Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: AMD Athlon(tm) XP 3000+ Percentage of Memory in Use: 71% Physical Memory (total/avail): 447.48 MiB / 128.33 MiB Pagefile Memory (total/avail): 1730.19 MiB / 1357.24 MiB Virtual Memory (total/avail): 2047.88 MiB / 1916.79 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 147.14 GiB total, 125.96 GiB free. D: is Fixed (FAT32) - 5.5 GiB total, 0.94 GiB free. E: is CDROM (No Media) F: is CDROM (No Media) G: is Removable (No Media) H: is Removable (No Media) I: is Removable (No Media) J: is Removable (No Media) \\.\PHYSICALDRIVE0 - Maxtor 6Y160P0 - 152.67 GiB - 2 partitions \PARTITION0 - Unknown - 5.52 GiB - D: \PARTITION1 (bootable) - Installable File System - 147.14 GiB - C: \\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device \\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device \\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device \\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. FW: ZoomTown Internet Security 6.15 v6.15 (F-Secure Corporation) AV: ZoomTown Internet Security 6.15 v6.15 (F-Secure Corporation) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Program Files\\ZoomTown Internet Security\\backweb\\7128158\\Program\\fspex.exe"="C:\\Program Files\\ZoomTown Internet Security\\backweb\\7128158\\Program\\fspex.exe:*:Enabled:ZoomTown Internet Security" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Paltalk Messenger\\paltalk8.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk8.exe:*:Enabled:Paltalk Messenger 8.0" "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox" "C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe"="C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe:*:Enabled:Spy Sweeper" "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk" "C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk Messenger 8.3" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Program Files\\ZoomTown Internet Security\\backweb\\7128158\\Program\\fspex.exe"="C:\\Program Files\\ZoomTown Internet Security\\backweb\\7128158\\Program\\fspex.exe:*:Enabled:ZoomTown Internet Security" "C:\\Program Files\\Rhapsody\\rhapsody.exe"="C:\\Program Files\\Rhapsody\\rhapsody.exe:*:Enabled:Rhapsody Media Player" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Juno\\bin\\juno.exe"="C:\\Program Files\\Juno\\bin\\juno.exe:*:Enabled:Juno" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Owner\Application Data CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=WAYTRISHGROUP ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Owner LOGONSERVER=\\WAYTRISHGROUP NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0a00 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp USERDOMAIN=WAYTRISHGROUP USERNAME=Owner USERPROFILE=C:\Documents and Settings\Owner windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Owner [I](admin)[/I] Administrator [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware Scanner" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus Client Security Installer" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure DAAS" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Diagnostics" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure E-mail Scanning" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure FWES" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure GUI" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Help" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Internet Shield" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Management Agent" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Spam Control" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Spam Scanner" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure TNB" --> "C:\Program Files\ZoomTown Internet Security\fsuninst.exe" /UninstRegKey:"F-Secure Web Filter" --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvhp.inf --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf --> VTUninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Timer' 3D ULTRA PINBALL --> C:\WINDOWS\IsUninst.exe -f"C:\SIERRA\3D ULTRA PINBALL\Uninst.isu" Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG Adobe Atmosphere Player for Acrobat and Adobe Reader --> C:\WINDOWS\atmoUn.exe Adobe Download Manager 2.0 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe" Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete Adobe Reader 7.0.8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70500000002} American Greetings CreataCard Select 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9770A25C-45A7-478E-AF50-4FDE53EED270}\setup.exe" -l0x9 anything ArcSoft ShowBiz 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{791B20D4-AE59-4DE9-B45F-BA01F3D0A493}\setup.exe" -l0x9 ArcSoft Software Suite --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F57D8342-E2E4-46F4-915A-F50817CBCB45}\setup.exe" -l0x9 AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe Belarc Advisor 6.1 --> C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG Bicycle Board Games 2.0 --> "C:\Program Files\Microsoft Games\Bicycle Board Games 2.0\UNINSTAL.EXE" /runtemp /addremove Bicycle Card Games 1.0 Demo --> "C:\Program Files\Microsoft Games\Bicycle Card Games 1.0 Demo\UNINSTAL.EXE" /runtemp /addremove Bid Whist Challenge --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Bid Whist Challenge\ST6UNST.LOG" Big Fish Games Client --> C:\Program Files\bfgclient\Uninstall.exe Bookworm Deluxe 1.13 --> C:\Program Files\PopCap Games\Bookworm Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Bookworm Deluxe\Install.log" Business Card Designer Plus --> C:\Program Files\CAM Development\Business Card\SETUP.EXE UNINSTAL.INF Business Card Designer Plus 8.2.0.0 --> "C:\Program Files\CAM Development\Business Card Designer Plus 8\Uninstall\unins000.exe" Canon i250 --> C:\WINDOWS\System32\CNMCP50.exe "-PRINTERNAMECanon i250" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon i250 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon i250 Installer\Inst2\cnmi0409.dll" Canon Utilities Easy-PhotoPrint --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Canon\Easy-PhotoPrint\Uninst.isu" -c"C:\Program Files\Canon\Easy-PhotoPrint\EZUNINST.DLL" CaptureSaver V3.1.352 --> "C:\Program Files\CaptureSaver\unins000.exe" CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe" Concentration (remove only) --> "C:\Program Files\Concentration\Uninstall.exe" CT Cookie Spy --> C:\PROGRA~1\Camtech\CTCOOK~1\UNWISE.EXE C:\PROGRA~1\Camtech\CTCOOK~1\INSTALL.LOG DrawPlus 3.0 --> C:\WINDOWS\UNINST.EXE -f"C:\PROGRA~1\BRODER~1\DrawPlus\DeIsL1.isu" Easy-WebPrint --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu" Excavation from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\C56C66C3-3462-4A3F-8661-9E18362A5E7C\Uninstall.exe" Five Card Frenzy from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\DA44615A-C243-46A4-8E47-184CFF33CD38\Uninstall.exe" Form Fill (Windows Live Toolbar) --> MsiExec.exe /X{548B3DC6-2300-47E1-BA7B-74AD25F8DEBF} G-Force --> C:\Program Files\SoundSpectrum\G-Force\Uninstall.exe Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly Google Talk (remove only) --> "C:\Program Files\Google\Google Talk\uninstall.exe" Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll" Google Video Player --> "C:\Program Files\Google\Google Video Player\Uninstall.exe" HijackThis 2.0.2 --> "C:\HJT\HijackThis.exe" /uninstall Home Attorney --> C:\PROGRA~1\HOMEAT~1\Uninstal.exe C:\PROGRA~1\HOMEAT~1\Install.log Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" Hoyle Board Games 2005 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98936CBC-5E7A-4AD7-B05B-6D34C7C68E37}\setup.exe" -l0x9 -removeonly Hoyle Card Games 2004 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{744F6CCF-9F56-40A0-A33D-2A45D53B6046} HP Deskjet Preloaded Printer Drivers --> MsiExec.exe /X{F419D20A-7719-4639-8E30-C073A040D878} HP Instant Support --> C:\PROGRA~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HPINST~1\INSTALL.LOG HP Organize --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}\Setup.exe" UNINSTALL HP Photo & Imaging 3.1 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat HP Photo and Imaging 2.0 - Photosmart Cameras --> MsiExec.exe /X{5D7F0A0E-369E-46C0-9F99-FAB21A064781} HP PSC & OfficeJet 3.0 --> "C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\setup\hpzscr01.exe" -datfile hposcr03.dat HP Software Update --> MsiExec.exe /X{CC0A24CB-87C9-4F1C-A1F2-F87D8D4DDCAF} HPIZ311 --> MsiExec.exe /X{F247869D-3643-4A9F-821B-3534145928E3} inSpeak build 420 --> "C:\Program Files\inSpeak\unins000.exe" Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572 IntelliMover Data Transfer Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9 InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL IsoBuster 1.6 --> "C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe" ItsDeductible Express --> MsiExec.exe /I{36495C59-089C-49D1-BD15-9E5BD86DC9A1} Java 2 Runtime Environment, SE v1.4.2 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142000} Juno --> "C:\Program Files\Juno7\uninst.exe" Juno --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92F36672-245D-11D5-AC74-00105A0CF83E}\setup.exe" Uninstall Juno Connection Wizard --> "C:\Program Files\Connection Wizard\unInstall.exe" Juno SpeedBand (remove only) --> "C:\Program Files\Juno7\uninstacc.exe" KBD --> C:\HP\KBD\KBD.EXE uninstalled Links LS 1998 --> C:\WINDOWS\uninst.exe -f"C:\Program Files\LinksLS98\DeIsL1.isu" Luxor --> C:\PROGRA~1\SHOCKW~1.COM\Luxor\UNWISE.EXE C:\PROGRA~1\SHOCKW~1.COM\Luxor\INSTALL.LOG Luxor 2 --> C:\PROGRA~1\SHOCKW~1.COM\LUXOR2~1\UNWISE.EXE C:\PROGRA~1\SHOCKW~1.COM\LUXOR2~1\INSTALL.LOG Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log MalwareWiped 6.4 --> C:\Program Files\MW\MalwareWiped 6.4\uninst.exe Map Button (Windows Live Toolbar) --> MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA} Media Library Management Wizard --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplibwiz.inf,DefaultUninstall Memories Disc Creator 2.0 --> MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA} Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Money 2004 --> MsiExec.exe /I{1D643CD7-4DD6-11D7-A4E0-000874180BB3} Microsoft Money 2004 System Pack --> MsiExec.exe /I{8C64E145-54BA-11D6-91B1-00500462BE80} Microsoft Office 2000 SR-1 Disc 2 --> MsiExec.exe /I{00040409-78E1-11D2-B60F-006097C998E7} Microsoft Office 2000 SR-1 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7} Microsoft Plus! Digital Media Edition --> MsiExec.exe /I{C6A7AF96-4EB1-4AAE-8318-1AB393C64F88} Microsoft Publisher 2000 Resume Wizard --> MsiExec.exe /I{95612A0C-0FAA-11D3-8258-00C04F6843FE} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84} mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall Monopoly --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Hasbro Interactive\Monopoly\Uninst.isu" Movie Maker Background Music Files --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmmusic.inf,DefaultUninstall Movie Maker Sound Effects --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmsounds.inf,DefaultUninstall Movie Maker Title Images --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmtitle.inf,DefaultUninstall Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSN Gaming Zone --> C:\PROGRA~1\MSNGAM~1\zsetup.exe /Uninstall Multimedia Card Reader --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{145CACAF-9B34-41FC-BE49-7D510A253E78} Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst My Search Bar --> rundll32 C:\PROGRA~1\MySearch\bar\1.bin\s4bar.dll,O Mystery Case Files: Huntsville (remove only) --> "C:\Program Files\Mystery Case Files - Huntsville\Uninstall.exe" Mystery Case Files: Prime Suspects (remove only) --> "C:\Program Files\Mystery Case Files - Prime Suspects\Uninstall.exe" Nero 7 Demo --> MsiExec.exe /I{0D9E1F52-CE29-B03B-D79F-8EC434821033} NVIDIA GART Driver --> C:\WINDOWS\System32\nvugart.exe Uninstall C:\WINDOWS\System32\Nvgart.nvu,NVIDIA GART Driver Office Animation Runtime --> MsiExec.exe /X{AEEB3643-71DE-414d-9E3F-1159177FE211} OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{DF821FC5-C198-452B-A0D4-82433EFEAE9B} Orbital from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\62067F4C-84A9-45B9-8573-B90468B0A3EF\Uninstall.exe" Otto from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\BFBCBAE3-8293-4215-9C4F-C2402C118EDB\Uninstall.exe" Overball from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\6723E59E-322A-417A-8E03-27A61E18253C\Uninstall.exe" PaintBrawl --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\HeadGames\PaintBrawl\UnInst.isu" Paltalk --> C:\Paltalk\puninstall.exe Paltalk Messenger --> C:\WINDOWS\iun6002.exe "C:\Program Files\Paltalk Messenger\irunin.ini" PaltalkScene --> "C:\WINDOWS\Paltalk Messenger\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml" Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan Photosmart 140,240,7200,7600,7700,7900 Series --> C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\setup\hpzscr01.exe -datfile hphscr01.dat Plus! MP3 Audio Converter LE --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\audcle.inf,DefaultUninstall Popup Blocker (Windows Live Toolbar) --> MsiExec.exe /X{66A7A386-6F35-41A7-A731-101F0C0153C8} PrintMaster --> C:\WINDOWS\UNINST.EXE -f"C:\PROGRA~1\BRODER~1\PRINTM~1\DeIsL1.isu" -c"C:\PROGRA~1\BRODER~1\PRINTM~1\psfinst.dll" PrintMaster Gold 4.00 --> c:\pmw\msrun.exe PS2 --> C:\WINDOWS\system32\ps2.exe uninstall pwhukisr --> c:\windows\system32\pwhukisr.exe -uninstall Python 2.2 combined Win32 extensions --> C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log Python 2.2.1 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG Quicken 2004 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{54DE0B75-6CD9-44C4-B10A-1F25DA9899D8} anything RealArcade --> C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2 RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19} Rhapsody --> C:\PROGRA~1\Rhapsody\Unwise32.exe /A C:\PROGRA~1\Rhapsody\INSTALL.LOG Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} S3 S3Display --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display' S3 S3Gamma2 --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2' S3 S3Info2 --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2' S3 S3Overlay --> vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay' Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe" Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" Sierra Utilities --> C:\Program Files\Sierra On-Line\sutil32.exe uninstall SigmaTel MSCN Audio Player --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8E240C1C-25D0-4248-BC6C-ACC3472E35CE}\setup.exe" -l0x9 Slyder from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\C2C3C2DB-7D8A-4E20-B527-E3149FAECC3A\Uninstall.exe" Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D} Starware 4.4.2.0 --> C:\Program Files\Starware337\Starware337Uninstall.exe TaxACT 2004 --> C:\PROGRA~1\2NDSTO~1\TAXACT~1\Unta04.exe C:\PROGRA~1\2NDSTO~1\TAXACT~1\Install.log TaxACT 2006 --> C:\PROGRA~1\2NDSTO~1\TAXACT~2\Unta06.exe C:\PROGRA~1\2NDSTO~1\TAXACT~2\Install.log Tiger Woods 99 PGA TOUR Golf --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\Uninst.isu toolkit --> c:\Windows\HPTK\unhptkit.exe Total Cleaner 1.0.7 --> C:\Program Files\Total Cleaner\uninst.exe TurboTax Deluxe 2003 --> C:\Program Files\TurboTax\Deluxe 2003\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2003\Uninstall.log" -NoGui TurboTax Deluxe 2004 --> C:\Program Files\TurboTax\Deluxe 2004\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2004\Uninstall.log" -NoGui TurboTax Deluxe 2005 --> C:\Program Files\TurboTax\Deluxe 2005\TaxUnst.EXE "C:\Program Files\TurboTax\Deluxe 2005\Uninstall.log" -NoGui TurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107} Ultimate Bid Whist --> C:\WINDOWS\ST5UNST.EXE -n "C:\Program Files\Ultimate Bid Whist\ST5UNST.LOG" Uninstall JL2005A Toy Camera --> "C:\Program Files\JL2005A\unins000.exe" Updates from HP --> C:\WINDOWS\BWUnin-6.2.3.66.exe -AppId 137903 VIA Rhine-Family Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA VIA/S3G Display Driver --> VTsetvga.exe -s -rRundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\system32\hg201hp.inf Viewpoint Manager (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe /u /k WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\setup.exe" -l0x9 -eliminate WildTangent GameChannel (remove only) --> "C:\Program Files\WildTangent\Apps\uninstallgamechannel.exe" WildTangent Web Driver --> C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe Windows Defender --> MsiExec.exe /I{B2D7CE29-614A-4ACC-8BFE-009EB3A244C9} Windows Defender Signatures --> MsiExec.exe /I{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C} Windows Desktop Search --> "C:\WINDOWS\$NtUninstallKB911993-V2$\spuninst\spuninst.exe" Windows Live Favorites for Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66} Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F} Windows Live Outlook Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE} Windows Live Sign-in Assistant --> MsiExec.exe /I{F652D238-5F29-42D5-BAF3-0115EF977EC2} Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750} Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750} Windows Live Toolbar Extension (Windows Live Toolbar) --> MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D} Windows Live Toolbar Feed Detector (Windows Live Toolbar) --> MsiExec.exe /X{68108E66-D13A-4EE8-A6F4-40E4B90C2A26} Windows Media Bonus Pack for Windows XP --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmbonus.inf,DefaultUninstall Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe Word Mojo Deluxe --> C:\PROGRA~1\ZONE~1.COM\WORDMO~1\UNWISE.EXE C:\PROGRA~1\ZONE~1.COM\WORDMO~1\INSTALL.LOG Yahoo! extras --> C:\PROGRA~1\Yahoo!\Common\unyext.exe Yahoo! Install Manager --> C:\WINDOWS\System32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe Yahtzee --> C:\WINDOWS\uninst.exe -fC:\WINDOWS\DeIsL1.isu You Don't Know Jack The Ride --> C:\WINDOWS\IsUninst.exe -f"C:\SIERRA\Jack The Ride\Uninst.isu" Zone Deluxe Games --> MsiExec.exe /I{66C018BD-6F16-4B32-B4CD-1DC1B21FBDFF} ZoomTown Internet Security --> C:\PROGRA~1\ZOOMTO~2\Common\fsbwih.exe /uninstall Zuma Deluxe 1.0 --> C:\Program Files\Zone.Com Deluxe Games\Zuma Deluxe\ZumaDeluxeUninstaller.exe "C:\Program Files\Zone.Com Deluxe Games\Zuma Deluxe\Install.log" -- Application Event Log ------------------------------------------------------- Event Record #/Type8447 / Error Event Submitted/Written: 12/21/2007 00:23:48 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 9 2007-12-21 00:23:48-04:00 waytrishgroup WAYTRISHGROUP\Owner F-Secure Anti-Virus No scanner engines loaded and enabled. Virus protection is disabled. Event Record #/Type8446 / Error Event Submitted/Written: 12/21/2007 00:23:47 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 8 2007-12-21 00:23:47-04:00 waytrishgroup WAYTRISHGROUP\Owner F-Secure Anti-Virus Crash detected. Event Record #/Type8445 / Error Event Submitted/Written: 12/21/2007 00:23:39 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 7 2007-12-21 00:23:39-04:00 waytrishgroup WAYTRISHGROUP\Owner F-Secure Anti-Virus Crash detected. Event Record #/Type8444 / Error Event Submitted/Written: 12/21/2007 00:23:27 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 6 2007-12-21 00:23:27-04:00 waytrishgroup WAYTRISHGROUP\Owner F-Secure Anti-Virus No scanner engines loaded and enabled. Virus protection is disabled. Event Record #/Type8443 / Error Event Submitted/Written: 12/21/2007 00:23:22 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 5 2007-12-21 00:23:21-04:00 waytrishgroup WAYTRISHGROUP\Owner F-Secure Anti-Virus Crash detected. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type40229 / Warning Event Submitted/Written: 12/21/2007 00:31:45 PM Event ID/Source: 1003 / Dhcp Event Description: Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 000FDB552DEE. The following error occurred: %%1223. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. Event Record #/Type40228 / Error Event Submitted/Written: 12/21/2007 00:31:44 PM Event ID/Source: 20106 / RemoteAccess Event Description: Unable to add the interface {A17ED2B8-A3EF-4FD4-853B-FDA561B5B8FB} with the Router Manager for the IP protocol. The following error occurred: Cannot complete this function. Event Record #/Type40227 / Error Event Submitted/Written: 12/21/2007 00:31:44 PM Event ID/Source: 20106 / RemoteAccess Event Description: Unable to add the interface {A17ED2B8-A3EF-4FD4-853B-FDA561B5B8FB} with the Router Manager for the IP protocol. The following error occurred: Cannot complete this function. Event Record #/Type40225 / Warning Event Submitted/Written: 12/21/2007 00:28:49 PM Event ID/Source: 1003 / Dhcp Event Description: Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 000FDB552DEE. The following error occurred: %%1223. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. Event Record #/Type40224 / Error Event Submitted/Written: 12/21/2007 00:28:49 PM Event ID/Source: 20106 / RemoteAccess Event Description: Unable to add the interface {A17ED2B8-A3EF-4FD4-853B-FDA561B5B8FB} with the Router Manager for the IP protocol. The following error occurred: Cannot complete this function. -- End of Deckard's System Scanner: finished at 2007-12-21 12:51:06 ------------