Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: AMD Athlon(tm) Processor Percentage of Memory in Use: 70% Physical Memory (total/avail): 255.48 MiB / 75.98 MiB Pagefile Memory (total/avail): 619.39 MiB / 458.6 MiB Virtual Memory (total/avail): 2047.88 MiB / 1944.25 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 5 GiB total, 1.37 GiB free. D: is Fixed (FAT32) - 38.15 GiB total, 16.3 GiB free. E: is Fixed (FAT32) - 9.3 GiB total, 5.92 GiB free. F: is CDROM (CDFS) G: is CDROM (No Media) H: is Fixed (NTFS) - 232.88 GiB total, 153.73 GiB free. Y: is Network (FAT) \\.\PHYSICALDRIVE1 - Maxtor 5 1536H2 SCSI Disk Device - 14.31 GiB - 2 partitions \PARTITION0 (bootable) - Installable File System - 5 GiB - C: \PARTITION1 - Extended w/Extended Int 13 - 9.31 GiB - E: \\.\PHYSICALDRIVE2 - Maxtor 5 T040H4 SCSI Disk Device - 38.16 GiB - 1 partition \PARTITION0 (bootable) - Unknown - 38.16 GiB - D: \\.\PHYSICALDRIVE0 - WDC WD25 00JB-00GVC0 SCSI Disk Device - 232.88 GiB - 1 partition \PARTITION0 - Installable File System - 232.88 GiB - H: -- Security Center ------------------------------------------------------------- Windows Internal Firewall is enabled. FirstRunDisabled is set. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "D:\\dnloads\\eMule\\eMule.exe"="D:\\dnloads\\eMule\\eMule.exe:*:Enabled:eMule Plus" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "E:\\EMule Extracts\\EMule.46c\\emule.exe"="E:\\EMule Extracts\\EMule.46c\\emule.exe:*:Enabled:eMule" "C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Program" "D:\\dnloads\\eMule\\eMule_II\\eMule.exe"="D:\\dnloads\\eMule\\eMule_II\\eMule.exe:*:Enabled:eMule Plus" "D:\\Program Files\\EMule\\emule.exe"="D:\\Program Files\\EMule\\emule.exe:*:Enabled:eMule" "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test" "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "E:\\Program Files\\TurboTax_07 Premier\\TurboTax Premier 2007\\32bit\\ttax.exe"="E:\\Program Files\\TurboTax_07 Premier\\TurboTax Premier 2007\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax" "E:\\Program Files\\TurboTax_07 Premier\\TurboTax Premier 2007\\32bit\\updatemgr.exe"="E:\\Program Files\\TurboTax_07 Premier\\TurboTax Premier 2007\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Linda Kristina\Application Data CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=C-1722815 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Linda Kristina LOGONSERVER=\\C-1722815 NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 4 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0402 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\LINDAK~1\LOCALS~1\Temp TMP=C:\DOCUME~1\LINDAK~1\LOCALS~1\Temp USERDOMAIN=C-1722815 USERNAME=Linda Kristina USERPROFILE=C:\Documents and Settings\Linda Kristina windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Linda Kristina [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Acoustica CD/DVD Label Maker --> E:\Program Files\Acoustica CD Label Maker\uisurvey.exe Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003} AnswerWorks 4.0 Runtime - English --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}\setup.exe" -l0x9 -removeonly avast! Antivirus --> E:\Program Files\Alwil Software\Avast4\aswRunDll.exe "E:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe" Comcast High-Speed Internet Install Wizard --> C:\Program Files\support.com\uninstall\chsi_uninstaller.exe Comcast Toolbar --> C:\Program Files\ComcastToolbar\uninstall.exe CrossTrainerII --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C7192C5-A4B4-42B1-AFA9-FE2FE7E6ADAF}\Setup.exe" -l0x9 Data Lifeguard Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2C0A655C-61E7-428A-8ED2-23A3D20E7DD2}\Setup.exe" Desktop Doctor --> MsiExec.exe /I{D87149B3-7A1D-4548-9CBF-032B791E5908} Dragon NaturallySpeaking 7.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6675E71B-9843-4971-BC15-18AB52801134}\setup.exe" DVD Decrypter (Remove Only) --> "D:\Program Files\DVD Decrypter\uninstall.exe" DVD Shrink 3.2 --> "D:\Program Files\DVD Shrink\unins000.exe" eMule --> "D:\Program Files\eMule\Uninstall.exe" EPSON CX 3800 Guide --> C:\Program Files\epson\guide\cx3800_e\uninstall.exe EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar4.dll" HijackThis 2.0.2 --> "C:\Documents and Settings\Linda Kristina\Desktop\HijackThis.exe" /uninstall iRiver Manager --> E:\Program Files\iRiver\iRiver Manager\iRiverUninstall.exe iRiver Updater --> E:\Program Files\iRiver\iRiver Manager\Updater\uninst.exe Logitech Audio Echo Cancellation Component --> MsiExec.exe /X{BEF726DD-4037-4214-8C6A-E625C02D2870} Logitech Video Enumerator --> MsiExec.exe /X{EA516024-D84D-41F1-814F-83175A6188F2} Logitech® Camera Driver --> "C:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft Office 2000 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7} Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9} MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP MSN Toolbar --> C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\mtbs.exe c MVision --> MsiExec.exe /I{35725FBC-A136-4A46-9F29-091759D9BB93} NTI CD & DVD-Maker 6.5 Platinum --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778} AnyText PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} TurboTax Premier 2007 --> E:\Program Files\TurboTax_07 Premier\TurboTax Premier 2007\TaxUnst.EXE "E:\Program Files\TurboTax_07 Premier\TurboTax Premier 2007\Uninstall.log" -NoGui U3Launcher --> MsiExec.exe /I{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54} Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F} Windows Live Sign-in Assistant --> MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7} Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E} WinISO 5.3 --> "E:\Program Files\WinISO\unins000.exe" WinRAR archiver --> E:\Program Files\WinRAR\uninstall.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type193 / Error Event Submitted/Written: 04/11/2008 06:20:29 PM Event ID/Source: 1000 / Application Error Event Description: Faulting application pareto_as.exe, version 5.7.5728.10, faulting module unknown, version 0.0.0.0, fault address 0x03295c10. Processing media-specific event for [pareto_as.exe!ws!] Event Record #/Type183 / Error Event Submitted/Written: 04/11/2008 11:47:47 AM Event ID/Source: 1000 / Application Error Event Description: Faulting application pareto_as.exe, version 5.7.5728.10, faulting module unknown, version 0.0.0.0, fault address 0x001a1bf5. Processing media-specific event for [pareto_as.exe!ws!] Event Record #/Type178 / Error Event Submitted/Written: 04/11/2008 10:35:58 AM Event ID/Source: 1000 / Application Error Event Description: Faulting application pareto_as.exe, version 5.7.5728.10, faulting module unknown, version 0.0.0.0, fault address 0x03285c10. Processing media-specific event for [pareto_as.exe!ws!] Event Record #/Type165 / Error Event Submitted/Written: 04/10/2008 11:07:04 PM Event ID/Source: 1000 / Application Error Event Description: Faulting application pareto_as.exe, version 5.7.5728.10, faulting module shdocvw.dll, version 6.0.2900.2180, fault address 0x0000a538. Processing media-specific event for [pareto_as.exe!ws!] Event Record #/Type90 / Success Event Submitted/Written: 04/07/2008 09:01:59 PM Event ID/Source: 12001 / usnjsvc Event Description: The Messenger Sharing USN Journal Reader service started successfully. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type25259 / Error Event Submitted/Written: 04/12/2008 00:01:37 PM Event ID/Source: 7023 / Service Control Manager Event Description: The Computer Browser service terminated with the following error: %%1460 Event Record #/Type25256 / Error Event Submitted/Written: 04/12/2008 11:58:11 AM Event ID/Source: 7006 / Service Control Manager Event Description: The ScRegSetValueExW call failed for Start with the following error: %%5 Event Record #/Type25255 / Error Event Submitted/Written: 04/12/2008 11:58:11 AM Event ID/Source: 7006 / Service Control Manager Event Description: The ScRegSetValueExW call failed for Start with the following error: %%5 Event Record #/Type25254 / Error Event Submitted/Written: 04/12/2008 11:58:11 AM Event ID/Source: 7006 / Service Control Manager Event Description: The ScRegSetValueExW call failed for Start with the following error: %%5 Event Record #/Type25253 / Error Event Submitted/Written: 04/12/2008 11:58:11 AM Event ID/Source: 7006 / Service Control Manager Event Description: The ScRegSetValueExW call failed for Start with the following error: %%5 -- End of Deckard's System Scanner: finished at 2008-04-12 12:40:33 ------------