1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Folders act like files

Discussion in 'Malware and Virus Removal Archive' started by bg9208, 2008/11/28.

  1. 2008/11/28
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    [Resolved] Folders act like files

    Sorry to be a pain but have a weird problem that just ocurred today.
    I have 2 hard drive, the boot drive and drive E:. On drive E: when I click on a folder I get the "Open With" window as if it is a file and I cannot access the files within the folder. On drive C: and can access files on main folders but I get the same "Open with" window on all sub-files. I attach a Hijack This log.

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Brian Owen at 2008-11-28 15:50:38
    Microsoft Windows XP Professional Service Pack 2
    System drive C: has 24 GB (31%) free of 78 GB
    Total RAM: 511 MB (28% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:50, on 28/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\crypserv.exe
    C:\Program Files\FolderSize\FolderSizeSvc.exe
    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\OrangeHSS\Launcher\Launcher.exe
    C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
    C:\Program Files\OrangeHSS\systray\systrayapp.exe
    C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
    C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
    C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
    C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Desktop\RSIT.exe
    C:\Program Files\trend micro\Brian Owen.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O2 - BHO: (no name) - {DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7} - (no file)
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe "
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe "
    O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe "
    O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe "
    O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
    O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
    O8 - Extra context menu item: Add to EverNote - res://C:\Program Files\EverNote\EverNote\enbar.dll/2000
    O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
    O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
    O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
    O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe (file missing)
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe


    --
    End of file - 8482 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\GoogleUpdateTaskUser.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
    FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2007-11-26 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DC5F9604-C6E2-47D0-8E0F-E60FCCB334C7}]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "ATIPTA "=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-05-15 339968]
    "SoundMan "=C:\WINDOWS\SOUNDMAN.EXE [2004-06-18 67584]
    "RemoteControl "=C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe [2003-10-31 32768]
    "AVG7_CC "=C:\PROGRA~1\Grisoft\AVG7\avgcc.exe [2008-10-18 590848]
    "SSBkgdUpdate "=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]
    "OpwareSE4 "=C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [2006-10-11 75304]
    "ORAHSSSessionManager "=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2007-06-12 94208]
    "QuickTime Task "=C:\Program Files\QuickTime Alternative\qttask.exe [2007-10-19 286720]
    "SunJavaUpdateSched "=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
    "InstantAccess "=C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE [2000-06-19 31744]
    "RegisterDropHandler "=C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE [2000-06-19 22528]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE "=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
    C:\Program Files\Creative\Shared Files\CamTray.exe [2003-10-13 184320]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hotkey]
    C:\Program Files\Hotkey\Hotkey.exe [2004-04-03 36864]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
    C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe [2003-12-22 86016]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
    C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
    C:\PROGRA~1\MI1933~1\Office\OSA9.EXE [1999-02-17 65588]

    C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup
    ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    Ati2evxx.dll []

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives "=0
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoResolveSearch "=
    "NoDriveTypeAutoRun "=
    "NoDrives "=
    "NoDriveAutoRun "=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "

    "C:\WINDOWS\system32\mmc.exe "= "C:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console "
    "C:\WINDOWS\system32\dpvsetup.exe "= "C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test "
    "C:\Program Files\Grisoft\AVG7\avginet.exe "= "C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe "
    "C:\Program Files\Grisoft\AVG7\avgamsvr.exe "= "C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe "
    "C:\Program Files\Grisoft\AVG7\avgcc.exe "= "C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe "
    "C:\Program Files\Grisoft\AVG7\avgemc.exe "= "C:\Program Files\Grisoft\AVG7\avgemc.exe:*:Enabled:avgemc.exe "
    "C:\Program Files\Skype\Phone\Skype.exe "= "C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
    "C:\Program Files\Avant Browser\avant.exe "= "C:\Program Files\Avant Browser\avant.exe:*:Enabled:Avant Browser "
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe "= "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger "
    "C:\Program Files\Yahoo!\Messenger\YServer.exe "= "C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server "
    "C:\Program Files\Bonjour\mDNSResponder.exe "= "C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour "
    "C:\Program Files\MSI\i-Speeder\i-Speeder.exe "= "C:\Program Files\MSI\i-Speeder\i-Speeder.exe:*:Enabled:i-Speeder "
    "C:\Program Files\Azureus\Azureus.exe "= "C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus "
    "C:\Program Files\Free Download Manager\fdm.exe "= "C:\Program Files\Free Download Manager\fdm.exe:*:Disabled:Free Download Manager "
    "C:\Program Files\I&M\MaxSea\MaxSea.exe "= "C:\Program Files\I&M\MaxSea\MaxSea.exe:*:Enabled:MaxSea "
    "C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe "= "C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    shell\AutoRun\command - E:\setupSNK.exe


    ======File associations======

    .reg - edit -
    .reg - open -

    ======List of files/folders created in the last 1 months======

    2008-11-28 15:15:47 ----SHD---- C:\RECYCLER
    2008-11-28 15:13:27 ----D---- C:\WINDOWS\temp
    2008-11-28 15:07:33 ----D---- C:\rsit
    2008-11-28 12:42:15 ----D---- C:\VB6
    2008-11-27 08:04:44 ----D---- C:\Carols
    2008-11-23 20:06:45 ----D---- C:\Linux
    2008-11-22 13:08:37 ----D---- C:\Program Files\Common Files\Adobe AIR
    2008-11-22 13:01:52 ----D---- C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    2008-11-19 08:12:24 ----D---- C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Application Data\opencpn
    2008-11-19 08:12:23 ----D---- C:\Program Files\OpenCPN
    2008-11-18 14:11:34 ----D---- C:\Program Files\Navichart-Trial
    2008-11-18 14:11:20 ----A---- C:\WINDOWS\uninst.exe
    2008-11-18 14:06:44 ----D---- C:\NAVCHART(BSB)
    2008-11-17 14:03:16 ----D---- C:\Bart
    2008-11-17 13:18:57 ----D---- C:\pebuilder3110a
    2008-11-17 12:30:07 ----A---- C:\WINDOWS\system32\TweakUI.exe
    2008-11-15 20:49:48 ----D---- C:\ubuntu
    2008-11-15 18:03:09 ----A---- C:\WINDOWS\system32\pgdfgsvc.exe
    2008-11-12 19:15:59 ----A---- C:\Boot.bak
    2008-11-12 19:15:45 ----RASHD---- C:\cmdcons
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\zip.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\VFIND.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\SWXCACLS.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\SWSC.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\SWREG.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\sed.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\NIRCMD.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\grep.exe
    2008-11-12 19:07:51 ----A---- C:\WINDOWS\fdsv.exe
    2008-11-07 19:22:14 ----D---- C:\Program Files\trend micro
    2008-11-07 16:18:37 ----D---- C:\Program Files\HijackThis
    2008-11-07 13:53:13 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-11-07 13:31:15 ----D---- C:\Program Files\Exterminate It!
    2008-11-07 12:14:46 ----A---- C:\WINDOWS\system32\0f3b8530-.txt
    2008-11-07 11:56:34 ----A---- C:\WINDOWS\iltwain.ini
    2008-11-07 11:55:58 ----D---- C:\Program Files\Earth Resource Mapping
    2008-11-07 11:53:34 ----D---- C:\bucket
    2008-11-04 10:35:22 ----A---- C:\WINDOWS\sfxthumb.ini
    2008-11-04 10:34:42 ----A---- C:\WINDOWS\system32\AWVIEW32.DLL
    2008-11-04 10:34:42 ----A---- C:\WINDOWS\system32\AWRESX32.DLL
    2008-11-04 10:34:42 ----A---- C:\WINDOWS\system32\AWDENC32.DLL
    2008-11-04 10:34:42 ----A---- C:\WINDOWS\system32\AWDCXC32.DLL
    2008-11-04 10:34:42 ----A---- C:\WINDOWS\system32\AWCODC32.DLL
    2008-11-04 10:34:30 ----A---- C:\WINDOWS\sfxalbum.ini
    2008-11-04 10:34:19 ----D---- C:\Program Files\Ssfxpro
    2008-11-04 10:27:03 ----D---- C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Application Data\Cyberlink
    2008-11-03 10:26:29 ----D---- C:\tcwf
    2008-11-03 10:19:30 ----D---- C:\Tsunamis
    2008-10-31 09:20:54 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
    2008-10-30 12:14:28 ----D---- C:\blk
    2008-10-30 12:13:03 ----D---- C:\New Folder (3)

    ======List of files/folders modified in the last 1 months======

    2008-11-28 15:49:44 ----D---- C:\WINDOWS\Prefetch
    2008-11-28 15:49:35 ----RD---- C:\Program Files
    2008-11-28 15:39:23 ----D---- C:\Program Files\Mozilla Firefox
    2008-11-28 15:25:50 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-28 15:23:46 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-28 15:13:30 ----D---- C:\WINDOWS\system32
    2008-11-28 15:13:27 ----D---- C:\WINDOWS
    2008-11-28 15:11:14 ----A---- C:\WINDOWS\system.ini
    2008-11-28 15:10:06 ----D---- C:\WINDOWS\system32\drivers
    2008-11-28 15:10:04 ----D---- C:\WINDOWS\AppPatch
    2008-11-28 15:10:04 ----D---- C:\Program Files\Common Files
    2008-11-28 12:44:21 ----D---- C:\WINDOWS\ERDNT
    2008-11-28 12:44:09 ----SHD---- C:\Config.Msi
    2008-11-28 12:44:07 ----SHD---- C:\WINDOWS\Installer
    2008-11-28 12:44:07 ----D---- C:\Program Files\Adobe
    2008-11-28 12:44:02 ----D---- C:\Program Files\Common Files\Adobe
    2008-11-28 12:43:37 ----D---- C:\WINDOWS\system32\Adobe
    2008-11-28 12:40:34 ----D---- C:\!!
    2008-11-28 11:00:41 ----D---- C:\!b(2)(2)
    2008-11-28 10:02:52 ----AC---- C:\WINDOWS\prin.bat
    2008-11-27 11:48:31 ----D---- C:\Incomplete
    2008-11-27 07:22:37 ----AC---- C:\WINDOWS\SeaDriver.ini
    2008-11-27 07:22:37 ----AC---- C:\WINDOWS\Predictor.ini
    2008-11-27 07:22:37 ----AC---- C:\WINDOWS\Maxsea.ini
    2008-11-27 07:22:33 ----AC---- C:\WINDOWS\CMapConfig.ini
    2008-11-25 08:06:15 ----D---- C:\be
    2008-11-24 15:50:26 ----D---- C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Application Data\AVG7
    2008-11-23 19:45:49 ----D---- C:\BOAT
    2008-11-22 12:09:39 ----D---- C:\Documents and Settings\Brian Owen.BRIAN-5KBUIEUHT\Application Data\Adobe
    2008-11-18 19:53:18 ----AC---- C:\WINDOWS\ALLETTER.INI
    2008-11-18 17:21:39 ----AC---- C:\WINDOWS\PSTUDIO.INI
    2008-11-18 14:50:51 ----D---- C:\WINDOWS\Help
    2008-11-17 12:26:30 ----D---- C:\Robark
    2008-11-17 10:53:31 ----AC---- C:\WINDOWS\SoftWriting.ini
    2008-11-17 10:50:57 ----D---- C:\Chenauds-gallery
    2008-11-16 10:03:26 ----HD---- C:\WINDOWS\inf
    2008-11-15 21:35:04 ----SD---- C:\WINDOWS\Tasks
    2008-11-15 21:11:04 ----RSH---- C:\boot.ini
    2008-11-15 13:48:25 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-11-15 08:23:20 ----RHD---- C:\$VAULT$.AVG
    2008-11-14 16:08:02 ----D---- C:\Program Files\OrangeHSS
    2008-11-14 11:07:52 ----SHD---- C:\WINDOWS\CSC
    2008-11-13 11:51:40 ----D---- C:\!b
    2008-11-12 19:36:43 ----D---- C:\WINDOWS\system32\config
    2008-11-07 18:08:41 ----AC---- C:\WINDOWS\ntbtlog.txt
    2008-11-07 12:20:26 ----D---- C:\WINDOWS\system32\wbem
    2008-11-07 12:20:24 ----D---- C:\WINDOWS\Registration
    2008-11-07 11:55:57 ----RSD---- C:\WINDOWS\Fonts
    2008-11-07 11:53:29 ----D---- C:\basket
    2008-11-04 10:34:30 ----D---- C:\WINDOWS\system
    2008-11-04 10:33:30 ----AC---- C:\WINDOWS\Install.ini
    2008-11-04 10:27:25 ----D---- C:\MyWorks
    2008-11-03 09:43:45 ----AC---- C:\WINDOWS\scrncapt.ini
    2008-11-02 15:46:19 ----D---- C:\Program Files\FreeCard
    2008-11-02 15:36:13 ----D---- C:\Program Files\SMS Sender
    2008-10-30 17:21:02 ----D---- C:\!b(2)
    2008-10-30 14:18:49 ----D---- C:\ash
    2008-10-30 14:17:57 ----D---- C:\1a
    2008-10-30 12:48:40 ----D---- C:\clovis
    2008-10-29 11:50:04 ----D---- C:\DOCUMENTS

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2004-08-03 37376]
    R1 Avg7Core;AVG7 Kernel; C:\WINDOWS\System32\Drivers\avg7core.sys [2007-10-25 821856]
    R1 Avg7RsW;AVG7 Wrap Driver; C:\WINDOWS\System32\Drivers\avg7rsw.sys [2007-10-09 4224]
    R1 Avg7RsXP;AVG7 Resident Driver XP; C:\WINDOWS\System32\Drivers\avg7rsxp.sys [2007-10-09 27776]
    R1 AvgClean;AVG7 Clean Driver; C:\WINDOWS\System32\Drivers\avgclean.sys [2007-12-21 10760]
    R1 BANTExt;Belarc SMBios Access; C:\WINDOWS\System32\Drivers\BANTExt.sys [2005-04-07 3840]
    R1 cdrbsvsd;cdrbsvsd; C:\WINDOWS\system32\drivers\cdrbsvsd.sys [2003-07-16 13056]
    R1 FileDisk;FileDisk; C:\WINDOWS\system32\drivers\FileDisk.sys [2005-10-16 12928]
    R1 NetworkX;NetworkX; C:\WINDOWS\system32\ckldrv.sys [2000-02-03 24608]
    R2 AvgTdi;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdi.sys [2007-10-09 4960]
    R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-21 626204]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2004-05-15 745984]
    R3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\System32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
    R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2002-09-03 9600]
    R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-09-03 12160]
    R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
    R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
    R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
    R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
    R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
    R3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
    S1 InCDPass;InCdPass; C:\WINDOWS\System32\DRIVERS\InCDPass.sys []
    S2 SENTINEL;Sentinel driver; C:\WINDOWS\system32\drivers\SENTINEL.sys []
    S3 athrusb;Atheros Wireless LAN USB device driver; C:\WINDOWS\system32\DRIVERS\athrusb.sys [2006-11-30 446976]
    S3 BRGSp50;BRGSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BRGSp50.sys [2005-06-08 20608]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
    S3 CnxTrLan;Conexant USB Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\CnxTrLan.sys [2002-10-14 22656]
    S3 CnxTrUsb;Conexant USB Network Interface Device Driver; C:\WINDOWS\system32\DRIVERS\CnxTrUsb.sys [2002-10-16 47360]
    S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
    S3 FETND5BV;VIA Rhine-Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2004-12-16 42496]
    S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
    S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service; C:\WINDOWS\System32\DRIVERS\fetnd5b.sys [2003-09-04 41984]
    S3 GMSIPCI;GMSIPCI; \??\D:\INSTALL\GMSIPCI.SYS []
    S3 GT680x;GrandTechICNameNT; C:\WINDOWS\System32\Drivers\gt680x.sys [2003-02-18 17504]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
    S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-03 40320]
    S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-06-29 42512]
    S3 NTACCESS;NTACCESS; \??\D:\NTACCESS.sys []
    S3 P1131VID;Creative WebCam NX Pro (WDM); C:\WINDOWS\system32\DRIVERS\P1131Vid.sys [2004-03-26 91241]
    S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
    S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    S3 sentemul;sentemul; \??\C:\WINDOWS\system32\drivers\sentemul.sys []
    S3 SetupNTGLM7X;SetupNTGLM7X; \??\D:\NTGLM7X.sys []
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
    S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
    S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS); C:\WINDOWS\System32\DRIVERS\zd1211Bu.sys [2006-08-24 477696]
    S4 InCDfs;InCD File System; C:\WINDOWS\system32\drivers\InCDfs.sys []
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2004-05-15 376832]
    R2 Avg7Alrt;AVG7 Alert Manager Server; C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe [2007-10-25 418816]
    R2 Avg7UpdSvc;AVG7 Update Service; C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe [2007-09-12 49664]
    R2 AVGEMS;AVG E-mail Scanner; C:\PROGRA~1\Grisoft\AVG7\avgemc.exe [2007-12-21 406528]
    R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
    R2 Crypkey License;Crypkey License; C:\WINDOWS\system32\crypserv.exe [2000-06-29 52224]
    R2 FolderSize;Folder Size; C:\Program Files\FolderSize\FolderSizeSvc.exe [2006-03-24 98304]
    R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-06-12 65536]
    R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2004-05-15 516096]
    S2 InCDsrv;InCD File System Service; C:\Program Files\Ahead\InCD\InCDsrv.exe []

    S3 Imapi Helper;Imapi Helper; C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe [2006-01-04 163840]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2007-06-29 92792]

    -----------------EOF-----------------

    Assistance would be appreciated!
     
  2. 2008/11/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi bg9208 :)

    A number of folders in C: caught my eye. Are these all legit folders?

    C:\!!
    C:\!b
    C:\!b(2)
    C:\!b(2)(2)
    C:\1a
    C:\ash
    C:\be
    C:\blk
    C:\clovis
    C:\tcwf

    The following 2 commands entered into a command window will recreate and associate the Folder file type and default actions for folders, though not sure if any of your installed programs have folder options which might be affected.

    ftype Folder=%SystemRoot%\Explorer.exe /idlist,%I,%L
    assoc Folder=Folder


    I would recommend you first export the registry key associated with Folders.
    HKEY_CLASSES_ROOT\Folder

    After completing the above, it might also be necessary to open Folder options, select Folder in the list, click Advanced, then select either open or explore and click Set Default, depending on what you choose to be the default behavior.

    Let me know if you need specific instructions for completing any of the above.
     

  3. to hide this advert.

  4. 2008/11/30
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    Hello,
    And thanks for the prompt response. All the folder you listed are legit with the exception of C:\tcwf - which I have just killed.

    I entered the two commands into the command window, they were both accepted OK and everything now seems to be fine.

    I have run "Housecall" and it reported that it had removed "WIMAD.AT ".
    I have since run ATF cleaner.
    You seem have, once again solved tge problem.

    regards
    Brian Owen
     
  5. 2008/11/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to hear that fixed the folder problem. Wimad is an infection generally associated with media files. Did you get a filename and location? Suggest you also do an online scan with Kaspersky.

    Please do an online scan with Kaspersky Online Scanner

    Click Accept, when prompted to download and install the program files and database of malware definitions.
    • Click Run at the Security prompt.
    • The program will then begin downloading and installing and will also update the database.
    • Please be patient as this can take several minutes.
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click View scan report at the bottom.
    • Click the Save Report As... button.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.


    Post the Kaspersky log here.
     
  6. 2008/12/01
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    Hello Dave,

    Sorry didn't get a file location from "Housecall ", at least I don't think so, as I don't believe that it produced a scan report however, I will look for one today and will then run Kaspersky again, got a shedload of work on the PC to do today so it probably won't be until this evening French time. Incidentally Someone sent me an online Xmas c andard with a xmas carol on an mp3 file, could this have been the problem? It does seem to date from the receipt of that email.
    Thanks again for your prompt help.

    regards

    Spoke too soon!
    The same problem has returned! - I notice that in the Tools, folder options, The edit function is disabled and although I am able to select "Explore" or "open ", neither function has any effect on enabling me to read files. Ther are also a couple of extra options added to the "open with" dialog box, one is "print folder" and the other is one of my old photo files!.
    Fortunately I can still work with the PC but this is a real pain.
    I will run Kaspersky later today and forward to you.

    regards

    Brian Owen
     
    Last edited: 2008/12/01
  7. 2008/12/01
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    The HKEY_CLASSES_ROOT\Folder which I exported as suggested had a number of sub-folders and the main file? named "PWD "
    there seem to be a lot of entries relating to acrobat reader and ACDsee 10 photo manager which I didn't know was even on my PC (I have always used ACDsee32). I have now deleted all the programme entries for this. Checking after running the suggested commands, The entries undey the HKEY_CLASSES_ROOT seem to have reverted to the exported values
    In the My Computer explorer-type listing I can click on any folder and sub folder and get a file listing in the right hand column and when I click on the file I still have to select from a dialog box the programe to open it with in most instances. I don't know if this is related but Firefox seems to take up lot of memory, with a couple of windows open just over 100,000K, is this exceptional? Kaspersky log follows.
    regards
     
  8. 2008/12/01
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    Here's the latest Kaspersky scan!

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7 REPORT
    Monday, December 1, 2008
    Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Monday, December 01, 2008 09:16:05
    Records in database: 1428907
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\

    Scan statistics:
    Files scanned: 279617
    Threat name: 0
    Infected objects: 0
    Suspicious objects: 0
    Duration of the scan: 06:22:09

    No malware has been detected. The scan area is clean.

    The selected area was scanned.

    regards

    Brian Owen
     
  9. 2008/12/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please post the contents of the previously exported key, then export it again (use a different name) and post that as well.

    If I understand correctly from your post prior to the Kaspersky scan, the folders are opening correctly and it's files that are now not opening properly. Is that correct? What type of files are they, eg; what extension do the have?
     
  10. 2008/12/04
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    Sorry if this is a bit longwinded.
    The problem doesn't seem to be just with files, mainly with sub-folders. I will try to describe more clearly. In Explorer and My Computer, When one selects a folder in the LEFT column, The files and sub folders appear in the RIGHT column - selecting files OR Sub-folders in the right column brings up the "Open With" dialog box. I can, however still open all sub folders and files as normal in the LEFT column but I am concerned that this may just be symptomatic of an underlying problem as in the set folder properties box, the edit function is disabled.
    I have noticed a perceptible slowing in printing directory listings to screen
    I have attempted to send WBBS copies of the ild and new REGEDIT logs but after many hours of waiting whilst seemingly processing the copy to function I have given up unless I can find a quicker way of doing it.
    After my last attempt today I looked in Task manager and found WMIPRV.EXE which seemed to be slowing things down. Googling tells me this is some form of Malware although a search does not find it.
    Any sugghestions of how to get the regedit logs to you?
    If it any help,When I select Folder Options then File types the File Folder, The Advanced options are : Browse with AVDSee 10 Photo manager (Which has recently been uninstalled). Find and Print directory listing. The Edit function is greyed out.
    On going back to dailog box and selecting Folder, then Advanced, the options are Explore, Open and Scan using Spybot S&D. Again the Edit function is greyed out.
     
    Last edited: 2008/12/05
  11. 2008/12/05
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    GOT IT (I think). I trolled thru WBBS looking for similar problems and found one that looked just like mine. The problem was solved by running Regsvr32 / i shell32.dll. Tried that on mine and everything now works as it should.
    Thanks again to everyone on WBBS for providing such a superb rescue service!
     
  12. 2008/12/07
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That's great news! Thanks for posting back with what worked. :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.