boatnerd06
New member
Their is no OS running on the F:/ drive, however it does seem to be infected with something as their is a $RECYCLE.BIN folder
mgadiag.txt
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-TV7MC-7MV9J-KJ3TY
Windows Product Key Hash: lCbeR4W9iEXWpqMYUWEzLtdzIi8=
Windows Product ID: 00371-152-2839481-85843
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {28DB8098-55C5-4C0D-833E-906BF774C36D}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Professional
Architecture: 0x00000000
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 103 Blocked VLK
Microsoft Office Access 2007 - 100 Genuine
Microsoft Office Excel 2007 - 103 Blocked VLK
Microsoft Office PowerPoint 2007 - 103 Blocked VLK
Microsoft Office Publisher 2007 - 100 Genuine
Microsoft Office Outlook 2007 - 100 Genuine
Microsoft Office Word 2007 - 103 Blocked VLK
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{28DB8098-55C5-4C0D-833E-906BF774C36D}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-KJ3TY</PKey><PID>00371-152-2839481-85843</PID><PIDType>5</PIDType><SID>S-1-5-21-541655578-1006378361-3361530724</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F6</Version><SMBIOSVersion major="2" minor="4"/><Date>20081114000000.000000+000</Date></BIOS><HWID>D1CC3907018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>103</Result><Products><Product GUID="{90120000-0015-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Access 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89384-707-0356806-63147</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0016-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Excel 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89385-707-0356806-63210</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0018-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office PowerPoint 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89400-707-0356806-63925</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0019-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Publisher 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89404-707-0356806-63595</Pid><PidType>14</PidType></Product><Product GUID="{90120000-001A-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Outlook 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89399-707-0356806-63075</Pid><PidType>14</PidType></Product><Product GUID="{90120000-001B-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Word 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89407-707-0356806-63723</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="103"/><App Id="18" Version="12" Result="103"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="103"/></Applications></Office></Software></GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Professional edition
Description: Windows Operating System - Windows(R) 7, RETAIL channel
Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00371-00170-152-283948-01-1033-7600.0000-3172009
Installation ID: 012843030550324256174432524860840414971714476816553442
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: KJ3TY
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 5/29/2012 9:35:50 AM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000003EFFF
Event Time Stamp: 5:27:2012 16:44
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\wat\watadminsvc.exe
Tampered File: %systemroot%\system32\wat\watweb.dll
Tampered File: %systemroot%\system32\wat\npwatweb.dll
Tampered File: %systemroot%\system32\wat\watux.exe
Tampered File: %systemroot%\system32\sppobjs.dll
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\sppwinob.dll
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
Tampered File: %systemroot%\system32\drivers\spsys.sys
Tampered File: %systemroot%\system32\drivers\spldr.sys
HWID Data-->
HWID Hash Current: RAAAAAIABgABAAIAAgABAAAABQABAAEA6GGE2Wrw7+2ENAiFwo8MNUa85L+gRc5w4HmC3o3vKs9OEwbV1jCuJa8lRso=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC GBT GBTUACPI
FACP GBT GBTUACPI
HPET GBT GBTUACPI
MCFG GBT GBTUACPI
EUDS GBT
SSDT PmRef CpuPm
mgadiag.txt
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Code: 0x8004FE21
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-TV7MC-7MV9J-KJ3TY
Windows Product Key Hash: lCbeR4W9iEXWpqMYUWEzLtdzIi8=
Windows Product ID: 00371-152-2839481-85843
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7601.2.00010100.1.0.048
ID: {28DB8098-55C5-4C0D-833E-906BF774C36D}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Professional
Architecture: 0x00000000
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/A
Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: Microsoft
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 103 Blocked VLK
Microsoft Office Access 2007 - 100 Genuine
Microsoft Office Excel 2007 - 103 Blocked VLK
Microsoft Office PowerPoint 2007 - 103 Blocked VLK
Microsoft Office Publisher 2007 - 100 Genuine
Microsoft Office Outlook 2007 - 100 Genuine
Microsoft Office Word 2007 - 103 Blocked VLK
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{28DB8098-55C5-4C0D-833E-906BF774C36D}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010100.1.0.048</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-KJ3TY</PKey><PID>00371-152-2839481-85843</PID><PIDType>5</PIDType><SID>S-1-5-21-541655578-1006378361-3361530724</SID><SYSTEM><Manufacturer>Gigabyte Technology Co., Ltd.</Manufacturer><Model>EP45-UD3P</Model></SYSTEM><BIOS><Manufacturer>Award Software International, Inc.</Manufacturer><Version>F6</Version><SMBIOSVersion major="2" minor="4"/><Date>20081114000000.000000+000</Date></BIOS><HWID>D1CC3907018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>103</Result><Products><Product GUID="{90120000-0015-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Access 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89384-707-0356806-63147</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0016-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Excel 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89385-707-0356806-63210</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0018-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office PowerPoint 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89400-707-0356806-63925</Pid><PidType>14</PidType></Product><Product GUID="{90120000-0019-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Publisher 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89404-707-0356806-63595</Pid><PidType>14</PidType></Product><Product GUID="{90120000-001A-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Outlook 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89399-707-0356806-63075</Pid><PidType>14</PidType></Product><Product GUID="{90120000-001B-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Word 2007</Name><Ver>12</Ver><Val>437005356259D86</Val><Hash>G5Qjl2nuHEjAmcG9TDdU8SHIOkc=</Hash><Pid>89407-707-0356806-63723</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="103"/><App Id="18" Version="12" Result="103"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="103"/></Applications></Office></Software></GenuineResults>
Spsys.log Content: 0x80070002
Licensing Data-->
Software licensing service version: 6.1.7601.17514
Name: Windows(R) 7, Professional edition
Description: Windows Operating System - Windows(R) 7, RETAIL channel
Activation ID: e838d943-63ed-4a0b-9fb1-47152908acc9
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 00371-00170-152-283948-01-1033-7600.0000-3172009
Installation ID: 012843030550324256174432524860840414971714476816553442
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88338
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88339
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88341
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88340
Partial Product Key: KJ3TY
License Status: Licensed
Remaining Windows rearm count: 4
Trusted time: 5/29/2012 9:35:50 AM
Windows Activation Technologies-->
HrOffline: 0x8004FE21
HrOnline: N/A
HealthStatus: 0x000000000003EFFF
Event Time Stamp: 5:27:2012 16:44
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:
Tampered File: %systemroot%\system32\wat\watadminsvc.exe
Tampered File: %systemroot%\system32\wat\watweb.dll
Tampered File: %systemroot%\system32\wat\npwatweb.dll
Tampered File: %systemroot%\system32\wat\watux.exe
Tampered File: %systemroot%\system32\sppobjs.dll
Tampered File: %systemroot%\system32\sppc.dll|sppc.dll.mui
Tampered File: %systemroot%\system32\sppcext.dll|sppcext.dll.mui
Tampered File: %systemroot%\system32\sppwinob.dll
Tampered File: %systemroot%\system32\slc.dll|slc.dll.mui
Tampered File: %systemroot%\system32\slcext.dll|slcext.dll.mui
Tampered File: %systemroot%\system32\sppuinotify.dll|sppuinotify.dll.mui
Tampered File: %systemroot%\system32\slui.exe|slui.exe.mui|COM Registration
Tampered File: %systemroot%\system32\sppcomapi.dll|sppcomapi.dll.mui
Tampered File: %systemroot%\system32\sppcommdlg.dll|sppcommdlg.dll.mui
Tampered File: %systemroot%\system32\sppsvc.exe|sppsvc.exe.mui
Tampered File: %systemroot%\system32\drivers\spsys.sys
Tampered File: %systemroot%\system32\drivers\spldr.sys
HWID Data-->
HWID Hash Current: RAAAAAIABgABAAIAAgABAAAABQABAAEA6GGE2Wrw7+2ENAiFwo8MNUa85L+gRc5w4HmC3o3vKs9OEwbV1jCuJa8lRso=
OEM Activation 1.0 Data-->
N/A
OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC GBT GBTUACPI
FACP GBT GBTUACPI
HPET GBT GBTUACPI
MCFG GBT GBTUACPI
EUDS GBT
SSDT PmRef CpuPm