Sorry its taken time but heres the main txt & extra txt plus tha kaspersky virus log, 4 found please if you can help.
Deckard's System Scanner v20070708.52
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlon XP 3200+
Percentage of Memory in Use: 25%
Physical Memory (total/avail): 1535.49 MiB / 1142.91 MiB
Pagefile Memory (total/avail): 3434.78 MiB / 3210.31 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1975.23 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 114.49 GiB total, 36.55 GiB free.
D: is Fixed (NTFS) - 114.49 GiB total, 9.73 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
J: is Removable (No Media)
K: is Removable (No Media)
L: is Removable (No Media)
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
AUState says computer is ready and waiting.
Windows Internal Firewall is disabled.
AntiVirusDisableNotify is set.
AV: AVG 7.5.476 v7.5.476 (GRISOFT)
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Pinnacle\\MediaCenter\\PMC.exe"="C:\\Program Files\\Pinnacle\\MediaCenter\\PMC.exe:LocalSubNet:Enabled:Pmc.exe"
"C:\\Program Files\\Pinnacle\\MediaCenter\\PSST.exe"="C:\\Program Files\\Pinnacle\\MediaCenter\\PSST.exe:LocalSubNet:Enabled:PSST.exe"
"C:\\Program Files\\Pinnacle\\MediaCenter\\PMSInstallInit.exe"="C:\\Program Files\\Pinnacle\\MediaCenter\\PMSInstallInit.exe:LocalSubNet:Enabled:PMSInstallInit.exe"
"C:\\Program Files\\Pinnacle\\MediaCenter\\PMC.Tvtv.Wizard.exe"="C:\\Program Files\\Pinnacle\\MediaCenter\\PMC.Tvtv.Wizard.exe:LocalSubNet:Enabled:PMC.Tvtv.Wizard.exe"
"C:\\Program Files\\Pinnacle\\Shared Files\\Programs\\MediaCenterService\\PMC.Service.Main.exe"="C:\\Program Files\\Pinnacle\\Shared Files\\Programs\\MediaCenterService\\PMC.Service.Main.exe:LocalSubNet:Disabled:PMCService"
"C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza Ultimate File Sharing"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\kevin\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=KEVIN-9OVL8YAP2
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\kevin
LOGONSERVER=\\KEVIN-9OVL8YAP2
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Executive Software\Diskeeper\;C:\Program Files\Common Files\iZotope\Runtimes;C:\Program Files\Common Files\Adobe\AGL;C:\PROGRA~1\COSIDS;
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
PS5ROOT=C:\Program Files\Roxio\Easy CD Creator 6\PhotoSuite\
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\kevin\LOCALS~1\Temp
TMP=C:\DOCUME~1\kevin\LOCALS~1\Temp
USERDOMAIN=KEVIN-9OVL8YAP2
USERNAME=kevin
USERPROFILE=C:\Documents and Settings\kevin
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
kevin
(admin)Administrator.KEVIN-9OVL8YAP2
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\PROGRA~1\BLUEYO~1\Uninstall.exe blueyonder
--> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3D Prophet RADEON Series --> rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Abacast Client --> C:\PROGRA~1\Abacast\UNWISE.EXE C:\PROGRA~1\Abacast\client.LOG
Acoustica Effects Pack --> C:\PROGRA~1\UNWISE.EXE C:\PROGRA~1\INSTALL.LOG
Acoustica Mixcraft --> C:\PROGRA~1\ACOUST~1\UNWISE.EXE C:\PROGRA~1\ACOUST~1\INSTALL.LOG
Ad-Aware SE Professional --> C:\PROGRA~1\Lavasoft\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~2\INSTALL.LOG
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Stock Photos 1.0 --> MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}
Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
Antares Filter VST DX v1.01 --> C:\PROGRA~1\Antares\UNINST~1\UNWISE.EXE C:\PROGRA~1\Antares\UNINST~1\INSTALL.LOG
ANWIDA Soft DX Reverb 1.1 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ANWIDA Soft\DX Reverb 1.1\Uninst.isu"
AnyDVD --> "C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
Audio Conversion Wizard 1.4 --> "C:\Program Files\LitexMedia\Audio Conversion Wizard\unins000.exe"
Audio WASP --> MsiExec.exe /I{B3A454E9-BA17-4F67-A638-13584380BA1F}
AVG Free Edition --> C:\Program Files\Grisoft\AVG Free\setup.exe /UNINSTALL
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Belkin Bluetooth Software --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}
blueyonder Instant Support Tool --> C:\WINDOWS\Motive\blueyonder\MCCUninst.exe
Cakewalk VST Adapter 4.4.4.0 --> C:\PROGRA~1\Cakewalk\CAKEWA~1\UNWISE.EXE C:\PROGRA~1\Cakewalk\CAKEWA~1\INSTALL.LOG
CDRWIN 5 --> MsiExec.exe /I{9B2B0EAD-2CC7-4589-B3AA-D23BAB724065}
CloneCD --> "C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
CloneDVD2 --> "C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Codec Pack - All In 1 6.0.1.8 --> C:\WINDOWS\iun6002.exe "C:\Program Files\Codec Pack - All In 1\irunin.ini"
Cool Edit Pro 2.1 --> C:\Program Files\coolpro2\cep2unin.exe
DigiDoc --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45159A27-7EA1-4BC8-A6EE-91E3F47A518E}\setup.exe"
Diskeeper Professional Edition --> MsiExec.exe /X{BDCE8614-49F7-4A51-B83A-544535D2DD09}
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DMXFireDriver --> "C:\DMXXfire1024\sp_uninstall.exe"
DreamStation DXi2 --> C:\WINDOWS\DSDXIRMV.EXE C:\PROGRAM FILES\CAKEWALK\SHARED DXI\AUDIO SIMULATION\DREAMSTATION DXI2
Easy CD & DVD Creator 6 --> MsiExec.exe /I{644F9DBE-CEDB-45AF-ACB8-E26692B74F62}
ed2k link catch0r --> "C:\Program Files\ed2k link catch0r\Uninstall.exe"
eDonkey2000 --> "C:\Program Files\eDonkey2000\uninstall_eDonkey2000.exe"
Elevayta VST Rak V1.21 --> "C:\Program Files\Elevayta Productivity Tools\Elevayta VST Rak\unins000.exe"
EPSON CardMonitor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\SETUP.EXE" -l0x9 uninst
EPSON PhotoQuicker3.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{65F5B7AF-3363-11D7-BB6B-00018021113F}\SETUP.EXE" -l0x9 uninst
EPSON PhotoStarter3.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C48817E7-AA05-4151-A99D-1E1E550CE801}\SETUP.EXE" -l0x9 uninst
EPSON Print CD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\SETUP.EXE" -l0x9 -SYSTEM
EPSON PRINT Image Framer Tool2.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{23B59ED4-C360-11D7-875B-0090CC005647}\SETUP.EXE" -l0x9 anything
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /r
ESPR300 Reference Guide --> C:\Program Files\EPSON\ESPR300\REF_G\DOCUNINS.EXE
ESPR300 Software Guide --> C:\Program Files\EPSON\ESPR300\PQU_G\DOCUNINS.EXE
ESPR300 Standalone Guide --> C:\Program Files\EPSON\ESPR300\STA_G\DOCUNINS.EXE
Fellowes/NEATO MediaFACE --> C:\PROGRA~1\MEDIAF~2\UNWISE.EXE C:\PROGRA~1\MEDIAF~2\INSTALL.LOG
FL Studio 5 --> C:\Program Files\Image-Line\FLStudio5\uninstall.exe
fxpansion!RobotikVocoder --> C:\UNWISE.EXE D:\ACIDLO~1\ROBOTI~1\FXPANS~1\INSTALL.LOG
GSpot Codec Information Appliance --> C:\Program Files\GSpot\Uninstall.exe
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 1.99.1 --> C:\Documents and Settings\kevin\My Documents\hijackthis\HijackThis.exe /uninstall
Hypersonic 1.1.1 --> C:\PROGRA~1\STEINB~1\VSTPLU~1\HYPERS~1\UNWISE.EXE C:\PROGRA~1\STEINB~1\VSTPLU~1\HYPERS~1\INSTALL.LOG
Internet Explorer Q903235 --> C:\WINDOWS\ieuninst.exe C:\WINDOWS\INF\Q903235.inf
IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe
IsoBuster 1.6 --> "C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
IZotope Ozone DX VST RTAS v3.08 --> C:\PROGRA~1\iZotope\OZONE3~1\UNWISE.EXE C:\PROGRA~1\iZotope\OZONE3~1\INSTALL.LOG
iZotope Vinyl --> "C:\Program Files\iZotope\Vinyl\unins000.exe"
J2SE Runtime Environment 5.0 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
J2SE Runtime Environment 5.0 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 8 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150080}
Java 2 Runtime Environment Standard Edition v1.3.1_04 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\JavaSoft\JRE\1.3.1_04\Uninst.isu"
LimeWire --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{4727EB39-BB6F-4571-A0B6-AB6331D57665}
LimeWire 4.9.30 --> "C:\Program Files\LimeWire\uninstall.exe"
Live 5.0.1 --> C:\PROGRA~1\Ableton\LIVE50~1.1\Install\UNWISE.EXE C:\PROGRA~1\Ableton\LIVE50~1.1\Install\INSTALL.LOG
Live 5.0.2 --> C:\PROGRA~1\Ableton\LIVE50~1.2\Install\UNWISE.EXE C:\PROGRA~1\Ableton\LIVE50~1.2\Install\INSTALL.LOG
Logitech Gaming Software --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9242864-2841-4ADE-86E0-8F90F91B04DD}\setup.exe" -l0x40c
LogViewer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5090856-6E87-4AE1-B6FE-DD4149CB097A}\Setup.exe" -l0x9
Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Making Waves v1.95 --> C:\WINDOWS\UNWISE.EXE C:\audio\makewave\INSTALL.LOG
MediaFood Designer Tools 1.31 --> "C:\Program Files\MediaFood\unins000.exe"
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft DirectX Transform optional components --> RUNDLL32.EXE ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\DXTXTRA.INF,UNINSTALL.NT,12
Microsoft Plus! for Windows XP --> MsiExec.exe /I{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR) --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A}
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
Mixcraft RealAudio Support --> C:\PROGRA~1\ACOUST~1\UNWISE.EXE C:\PROGRA~1\ACOUST~1\INSTALL.LOG
Mixed In Key --> MsiExec.exe /X{866EE467-669B-4911-9D1C-FB3B4DBD897A}
MixMeister BPM Analyzer 1.0 --> "C:\Program Files\MixMeister BPM Analyzer\unins000.exe"
MixMeister Pro 6 --> MsiExec.exe /I{6FF6CE46-2F27-4A4B-916F-AB1C678C8F5E}
ModPacker 1.0 --> MsiExec.exe /X{CC457DF0-D7AF-4362-A9D5-F87516FD3147}
MP3 Player Utilities --> MsiExec.exe /I{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B}
Nero Fast CD-Burning Plug-in --> C:\WINDOWS\UnWMPBurn.exe /UNINSTALL
Nero PhotoShow Express --> "C:\Program Files\Ahead\Nero PhotoShow\data\Xtras\Uninstall.exe"
Nero Suite --> C:\Program Files\Common Files\Nero\Uninstall\SetupX.exe /uninstall ExtraUninstallID=""
NewsBin Pro 4.3 --> C:\Program Files\nbpro\uninst-nbpro.exe
NewsLeecher --> "C:\Program Files\NewsLeecher\uninstall.exe"
Nimo Codecs Pack v5.0 (Remove Only) --> "C:\Program Files\NimoCodec Pack\uninstall.exe"
NVIDIA Drivers --> C:\WINDOWS\System32\NVUNINST.EXE UninstallGUI
PCI Audio Applications --> C:\Program Files\PCI Audio Applications\Bin\Uninstall.exe
PCI Audio Driver --> cmuninst.exe
Photo Resizer 1.06 (Free version) --> "c:\Program Files\Photo_Resizer\unins000.exe"
PIF DESIGNER2.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{23B59B9F-C360-11D7-875B-0090CC005647}\SETUP.EXE" -l0x9 anything
Plaxo Toolbar for Outlook and Outlook Express --> C:\Program Files\Plaxo\2.11.1.5\uninstall.exe
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Reason --> MsiExec.exe /X{E52BFE61-E0FF-11D6-9D69-00065BABCB42}
ReBirth 2.0 --> MsiExec.exe /X{427B2195-6A44-4B5F-81A1-135C8918038D}
rgcAudio Reverb v1.0 --> "C:\Program Files\rgcAudio\DirectX\Reverb\unins000.exe"
Roomulator VST 2.02 --> C:\WINDOWS\iun6002.exe "C:\Program Files\VstPlugins\Roomulator VST\irunin.ini"
ScanToWeb --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}\SETUP.EXE" ADDREMOVEDLG
Shareaza version 2.2.1.0 --> "C:\Program Files\Shareaza\Uninstall\unins000.exe"
SnagIt 8 --> MsiExec.exe /I{0AEA9ECE-2AD0-4DF0-932E-F0AC6B771749}
SONAR Home Studio 4 --> C:\PROGRA~1\Cakewalk\SONARH~1\UNWISE.EXE C:\PROGRA~1\Cakewalk\SONARH~1\INSTALL.LOG
Sonic Foundry XFX vol3 build 72 --> C:\audio\xfx3\UNWISE.EXE C:\audio\xfx3\INSTALL.LOG
Sony ACID Pro 5.0 --> MsiExec.exe /X{76902AF9-DA86-419D-B533-077643124722}
Sony Sound Forge 7.0 --> MsiExec.exe /I{EA1FFC52-3B2A-4FE8-A6CD-1EB914D8B644}
Sony Sound Forge 8.0 --> MsiExec.exe /X{767572FD-4D01-4FA3-B0A6-4B09FB2CFC37}
Sound Laundry Terratec --> C:\WINDOWS\Algoui.exe sle.exe alsetup.exe
Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steinberg VoiceMachine v1.0 --> C:\PROGRA~1\VSTPLU~1\STEINB~1\UNWISE.EXE C:\PROGRA~1\VSTPLU~1\STEINB~1\INSTALL.LOG
Synacast Plug-in 1.1.0.7 --> C:\Program Files\Common Files\Synacast\SynaLive\uninst.exe
Tablet --> C:\Program Files\Tablet\Remove.exe /u
TerraTec RIAA PlugIn --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8636CD81-7696-43CA-84D8-866AAD9131D7}\Setup.exe" -l0x9
The FilmMachine 1.5.0.11 --> "C:\Program Files\The FilmMachine\unins000.exe"
TimeWorks Reverb 4080L v1.101 --> C:\WINDOWS\UNWISE.EXE C:\audio\TIMEWO~1\Reverb\install.log
TMPGEnc Studio --> "C:\Program Files\Pegasys TMPGEnc Studio\unins000.exe"
Ulead Data-Add 2.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AD8E6D29-95EC-494E-8AF5-566E784819A6}\setup.exe" -l0x9
Ulead DVD MovieFactory 4.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{448AB2CB-C94A-47DE-80B8-9D7824DEFA57}\setup.exe" -l0x9
Ulead Photo Explorer 7.0 SE Platinum --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7C6D8763-EEB7-433E-A75E-2AB44892FCA2}\setup.exe" -l0x9
Video Edit Magic 3.36 --> "C:\Program Files\Deskshare\Video Edit Magic 3\unins000.exe"
Virtual Sound Canvas DXi --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E10E7FC-36CD-4C22-AC20-9E15692E8C2F}\setup.exe" UNINSTALL_XXX
Wave Arts MasterVerb --> C:\PROGRA~1\WAVEAR~1\MASTER~1\UNWISE.EXE C:\PROGRA~1\WAVEAR~1\MASTER~1\INSTAL~1.LOG
WaveLab Lite --> "C:\Program Files\Steinberg\WaveLab Lite\Unwise.exe" C:\PROGRA~1\STEINB~1\WAVELA~1\install.log
Waves 4.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C4D25EB-6513-4702-8355-F4194DE2E1D9}\setup.exe" -l0x9
Waves Gold Processors 3.5 --> C:\PROGRA~1\Waves\WAVES3~1\UNWISE.EXE C:\PROGRA~1\Waves\WAVES3~1\INSTALL.LOG
Waves Masters Bundle 3.5 --> C:\PROGRA~1\Waves\MASTER~1\UNWISE.EXE C:\PROGRA~1\Waves\MASTER~1\INSTALL.LOG
Waves Native Power Pack v2.35 --> C:\audio\waves\NATIVE~1\UNWISE.EXE C:\audio\waves\NATIVE~1\install.log
Waves Renaissance Collection 2 3.5 --> C:\PROGRA~1\Waves\RENCOL~1\UNWISE.EXE C:\PROGRA~1\Waves\RENCOL~1\INSTALL.LOG
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
XviD MPEG-4 Video Codec --> "C:\Program Files\XviD\unins000.exe"
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
-- End of Deckard's System Scanner: finished at 2007-07-11 at 14:09:07 ---------
VIRUS LOG BELOW>>>>
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, July 11, 2007 4:32:51 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 11/07/2007
Kaspersky Anti-Virus database records: 361143
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
H:\
I:\
J:\
K:\
L:\
Scan Statistics:
Total number of scanned objects: 190079
Number of viruses found: 4
Number of infected objects: 5 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:04:58
Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\backup\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.i skipped
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\kevin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\History\History.IE5\MSHist012007071120070712\index.dat Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\Temp\Perflib_Perfdata_69c.dat Object is locked skipped
C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\ID9YZAPG\gULEjWiXk[1].htm Infected: Exploit.Win32.IMG-ANI.af skipped
C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\kevin\ntuser.dat Object is locked skipped
C:\Documents and Settings\kevin\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP100\A0022677.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP100\A0022709.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP100\A0022724.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0022765.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0022779.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0022792.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023791.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023800.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023810.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023823.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023839.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP101\A0023848.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP102\change.log Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP92\A0017067.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP93\A0017087.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017165.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017178.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017193.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017203.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017217.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP94\A0017232.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP95\A0017248.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP95\A0017266.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP95\A0018266.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP96\A0018303.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP96\A0019303.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP96\A0019307.exe Infected: Trojan-Downloader.Win32.Small.cxs skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP96\A0019332.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP97\A0019377.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP97\A0020376.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP97\A0020387.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP97\A0020399.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP97\A0020417.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP98\A0022460.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP98\A0022518.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP98\A0022538.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP99\A0022564.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP99\A0022599.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP99\A0022621.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP99\A0022631.exe Object is locked skipped
C:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP99\A0022655.exe Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UPCTP_0001_91M1101NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.i skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\service\dlg.exe Object is locked skipped
C:\WINDOWS\system32\service\explorer.exe Infected: Trojan-Spy.Win32.Agent.mx skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_1d4.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{341936DC-D8F5-49DE-A8A1-25768EF52141}\RP102\change.log Object is locked skipped
Scan process completed.