Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Genuine Intel(R) CPU T2400 @ 1.83GHz CPU 1: Genuine Intel(R) CPU T2400 @ 1.83GHz Percentage of Memory in Use: 74% Physical Memory (total/avail): 503.36 MiB / 128.47 MiB Pagefile Memory (total/avail): 2514.91 MiB / 2049.99 MiB Virtual Memory (total/avail): 2047.88 MiB / 1928.33 MiB C: is Fixed (NTFS) - 74.52 GiB total, 62.35 GiB free. D: is CDROM (CDFS) F: is Network (Unformatted) L: is Network (Unformatted) N: is Network (Unformatted) O: is Network (Unformatted) R: is Network (Unformatted) \\.\PHYSICALDRIVE0 - FUJITSU MHW2060BH - 55.9 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 74.52 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is set to notify before download. Windows Internal Firewall is disabled. FirstRunDisabled is set. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Unified Messenger\\Common\\ummiddleman.exe"="C:\\Program Files\\Unified Messenger\\Common\\ummiddleman.exe:*:Enabled:Middleman" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" ""=":*:Enabled:Nod29 Service" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\ATL97990\Application Data CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=BFERRETTILAP ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\ATL97990 HOMESHARE=\\rsuifs\ATL97990$ LOGONSERVER=\\RSUIDC2 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\WBEM;C:\Program Files\Unified Messenger\Common;C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\Bin;C:\RSMS2;C:\Program Files\Microsoft SQL Server\80\Tools\BINN;C:\RSMS2;C:\Program Files\Insystems Corporation\Calligo\Components\Shared\PDFSupport PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 14 Stepping 8, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0e08 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\ATL97990\LOCALS~1\Temp TMP=C:\DOCUME~1\ATL97990\LOCALS~1\Temp UMCommon=C:\Program Files\Unified Messenger\Common USERDNSDOMAIN=RSUI.COM USERDOMAIN=RSUI USERNAME=atl97990 USERPROFILE=C:\Documents and Settings\ATL97990 WIN32DMIPATH=C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32 windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- admin [I](admin)[/I] svcwork [I](new local, admin)[/I] Administrator [I](admin)[/I] ATL97990 [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> MsiExec.exe /I{9579E862-5FC7-4337-B1CC-5E37451524C5} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 2005-2006 Premium Pro Allocator System Files --> C:\WINDOWS\Tritech\ALLOCA~1\UNWISE.EXE /A C:\WINDOWS\Tritech\ALLOCA~1\INSTALL.LOG 2005-2006 Premium Pro Calendar System Files --> C:\WINDOWS\Tritech\UNWISE.EXE /A C:\WINDOWS\Tritech\INSTALL.LOG 2005-2006 Premium Pro Life/PC System Files --> C:\WINDOWS\Tritech\PREMIU~1\UNWISE.EXE C:\WINDOWS\Tritech\PREMIU~1\INSTALL.LOG 2005-2006 Premium Pro Municipal System Files --> C:\WINDOWS\Tritech\MUNICI~1\UNWISE.EXE /A C:\WINDOWS\Tritech\MUNICI~1\INSTALL.LOG Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll" Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Agere Systems HDA Modem --> agrsmdel AT&T Communication Manager --> MsiExec.exe /X{A81BFA08-5D4C-4D4C-ACEF-BF558C70D99D} Avaya Modular Messaging Client Enablement Tool for Microsoft® Windows® XP SP2 --> MsiExec.exe /X{1A5BB945-0572-445D-BC19-1FCF6889472C} Broadcom NetXtreme Ethernet Controller --> MsiExec.exe /X{B7F54262-AB66-44B3-88BF-9FC69941B643} BVSInstall --> MsiExec.exe /I{46D3D628-4BDF-4759-B497-68C9F5DC370A} Calligo --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{8C7BDFE7-91EC-4A86-9C8F-DD216E9F0066} CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe" DeLorme Street Atlas USA 2006 Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5F75F6B6-8470-4DDD-B95B-18C57CBCF33F}\setup.exe" -l0x9 NoMode DeLorme Street Atlas USA 2006 Plus Data --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{677E5042-5DB9-4443-8CD3-35C6E3210CE5}\setup.exe" -l0x9 NoMode Driver Installer --> MsiExec.exe /X{753D852A-D86D-42C9-9978-40AE66FB8985} Fingerprint Sensor Minimum Install --> MsiExec.exe /I{CBDC0B97-C98E-4449-A08F-B8AF3F4E29C8} HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall HP BIOS Configuration for ProtectTools 2.00 E1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AE052EF7-2640-48D7-8915-69B810D975CB}\setup.exe" -l0x9 biosuninst HP Digital Sender 9100C - Administrator 4.00 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F46B22E0-AE8E-11D4-BED4-0010A409A5BF}\Setup.exe" HP Embedded Security for ProtectTools --> MsiExec.exe /I{2298055A-F5E6-4332-9A15-C5D99870E72F} HP Integrated Module with Bluetooth wireless technology --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679} HP ProtectTools Security Manager 2.00 C3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{914E1AB1-DCA0-4A7D-935F-B58C4B887A2B}\setup.exe" -l0x9 -removeonly hpquninst HP Quick Launch Buttons 6.00 D2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x9 -removeonly uninst HP Smart Card Security for ProtectTools 5.00 D4 --> C:\Program Files\Hewlett-Packard\HP Smart Card Security for ProtectTools\ahpunset.exe -{0515803B-5068-4599-8666-963E143C7381} ImageRight Database Connectivity --> C:\WINDOWS\irinstal\dbcon\UNWISE.EXE C:\WINDOWS\irinstal\dbcon\dbcon.LOG ImageRight Desktop --> C:\WINDOWS\irinstal\iwdsktop\UNWISE.EXE C:\WINDOWS\irinstal\iwdsktop\iwdsktop.LOG ImageRight Printer --> C:\Program Files\ImageRight Printer\IRPrntU.exe Imaging for Windows® Professional Edition --> C:\WINDOWS\spuninst.exe -f"C:\Program Files\Imaging Professional\DeIsL3.isu" Insight Management Agent --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Compaq\Compaq Management Agents\DeIsL1.isu" -c"C:\Program Files\Compaq\Compaq Management Agents\cpqdmun.dll" Intel(R) Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_27A6 PCI\VEN_8086&DEV_27A2 Intel(R) PRO Network Connections Drivers --> Prounstl.exe InterVideo DVD Check --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5D97A4A7-C274-4B63-86D9-07A33435F505}\setup.exe" REMOVEALL InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL MapInfo MapX 4.0 OCX --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MapInfo MapX\4.0\Mapx400uOCX.isu" McAfee VirusScan Enterprise --> MsiExec.exe /I{5DF3D1BB-894E-4DCD-8275-159AC9829B43} Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} MM Client --> MsiExec.exe /I{5BA04C60-79CD-46D8-B0F1-AFC8998C10BE} Nokia Connectivity Adapter Cable DKU-5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F1BA3CD5-89DC-4273-8603-A75F33E9B335}\Setup.exe" -l0x9 NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI OmniForm ActiveX Control --> C:\PROGRA~1\ScanSoft\OMNIFO~1\ScanSoft\OMNIFO~1\UNWISE.EXE C:\PROGRA~1\ScanSoft\OMNIFO~1\ScanSoft\OMNIFO~1\INSTALL.LOG Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe Realtek High Definition Audio Driver --> RtlUpd.exe -r -m Sophos Anti-Rootkit 1.3.1 --> C:\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe remove SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe" SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall Terminal Services Client --> C:\Program Files\Terminal Services Client\setup\Setup.exe Texas Instruments PCIxx21/x515/xx12 drivers. --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} /l1033 Tracker Client --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{658C833A-C6CD-45E2-891D-1B9BEB9B8AA0} Underwriting Outlook Addin --> MsiExec.exe /I{D286AF42-D3AE-4F9E-BE6B-174670F0071E} VNC Free Edition 4.1.1 --> "C:\Program Files\RealVNC\VNC4\unins000.exe" Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type5355 / Warning Event Submitted/Written: 07/10/2008 05:48:54 PM Event ID/Source: 257 / Alert Manager Event Interface Event Description: VirusScan Enterprise: Would be blocked by behaviour blocking rule (rule is currently in warn mode) (warn only mode!).(from BFERRETTILAP IP 192.168.1.3 user SYSTEM running VirusScan Enter 8.0 OAS) Event Record #/Type5354 / Warning Event Submitted/Written: 07/10/2008 05:48:54 PM Event ID/Source: 257 / Alert Manager Event Interface Event Description: VirusScan Enterprise: Would be blocked by behaviour blocking rule (rule is currently in warn mode) (warn only mode!).(from BFERRETTILAP IP 192.168.1.3 user SYSTEM running VirusScan Enter 8.0 OAS) Event Record #/Type5352 / Warning Event Submitted/Written: 07/10/2008 05:46:17 PM Event ID/Source: 257 / Alert Manager Event Interface Event Description: VirusScan Enterprise: Would be blocked by behaviour blocking rule (rule is currently in warn mode) (warn only mode!).(from BFERRETTILAP IP 192.168.1.3 user SYSTEM running VirusScan Enter 8.0 OAS) Event Record #/Type5351 / Error Event Submitted/Written: 07/10/2008 05:38:02 PM Event ID/Source: 15 / AutoEnrollment Event Description: Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. Event Record #/Type5350 / Error Event Submitted/Written: 07/10/2008 05:37:22 PM Event ID/Source: 352 / IFXSPMGT Event Description: The Upgrade Tool returned an error. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type108630 / Error Event Submitted/Written: 07/10/2008 05:42:02 PM Event ID/Source: 59 / SideBySide Event Description: Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL. Reference error message: The operation completed successfully. . Event Record #/Type108629 / Error Event Submitted/Written: 07/10/2008 05:42:02 PM Event ID/Source: 59 / SideBySide Event Description: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. . Event Record #/Type108628 / Error Event Submitted/Written: 07/10/2008 05:42:02 PM Event ID/Source: 32 / SideBySide Event Description: Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system. Event Record #/Type108627 / Error Event Submitted/Written: 07/10/2008 05:42:02 PM Event ID/Source: 59 / SideBySide Event Description: Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL. Reference error message: The operation completed successfully. . Event Record #/Type108626 / Error Event Submitted/Written: 07/10/2008 05:42:02 PM Event ID/Source: 59 / SideBySide Event Description: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. . -- End of Deckard's System Scanner: finished at 2008-07-10 17:49:37 ------------