As I was looking at this I noticed my system clock was set to 2007
.
Deckard's System Scanner v20071014.68
Run by Jordan Metzmeier on 2007-02-09 11:56:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
76: 2007-02-09 16:56:06 UTC - RP76 - Deckard's System Scanner Restore Point
75: 2007-02-09 01:08:37 UTC - RP75 - System Checkpoint
74: 2007-02-08 00:15:57 UTC - RP74 - System Checkpoint
73: 2007-02-06 21:32:05 UTC - RP73 - Logitech SetPoint Mouse and Keyboard Device Drivers
72: 2008-02-06 12:12:14 UTC - RP72 - System Checkpoint
-- First Restore Point --
1: 2008-01-16 21:09:43 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Jordan Metzmeier.exe) ------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-02-09 11:57:29
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Steam\Steam.exe
C:\Documents and Settings\Jordan Metzmeier\Desktop\dss.exe
C:\Program Files\HijackThis\Jordan Metzmeier.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Product Registration.lnk = C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM (file missing)
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM (file missing)
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM (file missing)
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplane...C_2.3.6.108.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1200518098070O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab Class) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1200518091975O16 - DPF: {77538FC7-CE52-4704-9865-494FE92BC320} (LaunchUBO.Ulit) -
http://www.ultimateb...o/launchubo.OCXO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7665 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 giveio - c:\windows\system32\giveio.sys
R0 speedfan - c:\windows\system32\speedfan.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2007-01-09 and 2007-02-09 -----------------------------
2008-02-04 02:18:52 0 d-------- C:\WINDOWS\system32\AGEIA
2008-02-04 02:18:51 0 d-------- C:\Program Files\AGEIA Technologies
2008-02-04 02:13:21 0 d-------- C:\Program Files\Flying Lab Software
2008-02-04 02:13:18 0 d-------- C:\Program Files\Sony
2008-02-03 19:45:33 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\AVG7
2008-02-03 19:45:10 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-03 19:44:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-03 19:44:40 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-02 21:33:43 0 d-------- C:\Program Files\WorldGate
2008-02-02 19:59:48 0 d-------- C:\Program Files\Intel Corporation
2008-02-02 03:08:56 0 dr-h----- C:\Documents and Settings\Jordan Metzmeier\Application Data\SecuROM
2008-02-02 01:37:35 0 d-------- C:\Program Files\Atari
2008-02-01 03:48:57 0 d-------- C:\Program Files\Guild Wars
2008-01-31 13:50:51 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\.sketsa
2008-01-31 13:50:31 0 d-------- C:\Program Files\Kiyut
2008-01-31 07:38:18 0 d-------- C:\Program Files\NETAMIN
2008-01-31 07:37:45 0 d-------- C:\WINDOWS\Downloaded Installations
2008-01-31 02:51:36 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\DAEMON Tools Pro
2008-01-31 02:51:24 0 d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-01-31 02:50:23 0 d-------- C:\Program Files\DAEMON Tools Pro
2008-01-31 02:43:15 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-01-31 02:12:34 0 d-------- C:\Program Files\The Witcher
2008-01-31 02:12:34 0 d-------- C:\Program Files\HERE_FIRST!
2008-01-31 01:51:03 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\WinRAR
2008-01-31 01:40:33 0 d-------- C:\Program Files\PowerISO
2008-01-28 01:07:04 0 d-------- C:\Program Files\Crazy Tao
2008-01-28 00:18:46 0 d-------- C:\Program Files\SystemRequirementsLab
2008-01-27 23:50:40 0 d-------- C:\WINDOWS\system32\URTTemp
2008-01-27 23:40:52 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\fretsonfire
2008-01-27 23:33:57 0 d-------- C:\Program Files\Frets on Fire
2008-01-22 22:09:10 0 d-------- C:\Program Files\Lavasoft
2008-01-22 22:09:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-22 22:08:43 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-22 22:05:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-21 00:00:52 0 d-------- C:\Program Files\uTorrent
2008-01-21 00:00:46 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\uTorrent
2008-01-20 23:14:02 0 d-------- C:\Program Files\Windows Media Connect 2
2008-01-20 23:13:01 0 d-------- C:\WINDOWS\system32\LogFiles
2008-01-20 23:13:01 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-20 21:15:54 0 d-------- C:\Program Files\Download Manager
2008-01-20 21:15:43 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\IGN_DLM
2008-01-20 20:55:13 0 d-------- C:\Program Files\EndlessOnline
2008-01-20 17:54:16 0 d-------- C:\Program Files\Microsoft Xbox 360 Accessories
2008-01-20 16:23:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-01-20 16:23:22 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-20 02:07:58 33292 --a------ C:\WINDOWS\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
2008-01-19 21:53:38 0 d-------- C:\WINDOWS\Sun
2008-01-19 21:53:38 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Sun
2008-01-19 21:52:04 0 d-------- C:\Program Files\Java
2008-01-19 21:51:37 0 d-------- C:\Program Files\Common Files\Java
2008-01-18 12:04:38 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\ieSpell
2008-01-18 12:04:14 0 d-------- C:\Program Files\ieSpell
2008-01-17 06:27:10 98304 --a------ C:\WINDOWS\system32CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-01-16 22:08:17 0 d-------- C:\WINDOWS\pss
2008-01-16 21:38:45 0 d-------- C:\WINDOWS\system32\Lang
2008-01-16 19:37:58 0 d-------- C:\Program Files\Gigabyte
2008-01-16 19:37:53 327168 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-01-16 19:30:35 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Macromedia
2008-01-16 19:30:34 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Adobe
2008-01-16 19:17:45 0 d-------- C:\Program Files\Steam
2008-01-16 17:29:44 0 d-------- C:\WINDOWS\network diagnostic
2008-01-16 17:19:57 0 d-------- C:\WINDOWS\nview
2008-01-16 17:19:34 0 d-------- C:\NVIDIA
2008-01-16 17:18:18 6684704 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-16 17:14:49 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-16 17:14:44 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-01-16 17:14:37 11264 --a------ C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-01-16 17:14:25 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-01-16 17:13:58 0 d-------- C:\WINDOWS\Internet Logs
2008-01-16 17:07:47 0 d-------- C:\Program Files\Lavalys
2008-01-16 16:59:54 0 d-------- C:\WINDOWS\system32\PreInstall
2008-01-16 16:59:53 0 d--h----- C:\WINDOWS\$hf_mig$
2008-01-16 16:58:54 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-01-16 16:58:54 53248 --a------ C:\WINDOWS\system32\CSVer.dll <Not Verified; Windows XP Bundled build C-Centric Single User; Windows XP Bundled build C-Centric Single User CSVer>
2008-01-16 16:58:54 0 d-------- C:\Program Files\Intel
2008-01-16 16:58:49 0 d-------- C:\Intel
2008-01-16 16:58:35 0 d-------- C:\WINDOWS\system32\RTCOM
2008-01-16 16:58:35 49152 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-01-16 16:58:19 520192 -r------- C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-01-16 16:58:19 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-01-16 16:58:16 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-16 16:50:01 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-01-16 16:49:31 0 d-------- C:\WINDOWS\Prefetch
2008-01-16 16:44:58 0 d-------- C:\WINDOWS\provisioning
2008-01-16 16:44:58 0 d-------- C:\WINDOWS\peernet
2008-01-16 16:44:15 0 d-------- C:\WINDOWS\ServicePackFiles
2008-01-16 16:42:12 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-01-16 16:40:49 0 d-------- C:\WINDOWS\EHome
2008-01-16 16:25:52 0 d-------- C:\5f45f795cae9deadcf2132c5ad586412
2008-01-16 16:23:20 0 d-------- C:\efc6fe11b6f6fa2f8adaa5d96a96afa1
2008-01-16 16:23:05 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-01-16 16:23:05 0 d--h---c- C:\WINDOWS\$xpsp1hfm$
2008-01-16 16:23:05 0 d-------- C:\cb367d408a22bcb67
2008-01-16 16:21:51 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-01-16 16:21:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-01-16 16:18:01 0 d-------- C:\WINDOWS\system32\bits
2008-01-16 16:14:57 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-01-16 16:14:33 0 d--hs---- C:\Documents and Settings\Jordan Metzmeier\UserData
2008-01-16 16:13:05 0 d-------- C:\WINDOWS\OPTIONS
2008-01-16 16:13:05 0 d-------- C:\Program Files\Realtek
2008-01-16 16:13:04 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-16 16:13:00 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\InstallShield
2008-01-16 16:11:02 0 d-------- C:\WINDOWS\system32\NtmsData
2008-01-16 16:09:37 0 d--hs---- C:\WINDOWS\Installer
2008-01-16 16:09:35 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Identities
2008-01-16 16:09:24 0 d--h----- C:\Documents and Settings\Jordan Metzmeier\Templates
2008-01-16 16:09:24 0 dr------- C:\Documents and Settings\Jordan Metzmeier\Start Menu
2008-01-16 16:09:24 0 dr-h----- C:\Documents and Settings\Jordan Metzmeier\SendTo
2008-01-16 16:09:24 0 dr-h----- C:\Documents and Settings\Jordan Metzmeier\Recent
2008-01-16 16:09:24 0 d--h----- C:\Documents and Settings\Jordan Metzmeier\PrintHood
2008-01-16 16:09:24 4718592 --ah----- C:\Documents and Settings\Jordan Metzmeier\NTUSER.DAT
2008-01-16 16:09:24 0 d--h----- C:\Documents and Settings\Jordan Metzmeier\NetHood
2008-01-16 16:09:24 0 dr------- C:\Documents and Settings\Jordan Metzmeier\My Documents
2008-01-16 16:09:24 0 d--h----- C:\Documents and Settings\Jordan Metzmeier\Local Settings
2008-01-16 16:09:24 0 dr------- C:\Documents and Settings\Jordan Metzmeier\Favorites
2008-01-16 16:09:24 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Desktop
2008-01-16 16:09:24 0 d--hs---- C:\Documents and Settings\Jordan Metzmeier\Cookies
2008-01-16 16:09:24 0 dr-h----- C:\Documents and Settings\Jordan Metzmeier\Application Data
2008-01-16 16:00:01 0 d--hs---- C:\System Volume Information
2008-01-16 16:00:00 1572864 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-01-16 16:00:00 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-01-16 16:00:00 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-01-16 16:00:00 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-01-16 16:00:00 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-01-16 16:00:00 1572864 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-01-16 16:00:00 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-01-16 16:00:00 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-01-16 16:00:00 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-01-16 16:00:00 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-01-16 15:57:42 0 d-------- C:\WINDOWS\system32\xircom
2008-01-16 15:57:42 0 d-------- C:\Program Files\microsoft frontpage
2008-01-16 15:57:41 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-01-16 15:57:30 0 -rahs---- C:\MSDOS.SYS
2008-01-16 15:57:30 0 -rahs---- C:\IO.SYS
2008-01-16 15:57:30 0 --a------ C:\CONFIG.SYS
2008-01-16 15:57:30 0 --a------ C:\AUTOEXEC.BAT
2008-01-16 15:56:54 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-01-16 15:56:47 0 dr------- C:\WINDOWS\Offline Web Pages
2008-01-16 15:56:47 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-01-16 15:56:29 0 d-------- C:\WINDOWS\srchasst
2008-01-16 15:56:24 0 d-------- C:\WINDOWS\system32\DirectX
2008-01-16 15:56:23 0 d-------- C:\WINDOWS\system32\Macromed
2008-01-16 15:56:11 0 d-------- C:\Program Files\Movie Maker
2008-01-16 15:55:48 0 d-------- C:\WINDOWS\system32\Restore
2008-01-16 15:55:44 0 d-------- C:\WINDOWS\PCHEALTH
2008-01-16 15:55:39 0 d---s---- C:\WINDOWS\Tasks
2008-01-16 15:55:36 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-16 15:55:29 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-01-16 15:55:14 0 d-------- C:\WINDOWS\Registration
2008-01-16 15:54:57 0 d--h----- C:\Program Files\WindowsUpdate
2008-01-16 15:54:57 0 d-------- C:\Program Files\Online Services
2008-01-16 15:54:53 0 d-------- C:\Program Files\Messenger
2008-01-16 15:54:44 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-16 15:54:36 0 d-------- C:\Program Files\Windows NT
2008-01-16 15:54:27 0 d-------- C:\WINDOWS\system32\MsDtc
2008-01-16 15:54:25 0 d-------- C:\WINDOWS\system32\Com
2008-01-16 10:42:15 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-16 10:42:12 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-01-16 10:42:11 0 dr------- C:\Program Files
2008-01-16 10:42:11 0 d-------- C:\Program Files\Common Files
2008-01-16 10:41:53 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-01-16 10:41:53 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-01-16 10:41:53 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-01-16 10:41:53 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-01-16 10:41:53 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-01-16 10:41:53 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-01-16 10:41:53 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-01-16 10:41:53 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-01-16 10:41:53 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-01-16 10:41:53 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-01-16 10:41:53 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-01-16 10:41:53 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-01-16 10:41:53 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-01-16 10:41:53 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-01-16 10:41:53 0 dr------- C:\Documents and Settings\All Users\Documents
2008-01-16 10:41:53 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-01-16 10:41:16 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-01-16 10:41:16 0 d-------- C:\WINDOWS\system32\CatRoot
2008-01-16 10:41:11 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-01-16 10:41:11 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-01-16 10:41:11 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-01-16 10:41:11 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-01-16 10:40:56 0 d-------- C:\Documents and Settings
2008-01-16 10:36:21 0 d-------- C:\WINDOWS
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\WinSxS
2008-01-16 10:36:21 0 dr------- C:\WINDOWS\Web
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\twain_32
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\wins
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\wbem
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\usmt
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\spool
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\ShellExt
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\Setup
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\ras
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\oobe
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\npp
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\mui
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\inetsrv
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\IME
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\icsxml
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\ias
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\export
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\drivers
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-01-16 10:36:21 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\dhcp
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\config
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\3076
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\2052
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1054
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1042
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1041
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1037
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1033
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1031
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1028
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system32\1025
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\system
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\security
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Resources
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\repair
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\mui
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\msapps
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\msagent
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Media
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\java
2008-01-16 10:36:21 0 d--h----- C:\WINDOWS\inf
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\ime
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Help
2008-01-16 10:36:21 0 dr--s---- C:\WINDOWS\Fonts
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Driver Cache
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Debug
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Cursors
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Connection Wizard
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\Config
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\AppPatch
2008-01-16 10:36:21 0 d-------- C:\WINDOWS\addins
2007-12-05 01:41:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-12-05 01:41:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-12-05 01:41:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 01:41:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-12-05 01:41:00 1474560 --a------ C:\WINDOWS\system32\nview.dll
2007-12-05 01:41:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 01:41:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-12-05 01:41:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
2007-08-07 12:58:08 8320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys <Not Verified; Lavasoft AB; Ad-Watch Registry Protection>
2007-08-07 12:56:58 9344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys <Not Verified; Lavasoft AB; Ad-Watch Connections>
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelTraditionalChinese.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelSwedish.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelSpanish.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelSimplifiedChinese.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelPortugese.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelKorean.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelJapanese.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelGerman.dll
2007-07-22 17:39:26 53248 --a------ C:\WINDOWS\system32\AgCPanelFrench.dll
2007-07-11 13:37:26 6272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys <Not Verified; Lavasoft AB; Ad-Watch Beta>
2007-02-06 16:38:54 0 d-------- C:\Program Files\SpeedFan
2007-02-06 16:33:35 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Logitech
2007-02-06 16:33:18 0 d-------- C:\Documents and Settings\Jordan Metzmeier\Application Data\Leadertech
2007-02-06 16:33:17 0 d-------- C:\Program Files\Common Files\LogiShared
2007-02-06 16:31:49 69632 --a------ C:\WINDOWS\system32\KemXML.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2007-02-06 16:31:49 110592 --a------ C:\WINDOWS\system32\KemWnd.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2007-02-06 16:31:49 135168 --a------ C:\WINDOWS\system32\KemUtil.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2007-02-06 16:31:49 163840 --a------ C:\WINDOWS\system32\kemutb.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2007-02-06 16:31:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2007-02-06 16:31:22 0 d-------- C:\Program Files\Logitech
2007-02-06 16:31:20 0 d-------- C:\Program Files\Common Files\Logitech
2007-02-06 16:31:00 0 d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
-- Find3M Report ---------------------------------------------------------------
2008-01-16 10:41:53 62 --ahs---- C:\Documents and Settings\Jordan Metzmeier\Application Data\desktop.ini
2007-10-31 06:01:41 1467 --a------ C:\Program Files\READ.ME!!.txt
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/2007 04:05 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 01:41 AM]
"nwiz"="nwiz.exe" [12/05/2007 01:41 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 01:41 AM]
"RTHDCPL"="RTHDCPL.EXE" [07/05/2007 03:08 AM C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 05:43 AM C:\WINDOWS\Alcmtr.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"XboxStat"="C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [09/26/2007 06:05 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [02/03/2008 07:46 PM]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [04/11/2007 03:32 PM C:\WINDOWS\KHALMNPR.Exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [03/05/2007 04:57 PM]
C:\Documents and Settings\Jordan Metzmeier\Start Menu\Programs\Startup\
Product Registration.lnk - C:\Program Files\Common Files\LogiShared\eReg\SetPoint\eReg.exe [4/9/2007 11:23:34 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2/6/2007 4:31:48 PM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
"C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVPro]
C:\Program Files\Gigabyte\ET5Pro\ETcall.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
*Newly Created Service* - PROCEXP111
-- Hosts -----------------------------------------------------------------------
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
7840 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2007-02-09 11:59:44 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Core2 Duo CPU E6750 @ 2.66GHz
CPU 1: Intel® Core2 Duo CPU E6750 @ 2.66GHz
Percentage of Memory in Use: 28%
Physical Memory (total/avail): 2046.42 MiB / 1459.01 MiB
Pagefile Memory (total/avail): 3428.93 MiB / 2872.08 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1919.67 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 127.99 GiB total, 31.68 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is CDROM (No Media)
Z: is Fixed (NTFS) - 151.48 GiB total, 151.39 GiB free.
\\.\PHYSICALDRIVE0 - Maxtor 6L300S0 - 279.47 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 127.99 GiB - C:
\PARTITION1 - Installable File System - 151.48 GiB - Z:
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before download.
Windows Internal Firewall is disabled.
FW: ZoneAlarm Firewall v7.0.462.000 (Check Point, LTD.)
AV: AVG 7.5.516 v7.5.516 (Grisoft)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\NETAMIN\\UBO_2007\\game\\ubo.exe"="C:\\Program Files\\NETAMIN\\UBO_2007\\game\\ubo.exe:*:Enabled:UBOnline"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"="C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Jordan Metzmeier\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=XP1
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Jordan Metzmeier
LOGONSERVER=\\XP1
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0b
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\JORDAN~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\JORDAN~1\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=XP1
USERNAME=Jordan Metzmeier
USERPROFILE=C:\Documents and Settings\Jordan Metzmeier
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Jordan Metzmeier
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> MsiExec /X{EFC1B35C-FFF2-41D8-A70A-CE6037F8040B}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
AGEIA PhysX v7.07.24 --> MsiExec.exe /X{EFC1B35C-FFF2-41D8-A70A-CE6037F8040B}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
CDDRV_Installer --> MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
Dark Messiah Might and Magic Multi-Player --> "C:\Program Files\Steam\steam.exe" steam://uninstall/2130
Dark Messiah Might and Magic Single Player --> "C:\Program Files\Steam\steam.exe" steam://uninstall/2100
Download Manager 2.3.6 --> C:\Program Files\Download Manager\uninst.exe
EasyTune5Pro --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Gigabyte\ET5Pro\Uninst.isu" -c"C:\Program Files\Gigabyte\ET5Pro\uninstdrv.dll"
EVEREST Home Edition v2.20 --> "C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Frets On Fire --> "C:\Program Files\Frets on Fire\Uninstall.exe"
Guild Wars --> "C:\Program Files\Guild Wars\Gw.exe" -uninstall
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 1.99.1 --> C:\Program Files\HijackThis\HijackThis.exe /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
ieSpell --> "C:\Program Files\ieSpell\uninst.exe"
Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
KhalInstallWrapper --> MsiExec.exe /I{56918C0C-0D87-4CA6-92BF-4975A43AC719}
Logitech Registration --> MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe -runfromtemp -l0x0009 -removeonly
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.1 --> "C:\WINDOWS\$NtUninstallWdf01001$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Xbox 360 Accessories 1.1 --> MsiExec.exe /X{66F0AC35-4805-44BC-A3D4-347D4196F9B3}
Neverwinter Nights 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F20C1251-1D0A-4944-B2AE-678581B33B19}\setup.exe" -l0x9 -removeonly
NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
Pirates of the Burning Sea --> "C:\Program Files\InstallShield Installation Information\{EF934638-0711-4123-AA92-1512B72C660A}\setup.exe" -runfromtemp -l0x0009 -removeonly
PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
REALTEK GbE & FE Ethernet PCI-E NIC Driver --> C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Sid Meier's Civilization IV --> "C:\Program Files\Steam\steam.exe" steam://uninstall/3900
Sid Meier's Civilization IV: Beyond the Sword --> "C:\Program Files\Steam\steam.exe" steam://uninstall/8800
SpeedFan (remove only) --> "C:\Program Files\SpeedFan\uninstall.exe"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe
Team Fortress 2 --> "C:\Program Files\Steam\steam.exe" steam://uninstall/440
Thermal Analysis Tool --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B2C675E-8040-431B-99C4-137DF4FBF75A}\setup.exe" -l0x9 -removeonly
Titan Quest --> "C:\Program Files\Steam\steam.exe" steam://uninstall/4540
Titan Quest: Immortal Throne --> "C:\Program Files\Steam\steam.exe" steam://uninstall/4550
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WorldGate Client --> MsiExec.exe /I{6010D25D-4BBE-4AD8-AABC-B1C4D63C739B}
ZoneAlarm --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type266 / Error
Event Submitted/Written: 02/09/2007 11:58:48 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <
http://www.download....uthrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Event Record #/Type263 / Error
Event Submitted/Written: 02/09/2007 11:58:48 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <
http://www.download....uthrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Event Record #/Type262 / Error
Event Submitted/Written: 02/09/2007 11:58:47 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <
http://www.download....uthrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Event Record #/Type259 / Error
Event Submitted/Written: 02/09/2007 11:58:47 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <
http://www.download....uthrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
Event Record #/Type258 / Error
Event Submitted/Written: 02/09/2007 11:58:47 AM
Event ID/Source: 11 / crypt32
Event Description:
Failed extract of third-party root list from auto update cab at: <
http://www.download....uthrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1418 / Warning
Event Submitted/Written: 02/09/2007 11:31:56 AM
Event ID/Source: 1007 / Dhcp
Event Description:
Your computer has automatically configured the IP address for the Network
Card with network address 001D7DA27BF7. The IP address being used is 169.254.122.191.
Event Record #/Type1417 / Warning
Event Submitted/Written: 02/09/2007 11:31:51 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 001D7DA27BF7. The following
error occurred:
%%121.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Event Record #/Type1416 / Warning
Event Submitted/Written: 02/09/2007 11:31:24 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 001D7DA27BF7. The following
error occurred:
%%1223.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Event Record #/Type1410 / Error
Event Submitted/Written: 02/09/2007 11:30:12 AM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 192.168.1.101 for the Network Card with network address 001D7DA27BF7 has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
Event Record #/Type1406 / Error
Event Submitted/Written: 02/09/2007 11:28:06 AM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 192.168.1.100 for the Network Card with network address 001D7DA27BF7 has been
denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
-- End of Deckard's System Scanner: finished at 2007-02-09 11:59:44 ------------