reboots ok, you can edit the boot.ini we just created.

You can change:

timeout=30

to

timeout=3

 

it'll reboot a bit faster, it'll cut down the wait time from 30 seconds to 3 seconds.

Member of:

UNITE

  • ExTS Admin
Posted
Re-booted fine but slow.

Yes, that was my mistake Sorry.

i should have altered the new boot.ini script to say:

timeout=3

 

that's why i added the previous post.

 

Now to see if everything works.......

Run Combofix again and see if it will install the recovery console now.

if no deletions are found, you need not post the report.

Member of:

UNITE

Posted

One deletion:

 

ComboFix 11-06-15.02 - Alan Smith 16/06/2011 21:27:53.4.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.758.403 [GMT 1:00]

Running from: c:\documents and settings\Alan Smith\Desktop\Combo-fix.exe

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\struct~.ini

.

.

((((((((((((((((((((((((( Files Created from 2011-05-16 to 2011-06-16 )))))))))))))))))))))))))))))))

.

.

2011-06-15 23:14 . 2011-06-16 14:04 -------- d-----w- c:\windows\SxsCaPendDel

2011-06-13 20:52 . 2008-04-14 00:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll

2011-06-13 20:52 . 2001-08-17 21:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll

2011-06-13 20:52 . 2008-04-14 00:12 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll

2011-06-13 20:51 . 2001-08-17 21:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe

2011-06-13 20:51 . 2001-08-17 21:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe

2011-06-13 20:49 . 2001-08-17 21:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe

2011-06-13 20:49 . 2001-08-17 11:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys

2011-06-13 20:49 . 2004-08-03 21:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys

2011-06-13 20:48 . 2004-08-03 21:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys

2011-06-13 20:47 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys

2011-06-13 20:47 . 2004-08-03 21:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys

2011-06-13 20:47 . 2001-08-17 11:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys

2011-06-13 20:46 . 2001-08-17 12:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys

2011-06-13 20:45 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll

2011-06-13 20:45 . 2001-08-17 21:36 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll

2011-06-13 20:45 . 2001-08-17 12:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys

2011-06-13 20:45 . 2004-08-03 21:29 23615 -c--a-w- c:\windows\system32\dllcache\wch7xxnt.sys

2011-06-13 20:45 . 2008-04-13 18:45 31744 -c--a-w- c:\windows\system32\dllcache\wceusbsh.sys

2011-06-13 20:44 . 2001-08-17 11:10 35871 -c--a-w- c:\windows\system32\dllcache\wbfirdma.sys

2011-06-13 20:44 . 2004-08-03 21:29 33599 -c--a-w- c:\windows\system32\dllcache\watv04nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 19551 -c--a-w- c:\windows\system32\dllcache\watv02nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 29311 -c--a-w- c:\windows\system32\dllcache\watv01nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 11775 -c--a-w- c:\windows\system32\dllcache\wadv05nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 12127 -c--a-w- c:\windows\system32\dllcache\wadv02nt.sys

2011-06-13 20:44 . 2004-08-03 21:29 12415 -c--a-w- c:\windows\system32\dllcache\wadv01nt.sys

2011-06-13 20:43 . 2001-08-17 11:13 16925 -c--a-w- c:\windows\system32\dllcache\w940nd.sys

2011-06-13 20:43 . 2001-08-17 11:13 19016 -c--a-w- c:\windows\system32\dllcache\w926nd.sys

2011-06-13 20:43 . 2001-08-17 11:13 19528 -c--a-w- c:\windows\system32\dllcache\w840nd.sys

2011-06-13 20:42 . 2001-08-17 12:28 64605 -c--a-w- c:\windows\system32\dllcache\vvoice.sys

2011-06-13 20:42 . 2001-08-17 12:28 397502 -c--a-w- c:\windows\system32\dllcache\vpctcom.sys

2011-06-13 20:42 . 2001-08-17 12:28 604253 -c--a-w- c:\windows\system32\dllcache\vmodem.sys

2011-06-13 20:42 . 2001-08-17 11:14 249402 -c--a-w- c:\windows\system32\dllcache\vinwm.sys

2011-06-13 20:41 . 2001-08-17 12:49 24576 -c--a-w- c:\windows\system32\dllcache\viairda.sys

2011-06-13 20:41 . 2008-04-13 18:40 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys

2011-06-13 20:41 . 2001-08-17 12:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys

2011-06-13 20:41 . 2001-08-17 12:28 765884 -c--a-w- c:\windows\system32\dllcache\usrti.sys

2011-06-13 20:40 . 2001-08-17 12:28 113762 -c--a-w- c:\windows\system32\dllcache\usrpda.sys

2011-06-13 20:40 . 2001-08-17 12:28 7556 -c--a-w- c:\windows\system32\dllcache\usroslba.sys

2011-06-13 20:40 . 2001-08-17 12:28 224802 -c--a-w- c:\windows\system32\dllcache\usr1807a.sys

2011-06-13 20:40 . 2001-08-17 12:28 794399 -c--a-w- c:\windows\system32\dllcache\usr1806v.sys

2011-06-13 20:39 . 2001-08-17 12:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys

2011-06-13 20:39 . 2001-08-17 12:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys

2011-06-13 20:39 . 2008-04-13 18:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys

2011-06-13 20:39 . 2008-04-13 18:45 17152 -c--a-w- c:\windows\system32\dllcache\usbohci.sys

2011-06-13 20:39 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys

2011-06-13 20:39 . 2004-08-03 21:31 32384 -c--a-w- c:\windows\system32\dllcache\usb101et.sys

2011-06-13 20:38 . 2001-08-17 21:36 94720 -c--a-w- c:\windows\system32\dllcache\umaxud32.dll

2011-06-13 20:38 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\umaxu40.dll

2011-06-13 20:38 . 2001-08-17 21:36 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll

2011-06-13 20:38 . 2001-08-17 21:36 69632 -c--a-w- c:\windows\system32\dllcache\umaxu12.dll

2011-06-13 20:37 . 2001-08-17 21:36 50688 -c--a-w- c:\windows\system32\dllcache\umaxscan.dll

2011-06-13 20:37 . 2001-08-17 12:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys

2011-06-13 20:37 . 2001-08-17 21:36 50176 -c--a-w- c:\windows\system32\dllcache\umaxp60.dll

2011-06-13 20:37 . 2001-08-17 21:36 47616 -c--a-w- c:\windows\system32\dllcache\umaxcam.dll

2011-06-13 20:37 . 2001-08-17 21:36 211968 -c--a-w- c:\windows\system32\dllcache\um54scan.dll

2011-06-13 20:36 . 2001-08-17 21:36 216064 -c--a-w- c:\windows\system32\dllcache\um34scan.dll

2011-06-13 20:36 . 2001-08-17 12:52 36736 -c--a-w- c:\windows\system32\dllcache\ultra.sys

2011-06-13 20:36 . 2001-08-17 12:48 11520 -c--a-w- c:\windows\system32\dllcache\twotrack.sys

2011-06-13 20:35 . 2001-08-17 11:51 166784 -c--a-w- c:\windows\system32\dllcache\tridxpm.sys

2011-06-13 20:35 . 2001-08-17 21:36 525568 -c--a-w- c:\windows\system32\dllcache\tridxp.dll

2011-06-13 20:35 . 2001-08-17 11:51 159232 -c--a-w- c:\windows\system32\dllcache\tridkbm.sys

2011-06-13 20:35 . 2001-08-17 13:56 440576 -c--a-w- c:\windows\system32\dllcache\tridkb.dll

2011-06-13 20:35 . 2001-08-17 11:51 222336 -c--a-w- c:\windows\system32\dllcache\trid3dm.sys

2011-06-13 20:34 . 2001-08-17 13:56 315520 -c--a-w- c:\windows\system32\dllcache\trid3d.dll

2011-06-13 20:34 . 2001-08-17 11:12 34375 -c--a-w- c:\windows\system32\dllcache\tpro4.sys

2011-06-13 20:34 . 2001-08-17 21:35 42496 -c--a-w- c:\windows\system32\dllcache\tp4res.dll

2011-06-13 20:34 . 2008-04-14 00:12 82944 -c--a-w- c:\windows\system32\dllcache\tp4mon.exe

2011-06-13 20:34 . 2001-08-17 21:36 31744 -c--a-w- c:\windows\system32\dllcache\tp4.dll

2011-06-13 20:33 . 2001-08-17 12:51 4992 -c--a-w- c:\windows\system32\dllcache\toside.sys

2011-06-13 20:33 . 2001-08-17 13:02 230912 -c--a-w- c:\windows\system32\dllcache\tosdvd03.sys

2011-06-13 20:33 . 2001-08-17 13:01 241664 -c--a-w- c:\windows\system32\dllcache\tosdvd02.sys

2011-06-13 20:33 . 2001-08-17 11:10 28232 -c--a-w- c:\windows\system32\dllcache\tos4mo.sys

2011-06-13 20:33 . 2001-08-17 11:14 123995 -c--a-w- c:\windows\system32\dllcache\tjisdn.sys

2011-06-13 20:32 . 2001-08-17 11:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys

2011-06-13 20:32 . 2001-08-17 13:56 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll

2011-06-13 20:32 . 2008-04-13 18:40 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys

2011-06-13 20:32 . 2001-08-17 11:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys

2011-06-13 20:31 . 2001-08-17 11:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys

2011-06-13 20:31 . 2001-08-17 12:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys

2011-06-13 20:31 . 2001-08-17 12:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys

2011-06-13 20:30 . 2001-08-17 11:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys

2011-06-13 20:30 . 2001-08-17 13:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll

2011-06-13 20:30 . 2001-08-17 13:07 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys

2011-06-13 20:30 . 2001-08-17 13:07 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys

2011-06-13 20:29 . 2001-08-17 13:07 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys

2011-06-13 20:29 . 2001-08-17 13:07 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys

2011-06-13 20:29 . 2001-08-17 21:36 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll

2011-06-13 20:29 . 2001-08-17 12:50 103936 -c--a-w- c:\windows\system32\dllcache\sx.sys

2011-06-13 20:29 . 2001-08-17 13:02 3968 -c--a-w- c:\windows\system32\dllcache\swusbflt.sys

2011-06-13 20:29 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpidflt.dll

2011-06-13 20:28 . 2001-08-17 21:36 10240 -c--a-w- c:\windows\system32\dllcache\swpdflt2.dll

2011-06-13 20:28 . 2001-08-17 21:36 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll

2011-06-13 20:28 . 2001-08-17 21:36 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll

2011-06-13 20:28 . 2001-08-17 21:36 155648 -c--a-w- c:\windows\system32\dllcache\stlnprop.dll

2011-06-13 20:27 . 2001-08-17 21:36 53248 -c--a-w- c:\windows\system32\dllcache\stlncoin.dll

2011-06-13 20:27 . 2001-08-17 11:18 285760 -c--a-w- c:\windows\system32\dllcache\stlnata.sys

2011-06-13 20:27 . 2001-08-17 12:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys

2011-06-13 20:27 . 2001-08-17 11:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys

2011-06-13 20:26 . 2001-08-17 21:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll

2011-06-13 20:26 . 2001-08-17 21:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll

2011-06-13 20:25 . 2001-08-17 12:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys

2011-06-13 20:25 . 2001-08-17 21:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll

2011-06-13 20:25 . 2001-08-17 13:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys

2011-06-13 20:25 . 2001-08-17 12:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys

2011-06-13 20:25 . 2001-08-17 11:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys

2011-06-13 20:24 . 2001-08-17 21:36 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll

2011-06-13 20:24 . 2001-08-17 11:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys

2011-06-13 20:24 . 2001-08-17 12:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys

2011-06-13 20:24 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys

2011-06-13 20:24 . 2004-08-04 12:00 143422 -c--a-w- c:\windows\system32\dllcache\softkey.dll

2011-06-13 20:24 . 2001-08-17 12:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys

2011-06-13 20:23 . 2001-08-17 11:51 58368 -c--a-w- c:\windows\system32\dllcache\smiminib.sys

2011-06-13 20:23 . 2001-08-17 13:56 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll

2011-06-13 20:23 . 2001-08-17 11:12 25034 -c--a-w- c:\windows\system32\dllcache\smcpwr2n.sys

2011-06-13 20:22 . 2001-08-17 11:12 24576 -c--a-w- c:\windows\system32\dllcache\smc8000n.sys

2011-06-13 20:22 . 2001-08-17 12:57 6784 -c--a-w- c:\windows\system32\dllcache\smbhc.sys

2011-06-13 20:22 . 2008-04-13 18:36 6912 -c--a-w- c:\windows\system32\dllcache\smbclass.sys

2011-06-13 20:22 . 2008-04-13 18:36 16000 -c--a-w- c:\windows\system32\dllcache\smbbatt.sys

2011-06-13 20:22 . 2001-08-17 21:36 45568 -c--a-w- c:\windows\system32\dllcache\smb3w.dll

2011-06-13 20:22 . 2001-08-17 21:36 33792 -c--a-w- c:\windows\system32\dllcache\smb0w.dll

2011-06-13 20:21 . 2001-08-17 21:36 28672 -c--a-w- c:\windows\system32\dllcache\sma0w.dll

2011-06-13 20:21 . 2001-08-17 21:36 28160 -c--a-w- c:\windows\system32\dllcache\sm91w.dll

2011-06-13 20:21 . 2004-08-03 21:31 63547 -c--a-w- c:\windows\system32\dllcache\sla30nd5.sys

2011-06-13 20:20 . 2001-08-17 11:12 91294 -c--a-w- c:\windows\system32\dllcache\skfpwin.sys

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-05-02 15:31 . 2004-08-13 16:00 692736 ----a-w- c:\windows\system32\inetcomm.dll

2011-04-29 16:19 . 2004-08-12 11:27 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-04-25 16:11 . 2004-08-12 11:28 916480 ----a-w- c:\windows\system32\wininet.dll

2011-04-25 16:11 . 2004-08-12 11:27 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-04-25 16:11 . 2004-08-12 11:27 1469440 ----a-w- c:\windows\system32\inetcpl.cpl

2011-04-25 12:01 . 2004-08-12 11:27 385024 ----a-w- c:\windows\system32\html.iec

2011-04-21 13:37 . 2004-08-12 11:28 105472 ----a-w- c:\windows\system32\drivers\mup.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TabletWizard"="c:\windows\help\SplshWrp.exe" [2008-04-14 16384]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-29 126976]

"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840]

"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363]

"FjDspMon"="c:\program files\Fujitsu\Utils\FjDspMon.exe" [2004-10-14 20480]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-09-13 172032]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]

"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

"avp"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-10-14 352976]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

.

c:\documents and settings\Alan Smith\Start Menu\Programs\Startup\

Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-11-6 368640]

.

c:\documents and settings\All Users\Start Menu\Programs\Startup\

AntSwitch.lnk - c:\windows\AntSwitch.exe [2005-11-2 28748]

BTTray.lnk - c:\program files\Fujitsu Siemens\Bluetooth Software\BTTray.exe [2004-9-21 557123]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\loginkey]

2008-04-14 00:11 47104 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\loginkey.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TabBtnWL]

2002-08-29 10:41 11776 ----a-w- c:\windows\system32\tabbtnwl.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpgwlnotify]

2008-04-14 00:12 32256 ----a-w- c:\windows\system32\tpgwlnot.dll

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

.

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]

backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FjEvents]

2004-12-16 14:08 20480 ----a-w- c:\program files\Fujitsu\Utils\FjEvents.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fujitsu Menu]

2004-12-16 14:10 32768 ----a-w- c:\program files\Fujitsu\Utils\FjMnuIco.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]

2007-05-08 15:24 54840 ----a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]

2006-06-26 08:46 497200 ----a-w- c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]

2006-06-26 09:34 614960 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]

2006-06-26 09:33 243248 ----a-w- c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]

2006-05-16 17:50 40960 ----a-w- c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TabletTip]

2008-04-14 00:12 271872 ----a-w- c:\program files\Common Files\Microsoft Shared\Ink\tabtip.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"WMPNetworkSvc"=3 (0x3)

"gusvc"=2 (0x2)

"gupdate1c9d31333ce2850"=2 (0x2)

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Messenger\\msmsgs.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4635:TCP"= 4635:TCP:ppLive

"6329:UDP"= 6329:UDP:ppLive

.

R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [09/06/2010 17:43 11352]

R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [28/09/2005 21:35 192608]

R3 Fjbtndrv;Fujitsu LIFEBOOK T3000 Button Driver;c:\windows\system32\drivers\FjBtndrv.sys [20/06/2003 14:30 11392]

R3 FUJ02E1;%FUJ02E1.DeviceDesc%;c:\windows\system32\drivers\FUJ02E1.sys [28/09/2005 21:35 6000]

R3 hidpen;Wacom Serial Pen HID MiniDriver;c:\windows\system32\drivers\hidpen.sys [28/09/2005 21:35 31104]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [07/05/2010 12:06 32856]

R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]

R3 OZSCR;O2Micro SmartCardBus Smartcard Reader;c:\windows\system32\drivers\ozscr.sys [28/09/2005 21:35 92550]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [25/05/2011 11:53 39984]

S3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [28/09/2005 21:35 6324]

S3 WacomPen;Wacom Serial Pen HID Driver;c:\windows\system32\drivers\wacompen.sys [13/08/2004 09:54 14208]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

vvdsvc REG_MULTI_SZ vvdsvc

.

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]

2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll

.

Contents of the 'Scheduled Tasks' folder

.

2011-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05]

.

2011-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 15:05]

.

2011-06-16 c:\windows\Tasks\User_Feed_Synchronization-{52548EC2-B4D7-439B-9623-1232966E9D66}.job

- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.co.uk/

uSearchURL,(Default) = hxxp://www.google.com/keyword/%s

IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm

TCP: DhcpNameServer = 192.168.0.1

.

.

------- File Associations -------

.

JSEFile=NOTEPAD.EXE %1

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-06-16 21:44

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Completion time: 2011-06-16 21:52:10

ComboFix-quarantined-files.txt 2011-06-16 20:52

ComboFix2.txt 2011-06-15 19:28

ComboFix3.txt 2011-06-09 18:06

.

Pre-Run: 6,179,082,240 bytes free

Post-Run: 6,176,911,360 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - BDD4FE5CA20FDB3B4E4E6CE576DA5738

  • ExTS Admin
Posted

Ok thanks.

 

and the recovery console installed i see:

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect

seems the boot problem is sorted. http://fc07.deviantart.net/images3/i/2004/146/9/1/Two_thumbs_up.gif

 

Let me have one last OTL report before we finish off the cleaning ( just so that i can double check everything)

Once we've finished i'll get some one to take a look at that 'Thermal sensor error' for you.

 

Double click on OTL to run it.

  • Under Extra Registry section, select Use SafeList.
  • Don't check the boxes beside 'LOP Check' and 'Purity Check' this time.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open. Please post the contents of these 2 Notepad files in your next reply.

 

Thanks

Member of:

UNITE

Posted

It's too long will have to post in three parts!

 

 

OTL logfile created on: 16/06/2011 22:29:49 - Run 3

OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Alan Smith\Desktop

Windows XP Tablet PC Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

 

758.48 Mb Total Physical Memory | 307.06 Mb Available Physical Memory | 40.48% Memory free

1.43 Gb Paging File | 1.03 Gb Available in Paging File | 71.90% Paging File free

Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 39.02 Gb Total Space | 5.77 Gb Free Space | 14.79% Space Free | Partition Type: NTFS

Drive D: | 16.85 Gb Total Space | 16.79 Gb Free Space | 99.62% Space Free | Partition Type: NTFS

 

Computer Name: NFRNTABLET11 | User Name: Alan Smith | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - C:\Documents and Settings\Alan Smith\Desktop\OTL.scr (OldTimer Tools)

PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)

PRC - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)

PRC - C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)

PRC - C:\WINDOWS\system32\digtizer.exe (WACOM)

PRC - C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Fujitsu PC Corporation)

PRC - C:\Program Files\Fujitsu Siemens\Bluetooth Software\BTTray.exe (WIDCOMM, Inc.)

PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)

PRC - C:\Program Files\Apoint2K\Hidfind.exe (Alps Electric Co., Ltd.)

PRC - C:\Program Files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.)

 

 

========== Modules (SafeList) ==========

 

MOD - C:\Documents and Settings\Alan Smith\Desktop\OTL.scr (OldTimer Tools)

MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)

 

 

========== Win32 Services (SafeList) ==========

 

SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.exe (HP)

SRV - (LVSrvLauncher) -- C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe (Logitech Inc.)

SRV - (LVPrcSrv) -- c:\Program Files\Common Files\Logitech\LVMVFM\LVPrcSrv.exe (Logitech Inc.)

SRV - (Digitizer) -- C:\WINDOWS\system32\digtizer.exe (WACOM)

SRV - (HP Port Resolver) -- C:\WINDOWS\system32\hpbpro.exe (Hewlett-Packard Company)

SRV - (HP Status Server) -- C:\WINDOWS\system32\hpboid.exe (Hewlett-Packard Company)

SRV - (btwdins) -- C:\Program Files\Fujitsu Siemens\Bluetooth Software\bin\btwdins.exe (WIDCOMM, Inc.)

 

 

========== Driver Services (SafeList) ==========

 

DRV - (catchme) -- File not found

DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)

DRV - (KLIF) -- C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)

DRV - (kl2) -- C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)

DRV - (KL1) -- C:\WINDOWS\system32\DRIVERS\kl1.sys (Kaspersky Lab ZAO)

DRV - (klim5) -- C:\WINDOWS\system32\drivers\klim5.sys (Kaspersky Lab ZAO)

DRV - (klmouflt) -- C:\WINDOWS\system32\drivers\klmouflt.sys (Kaspersky Lab)

DRV - (pccsmcfd) -- C:\WINDOWS\system32\drivers\pccsmcfd.sys (Nokia)

DRV - (n558) -- C:\WINDOWS\system32\drivers\n558.sys ()

DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()

DRV - (LVMVDrv) -- C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)

DRV - (LVcKap) -- C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)

DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)

DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)

DRV - (DLAUDFAM) -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Sonic Solutions)

DRV - (DLAUDF_M) -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Sonic Solutions)

DRV - (DLAIFS_M) -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Sonic Solutions)

DRV - (DLABOIOM) -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Sonic Solutions)

DRV - (DLAOPIOM) -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Sonic Solutions)

DRV - (DLAPoolM) -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Sonic Solutions)

DRV - (DLADResN) -- C:\WINDOWS\system32\DLA\DLADResN.SYS (Sonic Solutions)

DRV - (DLACDBHM) -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)

DRV - (DLARTL_N) -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)

DRV - (hidpen) -- C:\WINDOWS\system32\drivers\hidpen.sys (Wacom Co., Ltd)

DRV - (STAC97) -- C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)

DRV - (OZSCR) -- C:\WINDOWS\system32\drivers\ozscr.sys (O2Micro)

DRV - (CONAN) -- C:\WINDOWS\system32\drivers\o2mmb.sys (O2 Micro )

DRV - (MbxStby) -- C:\WINDOWS\system32\drivers\MbxStby.sys (O2 Micro)

DRV - (k750obex) -- C:\WINDOWS\system32\drivers\k750obex.sys (MCCI)

DRV - (k750mdm) -- C:\WINDOWS\system32\drivers\k750mdm.sys (MCCI)

DRV - (k750mdfl) -- C:\WINDOWS\system32\drivers\k750mdfl.sys (MCCI)

DRV - (k750bus) Sony Ericsson 750 driver (WDM) -- C:\WINDOWS\system32\drivers\k750bus.sys (MCCI)

DRV - (w29n51) Intel® -- C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)

DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)

DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)

DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)

DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)

DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (WIDCOMM, Inc.)

DRV - (BTSERIAL) -- C:\WINDOWS\system32\drivers\btserial.sys (WIDCOMM, Inc.)

DRV - (BTSLBCSP) -- C:\WINDOWS\system32\drivers\btslbcsp.sys (WIDCOMM, Inc.)

DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (WIDCOMM, Inc.)

DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (WIDCOMM, Inc.)

DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (WIDCOMM, Inc.)

DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (WIDCOMM, Inc.)

DRV - (cdrbsdrv) -- C:\WINDOWS\System32\drivers\CDRBSDRV.SYS (B.H.A Corporation)

DRV - (Fjbtndrv) -- C:\WINDOWS\system32\drivers\FjBtndrv.sys (Fujitsu PC Corporation)

DRV - (FUJ02E1) -- C:\WINDOWS\system32\drivers\FUJ02E1.sys (Fujitsu Limited)

DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC)

DRV - (FUJ02B1) -- C:\WINDOWS\system32\drivers\fuj02b1.sys (FUJITSU LIMITED)

DRV - (Aspi32) -- C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 60 04 EB 0C 2A F9 CA 01 [binary data]

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

========== FireFox ==========

 

FF - prefs.js..browser.search.defaultenginename: "Google"

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="

FF - prefs.js..browser.search.selectedEngine: "Google"

 

FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\THBExt [2010/10/14 14:31:46 | 000,000,000 | ---D | M]

 

[2009/05/07 11:06:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Alan Smith\Application Data\Mozilla\Firefox\Profiles\cibkoitq.default\extensions

[2008/06/10 16:09:27 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\Alan Smith\Application Data\Mozilla\Firefox\Profiles\cibkoitq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2009/11/24 15:09:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

[2008/05/04 12:06:42 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

[2011/06/08 23:25:46 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{422112EB-BC81-4FF3-A751-D14968EB3BC3}

File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\REAL-NETWORKS@PARTNERS.MOZILLA.COM

File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\TALKBACK@MOZILLA.ORG

File not found (No name found) -- C:\PROGRAM FILES\REAL\REALPLAYER\BROWSERRECORD

 

O1 HOSTS File: ([2011/06/16 21:44:19 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)

O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)

O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O4 - HKLM..\Run: [avp] C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)

O4 - HKLM..\Run: [bluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)

O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)

O4 - HKLM..\Run: [FjDspMon] C:\Program Files\Fujitsu\Utils\FjDspMon.exe (Fujitsu PC Corporation)

O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe (HP)

O4 - Startup: C:\Documents and Settings\Alan Smith\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Sony Corporation)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AntSwitch.lnk = C:\WINDOWS\AntSwitch.exe (Fujitsu Siemens Computers)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk = C:\Program Files\Fujitsu Siemens\Bluetooth Software\BTTray.exe (WIDCOMM, Inc.)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()

O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_26.dll (Sun Microsystems, Inc.)

O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Fujitsu Siemens\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Fujitsu Siemens\Bluetooth Software\btsendto_ie.htm ()

O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://active.macromedia.com/director/cabs/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)

O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} http://dl.tvunetworks.com/TVUAx.cab (CTVUAxCtrl Object)

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)

O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://194.168.163.96/activex/AxisCamControl.cab (CamImage Class)

O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)

O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} http://www.tvucricket.com/player/vjocx-en-black.cab (VodClient Control Class)

O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)

O18 - Protocol\Handler\widimg {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\BTXPPanel.dll (WIDCOMM, Inc.)

O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2011\kloehk.dll (Kaspersky Lab ZAO)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)

O20 - Winlogon\Notify\klogon: DllName - C:\windows\system32\klogon.dll - C:\WINDOWS\system32\klogon.dll (Kaspersky Lab ZAO)

O24 - Desktop WallPaper: C:\Documents and Settings\Alan Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O24 - Desktop BackupWallPaper: C:\Documents and Settings\Alan Smith\Local Settings\Application Data\Microsoft\Wallpaper1.bmp

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

 

========== Files/Folders - Created Within 30 Days ==========

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...