Page 1 of 3 123 LastLast
Results 1 to 10 of 23

Thread: HJT Log - Strange Problems

  1. #1
    Join Date
    Sep 2006
    Posts
    11

    HJT Log - Strange Problems

    I rebooted my machine to use checkdisk and when it restarted I lost my second drive. It says it is a RAW file system and contains 0 bytes! Windows has become very slow and some files have become hidden and others are now read only.

    Went into safe mode and ran spybot, adaware, bit defender, anti-virus, ewido and a few others. They say my computer is clean. Can someone tell me what my HJT logfile says?

    Thanks for any help.

    Logfile of HijackThis v1.99.1
    Scan saved at 1:59:55 PM, on 9/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Advanced Registry Doctor\RegManServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\GhostSurf 2005\DeleteSvc.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotC.exe
    C:\old program files\Program Files\Rainlendar\Rainlendar.exe
    C:\old program files\Program Files\Pixoria\Konfabulator\Konfabulator.exe
    C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfan.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\UnHackMe\hackmon.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\DOCUME~1\Dad\LOCALS~1\Temp\Temporary Directory 6 for gmer(2).zip\gmer.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com//0seenus/saos01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://online.tvguide.com/listings/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = My IE Explorer
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\GhostSurf 2005\SCActiveBlock.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\OLDPRO~1\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - (no file)
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\RunOnce: [GhostSurfDelSatellite] "C:\Program Files\GhostSurf 2005\DeleteSatellite.exe" nowait
    O4 - HKCU\..\Run: [UnHackMe Monitor] C:\Program Files\UnHackMe\hackmon.exe
    O4 - Startup: debug.nfo
    O4 - Startup: Konfabulator.lnk = C:\old program files\Program Files\Pixoria\Konfabulator\Konfabulator.exe
    O4 - Startup: speedfan.exe
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: HotC.exe
    O4 - Global Startup: Rainlendar.exe.lnk = C:\old program files\Program Files\Rainlendar\Rainlendar.exe
    O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
    O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1...datePortal.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1147272430281
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Advanced Registry Doctor\RegManServ.exe
    O23 - Service: Tenebril antispyware satellite (TNBRLDS) - Tenebril Inc. - C:\Program Files\GhostSurf 2005\DeleteSvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Why were you running to trying to run checkdisk?

  3. #3
    Join Date
    Sep 2006
    Posts
    11
    I added some new P2P programs and wanted to make sure they weren't going to interfere with anything. Now it looks like something did.

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Uninstall those new programs you added for a start. You always are taking a risk with p2p programs, many of them contain unwanted nasty items. What were the names of these programs?

  5. #5
    Join Date
    Sep 2006
    Posts
    11
    I was trying out BitTorrent and was visiting a few Bit Torrent sites and my first hard drive, which is 250 gigs, started filling up fast. I removed the sites from my history, the BT programs I was using and the files I DLed. After I removed about 100 gigs, I ran chkdsk and saw that there was a problem gaining access to my second drive as the file structure was changed. And some program files became read only.

    How does my HJT logfile look? Do you need to see anything else?

    Thanks for the quick replies.

  6. #6
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    There are several programs I question, only because I find no or very little information about them;
    This running process for instance, from the Temp file....It should not be running from the temp file PLUS it is known for creating keys for Malware
    C:\DOCUME~1\Dad\LOCALS~1\Temp\Temporary Directory 6 for gmer(2).zip\gmer.exe

    These files I have not found decent info for;
    Advanced Registry Doctor
    UnHackMe
    Pixoria\Konfabulator
    debug.nfo
    HotC.exe (which can be a legal program, though I am not certain what it does, but also can be the email worm W32.Silly.D).

    Since you say that files are missing or have been changed I am really questioning that Registry program. There are very few which should be run in the background, or all the time. Registry fixing is very tricky and should only be attempted after all other fixes have been applied.
    I really, at this point, only see one file for certain which is very suspect for malware and that is the debug.nfo.

    How about downloading and running WPFind
    Download WinPFind.zip and extract it to your C:\ folder. This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard as a reply.
    Please NOTE: not all files found with this program are necessarily bad. So don't remove anything noted there until we have had a chance to go through the log and see if there are suspicious items in it.

  7. #7
    Join Date
    Sep 2006
    Posts
    11
    Here are the results of the scan. Once again, thanks for your help.
    I know what all of the programs are that you questioned except for the debug.nfo. I will try to disable it.


    WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

    If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows sometimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

    »»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    Logfile created on: 9/30/2006 6:37:14 PM
    WinPFind v1.5.0 Folder = C:\WinPFind\WinPFind\
    Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
    Internet Explorer (Version = 6.0.2900.2180)

    »»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

    Checking %SystemDrive% folder...

    Checking %ProgramFilesDir% folder...

    Checking %WinDir% folder...

    Checking %System% folder...
    aspack 5/26/2005 3:34:52 PM 2297552 C:\WINDOWS\SYSTEM32\d3dx9_26.dll (Microsoft Corporation)
    PEC2 7/16/2003 4:26:44 PM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc ()
    PEC2 6/15/2006 5:55:04 PM 620180 C:\WINDOWS\SYSTEM32\DivX.dll (DivX, Inc.)
    PECompact2 6/15/2006 5:55:04 PM 620180 C:\WINDOWS\SYSTEM32\DivX.dll (DivX, Inc.)
    PTech 8/7/2006 9:50:22 AM 1484592 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL (Microsoft Corporation)
    PECompact2 9/11/2006 10:37:22 AM 8960936 C:\WINDOWS\SYSTEM32\MRT.exe (Microsoft Corporation)
    aspack 9/11/2006 10:37:22 AM 8960936 C:\WINDOWS\SYSTEM32\MRT.exe (Microsoft Corporation)
    aspack 8/4/2004 12:56:38 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll (Microsoft Corporation)
    WSUD 8/4/2004 12:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl (Microsoft Corporation)
    UPX! 11/28/2005 9:50:22 AM 27136 C:\WINDOWS\SYSTEM32\PCWizard.cpl ()
    Umonitor 8/4/2004 12:56:46 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll (Microsoft Corporation)
    winsync 7/16/2003 4:50:38 PM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu ()
    PTech 6/19/2006 4:19:26 PM 304944 C:\WINDOWS\SYSTEM32\WgaTray.exe (Microsoft Corporation)
    PEC2 8/24/2006 10:30:24 PM 8337920 C:\WINDOWS\SYSTEM32\wmploc.dll (Microsoft Corporation)
    WSUD 8/24/2006 10:30:24 PM 8337920 C:\WINDOWS\SYSTEM32\wmploc.dll (Microsoft Corporation)

    Checking %System%\Drivers folder and sub-folders...
    UPX! 9/28/2006 10:42:48 PM 778656 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys (GRISOFT, s.r.o.)
    FSG! 9/28/2006 10:42:48 PM 778656 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys (GRISOFT, s.r.o.)
    PEC2 9/28/2006 10:42:48 PM 778656 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys (GRISOFT, s.r.o.)
    aspack 9/28/2006 10:42:48 PM 778656 C:\WINDOWS\SYSTEM32\drivers\avg7core.sys (GRISOFT, s.r.o.)
    PTech 8/3/2004 10:41:38 PM 1309184 C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys (Smart Link)

    Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
    127.0.0.1 ad-w-a-r-e.com
    127.0.0.1 www.ad-w-a-r-e.com
    127.0.0.1 web-nexus.net
    127.0.0.1 thinstall.abetterinternet.com
    127.0.0.1 www.3abetterinternet.com
    127.0.0.1 download.abetterinternet.com
    127.0.0.1 www.abetterinternet.com
    127.0.0.1 dl.web-nexus.net


    Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
    9/30/2006 10:31:28 AM S 2048 C:\WINDOWS\bootstat.dat ()
    9/6/2006 4:45:18 AM HS 129 C:\WINDOWS\parserat.key ()
    9/3/2006 8:35:22 PM RHS 227 C:\WINDOWS\assembly\Desktop.ini ()
    9/3/2006 8:35:22 PM RH 0 C:\WINDOWS\assembly\PublisherPolicy.tme ()
    9/3/2006 8:35:22 PM RH 0 C:\WINDOWS\assembly\pubpol1.dat ()
    9/3/2006 8:50:14 PM RH 0 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ind ex1c.dat ()
    9/8/2006 4:16:28 PM H 65 C:\WINDOWS\Downloaded Program Files\desktop.ini ()
    9/30/2006 2:12:16 PM H 0 C:\WINDOWS\LastGood\INF\oem21.inf ()
    9/30/2006 2:12:16 PM H 0 C:\WINDOWS\LastGood\INF\oem21.PNF ()
    9/8/2006 4:17:24 PM H 65 C:\WINDOWS\Offline Web Pages\desktop.ini ()
    9/30/2006 10:37:02 AM H 48882 C:\WINDOWS\system32\vsconfig.xml ()
    9/12/2006 5:25:40 PM H 4212 C:\WINDOWS\system32\zllictbl.dat ()
    8/21/2006 9:00:10 AM S 11749 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB922582.cat ()
    8/24/2006 10:46:28 PM S 26948 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WMFDist11.cat ()
    8/24/2006 11:11:00 PM S 27852 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\wmp11.cat ()
    8/24/2006 8:43:58 PM S 10741 C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Wudf01000.cat ()
    9/30/2006 4:44:46 PM H 1024 C:\WINDOWS\system32\config\default.LOG ()
    9/30/2006 10:32:04 AM H 1024 C:\WINDOWS\system32\config\SAM.LOG ()
    9/30/2006 5:32:16 PM H 1024 C:\WINDOWS\system32\config\SECURITY.LOG ()
    9/30/2006 6:40:56 PM H 1024 C:\WINDOWS\system32\config\software.LOG ()
    9/30/2006 6:33:48 PM H 1024 C:\WINDOWS\system32\config\system.LOG ()
    9/28/2006 7:42:08 PM H 1024 C:\WINDOWS\system32\config\systemprofile\ntuser.da t.LOG ()
    9/8/2006 6:13:34 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\71C107NL\desktop.ini ()
    9/8/2006 6:13:34 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXMBK5EV\desktop.ini ()
    9/8/2006 6:13:34 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OYZ01234\desktop.ini ()
    9/8/2006 6:13:34 PM HS 67 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\YRS5VWGQ\desktop.ini ()
    9/24/2006 3:29:40 PM H 0 C:\WINDOWS\system32\drivers\UMDF\MsftWdf_user_01_0 0_00.Wdf ()
    8/20/2006 9:37:56 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\c4217e6d-3911-4ca7-9784-bf6f3c80d6f2 ()
    8/20/2006 9:37:56 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred ()
    8/5/2006 1:38:46 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\e929ae9d-f5ca-454a-8dc1-1ffb9d81ee75 ()
    8/5/2006 1:38:46 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred ()
    9/30/2006 10:31:44 AM H 6 C:\WINDOWS\Tasks\SA.DAT ()

    Checking for CPL files...
    8/4/2004 12:56:58 AM 68608 C:\WINDOWS\SYSTEM32\access.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 549888 C:\WINDOWS\SYSTEM32\appwiz.cpl (Microsoft Corporation)
    8/29/2003 4:30:28 PM 245825 C:\WINDOWS\SYSTEM32\btcpl.cpl (WIDCOMM, Inc.)
    8/4/2004 12:56:58 AM 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 135168 C:\WINDOWS\SYSTEM32\desk.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 80384 C:\WINDOWS\SYSTEM32\firewall.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 155136 C:\WINDOWS\SYSTEM32\hdwwiz.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 358400 C:\WINDOWS\SYSTEM32\inetcpl.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 129536 C:\WINDOWS\SYSTEM32\intl.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 380416 C:\WINDOWS\SYSTEM32\irprops.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 68608 C:\WINDOWS\SYSTEM32\joy.cpl (Microsoft Corporation)
    11/10/2005 1:03:50 PM 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl (Sun Microsystems, Inc.)
    7/16/2003 4:32:24 PM 187904 C:\WINDOWS\SYSTEM32\main.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 618496 C:\WINDOWS\SYSTEM32\mmsys.cpl (Microsoft Corporation)
    7/16/2003 4:37:20 PM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 25600 C:\WINDOWS\SYSTEM32\netsetup.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl (Microsoft Corporation)
    11/28/2005 9:50:22 AM 27136 C:\WINDOWS\SYSTEM32\PCWizard.cpl ()
    8/4/2004 12:56:58 AM 114688 C:\WINDOWS\SYSTEM32\powercfg.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 298496 C:\WINDOWS\SYSTEM32\sysdm.cpl (Microsoft Corporation)
    7/16/2003 4:47:58 PM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 94208 C:\WINDOWS\SYSTEM32\timedate.cpl (Microsoft Corporation)
    8/4/2004 12:56:58 AM 148480 C:\WINDOWS\SYSTEM32\wscui.cpl (Microsoft Corporation)
    5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl (Microsoft Corporation)
    7/16/2003 4:32:24 PM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl (Microsoft Corporation)
    7/16/2003 4:37:20 PM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl (Microsoft Corporation)
    7/16/2003 4:47:58 PM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl (Microsoft Corporation)

    Checking for Downloaded Program Files...
    {0E5F0222-96B9-11D3-8997-00104BD12D94} - PCPitstop Utility - CodeBase = http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    {17492023-C23A-453E-A040-C7C580BBF700} - Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?LinkID=39204
    {193C772A-87BE-4B19-A7BB-445B226FE9A1} - ewidoOnlineScan Control - CodeBase = http://download.ewido.net/ewidoOnlineScan.cab
    {31E68DE2-5548-4B23-88F0-C51E6A0F695E} - Microsoft PID Sniffer - CodeBase = https://support.microsoft.com/OAS/ActiveX/odc.cab
    {33564D57-0000-0010-8000-00AA00389B71} - - CodeBase = http://download.microsoft.com/downlo...22/wmv9VCM.CAB
    {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - - CodeBase = http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - BDSCANONLINE Control - CodeBase = http://download.bitdefender.com/reso...an8/oscan8.cab
    {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} - McUpdatePortalFactory Class - CodeBase = http://www.amiuptodate.com/vsc/bin/1...datePortal.cab
    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - MUWebControl Class - CodeBase = http://update.microsoft.com/microsof...?1147272430281
    {8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    {9600F64D-755F-11D4-A47F-0001023E6D5A} - Shutterfly Picture Upload Plugin - CodeBase = http://web1.shutterfly.com/downloads/Uploader.cab
    {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - ActiveScan Installer Class - CodeBase = http://acs.pandasoftware.com/actives...ree/asinst.cab
    {9F1C11AA-197B-4942-BA54-47A8489BB47F} - - CodeBase = http://v4.windowsupdate.microsoft.co...968.5893865741
    {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - - CodeBase = http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} - LycosMail Upload Control - CodeBase = http://mail.lycos.com/hanmail-ax/AttachMail.cab
    {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jin...ndows-i586.cab

    »»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

    Checking files in %ALLUSERSPROFILE%\Startup folder...
    6/27/2006 8:50:00 PM 681 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk ()
    5/3/2006 11:30:36 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ()
    8/23/2005 12:26:24 PM 47104 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotC.exe ()
    9/25/2006 8:40:10 PM 838 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Rainlendar.exe.lnk ()

    Checking files in %ALLUSERSPROFILE%\Application Data folder...
    5/3/2006 7:24:12 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini ()
    9/11/2006 8:50:10 AM 2173 C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache ()

    Checking files in %USERPROFILE%\Startup folder...
    9/30/2006 10:37:32 AM 18289 C:\Documents and Settings\Dad\Start Menu\Programs\Startup\debug.nfo ()
    5/3/2006 11:30:36 AM HS 84 C:\Documents and Settings\Dad\Start Menu\Programs\Startup\desktop.ini ()
    9/25/2006 8:40:08 PM 886 C:\Documents and Settings\Dad\Start Menu\Programs\Startup\Konfabulator.lnk ()
    2/8/2006 5:38:38 PM 2510336 C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfan.exe (Almico Software (www.almico.com))

    Checking files in %USERPROFILE%\Application Data folder...
    5/3/2006 7:24:12 AM HS 62 C:\Documents and Settings\Dad\Application Data\desktop.ini ()
    7/8/2006 11:05:26 AM 6814 C:\Documents and Settings\Dad\Application Data\wklnhst.dat ()

    »»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

    >>> Internet Explorer Settings <<<


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
    \\Start Page - http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SU B_PVER}&ar=home
    \\Search Page - http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    \\Default_Page_URL - http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
    \\Default_Search_URL - http://www.microsoft.com/isapi/redir...ie&ar=iesearch

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
    \\Start Page - http://online.tvguide.com/listings/
    \\Search Bar - http://g.msn.com//0seenus/saos01
    \\Search Page - http://www.microsoft.com/isapi/redir...ie&ar=iesearch

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
    \\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
    \\SearchAssistant - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    \\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation)

    >>> BHO's <<<
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
    \{0A87E45F-537A-40B4-B812-E2544C21A09F} - SpywareBlock Class = C:\Program Files\GhostSurf 2005\SCActiveBlock.dll (Tenebril Inc.)
    \{53707962-6F74-2D53-2644-206D7942484F} - = C:\OLDPRO~1\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
    \{5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
    \{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)

    >>> Internet Explorer Bars, Toolbars and Extensions <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
    \{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation)
    \{92A40B0A-740A-4A11-9DDB-70460C6DA383} - Copernic Desktop Search = ()
    \{C5F7A735-70F1-477F-8C36-6FF3C736017B} - Copernic Desktop Search = ()

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
    \{32683183-48a0-441b-a342-7c2a440a9478} - = ()
    \{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
    \{EFA24E62-B078-11D0-89E4-00C04FC9E26E} - History Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation)
    \{EFA24E64-B078-11D0-89E4-00C04FC9E26E} - Explorer Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
    \\{C5F7A735-70F1-477F-8C36-6FF3C736017B} - Copernic Desktop Search = ()

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
    \ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation)
    \ShellBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
    \WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation)
    \WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
    \WebBrowser\\{F2CF5485-4E02-4F68-819C-B92DE9277049} - = ()
    \WebBrowser\\{C5F7A735-70F1-477F-8C36-6FF3C736017B} - Copernic Desktop Search = ()

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\CmdMapping]
    \\NEXTID - 8198
    \\{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8193 =
    \\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8194 = Sun Java Console
    \\{306BBB66-D9E4-4481-833E-C1D5FCA06774} - 8195 =
    \\{546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - 8196 =
    \\{61039B22-563D-4922-B844-B076C318A66A} - 8197 =
    \\{E4143585-2688-4EBC-B264-27C774F600D5} - 8198 =
    \\{CCA281CA-C863-46ef-9331-5C8D4460577F} - 8200 = @btrez.dll,-4017
    \\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 8195 =
    \\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - 8196 =
    \\{85d1f590-48f4-11d9-9669-0800200c9a66} - 8197 = Uninstall BitDefender Online Scanner v8

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
    \{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
    \{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)(HKCU CLSID)
    \{85d1f590-48f4-11d9-9669-0800200c9a66} - MenuText: Uninstall BitDefender Online Scanner v8 = ()
    \{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - ButtonText: AIM = C:\Program Files\AIM\aim.exe (America Online, Inc.)
    \{CCA281CA-C863-46ef-9331-5C8D4460577F} - ButtonText: @btrez.dll,-4015 = C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    >>> Approved Shell Extensions (Non-Microsoft Only) <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Shell Extensions\Approved]
    \\{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = ()
    \\{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = ()
    \\{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = ()
    \\{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc.)
    \\{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = ()
    \\{32683183-48a0-441b-a342-7c2a440a9478} - Media Band = ()
    \\{7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = ()
    \\{DEE12703-6333-4D4E-8F34-738C4DCC2E04} - RecordNow! SendToExt = C:\Program Files\Sonic\RecordNow!\shlext.dll ()
    \\{5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
    \\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc.)
    \\ - = ()
    \\{6af09ec9-b429-11d4-a1fb-0090960218cb} - My Bluetooth Places = C:\WINDOWS\system32\BTNEIG~1.DLL (WIDCOMM, Inc.)
    \\{A155339D-CCCD-4714-85EB-3754B804C9DF} - a-squared Free Context Menu Shell Extension = C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL (Emsi Software GmbH)
    \\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - AVG7 Shell Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o.)
    \\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} - AVG7 Find Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o.)
    \\{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} - UnlockerShellExtension = C:\Program Files\Unlocker\UnlockerCOM.dll ()

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Shell Extensions\Approved]

    >>> Context Menu Handlers (Non-Microsoft Only) <<<
    [HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\Cont extMenuHandlers]
    \AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o.)
    \ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s.)
    \PowerArchiver - {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e} = ()

    [HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemO bjects\shellex\ContextMenuHandlers]
    \a2FreeContMenu - {A155339D-CCCD-4714-85EB-3754B804C9DF} = C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL (Emsi Software GmbH)
    \UnlockerShellExtension - {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} = C:\Program Files\Unlocker\UnlockerCOM.dll ()

    [HKEY_LOCAL_MACHINE\Software\Classes\Directory\shel lex\ContextMenuHandlers]
    \ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s.)

    [HKEY_LOCAL_MACHINE\Software\Classes\Directory\Back Ground\shellex\ContextMenuHandlers]

    [HKEY_LOCAL_MACHINE\Software\Classes\Folder\shellex \ContextMenuHandlers]
    \a2FreeContMenu - {A155339D-CCCD-4714-85EB-3754B804C9DF} = C:\PROGRA~1\A-SQUA~1\A2FREE~1.DLL (Emsi Software GmbH)
    \AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o.)
    \PowerArchiver - {d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e} = ()
    \UnlockerShellExtension - {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} = C:\Program Files\Unlocker\UnlockerCOM.dll ()

    >>> Column Handlers (Non-Microsoft Only) <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex \ColumnHandlers]
    \{A9AACA72-1C51-4F84-804D-90EDBA0D58F4} - Zinio Magazine Column Provider = ()

    >>> Registry Run Keys <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    !ewido - C:\Program Files\ewido anti-spyware 4.0\ewido.exe (Anti-Malware Development a.s.)
    AVG7_CC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe (GRISOFT, s.r.o.)
    Zone Labs Client - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Zone Labs, LLC)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents]
    IMAIL Installed = 1
    MAPI Installed = 1
    MSFS Installed = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce]
    GhostSurfDelSatellite - C:\Program Files\GhostSurf 2005\DeleteSatellite.exe (Tenebril Incorporated)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnceEx]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunServices]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunServicesOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    UnHackMe Monitor - C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunServices]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunServicesOnce]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

    >>> Startup Links <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Shell Folders\\Common Startup]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (WIDCOMM, Inc.)
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ()
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotC.exe ()
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Rainlendar.exe.lnk - C:\old program files\Program Files\Rainlendar\Rainlendar.exe (Rainy)

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\Shell Folders\\Startup]
    C:\Documents and Settings\Dad\Start Menu\Programs\Startup\debug.nfo ()
    C:\Documents and Settings\Dad\Start Menu\Programs\Startup\desktop.ini ()
    C:\Documents and Settings\Dad\Start Menu\Programs\Startup\Konfabulator.lnk - C:\old program files\Program Files\Pixoria\Konfabulator\Konfabulator.exe (Yahoo, Inc.)
    C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfan.exe (Almico Software (www.almico.com))

    >>> MSConfig Disabled Items <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\ExpandFrom

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\ExpandTo

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotC.exe
    path C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotC.exe
    backup C:\WINDOWS\pss\HotC.exeCommon Startup
    location Common Startup
    command C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotC.exe
    item HotC

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^debug.nfo
    path C:\Documents and Settings\Dad\Start Menu\Programs\Startup\debug.nfo
    backup C:\WINDOWS\pss\debug.nfoStartup
    location Startup
    command C:\Documents and Settings\Dad\Start Menu\Programs\Startup\debug.nfo
    item debug

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^Rainlendar.lnk
    backup C:\WINDOWS\pss\Rainlendar.lnkStartup
    location Startup
    command D:\PROGRA~1\RAINLE~1\RAINLE~1.EXE
    item Rainlendar

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^SFLog20060904-0001.csv
    backup C:\WINDOWS\pss\SFLog20060904-0001.csvStartup
    location Startup
    item SFLog20060904-0001

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^SFLog20060904.csv
    backup C:\WINDOWS\pss\SFLog20060904.csvStartup
    location Startup
    item SFLog20060904

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^SFLog20060905-0001.csv
    backup C:\WINDOWS\pss\SFLog20060905-0001.csvStartup
    location Startup
    item SFLog20060905-0001

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^SFLog20060905.csv
    backup C:\WINDOWS\pss\SFLog20060905.csvStartup
    location Startup
    item SFLog20060905

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^speedfan.exe
    path C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfan.exe
    backup C:\WINDOWS\pss\speedfan.exeStartup
    location Startup
    command C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfan.exe
    item speedfan

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^speedfanevents.cfg
    path C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfanevents.cfg
    backup C:\WINDOWS\pss\speedfanevents.cfgStartup
    location Startup
    command C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfanevents.cfg
    item speedfanevents

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^speedfanparams.cfg
    path C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfanparams.cfg
    backup C:\WINDOWS\pss\speedfanparams.cfgStartup
    location Startup
    command C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfanparams.cfg
    item speedfanparams

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^speedfansens.cfg
    path C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfansens.cfg
    backup C:\WINDOWS\pss\speedfansens.cfgStartup
    location Startup
    command C:\Documents and Settings\Dad\Start Menu\Programs\Startup\speedfansens.cfg
    item speedfansens

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^UD Agent.lnk
    backup C:\WINDOWS\pss\UD Agent.lnkStartup
    location Startup
    command D:\PROGRA~1\UNITED~1\UD.EXE
    item UD Agent

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^ud_mon.exe
    backup C:\WINDOWS\pss\ud_mon.exeStartup
    location Startup
    item ud_mon

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\!ewido
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item ewido
    hkey HKLM
    command "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BitTorrent
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item bittorrent
    hkey HKCU
    command "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item daemon
    hkey HKLM
    command "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\dla
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item tfswctrl
    hkey HKLM
    command C:\WINDOWS\system32\dla\tfswctrl.exe
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\McRegWiz
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item mcregwiz
    hkey HKLM
    command C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MCUpdateExe
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item McUpdate
    hkey HKLM
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item msmsgs
    hkey HKCU
    command "C:\Program Files\Messenger\msmsgs.exe" /background
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PC Pitstop Optimize Scheduler
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item PCPOptimize
    hkey HKLM
    command C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SoundMAXPnP
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item smax4pnp
    hkey HKLM
    command C:\Program Files\Analog Devices\Core\smax4pnp.exe
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UnlockerAssistant
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item UnlockerAssistant
    hkey HKLM
    command "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WinampAgent
    key SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item winampa
    hkey HKLM
    command C:\Program Files\Winamp\winampa.exe
    inimapping 0

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
    system.ini 0
    win.ini 0
    services 0
    startup 2


    [All Users Startup Folder Disabled Items]

    [Current User Startup Folder Disabled Items]

    >>> User Agent Post Platform <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform]
    \\Avant Browser - IEAK
    \\SV1 -

    >>> AppInit Dll's <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs]
    C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL = (Google)

    >>> Image File Execution Options <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
    \Your Image File Name Here without a path - Debugger = ntsd -d

    >>> Shell Service Object Delay Load <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad]
    \\PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
    \\CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation)
    \\WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation)
    \\SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll (Microsoft Corporation)
    \\WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} = C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)

    >>> Shell Execute Hooks <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
    \\{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation)
    \\{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll (Anti-Malware Development a.s.)

    >>> Shared Task Scheduler <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
    \\{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\System32\browseui.dll (Microsoft Corporation)
    \\{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\System32\browseui.dll (Microsoft Corporation)

    >>> Winlogon <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    \\UserInit = C:\WINDOWS\system32\userinit.exe,
    \\Shell = Explorer.exe
    \\System =

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
    \crypt32chain - crypt32.dll = (Microsoft Corporation)
    \cryptnet - cryptnet.dll = (Microsoft Corporation)
    \cscdll - cscdll.dll = (Microsoft Corporation)
    \ScCertProp - wlnotify.dll = (Microsoft Corporation)
    \Schedule - wlnotify.dll = (Microsoft Corporation)
    \sclgntfy - sclgntfy.dll = (Microsoft Corporation)
    \SensLogn - WlNotify.dll = (Microsoft Corporation)
    \termsrv - wlnotify.dll = (Microsoft Corporation)
    \WgaLogon - WgaLogon.dll = (Microsoft Corporation)
    \wlballoon - wlnotify.dll = (Microsoft Corporation)

    >>> DNS Name Servers <<<
    {47D57C94-914A-47CD-9BBB-2DC30C3003B8} - ()
    {E2C44183-EFA5-4AC4-808D-65ADB703A12E} - (Broadcom NetXtreme 57xx Gigabit Controller)
    {ED66B309-7BB8-4EDD-A35D-8FF0F5A608DC} - ()

    >>> All Winsock2 Catalogs <<<
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\WinSock2\Parameters\NameSpace_Catalog5\Catalog_ Entries]
    \000000000001\\LibraryPath - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation)
    \000000000002\\LibraryPath - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation)
    \000000000003\\LibraryPath - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation)
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\WinSock2\Parameters\Protocol_Catalog9\Catalog_E ntries]
    \000000000001\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000002\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000003\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000004\\PackedCatalogItem - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation)
    \000000000005\\PackedCatalogItem - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation)
    \000000000006\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000007\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000008\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000009\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000010\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000011\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000012\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000013\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000014\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)
    \000000000015\\PackedCatalogItem - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation)

    >>> Protocol Handlers (Non-Microsoft Only) <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Hand ler]
    \belarc - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
    \ipp - ()
    \msdaipp - ()

    >>> Protocol Filters (Non-Microsoft Only) <<<
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filt er]

    >>> Selected AddOn's <<<


    »»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

  8. #8
    Join Date
    Sep 2006
    Posts
    11
    debug.nfo is automatically generated by Almico's Speedfan when it starts. Guess I can't disable it without disabling Speedfan.

  9. #9
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok on the above. Give me awhile on this WPFind log...this is NOT my strongest suit here so it takes me awhile to read and decipher it. I will get back as soon as I can.
    Judy

  10. #10
    Join Date
    Sep 2006
    Posts
    11
    And I will patiently await your findings. Thanks for your help.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •