Seite 1 von 3 123 LetzteLetzte
Ergebnis 1 bis 10 von 25

Thema: Taskbar and Icons gone, Log posted

  1. #1
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Taskbar and Icons gone, Log posted

    I'm new and I have completely no knowledge on fixing big problems as these. >.<
    Below the description is my HijackThis Log.

    I started my laptop WindowsXP today and it started freezing a lot.
    I have been aware of viruses on my laptop, but I wasn't sure how to get rid of them.
    So I restarted the computer and to find that my taskbar and icons have disappeared. I can still open programs through Taskbar Manager. I've already tried typing in explorer.exe but led to a pop-up saying that "Windows cannot find explorer.exe". And every once in a while, when i try to open something else, it says svchost.exe cannot be found. I tried to restart it using Safe Mode and that didn't help either. And every time I turn on the computer, the viruses I quarantined with Zone Alarm or deleted comes back within a few days. In fact, new viruses get into my laptop everytime I start up the laptop. I haven't downloaded anything at all for the past two months. The laptop restarts by itself now. O.O Someone please help.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:33:56 PM, on 1/8/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\TEMP\xuqE.tmp
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\taskmgr.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.h...s=PTB&M=MX6427
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O20 - Winlogon Notify: gadfjh - C:\WINDOWS\SYSTEM32\gadfjh.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
    O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 7074 bytes

  2. #2
    Moderator (global) Team-Mitglied Avatar von Jintan
    Registriert seit
    25.11.2006
    Beiträge
    6.369

    Re: Taskbar and Icons gone, Log posted

    Welcome to HijackThis.de jrockfanatic,

    Infection showing there. Let's get more details to work from then start some repairs. If necessary to complete them try rebooting into Safe Mode with Networking (at startup tap the F8 key about once per second and select that from the list). You can also download the file, then use Task Manager - File - New Task as you tried with explorer.exe to run the scan.

    To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


    Download RSIT (random's system information tool) from here to your desktop, then click on the RSIT.exe to start the scan.

    If necessary allow it to locate or download a copy of HijackThis as needed.

    Once the scan completes a textbox will open - copy/paste those contents here for review please. The log can also be found at C:\rsit\log.txt.

    RSIT will also create a second log, info.txt, which will be minimized to your taskbar. Post that here as well please (it will also be stored at C:\rsit\info.txt).

    You can break logs into parts and use separate posts here when replying and posting the log files, if needed.
    Lebe den Tag!

    Jintan - Die Marke, bei der alles stimmt!

  3. #3
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    heres the log

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Owner at 2009-01-09 15:49:04
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 47 GB (68%) free of 69 GB
    Total RAM: 958 MB (48% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:49:46 PM, on 1/9/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Owner\Desktop\RSIT.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\Owner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.h...s=PTB&M=MX6427
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O20 - Winlogon Notify: gadfjh - C:\WINDOWS\SYSTEM32\gadfjh.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
    O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    --
    End of file - 7045 bytes

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
    HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-10 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
    CBrowserHelperObject Object - c:\windows\system32\BAE.dll [2006-01-31 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-10 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-10 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
    HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion \Run]
    "RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2005-01-12 32768]
    "SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-11-05 98394]
    "SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-11-05 688218]
    "Reminder"=C:\WINDOWS\Creator\Remind_XP.exe [2005-02-25 966656]
    "Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE [2002-09-13 212992]
    "ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-04-28 344064]
    "Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY []
    "MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall []
    "ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-07-09 919016]
    "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-06-29 98304]
    "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
    "hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
    "WinampAgent"=C:\Program Files\Winamp\winampa.exe []
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-10 136600]
    "UserFaultCheck"=C:\WINDOWS\system32\dumprep 0 -u []

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Run]
    "Power2GoExpress"= []
    "PowerBar"= []
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    BigFix.lnk - C:\Program Files\BigFix\bigfix.exe
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Documents and Settings\Owner\Start Menu\Programs\Startup
    OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2008-09-23 143360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gadfjh]
    C:\WINDOWS\system32\gadfjh.dll [2009-01-08 16896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot \Minimal\Hpx07.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot \network\Hpx07.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot \network\vsmon]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion \Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion \Policies\explorer]
    "AllowLegacyWebView"=
    "AllowUnhashedWebView"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda ccess\parameters\firewallpolicy\standardprofile\authorizedap plications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.e xe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
    "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
    "C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
    "C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
    "C:\Program Files\Common Files\AOL\1151644055\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1151644055\EE\AOLServiceHost.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "E:\setup\HPZNUI01.EXE"="E:\setup\HPZNUI01.EXE:*:Enabled:hpz nui01.exe"
    "E:\setup\HPONICIFS01.EXE"="E:\setup\HPONICIFS01.EXE:*:Enabl ed:hponicifs01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\WINDOWS\TEMP\BN6F.tmp"="C:\WINDOWS\TEMP\BN6F.tmp:*:Enabl ed:EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN4.tmp"="C:\WINDOWS\TEMP\BN4.tmp:*:Enabled :EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN2.tmp"="C:\WINDOWS\TEMP\BN2.tmp:*:Enabled :EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN3.tmp"="C:\WINDOWS\TEMP\BN3.tmp:*:Enabled :EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN5.tmp"="C:\WINDOWS\TEMP\BN5.tmp:*:Enabled :EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN7.tmp"="C:\WINDOWS\TEMP\BN7.tmp:*:Enabled :EMOTIONS_EXECUTABLE"
    "C:\WINDOWS\TEMP\BN8.tmp"="C:\WINDOWS\TEMP\BN8.tmp:*:Enabled :EMOTIONS_EXECUTABLE"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\shareda ccess\parameters\firewallpolicy\domainprofile\authorizedappl ications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.e xe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ explorer\mountpoints2\{5fbfba74-42ba-11db-86ce-00038a000015}]
    shell\Setup\command - setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\ explorer\mountpoints2\{d97c9738-29bf-11db-8645-00038a000015}]
    shell\Setup\command - F:\setup.exe


    ======List of files/folders created in the last 1 months======

    2009-01-09 15:49:04 ----D---- C:\rsit
    2009-01-08 16:50:02 ----D---- C:\Program Files\Trend Micro
    2009-01-07 15:26:10 ----A---- C:\WINDOWS\system32\gadfjh32.dll
    2009-01-06 20:28:54 ----A---- C:\WINDOWS\system32\gadfjh.dll
    2008-12-30 10:28:14 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-12-30 10:28:14 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-12-30 10:28:14 ----A---- C:\WINDOWS\system32\java.exe

    ======List of files/folders modified in the last 1 months======

    2009-01-09 15:49:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2009-01-09 15:49:27 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-01-09 15:49:21 ----A---- C:\WINDOWS\system32\svchost.exe
    2009-01-09 15:43:51 ----D---- C:\Program Files\Mozilla Firefox
    2009-01-09 15:37:30 ----D---- C:\WINDOWS\system32
    2009-01-09 15:37:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-01-09 15:36:46 ----D---- C:\WINDOWS\Temp
    2009-01-09 15:34:13 ----D---- C:\WINDOWS
    2009-01-08 23:44:00 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-01-08 22:41:36 ----D---- C:\Documents and Settings\Owner\Application Data\HPAppData
    2009-01-08 16:50:02 ----RD---- C:\Program Files
    2009-01-08 16:40:53 ----D---- C:\WINDOWS\Internet Logs
    2009-01-08 16:28:50 ----D---- C:\WINDOWS\system32\drivers
    2009-01-07 21:00:33 ----D---- C:\WINDOWS\Prefetch
    2009-01-07 20:50:48 ----A---- C:\WINDOWS\ntbtlog.txt
    2009-01-07 20:01:06 ----A---- C:\rollback.ini
    2009-01-07 15:40:02 ----D---- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
    2009-01-07 15:39:43 ----A---- C:\WINDOWS\win.ini
    2009-01-06 20:28:23 ----D---- C:\WINDOWS\system32\ZoneLabs
    2009-01-03 14:23:47 ----SHD---- C:\WINDOWS\Installer
    2008-12-30 10:28:20 ----HD---- C:\Config.Msi
    2008-12-30 10:28:10 ----D---- C:\Program Files\Java
    2008-12-29 20:37:07 ----D---- C:\WINDOWS\WinSxS
    2008-12-26 19:13:46 ----RSD---- C:\WINDOWS\Fonts
    2008-12-26 18:57:50 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-12-18 15:56:16 ----D---- C:\Program Files\Winamp
    2008-12-17 20:30:52 ----D---- C:\Documents and Settings\Owner\Application Data\SoundSpectrum
    2008-12-17 18:29:21 ----HD---- C:\WINDOWS\inf
    2008-12-17 18:25:31 ----D---- C:\WINDOWS\ie7updates
    2008-12-17 18:13:43 ----HD---- C:\WINDOWS\$hf_mig$
    2008-12-13 00:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-07 35840]
    R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2007-03-07 9336]
    R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2007-03-07 9464]
    R1 KLIF;KLIF; C:\WINDOWS\system32\DRIVERS\klif.sys [2007-07-19 127768]
    R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-07-09 394952]
    R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2006-06-29 17801]
    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-16 13059]
    R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-09-23 3331072]
    R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-02-11 371712]
    R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camc6aud.sys [2005-04-20 38016]
    R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2005-04-20 350080]
    R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
    R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-01-25 1038208]
    R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-01-25 200576]
    R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
    R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-11-05 185824]
    R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-09-21 162432]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-01-25 703616]
    S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 42752]
    S2 npkcrypt;npkcrypt; \??\C:\Nexon\MapleStory\npkcrypt.sys []
    S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
    S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\system32\DRIVERS\mxnic.sys [2001-08-17 19968]
    S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
    S3 StillCam;Still Serial Digital Camera Driver; C:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
    S3 TIEHDUSB;TIEHDUSB; C:\WINDOWS\system32\drivers\tiehdusb.sys [2008-05-01 49536]
    S3 TSP;TSP; \??\C:\WINDOWS\system32\drivers\klif.sys []
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2005-04-18 230912]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-09-23 581632]
    R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
    R2 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-10 152984]
    R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2009-01-09 14336]
    R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2009-01-09 14336]
    R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2006-06-29 172032]
    R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
    R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\wltrysvc.exe [2005-02-17 65536]
    R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
    S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-09-23 593920]
    S2 FCI;FCI; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
    S2 ICF;ICF; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.e xe [2007-10-24 33800]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2009-01-09 14336]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]

    -----------------EOF-----------------

  4. #4
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    and here's the info

    info.txt logfile of random's system information tool 1.05 2009-01-09 15:50:00

    ======Uninstall list======

    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
    7-Zip 4.58 beta-->"C:\Documents and Settings\Owner\My Documents\Avi Art\7-Zip\Uninstall.exe"
    Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
    Adobe Reader Japanese Fonts-->MsiExec.exe /I{AC76BA86-7AD7-5760-0000-705000000001}
    Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
    ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,Lau nchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_Run DLL@16 -force_restart -flags:0x2010001 -inf_classISPLAY -clean
    BigFix-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\BigFix\Uninst.isu" -c"C:\Program Files\BigFix\Lib\UninstallHelper.dll"
    Broadcom 802.11 Network Adapter-->C:\WINDOWS\system32\BCMWLU00.exe verbose
    Browser Address Error Redirector-->regsvr32 /u /s "c:\windows\system32\BAE.dll"
    ccff7_screensaver-->C:\WINDOWS\system32\ccff7_screensaver.scr /u
    Cessna Private Pilot Demo Version 2.0a-->C:\CessnaMM\PPilotCD\UNWISE.EXE C:\CessnaMM\PPilotCD\INSTALL.LOG
    Conexant AC-Link Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO\HXFSETUP.EXE -U -Iqta0300a.INF
    DIRGE of CERBERUS -Final Fantasy VII- ?????????-->C:\WINDOWS\system32\DIRGE of CERBERUS -Final Fantasy VII-.scr /u
    DVD Solution-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,Lau nchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
    FFXIII ScreenSaver v2-->"C:\WINDOWS\Final Fantasy XIII\uninstall FFXIII_S.exe"
    Final Fantasy VII Advent Children?????????-->C:\WINDOWS\Final Fantasy VII Advent Children.scr /u
    Final Fantasy X-2?????????-->C:\WINDOWS\Final Fantasy X-2.scr /u
    FLV Player 2.0, build 23-->C:\Documents and Settings\Owner\My Documents\Avi Art\FLV Player\uninst.exe
    gtw_logo-->C:\WINDOWS\system32\gtw_logo.scr /UNINSTALL "C:\WINDOWS\system32\gtw_logo.log"
    HijackThis 2.0.2-->"C:\Documents and Settings\Daddy\My Documents\HijackThis.exe" /uninstall
    Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
    Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    HP Customer Participation Program 10.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
    HP Imaging Device Functions 10.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
    HP Officejet J6400 Series-->C:\Program Files\HP\Digital Imaging\{7DCF7BBA-39A9-4e27-9154-F57BCED90CBF}\setup\hpzscr01.exe -datfile hpwscr14.dat -forcereboot
    HP Photosmart Essential 2.5-->C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
    HP Smart Web Printing-->C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
    HP Solution Center 10.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
    HP Update-->MsiExec.exe /X{11B83AD3-7A46-4C2E-A568-9505981D4C6F}
    IrfanView (remove only)-->C:\Documents and Settings\Owner\My Documents\Avi Art\IrfanView\iv_uninstall.exe
    J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
    Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe "
    Microsoft Digital Image Starter Edition 2006-->"C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=11
    Microsoft Excel 2000 Session 1 -->C:\WINDOWS\lkunins2.exe -uSplash.ini
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuni nst\spuninst.exe"
    Microsoft Money 2006-->"C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spu ninst\spuninst.exe"
    Microsoft Office Standard Edition 2003-->MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe "
    Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
    Mozilla Firefox (2.0.0.20)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Mozilla Thunderbird (1.5)-->C:\Program Files\Mozilla Thunderbird\uninstall\uninstall.exe /ua "1.5 (en-US)"
    MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    Napster Burn Engine-->MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
    Napster-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe" -l0x9
    OCR Software by I.R.I.S. 10.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
    OpenOffice.org 2.0-->MsiExec.exe /I{75852F49-2CAF-443F-B7C2-53DE5847DE56}
    Power2Go 4.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,Lau nchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
    PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,Lau nchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
    QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
    Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
    Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
    Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
    Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.e xe"
    Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.e xe"
    Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.ex e"
    Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Shop for HP Supplies-->C:\Program Files\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
    Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_03001 07B\HXFSETUP.EXE -U -Iqta0300m.inf
    Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    Texas Instruments PCIxx21/x515/xx12 drivers.-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.e xe /M{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} /l1033
    TI Connect 1.6-->MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
    Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    Update for Windows XP (KB953356)-->"C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe"
    Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    VC 9.0 Runtime-->MsiExec.exe /I{A040AC77-C1AA-4CC9-8931-9F648AF178F6}
    Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
    Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
    Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe "
    Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
    Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.ex e"
    ZoneAlarm Security Suite-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

    ======Security center information======

    AV: ZoneAlarm Security Suite Antivirus
    FW: ZoneAlarm Security Suite Firewall

    System event log

    Computer Name: YOUR-4BC5110200
    Event Code: 10010
    Message: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.

    Record Number: 33130
    Source Name: DCOM
    Time Written: 20090102135401.000000-360
    Event Type: error
    User: YOUR-4BC5110200\Owner

    Computer Name: YOUR-4BC5110200
    Event Code: 10010
    Message: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.

    Record Number: 33129
    Source Name: DCOM
    Time Written: 20090102135330.000000-360
    Event Type: error
    User: YOUR-4BC5110200\Owner

    Computer Name: YOUR-4BC5110200
    Event Code: 10010
    Message: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.

    Record Number: 33128
    Source Name: DCOM
    Time Written: 20090102135300.000000-360
    Event Type: error
    User: YOUR-4BC5110200\Owner

    Computer Name: YOUR-4BC5110200
    Event Code: 10010
    Message: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.

    Record Number: 33127
    Source Name: DCOM
    Time Written: 20090102135230.000000-360
    Event Type: error
    User: YOUR-4BC5110200\Owner

    Computer Name: YOUR-4BC5110200
    Event Code: 10010
    Message: The server {28DD3979-0566-4ED3-9B14-1548B3187491} did not register with DCOM within the required timeout.

    Record Number: 33126
    Source Name: DCOM
    Time Written: 20090102135200.000000-360
    Event Type: error
    User: YOUR-4BC5110200\Owner

    Application event log

    Computer Name: YOUR-4BC5110200
    Event Code: 1001
    Message: Detection of product '{A5AB9D5E-52E2-440E-A3ED-9512E253C81A}', feature 'SolutionCenter' failed during request for component '{5FD5BEDB-A426-4F68-BA15-037E44388CE8}'

    Record Number: 7412
    Source Name: MsiInstaller
    Time Written: 20081014080502.000000-300
    Event Type: warning
    User: YOUR-4BC5110200\Daddy

    Computer Name: YOUR-4BC5110200
    Event Code: 1004
    Message: Detection of product '{A5AB9D5E-52E2-440E-A3ED-9512E253C81A}', feature 'SolutionCenter', component '{C8AA5B6D-C6A6-487D-B2AD-B6C2DC258E47}' failed. The resource 'C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx' does not exist.

    Record Number: 7411
    Source Name: MsiInstaller
    Time Written: 20081014080502.000000-300
    Event Type: warning
    User: YOUR-4BC5110200\Daddy

    Computer Name: YOUR-4BC5110200
    Event Code: 11729
    Message: Product: SolutionCenter -- Configuration failed.

    Record Number: 7410
    Source Name: MsiInstaller
    Time Written: 20081014080502.000000-300
    Event Type: information
    User: YOUR-4BC5110200\Daddy

    Computer Name: YOUR-4BC5110200
    Event Code: 11706
    Message: Product: SolutionCenter -- Error 1706. An installation package for the product SolutionCenter cannot be found. Try the installation again using a valid copy of the installation package 'SolutionCenter.msi'.

    Record Number: 7409
    Source Name: MsiInstaller
    Time Written: 20081014080502.000000-300
    Event Type: error
    User: YOUR-4BC5110200\Daddy

    Computer Name: YOUR-4BC5110200
    Event Code: 1001
    Message: Detection of product '{A5AB9D5E-52E2-440E-A3ED-9512E253C81A}', feature 'SolutionCenter' failed during request for component '{5FF21F12-FDC3-4FB0-A6BE-04FE524B1C11}'

    Record Number: 7408
    Source Name: MsiInstaller
    Time Written: 20081014080223.000000-300
    Event Type: warning
    User: YOUR-4BC5110200\Daddy

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\Syste m32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier"
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 36 Stepping 2, AuthenticAMD
    "PROCESSOR_REVISION"=2402
    "NUMBER_OF_PROCESSORS"=1
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.W SH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "tvdumpflags"=8

    -----------------EOF-----------------

  5. #5
    Moderator (global) Team-Mitglied Avatar von Jintan
    Registriert seit
    25.11.2006
    Beiträge
    6.369

    Re: Taskbar and Icons gone, Log posted

    Ah, the malware is set to also load it's drivers even in Safe Mode there. We will have to take a look before they completely load to identify what to remove there. I will provide two different procedures for that. The first requires you have, or borrow for a short time, and XP CD. This is also a cleaner view as it will check things prior to Windows loading. The second only uses what is there, but is not as complete a view. Do what you are able to, or both if possible.


    Step 1:

    Code:
    listsvc
    dir c:\windows\system32\drivers
    Open Notepad (Start - Run, type notepad and press Enter).

    Copy/paste the above text (inside the Code box) into the open text box, then save this to your C:\Windows folder as "servcheck.bat"

    It should then be C:\Windows\servcheck.bat (important)


    Then load the XP CD into the CD-ROM drive and restart the system. On reboot watch for and agree to any prompts to boot from the CD. If the system only reboots to Windows stop and post back here and we will discuss steps to make changes in the BIOS.

    After the installation software inspects the system and loads all necessary device drivers you will see the "Welcome To Setup" screen, with the following menu:

    This portion of the Setup program prepares Microsoft Windows XP to run on your computer:

    To setup Windows XP now, press ENTER.

    To repair a Windows XP installation using Recovery Console, press R.

    To quit Setup without installing Windows XP, press F3.
    Press "R" to start the Recovery Console setup. After you start the Windows Recovery Console, you receive the following message:

    Microsoft Windows(R) Recovery Console

    The Recovery Console provides system repair and recovery functionality.
    Type EXIT to quit the Recovery Console and restart the computer.

    1: C:\WINDOWS

    Which Windows Installation would you like to log on to
    (To cancel, press ENTER)?
    After you enter the number for the appropriate Windows installation (usually #1), Windows will then prompt you to enter the Administrator account password if one was created (if one was not created then just press Enter).

    At the prompt type the following, pressing Enter after each:

    batch servcheck.bat c:\windows\servicelook.txt

    exit


    When you hit Enter after typing exit your computer will reboot. Do Not press any key until the system has completely rebooted, then after the reboot be sure to remove your XP CD from the CD-ROM drive.

    Then locate and post back here the contents of c:\windows\servicelook.txt please.

    ==========================

    Step 2:

    1 - Go to Start > Run, type in msconfig (and OK)

    In msconfig go to the Boot.ini tab, and place a check next to the following entry:

    /Bootlog

    Then Apply/OK and allow the restart. Don't make any other changes in msconfig throughout the remaining procedures.


    2 - After the reboot navigate to and delete the following file:

    C:\Windows\ntbtlog.txt

    Then restart the computer again.


    3 - As the system boots up tap the F8 key about once per second to access the startup menu, and on that list select the following, and allow the computer to complete the bootup.

    Enable Boot Logging


    4 - After Windows has loaded again locate the C:\Windows\ntbtlog.txt file and copy/paste those contents back here please.
    Lebe den Tag!

    Jintan - Die Marke, bei der alles stimmt!

  6. #6
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    i was only able to do step 2.
    here's the log.


    Did not load driver \SystemRoot\system32\drivers\aec.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys
    Service Pack 3 1 10 2009 14:43:16.500
    Loaded driver \WINDOWS\system32\ntkrnlpa.exe
    Loaded driver \WINDOWS\system32\hal.dll
    Loaded driver \WINDOWS\system32\KDCOM.DLL
    Loaded driver \WINDOWS\system32\BOOTVID.dll
    Loaded driver ACPI.sys
    Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
    Loaded driver pci.sys
    Loaded driver isapnp.sys
    Loaded driver compbatt.sys
    Loaded driver \WINDOWS\system32\DRIVERS\BATTC.SYS
    Loaded driver pciide.sys
    Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver aliide.sys
    Loaded driver cmdide.sys
    Loaded driver toside.sys
    Loaded driver viaide.sys
    Loaded driver intelide.sys
    Loaded driver pcmcia.sys
    Loaded driver MountMgr.sys
    Loaded driver ftdisk.sys
    Loaded driver PartMgr.sys
    Loaded driver ACPIEC.sys
    Loaded driver \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
    Loaded driver VolSnap.sys
    Loaded driver cpqarray.sys
    Loaded driver \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
    Loaded driver atapi.sys
    Loaded driver aha154x.sys
    Loaded driver sparrow.sys
    Loaded driver symc810.sys
    Loaded driver aic78xx.sys
    Loaded driver dac960nt.sys
    Loaded driver ql10wnt.sys
    Loaded driver amsint.sys
    Loaded driver asc.sys
    Loaded driver asc3550.sys
    Loaded driver mraid35x.sys
    Loaded driver i2omp.sys
    Loaded driver ini910u.sys
    Loaded driver ql1240.sys
    Loaded driver aic78u2.sys
    Loaded driver symc8xx.sys
    Loaded driver sym_hi.sys
    Loaded driver sym_u3.sys
    Loaded driver ABP480N5.SYS
    Loaded driver asc3350p.sys
    Loaded driver cd20xrnt.sys
    Loaded driver ultra.sys
    Loaded driver adpu160m.sys
    Loaded driver dpti2o.sys
    Loaded driver ql1080.sys
    Loaded driver ql1280.sys
    Loaded driver ql12160.sys
    Loaded driver perc2.sys
    Loaded driver perc2hib.sys
    Loaded driver hpn.sys
    Loaded driver cbidf2k.sys
    Loaded driver dac2w2k.sys
    Loaded driver disk.sys
    Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver Hpx07.sys
    Loaded driver fltmgr.sys
    Loaded driver sr.sys
    Loaded driver PxHelp20.sys
    Loaded driver KSecDD.sys
    Loaded driver Ntfs.sys
    Loaded driver NDIS.sys
    Loaded driver viaagp.sys
    Loaded driver srescan.sys
    Loaded driver sisagp.sys
    Loaded driver ohci1394.sys
    Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS
    Loaded driver Mup.sys
    Loaded driver agp440.sys
    Loaded driver alim1541.sys
    Loaded driver amdagp.sys
    Loaded driver agpCPQ.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nic1394.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AmdK8.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ati2mtag.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bcmwl5.sys
    Loaded driver \SystemRoot\system32\drivers\tifm21.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sdbus.sys
    Loaded driver \SystemRoot\system32\drivers\camc6hal.sys
    Loaded driver \SystemRoot\system32\drivers\camc6aud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSFHWATI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_DPV.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\update.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
    Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
    Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\klif.sys
    Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
    Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\arp1394.sys
    Loaded driver \SystemRoot\System32\vsdatant.sys
    Loaded driver \SystemRoot\System32\drivers\ws2ifsl.sys
    Loaded driver \SystemRoot\System32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\system32\DRIVERS\serial.sys
    Did not load driver \SystemRoot\system32\DRIVERS\p3.sys
    Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\AegisP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    Did not load driver \??\C:\Nexon\MapleStory\npkcrypt.sys
    Service Pack 3 1 10 2009 14:44:38.500
    Loaded driver \WINDOWS\system32\ntkrnlpa.exe
    Loaded driver \WINDOWS\system32\hal.dll
    Loaded driver \WINDOWS\system32\KDCOM.DLL
    Loaded driver \WINDOWS\system32\BOOTVID.dll
    Loaded driver ACPI.sys
    Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
    Loaded driver pci.sys
    Loaded driver isapnp.sys
    Loaded driver compbatt.sys
    Loaded driver \WINDOWS\system32\DRIVERS\BATTC.SYS
    Loaded driver pciide.sys
    Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver aliide.sys
    Loaded driver cmdide.sys
    Loaded driver toside.sys
    Loaded driver viaide.sys
    Loaded driver intelide.sys
    Loaded driver pcmcia.sys
    Loaded driver MountMgr.sys
    Loaded driver ftdisk.sys
    Loaded driver PartMgr.sys
    Loaded driver ACPIEC.sys
    Loaded driver \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
    Loaded driver VolSnap.sys
    Loaded driver cpqarray.sys
    Loaded driver \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
    Loaded driver atapi.sys
    Loaded driver aha154x.sys
    Loaded driver sparrow.sys
    Loaded driver symc810.sys
    Loaded driver aic78xx.sys
    Loaded driver dac960nt.sys
    Loaded driver ql10wnt.sys
    Loaded driver amsint.sys
    Loaded driver asc.sys
    Loaded driver asc3550.sys
    Loaded driver mraid35x.sys
    Loaded driver i2omp.sys
    Loaded driver ini910u.sys
    Loaded driver ql1240.sys
    Loaded driver aic78u2.sys
    Loaded driver symc8xx.sys
    Loaded driver sym_hi.sys
    Loaded driver sym_u3.sys
    Loaded driver ABP480N5.SYS
    Loaded driver asc3350p.sys
    Loaded driver cd20xrnt.sys
    Loaded driver ultra.sys
    Loaded driver adpu160m.sys
    Loaded driver dpti2o.sys
    Loaded driver ql1080.sys
    Loaded driver ql1280.sys
    Loaded driver ql12160.sys
    Loaded driver perc2.sys
    Loaded driver perc2hib.sys
    Loaded driver hpn.sys
    Loaded driver cbidf2k.sys
    Loaded driver dac2w2k.sys
    Loaded driver disk.sys
    Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver Hpx07.sys
    Loaded driver fltmgr.sys
    Loaded driver sr.sys
    Loaded driver PxHelp20.sys
    Loaded driver KSecDD.sys
    Loaded driver Ntfs.sys
    Loaded driver NDIS.sys
    Loaded driver viaagp.sys
    Loaded driver srescan.sys
    Loaded driver sisagp.sys
    Loaded driver ohci1394.sys
    Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS
    Loaded driver Mup.sys
    Loaded driver agp440.sys
    Loaded driver alim1541.sys
    Loaded driver amdagp.sys
    Loaded driver agpCPQ.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nic1394.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AmdK8.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ati2mtag.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bcmwl5.sys
    Loaded driver \SystemRoot\system32\drivers\tifm21.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sdbus.sys
    Loaded driver \SystemRoot\system32\drivers\camc6hal.sys
    Loaded driver \SystemRoot\system32\drivers\camc6aud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSFHWATI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_DPV.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\update.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
    Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
    Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\klif.sys
    Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
    Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\arp1394.sys
    Loaded driver \SystemRoot\System32\vsdatant.sys
    Loaded driver \SystemRoot\System32\drivers\ws2ifsl.sys
    Loaded driver \SystemRoot\System32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\system32\DRIVERS\serial.sys
    Did not load driver \SystemRoot\system32\DRIVERS\p3.sys
    Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\AegisP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
    Did not load driver \??\C:\Nexon\MapleStory\npkcrypt.sys
    Service Pack 3 1 10 2009 14:46:59.500
    Loaded driver \WINDOWS\system32\ntkrnlpa.exe
    Loaded driver \WINDOWS\system32\hal.dll
    Loaded driver \WINDOWS\system32\KDCOM.DLL
    Loaded driver \WINDOWS\system32\BOOTVID.dll
    Loaded driver ACPI.sys
    Loaded driver \WINDOWS\system32\DRIVERS\WMILIB.SYS
    Loaded driver pci.sys
    Loaded driver isapnp.sys
    Loaded driver compbatt.sys
    Loaded driver \WINDOWS\system32\DRIVERS\BATTC.SYS
    Loaded driver pciide.sys
    Loaded driver \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    Loaded driver aliide.sys
    Loaded driver cmdide.sys
    Loaded driver toside.sys
    Loaded driver viaide.sys
    Loaded driver intelide.sys
    Loaded driver pcmcia.sys
    Loaded driver MountMgr.sys
    Loaded driver ftdisk.sys
    Loaded driver PartMgr.sys
    Loaded driver ACPIEC.sys
    Loaded driver \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
    Loaded driver VolSnap.sys
    Loaded driver cpqarray.sys
    Loaded driver \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
    Loaded driver atapi.sys
    Loaded driver aha154x.sys
    Loaded driver sparrow.sys
    Loaded driver symc810.sys
    Loaded driver aic78xx.sys
    Loaded driver dac960nt.sys
    Loaded driver ql10wnt.sys
    Loaded driver amsint.sys
    Loaded driver asc.sys
    Loaded driver asc3550.sys
    Loaded driver mraid35x.sys
    Loaded driver i2omp.sys
    Loaded driver ini910u.sys
    Loaded driver ql1240.sys
    Loaded driver aic78u2.sys
    Loaded driver symc8xx.sys
    Loaded driver sym_hi.sys
    Loaded driver sym_u3.sys
    Loaded driver ABP480N5.SYS
    Loaded driver asc3350p.sys
    Loaded driver cd20xrnt.sys
    Loaded driver ultra.sys
    Loaded driver adpu160m.sys
    Loaded driver dpti2o.sys
    Loaded driver ql1080.sys
    Loaded driver ql1280.sys
    Loaded driver ql12160.sys
    Loaded driver perc2.sys
    Loaded driver perc2hib.sys
    Loaded driver hpn.sys
    Loaded driver cbidf2k.sys
    Loaded driver dac2w2k.sys
    Loaded driver disk.sys
    Loaded driver \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    Loaded driver Hpx07.sys
    Loaded driver fltmgr.sys
    Loaded driver sr.sys
    Loaded driver PxHelp20.sys
    Loaded driver KSecDD.sys
    Loaded driver Ntfs.sys
    Loaded driver NDIS.sys
    Loaded driver viaagp.sys
    Loaded driver srescan.sys
    Loaded driver sisagp.sys
    Loaded driver ohci1394.sys
    Loaded driver \WINDOWS\system32\DRIVERS\1394BUS.SYS
    Loaded driver Mup.sys
    Loaded driver agp440.sys
    Loaded driver alim1541.sys
    Loaded driver amdagp.sys
    Loaded driver agpCPQ.sys
    Loaded driver \SystemRoot\system32\DRIVERS\nic1394.sys
    Loaded driver \SystemRoot\system32\DRIVERS\CmBatt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\AmdK8.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ati2mtag.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbohci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\usbehci.sys
    Loaded driver \SystemRoot\system32\DRIVERS\imapi.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\cdrom.sys
    Loaded driver \SystemRoot\system32\DRIVERS\redbook.sys
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\i8042prt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\kbdclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\SynTP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mouclass.sys
    Loaded driver \SystemRoot\system32\DRIVERS\bcmwl5.sys
    Loaded driver \SystemRoot\system32\drivers\tifm21.sys
    Loaded driver \SystemRoot\system32\DRIVERS\sdbus.sys
    Loaded driver \SystemRoot\system32\drivers\camc6hal.sys
    Loaded driver \SystemRoot\system32\drivers\camc6aud.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSFHWATI.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_DPV.sys
    Loaded driver \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\audstub.sys
    Loaded driver \SystemRoot\system32\DRIVERS\rasl2tp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndistapi.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndiswan.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspppoe.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspptp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\msgpc.sys
    Loaded driver \SystemRoot\system32\DRIVERS\psched.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ptilink.sys
    Loaded driver \SystemRoot\system32\DRIVERS\raspti.sys
    Loaded driver \SystemRoot\system32\DRIVERS\termdd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\swenum.sys
    Loaded driver \SystemRoot\system32\DRIVERS\update.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mssmbios.sys
    Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\usbhub.sys
    Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
    Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
    Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\klif.sys
    Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
    Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdr4_xp.SYS
    Loaded driver \SystemRoot\System32\Drivers\Cdralw2k.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
    Loaded driver \SystemRoot\System32\Drivers\Null.SYS
    Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
    Loaded driver \SystemRoot\System32\drivers\vga.sys
    Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
    Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
    Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
    Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rasacd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipsec.sys
    Loaded driver \SystemRoot\system32\DRIVERS\tcpip.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbt.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\DRIVERS\wanarp.sys
    Loaded driver \SystemRoot\system32\DRIVERS\arp1394.sys
    Loaded driver \SystemRoot\System32\vsdatant.sys
    Loaded driver \SystemRoot\System32\drivers\ws2ifsl.sys
    Loaded driver \SystemRoot\System32\drivers\afd.sys
    Loaded driver \SystemRoot\system32\DRIVERS\netbios.sys
    Did not load driver \SystemRoot\system32\DRIVERS\serial.sys
    Did not load driver \SystemRoot\system32\DRIVERS\p3.sys
    Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
    Loaded driver \SystemRoot\System32\Drivers\Fastfat.SYS
    Loaded driver \SystemRoot\system32\DRIVERS\AegisP.sys
    Loaded driver \SystemRoot\system32\DRIVERS\ndisuio.sys
    Did not load driver \SystemRoot\system32\DRIVERS\rdbss.sys
    Did not load driver \SystemRoot\system32\DRIVERS\mrxsmb.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mrxdav.sys
    Loaded driver \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    Loaded driver \SystemRoot\system32\DRIVERS\srv.sys
    Did not load driver \??\C:\Nexon\MapleStory\npkcrypt.sys
    Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
    Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
    Loaded driver \SystemRoot\system32\drivers\splitter.sys
    Loaded driver \SystemRoot\system32\drivers\aec.sys
    Did not load driver \SystemRoot\system32\DRIVERS\ipnat.sys
    Loaded driver \SystemRoot\system32\drivers\swmidi.sys
    Loaded driver \SystemRoot\system32\drivers\DMusic.sys
    Loaded driver \SystemRoot\system32\drivers\kmixer.sys
    Loaded driver \SystemRoot\system32\drivers\drmkaud.sys

  7. #7
    Moderator (global) Team-Mitglied Avatar von Jintan
    Registriert seit
    25.11.2006
    Beiträge
    6.369

    Re: Taskbar and Icons gone, Log posted

    Not seeing them loading at boot there, at least by this view. Let's go with some repairs then check as we go.


    To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


    Go to Start > Run and type

    cmd

    and OK. At the prompt type (or copy\paste) the below commands and hit "Enter" after each line

    sc config FCI start= disabled
    sc config ICF start= disabled


    Type Exit to close.

    ---------------------

    Go to Start - Run, type firewall.cpl (and Enter). Click the Exceptions tab. If the following item(s) is present on that list click to hilight it, and select "Delete", and OK to close the Windows Firewall display.

    EMOTIONS_EXECUTABLE

    ----------------------

    Download Malwarebytes' Anti-Malware from Here or Here.

    Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform quick scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.

    ---------------------

    Download SDFix.exe and save it to your desktop.

    =============================

    Reboot into Safe Mode (at startup tap the F8 key and select Safe Mode).


    In Safe Mode, click the C:\SDFix.exe folder and allow it to extract to it's own folder (C:\SDFix). Navigate to that folder and double click RunThis.bat to start the script.

    Next type Y to begin the script. Once the fix has run it will prompt you to restart your computer. Press any key to restart at this time. Your system will take longer that normal to restart as the fixtool will be running and removing files.

    When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.

    Then open the C:\SDFix folder and copy and paste the contents of the results file Report.txt back here.

    =======================

    Run a new RSIT scan, and post that log along with the Malwarebytes log and the SDFix report.txt log please.
    Lebe den Tag!

    Jintan - Die Marke, bei der alles stimmt!

  8. #8
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    Malwarebytes log

    Malwarebytes' Anti-Malware 1.32
    Database version: 1643
    Windows 5.1.2600 Service Pack 3

    1/11/2009 7:33:22 PM
    mbam-log-2009-01-11 (19-33-22).txt

    Scan type: Quick Scan
    Objects scanned: 63677
    Time elapsed: 34 minute(s), 4 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 14
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 2
    Files Infected: 10

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{343ce214-9998-4b21-a151-ffe970167297} (Rogue.Installer) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hpx07 (Rootkit.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\hpx07 (Rootkit.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\hpx07 (Rootkit.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hpx07 (Rootkit.Agent) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fci (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion \Run\svchost (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    C:\Program Files\Microsoft Common (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.

    Files Infected:
    C:\Program Files\Microsoft Common\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drivers\Hpx07.sys (Rootkit.Agent) -> Delete on reboot.
    C:\RECYCLER\S-1-5-21-137398485-1955139709-3445199493-1006\Dc1\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Temp\BN7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

  9. #9
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    SDfix log is in the attachment.
    some reason it wouldn't let me post it.
    Angehängte Dateien Angehängte Dateien

  10. #10
    Einsteiger
    Registriert seit
    08.01.2009
    Beiträge
    17

    Re: Taskbar and Icons gone, Log posted

    wouldn't let me post the RSIT log and the attachment is too big.
    so here's a link to megaupload with it.
    http://www.megaupload.com/?d=V3JU29I9

Seite 1 von 3 123 LetzteLetzte

Aktive Benutzer

Aktive Benutzer

Aktive Benutzer in diesem Thema: 1 (Registrierte Benutzer: 0, Gäste: 1)

Ähnliche Themen

  1. Need help...hijackthis log posted...
    Von ashleyq im Forum English-Help
    Antworten: 8
    Letzter Beitrag: 07.01.2009, 18:12
  2. please help, log posted
    Von kupsjon im Forum English-Help
    Antworten: 22
    Letzter Beitrag: 24.08.2008, 00:18
  3. Desktop doesnt come up with icons or taskbar
    Von juliasdream im Forum Archiv
    Antworten: 1
    Letzter Beitrag: 07.10.2007, 11:04
  4. no icons/taskbar lots of spyware virus
    Von professionaltard im Forum Archiv
    Antworten: 3
    Letzter Beitrag: 20.09.2005, 16:18
  5. Antworten: 0
    Letzter Beitrag: 24.01.2005, 14:37

Berechtigungen

  • Neue Themen erstellen: Nein
  • Themen beantworten: Nein
  • Anhänge hochladen: Nein
  • Beiträge bearbeiten: Nein
  •