adoginhispen.com b.skitodayplease.com --Trojan problem!
#1
Posted 04 February 2008 - 07:33 PM
#2
Posted 04 February 2008 - 09:13 PM
Welcome to G2Go.
==================
* Click here to download HJTsetup.exe
- Save HJTsetup.exe to your desktop.
- Doubleclick on the HJTsetup.exe icon on your desktop.
- By default it will install to C:\Program Files\Trend Micro\Hijack This.
- Click on I agree
- Then Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
- Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
- Come back here to this thread and Paste the log in your next reply.
- DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
#3
Posted 04 February 2008 - 11:11 PM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:34 PM, on 2/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.co...GenXInstall.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...wlscbase370.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1177009672531
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} (O2C-Player (ELECO Software GmbH)) - http://www.o2c.de/do...d/o2cplayer.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/...all/Crusher.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Desktop Utilities Service (iHCService) - Unknown owner - C:\Program Files\Intel\IDU\IDUServ.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 10763 bytes
#4
Posted 05 February 2008 - 03:10 AM
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT - Press 1, then press Enter
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
Also Please download Deckard's System Scanner (DSS) and save it to your Desktop.
- Close all other windows before proceeding.
- Double-click on dss.exe and follow the prompts.
- When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
#5
Posted 05 February 2008 - 04:05 PM
Find AWF report by noahdfear ©2006
Version 1.40
The current date is: Tue 02/05/2008
The current time is: 13:48:02.78
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\INTELA~1\BAK
08/09/2005 04:35 PM 8,597,586 IntelAudioStudio.exe
1 File(s) 8,597,586 bytes
Directory of C:\PROGRA~1\ITUNES\BAK
11/15/2007 01:11 PM 267,048 iTunesHelper.exe
1 File(s) 267,048 bytes
Directory of C:\PROGRA~1\MESSEN~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\QUICKT~1\BAK
01/10/2008 03:27 PM 385,024 qttask.exe
1 File(s) 385,024 bytes
Directory of C:\WINDOWS\SYSTEM32\BAK
02/28/2006 04:00 AM 15,360 ctfmon.exe
07/19/2005 10:06 AM 77,824 hkcmd.exe
07/19/2005 10:10 AM 114,688 igfxpers.exe
07/19/2005 10:09 AM 94,208 igfxtray.exe
07/09/2001 10:50 AM 155,648 NeroCheck.exe
5 File(s) 457,728 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\BAK
06/27/2007 06:32 AM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytes
Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK
07/10/2007 05:29 AM 1,836,544 GoogleDesktop.exe
1 File(s) 1,836,544 bytes
Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK
06/18/2003 11:00 AM 200,704 mnyexpr.exe
1 File(s) 200,704 bytes
Directory of C:\PROGRA~1\SANDISK\SANSAU~1\BAK
10/22/2007 12:52 PM 75,584 SansaDispatch.exe
1 File(s) 75,584 bytes
Directory of C:\PROGRA~1\SLYSOFT\ANYDVD\BAK
12/21/2007 04:34 AM 1,649,600 AnyDVD.exe
1 File(s) 1,649,600 bytes
Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK
08/30/2007 05:43 PM 4,670,704 YAHOOM~1.EXE
1 File(s) 4,670,704 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
10/10/2007 06:51 PM 39,792 Reader_sl.exe
1 File(s) 39,792 bytes
Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
08/22/2007 09:41 PM 185,632 realsched.exe
1 File(s) 185,632 bytes
Directory of C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK
09/25/2007 01:11 AM 132,496 jusched.exe
1 File(s) 132,496 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
8597586 Aug 9 2005 "C:\Program Files\Intel Audio Studio\bak\IntelAudioStudio.exe"
267048 Nov 15 2007 "C:\Program Files\iTunes\iTunesHelper.exe"
267048 Nov 15 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102400 Feb 5 2008 "C:\WINDOWS\Installer\{4F5CE18C-D97D-48FF-A510-A0D90C918294}\iTunesIco.exe"
116008 Nov 22 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe"
116008 Nov 22 2007 "C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6DNSWCOG\iTunesSetupAdmin[1].exe"
385024 Jan 10 2008 "C:\Program Files\QuickTime\bak\qttask.exe"
15360 Feb 28 2006 "C:\WINDOWS\system32\ctfmon.exe"
15360 Feb 28 2006 "C:\WINDOWS\system32\bak\ctfmon.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
52272 Jan 28 2008 "C:\Program Files\Google\googletoolbar2user.exe"
1823792 Jan 31 2008 "C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe"
69632 Nov 13 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
26694 Jan 30 2008 "C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
13411824 Nov 18 2007 "C:\Documents and Settings\Maxine\My Documents\My Downloads\Google_Earth_BZXD.exe"
1145896 Aug 22 2007 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138680 Jan 28 2008 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\bak\GoogleDesktop.exe"
1831936 May 12 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp1\GoogleDesktopSetupHelper.exe"
1831936 May 13 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp2\GoogleDesktopSetupHelper.exe"
1831936 May 15 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp3\GoogleDesktopSetupHelper.exe"
1836544 Jul 9 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp4\GoogleDesktopSetupHelper.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp5\GoogleDesktopSetupHelper.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\2.2.1070.1219\GoogleUpdaterRestartManager.exe"
52272 Jan 28 2008 "C:\Program Files\Google\googletoolbar2user.exe"
1823792 Jan 31 2008 "C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe"
69632 Nov 13 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
26694 Jan 30 2008 "C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
13411824 Nov 18 2007 "C:\Documents and Settings\Maxine\My Documents\My Downloads\Google_Earth_BZXD.exe"
1145896 Aug 22 2007 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138680 Jan 28 2008 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\bak\GoogleDesktop.exe"
1831936 May 12 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp1\GoogleDesktopSetupHelper.exe"
1831936 May 13 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp2\GoogleDesktopSetupHelper.exe"
1831936 May 15 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp3\GoogleDesktopSetupHelper.exe"
1836544 Jul 9 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp4\GoogleDesktopSetupHelper.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp5\GoogleDesktopSetupHelper.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\2.2.1070.1219\GoogleUpdaterRestartManager.exe"
200704 Jun 18 2003 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe"
75584 Oct 22 2007 "C:\Program Files\SanDisk\Sansa Updater\bak\SansaDispatch.exe"
108616 May 15 2007 "C:\Documents and Settings\Maxine\Local Settings\Temp\{65DA4E07-0692-450B-A48C-9FB475B1DE3C}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\SansaDispatchSchedule.exe"
1649600 Dec 21 2007 "C:\Program Files\SlySoft\AnyDVD\bak\AnyDVD.exe"
4670704 Aug 30 2007 "C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE"
39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
185632 Aug 22 2007 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe"
end of report
MAIN TXT>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Deckard's System Scanner v20071014.68
Run by Maxine on 2008-02-05 13:50:59
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
105: 2008-02-05 21:51:18 UTC - RP318 - Deckard's System Scanner Restore Point
104: 2008-02-05 05:06:49 UTC - RP317 - Software Distribution Service 3.0
103: 2008-02-05 04:48:31 UTC - RP316 - Installed WD Diagnostics
102: 2008-02-05 04:46:21 UTC - RP315 - Installed WD FAT32 Formatter
101: 2008-02-04 19:39:17 UTC - RP314 - Installed Symantec Technical Support Web Controls
-- First Restore Point --
1: 2007-11-08 00:18:39 UTC - RP214 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Maxine.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:53:56 PM, on 2/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\Maxine\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Maxine.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.co...GenXInstall.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...wlscbase370.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1177009672531
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} (O2C-Player (ELECO Software GmbH)) - http://www.o2c.de/do...d/o2cplayer.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/...all/Crusher.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Desktop Utilities Service (iHCService) - Unknown owner - C:\Program Files\Intel\IDU\IDUServ.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 10881 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 Gernuwa - c:\windows\system32\drivers\gernuwa.sys <Not Verified; Symantec Corporation; pcAnywhere>
R1 AW_HOST - c:\windows\system32\drivers\aw_host5.sys <Not Verified; Symantec Corporation; pcAnywhere>
R1 awecho - c:\windows\system32\drivers\awechomd.sys <Not Verified; Symantec Corporation; pcAnywhere>
R1 awlegacy - c:\windows\system32\drivers\awlegacy.sys <Not Verified; Symantec Corporation; pcAnywhere>
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>
R2 OsaFsLoc - c:\windows\system32\drivers\osafsloc.sys <Not Verified; OSA Technologies; >
R2 osaio - c:\windows\system32\drivers\osaio.sys <Not Verified; Avocent/OSA Technologies Inc.; Windows ® Server 2003 DDK driver>
R2 SIODRV - c:\windows\system32\drivers\siodrv.sys <Not Verified; Intel Corporation; Intel® Active Monitor>
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
R3 NTIDrvr (Upper Class Filter Driver) - c:\windows\system32\drivers\ntidrvr.sys <Not Verified; NewTech Infosystems, Inc.; >
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 SMBios (Intel ® System Management BIOS Service) - c:\windows\system32\drivers\smbios.sys <Not Verified; Intel Corporation; Intel ® System Management BIOS Driver>
S3 exdisk (Express Disk Service) - c:\windows\system32\drivers\exdisk.sys
S3 smbusp (Intel® SMBus 2.0 Driver) - c:\windows\system32\drivers\intelsmb.sys <Not Verified; Intel Corporation; Intel® SMBus Controller>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
S2 iHCService (Intel® Desktop Utilities Service) - "c:\program files\intel\idu\iduserv.exe" (file missing)
S3 awhost32 (Symantec pcAnywhere Host Service) - "c:\program files\symantec\pcanywhere\awhost32.exe" <Not Verified; Symantec Corporation; pcAnywhere>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-04 20:02:06 624 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Maxine.job
2008-01-31 13:15:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-01-05 and 2008-02-05 -----------------------------
2008-02-04 21:06:53 0 d-------- C:\Program Files\Trend Micro
2008-02-04 21:01:22 0 d-------- C:\Documents and Settings\Maxine\WD Sync Data
2008-02-04 20:46:22 0 d-------- C:\Program Files\Western Digital Technologies
2008-02-04 10:41:32 0 dr-h----- C:\$VAULT$.AVG
2008-02-04 10:01:57 0 d-------- C:\Documents and Settings\Maxine\Application Data\AVG7
2008-02-04 10:01:46 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-04 10:01:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-04 10:01:09 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-03 20:55:53 0 d-------- C:\Program Files\Windows Live Safety Center
2008-02-02 09:04:59 19 --a------ C:\WINDOWS\msxfcg32.dll
2008-01-31 09:59:46 0 d-------- C:\Program Files\Lavasoft
2008-01-31 09:59:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-30 17:00:11 0 d-------- C:\Documents and Settings\Default User\Application Data\Macromedia
2008-01-29 20:19:25 0 d-------- C:\Documents and Settings\Maxine\Application Data\Roxio
2008-01-29 18:56:12 0 d-------- C:\Documents and Settings\All Users\Application Data\Napster
2008-01-28 17:04:41 0 d-------- C:\WINDOWS\system32\bak
2008-01-28 15:27:13 0 dr-h----- C:\Documents and Settings\Maxine\Application Data\yahoo!
2008-01-28 13:58:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-28 12:17:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-19 11:07:03 0 d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-01-19 10:33:07 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-01-19 10:33:07 0 d-------- C:\Documents and Settings\Maxine\Application Data\Vso
2008-01-19 10:33:07 47360 --a------ C:\Documents and Settings\Maxine\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-01-19 10:33:05 0 d-------- C:\Program Files\DVDFab Gold 4
2008-01-19 09:25:26 0 d-------- C:\Program Files\DVD Shrink
2008-01-17 21:08:51 0 d-------- C:\Program Files\QuickTime
2008-01-05 11:56:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
-- Find3M Report ---------------------------------------------------------------
2008-02-05 13:52:33 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-05 13:09:16 0 d-------- C:\Program Files\iTunes
2008-02-04 17:54:32 0 d-------- C:\Documents and Settings\Maxine\Application Data\Ahead
2008-02-04 15:47:09 0 d-------- C:\Program Files\Intel Audio Studio
2008-02-03 20:34:10 0 d-------- C:\Program Files\Online Services
2008-02-03 20:33:50 0 d-------- C:\Program Files\Windows NT
2008-02-03 20:25:42 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-03 20:25:37 0 d-------- C:\Program Files\Common Files
2008-02-03 20:17:33 0 d-------- C:\Documents and Settings\Maxine\Application Data\MSN6
2008-01-31 10:02:12 0 d-------- C:\Program Files\Hormonal Forecaster
2008-01-31 09:59:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-30 08:55:33 0 d-------- C:\Program Files\Yahoo!
2008-01-30 08:52:45 0 d-------- C:\Program Files\Elaborate Bytes
2008-01-30 08:52:19 0 d-------- C:\Program Files\Best Buy Rhapsody
2008-01-28 17:04:41 0 d-------- C:\Program Files\Messenger
2008-01-28 13:59:04 0 d-------- C:\Program Files\Google
2008-01-27 00:01:14 4 --a------ C:\WINDOWS\system32\340823
2008-01-26 19:12:19 0 d-------- C:\Documents and Settings\Maxine\Application Data\Real
2008-01-20 19:07:29 0 d-------- C:\Program Files\Symantec
2008-01-19 10:33:13 34 --a------ C:\Documents and Settings\Maxine\Application Data\pcouffin.log
2008-01-19 10:33:07 1144 --a------ C:\Documents and Settings\Maxine\Application Data\pcouffin.inf
2008-01-19 10:33:07 7887 --a------ C:\Documents and Settings\Maxine\Application Data\pcouffin.cat
2007-12-25 18:01:48 0 d-------- C:\Documents and Settings\Maxine\Application Data\PlayFirst
2007-12-25 18:01:21 0 d-------- C:\Program Files\Chocolatier
2007-12-25 17:51:02 0 d-------- C:\Program Files\Wyzo
2007-12-23 19:48:43 0 d-------- C:\Program Files\bfgclient
2007-12-22 10:23:02 520192 --a------ C:\WINDOWS\system32\Beautiful Katamari.scr <Not Verified; ScreenTime Media; ScreenTime For Flash>
2007-12-05 09:26:25 0 d-------- C:\Documents and Settings\Maxine\Application Data\Adobe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"farstone"="" []
"SigmatelSysTrayApp"="sttray.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [01/31/2008 09:23 AM]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [06/04/2007 06:05 PM]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [06/25/2007 09:00 PM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [11/28/2007 07:51 PM]
"QuickTime Task"="C:\Program Files\QuickTime\bak\qttask.exe" [01/10/2008 03:27 PM]
"NapsterShell"="C:\Program Files\Napster\napster.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [02/04/2008 10:01 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [11/15/2007 01:11 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [02/28/2006 04:00 AM]
"Aim6"="" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [04/14/2005 03:56 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [1/28/2008 1:58:28 PM]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [4/10/2007 5:10:46 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 02/14/2006 11:00 AM 8704 C:\WINDOWS\system32\PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
*Newly Created Service* - COMHOST
-- End of Deckard's System Scanner: finished at 2008-02-05 13:54:25 ------------
EXTRA TXT>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 50%
Physical Memory (total/avail): 1014.03 MiB / 505.51 MiB
Pagefile Memory (total/avail): 1673.22 MiB / 1283.17 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1927.04 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 149.04 GiB total, 118.37 GiB free.
D: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD1600JS-61MHB1 - 149.05 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 149.04 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FirstRunDisabled is set.
FW: Norton Internet Security v2007 (Symantec Corporation)
AV: AVG 7.5.516 v7.5.516 (Grisoft)
AV: Norton Internet Security v2007 (Symantec Corporation)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Symantec\\pcAnywhere\\Winaw32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\Winaw32.exe:*:Enabled:Symantec pcAnywhere"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Maxine\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MAXINE-FD6A8675
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Maxine
LOGONSERVER=\\MAXINE-FD6A8675
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Symantec\pcAnywhere\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 6 Stepping 5, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0605
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Maxine\LOCALS~1\Temp
TMP=C:\DOCUME~1\Maxine\LOCALS~1\Temp
USERDOMAIN=MAXINE-FD6A8675
USERNAME=Maxine
USERPROFILE=C:\Documents and Settings\Maxine
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
Maxine (admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNNMP.exe /UNINSTALL
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
AIM 6 --> C:\Program Files\AIM6\uninst.exe
AnyDVD --> "C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
AOpen FM56-PLV Controllerless PCI Modem --> C:\UIU\CXT10B4\HXFSETUP.EXE -U -IVEN_14F1&DEV_10B4&SUBSYS_010DA0A0
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Apple Mobile Device Support --> MsiExec.exe /I{B5C209B1-8DDB-4642-A573-375B951514CB}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
Beautiful Katamari Screen Saver --> C:\WINDOWS\system32\Beautiful Katamari.scr /u
Big Fish Games Client --> C:\Program Files\bfgclient\Uninstall.exe
Canon Camera Support Core Library --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A1D0D14A-B776-4907-BC00-5149F2298086} /l1033
Canon Camera Window DC_DV 5 for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{001AB29C-5468-4972-8D24-2EBDB2B12133}
Canon Camera Window DS for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{6B8BDABA-6737-4998-AEE4-E218EDE5FC7A}
Canon Camera Window MC 5 for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{89EB3ED7-225A-412E-B048-623D502C000F}
Canon MovieEdit Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{68D27126-BF6A-457D-8DD0-5F35E8D41310}
Canon PhotoRecord --> MsiExec.exe /X{6693BD7C-CB4E-43AC-A0D6-10D1A1B88DCF}
Canon RAW Image Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{001EB665-D9EC-415E-9E13-AD2125B2B992}
Canon Utilities PhotoStitch 3.1 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{218BBBE3-FE63-4BB2-81A8-7435575A84FA}
Canon ZoomBrowser EX --> MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
DVDFab Gold 4.0.5.0 --> "C:\Program Files\DVDFab Gold 4\unins000.exe"
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
IKEA HomePlanner Kitchen --> MsiExec.exe /I{E215F522-2FD6-46F4-9507-747E14D71598}
Intel Audio Studio 2.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D1B20A6-E31D-4BB5-BC5C-DDD3B0D91728}\setup.exe" -l0x9
Intel Special Offers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F89FD8CD-FC96-4F75-8376-3C3C292907D5}\setup.exe" -l0x9 -removeonly
Intel® Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2776 PCI\VEN_8086&DEV_2772
Intel® PRO Network Connections Drivers --> Prounstl.exe
InterVideo Home Theater --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7514465-E5F3-48E9-A952-327DAEF33DE6}\setup.exe" REMOVEALL
iTunes --> MsiExec.exe /I{4F5CE18C-D97D-48FF-A510-A0D90C918294}
Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
LiveUpdate 3.2 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
LiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Digital Image Standard 2006 Update --> "C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM VERSION=12
Microsoft Money 2004 --> MsiExec.exe /I{1D643CD0-4DD6-11D7-A4E0-000874180BB3}
Microsoft Money 2004 System Pack --> MsiExec.exe /I{8C64E149-54BA-11D6-91B1-00500462BE80}
Microsoft Office FrontPage 2003 --> MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\Maxine\Application Data\Move Networks\ie_bin\Uninst.exe
MSN --> C:\Program Files\MSN\MsnInstaller\msniadm.exe /Action:ARP
MSN Messenger 7.0 --> MsiExec.exe /I{ABEB838C-A1A7-4C5D-B7E1-8B4314600816}
MSRedist --> MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
Nero Suite --> C:\Program Files\Common Files\Nero\Uninstall\setupx.exe /uninstall ExtraUninstallID=""
Netflix Movie Viewer --> MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
Norton AntiVirus --> MsiExec.exe /X{830D8CBD-C668-49E2-A969-C2C2106332E0}
Norton Confidential Browser Component --> MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
Norton Confidential Web Protection Component --> MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
Norton Internet Security --> MsiExec.exe /I{48185814-A224-447A-81DA-71BD20580E1B}
Norton Internet Security --> MsiExec.exe /I{5AA2CD16-706F-41F3-87C5-2B5A031F2B3B}
Norton Internet Security --> MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Internet Security --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Norton Internet Security (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41F3-87C5-2B5A031F2B3B}_10_4_0_13\{5AA2CD16-706F-41F3-87C5-2B5A031F2B3B}.exe" /X
Norton Protection Center --> MsiExec.exe /I{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}
Pirate Poppers --> "C:\Program Files\MSN Games\Pirate Poppers\Uninstall.exe" "C:\Program Files\MSN Games\Pirate Poppers\install.log"
QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Sansa Updater --> C:\Program Files\InstallShield Installation Information\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\setup.exe -runfromtemp -l0x0009 -removeonly
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SigmaTel Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\Setup.exe" -l0x9 -remove -removeonly
SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Sri Ram Kaa & Kira Raa Modaview Player Version 1.0 --> "C:\Program Files\Modaview\sri ram kaa & kira raa\unins000.exe"
Symantec pcAnywhere --> MsiExec.exe /I{12018183-866A-11D3-97DF-0000F8D8F2E9}
Symantec Technical Support Web Controls --> MsiExec.exe /X{9743AF47-B746-4324-B4C4-512E67D04370}
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
WCreator2 --> "C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
WD Diagnostics --> MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
WD FAT32 Formatter --> MsiExec.exe /I{A0D85877-DC09-4F08-9164-BE8381CB8E27}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Wyzo 0.5.3 --> C:\Program Files\Wyzo\uninst.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type16535 / Warning
Event Submitted/Written: 02/05/2008 01:07:45 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{4F5CE18C-D97D-48FF-A510-A0D90C918294}', feature 'iTunes' failed during request for component '{E8A1D3E2-F5D3-4B24-AB93-52F7E602A235}'
Event Record #/Type16534 / Warning
Event Submitted/Written: 02/05/2008 01:07:45 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{4F5CE18C-D97D-48FF-A510-A0D90C918294}', feature 'iTunes', component '{C08B990C-B647-4700-8D9D-68E62B841B72}' failed. The resource 'C:\Program Files\iTunes\iTunesHelper.exe' does not exist.
Event Record #/Type16467 / Warning
Event Submitted/Written: 02/04/2008 08:22:01 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{1D643CD0-4DD6-11D7-A4E0-000874180BB3}', feature 'feat.Program' failed during request for component '{8C64DF9F-54BA-11D6-91B1-00500462BE80}'
Event Record #/Type16466 / Warning
Event Submitted/Written: 02/04/2008 08:22:01 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{1D643CD0-4DD6-11D7-A4E0-000874180BB3}', feature 'feat.Program', component '{8C64DD1F-54BA-11D6-91B1-00500462BE80}' failed. The resource 'C:\Program Files\Microsoft Money\System\mnyexpr.exe' does not exist.
Event Record #/Type16464 / Warning
Event Submitted/Written: 02/04/2008 08:21:59 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{1D643CD0-4DD6-11D7-A4E0-000874180BB3}', feature 'feat.Program' failed during request for component '{8C64E09F-54BA-11D6-91B1-00500462BE80}'
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type23497 / Error
Event Submitted/Written: 02/04/2008 08:28:00 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.
Event Record #/Type23496 / Error
Event Submitted/Written: 02/04/2008 08:28:00 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.nist.gov,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)
Event Record #/Type23495 / Error
Event Submitted/Written: 02/04/2008 08:27:43 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.
Event Record #/Type23494 / Error
Event Submitted/Written: 02/04/2008 08:27:43 PM
Event ID/Source: 17 / W32Time
Event Description:
Time Provider NtpClient: An error occurred during DNS lookup of the manually
configured peer 'time.nist.gov,0x1'. NtpClient will try the DNS lookup again in 15
minutes.
The error was: A socket operation was attempted to an unreachable host. (0x80072751)
Event Record #/Type23493 / Error
Event Submitted/Written: 02/04/2008 08:27:39 PM
Event ID/Source: 29 / W32Time
Event Description:
The time provider NtpClient is configured to acquire time from one or more
time sources, however none of the sources are currently accessible.
No attempt to contact a source will be made for 14 minutes.
NtpClient has no source of accurate time.
-- End of Deckard's System Scanner: finished at 2008-02-05 13:54:25 ------------
-MAX --- I feel so naked and exposed....I've just been technolested....lol
Edited by Max214, 05 February 2008 - 04:10 PM.
#6
Posted 05 February 2008 - 07:49 PM
I feel so naked and exposed....I've just been technolested
I see that you have 2 antivirus programs running.
I personally hate norton and would remove it but the choice is yours but please remove avg or norton.
===================================================================
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
"C:\Program Files\Intel Audio Studio\bak\IntelAudioStudio.exe"
"C:\Program Files\iTunes\bak\iTunesHelper.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\system32\bak\ctfmon.exe"
"C:\WINDOWS\system32\bak\hkcmd.exe"
"C:\WINDOWS\system32\bak\igfxpers.exe"
"C:\WINDOWS\system32\bak\igfxtray.exe"
"C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"C:\Program Files\Google\Google Desktop Search\bak\GoogleDesktop.exe"
"C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe"
"C:\Program Files\SanDisk\Sansa Updater\bak\SansaDispatch.exe"
"C:\Program Files\SlySoft\AnyDVD\bak\AnyDVD.exe"
"C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe"
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT - Press 2, then press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of files to be restored.
- Right click below this line and select Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
- The program will proceed to move the legit files and will perform another scan for .bak folder
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
#7
Posted 05 February 2008 - 11:28 PM
<<Question>> Should I remove it prior to doing your next task? My concern is about the files that are currently quarantined in the Norton application. Does that matter or not?
#8
Posted 06 February 2008 - 03:32 AM
#9
Posted 06 February 2008 - 11:34 AM
Version 1.40
Option 2 run successfully
The current date is: Wed 02/06/2008
The current time is: 9:28:02.09
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\INTELA~1\BAK
08/09/2005 04:35 PM 8,597,586 IntelAudioStudio.exe
1 File(s) 8,597,586 bytes
Directory of C:\PROGRA~1\ITUNES\BAK
11/15/2007 01:11 PM 267,048 iTunesHelper.exe
1 File(s) 267,048 bytes
Directory of C:\PROGRA~1\MESSEN~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\QUICKT~1\BAK
01/10/2008 03:27 PM 385,024 qttask.exe
1 File(s) 385,024 bytes
Directory of C:\WINDOWS\SYSTEM32\BAK
02/28/2006 04:00 AM 15,360 ctfmon.exe
07/19/2005 10:06 AM 77,824 hkcmd.exe
07/19/2005 10:10 AM 114,688 igfxpers.exe
07/19/2005 10:09 AM 94,208 igfxtray.exe
07/09/2001 10:50 AM 155,648 NeroCheck.exe
5 File(s) 457,728 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\BAK
06/27/2007 06:32 AM 68,856 GoogleToolbarNotifier.exe
1 File(s) 68,856 bytes
Directory of C:\PROGRA~1\GOOGLE\GOOGLE~2\BAK
07/10/2007 05:29 AM 1,836,544 GoogleDesktop.exe
1 File(s) 1,836,544 bytes
Directory of C:\PROGRA~1\MICAC0~1\SYSTEM\BAK
06/18/2003 11:00 AM 200,704 mnyexpr.exe
1 File(s) 200,704 bytes
Directory of C:\PROGRA~1\SANDISK\SANSAU~1\BAK
10/22/2007 12:52 PM 75,584 SansaDispatch.exe
1 File(s) 75,584 bytes
Directory of C:\PROGRA~1\SLYSOFT\ANYDVD\BAK
12/21/2007 04:34 AM 1,649,600 AnyDVD.exe
1 File(s) 1,649,600 bytes
Directory of C:\PROGRA~1\YAHOO!\MESSEN~1\BAK
08/30/2007 05:43 PM 4,670,704 YAHOOM~1.EXE
1 File(s) 4,670,704 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
10/10/2007 06:51 PM 39,792 Reader_sl.exe
1 File(s) 39,792 bytes
Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
08/22/2007 09:41 PM 185,632 realsched.exe
1 File(s) 185,632 bytes
Directory of C:\PROGRA~1\JAVA\JRE16~1.0_0\BIN\BAK
09/25/2007 01:11 AM 132,496 jusched.exe
1 File(s) 132,496 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
8597586 Aug 9 2005 "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe"
8597586 Aug 9 2005 "C:\Program Files\Intel Audio Studio\bak\IntelAudioStudio.exe"
267048 Nov 15 2007 "C:\Program Files\iTunes\iTunesHelper.exe"
267048 Nov 15 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102400 Feb 5 2008 "C:\WINDOWS\Installer\{4F5CE18C-D97D-48FF-A510-A0D90C918294}\iTunesIco.exe"
116008 Nov 22 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.5.0.20\iTunesSetupAdmin.exe"
116008 Nov 22 2007 "C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\6DNSWCOG\iTunesSetupAdmin[1].exe"
385024 Jan 10 2008 "C:\Program Files\QuickTime\qttask.exe"
385024 Jan 10 2008 "C:\Program Files\QuickTime\bak\qttask.exe"
15360 Feb 28 2006 "C:\WINDOWS\system32\ctfmon.exe"
15360 Feb 28 2006 "C:\WINDOWS\system32\bak\ctfmon.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\hkcmd.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\igfxpers.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\igfxtray.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
155648 Jul 9 2001 "C:\WINDOWS\system32\bak\NeroCheck.exe"
52272 Jan 28 2008 "C:\Program Files\Google\googletoolbar2user.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
1823792 Jan 31 2008 "C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe"
69632 Nov 13 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
26694 Jan 30 2008 "C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
13411824 Nov 18 2007 "C:\Documents and Settings\Maxine\My Documents\My Downloads\Google_Earth_BZXD.exe"
1145896 Aug 22 2007 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138680 Jan 28 2008 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\bak\GoogleDesktop.exe"
1831936 May 12 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp1\GoogleDesktopSetupHelper.exe"
1831936 May 13 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp2\GoogleDesktopSetupHelper.exe"
1831936 May 15 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp3\GoogleDesktopSetupHelper.exe"
1836544 Jul 9 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp4\GoogleDesktopSetupHelper.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp5\GoogleDesktopSetupHelper.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\2.2.1070.1219\GoogleUpdaterRestartManager.exe"
52272 Jan 28 2008 "C:\Program Files\Google\googletoolbar2user.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
1823792 Jan 31 2008 "C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe"
69632 Nov 13 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\GoogleUpdater.exe"
26694 Jan 30 2008 "C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
13411824 Nov 18 2007 "C:\Documents and Settings\Maxine\My Documents\My Downloads\Google_Earth_BZXD.exe"
1145896 Aug 22 2007 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe"
138680 Jan 28 2008 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
68856 Jun 27 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\bak\GoogleDesktop.exe"
1831936 May 12 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp1\GoogleDesktopSetupHelper.exe"
1831936 May 13 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp2\GoogleDesktopSetupHelper.exe"
1831936 May 15 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp3\GoogleDesktopSetupHelper.exe"
1836544 Jul 9 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp4\GoogleDesktopSetupHelper.exe"
1836544 Jul 10 2007 "C:\Program Files\Google\Google Desktop Search\gcdtmp5\GoogleDesktopSetupHelper.exe"
124400 Jan 28 2008 "C:\Program Files\Google\Google Updater\2.2.1070.1219\GoogleUpdaterRestartManager.exe"
200704 Jun 18 2003 "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
200704 Jun 18 2003 "C:\Program Files\Microsoft Money\System\bak\mnyexpr.exe"
75584 Oct 22 2007 "C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe"
75584 Oct 22 2007 "C:\Program Files\SanDisk\Sansa Updater\bak\SansaDispatch.exe"
108616 May 15 2007 "C:\Deckard\System Scanner\backup\DOCUME~1\Maxine\LOCALS~1\Temp\{65DA4E07-0692-450B-A48C-9FB475B1DE3C}\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\SansaDispatchSchedule.exe"
1649600 Dec 21 2007 "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
1649600 Dec 21 2007 "C:\Program Files\SlySoft\AnyDVD\bak\AnyDVD.exe"
4670704 Aug 30 2007 "C:\Program Files\Yahoo!\Messenger\YAHOOM~1.EXE"
4670704 Aug 30 2007 "C:\Program Files\Yahoo!\Messenger\bak\YAHOOM~1.EXE"
39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
185632 Aug 22 2007 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
185632 Aug 22 2007 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
132496 Sep 25 2007 "C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe"
end of report
#10
Posted 06 February 2008 - 07:19 PM
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\Program Files\Intel Audio Studio\bak
C:\Program Files\iTunes\bak
C:\Program Files\QuickTime\bak
C:\WINDOWS\system32\bak
C:\Program Files\Google\GoogleToolbarNotifier\bak
C:\Program Files\Google\Google Desktop Search\bak
C:\Program Files\Microsoft Money\System\bak
C:\Program Files\SanDisk\Sansa Updater\bak
C:\Program Files\SlySoft\AnyDVD\bak
C:\Program Files\Yahoo!\Messenger\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Java\jre1.6.0_03\bin\bak
C:\Program Files\Messenger\bak
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT - Press 3, then press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
- Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
- The program will proceed to remove the bad folders and will perform another scan for .bak folder
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
#11
Posted 06 February 2008 - 07:43 PM
This happened this time, as well as the last... I chose ignore. What is that? I figured it might have something to do with Norton or PCAnywhere????
Anyways here's the txt
Find AWF report by noahdfear ©2006
Version 1.40
Option 3 run successfully
The current date is: Wed 02/06/2008
The current time is: 17:34:49.10
bak folders found
~~~~~~~~~~~
Directory of C:\WINDOWS\SYSTEM32\BAK
07/19/2005 10:06 AM 77,824 hkcmd.exe
07/19/2005 10:10 AM 114,688 igfxpers.exe
07/19/2005 10:09 AM 94,208 igfxtray.exe
3 File(s) 286,720 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
10/10/2007 06:51 PM 39,792 Reader_sl.exe
1 File(s) 39,792 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
77824 Jul 19 2005 "C:\WINDOWS\system32\hkcmd.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\igfxpers.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\igfxtray.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
end of report
#12
Posted 06 February 2008 - 08:13 PM
Some files didn't get copied over correctly we will have do repeat steps 2 and 3 again but almost there.
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
"C:\WINDOWS\system32\bak\hkcmd.exe"
"C:\WINDOWS\system32\bak\igfxpers.exe"
"C:\WINDOWS\system32\bak\igfxtray.exe"
"C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT - Press 2, then press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of files to be restored.
- Right click below this line and select Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
- The program will proceed to move the legit files and will perform another scan for .bak folder
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
#13
Posted 06 February 2008 - 11:01 PM
Version 1.40
Option 2 run successfully
The current date is: Wed 02/06/2008
The current time is: 20:56:17.40
bak folders found
~~~~~~~~~~~
Directory of C:\WINDOWS\SYSTEM32\BAK
07/19/2005 10:06 AM 77,824 hkcmd.exe
07/19/2005 10:10 AM 114,688 igfxpers.exe
07/19/2005 10:09 AM 94,208 igfxtray.exe
3 File(s) 286,720 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK
10/10/2007 06:51 PM 39,792 Reader_sl.exe
1 File(s) 39,792 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
77824 Jul 19 2005 "C:\WINDOWS\system32\hkcmd.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\igfxpers.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\igfxtray.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
39792 Oct 10 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
end of report
#14
Posted 07 February 2008 - 03:28 AM
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\system32\bak
C:\Program Files\Adobe\Reader 8.0\Reader\bak
C:\Program Files\Common Files\Symantec\bak
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- You will be presented with a Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT - Press 3, then press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
- Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
- The program will proceed to remove the bad folders and will perform another scan for .bak folder
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
#15
Posted 07 February 2008 - 03:33 PM
Version 1.40
Option 3 run successfully
The current date is: Thu 02/07/2008
The current time is: 13:28:55.82
bak folders found
~~~~~~~~~~~
Directory of C:\WINDOWS\SYSTEM32\BAK
07/19/2005 10:06 AM 77,824 hkcmd.exe
07/19/2005 10:10 AM 114,688 igfxpers.exe
07/19/2005 10:09 AM 94,208 igfxtray.exe
3 File(s) 286,720 bytes
Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK
0 File(s) 0 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
77824 Jul 19 2005 "C:\WINDOWS\system32\hkcmd.exe"
77824 Jul 19 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\igfxpers.exe"
114688 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\igfxtray.exe"
94208 Jul 19 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
end of report
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users