Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Hard drive keeps filling up!
   
BullGuard Antivirus Forum > Virus > Virus Questions > Hard drive keeps filling up!  
Forum Quick Jump
 
New Topic Post reply to : Hard drive keeps filling up! Printable version of : Hard drive keeps filling up!
[ << Previous Thread | Next Thread >> ]

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-2-2010 6:56 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Hi,

My hardrive keeps filling up and I have no idea why???

I have Zone Alarm and have run a scan and no viruses...

Can anyone help please as I am having to use windows clear up thing once every couple of days!


Thanks
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-2-2010 11:10 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:03:27, on 02/01/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Windows\sttray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 82.98.86.175 vibepc.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9920 bytes

MALWARE LOG

Malwarebytes' Anti-Malware 1.43
Database version: 3479
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18865

02/01/2010 20:29:34
mbam-log-2010-01-02 (20-29-34).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 256638
Time elapsed: 2 hour(s), 38 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 26

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\update (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Windows\System32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\drmgs.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Windows\fmark2.dat (Malware.Trace) -> Quarantined and deleted successfully.

DDS LOG


DDS (Ver_09-12-01.01) - NTFSx86
Run by Chloe at 20:50:15.40 on 02/01/2010
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.44.1033.18.1013.109 [GMT 0:00]

AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
AV: AVG 0.5.519 *On-access scanning enabled* (Outdated) {41564737-3200-1071-989B-0000E87B4FB1}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
SP: ZoneAlarm Security Suite Anti-Spyware *enabled* (Updated) {F245A209-1085-48B4-B927-35D56015EC60}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Security Suite Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\System32\ZoneLabs\avsys\ScanningProcess.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Windows\sttray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\taskeng.exe
C:\Users\Chloe\Desktop\dds.scr
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.facebook.com/
uWindow Title = Internet Explorer provided by Dell
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {2C688203-7EB3-4327-9995-1CB417BA23F9} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [dscactivate] c:\dell\dsca.exe 3
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [<NO NAME>]
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgwlntf - avgwlntf.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 82.98.86.175 vibepc.com

============= SERVICES / DRIVERS ===============

R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2008-2-3 10760]
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;c:\windows\system32\drivers\avgmfx86.sys [2008-2-3 26952]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-2-29 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-2-29 51440]
S3 AvgWFP;AVG7 Firewall Driver x86;c:\windows\system32\drivers\avgwfp.sys [2008-2-3 53768]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
S3 wrssweep;Webroots Volume Access Driver;c:\program files\webroot\washer\wrSSweep.sys [2008-2-5 21832]

=============== Created Last 30 ================

2010-01-02 17:32:17 0 d-----w- c:\users\chloe\appdata\roaming\Malwarebytes
2010-01-02 17:31:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 17:31:30 0 d-----w- c:\programdata\Malwarebytes
2010-01-02 17:31:19 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 17:31:17 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 17:08:37 0 d-----w- c:\program files\CCleaner
2010-01-01 22:55:34 65536 --sha-w- c:\users\chloe\ntuser.dat{cf5ee9fa-f625-11de-a04d-00038a000015}.TM.blf
2010-01-01 22:55:34 524288 --sha-w- c:\users\chloe\ntuser.dat{cf5ee9fa-f625-11de-a04d-00038a000015}.TMContainer00000000000000000002.regtrans-ms
2010-01-01 22:55:34 524288 --sha-w- c:\users\chloe\ntuser.dat{cf5ee9fa-f625-11de-a04d-00038a000015}.TMContainer00000000000000000001.regtrans-ms
2010-01-01 22:51:09 262144 ---ha-w- c:\users\chloe\ntuser.dat_TU_67238.LOG1
2010-01-01 22:51:09 0 ---ha-w- c:\users\chloe\ntuser.dat_TU_67238.LOG2
2009-12-27 10:34:10 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-22 11:49:28 0 d-----w- c:\users\chloe\appdata\roaming\Totally Rad Dirty Pictures
2009-12-21 10:46:47 0 d-----w- c:\users\chloe\appdata\roaming\ZoomBrowser EX
2009-12-21 10:23:15 0 d-----w- c:\program files\common files\Canon
2009-12-20 09:30:46 0 d-----w- c:\program files\uTorrent
2009-12-14 15:58:39 524288 --sha-w- c:\users\chloe\ntuser.dat{3523bb62-e8c6-11de-8a77-00038a000015}.TMContainer00000000000000000002.regtrans-ms
2009-12-14 15:58:39 524288 --sha-w- c:\users\chloe\ntuser.dat{3523bb62-e8c6-11de-8a77-00038a000015}.TMContainer00000000000000000001.regtrans-ms
2009-12-14 15:58:38 65536 --sha-w- c:\users\chloe\ntuser.dat{3523bb62-e8c6-11de-8a77-00038a000015}.TM.blf
2009-12-14 15:55:25 0 ---ha-w- c:\users\chloe\ntuser.dat_TU_42617.LOG2
2009-12-14 15:55:25 0 ---ha-w- c:\users\chloe\ntuser.dat_TU_42617.LOG1
2009-12-14 13:56:52 244224 ----a-w- c:\windows\system32\rastls.dll
2009-12-14 13:56:51 281600 ----a-w- c:\windows\system32\raschap.dll
2009-12-14 13:56:14 378368 ----a-w- c:\windows\system32\winhttp.dll
2009-12-14 13:53:23 411136 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-14 13:53:22 31232 ----a-w- c:\windows\system32\httpapi.dll
2009-12-14 13:53:20 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-08 12:15:36 389180 ----a-w- c:\windows\system32\UCS32P.DLL
2009-12-08 12:15:33 36864 ----a-w- c:\windows\system32\CNQU81.DLL
2009-12-08 12:15:32 745472 ----a-w- c:\windows\system32\CNQA2403.dll
2009-12-08 12:15:32 204800 ----a-w- c:\windows\system32\CNQL2403.dll

==================== Find3M ====================

2010-01-02 20:37:46 351220 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2010-01-02 20:36:18 1101524512 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-01-02 20:33:13 14754512 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-12-09 13:55:02 1007806496 --sha-w- c:\windows\system32\drivers\fidbox(1047).dat
2009-12-08 12:31:26 351220 ---ha-w- c:\windows\system32\drivers\vsconfig(1049).xml
2009-12-08 12:26:23 13433000 --sha-w- c:\windows\system32\drivers\fidbox(1048).idx
2009-12-08 12:18:33 51200 ----a-w- c:\windows\inf\infpub.dat
2009-12-08 12:18:33 143360 ----a-w- c:\windows\inf\infstor.dat
2009-12-08 12:18:32 143360 ----a-w- c:\windows\inf\infstrng.dat
2009-11-21 06:40:20 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34:39 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34:39 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-02 20:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:41:23 2048 ----a-w- c:\windows\system32\tzres.dll
2008-09-11 15:40:50 174 --sha-w- c:\program files\desktop.ini
2008-09-11 15:04:11 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:39:34 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:39:34 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:39:34 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:39:34 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-03-17 23:20:47 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031020080317\index.dat
2008-03-24 09:47:34 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008031720080324\index.dat
2008-03-31 17:24:35 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008032420080331\index.dat
2008-03-31 17:33:31 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008033120080401\index.dat
2008-04-04 11:10:20 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008040420080405\index.dat
2008-04-05 12:59:17 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008040520080406\index.dat
2008-03-06 12:21:56 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
2009-07-29 07:35:23 594673440 --sha-w- c:\windows\system32\drivers\fidbox(1461).dat
2008-04-10 23:16:33 11148064 --sha-w- c:\windows\system32\drivers\fidbox(347).dat
2009-07-03 07:47:30 437642272 --sha-w- c:\windows\system32\drivers\fidbox(547).dat
2007-09-19 00:05:06 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:54:55.16 ===============

Post Edited (panther) : 03-01-2010 21:05:45 GMT



File Attachment :
Attach.zip   2KB (application/x-zip-compressed)
This file has been downloaded 112 time(s).
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-8-2010 3:40 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Sorry we overlooked your request thread panther, and welcome to BG forums. No infection showing here, but let's do a different check to see other files it might show.


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


Download RSIT (random's system information tool) from here to your desktop. Then click on the RSIT.exe to open the RSIT display, and click the Continue button.

If necessary allow it to locate or download a copy of HijackThis as needed.

Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.

RSIT will also create a second log, info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt).

You can break logs into parts and use separate posts here when replying and posting the log files, if needed.

In your next reply also post some details on what you see that suggests the drive is quickly accumulating files please.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-8-2010 10:35 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Hi,

thanks for your reply and the welcome :)

When I go into my Computer the icon showing the C Drive is red and says that it is reaching its capacity. I deleted some restore points using the windows clean up thing which did the trick but then 2 days later it was back in the red again. I went through and deleted lots of documents and music, and also some programs I dont need and I freed up a lot of space, turned my laptop off and then didnt touch it for 2 days, and when I came back it had gone down 2 gb!! Also my laptop runs quite slowly compared to what it used to, sometimes taking about 20 mins to boot up and also 5 or so minutes if not more just to open internet explorer.

Also I can see from the log thing that I have 5 AV programs installed, I only want Zone Alarm as I unistalled the others in the control panel ages ago! Here are the logs requested:

LOG:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:16:32, on 08/01/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Windows\sttray.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Users\Chloe\Desktop\RSIT.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HijackThis\Chloe.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 82.98.86.175 vibepc.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - (no file)
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9641 bytes

======Scheduled tasks folder======

C:\Windows\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - c:\Program Files\Java\jre1.6.0\bin\ssv.dll [2007-09-18 501384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-29 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-29 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2007-03-16 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-29 263280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-04-28 857648]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2007-07-02 138008]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2007-07-02 154392]
"Broadcom Wireless Manager UI"=C:\Windows\system32\WLTRAY.exe [2007-03-21 1548288]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2008-10-24 79136]
"dscactivate"=c:\dell\dsca.exe [2007-07-30 16384]
"ECenter"=c:\dell\E-Center\EULALauncher.exe [2007-03-16 17920]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
"SigmatelSysTrayApp"=C:\Windows\sttray.exe [2007-03-06 303104]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-03-31 982408]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-08-02 122368]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-08-13 177440]
"BlackBerryAutoUpdate"=C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe [2009-07-01 623960]
""= []
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2009-04-11 236016]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-01-30 68856]
"msnmsgr"=C:\Program Files\MSN Messenger\msnmsgr.exe /background []
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2008-10-24 206112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1190134290\ee\AOLSoftware.exe [2006-11-14 50736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
C:\Windows\vsnpstd.exe [2005-10-11 339968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgwlntf]
C:\Windows\system32\avgwlntf.dll [2008-02-03 9216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2007-07-02 204800]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{057c464d-3ff7-11de-8961-806e6f6e6963}]
shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7b609c36-c77d-11dc-ac73-00038a000015}]
shell\AutoRun\command - wd_windows_tools\setup.exe


======File associations======

.js - edit -
.js - open -
.txt - open -

======List of files/folders created in the last 1 months======

2010-01-08 08:14:44 ----D---- C:\rsit
2010-01-02 21:41:21 ----SHD---- C:\Config.Msi
2010-01-02 21:01:28 ----D---- C:\Program Files\Trend Micro
2010-01-02 17:32:17 ----D---- C:\Users\Chloe\AppData\Roaming\Malwarebytes
2010-01-02 17:31:30 ----D---- C:\ProgramData\Malwarebytes
2010-01-02 17:31:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-02 17:08:37 ----D---- C:\Program Files\CCleaner
2009-12-22 11:49:28 ----D---- C:\Users\Chloe\AppData\Roaming\Totally Rad Dirty Pictures
2009-12-21 10:46:47 ----D---- C:\Users\Chloe\AppData\Roaming\ZoomBrowser EX
2009-12-21 10:23:15 ----D---- C:\Program Files\Common Files\Canon
2009-12-20 09:30:46 ----D---- C:\Program Files\uTorrent
2009-12-14 13:56:52 ----A---- C:\Windows\system32\rastls.dll
2009-12-14 13:56:51 ----A---- C:\Windows\system32\raschap.dll
2009-12-14 13:56:14 ----A---- C:\Windows\system32\winhttp.dll
2009-12-14 13:55:26 ----A---- C:\Windows\system32\mshtml.dll
2009-12-14 13:55:19 ----A---- C:\Windows\system32\ieframe.dll
2009-12-14 13:55:15 ----A---- C:\Windows\system32\iertutil.dll
2009-12-14 13:55:14 ----A---- C:\Windows\system32\urlmon.dll
2009-12-14 13:55:12 ----A---- C:\Windows\system32\wininet.dll
2009-12-14 13:55:12 ----A---- C:\Windows\system32\msfeeds.dll
2009-12-14 13:55:11 ----A---- C:\Windows\system32\occache.dll
2009-12-14 13:55:11 ----A---- C:\Windows\system32\iedkcs32.dll
2009-12-14 13:55:08 ----A---- C:\Windows\system32\ieui.dll
2009-12-14 13:55:07 ----A---- C:\Windows\system32\ieUnatt.exe
2009-12-14 13:55:07 ----A---- C:\Windows\system32\iepeers.dll
2009-12-14 13:55:06 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-14 13:55:06 ----A---- C:\Windows\system32\iesysprep.dll
2009-12-14 13:55:05 ----A---- C:\Windows\system32\jsproxy.dll
2009-12-14 13:55:04 ----A---- C:\Windows\system32\msfeedssync.exe
2009-12-14 13:55:04 ----A---- C:\Windows\system32\ie4uinit.exe
2009-12-14 13:55:03 ----A---- C:\Windows\system32\iesetup.dll
2009-12-14 13:55:03 ----A---- C:\Windows\system32\iernonce.dll
2009-12-14 13:53:22 ----A---- C:\Windows\system32\httpapi.dll
2009-12-14 13:53:20 ----A---- C:\Windows\system32\nshhttp.dll

======List of files/folders modified in the last 1 months======

2010-01-08 08:15:39 ----D---- C:\Windows\Prefetch
2010-01-08 08:14:53 ----D---- C:\Windows\Temp
2010-01-08 08:14:11 ----SHD---- C:\System Volume Information
2010-01-08 08:14:06 ----D---- C:\Windows\Internet Logs
2010-01-08 07:51:40 ----D---- C:\Windows\System32
2010-01-08 07:51:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-01-08 07:51:37 ----D---- C:\Windows\inf
2010-01-08 07:20:20 ----D---- C:\Users\Chloe\AppData\Roaming\uTorrent
2010-01-07 19:07:07 ----A---- C:\rollback.ini
2010-01-02 21:47:10 ----SHD---- C:\Windows\Installer
2010-01-02 21:46:47 ----RD---- C:\Program Files
2010-01-02 21:44:28 ----D---- C:\Program Files\Common Files\microsoft shared
2010-01-02 21:41:32 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-02 21:41:31 ----D---- C:\Program Files\SUPERAntiSpyware
2010-01-02 20:33:47 ----D---- C:\Windows\system32\drivers
2010-01-02 20:33:47 ----D---- C:\Windows\Minidump
2010-01-02 20:29:31 ----D---- C:\Windows
2010-01-02 17:31:30 ----HD---- C:\ProgramData
2010-01-01 22:51:08 ----D---- C:\Windows\system32\config
2009-12-31 17:11:05 ----SD---- C:\Windows\Downloaded Program Files
2009-12-31 15:56:58 ----HD---- C:\Program Files\InstallShield Installation Information
2009-12-31 15:56:37 ----D---- C:\Program Files\Canon
2009-12-29 19:54:52 ----D---- C:\Windows\system32\ZoneLabs
2009-12-29 11:19:28 ----D---- C:\Windows\system32\catroot2
2009-12-27 10:44:43 ----D---- C:\Users\Chloe\AppData\Roaming\Apple Computer
2009-12-27 10:34:00 ----D---- C:\ProgramData\Apple
2009-12-22 11:51:06 ----D---- C:\Program Files\Adobe
2009-12-21 11:04:14 ----SD---- C:\Users\Chloe\AppData\Roaming\Microsoft
2009-12-21 10:23:15 ----D---- C:\Program Files\Common Files
2009-12-21 08:51:22 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-12-21 08:31:29 ----D---- C:\ProgramData\Adobe
2009-12-21 08:30:23 ----D---- C:\Users\Chloe\AppData\Roaming\Adobe
2009-12-15 18:31:11 ----D---- C:\Windows\system32\Tasks
2009-12-15 13:34:15 ----D---- C:\Users\Chloe\AppData\Roaming\Canon
2009-12-15 07:22:50 ----D---- C:\Windows\winsxs
2009-12-15 07:20:39 ----D---- C:\Windows\rescache
2009-12-15 07:01:39 ----D---- C:\Windows\system32\catroot
2009-12-15 06:55:01 ----D---- C:\Windows\system32\migration
2009-12-15 06:55:00 ----D---- C:\Program Files\Internet Explorer
2009-12-15 06:54:59 ----D---- C:\Windows\system32\en-US
2009-12-15 06:54:59 ----D---- C:\Program Files\Windows Mail
2009-12-14 16:55:08 ----SD---- C:\ProgramData\Microsoft
2009-12-14 15:55:24 ----SHD---- C:\Boot
2009-12-14 12:57:46 ----D---- C:\Windows\system32\wbem
2009-12-14 12:55:19 ----D---- C:\Windows\Tasks
2009-12-14 12:55:18 ----D---- C:\Windows\system32\spool
2009-12-14 12:55:18 ----D---- C:\Windows\system32\Msdtc
2009-12-14 12:55:18 ----D---- C:\Windows\system32\CodeIntegrity
2009-12-14 12:55:01 ----D---- C:\Users\Chloe\AppData\Roaming\Winamp
2009-12-14 12:54:34 ----D---- C:\Windows\registration

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgClean;AVG7 Clean Driver; C:\Windows\System32\Drivers\avgclean.sys [2008-02-03 10760]
R1 AvgMfx86;AVG Minifilter x86 Resident Driver; C:\Windows\System32\Drivers\avgmfx86.sys [2008-02-03 26952]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2009-03-31 150544]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-01-03 5632]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2009-03-31 293528]
R2 dsunidrv;DellSupport UniDriver; C:\Windows\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2006-11-27 32256]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2006-11-27 43520]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2006-11-27 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-05 8192]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-03-21 534016]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-21 45568]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-19 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-11-03 986624]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2006-11-03 206848]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-07-02 1675776]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\Windows\system32\DRIVERS\RimSerial.sys [2009-01-09 27136]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\Windows\System32\Drivers\RootMdm.sys [2008-01-19 8192]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-19 88576]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-03-06 323584]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-04-28 182456]
R3 wanatw;WAN Miniport (ATW); C:\Windows\system32\DRIVERS\wanatw4.sys [2006-11-01 33588]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-11-03 659968]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-19 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
S2 adfs;adfs; C:\Windows\system32\drivers\adfs.sys []
S3 AvgWFP;AVG7 Firewall Driver x86; C:\Windows\System32\Drivers\avgwfp.sys [2008-03-13 53768]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [2006-10-05 4736]
S3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2006-11-02 200704]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 RimUsb;BlackBerry Smartphone; C:\Windows\System32\Drivers\RimUsb.sys [2008-05-20 22784]
S3 snpstd;Trust Webcam 14823; C:\Windows\system32\DRIVERS\snpstd.sys [2006-05-03 390784]
S3 tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2008-11-07 41984]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 wrssweep;Webroots Volume Access Driver; \??\C:\Program Files\Webroot\Washer\wrssweep.sys [2007-10-03 21832]
S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2007-02-12 277784]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2006-10-23 46640]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-07-09 144712]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Capture Device Service;Capture Device Service; C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe [2006-08-11 200704]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 STacSV;SigmaTel Audio Service; C:\Windows\system32\STacSV.exe [2007-03-06 90112]
R2 wltrysvc;Dell Wireless WLAN Tray Service; C:\Windows\System32\WLTRYSVC.EXE [2007-03-21 24064]
R2 wwEngineSvc;Window Washer Engine; C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-10-03 598856]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-05 386560]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
S2 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-12-06 362992]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2009-04-11 313840]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2009-04-11 170480]
S2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2009-03-31 2404232]
S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-19 70656]
S3 getPlusHelper;@C:\Program Files\NOS\bin\getPlus_Helper.dll,-101; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-17 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-12-06 88560]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2009-04-11 1108464]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe []
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2008-02-20 306432]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 Avg7Alrt;AVG7 Alert Manager Server; C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe [2008-02-03 418816]
S4 Avg7UpdSvc;AVG7 Update Service; C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe [2008-02-03 49664]
S4 AvgCoreSvc;AVG7 Resident Shield Service; C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe [2008-02-03 192512]
S4 AVGEMS;AVG E-mail Scanner; C:\PROGRA~1\Grisoft\AVG7\avgemc.exe [2008-02-03 406528]
S4 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]

-----------------EOF-----------------

INFO:

info.txt logfile of random's system information tool 1.06 2010-01-08 08:16:47

======Uninstall list======

µTorrent-->"C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
Adobe Download Manager-->"C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /Get1
Adobe ExtendScript Toolkit 2-->C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop CS4-->"C:\Program Files\Adobe\Photoshop CS4\unins000.exe"
Adobe Reader 9.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Adobe Setup-->MsiExec.exe /I{8CE08C3C-8FF4-45D9-925E-4F3CE2D7FA7D}
Adobe Setup-->MsiExec.exe /I{B3C02EC1-A7B0-4987-9A43-8789426AAA7D}
Adobe Shockwave Player 11-->C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
AOL Uninstaller (Choose which Products to Remove)-->C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
BlackBerry Desktop Software 5.0-->MsiExec.exe /i{EE59E3BD-6B7D-4BBB-B9CD-20EA7AEF1E10}
BlackBerry Desktop Software 5.0-->MsiExec.exe /I{EE59E3BD-6B7D-4BBB-B9CD-20EA7AEF1E10}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Broadcom Management Programs-->MsiExec.exe /I{C99C0593-3B48-41D9-B42F-6E035B320449}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant HDA D330 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\HXFSETUP.EXE -U -Idel000fz.inf
Dell Support Center-->MsiExec.exe /X{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}
Dell System Customization Wizard-->MsiExec.exe /I{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}
Dell Touchpad-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Dell Wireless WLAN Card-->"C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
DellSupport-->MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Digital Line Detect-->C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
ExtractNow-->"C:\Program Files\ExtractNow\unins000.exe"
FLV Player 2.0 (build 25)-->C:\Program Files\FLV Player\uninst.exe
Google Gmail Notifier-->"C:\Program Files\Google\Gmail Notifier\UninstallGmail.exe"
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
InterVideo DeviceService-->MsiExec.exe /I{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}
iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
MainType 2.1.1-->"C:\Program Files\High-Logic\MainType\unins000.exe"
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MediaDirect-->C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x0009 -cluninstall
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
MobileMe Control Panel-->MsiExec.exe /I{3AC54383-31D1-4907-961B-B12CBB1D0AE8}
Modem Diagnostic Tool-->MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
MSVC80_x86-->MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
OutlookAddinSetup-->MsiExec.exe /I{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}
PC Camera (6005 CIF)-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ABE6EF98-9D69-471F-A52D-CE5E86B84FFC}\setup.exe" -l0x9
QuickSet-->MsiExec.exe /I{7F0C4457-8E64-491B-8D7B-991504365D1E}
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Roxio Media Manager-->MsiExec.exe /X{4D612FB2-1AE7-4E46-9377-35BB2F06A787}
RTC Client API v1.2-->MsiExec.exe /X{44CDBD1B-89FB-4E02-8319-2A4C550F664A}
SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Sonic Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
TuneUp Utilities 2008-->MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
URL Assistant-->regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
User's Guides-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
VC 9.0 Runtime-->MsiExec.exe /I{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}
VC 9.0 Runtime-->MsiExec.exe /I{A040AC77-C1AA-4CC9-8931-9F648AF178F6}
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Window Washer-->C:\Windows\Unwash6.exe
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
ZoneAlarm Security Suite-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

======Hosts File======

82.98.86.175 vibepc.com

======Security center information======

AV: ZoneAlarm Security Suite Antivirus (disabled)
AV: AVG 0.5.519 (outdated)
AV: McAfee VirusScan
FW: McAfee Personal Firewall (disabled)
FW: ZoneAlarm Security Suite Firewall (disabled)
AS: ZoneAlarm Security Suite Anti-Spyware
AS: McAfee VirusScan
AS: AVG Anti-Spyware (disabled) (outdated)
AS: Windows Defender

======System event log======

Computer Name: Chloe-PC
Event Code: 4001
Message: WLAN AutoConfig service has successfully stopped.

Record Number: 1175542
Source Name: Microsoft-Windows-WLAN-AutoConfig
Time Written: 20100108080137.223600-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Chloe-PC
Event Code: 15016
Message: Unable to initialize the security package Kerberos for server side authentication. The data field contains the error number.
Record Number: 1175556
Source Name: Microsoft-Windows-HttpEvent
Time Written: 20100108080439.785495-000
Event Type: Error
User:

Computer Name: Chloe-PC
Event Code: 7000
Message: The adfs service failed to start due to the following error:
The system cannot find the file specified.
Record Number: 1175594
Source Name: Service Control Manager
Time Written: 20100108080615.000000-000
Event Type: Error
User:

Computer Name: Chloe-PC
Event Code: 7009
Message: A timeout was reached (30000 milliseconds) while waiting for the Roxio Hard Drive Watcher 9 service to connect.
Record Number: 1175608
Source Name: Service Control Manager
Time Written: 20100108080615.000000-000
Event Type: Error
User:

Computer Name: Chloe-PC
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
SASKUTIL
Record Number: 1175627
Source Name: Service Control Manager
Time Written: 20100108080820.000000-000
Event Type: Error
User:

=====Application event log=====

Computer Name: Chloe-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-774873819-2361761717-3071640680-1000:
Process 1492 (\Device\HarddiskVolume3\Windows\System32\ZoneLabs\vsmon.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000
Process 1492 (\Device\HarddiskVolume3\Windows\System32\ZoneLabs\vsmon.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000

Record Number: 31869
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100104221043.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Chloe-PC
Event Code: 1002
Message: The program QuickTimePlayer.exe version 7.65.17.80 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 255c Start Time: 01ca8e381772b290 Termination Time: 1728
Record Number: 31913
Source Name: Application Hang
Time Written: 20100105191416.000000-000
Event Type: Error
User:

Computer Name: Chloe-PC
Event Code: 508
Message: Windows (3168) Windows: A request to write to the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb" at offset 73596928 (0x0000000004630000) for 8192 (0x00002000) bytes succeeded, but took an abnormally long time (2266 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.
Record Number: 31918
Source Name: ESENT
Time Written: 20100106093027.000000-000
Event Type: Warning
User:

Computer Name: Chloe-PC
Event Code: 1000
Message: Faulting application iexplore.exe, version 8.0.6001.18865, time stamp 0x4b077416, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000374, fault offset 0x000b015d, process id 0x1058, application start time 0x01ca8f84cbfeaa00.
Record Number: 31930
Source Name: Application Error
Time Written: 20100107103559.000000-000
Event Type: Error
User:

Computer Name: Chloe-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
4 user registry handles leaked from \Registry\User\S-1-5-21-774873819-2361761717-3071640680-1000:
Process 1524 (\Device\HarddiskVolume3\Windows\System32\ZoneLabs\vsmon.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000
Process 1524 (\Device\HarddiskVolume3\Windows\System32\ZoneLabs\vsmon.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000
Process 1032 (\Device\HarddiskVolume3\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000
Process 1032 (\Device\HarddiskVolume3\Windows\System32\wuauclt.exe) has opened key \REGISTRY\USER\S-1-5-21-774873819-2361761717-3071640680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer

Record Number: 31946
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20100108080010.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

=====Security event log=====

Computer Name: Chloe-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Windows\System32\drivers\vsdatant.sys
Record Number: 86539
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100108081630.073495-000
Event Type: Audit Failure
User:

Computer Name: Chloe-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Windows\System32\drivers\vsdatant.sys
Record Number: 86540
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100108081630.167095-000
Event Type: Audit Failure
User:

Computer Name: Chloe-PC
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: CHLOE-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x26c
Process Name: C:\Windows\System32\services.exe

Network Information:
Network Address: -
Port: -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 86541
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100108081801.629895-000
Event Type: Audit Success
User:

Computer Name: Chloe-PC
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-5-18
Account Name: CHLOE-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7

Logon Type: 5

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x26c
Process Name: C:\Windows\System32\services.exe

Network Information:
Workstation Name:
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 86542
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100108081801.629895-000
Event Type: Audit Success
User:

Computer Name: Chloe-PC
Event Code: 4672
Message: Special privileges assigned to new logon.

Subject:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7

Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Record Number: 86543
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20100108081801.629895-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 22 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=1601
"NUMBER_OF_PROCESSORS"=1
"tvdumpflags"=8
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip

-----------------EOF-----------------
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-8-2010 7:29 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
The logs don't reflect the extra data issues. Malwarebytes removed some tough enough rootkit files, so let's see if something isn't creating it's own data files there. Then we need to have you run some uninstallers for the older security softwares still remaining.


To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.

Download ComboFix.exe from here to your desktop, but I would like you to rename the file as you download it (do not download it directly without renaming it - use right click "Save Target/Link As" ). For this, rename the downloading file to 456out.com, then click the renamed 456out.com to run that scan.

Be sure to install the Recovery Console if you are asked to do so. When the scan completes, a text window with your log will open. Please copy and paste that log back here.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-8-2010 10:07 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Hi,

Combofix is bringing up a warning box saying that antivirus are still running and that it can affect my system or the scan if I proceed. I have disabled Zone Alarm but it is saying AVG and McAfee are also running, but I have no details of them in my program list? How do I disable them or shall I just run the scan "at my own risk"?
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-9-2010 2:12 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
ComboFix is reading their status using the WMI, so it isn't actually an indication that the softwares are still installed and active. Go ahead and agree and run the ComboFix scan please.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-9-2010 3:01 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
ComboFix 10-01-04.01 - Chloe 09/01/2010   0:37.1.1 - x86
Microsoft® Windows Vista™ Home Basic   6.0.6001.1.1252.44.1033.18.1013.331 [GMT 0:00]
Running from: c:\users\Chloe\Desktop\456out.com
AV: AVG 0.5.519 *On-access scanning enabled* (Outdated) {41564737-3200-1071-989B-0000E87B4FB1}
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: ZoneAlarm Security Suite Antivirus *On-access scanning enabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Security Suite Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: McAfee VirusScan *enabled* (Updated) {C78B3C70-4777-4742-BB91-9D615CC575E6}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Security Suite Anti-Spyware *enabled* (Updated) {F245A209-1085-48B4-B927-35D56015EC60}
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1738422755-998661840-641317060-500
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-774873819-2361761717-3071640680-500
c:\windows\system32\tmp0_101409523081.bk
c:\windows\system32\tmp0_142698521966.bk
c:\windows\system32\tmp0_1657323018.bk
c:\windows\system32\tmp0_170313440157.bk
c:\windows\system32\tmp0_180500832853.bk
c:\windows\system32\tmp0_285365210604.bk
c:\windows\system32\tmp0_325551439838.bk
c:\windows\system32\tmp0_357023847040.bk
c:\windows\system32\tmp0_384183184982.bk
c:\windows\system32\tmp0_446122672556.bk
c:\windows\system32\tmp0_54744126897.bk
c:\windows\system32\tmp0_58124448552.bk
c:\windows\system32\tmp0_63650385635.bk
c:\windows\system32\tmp0_654069738918.bk
c:\windows\system32\tmp0_6783178039.bk
c:\windows\system32\tmp0_709911597493.bk
c:\windows\system32\tmp0_738755283594.bk
c:\windows\system32\tmp0_792010310305.bk
c:\windows\system32\tmp0_807650106345.bk
c:\windows\system32\tmp0_832264716553.bk
c:\windows\system32\tmp0_855815380242.bk
c:\windows\system32\tmp0_858397496767.bk
c:\windows\system32\tmp0_888766443184.bk
c:\windows\system32\tmp1_141278220358.bk
c:\windows\system32\tmp1_14933793802.bk
c:\windows\system32\tmp1_152037193626.bk
c:\windows\system32\tmp1_213128863021.bk
c:\windows\system32\tmp1_29389622562.bk
c:\windows\system32\tmp1_553284363367.bk
c:\windows\system32\tmp1_755510726092.bk
c:\windows\system32\tmp1_789234280168.bk
c:\windows\system32\tmp1_8776699839.bk
c:\windows\system32\tmp1_92044896789.bk
c:\windows\system32\tmp3_198111262173.bk
c:\windows\system32\tmp3_199320292308.bk
c:\windows\system32\tmp3_251725529135.bk
c:\windows\system32\tmp3_284098757172.bk
c:\windows\system32\tmp3_346113628581.bk
c:\windows\system32\tmp3_357191742348.bk
c:\windows\system32\tmp3_365753397645.bk
c:\windows\system32\tmp3_377358877699.bk
c:\windows\system32\tmp3_393222126047.bk
c:\windows\system32\tmp3_433831261936.bk
c:\windows\system32\tmp3_462289692382.bk
c:\windows\system32\tmp3_491495538824.bk
c:\windows\system32\tmp3_503572640067.bk
c:\windows\system32\tmp3_54328194075.bk
c:\windows\system32\tmp3_567597309987.bk
c:\windows\system32\tmp3_593978888589.bk
c:\windows\system32\tmp3_61037131427.bk
c:\windows\system32\tmp3_613466250658.bk
c:\windows\system32\tmp3_664290335467.bk
c:\windows\system32\tmp3_66863793278.bk
c:\windows\system32\tmp3_772089225537.bk
c:\windows\system32\tmp3_796232524473.bk
c:\windows\system32\tmp3_84869767283.bk
c:\windows\system32\tmp3_878845819535.bk
c:\windows\system32\tmp4_220501526280.bk
c:\windows\system32\tmp4_225972141538.bk
c:\windows\system32\tmp4_23374717497.bk
c:\windows\system32\tmp4_24641145380.bk
c:\windows\system32\tmp4_253607264104.bk
c:\windows\system32\tmp4_352147542318.bk
c:\windows\system32\tmp4_366097440624.bk
c:\windows\system32\tmp4_395308530226.bk
c:\windows\system32\tmp4_429643164489.bk
c:\windows\system32\tmp4_443677402241.bk
c:\windows\system32\tmp4_467202264894.bk
c:\windows\system32\tmp4_471963851339.bk
c:\windows\system32\tmp4_486180172150.bk
c:\windows\system32\tmp4_571431477298.bk
c:\windows\system32\tmp4_583506845805.bk
c:\windows\system32\tmp4_66788170696.bk
c:\windows\system32\tmp4_672174448279.bk
c:\windows\system32\tmp4_697485409501.bk
c:\windows\system32\tmp4_724290282211.bk
c:\windows\system32\tmp4_730738663281.bk
c:\windows\system32\tmp4_808112198046.bk
c:\windows\system32\tmp4_861423731589.bk
c:\windows\system32\tmp4_888845271374.bk
c:\windows\system32\tmp4_91056599609.bk
.
(((((((((((((((((((((((((   Files Created from 2009-12-09 to 2010-01-09  )))))))))))))))))))))))))))))))
.
2010-01-09 00:50 . 2010-01-09 00:50 -------- d-----w- c:\users\Chloe\AppData\Local\temp
2010-01-09 00:50 . 2010-01-09 00:50 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-01-09 00:50 . 2010-01-09 00:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-08 08:14 . 2010-01-08 08:16 -------- d-----w- C:\rsit
2010-01-02 21:01 . 2010-01-02 21:01 -------- d-----w- c:\program files\Trend Micro
2010-01-02 17:32 . 2010-01-02 17:32 -------- d-----w- c:\users\Chloe\AppData\Roaming\Malwarebytes
2010-01-02 17:31 . 2009-12-30 14:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 17:31 . 2010-01-02 17:31 -------- d-----w- c:\programdata\Malwarebytes
2010-01-02 17:31 . 2009-12-30 14:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 17:31 . 2010-01-02 17:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 17:08 . 2010-01-02 17:08 -------- d-----w- c:\program files\CCleaner
2009-12-22 11:49 . 2009-12-22 11:57 -------- d-----w- c:\users\Chloe\AppData\Roaming\Totally Rad Dirty Pictures
2009-12-21 11:03 . 2009-12-21 11:03 -------- d-----w- c:\users\Chloe\AppData\Local\CANON_INC
2009-12-21 10:46 . 2009-12-21 10:46 -------- d-----w- c:\users\Chloe\AppData\Roaming\ZoomBrowser EX
2009-12-21 10:23 . 2009-12-21 10:25 -------- d-----w- c:\program files\Common Files\Canon
2009-12-20 09:30 . 2009-12-20 09:30 -------- d-----w- c:\program files\uTorrent
2009-12-14 13:56 . 2009-10-07 12:41 244224 ----a-w- c:\windows\system32\rastls.dll
2009-12-14 13:56 . 2009-10-07 12:41 281600 ----a-w- c:\windows\system32\raschap.dll
2009-12-14 13:56 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2009-12-14 13:53 . 2009-11-03 19:53 411136 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-14 13:53 . 2009-11-03 22:15 31232 ----a-w- c:\windows\system32\httpapi.dll
2009-12-14 13:53 . 2009-11-03 22:17 24064 ----a-w- c:\windows\system32\nshhttp.dll
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 00:53 . 2008-03-13 20:36 1159977760 --sha-w- c:\windows\system32\drivers\fidbox.dat
2010-01-09 00:46 . 2008-05-29 19:30 -------- d-----w- c:\users\Chloe\AppData\Roaming\uTorrent
2010-01-08 20:15 . 2008-03-13 20:20 351220 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2010-01-08 20:10 . 2008-03-13 20:36 15485840 --sha-w- c:\windows\system32\drivers\fidbox.idx
2010-01-08 10:50 . 2009-10-03 09:00 -------- d-----w- c:\program files\Canon
2010-01-08 10:18 . 2009-12-08 12:38 -------- d-----w- c:\users\Chloe\AppData\Roaming\Canon
2010-01-08 10:18 . 2007-09-18 16:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-02 21:41 . 2008-04-27 13:41 -------- d-----w- c:\users\Chloe\AppData\Roaming\SUPERAntiSpyware.com
2010-01-02 21:41 . 2008-02-20 23:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-02 21:41 . 2008-04-27 13:41 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-27 10:44 . 2007-10-07 12:00 -------- d-----w- c:\users\Chloe\AppData\Roaming\Apple Computer
2009-12-27 10:34 . 2009-12-27 10:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-27 10:34 . 2007-10-07 11:48 -------- d-----w- c:\programdata\Apple
2009-12-21 08:51 . 2009-08-12 21:17 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-15 06:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-14 12:55 . 2008-01-29 14:26 -------- d-----w- c:\users\Chloe\AppData\Roaming\Winamp
2009-12-09 13:55 . 2008-03-13 20:36 1007806496 --sha-w- c:\windows\system32\drivers\fidbox(1047).dat
2009-12-08 12:31 . 2008-03-13 20:20 351220 ---ha-w- c:\windows\system32\drivers\vsconfig(1049).xml
2009-12-08 12:26 . 2008-03-13 20:36 13433000 --sha-w- c:\windows\system32\drivers\fidbox(1048).idx
2009-12-08 07:20 . 2008-06-17 04:49 29964830 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-12-07 15:39 . 2008-03-03 20:53 -------- d-----w- c:\program files\EPSON
2009-11-30 18:42 . 2009-11-30 18:40 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-30 18:42 . 2009-11-30 18:40 -------- d-----w- c:\program files\iTunes
2009-11-30 18:40 . 2009-11-30 18:40 -------- d-----w- c:\program files\iPod
2009-11-30 18:40 . 2007-10-07 11:48 -------- d-----w- c:\program files\Common Files\Apple
2009-11-30 18:34 . 2009-11-30 18:32 -------- d-----w- c:\program files\QuickTime
2009-11-30 17:59 . 2009-11-30 17:59 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-29 10:44 . 2009-11-29 10:45 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb7A5B.tmp.exe
2009-11-27 20:07 . 2009-11-27 20:07 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbF9C7.tmp.exe
2009-11-21 06:40 . 2009-12-14 13:55 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-14 13:55 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-14 13:55 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-14 13:55 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-02 20:42 . 2009-10-04 13:10 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 09:41 . 2009-11-27 08:03 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-17 20:11 . 2007-10-03 20:45 85640 ----a-w- c:\users\Chloe\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-29 07:35 . 2008-03-13 20:36 594673440 --sha-w- c:\windows\System32\drivers\fidbox(1461).dat
2008-04-10 23:16 . 2008-03-13 20:36 11148064 --sha-w- c:\windows\System32\drivers\fidbox(347).dat
2009-07-03 07:47 . 2008-03-13 20:36 437642272 --sha-w- c:\windows\System32\drivers\fidbox(547).dat
2007-09-19 00:05 . 2007-09-18 23:59 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-30 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-02 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-02 154392]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-03-31 982408]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-02 122368]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-07-01 623960]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-04-11 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-9-18 50688]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-9-18 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
2008-02-03 22:05 9216 ----a-w- c:\windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2006-11-14 14:01 50736 ----a-w- c:\program files\Common Files\aol\1190134290\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 16:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 23:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
2005-10-11 19:54 339968 ----a-w- c:\windows\vsnpstd.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe"
"Persistence"=c:\windows\system32\igfxpers.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [05/02/2008 15:14 598856]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [08/08/2009 18:17 722416]
S3 AvgWFP;AVG7 Firewall Driver x86;c:\windows\System32\drivers\avgwfp.sys [03/02/2008 22:05 53768]
S3 wrssweep;Webroots Volume Access Driver;c:\program files\Webroot\Washer\wrSSweep.sys [05/02/2008 15:14 21832]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ    PLA DPS BFE mpssvc
getPlusHelper REG_MULTI_SZ    getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-01-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKU-Default-Run-AVG7_Run - c:\progra~1\Grisoft\AVG7\avgw.exe
HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-Acrobat Assistant 8 - c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
MSConfigStartUp-Adobe Acrobat Speed Launcher - c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
MSConfigStartUp-PWRISOVM - c:\program files\PowerISO\PWRISOVM.EXE
MSConfigStartUp-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-09 00:50
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ... 
 [0] 0x000113A0
 [0] 0x558BF045
scanning hidden autostart entries ...
scanning hidden files ... 
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-774873819-2361761717-3071640680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v9o\UserChoice]
@Denied: (2) (S-1-5-21-774873819-2361761717-3071640680-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 9.0.v9o"
[HKEY_USERS\S-1-5-21-774873819-2361761717-3071640680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v9p\UserChoice]
@Denied: (2) (S-1-5-21-774873819-2361761717-3071640680-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 9.0.v9p"
[HKEY_USERS\S-1-5-21-774873819-2361761717-3071640680-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v9pf\UserChoice]
@Denied: (2) (S-1-5-21-774873819-2361761717-3071640680-1000)
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 9.0.v9pf"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-09  00:57:49
ComboFix-quarantined-files.txt  2010-01-09 00:57
Pre-Run: 11,700,797,440 bytes free
Post-Run: 11,662,987,264 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - 2F23E28AC65A67F1B0F22FB28DA6828E
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-9-2010 4:09 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Some permissions restrictions on some Registry keys at the end of that log, but I read them as Bullguard created/use, and a dialer entry I am beginning to suspect is from some past or current AOL install.

I also think the items ComboFix removed were more due to their names, than actually identified infection files. But all those that are named similar to this:

c:\windows\system32\tmp0_xxxxxxxxxxxx.bk

Something appears to be creating and saving backup files, which could also be very large. Not right sure just what yet.

Go to Start Search, type cmd.exe in the Start Search box. Cmd.exe will appear at the top of the Menu. Rightclick on it and choose "Run as administrator". At the prompt copy/paste the following, pressing Enter after:

dir /s /a "c:\*tmp0_*.bk*.*" > c:\find.txt && notepad c:\find.txt

Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread. If it turns out to be a huge logfile, then just locate some of those similarly-named files from it, and see if you can determine what creates them (right click - select Properties, check the tabs).

Post Edited (Jintan) : 09-01-2010 02:10:09 GMT

Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-9-2010 11:25 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
 Volume in drive C is OS
 Volume Serial Number is E045-CC3D
 Directory of c:\Qoobox\Quarantine\C\Windows\System32
14/04/2008  11:31                68 tmp0_101409523081.bk.vir
01/04/2008  06:14                68 tmp0_142698521966.bk.vir
16/04/2008  17:09                68 tmp0_1657323018.bk.vir
05/04/2008  01:07                68 tmp0_170313440157.bk.vir
15/04/2008  15:41                68 tmp0_180500832853.bk.vir
17/04/2008  07:31                68 tmp0_285365210604.bk.vir
23/04/2008  14:07                68 tmp0_325551439838.bk.vir
03/04/2008  16:45                68 tmp0_357023847040.bk.vir
19/04/2008  08:07                68 tmp0_384183184982.bk.vir
21/04/2008  16:07                68 tmp0_446122672556.bk.vir
10/04/2008  22:46                68 tmp0_54744126897.bk.vir
26/04/2008  23:51                68 tmp0_58124448552.bk.vir
06/04/2008  01:07                68 tmp0_63650385635.bk.vir
10/04/2008  07:25                68 tmp0_654069738918.bk.vir
07/04/2008  00:25                68 tmp0_6783178039.bk.vir
22/04/2008  17:43                68 tmp0_709911597493.bk.vir
26/04/2008  06:41                68 tmp0_738755283594.bk.vir
25/04/2008  07:07                68 tmp0_792010310305.bk.vir
08/04/2008  17:27                68 tmp0_807650106345.bk.vir
17/04/2008  23:54                68 tmp0_832264716553.bk.vir
24/04/2008  18:01                68 tmp0_855815380242.bk.vir
02/04/2008  16:13                68 tmp0_858397496767.bk.vir
03/04/2008  23:12                68 tmp0_888766443184.bk.vir
              23 File(s)          1,564 bytes
     Total Files Listed:
              23 File(s)          1,564 bytes
               0 Dir(s)  11,031,384,064 bytes free
 
The Hard drive seems to be filling up less quickly now, but is still going down? I'm rubbish with computers  so I don't know whether this is because its normal to do so or whether there is still something wrong. Just so you have some more insight :)
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-10-2010 12:27 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Let's check one of those files to see if we can ID it.

Make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"

Then just go here, press new topic, fill in the needed details and just give a link to your post back here (see the "Instructions for uploading files" there for help, if needed). Then press the browse button and then navigate to & select the following file on your computer.

c:\Qoobox\Quarantine\C\Windows\System32\68 tmp0_101409523081.bk.vir

You DO NOT need to be a member to upload, anybody can upload the files. You will not be able to see the file once uploaded.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-10-2010 12:44 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
All done Jintan
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-10-2010 2:02 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Just included these strings:

perfmonss.exe=2.0.0.4
wmiprves.exe=2.0.1.110
discover.exe=2.0.0.32

Not quite sure what creates those files. Seems like files and version numbers, but "perfmonss.exe" has one too many "s"'s in it.

A web search of that file name and that number leads to a uTorrent forum page, where someone locates a performance monitor log that includes the info in your files, but not sure it was uTorrent related.


Go to Start > Run and type:

cmd.exe

and ok. At the prompt type or copy/paste each of the following, pressing Enter after each:

dir /s /a "c:\*perfmons*.*" > c:\find.txt && notepad c:\find.txt

Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread please.

Once that Notepad textbox opens, also click at the prompt in the still open command console window and type exit to close that.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-10-2010 2:22 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Won't let me perform the search, is saying access denied?
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-10-2010 5:19 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Darn, I don't want to add delays to our work here, but what gave you access denied please? Opening the command window, or running that command line? Maybe it was my providing XP steps, and not Vista. Try this please:


Go to Start Search, type cmd.exe in the Start Search box. Cmd.exe will appear at the top of the Menu. Rightclick on it and choose "Run as administrator". At the prompt copy/paste the following, pressing Enter after:

dir /s /a "c:\*perfmons*.*" > c:\find.txt && notepad c:\find.txt

Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread.
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-10-2010 11:02 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Volume in drive C is OS
Volume Serial Number is E045-CC3D

Directory of c:\Windows\inf\.NETFramework

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:22 1,406,108 corperfmonsymbols.ini
2 File(s) 1,412,175 bytes

Directory of c:\Windows\inf\.NETFramework\0000

18/09/2006 21:32 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\inf\.NETFramework\0409

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs

02/11/2006 11:19 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16386_none_ce9b7ddbcb9fa3ba
22/07/2009 12:58 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16720_none_ce96043fcba4732e
22/07/2009 12:58 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.20883_none_b7ce1ae3e546b821
11/09/2008 14:19 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18000_none_ce6fff97cbf74c86
22/07/2009 12:57 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18111_none_ce70e8f5cbf67fcf
22/07/2009 12:57 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.22230_none_b7a55991e59bf8e2
24/09/2009 01:24 <DIR> x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6002.18005_none_ce4b84d3cc48e09a
0 File(s) 0 bytes

Directory of c:\Windows\winsxs\Manifests

02/11/2006 10:11 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16386_none_ce9b7ddbcb9fa3ba.manifest
27/07/2008 23:18 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16720_none_ce96043fcba4732e.manifest
27/07/2008 23:21 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.20883_none_b7ce1ae3e546b821.manifest
18/01/2008 23:09 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18000_none_ce6fff97cbf74c86.manifest
27/07/2008 23:43 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18111_none_ce70e8f5cbf67fcf.manifest
27/07/2008 23:29 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.22230_none_b7a55991e59bf8e2.manifest
10/04/2009 23:17 4,351 x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6002.18005_none_ce4b84d3cc48e09a.manifest
7 File(s) 30,457 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16386_en-us_014bf45395655ea8

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.16720_en-us_0186d9b7953a1394

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6000.20883_en-us_01d297d8ae85a709

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18000_en-us_0382b64f92506f7c

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.18111_en-us_0378e8939257a1eb

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6001.22230_en-us_03ebe53cab866040

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_microsoft-windows-n..xcorecomp.resources_31bf3856ad364e35_6.0.6002.18005_en-us_056e2f5b8f723ac8

02/11/2006 12:38 36 corperfmonsymbols_D.ini
1 File(s) 36 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16386_none_ce9b7ddbcb9fa3ba

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
18/09/2006 21:32 1,508,068 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,514,171 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.16720_none_ce96043fcba4732e

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:25 1,406,108 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,412,211 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6000.20883_none_b7ce1ae3e546b821

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:19 1,406,108 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,412,211 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18000_none_ce6fff97cbf74c86

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
05/01/2008 11:26 1,507,910 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,514,013 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.18111_none_ce70e8f5cbf67fcf

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:22 1,406,108 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,412,211 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6001.22230_none_b7a55991e59bf8e2

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:23 1,406,108 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,412,211 bytes

Directory of c:\Windows\winsxs\x86_netfx-corperfmonsymbols_b03f5f7f11d50a3a_6.0.6002.18005_none_ce4b84d3cc48e09a

18/09/2006 21:32 6,067 CORPerfMonSymbols.h
16/06/2008 22:19 1,406,108 corperfmonsymbols.ini
18/09/2006 21:32 36 corperfmonsymbols_D.ini
3 File(s) 1,412,211 bytes

Total Files Listed:
39 File(s) 11,532,195 bytes
7 Dir(s) 10,242,342,912 bytes free
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-10-2010 6:27 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Good, you got it. Nothing in that that suggests these other unusual file creations though. Has the effect stopped now?
Back to Top
 

panther
New Member


Date Joined Jan 2010
Total Posts : 10
 
   Posted 1-10-2010 11:50 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
Hi,
 
Yes I still have the problem,  roughly in the past 5 days my hard drive has increased by about 6 GB. Apart from the programmes that you have asked me to install and also a small program for my camera (400 KB) I have not added anything or created any files.
 
My partner uses my laptop to work on his pictures, but these are all stored on his memory stick, he never saves to my laptop. Coincedentally this morning when he tried to access his stick on Computer, the icon was showing as blank (not named as his stick is, just removable storage device) and was blank, saying "The request could not be performed due to an I O device error". He paniced because he thought he had lost everything but after we ejected it a few times is registered it and he could access everything. I don't know whether either of these things make any difference?
 
I only really use my laptop for the internet and the occasional document, listening to music and storing pictures and as I said my partner uses it for image manipulation and documents but always saves on his sticks so I don't know whether these things do take up space and whether I am over reacting to the problem?
 
Thank you for all your help with this, it's frustrating that everything doesn't reflect what is happening!
 
 
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 1-11-2010 7:02 (GMT +2)    Quote: Hard drive keeps filling up!Alert an admin about: Hard drive keeps filling up!
I am leaning towards your torrent software being responsible for this issue. I have had request threads in the past with a similar problem, and in those it was some altered Limewire swarm file saving method.

One other possible culprit is Zone Alarm, as it can save logs of it's monitoring that can stack up pretty quickly.
Back to Top
 
New Topic Post reply to : Hard drive keeps filling up! Printable version of : Hard drive keeps filling up!
 
Forum Information
Currently it is Thursday, September 02, 2010 10:24 PM (GMT +2)
There are a total of 79.571 posts in 17.981 threads.
In the last 3 days there were 4 new threads and 20 reply posts. View Active Threads
Who's Online
This forum has 32134 registered members. Please welcome our newest member, goodlooking.
35 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Material Handling Equipment (0)02-09-2010 17:50:50 (aayushinfo56)
Beta testers for our latest product: Internet Security 10 - win an HTC Desire! (5)02-09-2010 16:56:21 (x ZauX x)
How to Remove Trojan.Gen? (10)02-09-2010 10:33:47 (NooBRuLz)
My gaming experience was worse with this (4)02-09-2010 09:07:51 (jesso2000)
Redirected to different sites from links on Google (4)02-09-2010 05:11:45 (Rabnud)