followed what i saw PropogandaPanda write about these programs but i couldnt get FlashDisinfector to work. says the file cannot be saved because it cannot be read.
( i also tried to take a screenshot but for some reason it will not let me copy/paste the http link)
it looks just the same as killa57's screenshot as well as a couple others i have seen around the site concerning this bug.
anyway, here are my log results according to the guidance from killa57's post:
========== FILES ==========
c:\RECYCLER\S-1-5-21-2990273130-2400861128-3873276286-1009 moved successfully.
c:\RECYCLER moved successfully.
d:\RECYCLER moved successfully.
Folder e:\recycler not found.
Folder f:\recycler not found.
Folder g:\recycler not found.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02032009_063957
Malwarebytes' Anti-Malware 1.33
Database version: 1718
Windows 5.1.2600 Service Pack 2
2/3/2009 6:47:27 AM
mbam-log-2009-02-03 (06-47-27).txt
Scan type: Quick Scan
Objects scanned: 54935
Time elapsed: 5 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Error: Unable to interpret <c:\recycled\> in the current context!
Error: Unable to interpret <d:\recycled\> in the current context!
Error: Unable to interpret <e:\recycled\> in the current context!
Error: Unable to interpret <f:\recycled\> in the current context!
Error: Unable to interpret <g:\recycled\> in the current context!
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02032009_065730
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1726b93a-651f-11da-a100-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1726b93b-651f-11da-a100-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1726b93c-651f-11da-a100-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{484a9f20-eb72-11da-8404-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{484a9f21-eb72-11da-8404-806d6172696f}
BaseClass REG_SZ Drive
_AutorunStatus REG_BINARY 01000100000100DFDF5FDF5F5F5F5FDFDF5F5F5FDFDFDF5F5F5FDFDFDF5F5FDF5F5F5F5F5FCF5F5F5F5F5FCFCF5F5F5F5FCFCFCFCFCFDFDFDF5FDFDF0101FFFFFFFFFFFFFFFFFF000100000008000000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{484a9f22-eb72-11da-8404-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}
BaseClass REG_SZ Drive
_AutorunStatus REG_BINARY 01000100000100DFDF5FDF5F5F5F5FDFDF5F5F5FDFDFDF5F5F5FDFDFDF5F5FDF5F5F5F5F5F01000101EEFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000100000009070000
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell
<NO NAME> REG_SZ Autorun
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\Autoplay
MUIVerb REG_SZ @shell32.dll,-8504
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\Autoplay\DropTarget
CLSID REG_SZ {f26a669a-bcbb-4e37-abf9-7325da15f931}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\AutoRun
<NO NAME> REG_SZ Auto&Play
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\AutoRun\command
<NO NAME> REG_SZ C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-7-4-88-100021111-100026562-100029917-6919.com g:\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\Open
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55453ac7-f1ee-11dd-8e9e-00040b808080}\Shell\Open\command
<NO NAME> REG_SZ RECYCLER\S-7-4-88-100021111-100026562-100029917-6919.com g:\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29220-f145-11dd-8e9b-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}
BaseClass REG_SZ Drive
_CommentFromDesktopINI REG_SZ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}\Shell
<NO NAME> REG_SZ Autorun
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}\Shell\AutoRun
<NO NAME> REG_SZ Auto&Play
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}\Shell\AutoRun\command
<NO NAME> REG_SZ C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-6-0-63-100026664-100023447-100001691-5132.com d:\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}\Shell\Open
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29221-f145-11dd-8e9b-806d6172696f}\Shell\Open\command
<NO NAME> REG_SZ D:\RECYCLER\S-6-0-63-100026664-100023447-100001691-5132.com d:\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{71a29222-f145-11dd-8e9b-806d6172696f}
BaseClass REG_SZ Drive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{55453ac7-f1ee-11dd-8e9e-00040b808080}
Data REG_BINARY 360B00005C005C003F005C00530054004F005200410047004500230056006F006C0075006D006500230031002600330030006100390036003500390038002600300026005300690067006E0061007400750072006500340034004600440046004500300036004F006600660073006500740037004500300030004C0065006E00670074006800370034003700300039003800300034003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00350035003400350033006100630037002D0066003100650065002D0031003100640064002D0038006500390065002D003000300030003400300062003800300038003000380030007D005C0000004D007900200042006F006F006B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000046004100540033003200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002F00000011000000080000000190000006000000FF00000010000000D545EB47000000000000003000600000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Generation REG_DWORD 0x1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{71a29220-f145-11dd-8e9b-806d6172696f}
Data REG_BINARY 000000005C005C003F005C00530054004F005200410047004500230056006F006C0075006D006500230031002600330030006100390036003500390038002600300026005300690067006E0061007400750072006500430041004200310030004200450045004F006600660073006500740037004500300030004C0065006E00670074006800310041003200420037003700430034003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00370031006100320039003200320030002D0066003100340035002D0031003100640064002D0038006500390062002D003800300036006400360031003700320036003900360066007D005C00000050005200450053004100520049004F0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004E0054004600530000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000800000001100000FF000500FF0000003600000060A306B4000000000000003000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
Generation REG_DWORD 0x1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{71a29221-f145-11dd-8e9b-806d6172696f}
Data REG_BINARY 000000005C005C003F005C00530054004F005200410047004500230056006F006C0075006D006500230031002600330030006100390036003500390038002600300026005300690067006E0061007400750072006500430041004200310030004200450045004F006600660073006500740031004100320042004600350043003400300030004C0065006E0067007400680031004300360037003900420045003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00370031006100320039003200320031002D0066003100340035002D0031003100640064002D0038006500390062002D003800300036006400360031003700320036003900360066007D005C00000050005200450053004100520049004F005F0052005000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000046004100540033003200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000080000000110000006000000FF00000010000000C06B6E4B000000000000003000E00000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
Generation REG_DWORD 0x1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{71a29222-f145-11dd-8e9b-806d6172696f}
Data REG_BINARY 000000005C005C003F005C0049004400450023004300640052006F006D004C004900540045002D004F004E005F0043004F004D0042004F005F0053004F00480043002D0034003800330036004B005F005F005F005F005F005F005F005F005F005F005F005F005F005F005F005F00530050004A0032005F005F005F005F002300330030003300320033003600330030003300340033003000330038003300310033003000330030003300310033003000330037003300380033003400330030003200300032003000320030003200300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00370031006100320039003200320032002D0066003100340035002D0031003100640064002D0038006500390062002D003800300036006400360031003700320036003900360066007D005C00000049006E00760061006C00690064000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000049006E00760061006C00690064000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000100000001F010000BDADDBBABDADDBBABDADDBBABDADDBBABDADDBBA0000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
Generation REG_DWORD 0x1
========== FILES ==========
Folder c:\recycled not found.
d:\Recycled moved successfully.
Folder e:\recycled not found.
f:\Recycled moved successfully.
Folder g:\recycled not found.
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\\ not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a5943ea3-6e52-11dd-ad2e-0016b65751d5}\\ not found.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02032009_070110
and i still cannot open my external HD (F:) at this point. please help.
Edited by elesdee, 03 February 2009 - 09:16 PM.