Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all! We have been experiencing an issue on site where threads have been missing the latest postings. The platform host Vanilla are working on this issue. A workaround that has been used by some is to navigate back from 1 to 10+ pages to re-sync the thread and this will then show the latest posts. Thanks, Mike.
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Computer is acting the maggot.

  • 21-05-2007 11:16pm
    #1
    Closed Accounts Posts: 5,332 ✭✭✭


    Hello ,I've a few wee niggles to sort out with the house computer.
    Basically everyone uses this paticular one ,but it's starting to act strange.

    1. Occasionaly the keyboard won't work ,at all. The system needs a reboot.
    Have to hold the power button.

    2. internet connection dies ,if I click on comodo to take itself out of hidden mode . the internet connection will come back.
    This problem has me miffed.

    Because everyone uses it ,I can't have tea timer running or stuff that asks questions . Otherwise I get a phonecall ,WHAT IS GOING ON !:eek: :D

    Anything I can do ?,I've a feeling theres something running thats closing stuff down. But I'm not familiar with viruses,so I'm only guessing.

    Thanks,
    Brian.


Comments

  • Closed Accounts Posts: 4,469 ✭✭✭weeder


    when somthing like this happens to me i reinstall windows but someone might be able to help you fix it anot do that at all


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Try this

    Please download the self-extracting version of HijackThis from here:

    HijackThis_sfx download

    Save HijackThis_sfx to your desktop.

    Double-click the file then click the Unzip button. Then close the Self-Extractor window.

    Using My Computer/Windows Explorer, navigate to C:\Program Files\HijackThis and double click on HijackThis.exe to run it. If you would like to make a shortcut for your Desktop so it's more easily accessable, right click HijackThis.exe and choose Send To > Desktop (create shortcut).

    Please run the extracted HijackThis.exe from now on. Delete any copies of HijackThis.zip that you have saved.

    Open HijackThis and click Do a system scan and save a log file. Copy the entire contents of that log and post it here


  • Closed Accounts Posts: 5,332 ✭✭✭311


    Thanks for that help ,heres the log


  • Closed Accounts Posts: 5,332 ✭✭✭311


    I dont know whats going on there ,the attachment wont stick
    I will try and post the log on screen.


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    It's easier for me if you post the log in a reply here, instead of attaching it also :)


  • Advertisement
  • Closed Accounts Posts: 5,332 ✭✭✭311


    Logfile of HijackThis v1.99.1
    Scan saved at 08:52:39, on 22/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\WINDOWS\System32\aniServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\Comodo\Firewall\cmdagent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\PROGRA~1\Grisoft\AVG7\avgw.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Microsoft Plus! Dancer LE\DncLE.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/ig?hl=en
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Dancer] "C:\Program Files\Microsoft Plus! Dancer LE\DncLE.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155030234328
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1171121330296
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Airgo Networks NIC Service (ANISERVICE) - Airgo Networks, Inc. - C:\WINDOWS\System32\aniServ.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


  • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


    Hey can't see anything wrong with your PC, there are some things we can try though. So do the following :

    Run HijackThis, click "Do a system scan only" and check these entries :

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    close all windows except for HijackThis and click "Fix checked".

    Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
    http://www.adobe.com/products/acrobat/readstep2.html

    You now need to update your Java and remove your older versions.
    Please follow these steps to remove older version Java components.

    * Click Start > Control Panel.
    * Click Add/Remove Programs.
    * Check any item with Java Runtime Environment (JRE) in the name.
    * Click the Remove or Change/Remove button.

    Download the latest version of Java Runtime Environment (JRE), and install it to your computer.
    http://java.sun.com/javase/downloads/index.jsp
    Go to Java Runtime Environment (JRE) to get it.


    Download and Save Blacklight to your desktop (choose "I ACCEPT" then click "DOWNLOAD" on the website).

    Double-click fsbl.exe then accept the agreement, click > "Scan" then > "Next".

    You'll see a list of all items found. There will also be a log on your desktop with the name "fsbl.xxxxxxxxxxxxxx.log" (the xxxxxxxxxxxxxx stand for numbers).

    Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"

    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.


        So in your next reply, please tell me if Blacklight found anything and post the log here if it did. Same for Kaspersky webscanner.


      • Closed Accounts Posts: 5,332 ✭✭✭311


        Appreciate the help ,I tried kasper and backlight ,nothing showed up.
        I deleted the entries with hijack and downloaded the latest programs.

        Hopefully that will be problem solved ,I feel I owe you for the favour.

        In the meantime while that scanning was going on ,my laptop has begun to stop at the welcome screen ,no sign of the drive being accessed ,then about a minute later windows finishes loading.
        I will probably install a fresh windows on the laptop.

        This machine is more akward to reinstall on ,because there is six user accounts on it .
        So thanks for the help with it ,really appreciate it :)

        Brian.

        Sorry the scan was finished in kasper ,but files showed up as locked


        <title>KASPERSKY ONLINE SCANNER REPORT</title>
        <meta http-equiv='Content-Type' content='text/html; charset=utf-8'>
        </head>

        <style>
        .pagetitle { font-size:20px; color:#FFFFFF; font-family: Arial, Geneva, sans-serif; }
        .text { font-size:11px; font-family: Arial, Geneva, sans-serif; }
        TD { font-size:11px; font-family: Arial, Geneva, sans-serif; }
        </style>

        <body>
        <table width='100%' height='110' border='0'>
        <tr height='30' align='center' bgcolor='#005447'>
        <td colspan='2' height='30' class='pagetitle'>
        <b>KASPERSKY ONLINE SCANNER REPORT</b>
        </td>
        </tr>
        <tr height='70'>
        <td colspan='2' height='70'>
        Tuesday, May 22, 2007 4:51:35 PM<br>
        Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)<br>
        Kaspersky Online Scanner version: 5.0.83.0<br>
        Kaspersky Anti-Virus database last update: 22/05/2007<br>
        Kaspersky Anti-Virus database records: 306284<br>
        </td>
        </tr>
        <tr height='10'>
        <td colspan='2' height='10'>
        </td>
        </tr>
        </table>
        <table width='100%' height='145' border='0'>
        <tr height='20' bgcolor='#EFEBDE'>
        <td colspan='2' height='20'><b>Scan Settings</b></td>
        </tr>
        <tr height='15'>
        <td height='15' width='250'>Scan using the following antivirus database</td>
        <td>standard</td>
        </tr>
        <tr height='15'>
        <td height='15'>Scan Archives</td>
        <td>true</td>
        </tr>
        <tr height='15'>
        <td height='15'>Scan Mail Bases</td>
        <td>true</td>
        </tr>
        <tr height='10'>
        <td colspan='2' height='10'>
        </td>
        </tr>
        <tr height='20' bgcolor='#EFEBDE'>
        <td height='20'><b>Scan Target</b></td>
        <td>My Computer</td>
        </tr>
        <tr height='20'>
        <td colspan='2' height='20'>
        A:\<br>
        C:\<br>
        D:\<br>
        E:\<br>
        H:\<br>
        I:\
        </td>
        </tr>
        <tr height='10'>
        <td colspan='2' height='10'>
        </td>
        </tr>
        <tr height='20' bgcolor='#EFEBDE'>
        <td colspan='2' height='20'><b>Scan Statistics</b></td>
        </tr>
        <tr height='15'>
        <td height='15'>Total number of scanned objects</td>
        <td>101994</td>
        </tr>
        <tr height='15'>
        <td height='15'>Number of viruses found</td>
        <td>0</td>
        </tr>
        <tr height='15'>
        <td height='15'>Number of infected objects</td>
        <td>0 / 0</td>
        </tr>
        <tr height='15'>
        <td height='15'>Number of suspicious objects</td>
        <td>0</td>
        </tr>
        <tr height='15'>
        <td height='15'>Duration of the scan process</td>
        <td>02:02:04</td>
        </tr>
        </table>
        <br>
        <table width='100%' border='0'>
        <tr height='20' bgcolor='#EFEBDE'>
        <td height='20'><b>Infected Object Name</b></td>
        <td width='200'><b>Virus Name</b></td>
        <td width='100'><b>Last Action</b></td>
        </tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Cookies\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\History\History.IE5\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\History\History.IE5\MSHist012007052220070523\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\dnc20.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\~DFC4BA.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\~DFC4C0.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\~DFD04F.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\~DFEA8A.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temp\~DFEA90.tmp </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\Local Settings\Temporary Internet Files\Content.IE5\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\NTUSER.DAT </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\First User\ntuser.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\Cookies\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\NTUSER.DAT </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\LocalService\ntuser.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\NetworkService\NTUSER.DAT </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\Documents and Settings\NetworkService\ntuser.dat.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\System Volume Information\MountPointManagerRemoteDatabase </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\Debug\PASSWD.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\SchedLgU.Txt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\SoftwareDistribution\EventCache\{8C1ED0A4-7B36-4C19-BA9D-3AAEFD4E25A3}.bin </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\SoftwareDistribution\EventCache\{A90489E9-2C75-40F5-8293-D45F2E571935}.bin </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\SoftwareDistribution\ReportingEvents.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\Sti_Trace.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\CatRoot2\edb.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\CatRoot2\tmp.edb </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\AppEvent.Evt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\default </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\default.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\Internet.evt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SAM </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SAM.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SecEvent.Evt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SECURITY </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SECURITY.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\software </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\software.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\SysEvent.Evt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\system </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\config\system.LOG </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\h323log.txt </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\wiadebug.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\wiaservc.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>C:\WINDOWS\WindowsUpdate.log </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>D:\System Volume Information\MountPointManagerRemoteDatabase </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td height='20'>E:\System Volume Information\MountPointManagerRemoteDatabase </td>
        <td>Object is locked </td>
        <td>skipped </td>
        </tr>
        <tr><td colspan='3' height='1' bgcolor='#EFEBDE'></td></tr>
        <tr height='20'>
        <td colspan='3' height='20'><b>Scan process completed.</b></td>
        </tr>
        </table>
        </body>
        </html>


      • Closed Accounts Posts: 1,970 ✭✭✭ActorSeeksJob


        No problem for the help, I'm glad to help out people with PC problems. Sorry we couldn't find out what was wrong. However we have ruled out it being a malware/virus/rookit problem which is pretty handy. Must be some hardware problem or something like that(not my area of expertise unfortunately).


      • Closed Accounts Posts: 5,332 ✭✭✭311


        Thanks again for the help ,it was great to use a few utils like that .
        I'll keep them in mind for future reference ;)

        I work in construction ,so guidance with these things is brilliant.

        Cheers,
        Brian.


      • Advertisement
      Advertisement