Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft® Windows Vista™ Business (build 6000) Architecture: X64; Language: English CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ Percentage of Memory in Use: 39% Physical Memory (total/avail): 4094.75 MiB / 2493.77 MiB Pagefile Memory (total/avail): 8340.59 MiB / 6651.69 MiB Virtual Memory (total/avail): 4095.88 MiB / 3967.05 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 221.17 GiB total, 94.36 GiB free. D: is CDROM (CDFS) E: is CDROM (No Media) F: is CDROM (CDFS) G: is Removable (FAT) \\.\PHYSICALDRIVE0 - WDC WD25 00JS-22NCB1 SCSI Disk Device - 232.88 GiB - 2 partitions \PARTITION0 (bootable) - Installable File System - 221.17 GiB - C: \PARTITION1 - Unknown - 11.72 GiB \\.\PHYSICALDRIVE1 - Best Buy Geek Squad U3 USB Device - 972.69 MiB - 1 partition \PARTITION0 (bootable) - Win95 w/Extended Int 13 - 973.99 MiB - G: -- Security Center ------------------------------------------------------------- Windows Internal Firewall is disabled. FW: AVG Firewall v8.0 (AVG Technologies CZ, s.r.o.) AV: AVG Internet Security v8.0 (AVG Technologies) AS: AVG Internet Security v8.0 (AVG Technologies) [COLOR=RED]Disabled[/COLOR] AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\ProgramData APPDATA=C:\Users\Justin Kahl\AppData\Roaming CLASSPATH=.;C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip CommonProgramFiles=C:\Program Files (x86)\Common Files CommonProgramFiles(x86)=C:\Program Files (x86)\Common Files CommonProgramW6432=C:\Program Files\Common Files COMPUTERNAME=DUSTY ComSpec=C:\Windows\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Users\Justin Kahl INCLUDE=C:\Windows\watcom-1.3\h;C:\Windows\watcom-1.3\h\nt;C:\Windows\watcom-1.3\maple\include KMP_DUPLICATE_LIB_OK=TRUE LOCALAPPDATA=C:\Users\Justin Kahl\AppData\Local LOGONSERVER=\\DUSTY NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Windows\watcom-1.3\binnt;C:\Windows\watcom-1.3\binw;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files (x86)\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC PROCESSOR_ARCHITECTURE=x86 PROCESSOR_ARCHITEW6432=AMD64 PROCESSOR_IDENTIFIER=AMD64 Family 15 Model 75 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=15 PROCESSOR_REVISION=4b02 ProgramData=C:\ProgramData ProgramFiles=C:\Program Files (x86) ProgramFiles(x86)=C:\Program Files (x86) ProgramW6432=C:\Program Files PROMPT=$P$G PUBLIC=C:\Users\Public QTJAVA=C:\Program Files (x86)\QuickTime\QTSystem\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\Windows TEMP=C:\Users\JUSTIN~1\AppData\Local\Temp TMP=C:\Users\JUSTIN~1\AppData\Local\Temp USERDOMAIN=Dusty USERNAME=Justin Kahl USERPROFILE=C:\Users\Justin Kahl WATCOM=C:\Windows\watcom-1.3 windir=C:\Windows -- User Profiles --------------------------------------------------------------- Justin Kahl [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files (x86)\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\Windows\UNNeroBackItUp.exe /UNINSTALL --> C:\Windows\UNNeroMediaHome.exe /UNINSTALL --> C:\Windows\UNNeroShowTime.exe /UNINSTALL --> C:\Windows\UNNeroVision.exe /UNINSTALL --> C:\Windows\UNRecode.exe /UNINSTALL AbiWord 2.4.6 (remove only) --> C:\Program Files (x86)\AbiSuite2\UninstallAbiWord2.exe Ad-Aware 2007 --> MsiExec.exe /X{46AC899A-9ECB-43DC-85DE-272E0D116A1E} Adobe Flash Player 9 ActiveX --> C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock Adobe Flash Player ActiveX --> C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin --> C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003} AIM 6 --> C:\Program Files (x86)\AIM6\uninst.exe AudioConverter Studio 5.9 --> "C:\Program Files (x86)\AudioConverter Studio\unins000.exe" AVG 8.0 --> C:\Program Files (x86)\AVG\AVG8\setup.exe /UNINSTALL AVI Movie Player --> C:\Program Files (x86)\AVI Movie Player\uninstall.exe Azureus Vuze --> C:\Program Files (x86)\Azureus\uninstall.exe BitTornado 0.3.17 --> C:\Program Files (x86)\BitTornado\uninst.exe COSMOSMotion 2007 SP0 --> MsiExec.exe /I{9BE2AFE1-617E-478F-9BE5-DABB63B4380A} COSMOSWorks 2007 SP0 --> MsiExec.exe /I{AF2D85EE-D6F9-4E7B-B9FA-BBB9BCA9A01E} Dassault Systemes Software B14 --> "C:\Program Files (x86)\Dassault Systemes\B14\intel_a\code\bin\Uninstall.exe" "C:\Program Files (x86)\Dassault Systemes\B14" "CODE" "GUI" "B14" "0" DVD Decrypter (Remove Only) --> "C:\Program Files (x86)\DVD Decrypter\uninstall.exe" DWGeditor --> MsiExec.exe /X{F5125699-C01A-4ED8-BD3A-265DF29859FE} Easy DVD Shrink --> C:\PROGRA~2\EASYDV~1\UNWISE.EXE C:\PROGRA~2\EASYDV~1\INSTALL.LOG eDrawings 2007 --> MsiExec.exe /I{75FEB085-179F-4C85-B0E4-B517D2160750} G-Force --> C:\Program Files (x86)\SoundSpectrum\G-Force\Uninstall.exe Halo 2 for Windows Vista --> C:\Program Files (x86)\Microsoft Games\Halo 2\StartUp.exe /tnp:/remove HijackThis 2.0.2 --> "C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe" /uninstall Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java(TM) 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Logitech Desktop Messenger --> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x9 UNINSTALL Logitech SetPoint --> C:\Program Files (x86)\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly Maple 10 --> "C:\Program Files\Maple 10\Uninstall_Maple 10\Uninstall Maple 10.exe" Microsoft Games for Windows - LIVE Redistributable --> MsiExec.exe /X{929CE49F-1CA7-4CF3-A9A1-6D757443C63F} Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE} Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE} Microsoft Office Enterprise 2007 --> "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISER /dll OSETUP.DLL Microsoft Office Enterprise 2007 --> MsiExec.exe /X{91120000-0030-0000-0000-0000000FF1CE} Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE} Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE} Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE} Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE} Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE} Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE} Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE} Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE} Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE} Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE} Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE} Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE} Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} Mozilla Firefox (2.0.0.16) --> C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe Mozilla Thunderbird (2.0.0.6) --> C:\Program Files (x86)\Mozilla Thunderbird\uninstall\helper.exe MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF} Nero 7 Essentials --> MsiExec.exe /X{A20A58C4-6784-4B4B-86CC-94E2E3671033} Nero PhotoShow Express 4 --> "C:\Program Files (x86)\Nero\Nero PhotoShow 4\data\Xtras\Uninstall.exe" neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI PowerDVD --> RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall PowerISO --> "C:\Program Files (x86)\PowerISO\uninstall.exe" QuickTime --> MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335} Realtek AC'97 Audio --> Alcrmv64.exe -r -m SecureShell --> "C:\Program Files (x86)\InstallShield Installation Information\{4F6F13BA-F5D1-4D4C-A5FF-485A5DFD3051}\setup.exe" -runfromtemp -l0x0409 -removeonly SecureShell --> MsiExec.exe /X{4F6F13BA-F5D1-4D4C-A5FF-485A5DFD3051} Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E} Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85} Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00} Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9} Security Update for Office 2007 (KB934062) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33} Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E} Security Update for Outlook 2007 (KB946983) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3} Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-002A-0000-1000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86} Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86} Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41} SolidWorks 2007 SP0 --> MsiExec.exe /I{95FCA50A-CF7D-457E-AF69-F058F8BC2844} SolidWorks Explorer 2007 sp0 --> MsiExec.exe /I{559FAB96-A0CD-4105-A02F-1C21DEBCEF89} SolidWorks Installation Manager --> MsiExec.exe /X{26621E14-A45B-45CD-9ED9-7A0A9B585DB4} Spybot - Search & Destroy --> "C:\Program Files (x86)\Spybot - Search & Destroy\unins001.exe" Spybot - Search & Destroy 1.5.2.20 --> "C:\Windows\unins000.exe" Update for Office 2007 (KB932080) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7} Update for Office 2007 (KB934391) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5} Update for Office 2007 (KB946691) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278} Update for Outlook 2007 Junk Email Filter (kb953463) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {1B78D541-9FF1-4330-ADD8-CED14F0C1E8E} VeohTV BETA --> C:\Program Files (x86)\InstallShield Installation Information\{97A96172-A963-4A37-9FFB-DA6805BB915A}\setup.exe -runfromtemp -l0x0409 VideoLAN VLC media player 0.8.6f --> C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe Visual C++ 8.0 Runtime Setup Package (x64) --> MsiExec.exe /I{021C4C4F-C93C-4425-BFFD-C2D16776BFAE} Winamp --> "C:\Program Files (x86)\Winamp\UninstWA.exe" Winamp Remote --> "C:\Program Files (x86)\Winamp Remote\uninstall.exe" WinRAR archiver --> C:\Program Files (x86)\WinRAR\uninstall.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type6745 / Success Event Submitted/Written: 07/25/2008 10:13:29 PM Event ID/Source: 5617 / WinMgmt Event Description: Event Record #/Type6744 / Success Event Submitted/Written: 07/25/2008 10:13:27 PM Event ID/Source: 5615 / WinMgmt Event Description: Event Record #/Type6742 / Success Event Submitted/Written: 07/25/2008 10:13:18 PM Event ID/Source: 902 / Software Licensing Service Event Description: The Software Licensing service has started. Event Record #/Type6734 / Warning Event Submitted/Written: 07/25/2008 10:09:33 PM Event ID/Source: 1530 / profsvc Event Description: 1 user registry handles leaked from \Registry\User\S-1-5-21-2146798151-3893196241-1090079629-1000_Classes: Process 984 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2146798151-3893196241-1090079629-1000_CLASSES Event Record #/Type6733 / Warning Event Submitted/Written: 07/25/2008 10:09:33 PM Event ID/Source: 1530 / profsvc Event Description: 1 user registry handles leaked from \Registry\User\S-1-5-21-2146798151-3893196241-1090079629-1000: Process 984 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2146798151-3893196241-1090079629-1000 -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type129883 / Warning Event Submitted/Written: 07/25/2008 10:30:54 PM Event ID/Source: 3004 / WinDefend Event Description: %%8271.1.1505.0{CFF093F2-B0CC-46C5-98AC-DDE8954B42DC}DustyJustin KahlS-1-5-21-2146798151-3893196241-1090079629-1000Unknown%%832driver:xpdt0%%807 Event Record #/Type129882 / Warning Event Submitted/Written: 07/25/2008 10:30:54 PM Event ID/Source: 3004 / WinDefend Event Description: %%8271.1.1505.0{AA420DBA-9119-472B-8978-F955C8953467}DustyJustin KahlS-1-5-21-2146798151-3893196241-1090079629-1000Unknown%%832service:xpdt0%%807 Event Record #/Type129881 / Warning Event Submitted/Written: 07/25/2008 10:30:54 PM Event ID/Source: 3004 / WinDefend Event Description: %%8271.1.1505.0{451567EA-5BF4-4E55-A563-9EFDA5CA8F93}DustyJustin KahlS-1-5-21-2146798151-3893196241-1090079629-1000Unknown%%832driver:huy320%%807 Event Record #/Type129880 / Warning Event Submitted/Written: 07/25/2008 10:30:51 PM Event ID/Source: 3004 / WinDefend Event Description: %%8271.1.1505.0{83E75807-5314-4D7A-8689-3D3AAFEBF627}DustyJustin KahlS-1-5-21-2146798151-3893196241-1090079629-1000Unknown%%832service:huy320%%807 Event Record #/Type129879 / Warning Event Submitted/Written: 07/25/2008 10:30:51 PM Event ID/Source: 3004 / WinDefend Event Description: %%8271.1.1505.0{463FCE4F-8596-4FBC-9EFA-9748B53CB09C}DustyJustin KahlS-1-5-21-2146798151-3893196241-1090079629-1000Unknown%%832driver:lzx320%%807 -- End of Deckard's System Scanner: finished at 2008-07-25 22:32:26 ------------