Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 3.0 Architecture: X86; Language: English CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 5000+ Percentage of Memory in Use: 38% Physical Memory (total/avail): 1790.42 MiB / 1100.05 MiB Pagefile Memory (total/avail): 3684.46 MiB / 3005.34 MiB Virtual Memory (total/avail): 2047.88 MiB / 1792.56 MiB C: is Fixed (NTFS) - 150.01 GiB total, 1 GiB free. D: is CDROM (CDFS) E: is CDROM (UDF) F: is Fixed (Ext2) - 300.24 GiB total, 133.55 GiB free. G: is Fixed (Ext2) - 0.04 GiB total, 0.03 GiB free. \\.\PHYSICALDRIVE0 - WDC WD5000AAKS-00YGA0 - 465.63 GiB - 4 partitions \PARTITION0 (bootable) - Installable File System - 150.01 GiB - C: \PARTITION1 - Unknown - 4.02 GiB \PARTITION2 - Extended Partition - 39.22 MiB - G: \PARTITION3 - Unknown - 300.24 GiB - F: -- Security Center ------------------------------------------------------------- AUOptions is set to notify before download. -- Environment Variables ------------------------------------------------------- ALKY=C:\WINDOWS\System32\Libraries\ ALLUSERSPROFILE=C:\Users\All Users APPDATA=C:\Users\Johannes\Application Data CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=GT-FORCE ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Johannes LOGONSERVER=\\GT-FORCE NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\System32\Libraries;C:\Program Files\ESTsoft\ALZip;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem;C:\Program Files\ESTsoft\ALZip PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 107 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=15 PROCESSOR_REVISION=6b02 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\Users\Johannes\LOCALS~1\Temp TMP=C:\Users\Johannes\LOCALS~1\Temp USERDOMAIN=GT-FORCE USERNAME=Johannes USERPROFILE=C:\Users\Johannes windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Johannes [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\NuNInst.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95} Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61} Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394} Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23} Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C} Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C} Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E} Adobe Color Common Settings --> MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9} Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8} Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029} Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5} Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D} Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD} Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2} Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B} Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245} Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078} Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C} Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exe Adobe Photoshop CS3 --> MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05} Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003} Adobe Setup --> MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462} Adobe Shockwave Player 11 --> C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183} Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312} Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8} Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5} Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6} Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923} Alky for Applications (Windows XP) --> MsiExec.exe /X{BB05D173-9681-4812-A7FA-BD4042A3DA00} Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4} Arial Sound Recorder version 1.5.9 --> "C:\Program Files\Arial Sound Recorder\unins000.exe" ATI - Hjälp för avinstallation av program --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe ATI Catalyst Control Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0 ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean ATI Parental Control & Encoder --> MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7} µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL Audacity 1.2.6 --> "C:\Program Files\Audacity\unins000.exe" avast! Antivirus --> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL COMODO Firewall Pro --> C:\Program Files\COMODO\Firewall\cfpconfg.exe -u DirectVobSub (remove only) --> "C:\Program Files\DirectVobSub\uninstall.exe" Ext2 IFS 1.11 for Windows XP --> RunDll32 setupapi.dll,InstallHinfSection DefaultUninstall 130 Ext2Ifs_for_NT501.inf FastStone Image Viewer 3.5 --> C:\Program Files\FastStone Image Viewer\uninst.exe File Transfer Plus 1.1 RELEASE --> "C:\Program Files\Messenger Plus! Live\Scripts\File Transfer Plus 1.1\unins000.exe" Gadget Installer --> MsiExec.exe /I{3F3733A5-8322-454D-A638-3B74E1C83752} Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 2.0.2 --> "C:\Program Files\HijackThis\HijackThis.exe" /uninstall IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Kleptomania 2.5 --> C:\Program Files\Kleptomania\k-mania.exe /u Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Messenger Plus! Live --> "C:\Program Files\Messenger Plus! Live\Uninstall.exe" Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{9011041D-6000-11D3-8CFE-0150048383C9} Microsoft SQL Server 2005 Compact Edition [ENU] --> MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} mst IsUsedBy --> MsiExec.exe /X{7EBF8243-DE29-4133-AB11-03169DC0F284} Nero 8 --> MsiExec.exe /X{5FCCD531-1B38-4A94-924C-127F722F1053} neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Next Generation Visualisations --> MsiExec.exe /I{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B} NVIDIA Media Center Extensions --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4BE15737-07C5-4705-9DFC-D9D533939942}\setup.exe" -l0x9 -uninstall NVIDIA PureVideo Decoder --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055FEF8E-4B86-400F-A5C6-8FAC0042DCD9}\setup.exe" -l0x9 -uninstall Opera 9.26 --> MsiExec.exe /X{9894D22D-0558-41D9-95FC-8E9BFD6E8170} PDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5} Personal 4.5.4 --> "C:\Program Files\Personal\bin\persinst.exe" -u QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD} REALTEK GbE & FE Ethernet PCI NIC Driver --> C:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\SETUP.EXE -runfromtemp -l0x001d -removeonly Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -l0x1d -removeonly Sandboxie 3.24 --> "C:\WINDOWS\Installer\SandboxieInstall.exe" /remove Save Flash 4.1 --> C:\Program Files\Save Flash\uninst.exe Slaget om Midgård(tm) --> C:\Program Files\EA GAMES\Slaget om Midgård(tm)\EAUninstall.exe SPCS Administration --> MsiExec.exe /I{A737F62C-E5B4-4DF4-9CAC-5A4928BC983C} SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe" Total Recorder 6.1 --> "C:\Program Files\TotalRecorder\setup.exe" U Uniblue RegistryBooster 2 --> "C:\Program Files\RegistryBooster 2\unins000.exe" VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027} What's Running 2.2 --> "C:\Program Files\WhatsRunning\unins000.exe" VideoLAN VLC media player 0.8.6e --> C:\Program Files\VideoLAN\VLC\uninstall.exe Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401} Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) --> C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\DPInst.exe /d /u C:\WINDOWS\system32\DRVSTORE\amdk8_6FE44FCD212D4A086C7BC0C98B9A619782073FB7\amdk8.inf Windows Live inloggningsassistenten --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} Windows Live installer --> MsiExec.exe /X{E17F76BE-50E9-4E7C-ADF6-6D8F44A9C6F3} Windows Live Mail --> MsiExec.exe /I{7664A2EF-34F5-42D2-8FD8-4FEF0047A929} Windows Live Messenger --> MsiExec.exe /X{20503DFE-E5B2-491E-B2C5-8BCB5BF5B9E9} Windows Live Photo Gallery --> MsiExec.exe /X{2D4F6BE3-6FEF-4FE9-9D01-1406B220D08C} Windows Live Writer --> MsiExec.exe /X{8A16A4FC-B43F-46A6-8DB5-C42B145EBFBD} WordFinder --> C:\PROGRA~1\Wfwin\UNWISE.EXE C:\PROGRA~1\Wfwin\INSTALL.LOG WordFinder Language Suite --> C:\PROGRA~1\Wfwin\UNWISE.EXE C:\PROGRA~1\Wfwin\INSTALL.LOG XML Paper Specification Shared Components Pack 1.0 --> Yahoo! Companion --> rundll32.exe C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YCOMP5~1.DLL,DllCommand ui -- Application Event Log ------------------------------------------------------- Event Record #/Type1305 / Error Event Submitted/Written: 05/09/2008 02:21:34 PM Event ID/Source: 3003 / WinDefendRtp Event Description: %GT-FORCE27 Real-Time Protection checkpoint has encountered an error and failed to start. User: GT-FORCE\Johannes Checkpoint ID: 1 Error Code: 0x8000ffff Error description: Catastrophic failure Event Record #/Type1304 / Error Event Submitted/Written: 05/09/2008 02:21:34 PM Event ID/Source: 3003 / WinDefendRtp Event Description: %GT-FORCE27 Real-Time Protection checkpoint has encountered an error and failed to start. User: GT-FORCE\Johannes Checkpoint ID: 1 Error Code: 0x80070005 Error description: Access is denied. Event Record #/Type1301 / Warning Event Submitted/Written: 05/09/2008 02:19:37 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type1294 / Warning Event Submitted/Written: 05/09/2008 11:01:38 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type1288 / Warning Event Submitted/Written: 05/09/2008 09:15:59 AM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type5498 / Warning Event Submitted/Written: 05/09/2008 05:39:44 PM Event ID/Source: 3004 / WinDefend Event Description: %GT-FORCE27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %GT-FORCE27 can't undo changes that you allow. For more information please see the following: %GT-FORCE275 Scan ID: {F891BBEA-DD34-4477-802F-852AD327D57B} User: GT-FORCE\Johannes Name: %GT-FORCE271 ID: %GT-FORCE272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %GT-FORCE276 Alert Type: %GT-FORCE278 Detection Type: 1.1.1593.02 Event Record #/Type5497 / Warning Event Submitted/Written: 05/09/2008 05:39:44 PM Event ID/Source: 3004 / WinDefend Event Description: %GT-FORCE27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %GT-FORCE27 can't undo changes that you allow. For more information please see the following: %GT-FORCE275 Scan ID: {6E5AB632-E49E-4436-A4CF-6811BA665A26} User: GT-FORCE\Johannes Name: %GT-FORCE271 ID: %GT-FORCE272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %GT-FORCE276 Alert Type: %GT-FORCE278 Detection Type: 1.1.1593.02 Event Record #/Type5496 / Warning Event Submitted/Written: 05/09/2008 05:39:44 PM Event ID/Source: 3004 / WinDefend Event Description: %GT-FORCE27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %GT-FORCE27 can't undo changes that you allow. For more information please see the following: %GT-FORCE275 Scan ID: {5A8E935C-B373-4AB4-9E2B-3F88ECE4FB03} User: GT-FORCE\Johannes Name: %GT-FORCE271 ID: %GT-FORCE272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %GT-FORCE276 Alert Type: %GT-FORCE278 Detection Type: 1.1.1593.02 Event Record #/Type5495 / Warning Event Submitted/Written: 05/09/2008 05:39:42 PM Event ID/Source: 3004 / WinDefend Event Description: %GT-FORCE27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %GT-FORCE27 can't undo changes that you allow. For more information please see the following: %GT-FORCE275 Scan ID: {EDE4E2F9-B3C4-4485-8981-EA42ED2E74B3} User: GT-FORCE\Johannes Name: %GT-FORCE271 ID: %GT-FORCE272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %GT-FORCE276 Alert Type: %GT-FORCE278 Detection Type: 1.1.1593.02 Event Record #/Type5494 / Warning Event Submitted/Written: 05/09/2008 05:39:42 PM Event ID/Source: 3004 / WinDefend Event Description: %GT-FORCE27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %GT-FORCE27 can't undo changes that you allow. For more information please see the following: %GT-FORCE275 Scan ID: {18E9CD03-BD7F-4293-8858-65B523252596} User: GT-FORCE\Johannes Name: %GT-FORCE271 ID: %GT-FORCE272 Severity: 1.1.1593.05 Category: 1.1.1593.06 Path Found: %GT-FORCE276 Alert Type: %GT-FORCE278 Detection Type: 1.1.1593.02 -- End of Deckard's System Scanner: finished at 2008-05-09 17:41:19 ------------