![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jul 2009
Location: Scotland
Posts: 3
OS: XP Home (ver 2002 SP3)
|
Windows explorer problem - Malware or corrupt windows files?
Hi - hope you can help with my pc.
Have been putting up with the error message "Windows Explorer has encountered a problem and needs to close" message for a while now. When Googling the error message I came across your excellent site - hope you can help sort this out. The error message comes up every now and then when I try and get into windows explorer, either from the desktop shortcut, or from my documents. The details in the error signature part of the message lists the following: AppName: explorer.exe AppVer: 6.0.2900.5512 ModName: explorer.exe ModVer: 6.0.2900.5512 Offset: 00011900 When I click on the debug option all my icons on the desktop disappear momentarily, then re-appear. I'm not sure if this could be down to Malware of some sort or perhaps a corrupt windows file somewhere. I'm using Kaspersky Internet Suite 2009 (ver 8.0.0.506) and Ashampoo Antispyware 2 Guard (ver 2.05) - both of which are updated regularly. Neither have shown anything untoward. My dds.txt file is: DDS (Ver_09-06-26.01) - NTFSx86 Run by Colin at 8:32:24.46 on 21/07/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2047.1286 [GMT 1:00] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\svchost.exe -k bthsvcs C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Trusteer\Rapport\bin\RapportService.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Logitech\iTouch\iTouch.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\oodtray.exe C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe C:\Program Files\Kontiki\KHost.exe C:\WINDOWS\system32\CTHELPER.EXE C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe C:\Program Files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\Program Files\Sitecom\Bluetooth Software\BTTray.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\HPZipm12.exe C:\Documents and Settings\Colin\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.virginmedia.com uSearch Page = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR uSearch Bar = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR uURLSearchHooks: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFre0.dll BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFre0.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFre0.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [kdx] c:\program files\kontiki\KHost.exe -all uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" mRun: [SBDrvDet] c:\program files\creative\sb drive det\SBDrvDet.exe /r mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe mRun: [DeviceDiscovery] c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe mRun: [CTSysVol] c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe /r mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [OODefragTray] c:\windows\system32\oodtray.exe mRun: [CTxfiHlp] CTXFIHLP.EXE mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe mRun: [Launch LGDCore] "c:\program files\common files\logitech\g-series software\LGDCore.exe" /SHOWHIDE mRun: [OSSelectorReinstall] c:\program files\common files\acronis\acronis disk director\oss_reinstall.exe mRun: [HPWS myPrintMileage Agent] c:\program files\hewlett-packard\hp deskjet 1280\toolbox\mpm.exe mRun: [kdx] "c:\program files\kontiki\KHost.exe" -all mRun: [CTHelper] CTHELPER.EXE mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe mRun: [Broadbandadvisor.exe] "c:\program files\virgin broadband\advisor\Broadbandadvisor.exe" /AUTORUN mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler mRun: [Name of App] c:\program files\samsung\fw liveupdate\FWManager.exe r mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: ['Ashampoo AntiSpyWare 2 Guard'] c:\program files\ashampoo\ashampoo antispyware 2\AntiSpyWare2Guard.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\sitecom\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm IE: Download All Links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: Send To &Bluetooth - c:\program files\sitecom\bluetooth software\btsendto_ie_ctx.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\sitecom\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.8.110.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - Eudora's Shell Extension SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\colin\applic~1\mozilla\firefox\profiles\e9ior684.oor hoose profile\ FF - component: c:\documents and settings\colin\application data\idm\idmmzcc3\components\idmmzcc.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\NPAbacheck.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npdeploytk.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npdivx32.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npLegitCheckPlugin.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npnul32.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nppbss.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nppdf32.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nppl3260.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin2.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin3.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin4.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin5.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin6.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npqtplugin7.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nprjplug.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\nprpjplug.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npsnapfish.dll FF - plugin: c:\progra~1\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAbacheck.dll FF - plugin: c:\program files\mozilla firefox\plugins\nppbss.dll FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\drivers\snman380.sys [2009-4-21 134272] R0 tdrpman174;Acronis Try&Decide and Restore Points filter (build 174);c:\windows\system32\drivers\tdrpm174.sys [2009-4-21 971552] R1 klif;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2008-7-18 226832] R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2009-2-26 57320] R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2009-2-26 239336] R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;c:\program files\ashampoo\ashampoo antispyware 2\AntiSpyWareService.exe [2008-10-29 749400] R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007-9-11 124832] R2 avp;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe -r --> c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe -r [?] R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [2008-7-24 15896] R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2009-6-1 664808] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2008-7-24 99352] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2008-7-24 555032] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2008-7-24 566296] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592] S2 gupdate1c9ad364d76f290;Google Update Service (gupdate1c9ad364d76f290);c:\program files\google\update\GoogleUpdate.exe [2009-3-25 133104] S2 Symantec Core LC;Symantec Core LC;"c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe" --> c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [?] S3 ALSysIO;ALSysIO;c:\docume~1\colin\locals~1\temp\ALSysIO.sys [2009-7-15 13832] S3 ASNDIS5;ASNDIS5 Protocol Driver;c:\windows\system32\ASNDIS5.sys [2006-11-6 16269] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2008-7-24 99352] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2008-7-24 555032] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2008-7-24 100888] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2008-7-24 100888] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2008-7-24 566296] S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2007-3-20 14095] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064] S4 iteraid;iteraid; [x] S4 Si3112r;Si3112r; [x] S4 viasraid;viasraid; [x] =============== Created Last 30 ================ 2009-07-17 19:55 <DIR> --d----- c:\program files\Trend Micro 2009-07-15 09:27 <DIR> -cd----- c:\docume~1\alluse~1\applic~1\{81D4BDA8-1F33-4633-B176-8A7E942ABDE1} 2009-07-14 16:45 <DIR> --d----- c:\program files\RivaTuner v2.24 2009-07-14 12:47 <DIR> --d----- c:\docume~1\colin\applic~1\Xfire 2009-07-14 12:47 <DIR> --d----- c:\program files\Xfire 2009-07-14 11:40 4,096 a------- c:\windows\system32\crash 2009-07-13 18:21 189,104 a------- c:\windows\system32\PnkBstrB.xtr 2009-07-13 17:28 <DIR> --d----- c:\program files\Activision 2009-07-08 00:56 41,808 a------- c:\windows\system32\xfcodec.dll 2009-07-07 13:47 <DIR> --dsh--- c:\documents and settings\colin\IECompatCache 2009-07-01 17:19 <DIR> --d----- c:\docume~1\colin\applic~1\Flickr 2009-07-01 17:17 <DIR> --d----- c:\program files\Flickr Uploadr ==================== Find3M ==================== 2009-07-20 19:31 606,004,256 a--sh--- c:\windows\system32\drivers\fidbox.dat 2009-07-20 19:31 8,384,032 a--sh--- c:\windows\system32\drivers\fidbox2.dat 2009-07-20 19:31 8,123,468 a--sh--- c:\windows\system32\drivers\fidbox.idx 2009-07-20 19:31 790,208 a--sh--- c:\windows\system32\drivers\fidbox2.idx 2009-07-20 19:29 189,104 a------- c:\windows\system32\PnkBstrB.exe 2009-07-20 18:29 139,584 a------- c:\windows\system32\drivers\PnkBstrK.sys 2009-07-13 18:14 75,064 a------- c:\windows\system32\PnkBstrA.exe 2009-07-13 17:42 22,328 a------- c:\docume~1\colin\applic~1\PnkBstrK.sys 2009-06-17 12:09 410,984 a------- c:\windows\system32\deploytk.dll 2009-06-16 15:36 119,808 a------- c:\windows\system32\t2embed.dll 2009-06-16 15:36 81,920 a------- c:\windows\system32\fontsub.dll 2009-06-03 20:09 1,291,264 a------- c:\windows\system32\quartz.dll 2009-05-25 00:24 350,208 -------- c:\windows\system32\mssph.dll 2009-05-13 06:15 915,456 a------- c:\windows\system32\wininet.dll 2009-05-12 15:12 26,144 a------- c:\windows\system32\spupdsvc.exe 2009-05-07 16:32 345,600 a------- c:\windows\system32\localspl.dll 2009-04-28 06:12 11,845,632 a------- c:\windows\system32\atioglxx.dll 2009-04-28 05:41 442,368 a------- c:\windows\system32\ATIDEMGX.dll 2009-04-28 05:40 325,120 a------- c:\windows\system32\ati2dvag.dll 2009-04-28 05:32 290,816 a------- c:\windows\system32\atiok3x2.dll 2009-04-28 05:32 204,800 a------- c:\windows\system32\atipdlxx.dll 2009-04-28 05:31 155,648 a------- c:\windows\system32\Oemdspif.dll 2009-04-28 05:31 26,112 a------- c:\windows\system32\Ati2mdxx.exe 2009-04-28 05:31 43,520 a------- c:\windows\system32\ati2edxx.dll 2009-04-28 05:31 155,648 a------- c:\windows\system32\ati2evxx.dll 2009-04-28 05:30 602,112 a------- c:\windows\system32\ati2evxx.exe 2009-04-28 05:28 53,248 a------- c:\windows\system32\ATIDDC.DLL 2009-04-28 05:21 3,818,272 a------- c:\windows\system32\ati3duag.dll 2009-04-28 05:08 2,670,720 a------- c:\windows\system32\ativvaxx.dll 2009-04-28 04:58 307,200 a------- c:\windows\system32\atiiiexx.dll 2009-04-28 04:55 49,664 a------- c:\windows\system32\amdpcom32.dll 2009-04-28 04:51 475,136 a------- c:\windows\system32\atikvmag.dll 2009-04-28 04:50 126,976 a------- c:\windows\system32\atiadlxx.dll 2009-04-28 04:49 17,408 a------- c:\windows\system32\atitvo32.dll 2009-04-28 04:44 626,688 a------- c:\windows\system32\ati2cqag.dll 2009-04-28 02:58 45,056 a------- c:\windows\system32\aticalrt.dll 2009-04-28 02:58 45,056 a------- c:\windows\system32\aticalcl.dll 2009-04-28 02:56 3,227,648 a------- c:\windows\system32\aticaldd.dll 2009-04-27 21:20 593,920 -------- c:\windows\system32\ati2sgag.exe 2009-04-23 22:29 189,051 a------- c:\windows\system32\atiicdxx.dat 2009-02-16 18:28 170 a------- c:\program files\Install.Log 2009-01-29 16:41 2,788,800 a------- c:\program files\FLV PlayerFCSetup.exe 2008-08-26 09:31 1,570,816 a------- c:\docume~1\colin\applic~1\tsdnwin.dll 2006-12-20 17:08 630,784 a------- c:\documents and settings\colin\GoToAssist_chat2way__317_en.exe 2007-07-27 16:30 5 a--sh--- c:\windows\system32\acaddadc2_d.dll 2008-07-30 19:01 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008073020080731\index.dat ============= FINISH: 8:33:02.78 =============== I have attached my ark.txt and attach.txt files as requested. Hope you can help. Thanks, Colin |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#4 (permalink) |
|
Moderator, Analyst, Security Team
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP
|
Re: Windows explorer problem - Malware or corrupt windows files?
Sorry we missed you, but the forum is overwhelmed with requests for assistance, and we're simply not able to get to everyone.
Surf Safely, and Think Prevention! This topic is closed at users request. |
|
|
![]() |
| Thread Tools | |
|
|