Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Mobile Intel(R) Pentium(R) 4 - M CPU 1.80GHz Percentage of Memory in Use: 75% Physical Memory (total/avail): 510.98 MiB / 125.77 MiB Pagefile Memory (total/avail): 865.68 MiB / 409.79 MiB Virtual Memory (total/avail): 2047.88 MiB / 1928.98 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 27.91 GiB total, 19.21 GiB free. D: is CDROM (No Media) \\.\PHYSICALDRIVE0 - FUJITSU MHS2030AT - 27.95 GiB - 2 partitions \PARTITION0 - Unknown - 31.35 MiB \PARTITION1 (bootable) - Installable File System - 27.91 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. AntiVirusDisableNotify is set. FirewallDisableNotify is set. AV: Trend Micro AntiVirus v16.05.1022 () [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\CuteFTP\\CUTFTP32.EXE"="C:\\Program Files\\CuteFTP\\CUTFTP32.EXE:*:Enabled:CuteFTP" "C:\\Program Files\\K-Lite Codec Pack\\filters\\ac3config.exe"="C:\\Program Files\\K-Lite Codec Pack\\filters\\ac3config.exe:*:Enabled:AC3Filter" "C:\\WINDOWS\\SYSTEM32\\ftp.exe"="C:\\WINDOWS\\SYSTEM32\\ftp.exe:*:Enabled:ftp" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS APPDATA=C:\Documents and Settings\Brian\Application Data CLIENTNAME=Console COLLECTIONID=COL8143 CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=BRIANLAPTOP ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HMSERVER=https://wwss1proa.cce.hp.com/wuss/servlet/WUSSServlet HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Brian ITEMID=dj-22741-15 LANG=1033 LOGONSERVER=\\BRIANLAPTOP NUMBER_OF_PROCESSORS=1 OS=Windows_NT OSVER=winXPH Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 7, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0207 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONID=1133644085612htx6060cc2061:107fc087cb1:-3a9a SESSIONNAME=Console SWUTVER=1.0.3.1 SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Brian\LOCALS~1\Temp TIMEOUT=0 TMP=C:\DOCUME~1\Brian\LOCALS~1\Temp TOOLPATH=/C:\Program%20Files\Hewlett-Packard\HP%20Software%20Update\install.htm UPDATEDIR=C:\DOCUME~1\Brian\LOCALS~1\Temp\rad7F7AC.tmp USERDOMAIN=BRIANLAPTOP USERNAME=Brian USERPROFILE=C:\Documents and Settings\Brian VERSION=3.0.5.001 windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Brian [I](admin)[/I] Administrator [I](new local, admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf AC97 SoftV92 Data Fax Modem --> C:\Program Files\CONEXANT\CNXT_MODEM\HXFSETUP.EXE -U -Icnxthsf2.inf Adobe Download Manager 2.0 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe" Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Photoshop 6.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 6.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 6.0\Uninst.dll" Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002} AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe FinePixViewer Ver.2.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\SETUP.EXE" FUJIFILM USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\SETUP.EXE" getPlus(R)_ocx --> rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\inf\GETPLUSo.INF, DefaultUninstall Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar3.dll" HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" hp instant support --> C:\PROGRA~1\HEWLET~1\hpis\Uninstall.exe /s CeS HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D} K-Lite Mega Codec Pack 2.2.0 --> "C:\Program Files\K-Lite Codec Pack\unins000.exe" LiveUpdate 3.0 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U LiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8} MailWasher --> "C:\Program Files\MailWasher\unins000.exe" Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe" Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Office 2000 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" mIRC --> "C:\Hanscript\mirc.exe" -uninstall MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E} Odyssey Client --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{99D42EC7-652B-4819-B3E6-6450C815E03F} Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} Symantec KB-DocID:2003093015493306 --> MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68} Trend Micro AntiVirus --> C:\Program Files\Trend Micro\Internet Security\remove.exe Trend Micro AntiVirus --> MsiExec.exe /X{A621B45A-D138-4A95-BE10-7CABA05EF94E} USB Storage Driver --> DelUIDrv.exe VideoLAN VLC media player 0.8.6c --> C:\Program Files\VideoLAN\VLC\uninstall.exe Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401} Windows Defender Signatures --> MsiExec.exe /I{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C} Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe" Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe" Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840} WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe Wireless-G Notebook Adapter --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A2EDF5F-F3C6-4919-AE34-C08A71AD034A}\Setup.exe" -l0x9 XML Paper Specification Shared Components Pack 1.0 --> -- Application Event Log ------------------------------------------------------- Event Record #/Type5526 / Warning Event Submitted/Written: 02/18/2008 01:36:28 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type5445 / Warning Event Submitted/Written: 02/16/2008 00:37:42 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type5432 / Warning Event Submitted/Written: 02/16/2008 00:30:13 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type5387 / Warning Event Submitted/Written: 02/15/2008 10:32:23 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type5375 / Warning Event Submitted/Written: 02/15/2008 10:21:20 PM Event ID/Source: 40 / WinMgmt Event Description: WMI ADAP was unable to create the object Win32_PerfRawData_ASPNET_2050727_ASPNETAppsv2050727 for Performance Library ASP.NET_2.0.50727 because error 0x80041001 was returned -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type10520 / Warning Event Submitted/Written: 02/19/2008 04:55:40 PM Event ID/Source: 1005 / Dhcp Event Description: Your computer has detected that the IP address 192.168.1.101 for the Network Card with network address 001310F7932D is already in use on the network. Your computer will automatically attempt to obtain a different address. Event Record #/Type10519 / Warning Event Submitted/Written: 02/19/2008 04:55:40 PM Event ID/Source: 1005 / Dhcp Event Description: Your computer has detected that the IP address 192.168.1.101 for the Network Card with network address 001310F7932D is already in use on the network. Your computer will automatically attempt to obtain a different address. Event Record #/Type10494 / Error Event Submitted/Written: 02/19/2008 04:52:59 PM Event ID/Source: 7026 / Service Control Manager Event Description: The following boot-start or system-start driver(s) failed to load: nvport Event Record #/Type10493 / Error Event Submitted/Written: 02/19/2008 04:52:51 PM Event ID/Source: 7000 / Service Control Manager Event Description: The ASCTRM service failed to start due to the following error: %%2 Event Record #/Type10457 / Error Event Submitted/Written: 02/17/2008 08:05:00 PM Event ID/Source: 7026 / Service Control Manager Event Description: The following boot-start or system-start driver(s) failed to load: nvport -- End of Deckard's System Scanner: finished at 2008-02-19 17:25:01 ------------