Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

WinPatrol PLUS Residual Malware??


  • This topic is locked This topic is locked
2 replies to this topic

#1 Guest_hipityhopscott_*

Guest_hipityhopscott_*

  • Guests
  • OFFLINE
  •  

Posted 19 July 2010 - 02:45 AM


Recently I installed Project64 which is an emulator for Nintendo64. It contained a trojan-- Zbot 'Zeus.' The threat was removed by Iobit Security. Although I removed it video sites for example: Youtube are much slower than before. I also took a gander in the task manager and there are 2 sometimes 3 explorer.exe and 2 taskeng.exe processes running. I'm unsure if Zbot and these processes are related. I've included my WinPatrol Hijack log. Appreciate the help! if I need it... maybe I'm just paranoid haha. thumbup2.gif





Log created by WinPatrol PLUS version 18.1.2010.0:18.1.2010.0
Scan saved at 0:13:18 AM, on 7/19/2010
Platform: Windows Vista Home Edition (Build 7600)
MSIE: Internet Explorer (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\PROGRAM FILES (X86)\IObit\ADVANCED SYSTEMCARE 3\AWC.exe
C:\PROGRAM FILES (X86)\Toshiba\UTILITIES\KeNotify.exe
C:\PROGRAM FILES\ALWIL SOFTWARE\Avast5\AvastUI.exe
C:\PROGRAM FILES (X86)\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES (X86)\IObit\IOBIT SECURITY 360\IS360TRAY.EXE
C:\PROGRAM FILES (X86)\Toshiba\CONFIGFREE\NDSTray.exe
C:\PROGRAM FILES (X86)\Toshiba\CONFIGFREE\CFSwMgr.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\PROGRAM FILES (X86)\BILLP STUDIOS\WINPATROL\WINPATROLEX.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig?brand=TSNA&bmod=TSNA
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br...A&bmod=TSNA
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br...A&bmod=TSNA
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} -
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: - Locked -
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SVPWUTIL]C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [HWSetup]C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [KeNotify]C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [ToshibaServiceStation]C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKLM\..\Run: [avast5]C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [WinPatrol PLUS]C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [IObit Security 360]C:\Program Files (x86)\IObit\IObit Security 360\IS360tray.exe /autostart
O4 - HKCU\..\Run: [swg]C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware]C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKU\..\Run: [SVPWUTIL]C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKU\..\Run: [HWSetup]C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
O4 - HKU\..\Run: [KeNotify]C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
O4 - HKU\..\Run: [ToshibaServiceStation]C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe /hide:60
O4 - HKU\..\Run: [avast5]C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui
O4 - HKU\..\Run: [WinPatrol PLUS]C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKU\..\Run: [IObit Security 360]C:\Program Files (x86)\IObit\IObit Security 360\IS360tray.exe /autostart
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O11 - Options group: [] -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_14) - http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) - http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) - http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab
O23 - Service: SAS Core Service - SUPERAntiSpyware.com - C:\PROGRAM FILES\SUPERANTISPYWARE\SASCORE64.EXE
O23 - Service: avast! Antivirus - AVAST Software - C:\PROGRAM FILES\ALWIL SOFTWARE\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\PROGRAM FILES\ALWIL SOFTWARE\Avast5\afwServ.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\PROGRAM FILES\ALWIL SOFTWARE\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\PROGRAM FILES\ALWIL SOFTWARE\Avast5\AvastSvc.exe
O23 - Service: ConfigFree WiMAX Service - TOSHIBA CORPORATION - C:\PROGRAM FILES (X86)\Toshiba\CONFIGFREE\CFIWMXSVCS64.EXE
O23 - Service: ConfigFree Gadget Service - TOSHIBA CORPORATION - C:\PROGRAM FILES (X86)\Toshiba\CONFIGFREE\CFPROCSRVC.EXE
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\PROGRAM FILES (X86)\Toshiba\CONFIGFREE\CFSvcs.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\PROGRAM FILES (X86)\TOSHIBA GAMES\TOSHIBA GAME CONSOLE\GAMECONSOLESERVICE.EXE
O23 - Service: Google Update Service (gupdate) - Google Inc. - C:\PROGRAM FILES (X86)\Google\Update\GOOGLEUPDATE.EXE
O23 - Service: Google Software Updater - Google - C:\PROGRAM FILES (X86)\Google\Common\GOOGLE UPDATER\GOOGLEUPDATERSERVICE.EXE
O23 - Service: IS360service - IObit - C:\PROGRAM FILES (X86)\IObit\IOBIT SECURITY 360\is360srv.exe
O23 - Service: Partner Service - Google Inc. - C:\PROGRAMDATA\Partner\Partner.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\PROGRAM FILES (X86)\Toshiba\TOSHIBA SERVICE STATION\TMACHINFO.EXE
O23 - Service: TOSHIBA Optical Disc Drive Service - TOSHIBA Corporation - C:\WINDOWS\SYSTEM32\TODDSRV.EXE
O23 - Service: TOSHIBA Power Saver - TOSHIBA Corporation - C:\PROGRAM FILES\TOSHIBA\POWER SAVER\TosCoSrv.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\PROGRAM FILES\TOSHIBA\TOSHIBA HDD SSD ALERT\TOSSMARTSRV.EXE
O23 - Service: Windows Defender - - C:\PROGRAM FILES (X86)\WINDOWS DEFENDER\MPSVC.DLL
O23 - Service: Windows Media Player Network Sharing Service - - C:\PROGRAM FILES (X86)\WINDOWS MEDIA PLAYER\WMPNETWK.EXE

--- Additional WinPatrol Info ---
Default Browser: Windows® Internet Explorer - Internet Explorer version 8.00.7600.16385
MSIE: Internet Explorer (8.00.7600.16385)
5 IE Cookies in Folder: C:\Users\marie\AppData\Roaming\Microsoft\Windows\Cookies\low\

WP00 - HKLM\CS1: BootExecute = autocheck autochk *
WP00 - HKLM\CCS: BootExecute = autocheck autochk *
WP00 - HKLM\CS2: BootExecute = autocheck autochk *
WP01 - HKLM\CS1: PendingFileRenameOperations = \??\C:\Users\marie\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
WP01 - HKLM\CCS: PendingFileRenameOperations = \??\C:\Users\marie\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
WP02 - HKLM\CCS: Command = C:\windows\system32\cmd.exe


WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix: Default = http://
WP08 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes: www = http://

WP31 - Scheduled Tasks: [GoogleUpdateTaskMachineCore.job]C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 07/18/2010 11:15 PM
WP31 - Scheduled Tasks: [AWC Update.job]C:\Program Files (x86)\IObit\Advanced SystemCare 3\IObitUpdate.exe 07/18/2010 3:20 PM
WP31 - Scheduled Tasks: [AWC Startup.job]C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe 07/18/2010 11:15 PM
WP31 - Scheduled Tasks: [AWC AutoSweep.job]C:\Program Files (x86)\IObit\Advanced SystemCare 3\AutoSweep.exe 07/18/2010 11:15 PM
WP31 - Scheduled Tasks: [AWC AutoCare.job]C:\Program Files (x86)\IObit\Advanced SystemCare 3\AutoCare.exe Never
WP31 - Scheduled Tasks: [GoogleUpdateTaskMachineUA.job]C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 07/19/2010 12:07 AM

WP16 - ActiveX: {00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} [Google Script Object] C:\PROGRAM FILES (X86)\Google\GOOGLE TOOLBAR\GOOGLETOOLBAR_32.DLL 6, 5, 708, 1000
WP16 - ActiveX: {25336920-03F9-11CF-8FD0-00AA00686F13} [HTML Document] C:\Windows\SysWOW64\mshtml.dll 8.00.7600.16385
WP16 - ActiveX: {2933BF90-7B36-11D2-B20E-00C04F983E60} [XML DOM Document] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {48123BC4-99D9-11D1-A6B3-00C04FD91555} [XML Document] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {6BF52A52-394A-11D3-B153-00C04F79FAA6} [Windows Media Player] C:\Windows\System32\wmp.dll 12.0.7600.16415
WP16 - ActiveX: {8856F961-340A-11D0-A96B-00C04FD705A2} [Microsoft Web Browser] C:\Windows\SysWOW64\ieframe.dll 8.00.7600.16385
WP16 - ActiveX: {88D96A05-F192-11D4-A65F-0040963251E5} [XML DOM Document 6.0] C:\Windows\System32\msxml6.dll 6.30.7600.16385
WP16 - ActiveX: {88D96A0A-F192-11D4-A65F-0040963251E5} [XML HTTP 6.0] C:\Windows\System32\msxml6.dll 6.30.7600.16385
WP16 - ActiveX: {CA8A9780-280D-11CF-A24D-444553540000} [Adobe PDF Reader] C:\PROGRAM FILES (X86)\COMMON FILES\Adobe\Acrobat\ActiveX\AcroPDF.dll
WP16 - ActiveX: {CD3AFA94-B84F-48F0-9393-7EDC34128127} [VIDEO__X_MS_WMV Moniker Class] C:\Windows\System32\wmp.dll 12.0.7600.16415
WP16 - ActiveX: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} [Microsoft Url Search Hook] C:\Windows\SysWOW64\ieframe.dll 8.00.7600.16385
WP16 - ActiveX: {D2517915-48CE-4286-970F-921E881B8C5C} [Windows Live Sign-in Control] C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WINDOWSLIVELOGIN.DLL 5.000.818.5
WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\Windows\SysWOW64\Macromed\Flash\Flash10b.ocx 10,0,22,87
WP16 - ActiveX: {DFEAF541-F3E1-4C24-ACAC-99C30715084A} [Microsoft Silverlight] C:\PROGRAM FILES (X86)\MICROSOFT SILVERLIGHT\3.0.40624.0\npctrl.dll 3.0.40624.0
WP16 - ActiveX: {ED8C108E-4349-11D2-91A4-00C04F7969E8} [XML HTTP Request] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {F5078F32-C551-11D3-89B9-0000F81FE221} [XML DOM Document 3.0] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {F5078F35-C551-11D3-89B9-0000F81FE221} [XML HTTP 3.0] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {F6D90F11-9C73-11D3-B32E-00C04F990BB4} [XML DOM Document] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {F6D90F16-9C73-11D3-B32E-00C04F990BB4} [XML HTTP] C:\Windows\System32\msxml3.dll 8.110.7600.16385
WP16 - ActiveX: {00024522-0000-0000-C000-000000000046} [RefEdit.Ctrl] C:\Program Files (x86)\Microsoft Office\Office12\REFEDIT.DLL 12.0.6413.1000
WP16 - ActiveX: {05589fa1-c356-11ce-bf01-00aa0055595a} [ActiveMovieControl Object] C:\Windows\SysWOW64\wmpdxm.dll 12.0.7600.16385
WP16 - ActiveX: {DFEAF541-F3E1-4c24-ACAC-99C30715084A} [Microsoft Silverlight] C:\PROGRAM FILES (X86)\MICROSOFT SILVERLIGHT\3.0.40624.0\npctrl.dll 3.0.40624.0
WP16 - ActiveX: {52A2AAAE-085D-4187-97EA-8C30DB990436} [HHCtrl Object] C:\Windows\System32\hhctrl.ocx 6.1.7600.16385
WP16 - ActiveX: {54CE37E0-9834-41ae-9896-4DAB69DC022B} [Microsoft RDP Client Control (redistributable) - version 5a] C:\Windows\System32\mstscax.dll 6.1.7600.16385
WP16 - ActiveX: {6A6F4B83-45C5-4ca9-BDD9-0D81C12295E4} [Microsoft RDP Client Control (redistributable) - version 4a] C:\Windows\System32\mstscax.dll 6.1.7600.16385
WP16 - ActiveX: {8856F961-340A-11D0-A96B-00C04FD705A2} [Microsoft Web Browser] C:\Windows\SysWOW64\ieframe.dll 8.00.7600.16385
WP16 - ActiveX: {8BD21D50-EC42-11CE-9E0D-00AA006002F3} [Microsoft Forms 2.0 OptionButton] C:\Windows\SysWOW64\FM20.DLL 12.0.6415.1000
WP16 - ActiveX: {971127BB-259F-48c2-BD75-5F97A3331551} [Microsoft RDP Client Control (redistributable) - version 3a] C:\Windows\System32\mstscax.dll 6.1.7600.16385
WP16 - ActiveX: {AE24FDAE-03C6-11D1-8B76-0080C744F389} [Microsoft Scriptlet Component] C:\Windows\SysWOW64\mshtml.dll 8.00.7600.16385
WP16 - ActiveX: {CA8A9780-280D-11CF-A24D-444553540000} [Adobe PDF Reader] C:\PROGRAM FILES (X86)\COMMON FILES\Adobe\Acrobat\ActiveX\AcroPDF.dll
WP16 - ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} [Shockwave Flash Object] C:\Windows\SysWOW64\Macromed\Flash\Flash10b.ocx 10,0,22,87

WP32 - Hidden File: C:\bootmgr
WP32 - Hidden File: C:\BOOTSECT.BAK
WP32 - Hidden File: C:\hiberfil.sys
WP32 - Hidden File: C:\pagefile.sys
WP32 - Hidden File: C:\Windows\WindowsShell.Manifest
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-security-lsalookup-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-security-sddl-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-service-core-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-service-management-l1-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-service-management-l2-1-0.dll
WP32 - Hidden File: C:\Windows\System32\api-ms-win-service-winsvc-l1-1-0.dll

WP33 - File Type .AVI: [Video Clip]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:8 /Open %L
WP33 - File Type .BAT: [Windows Batch File]%1 %*
WP33 - File Type .CAB: [Cabinet File]C:\windows\Explorer.exe /idlist,%I,%L
WP33 - File Type .CAT: [Security Catalog]C:\windows\system32\rundll32.exe cryptext.dll,CryptExtOpenCAT %1
WP33 - File Type .CHM: [Compiled HTML Help file]C:\windows\hh.exe %1
WP33 - File Type .COM: [MS-DOS Application]%1 %*
WP33 - File Type .CMD: [Windows Command Script]%1 %*
WP33 - File Type .DOC: [Microsoft Office Word 97 - 2003 Document]C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE /n /dde
WP33 - File Type .EML: [Windows Live Mail Mail Message]C:\Program Files (x86)\Windows Live\Mail\wlmail.exe /eml:%1
WP33 - File Type .EXE: [Application]%1 %*
WP33 - File Type .INF: [Setup Information]C:\windows\system32\NOTEPAD.EXE %1
WP33 - File Type .JS: [JScript Script File]C:\Windows\System32\WScript.exe %1 %*
WP33 - File Type .LOG: [Text Document]C:\windows\system32\NOTEPAD.EXE %1
WP33 - File Type .MSI: [Windows Installer Package]C:\windows\System32\msiexec.exe /i %1 %*
WP33 - File Type .MID: [MIDI Sequence]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /Open %L
WP33 - File Type .MP3: [MP3 Format Sound]C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:6 /Open %L
WP33 - File Type .PIF: [Shortcut to MS-DOS Program]%1 %*
WP33 - File Type .REG: [Registration Entries]regedit.exe %1
WP33 - File Type .RTF: [Rich Text Format]C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE /n /dde
WP33 - File Type .SCR: [Screen saver]%1 /S
WP33 - File Type .TXT: [Text Document]C:\windows\system32\NOTEPAD.EXE %1
WP33 - File Type .URL: [Windows host process (Rundll32)]C:\Windows\System32\rundll32.exe C:\Windows\System32\ieframe.dll,OpenURL %l
WP33 - File Type .VBS: [VBScript Script File]C:\windows\System32\WScript.exe %1 %*
WP33 - File Type .VBE: [VBScript Encoded File]C:\windows\System32\WScript.exe %1 %*
WP33 - File Type .WSF: [Windows Script File]C:\windows\System32\WScript.exe %1 %*
WP33 - File Type .WSH: [Windows Script Host Settings File]C:\windows\System32\WScript.exe %1 %*
WP33 - File Type .XLS: [Microsoft Office Excel 97-2003 Worksheet]C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE /e

Memory currently in use: 53%
Physical Memory Free: 909,508 KB
Paging File Free: 2,610,140 KB
Virtual Memory Free: 1,986,732 KB


--
End of file


BC AdBot (Login to Remove)

 


#2 Guest_hipityhopscott_*

Guest_hipityhopscott_*

  • Guests
  • OFFLINE
  •  

Posted 22 July 2010 - 04:19 PM

Post solved. I was helped by Bill from Winpatrol. Others needed your help more than I did. Thank you.

#3 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,579 posts
  • OFFLINE
  •  
  • Gender:Male

Posted 22 July 2010 - 04:23 PM

As this issue appears to be resolved I am closing the topic. Please send me (or any other Moderator) a Personal Message (PM) if you would like the topic re-opened.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users