View Single Post
Old 05-04-2008, 04:44 AM   #1 (permalink)
aadam
Registered User
 
Join Date: Apr 2008
Posts: 8
OS: win xp sp2


Please look at my HJT log and help me..Please

I have spyware or malware as I keep getting fp-pc-on.. and the dial-up connection....I have tried various spyware removal to no effect. Your help is appreciated. Thank you

Log below:
Deckard's System Scanner v20071014.68
Run by test on 2008-05-04 12:36:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as test.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:37:20, on 04/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE
C:\PROGRA~1\Comodo\CBOClean\BOC426.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\WINDOWS\system32\crypserv.exe
C:\PROGRA~1\ADBSER~1\dbServer.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SALESSTREAM\Binn\sqlservr.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Registry Easy\RegistryEasy.exe
C:\Documents and Settings\test\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\test.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = PlusNet Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=http://www-cache.freeserve.com:8080;http=http://www-cache.freeserve.com:8080
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
F2 - REG:system.ini: UserInit=UserInit = "<data found in OldUserInit>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [BOC-426] C:\PROGRA~1\Comodo\CBOClean\BOC426.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Policies\Explorer\Run: [{00000000-05D7-C:\-0912-010531010000}] "C:\Program Files\Common Files\{00000000-05D7-C:\-0912-010531010000}\Update.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\ccprovsp.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Arsenal Database Server (DBSERVER) - Inborne Technology Corp. - C:\PROGRA~1\ADBSER~1\dbServer.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\PROGRA~1\Borland\INTERB~1\Bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\PROGRA~1\Borland\INTERB~1\Bin\ibserver.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SKAN ECR Communications Service (SKANLanService) - Inland Cash Register - C:\WINDOWS\System32\SKANLan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 10210 bytes

-- Files created between 2008-04-04 and 2008-05-04 -----------------------------

2008-05-04 12:36:36 0 d-------- C:\Program Files\Trend Micro
2008-05-04 00:43:20 0 dr-h----- C:\Documents and Settings\test\Recent
2008-05-03 19:58:55 0 d-------- C:\Program Files\NCH Software
2008-05-03 19:13:19 0 d-------- C:\Program Files\ADBServer
2008-05-03 19:12:31 0 d-------- C:\Point of Success
2008-05-03 19:12:04 0 d-------- C:\Program Files\Point of Success
2008-04-30 22:31:21 0 d-------- C:\Safe
2008-04-28 16:45:06 0 d-------- C:\Documents and Settings\All Users\Application Data\C
2008-04-28 00:10:06 0 d-------- C:\Program Files\SpywareBlaster
2008-04-27 21:10:04 262144 --a------ C:\Documents and Settings\Guest\NTUSER.DAT
2008-04-27 21:10:04 262144 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
2008-04-27 21:10:03 262144 --a------ C:\Documents and Settings\Owner\NTUSER.DAT
2008-04-27 21:10:03 262144 --a------ C:\Documents and Settings\kepos\NTUSER.DAT
2008-04-25 15:46:23 3446631 --a------ C:\WINDOWS\system32\SBSP.dat
2008-04-25 15:45:33 104 --a------ C:\WINDOWS\system32\SBRC.dat
2008-04-25 15:45:33 528 --a------ C:\WINDOWS\system32\SBFC.dat
2008-04-25 15:34:23 248 --a------ C:\WINDOWS\system32\PavCPL.dat
2008-04-21 20:21:46 0 d-------- C:\Program Files\Netcom3 Cleaner
2008-04-21 10:11:09 0 d-------- C:\Documents and Settings\All Users\Application Data\BOC426
2008-04-21 10:11:01 0 d-------- C:\Program Files\Comodo
2008-04-20 23:34:47 0 d-------- C:\Program Files\Common Files\Panda Software
2008-04-20 19:30:46 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-04-20 19:01:46 0 d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2008-04-20 18:59:57 0 d-------- C:\WINDOWS\system32\PAV
2008-04-20 09:09:43 164 --a------ C:\install.dat
2008-04-20 01:32:19 0 d-------- C:\Program Files\Panda Security
2008-04-20 01:13:42 0 d-------- C:\Program Files\XoftSpySE
2008-04-20 00:29:19 0 d-------- C:\Program Files\Registry Easy
2008-04-20 00:01:57 0 d-------- C:\Documents and Settings\test\Application Data\ErrorSmart
2008-04-17 21:59:12 11505664 --a------ C:\Documents and Settings\test\ntuser.dat
2008-04-16 21:17:01 0 d-------- C:\SPEDI
2008-04-16 21:00:54 0 d-------- C:\SPEDI Till
2008-04-16 21:00:54 0 d-------- C:\Documentation
2008-04-10 21:45:57 0 d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-10 21:36:51 0 d-------- C:\Program Files\Windows Live Toolbar
2008-04-10 21:36:39 0 d-------- C:\Program Files\Windows Live Favorites
2008-04-10 20:53:43 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-10 08:39:45 0 d-------- C:\Program Files\CCleaner


-- Find3M Report ---------------------------------------------------------------

2008-05-03 20:03:13 1632 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-05-03 17:04:42 1744 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-03 16:41:53 0 d-------- C:\Program Files\EPSON
2008-05-02 07:25:59 0 d-------- C:\Program Files\Spyware Doctor
2008-04-27 20:19:02 0 d-------- C:\Program Files\Copier 2.1
2008-04-27 20:18:58 0 d-------- C:\Program Files\Common Files\Sandlot Shared
2008-04-27 20:18:57 0 d-------- C:\Program Files\Graphic Converter 2003
2008-04-27 20:18:57 0 d-------- C:\Program Files\Common Files\Scanner
2008-04-27 20:09:54 0 d-------- C:\Program Files\Common Files
2008-04-27 20:09:29 0 d-------- C:\Program Files\ABC Amber PDF Converter
2008-04-26 15:17:31 0 d-------- C:\Program Files\380MPC
2008-04-26 15:10:02 0 d-------- C:\Documents and Settings\test\Application Data\Screenshot Sender
2008-04-26 14:00:14 0 d-------- C:\Documents and Settings\test\Application Data\MSN6
2008-04-26 11:49:36 0 d-------- C:\Program Files\Microsoft Works
2008-04-23 1823 0 d-------- C:\Program Files\Google
2008-04-23 07:32:46 0 d-------- C:\Program Files\Picasa2
2008-04-22 00:25:08 0 d-------- C:\Program Files\ewido anti-malware
2008-04-21 09:16:09 8854 --a----c- C:\WINDOWS\hh.dat
2008-04-20 18:58:19 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-20 16:08:52 0 d-------- C:\Program Files\CA
2008-04-20 08:27:40 0 d-------- C:\Program Files\Nokia
2008-04-20 08:23:55 0 d-------- C:\Program Files\NewzToolz
2008-04-20 08:10:40 0 d-------- C:\Program Files\Java
2008-04-20 00:55:10 0 d-------- C:\Program Files\Training
2008-04-20 00:55:10 0 d-------- C:\Program Files\Samsung ER650 Programming Utility
2008-04-20 00:55:10 0 d-------- C:\Program Files\SAM4S SPS1000 and SER7000 Utility
2008-04-20 00:55:09 0 d-------- C:\Program Files\pspvideo9
2008-04-20 00:55:09 0 d-------- C:\Program Files\Microsoft Money
2008-04-20 00:55:09 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-20 00:55:09 0 d-------- C:\Program Files\LimeWire
2008-04-20 00:55:06 0 d-------- C:\Program Files\Ideal POS System 4.0
2008-04-20 00:55:04 0 d-------- C:\Program Files\Disk Cleaner
2008-04-20 00:55:04 0 d-------- C:\Program Files\Common Files\fastlynx
2008-04-20 00:55:04 0 d-------- C:\Program Files\America Online 6.0
2008-04-20 00:54:41 0 d-------- C:\Documents and Settings\test\Application Data\Adobe
2008-04-19 18:58:30 0 d-------- C:\Program Files\QuickTime
2008-04-19 18:57:14 0 d-------- C:\Program Files\Windows Defender
2008-04-14 09:32:36 0 d-------- C:\Program Files\Windows Live
2008-04-10 21:24:36 0 d-------- C:\Program Files\MSN Messenger
2008-03-14 11:59:50 0 d-------- C:\Program Files\Access 97 Runtime
2008-03-06 20:08:39 97880 --a----c- C:\Documents and Settings\test\Application Data\GDIPFONTCACHEV1.DAT
2008-03-06 18:26:12 0 d-------- C:\Program Files\Lavasoft
2008-03-06 18:24:58 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-06 17:45:20 0 d-------- C:\Program Files\MSBuild
2008-03-06 17:35:34 0 d-------- C:\Program Files\Microsoft.NET
2008-03-06 17:18:46 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-03-06 17:16:52 0 d-------- C:\Program Files\Snapshot Viewer
2008-02-20 15:05:11 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
17/12/2007 11:12 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [25/10/2006 19:58]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [01/02/2008 13:55]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 05:25]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.exe" [04/10/2007 15:14]
"BOC-426"="C:\PROGRA~1\Comodo\CBOClean\BOC426.exe" [10/04/2008 11:08]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/10/2006 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 08:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"=0 (0x0)
"Btn_Search"=0 (0x0)
"NoSaveSettings"=0 (0x0)
"NoResolveTrack"=1 (0x1)
"NoThumbnailCache"=1 (0x1)
"DisableRegistryTools"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"{00000000-05D7-C:\-0912-010531010000}"="C:\Program Files\Common Files\{00000000-05D7-C:\-0912-010531010000}\Update.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 15/02/2007 20:02 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^IPS Server Monitor.lnk]
backup=C:\WINDOWS\pss\IPS Server Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Veloce Server.lnk]
backup=C:\WINDOWS\pss\Veloce Server.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^test^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^test^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BillproProtect]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cacheman]
C:\PROGRA~1\Cacheman\Cacheman.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eTrustPPAP]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\Money Express.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nzyiesp]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDRealtime]
C:\WINDOWS\realtime.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QOELOADER]
"C:\Program Files\Qurb\QSP-3.0.311.7\QOELoader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBCSTray]
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrustKeybd]
C:\PROGRA~1\Trust\270KDS~1\Keyboard\Ikeymain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse]
C:\PROGRA~1\Trust\270KDS~1\Mouse\Amoumain.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xfougk]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\_SETIMG\EPDETECT.EXE




-- End of Deckard's System Scanner: finished at 2008-05-04 12:38:55 ------------

EXTRA
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) 4 CPU 1500MHz
Percentage of Memory in Use: 72%
Physical Memory (total/avail): 511.48 MiB / 141.35 MiB
Pagefile Memory (total/avail): 1249.02 MiB / 635.51 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1908.31 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 37.22 GiB total, 9.56 GiB free.
D: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - ST340810A - 37.27 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.22 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AV: Panda Antivirus 2008 v3.01.00 (Panda Security)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\TOUCH\\touch.exe"="C:\\TOUCH\\touch.exe:*:Disabled:Touch Screen software for EPOS Markets"
"C:\\Program Files\\Alertsoft\\WINICS Retail\\Monitor.exe"="C:\\Program Files\\Alertsoft\\WINICS Retail\\Monitor.exe:*:Enabled:Nimrod - Monitor"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LEGO Media\\Constructive\\LEGO LOCO\\Exe\\Loco.exe"="C:\\Program Files\\LEGO Media\\Constructive\\LEGO LOCO\\Exe\\Loco.exe:*:Enabled:LOCO Executable"
"C:\\Program Files\\POS\\LicMan.exe"="C:\\Program Files\\POS\\LicMan.exe:*:Enabled:LicMan"
"C:\\Program Files\\Sony Ericsson\\Update Service\\ma3platform.exe"="C:\\Program Files\\Sony Ericsson\\Update Service\\ma3platform.exe:*:Enabled:ma3platform"
"C:\\Program Files\\LEGO Media\\Games\\LEGO Chess\\Lego Chess.exe"="C:\\Program Files\\LEGO Media\\Games\\LEGO Chess\\Lego Chess.exe:*:Enabled:Lego Chess"
"C:\\Program Files\\MSN Messenger\\msgr.exe"="C:\\Program Files\\MSN Messenger\\msgr.exe:*:Enabled:MSN Messenger"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Age Of Empire-II\\empires2.exe"="C:\\Age Of Empire-II\\empires2.exe:*:Enabled:Age of Empires II"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Ideal POS System 4.0\\IPSServer.exe"="C:\\Program Files\\Ideal POS System 4.0\\IPSServer.exe:*:Enabled:IPSServer"
"C:\\Program Files\\Ideal POS System 4.0\\IPS.exe"="C:\\Program Files\\Ideal POS System 4.0\\IPS.exe:*:Enabled:IPS"
"C:\\Program Files\\SPCK Software\\Doorway Blaster\\Doorway Blaster.exe"="C:\\Program Files\\SPCK Software\\Doorway Blaster\\Doorway Blaster.exe:*:Enabled:Doorway Blaster"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\test\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=YOUR-KF1Y8XKSRV
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\test
LOGONSERVER=\\YOUR-KF1Y8XKSRV
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Common Files\Adobe\AGL;C:\SYSTEM5\PVSW;C:\SYSTEM5\SPEEDY~1\\PVSW;C:\SYSTEM5\SPEEDY~1\\SPEEDY~2\\PVSW;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Panda Security\Panda Antivirus 2008\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 0 Stepping 10, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=000a
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\test\LOCALS~1\Temp
TMP=C:\DOCUME~1\test\LOCALS~1\Temp
USERDOMAIN=YOUR-KF1Y8XKSRV
USERNAME=test
USERPROFILE=C:\Documents and Settings\test
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Owner (admin)
test (admin)
kepos (new local, admin)
Administrator (new local, admin)
Guest (new local, guest)


-- Add/Remove Programs ---------------------------------------------------------

--> .
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\Temp\MVInstall\Uninst.isu
--> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {926CC8AE-8414-43DF-8EB4-CF26D9C3C663}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
America Online --> C:\Program Files\Common Files\aolshare\Aolunins_us.exe
Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
AXIS Media Control --> rundll32 "C:\Program Files\Axis Communications\AXIS Media Control\AxisMediaControl.dll",UninstallMe
AXIS Media Control Embedded --> rundll32 "C:\Program Files\Axis Communications\AXIS Media Control Embedded\AxisMediaControlEmb.dll",UninstallMe
BOClean --> C:\WINDOWS\UNBOC.EXE
CA Anti-Spyware --> "C:\Program Files\CA\eTrust Internet Security Suite\CA Anti-Spyware\setup\ccinstaller.exe" /u /silent /module="pp"
CA Anti-Spyware --> "C:\Program Files\CA\eTrust Internet Security Suite\caunst.exe" /u /product=pp
Cacheman 5.50 --> C:\PROGRA~1\Cacheman\UNWISE.EXE C:\PROGRA~1\Cacheman\install.dat
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
CES Software - Version 1.8.26 - 28/06/2002 --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.24 --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.27 (Update) --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.55 Build 10 --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.62 (03.12.03) --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.63 (30.01.04) --> C:\TOUCH\setup\setup.exe
CES TS Software - Version 1.8.64 (07.07.04) Clean Demo £ --> C:\TOUCH\setup\setup.exe
CES TS Software Installation Version 1.8.64 (18 June 2004) --> C:\TOUCH\setup\setup.exe
Client Activator 2.0 - English --> C:\WINDOWS\Rainbow Technologies\Client Activator\2.0\English\AUNINST.EXE
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
CRE 2004 --> C:\WINDOWS\uninst.exe -fC:\cre2000\DeIsL4.isu -cC:\cre2000\_ISREG32.DLL
CrystalReports --> MsiExec.exe /I{84177CE2-960D-4D6E-AA0D-DA9B022B5880}
DigitalPageAuthor Evaluation V2.4.6b DAT --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\DigitalPageAuthorEv246b DAT\ST6UNST.LOG"
Disk Cleaner (remove only) --> "C:\Program Files\Disk Cleaner\uninstall.exe"
Disney Pirates of the Caribbean Online --> C:\Program Files\Disney\Disney Online\PiratesOnline\uninst.exe
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Doorway Blaster --> C:\PROGRA~1\SPCKSO~1\DOORWA~1\UNWISE.EXE C:\PROGRA~1\SPCKSO~1\DOORWA~1\INSTALL.LOG
EPSON OPOS ADK Version 2.40 --> C:\PROGRA~1\OPOS\Epson2\Uninstaller.exe
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
ExactSEEK.com Site Submitter --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Site Submitter!\ST6UNST.LOG"
exPressit SX 3.0 --> "C:\Program Files\exPressit SX 3.0\UninstallerData\Uninstall exPressit SX 3.0.exe"
Free Internet Eraser 2.05 --> "C:\Program Files\PrivacyEraser Computing\Free Internet Eraser\unins000.exe"
Google Earth --> MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HASP HL Device Driver --> C:\WINDOWS\system32\UNWISE.EXE C:\WINDOWS\system32\hdd32.log
Highlight Viewer (Windows Live Toolbar) --> MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HTML-Kit --> "C:\Program Files\Chami\HTML-Kit\unins000.exe"
Ideal POS System 4.0 --> MsiExec.exe /X{3C550141-7965-449E-BF77-BC072E9849BF}
InternetGameBox --> C:\Program Files\InternetGameBox\uninst.exe
IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe
iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150070}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
keyboard --> C:\WINDOWS\uninst.exe -fc:\keyboard\DeIsL5.isu -cc:\keyboard\_ISREG32.DLL
Keyprint 2004 --> MsiExec.exe /I{1F7CDD0D-498F-4514-9FEC-5EC1BED32E03}
Keyprint 2004 --> MsiExec.exe /I{3685B36F-3DDD-4017-B7FB-7725E25800A8}
LEGO Chess --> C:\WINDOWS\uninst.exe -f"C:\Program Files\LEGO Media\Games\LEGO Chess\DeIsL1.isu"
LimeWire 4.16.6 --> "C:\Program Files\LimeWire\uninstall.exe"
Link Maven 1.20 --> C:\PROGRA~1\LMaven\UNINSTL.EXE C:\PROGRA~1\LMaven\INSTALL.LOG
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
LiveUpdate 1.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Map Button (Windows Live Toolbar) --> MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
Microsoft 3D Movie Maker 1.0 --> C:\PROGRA~1\MI46C1~1\COMMON~1\Setup\setup.exe /L Ms3DMu.lst /W Ms3DMu.stf
Microsoft Access 2002 Runtime --> MsiExec.exe /I{901C0409-6000-11D3-8CFE-0050048383C9}
Microsoft ActiveX Control Pad --> C:\Program Files\ActiveX Control Pad\Setup\Remove.exe
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Interactive Training --> C:\Program Files\MSPress\Training\lunins32_s.exe
Microsoft Money 2002 --> MsiExec.exe /I{E7298FD5-1386-11D5-8D6C-0050DAD32D95}
Microsoft Money 2002 System Pack --> MsiExec.exe /I{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}
Microsoft Office 2000 Disc 2 --> MsiExec.exe /I{00040409-78E1-11D2-B60F-006097C998E7}
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft SQL Server Desktop Engine (SALESSTREAM) --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
Microsoft Works 6.0 --> MsiExec.exe /I{F8D0829C-9C6F-11D3-8080-00C04FA329AA}
Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\test\Application Data\Move Networks\ie_bin\Uninst.exe
Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MyPhoneExplorer --> C:\Program Files\MyPhoneExplorer\uninstall.exe
Nokia PC Connectivity Solution --> MsiExec.exe /I{588AA47B-9115-44D3-B2E5-4F10BC659D6C}
Nokia PC Suite --> MsiExec.exe /I{508FA22B-AFFC-46CD-9441-2567976574A4}
Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Panda Antivirus 2008 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\setup.exe" -l0x9 -removeonly
PC-Link XE-A201 --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\SHARP ECR TOOL\Pclink\XE-A201\ST6UNST.LOG"
PC-Link XE-A203A213 --> MsiExec.exe /X{9DAE4152-92CF-49C7-BD10-3D1989901D88}
Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
PixNewsPro --> C:\WINDOWS\uninst.exe -f"C:\Program Files\PixNewsPro\DeIsL1.isu" -c"C:\Program Files\PixNewsPro\_ISREG32.DLL"
POSUtility --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\POSUtility\ST6UNST.LOG"
QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
Qurb --> "C:\Program Files\CA\eTrust Internet Security Suite\caunst.exe" /u /product=as
Qurb --> "C:\Program Files\Qurb\QSP-3.0.311.7\Q-Update.exe" /u
RealArcade --> C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Registry Easy v4.2 --> "C:\Program Files\Registry Easy\unins000.exe"
SalesStream Hospitality --> C:\WINDOWS\odeunst.exe -n "C:\SalesStream\Hospitality\ODEUNST.LOG"
SamPOS Utility --> C:\WINDOWS\SamPOS Utility Uninstaller.exe
SamStock V3.0.2 Evaluation --> C:\SamStock\UNWISE.EXE C:\SamStock\INSTALL.LOG
SamStock V3.0.9 --> C:\SamStock\UNWISE.EXE C:\SamStock\INSTALL.LOG
SamStock Version 4 --> C:\SAMSTO~1\UNWISE.EXE C:\SAMSTO~1\INSTALL.LOG
Samsung ER650 Utility. --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Samsung ER650 Programming Utility\ST6UNST.LOG"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Visio 2007 (KB947590) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Sentinel Default Demonstration --> C:\TOUCH\setup\setup.exe
Sentinel Retail Demonstration --> C:\TOUCH\setup\setup.exe
Sentinel System Driver --> MsiExec.exe /I{791CAF6C-90A3-11D4-8306-00D0B72E1DB9}
Shockwave --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
SmartDraw 7 --> C:\PROGRA~1\SMARTD~1\UNWISE.EXE C:\PROGRA~1\SMARTD~1\install.log
SmartSoft Video Converter --> "C:\Program Files\SmartSoftVideoConverter\unins000.exe"
SPEDI Till --> MsiExec.exe /I{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}
Speedway! --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Speedway!\Uninst.isu" -c"C:\Program Files\Speedway!\UNINST.DLL"
Speedy POS Demo --> C:\SYSTEM5\SPEEDY~1\\SPEEDY~2\\SPEEDY~1\UNWISE.EXE C:\SYSTEM5\SPEEDY~1\\SPEEDY~2\\SPEEDY~1\INSTALL.LOG
SpeedyPOS Demo --> C:\SYSTEM5\SPEEDY~1\UNWISE.EXE C:\SYSTEM5\SPEEDY~1\INSTALL.LOG
SPS1000 and SER7000 Utility --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\SAM4S SPS1000 and SER7000 Utility\ST6UNST.LOG"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe"
TAS Books Accounting --> C:\WINDOWS\IsUninst.exe -f"C:\TAS Books Accounting\Uninst.isu"
Task Easy Reports POS Software --> "C:\TaskPOS\uninstall.exe" C:\TaskPOS\install.log
Task Manager POS Software --> "C:\TaskPOS\uninstall.exe" C:\TaskPOS\install.log
Theme Hospital --> C:\WINDOWS\uninst.exe -f"C:\Program Files\Bullfrog\Hospital\DeIsL2.isu"
TimeTrax PC --> MsiExec.exe /I{84BC2E91-B20D-4400-A2DF-CB292EE72E32}
Trust 270KD Wireless Mouse --> C:\WINDOWS\system32\Amuninst.exe
Trust iKeyWorks Office 6.1 --> C:\Program Files\Trust\270KD Silverline Keyboard & Wireless Mouse\Keyboard\Uninst32.exe
Update for Office 2007 (KB946691) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb949037) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B4F188C6-6DBF-42A5-A8A3-3086D1A384F2}
Update Service --> C:\Program Files\Sony Ericsson\Update Service\uninst.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
WebBot --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\WebBot\ST6UNST.LOG"
WebFormDesigner --> C:\Program Files\WebFormDesigner\Uninstal.exe
Windows Blaster Worm Removal Tool (KB833330) --> C:\WINDOWS\$NtUninstallKB833330$\spuninst\spuninst.exe
Windows Defender --> MsiExec.exe /I{B2D7CE29-614A-4ACC-8BFE-009EB3A244C9}
Windows Defender Signatures --> MsiExec.exe /I{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}
Windows Driver Package - Nokia Modem (04/06/2006 6.8.0.17) --> C:\PROGRA~1\DIFX\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_7F91C37896B530901B0665F9EF32E19FF06F5687\nokbtmdm.inf
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Favorites for Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live OneCare Family Safety --> MsiExec.exe /X{3403CB31-D7C1-43F4-9D2F-579758C0CF09}
Windows Live Photo Gallery --> MsiExec.exe /X{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Live Toolbar Extension (Windows Live Toolbar) --> MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinICS Retail Demo --> MsiExec.exe /X{CBFA50A6-BCDA-4A2B-9C64-9774322153CF}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
YCR Modem --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\modem\ST6UNST.LOG"


-- Application Event Log -------------------------------------------------------

Event Record #/Type7380 / Warning
Event Submitted/Written: 04/28/2008 00:29:05 AM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}', feature 'AlwaysInstall' failed during request for component '{4CA981CF-CDB8-4A6A-886C-19D41BDC36F7}'

Event Record #/Type7379 / Warning
Event Submitted/Written: 04/28/2008 00:29:05 AM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}', feature 'AlwaysInstall', component '{A3F69FE1-8E4F-420A-8296-CE11C97D0E78}' failed. The resource 'C:\SPEDI Till\SPEDITill_Disk.exe' does not exist.

Event Record #/Type7377 / Warning
Event Submitted/Written: 04/28/2008 00:29:03 AM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}', feature 'AlwaysInstall' failed during request for component '{4CA981CF-CDB8-4A6A-886C-19D41BDC36F7}'

Event Record #/Type7376 / Warning
Event Submitted/Written: 04/28/2008 00:29:03 AM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}', feature 'AlwaysInstall', component '{A3F69FE1-8E4F-420A-8296-CE11C97D0E78}' failed. The resource 'C:\SPEDI Till\SPEDITill_Disk.exe' does not exist.

Event Record #/Type7374 / Warning
Event Submitted/Written: 04/28/2008 00:28:58 AM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{15CD6D80-DD32-4980-B512-EAE7C8D18DB3}', feature 'AlwaysInstall' failed during request for component '{4CA981CF-CDB8-4A6A-886C-19D41BDC36F7}'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type67071 / Error
Event Submitted/Written: 04/27/2008 06:09:48 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The SKAN ECR Communications Service service terminated with the following error:
%%183

Event Record #/Type67070 / Error
Event Submitted/Written: 04/27/2008 06:09:48 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The InterBase Guardian service failed to start due to the following error:
%%1053

Event Record #/Type67069 / Error
Event Submitted/Written: 04/27/2008 06:09:48 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the InterBase Guardian service to connect.

Event Record #/Type67068 / Warning
Event Submitted/Written: 04/27/2008 06:07:35 PM
Event ID/Source: 1007 / Dhcp
Event Description:
Your computer has automatically configured the IP address for the Network
Card with network address 00038A000011. The IP address being used is 169.254.101.152.

Event Record #/Type67050 / Error
Event Submitted/Written: 04/27/2008 10:56:24 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The SKAN ECR Communications Service service terminated with the following error:
%%183



-- End of Deckard's System Scanner: finished at 2008-04-28 00:31:50 ------------
aadam is offline