Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel(R) Pentium(R) 4 CPU 3.00GHz CPU 1: Intel(R) Pentium(R) 4 CPU 3.00GHz Percentage of Memory in Use: 92% Physical Memory (total/avail): 502.07 MiB / 36.33 MiB Pagefile Memory (total/avail): 1560.48 MiB / 413.07 MiB Virtual Memory (total/avail): 2047.88 MiB / 1950.16 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 37.21 GiB total, 18.19 GiB free. D: is CDROM (No Media) E: is Removable (FAT32) \\.\PHYSICALDRIVE0 - ST340014AS - 37.25 GiB - 2 partitions \PARTITION0 - Unknown - 31.35 MiB \PARTITION1 (bootable) - Installable File System - 37.21 GiB - C: \\.\PHYSICALDRIVE1 - JetFlash TS1GJF110 USB Device - 996.22 MiB - 1 partition \PARTITION0 (bootable) - Unknown - 998.13 MiB - E: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is disabled. FW: Bitdefender Firewall v8.0 (BitDefender) AV: Bitdefender Antivirus v8.0 (BitDefender) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\jll2\Application Data CLASSPATH="C:\Program Files\Java\j2re1.4.2_04\lib\ext\QTJava.zip" CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=PC3 ComSpec=C:\WINDOWS\system32\cmd.exe DEFAULT_CA_NR=CA18 FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\jll2 LOGONSERVER=\\PC3 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\SAP\FrontEnd\sapgui\FILC\odbc;C:\Program Files\Internet Explorer;;C:\Program Files\Common Files\Autodesk Shared;C:\Program Files\Common Files\Teleca Shared PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 3, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0403 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA="C:\Program Files\Java\j2re1.4.2_04\lib\ext\QTJava.zip" ROLE=DESKTOP SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\jll2\LOCALS~1\Temp TMP=C:\DOCUME~1\jll2\LOCALS~1\Temp USERDOMAIN=PC3 USERNAME=jll2 USERPROFILE=C:\Documents and Settings\jll2 windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Default.Profile suhail jll1 [I](admin)[/I] jll2 [I](admin)[/I] Administrator [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Adobe Acrobat - Reader 6.0.2 Update --> MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01} Adobe Acrobat and Reader 6.0.3 Update --> MsiExec.exe /I{AC76BA86-0000-7EC8-7489-000000000603} Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001} Adobe Reader Chinese Simplified Fonts --> MsiExec.exe /I{AC76BA86-7AD7-2447-5A64-7E8A45000001} Adobe Reader Chinese Traditional Fonts --> MsiExec.exe /I{AC76BA86-7AD7-2448-5A64-7E8A45000001} Adobe Reader Japanese Fonts --> MsiExec.exe /I{AC76BA86-7AD7-5A76-5A64-7E8A45000001} Adobe Reader Korean Fonts --> MsiExec.exe /I{AC76BA86-7AD7-5676-5A64-7E8A45000001} Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5 --> MsiExec.exe /I{E031338C-839D-4EDD-9537-99B653C39D81} BitDefender Total Security 2008 --> MsiExec.exe /I{92098E58-00AD-4F78-AD6E-807BDB323478} CARGO --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\JLL\Cargo\ST6UNST.LOG" Citrix ICA Client --> MsiExec.exe /I{956F3E9A-3AED-40F8-8522-5F6A524CFC3E} Citrix ICA Web Client --> C:\WINDOWS\System32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf CMD Prompt Here PowerToy --> rundll32.exe syssetup.dll,SetupInfObjectInstallAction DefaultUninstall 132 C:\WINDOWS\INF\CmdHere.inf Crystal Analysis Rich Client --> MsiExec.exe /X{C1F698BD-9C05-49C7-99E0-9EC291F050CA} Digital Locker Assistant --> MsiExec.exe /I{D01653EF-9F9F-41D6-B879-654A6BF5892C} Flat Panel Adjust --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Dell\FPAdjust\Uninst.isu" FriendFinder Messenger v4.1 --> MsiExec.exe /I{090E87A8-C7FE-4524-B625-65657F258121} HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall IE5 Registration --> MsiExec.exe /I{C1E26EED-CC8B-4371-9CC7-AD8A5814B4B2} IE6SP1 for Jones Lang LaSalle --> MsiExec.exe /I{2B93C225-1FF3-448B-92B7-DA48E8C4690A} Intel(R) Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2776 PCI\VEN_8086&DEV_2772 Intel(R) PRO Network Adapters and Drivers --> Prounstl.exe Java 2 Runtime Environment, SE v1.4.2_04 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142040} JLL ScreenSaver --> MsiExec.exe /I{5451A718-4A95-458A-9B98-84393D7A95D8} JLL Screensaver (0504) --> MsiExec.exe /I{3189DFB8-11F1-4A96-A291-6D59A97545E7} K-Lite Codec Pack 3.7.5 Full --> "C:\Program Files\K-Lite Codec Pack\unins000.exe" McAfee VirusScan Enterprise --> MsiExec.exe /I{5DF3D1BB-894E-4DCD-8275-159AC9829B43} Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf Microsoft GB18030 Support Package --> MsiExec.exe /I{DEBACE7E-5DD1-42DB-AFE7-2B60E7CC80A8} Microsoft Office 2003 Chinese (Simplified) User Interface Pack --> MsiExec.exe /I{901E0804-6000-11D3-8CFE-0150048383C9} Microsoft Office 2003 Chinese (Traditional) User Interface Pack --> MsiExec.exe /I{901E0404-6000-11D3-8CFE-0150048383C9} Microsoft Office 2003 Japanese User Interface Pack --> MsiExec.exe /I{901E0411-6000-11D3-8CFE-0150048383C9} Microsoft Office 2003 Korean User Interface Pack --> MsiExec.exe /I{901E0412-6000-11D3-8CFE-0150048383C9} Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Microsoft Office Sounds --> MsiExec.exe /I{10CE1EA2-12E9-11D3-825E-00C04F6843FE} Microsoft Office Visio Viewer 2003 (English) --> MsiExec.exe /I{90520409-6000-11D3-8CFE-0150048383C9} Microsoft Outlook Personal Folders Backup --> MsiExec.exe /X{C63E7C60-25EB-11D3-8EDA-00A0C911E8E5} Microsoft Tool Web Package:WntIpcfg.exe --> MsiExec.exe /X{EA82FF50-E258-4DFE-839B-8F26A01A34A7} Motorola USB Drivers v2.9 --> MsiExec.exe /X{86EB9B75-C7F8-4D7D-A032-6C5858757525} Mozilla Firefox (2.0.0.12) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe Pdf995 --> C:\Program Files\pdf995\setup.exe uninstall QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log SAP Front End --> "C:\WINDOWS\SAPwksta\setup\sapsetup.exe" /uninstall /norestart SAPGUI --> MsiExec.exe /X{F1FCADE3-CB8C-4331-AA80-38D939EE144E} Snapshot Viewer --> C:\program files\microsoft\Snapshot Viewer\Setup\Setup.exe /T snap90.stf Sony Ericsson Device Data --> MsiExec.exe /I{C92E7DF1-624A-4D95-A4C4-18CB491B44A4} Sony Ericsson Drivers --> MsiExec.exe /I{C60BA916-9E44-4DA4-B11A-9E27B7624EF5} Sony Ericsson PC Suite --> C:\WINDOWS\Installer\{D6BF6477-8369-489F-8DE6-3731F4B88560}\Setup.exe /uninstall Sony Ericsson PC Suite --> MsiExec.exe /I{25BEC3AB-5CD4-481D-9143-215C1BBB189E} Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe" StumbleUpon IE Toolbar --> C:\Program Files\StumbleUpon\uninstall.exe SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} Tera Term Pro --> C:\WINDOWS\ttuninst.exe Uniblue RegistryBooster 2 --> "C:\Program Files\Uniblue\RegistryBooster 2\unins000.exe" Unity Web Player --> C:\Program Files\Unity\WebPlayer\Uninstall.exe Volo View Express --> MsiExec.exe /I{1ECD6EC8-7BB2-4CD5-A384-BAA371BC4D21} Winamp --> "C:\Program Files\Winamp\UninstWA.exe" Windows Blaster Worm Removal Tool (KB833330) --> C:\WINDOWS\$NtUninstallKB833330$\spuninst\spuninst.exe Windows Messenger 5.0 --> MsiExec.exe /I{1F0BD960-6525-4FEE-B577-2473F77F1277} WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall Xilisoft 3GP Video Converter --> C:\Program Files\Xilisoft\3GP Video Converter 3\Uninstall.exe Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S Yahoo! Extras --> C:\PROGRA~1\Yahoo!\Common\unyext.exe Yahoo! Install Manager --> C:\WINDOWS\System32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL Yahoo! Internet Mail --> C:\WINDOWS\System32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type2990 / Error Event Submitted/Written: 03/03/2008 08:28:57 PM Event ID/Source: 439 / ESENT Event Description: Catalog Database (1536) Unable to write a shadowed header for file C:\WINDOWS\system32\CatRoot2\edb.chk. Error -1032. Event Record #/Type2989 / Error Event Submitted/Written: 03/03/2008 08:28:57 PM Event ID/Source: 490 / ESENT Event Description: svchost (1536) An attempt to open the file "C:\WINDOWS\system32\CatRoot2\edb.chk" for read / write access failed with system error 5 (0x00000005): "Access is denied. ". The open file operation will fail with error -1032 (0xfffffbf8). Event Record #/Type2987 / Error Event Submitted/Written: 03/03/2008 08:25:54 PM Event ID/Source: 1008 / McLogEvent Event Description: The McShield service terminated unexpectedly. Please review event 5019 or 5051 for details. The McShield service will be restarted in 60 seconds; Event Record #/Type2985 / Error Event Submitted/Written: 03/03/2008 08:22:18 PM Event ID/Source: 1008 / McLogEvent Event Description: The McShield service terminated unexpectedly. Please review event 5019 or 5051 for details. The McShield service will be restarted in 60 seconds; Event Record #/Type2984 / Error Event Submitted/Written: 03/03/2008 08:22:05 PM Event ID/Source: 5051 / McLogEvent Event Description: A thread in process C:\Program Files\Network Associates\VirusScan\Mcshield.exe took longer than 90000 ms to complete a request. The process will be terminated. Thread id : 3328 (0xd00) Thread address : 0x7C90EB94 Thread message : Build Aug 20 2004 04:46:11 / 5200.2160 Object being scanned = \Device\HarddiskVolume2\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920683.cat by svchost.exe 7600(0)(0) 7531(0)(0) 7590(0)(0) 7006(0)(0) 7005(0)(0) 7512(0)(0) 7004(0)(0) 7003(0)(0) -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type7000 / Error Event Submitted/Written: 03/03/2008 08:39:09 PM Event ID/Source: 7034 / Service Control Manager Event Description: The Network Associates McShield service terminated unexpectedly. It has done this 104 time(s). Event Record #/Type6999 / Error Event Submitted/Written: 03/03/2008 08:38:57 PM Event ID/Source: 7011 / Service Control Manager Event Description: Timeout (30000 milliseconds) waiting for a transaction response from the ShellHWDetection service. Event Record #/Type6998 / Error Event Submitted/Written: 03/03/2008 08:38:33 PM Event ID/Source: 7011 / Service Control Manager Event Description: Timeout (30000 milliseconds) waiting for a transaction response from the ShellHWDetection service. Event Record #/Type6997 / Error Event Submitted/Written: 03/03/2008 08:38:08 PM Event ID/Source: 7011 / Service Control Manager Event Description: Timeout (30000 milliseconds) waiting for a transaction response from the 6to4 service. Event Record #/Type6994 / Error Event Submitted/Written: 03/03/2008 08:25:54 PM Event ID/Source: 7034 / Service Control Manager Event Description: The Network Associates McShield service terminated unexpectedly. It has done this 103 time(s). -- End of Deckard's System Scanner: finished at 2008-03-03 20:41:03 ------------