Help Me To Remove XP Police

View previous topic View next topic Go down

Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 2:23 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:47 PM, on 3/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: WinGDI Class - {12c7290a-157b-4f43-b109-97e792c598ed} - C:\WINDOWS\iehost.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PoliceAV] C:\Program Files\XPPoliceAntivirus\xppolice.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EAD4A62-3D5B-4DE6-B13F-2545F52273B0}: NameServer = 123.231.0.167 123.231.0.181
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 6287 bytes


Please Help Me To Remove This.

Thank You!

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by Belahzur on Mon Mar 09, 2009 3:09 pm

Hello.

I notice that you have Spybot's TeaTimer running. While this is normally a wonderful tool to protect against hijackers, it can also interfere with HijackThis fixes. So please disable TeaTimer by doing the following:
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
You can reenable TeaTimer once your system is clean.

Please make sure Teatimer is disable before we do this, otherwise this fix will fail.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: WinGDI Class - {12c7290a-157b-4f43-b109-97e792c598ed} - C:\WINDOWS\iehost.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKCU\..\Run: [PoliceAV] C:\Program Files\XPPoliceAntivirus\xppolice.exe


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 3:46 pm

Thanks Belahzur Here Is The Log...

Malwarebytes' Anti-Malware 1.34
Database version: 1828
Windows 5.1.2600 Service Pack 2

3/9/2009 9:05:04 PM
mbam-log-2009-03-09 (21-05-04).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 156695
Time elapsed: 34 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\wingdiapp.wingdi (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{12c7290a-157b-4f43-b109-97e792c598ed} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{12c7290a-157b-4f43-b109-97e792c598ed} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{12c7290a-157b-4f43-b109-97e792c598ed} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\wingdiapp.wingdi.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\iehost.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\Cheap Software.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sf.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\MP3 Download.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\m3.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\Search Online.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\VIP Casino.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\SMS TRAP.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\Cheap Pharmacy Online.LNK (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\c.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\m.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\p.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\s.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\A.F.R.A.K\Start Menu\XP Police Antivirus.lnk (Rogue.XP-Police-Antivirus) -> Quarantined and deleted successfully.

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by Belahzur on Mon Mar 09, 2009 3:47 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Save the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 3:54 pm

Hello I'm Getting This Error ???


A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by Belahzur on Mon Mar 09, 2009 3:56 pm

Lets use this instead.


  • Download random's system information tool (RSIT) by random/random from [You must be registered and logged in to see this link.] and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of log.txt (<< will be maximized) and save info.txt (<< will be minimized) for later.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:04 pm

Logfile of random's system information tool 1.05 (written by random/random)
Run by A.F.R.A.K at 2009-03-09 21:32:20
Microsoft Windows XP Professional Service Pack 2
System drive C: has 9 GB (44%) free of 20 GB
Total RAM: 1982 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:32:23 PM, on 3/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Documents and Settings\A.F.R.A.K\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\A.F.R.A.K.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} (KooPlayer Control) - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EAD4A62-3D5B-4DE6-B13F-2545F52273B0}: NameServer = 123.231.0.167 123.231.0.181
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EAD4A62-3D5B-4DE6-B13F-2545F52273B0}: NameServer = 123.231.0.167 123.231.0.181
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 5646 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\1-Click Maintenance.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-01-22 161200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-02-24 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-02-24 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2009-02-06 2021400]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe [2009-02-24 2745776]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2007-07-22 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"SetVisualStyle"=C:\WINDOWS\Resources\Themes\Inspirat2\Inspirat2.msstyles

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\Program Files\Condition Zero\hl.exe"="C:\Program Files\Condition Zero\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Condition Zero\hlds.exe"="C:\Program Files\Condition Zero\hlds.exe:*:Enabled:HLDS Launcher"
"C:\Program Files\Internet Download Manager\IDMan.exe"="C:\Program Files\Internet Download Manager\IDMan.exe:*:Enabled:Internet Download Manager (IDM)"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Counter-Strike 1.6\hl.exe"="C:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:06 pm

======List of files/folders created in the last 1 months======

2009-03-09 21:30:58 ----D---- C:\rsit
2009-03-09 19:47:34 ----D---- C:\Program Files\Trend Micro
2009-03-09 19:18:36 ----D---- C:\Program Files\Enigma Software Group
2009-03-09 19:11:32 ----D---- C:\Program Files\Unlocker
2009-03-08 14:09:34 ----D---- C:\Program Files\Flock
2009-03-06 21:50:41 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\ESET
2009-03-06 21:49:14 ----D---- C:\Program Files\ESET
2009-03-06 21:49:14 ----D---- C:\Documents and Settings\All Users\Application Data\ESET
2009-03-06 21:19:43 ----D---- C:\Program Files\Counter-Strike 1.6
2009-03-06 19:52:10 ----D---- C:\Program Files\uTorrent
2009-03-06 19:52:03 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\uTorrent
2009-03-05 19:13:18 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Flock
2009-03-03 07:43:04 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2009-03-02 19:19:18 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Helios
2009-03-01 22:23:31 ----A---- C:\WINDOWS\NeroDigital.ini
2009-03-01 00:31:34 ----D---- C:\rms
2009-03-01 00:31:27 ----D---- C:\Program Files\Sjboy Emulator
2009-02-27 17:00:47 ----D---- C:\Program Files\Condition Zero
2009-02-27 14:58:25 ----D---- C:\Program Files\TVAnts
2009-02-27 07:27:21 ----HDC---- C:\WINDOWS\$NtUninstallKB937894$
2009-02-27 07:27:13 ----HDC---- C:\WINDOWS\$NtUninstallKB933729$
2009-02-27 07:27:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938828$
2009-02-27 07:26:59 ----HDC---- C:\WINDOWS\$NtUninstallKB946026$
2009-02-27 07:26:51 ----HDC---- C:\WINDOWS\$NtUninstallKB943485$
2009-02-27 07:26:44 ----HDC---- C:\WINDOWS\$NtUninstallKB945553$
2009-02-27 07:26:33 ----HDC---- C:\WINDOWS\$NtUninstallKB950749$
2009-02-27 07:26:25 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$
2009-02-27 07:26:18 ----HDC---- C:\WINDOWS\$NtUninstallKB943055$
2009-02-27 07:26:08 ----HDC---- C:\WINDOWS\$NtUninstallKB944653$
2009-02-26 23:22:32 ----HD---- C:\WINDOWS\PIF
2009-02-26 14:40:00 ----D---- C:\WINDOWS\system32\Nagasoft
2009-02-26 14:39:23 ----D---- C:\Program Files\SopCast
2009-02-25 22:45:39 ----D---- C:\WINDOWS\Sun
2009-02-25 22:36:31 ----D---- C:\Documents and Settings\All Users\Application Data\JCreator
2009-02-25 22:36:31 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\JCreator
2009-02-25 16:33:13 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-02-25 15:41:38 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-02-25 14:33:22 ----D---- C:\Documents and Settings\All Users\Application Data\TVU Networks
2009-02-25 08:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-02-25 08:26:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-02-25 08:25:24 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-02-25 08:25:06 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-02-25 08:23:37 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-02-25 08:21:50 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-02-25 08:21:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-02-25 08:20:51 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-02-25 08:20:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-02-25 08:17:50 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-02-25 08:16:06 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-02-25 08:15:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-02-25 08:15:21 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-02-25 08:15:06 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-02-25 08:12:29 ----D---- C:\WINDOWS\SQL9_KB960089_ENU
2009-02-25 08:11:45 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-02-25 08:11:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-02-25 08:11:06 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-02-25 08:10:49 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2009-02-25 08:10:33 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-02-25 08:08:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-02-25 08:08:23 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-02-25 08:07:52 ----D---- C:\WINDOWS\ie7updates
2009-02-25 08:07:32 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-02-25 08:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-02-25 08:06:59 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-02-25 08:06:42 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-02-25 08:06:22 ----D---- C:\Program Files\MSXML 4.0
2009-02-25 08:06:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-02-25 08:05:43 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-02-25 08:05:37 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2009-02-25 08:05:01 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-02-25 08:05:00 ----HD---- C:\WINDOWS\$hf_mig$
2009-02-25 07:59:17 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-02-25 07:07:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-02-24 22:28:50 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2009-02-24 21:55:43 ----A---- C:\WINDOWS\system32\h323log.txt
2009-02-24 21:52:58 ----A---- C:\WINDOWS\system32\usbui.dll
2009-02-24 21:51:12 ----SHD---- C:\WINDOWS\Installer
2009-02-24 21:51:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-02-24 21:51:11 ----D---- C:\Program Files\Common Files\ODBC
2009-02-24 21:51:11 ----A---- C:\WINDOWS\ODBCINST.INI
2009-02-24 21:51:08 ----RD---- C:\Program Files
2009-02-24 21:51:08 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-02-24 21:51:08 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-02-24 21:51:08 ----D---- C:\Program Files\Common Files
2009-02-24 21:51:05 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-02-24 21:51:05 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-02-24 21:51:05 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-02-24 21:51:03 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-02-24 21:51:01 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-02-24 21:51:00 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-02-24 21:51:00 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-02-24 21:51:00 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-02-24 21:51:00 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-02-24 21:51:00 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-02-24 21:50:58 ----RA---- C:\WINDOWS\system32\KBDAL.DLL

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:07 pm

2009-02-24 21:50:56 ----A---- C:\WINDOWS\system32\irclass.dll
2009-02-24 21:50:55 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-02-24 21:50:55 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-02-24 21:50:55 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-02-24 21:50:55 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-02-24 21:50:53 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-02-24 21:50:53 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-02-24 21:50:53 ----A---- C:\WINDOWS\system32\batt.dll
2009-02-24 21:50:52 ----A---- C:\WINDOWS\system32\storprop.dll
2009-02-24 21:50:52 ----A---- C:\WINDOWS\notepad.exe
2009-02-24 21:50:43 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-02-24 21:50:19 ----RA---- C:\WINDOWS\SET8.tmp
2009-02-24 21:50:17 ----RA---- C:\WINDOWS\SET4.tmp
2009-02-24 21:50:16 ----RA---- C:\WINDOWS\SET3.tmp
2009-02-24 21:50:11 ----D---- C:\WINDOWS\system32\CatRoot2
2009-02-24 21:50:11 ----D---- C:\WINDOWS\system32\CatRoot
2009-02-24 21:50:05 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-02-24 21:49:43 ----SHD---- C:\System Volume Information
2009-02-24 21:49:43 ----D---- C:\Documents and Settings
2009-02-24 21:48:43 ----SH---- C:\boot.ini
2009-02-24 21:44:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-02-24 21:44:52 ----RSD---- C:\WINDOWS\Fonts
2009-02-24 21:44:52 ----RD---- C:\WINDOWS\Web
2009-02-24 21:44:52 ----HD---- C:\WINDOWS\inf
2009-02-24 21:44:52 ----D---- C:\WINDOWS\WinSxS
2009-02-24 21:44:52 ----D---- C:\WINDOWS\twain_32
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Temp
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\wins
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\wbem
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\usmt
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\spool
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\ShellExt
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\Setup
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\ras
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\PreInstall
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\oobe
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\npp
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\mui
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\Macromed
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\inetsrv
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\IME
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\icsxml
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\ias
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\export
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\en-us
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\drivers
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\dhcp
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\config
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\3com_dmi
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\3076
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\2052
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1054
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1042
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1041
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1037
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1033
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1031
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1028
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32\1025
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system32
2009-02-24 21:44:52 ----D---- C:\WINDOWS\system
2009-02-24 21:44:52 ----D---- C:\WINDOWS\SoftwareDistribution
2009-02-24 21:44:52 ----D---- C:\WINDOWS\security
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Resources
2009-02-24 21:44:52 ----D---- C:\WINDOWS\repair
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Provisioning
2009-02-24 21:44:52 ----D---- C:\WINDOWS\PeerNet
2009-02-24 21:44:52 ----D---- C:\WINDOWS\pchealth
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Network Diagnostic
2009-02-24 21:44:52 ----D---- C:\WINDOWS\mui
2009-02-24 21:44:52 ----D---- C:\WINDOWS\msapps
2009-02-24 21:44:52 ----D---- C:\WINDOWS\msagent
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Media
2009-02-24 21:44:52 ----D---- C:\WINDOWS\l2schemas
2009-02-24 21:44:52 ----D---- C:\WINDOWS\java
2009-02-24 21:44:52 ----D---- C:\WINDOWS\ime
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Help
2009-02-24 21:44:52 ----D---- C:\WINDOWS\ehome
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Driver Cache
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Debug
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Cursors
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Connection Wizard
2009-02-24 21:44:52 ----D---- C:\WINDOWS\Config
2009-02-24 21:44:52 ----D---- C:\WINDOWS\AppPatch
2009-02-24 21:44:52 ----D---- C:\WINDOWS\addins
2009-02-24 21:44:52 ----D---- C:\WINDOWS
2009-02-24 21:21:48 ----D---- C:\Program Files\Messenger Plus! Live
2009-02-24 20:47:02 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Apple Computer
2009-02-24 20:13:21 ----D---- C:\Program Files\Microsoft.NET
2009-02-24 20:13:03 ----D---- C:\Program Files\MSXML 6.0
2009-02-24 20:07:53 ----RSD---- C:\WINDOWS\assembly
2009-02-24 20:07:16 ----D---- C:\WINDOWS\Microsoft.NET
2009-02-24 20:06:34 ----D---- C:\Program Files\Microsoft SQL Server
2009-02-24 20:02:38 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Malwarebytes
2009-02-24 20:02:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-02-24 20:02:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-02-24 20:02:02 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2009-02-24 20:02:01 ----A---- C:\WINDOWS\system32\TuneUpDefragService.exe
2009-02-24 20:02:00 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\TuneUp Software
2009-02-24 20:01:51 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2009-02-24 20:01:48 ----D---- C:\Program Files\TuneUp Utilities 2008
2009-02-24 20:01:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-02-24 19:59:35 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\URSoft
2009-02-24 19:59:34 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-02-24 19:59:30 ----D---- C:\Program Files\Your Uninstaller 2008
2009-02-24 19:58:25 ----A---- C:\WINDOWS\system32\javaws.exe
2009-02-24 19:58:25 ----A---- C:\WINDOWS\system32\javaw.exe
2009-02-24 19:58:25 ----A---- C:\WINDOWS\system32\java.exe
2009-02-24 19:58:25 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-02-24 19:58:16 ----D---- C:\Program Files\Java
2009-02-24 19:55:29 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Sun
2009-02-24 19:55:06 ----A---- C:\WINDOWS\system32\msonpmon.dll
2009-02-24 19:53:24 ----D---- C:\Program Files\Microsoft Works
2009-02-24 19:53:15 ----D---- C:\Program Files\MSBuild
2009-02-24 19:53:02 ----D---- C:\Program Files\Common Files\DESIGNER
2009-02-24 19:50:12 ----D---- C:\WINDOWS\SHELLNEW
2009-02-24 19:49:53 ----D---- C:\Program Files\Microsoft Office
2009-02-24 19:49:53 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-02-24 19:45:33 ----RHD---- C:\MSOCache
2009-02-24 19:43:45 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\IDM
2009-02-24 19:43:45 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\DMCache
2009-02-24 19:43:41 ----D---- C:\Program Files\Internet Download Manager
2009-02-24 19:42:28 ----D---- C:\Program Files\CCleaner
2009-02-24 19:41:24 ----D---- C:\Program Files\Microsoft
2009-02-24 19:41:06 ----D---- C:\Program Files\Windows Live SkyDrive
2009-02-24 19:40:43 ----D---- C:\Program Files\Windows Live
2009-02-24 19:31:21 ----D---- C:\Program Files\Common Files\Windows Live
2009-02-24 19:29:52 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-02-24 19:28:54 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-02-24 19:28:05 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-02-24 19:26:39 ----D---- C:\Program Files\The KMPlayer1431
2009-02-24 19:23:41 ----D---- C:\Program Files\Nero
2009-02-24 19:23:41 ----D---- C:\Program Files\Common Files\Ahead
2009-02-24 19:21:53 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Mozilla
2009-02-24 19:21:46 ----D---- C:\Program Files\Mozilla Firefox
2009-02-24 19:20:19 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-02-24 19:20:16 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Macromedia
2009-02-24 19:20:16 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Adobe
2009-02-24 19:19:40 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-24 19:19:33 ----D---- C:\Program Files\Common Files\Adobe
2009-02-24 19:19:33 ----D---- C:\Program Files\Adobe
2009-02-24 19:18:09 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\FastStone
2009-02-24 19:17:57 ----D---- C:\Program Files\FastStone Capture
2009-02-24 19:09:35 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2009-02-24 19:09:33 ----SHD---- C:\RECYCLER
2009-02-24 19:08:19 ----A---- C:\WINDOWS\BricoPackUninst.txt
2009-02-24 19:08:00 ----D---- C:\WINDOWS\BricoPacks
2009-02-24 19:07:24 ----D---- C:\Program Files\WinRAR
2009-02-24 16:21:36 ----R---- C:\WINDOWS\system32\ChCfg.exe
2009-02-24 16:21:16 ----R---- C:\WINDOWS\system32\RTLCPL.exe
2009-02-24 16:21:16 ----R---- C:\WINDOWS\system32\RtlCPAPI.dll
2009-02-24 16:21:15 ----R---- C:\WINDOWS\soundman.exe
2009-02-24 16:21:14 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-02-24 16:21:09 ----D---- C:\Program Files\Realtek Sound Manager
2009-02-24 16:21:07 ----R---- C:\WINDOWS\avrack.ini
2009-02-24 16:21:07 ----D---- C:\Program Files\AvRack
2009-02-24 16:20:58 ----D---- C:\Program Files\Realtek AC97
2009-02-24 16:20:46 ----RA---- C:\WINDOWS\Alcrmv.exe
2009-02-24 16:20:46 ----R---- C:\WINDOWS\alcupd.exe
2009-02-24 16:13:41 ----D---- C:\Program Files\S3
2009-02-24 16:11:30 ----HD---- C:\Program Files\InstallShield Installation Information
2009-02-24 16:10:17 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-02-24 16:10:07 ----D---- C:\Program Files\VIA
2009-02-24 16:09:59 ----D---- C:\Program Files\Common Files\InstallShield
2009-02-24 16:08:17 ----D---- C:\Documents and Settings\A.F.R.A.K\Application Data\Identities

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:08 pm

2009-02-24 16:08:14 ----HD---- C:\Program Files\Uninstall Information
2009-02-24 16:08:06 ----SD---- C:\Documents and Settings\A.F.R.A.K\Application Data\Microsoft
2009-02-24 16:08:06 ----ASH---- C:\Documents and Settings\A.F.R.A.K\Application Data\desktop.ini
2009-02-24 16:06:03 ----D---- C:\WINDOWS\Prefetch
2009-02-24 16:06:02 ----SD---- C:\WINDOWS\system32\Microsoft
2009-02-24 16:06:02 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-02-24 16:02:12 ----D---- C:\WINDOWS\system32\xircom
2009-02-24 16:02:12 ----D---- C:\Program Files\xerox
2009-02-24 16:02:12 ----D---- C:\Program Files\microsoft frontpage
2009-02-24 16:01:52 ----A---- C:\WINDOWS\control.ini
2009-02-24 16:01:52 ----A---- C:\AUTOEXEC.BAT
2009-02-24 16:01:38 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-02-24 16:00:43 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-02-24 16:00:39 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-02-24 16:00:35 ----HD---- C:\Program Files\WindowsUpdate
2009-02-24 16:00:16 ----D---- C:\WINDOWS\system32\DirectX
2009-02-24 15:59:59 ----A---- C:\WINDOWS\system32\atrace.dll
2009-02-24 15:59:56 ----A---- C:\WINDOWS\system32\desktop.ini
2009-02-24 15:59:56 ----A---- C:\WINDOWS\desktop.ini
2009-02-24 15:59:51 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-02-24 15:59:50 ----A---- C:\WINDOWS\system32\acctres.dll
2009-02-24 15:59:49 ----D---- C:\Program Files\Common Files\Services
2009-02-24 15:59:48 ----SD---- C:\WINDOWS\Tasks
2009-02-24 15:59:48 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-02-24 15:59:47 ----D---- C:\Program Files\Common Files\MSSoap
2009-02-24 15:59:44 ----D---- C:\WINDOWS\srchasst
2009-02-24 15:59:41 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-02-24 15:59:41 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-02-24 15:59:41 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-02-24 15:59:41 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\wups.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-02-24 15:59:40 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-02-24 15:59:37 ----D---- C:\Program Files\Movie Maker
2009-02-24 15:59:33 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-02-24 15:59:33 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-02-24 15:59:33 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-02-24 15:59:33 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-02-24 15:59:30 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-02-24 15:59:30 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-02-24 15:59:29 ----D---- C:\WINDOWS\system32\Restore
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\srclient.dll
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-02-24 15:59:29 ----A---- C:\WINDOWS\system32\ils.dll
2009-02-24 15:59:28 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-02-24 15:59:28 ----A---- C:\WINDOWS\system32\msconf.dll
2009-02-24 15:59:28 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-02-24 15:59:26 ----D---- C:\Program Files\NetMeeting
2009-02-24 15:59:26 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-02-24 15:59:26 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-02-24 15:59:25 ----A---- C:\WINDOWS\system32\inetres.dll
2009-02-24 15:59:25 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-02-24 15:59:23 ----D---- C:\Program Files\Outlook Express
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\mstask.dll
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\isign32.dll
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-02-24 15:59:23 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-02-24 15:59:22 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-02-24 15:59:18 ----D---- C:\Program Files\Common Files\System
2009-02-24 15:58:32 ----D---- C:\Program Files\ComPlus Applications
2009-02-24 15:58:30 ----A---- C:\WINDOWS\vbaddin.ini
2009-02-24 15:58:30 ----A---- C:\WINDOWS\vb.ini
2009-02-24 15:58:25 ----D---- C:\WINDOWS\Registration
2009-02-24 15:58:19 ----D---- C:\Program Files\Online Services
2009-02-24 15:58:07 ----D---- C:\Program Files\Windows Media Connect 2
2009-02-24 15:58:06 ----D---- C:\Program Files\Windows Media Player
2009-02-24 15:58:05 ----A---- C:\WINDOWS\system32\ieframe.dll.mui
2009-02-24 15:58:04 ----A---- C:\WINDOWS\system32\advpack.dll.mui
2009-02-24 15:58:03 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-02-24 15:58:03 ----D---- C:\WINDOWS\Offline Web Pages
2009-02-24 15:58:03 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2009-02-24 15:58:02 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-02-24 15:58:02 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-02-24 15:58:01 ----D---- C:\WINDOWS\wbem
2009-02-24 15:57:59 ----D---- C:\Program Files\Internet Explorer
2009-02-24 15:57:57 ----D---- C:\Program Files\Messenger
2009-02-24 15:57:55 ----D---- C:\Program Files\MSN Gaming Zone
2009-02-24 15:57:55 ----A---- C:\WINDOWS\system32\write.exe
2009-02-24 15:57:48 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-02-24 15:57:48 ----A---- C:\WINDOWS\system32\hticons.dll
2009-02-24 15:57:47 ----A---- C:\WINDOWS\system32\winchat.exe
2009-02-24 15:57:47 ----A---- C:\WINDOWS\system32\avwav.dll
2009-02-24 15:57:47 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-02-24 15:57:47 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-02-24 15:57:42 ----A---- C:\WINDOWS\system32\getuname.dll
2009-02-24 15:57:42 ----A---- C:\WINDOWS\system32\charmap.exe
2009-02-24 15:57:42 ----A---- C:\WINDOWS\system32\calc.exe
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\winmine.exe
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\sol.exe
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\reset.exe
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-02-24 15:57:41 ----A---- C:\WINDOWS\system32\freecell.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\tskill.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\tscon.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\shadow.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\regini.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\msg.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\logoff.exe
2009-02-24 15:57:40 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-02-24 15:57:39 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-02-24 15:57:38 ----A---- C:\WINDOWS\system32\stclient.dll
2009-02-24 15:57:38 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-02-24 15:57:34 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-02-24 15:57:26 ----D---- C:\Program Files\MSN
2009-02-24 15:57:25 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-02-24 15:57:25 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-02-24 15:57:25 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-02-24 15:57:25 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-02-24 15:57:24 ----D---- C:\Program Files\Windows NT
2009-02-24 15:57:24 ----A---- C:\WINDOWS\system32\spider.exe
2009-02-24 15:57:24 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-02-24 15:57:24 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-02-24 15:57:23 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-02-24 15:57:22 ----D---- C:\WINDOWS\system32\MsDtc
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-02-24 15:57:22 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-02-24 15:57:21 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-02-24 15:57:20 ----D---- C:\WINDOWS\system32\Com
2009-02-24 15:57:20 ----A---- C:\WINDOWS\system32\colbact.dll
2009-02-24 15:57:20 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-02-24 15:57:20 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-02-24 15:57:20 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-02-24 15:57:20 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-02-24 15:57:19 ----A---- C:\WINDOWS\system32\comuid.dll
2009-02-24 15:57:19 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-02-24 15:57:19 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-02-24 15:57:14 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-02-24 15:57:14 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-02-24 15:57:14 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-02-24 15:57:14 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-02-25 19:28:12 ----A---- C:\WINDOWS\win.ini
2009-02-24 21:51:07 ----A---- C:\WINDOWS\system.ini
2009-02-24 19:09:35 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-02-11 20:56:18 ----A---- C:\WINDOWS\system32\MRT.exe

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:09 pm

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2009-02-06 56280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-07-22 36096]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2009-02-06 130952]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2007-07-22 62336]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-11-06 4024832]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2009-02-06 33096]
R3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5b.sys [2004-04-15 42496]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-23 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2007-07-22 12160]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2007-07-22 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2007-07-22 59392]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2007-07-22 20608]
R3 viagfx;viagfx; C:\WINDOWS\system32\DRIVERS\vtmini.sys [2006-04-13 252416]
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
S3 GMSIPCI;GMSIPCI; \??\G:\INSTALL\GMSIPCI.SYS []
S3 NTACCESS;NTACCESS; \??\G:\NTACCESS.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\G:\NTGLM7X.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2007-07-22 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2007-07-22 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-24 152984]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-12-18 29181272]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S2 vvdsvc;VJVodServices; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2009-02-06 20680]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2009-02-24 355584]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]

-----------------EOF-----------------

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by Belahzur on Mon Mar 09, 2009 4:10 pm

Everything looks fine from here.
How's the machine running for you?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Help Me To Remove XP Police

Post by A.F.R.A.K on Mon Mar 09, 2009 4:16 pm

Thanks alot Belahzur....

machine is smooth now... Hooray!

Thank You!

A.F.R.A.K
Novice
Novice

Posts Posts : 48
Joined Joined : 2008-11-14
OS OS : Windows xp (sp2)
Points Points : 29407
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum