Ok the files got moves and here are all the logs... Explorer being pegged makes this slow
[Custom Input]
< :\WINDOWS\system32\cvgieesi.dat >
File/Folder :\WINDOWS\system32\cvgieesi.dat not found.
< C:\WINDOWS\system32\hapgnkpg.dat >
C:\WINDOWS\system32\hapgnkpg.dat moved successfully.
< C:\WINDOWS\system32\mmoblqbc.dat >
C:\WINDOWS\system32\mmoblqbc.dat moved successfully.
< C:\WINDOWS\system32\nlskxwcw.dat >
C:\WINDOWS\system32\nlskxwcw.dat moved successfully.
< C:\WINDOWS\system32\lygluksa.dat >
C:\WINDOWS\system32\lygluksa.dat moved successfully.
< C:\WINDOWS\system32\AppCert\wsil32.dll >
DllUnregisterServer procedure not found in C:\WINDOWS\system32\AppCert\wsil32.dll
C:\WINDOWS\system32\AppCert\wsil32.dll NOT unregistered.
C:\WINDOWS\system32\AppCert\wsil32.dll moved successfully.
< C:\WINDOWS\system32\vsmidi.dll >
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vsmidi.dll
C:\WINDOWS\system32\vsmidi.dll NOT unregistered.
C:\WINDOWS\system32\vsmidi.dll moved successfully.
< C:\VundoFix Backups >
C:\VundoFix Backups moved successfully.
< HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls\\AppSecDll >
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls\\AppSecDll deleted successfully.
OTMoveIt2 v1.0.20 log created on 02132008_201543
Deckard's System Scanner v20071014.68
Run by Ner0z on 2008-02-13 20:20:24
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2008-02-14 02:24:02 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-02-13 14:30:15 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Ner0z.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:32 PM, on 2/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\Program Files\NoteBurner\VTBurnerGUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CMS Products\BounceBack Professional\BBLauncher.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Ner0z\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ner0z.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [DUMPREP ] C:\WINDOWS%\SYSTEM32\DUMPREP 0 -U
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: BounceBack Launcher.lnk = ?
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.appl...ex/qtplugin.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1200413034894O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1200413007816O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) -
http://ak.imgag.com/...tall/AxCtp2.cabO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) -
http://a532.g.akamai...l/installer.exeO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: M-Audio USB Installer (MAudioUSBService) - M-Audio - C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - (no file)
--
End of file - 6656 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 ntcdrdrv - c:\windows\system32\drivers\ntcdrdrv.sys <Not Verified; NoteBurn Software; NoteBurn>
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R3 Afc (PPdus ASPI Shell) - c:\windows\system32\drivers\afc.sys <Not Verified; Arcsoft, Inc.; Arcsoft® ASPI Shell>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 catchme - c:\docume~1\ner0z\locals~1\temp\catchme.sys (file missing)
S3 MAUSB (Service for M-Audio Fast Track Pro Driver (WDM)) - c:\windows\system32\drivers\mausb.sys <Not Verified; Midiman/M-Audio; M-Audio Delta FW WDM Driver>
S3 ossrv (Creative OS Services Driver) - c:\windows\system32\drivers\ctoss2k.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 MAudioUSBService (M-Audio USB Installer) - c:\program files\m-audio\fast track pro\mausbinst.exe <Not Verified; M-Audio; M-Audio USB Installer service>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-09 15:29:04 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-01-13 and 2008-02-13 -----------------------------
2008-02-13 19:46:37 3635 --a------ C:\Start_.cmd
2008-02-13 19:46:34 0 d-------- C:\327882R2FWJFW
2008-02-13 08:13:02 68096 --a------ C:\WINDOWS\system32\zip.exe
2008-02-13 08:13:02 98816 --a------ C:\WINDOWS\system32\sed.exe
2008-02-13 08:13:02 80412 --a------ C:\WINDOWS\system32\grep.exe
2008-02-13 08:13:02 73728 --a------ C:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-12 20:00:20 0 d-------- C:\Program Files\Trend Micro
2008-02-12 11:29:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-11 21:58:51 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-02-11 20:30:01 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-11 20:30:01 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-02-11 20:30:01 85504 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-02-11 20:30:01 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-02-11 20:30:01 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-02-11 20:30:01 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-11 20:30:00 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-02-11 20:00:54 2948 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-11 11:43:04 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-11 11:42:58 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 11:42:58 0 d-------- C:\Documents and Settings\Ner0z\Application Data\SUPERAntiSpyware.com
2008-02-09 08:54:22 0 d-------- C:\Program Files\iPod
2008-02-09 08:54:16 0 d-------- C:\Program Files\iTunes
2008-02-09 08:35:58 0 d-------- C:\Program Files\Cloudbrain
2008-02-09 08:29:59 0 d-------- C:\Documents and Settings\Ner0z\Application Data\Reasonable Software House Ltd
2008-02-09 08:29:35 0 d-------- C:\Program Files\Reasonable NoClone 2007 Home
2008-02-06 16:34:41 0 d-------- C:\Bran
2008-01-22 18:19:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-18 15:46:14 246545 --a------ C:\WINDOWS\system32\libssl32.dll <Not Verified; OpenSSL <www.openssl.org>; OpenSSL>
2008-01-18 15:46:14 1188375 --a------ C:\WINDOWS\system32\libeay32.dll <Not Verified; OpenSSL <www.openssl.org>; OpenSSL>
2008-01-18 15:46:14 741632 --a------ C:\WINDOWS\system32\cvgieesi.dat
2008-01-17 22:09:17 0 d-------- C:\Program Files\Lavasoft
2008-01-17 22:09:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-17 22:08:44 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-17 19:33:17 0 d-------- C:\Program Files\MSXML 6.0
2008-01-17 19:30:15 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-17 15:37:30 0 d-------- C:\WINDOWS\system32\AppCert
-- Find3M Report ---------------------------------------------------------------
2008-02-09 08:49:28 0 d-------- C:\Program Files\QuickTime
2008-01-22 18:20:12 0 d-------- C:\Program Files\Google
2008-01-17 22:08:44 0 d-------- C:\Program Files\Common Files
2008-01-14 11:39:08 0 d-------- C:\Program Files\eMule
2008-01-06 19:10:10 0 d-------- C:\Documents and Settings\Ner0z\Application Data\AceBIT
2008-01-06 19:09:30 0 d-------- C:\Program Files\AceBIT
2008-01-06 19:09:29 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-24 21:16:56 0 dr-h----- C:\Documents and Settings\Ner0z\Application Data\SecuROM
2007-12-24 20:54:01 0 d-------- C:\Program Files\EA SPORTS
2007-11-27 09:36:58 1366528 --a------ C:\WINDOWS\system32\we5.dll <Not Verified; AceBIT GmbH; >
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [09/16/2004 06:39 AM C:\WINDOWS\SOUNDMAN.EXE]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/20/2005 08:07 PM]
"nwiz"="nwiz.exe" [07/20/2005 08:07 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [07/20/2005 08:07 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [11/09/2006 03:07 PM]
"EEventManager"="C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [03/17/2006 09:30 AM]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [04/19/2007 11:33 AM]
"M-Audio Taskbar Icon"="C:\WINDOWS\System32\M-AudioTaskBarIcon.exe" [12/13/2005 09:39 AM]
"NoteBurner"="C:\Program Files\NoteBurner\VTBurnerGUI.exe" [10/15/2007 10:41 AM]
"DUMPREP "="C:\WINDOWS%\SYSTEM32\DUMPREP 0 -U" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/31/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/04/2008 02:18 PM]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [12/21/2007 08:21 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/10/2007 08:57 PM]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [02/25/2007 09:00 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{792dffd6-b2cf-11db-ba82-00142ae01fa0}]
AutoRun\command- H:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2008-02-13 20:48:50 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Sempron Processor 3000+
Percentage of Memory in Use: 34%
Physical Memory (total/avail): 1023.48 MiB / 672.7 MiB
Pagefile Memory (total/avail): 2364.59 MiB / 2105.21 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1946.4 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 74.52 GiB total, 22 GiB free.
D: is CDROM (CDFS)
E: is Fixed (NTFS) - 37.27 GiB total, 17.66 GiB free.
F: is Fixed (FAT32) - 149.01 GiB total, 30.89 GiB free.
G: is Fixed (NTFS) - 37.27 GiB total, 4.96 GiB free.
H: is Fixed (NTFS) - 279.46 GiB total, 191.13 GiB free.
I: is CDROM (Unformatted)
X: is Network (NTFS)
\\.\PHYSICALDRIVE1 - MAXTOR 6L040J2 - 37.28 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.27 GiB - E:
\\.\PHYSICALDRIVE0 - WDC WD800BB-00JHC0 - 74.53 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - C:
\\.\PHYSICALDRIVE2 - ST330062 0A USB Device - 279.46 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 279.46 GiB - H:
\\.\PHYSICALDRIVE3 - WD 1600BB External USB Device - 149.05 GiB - 1 partition
\PARTITION0 - Unknown - 149.05 GiB - F:
\\.\PHYSICALDRIVE4 - WDC WD400EB-00CPF0 USB Device - 37.27 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.27 GiB - G:
-- Security Center -------------------------------------------------------------
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AV: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)
Disabled[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Ner0z\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=ICHTHUS
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Ner0z
LOGONSERVER=\\ICHTHUS
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 44 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2c02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_10\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Ner0z\LOCALS~1\Temp
TMP=C:\DOCUME~1\Ner0z\LOCALS~1\Temp
USERDOMAIN=ICHTHUS
USERNAME=Ner0z
USERPROFILE=C:\Documents and Settings\Ner0z
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Ner0z
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint --> MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Able2Extract Professional v4.0 --> C:\Program Files\Investintech.com Inc\Able2Extract Professional 4.0\Uninstal.exe
Able2Extract v4.0 --> C:\Program Files\Investintech.com Inc\Able2Extract 4.0\Uninstal.exe
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Download Manager 2.0 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Adobe Reader 7.0.8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
AI RoboForm (All Users) --> "C:\Program Files\Siber Systems\AI RoboForm\rfwipeout.exe"
AP Tuner 3.08 --> "C:\Program Files\AP Tuner\AP Tuner 3.08\uninstall.exe"
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ArcSoft PhotoImpression 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D433ABC3-0CD8-4BB0-B6A9-84501B4B47B7}\SETUP.EXE" -l0x9
ASIO4ALL --> C:\Program Files\ASIO4ALL v2\uninstall.exe
BounceBack Professional --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Documents and Settings\Ner0z\Application Data\InstallShield Installation Information\{95632566-071E-4A02-92C1-4BD907065736}\Setup.exe" -l0x9
CLSetup for Tiger Woods PGA Tour 07 --> "C:\Program Files\CLSetup07\uninstall.exe"
CodeCoopEncrypt --> MsiExec.exe /I{AB6AC54F-E2AA-49C2-B414-6DAD0C7C0ABF}
Collab --> C:\Program Files\Image-Line\Collab\uninstall.exe
CuteFTP 8 Home --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{949DBB22-2FB7-4DE1-804C-23D495A988D8}\Setup.exe" -l0x9
Devine Machine Standalone 1.0 & VSTi 1.1 --> "c:\VSTi\uninstall.exe"
Duplicate Email Remover --> MsiExec.exe /I{7AA36634-4324-4EF4-8C0C-D8EF1FC2BEA4}
EA SPORTS online 2008 --> C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
eMule --> "C:\Program Files\eMule\Uninstall.exe"
EPSON Attach To Email --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Copy Utility 3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall
EPSON Event Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48F22622-1CC2-4A83-9C1E-644DD96F832D}\Setup.exe" -l0x9 -u
EPSON Perfection V100 Photo Scanner Driver Update --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1C278B97-9D25-48B0-9A4E-F4F2BB992043}\Setup.exe"
EPSON Perfection V100P User's Guide --> C:\Program Files\epson\guide\pv100p_e\uninstall.exe
EPSON Scan --> C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Scan Assistant --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
ESET NOD32 Antivirus --> MsiExec.exe /I{57ECFB4D-FE11-491A-9AA0-0AF7C3ABC51D}
EZdrummer --> MsiExec.exe /I{43E8D9E7-AFC9-4BA3-8106-B95E02B87AB7}
EZplayer --> MsiExec.exe /I{D93399F6-C902-47E8-B2A4-9C38ACAC03B5}
EZXDfh --> MsiExec.exe /I{DB1299AF-9EE0-422B-959E-F4171B2AE0F7}
Fast Track Pro --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3E67F68D-3797-4B6A-B02C-27BC98DFEBDA}\setup.exe" -l0x9 -removeonly
FixTunes (remove only) --> "C:\Program Files\Cloudbrain\FixTunes\uninstall.exe"
FL Studio 7 --> C:\Program Files\Image-Line\FL Studio 7.3 Beta\uninstall.exe
Good Sync version 4.6.10 --> "C:\Program Files\Siber Systems\Good Sync\unins000.exe"
Google Earth --> MsiExec.exe /I{407B9B5C-DAC5-4F44-A756-B57CAB4E6A8B}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Memories Disc --> MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70}
IL Download Manager --> C:\Program Files\Image-Line\Downloader\uninstall.exe
iTunes --> MsiExec.exe /I{02DFB3FD-CF52-4183-8BCA-2A127D4888F4}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 9 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Johnson Amplification J-Edit --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Johnson Amplification\Uninst.isu"
Live 5.0.4 --> C:\PROGRA~1\Ableton\LIVE50~1.4\Install\UNWISE.EXE C:\PROGRA~1\Ableton\LIVE50~1.4\Install\INSTALL.LOG
LUXONIX Purity --> C:\Program Files\LUXONIX\Purity\uninst Purity.exe
Mastering Effects Bundle for Sound Forge --> "C:\Program Files\iZotope\SoundForgeMasteringBundle\unins000.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MOTU USB MIDI Installer --> MsiExec.exe /I{3CA12A20-67E8-43F4-B692-ED04E92E42EC}
Move Networks Media Player for Internet Explorer --> C:\Documents and Settings\Ner0z\Application Data\Move Networks\ie_bin\Uninst.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MusicLab Fill-in Drummer --> "C:\Program Files\MusicLab\FillinDrummer\Uninstall.exe" "C:\Program Files\MusicLab\FillinDrummer\install.log"
MusicLab SlicyDrummer --> "C:\Program Files\MusicLab\SlicyDrummer\Uninstall.exe" "C:\Program Files\MusicLab\SlicyDrummer\install.log"
Native Instruments Battery 3 --> C:\PROGRA~1\NATIVE~1\BATTER~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\BATTER~1\INSTALL.LOG
Native Instruments Guitar Rig 3 --> C:\PROGRA~1\NATIVE~1\GUITAR~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\GUITAR~1\INSTALL.LOG
Native Instruments Service Center --> C:\PROGRA~1\NATIVE~1\SERVIC~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\SERVIC~1\INSTALL.LOG
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
NoteBurner 1.40 --> "C:\Program Files\NoteBurner\unins000.exe"
Nuton Tuner EX 2.0 --> "C:\Program Files\VstPlugins\TunerExUninst.exe"
NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI
Paint Shop Pro 7 ESD --> MsiExec.exe /I{D6DE02C7-1F47-11D4-9515-00105AE4B89A}
PC Study Bible (remove only) --> C:\Program Files\Common Files\pcsbclean.exe /uninstall
Power Tab Editor 1.7 --> C:\PROGRA~1\PTSOFT~1\PTEDIT~1\UNWISE.EXE C:\PROGRA~1\PTSOFT~1\PTEDIT~1\INSTALL.LOG
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
REAPER --> "C:\Program Files\REAPER\Uninstall.exe"
Reasonable NoClone 2007 Home --> MsiExec.exe /I{3AC91151-98F3-4723-8E22-E9BEA94556C1}
ReValver Mk II --> "C:\Program Files\Alien Connections\ReValver Mk II\unins000.exe"
rgc:audio z3ta+ 1.5 --> "C:\Program Files\Cakewalk\z3ta+\unins000.exe"
rgc:audio z3ta+ VSTi v1.4 DEMO --> "C:\Program Files\VstPlugins\unins001.exe"
ScanSoft OmniPage Pro 14.0 --> MsiExec.exe /I{7ED00F05-2109-4F42-B3DC-370EE3E2C1FE}
ScanSoft PDF Converter --> MsiExec.exe /I{87001C85-FF5F-42F9-B78A-114A7ED373BE}
ScanSoft PDF Printer --> MsiExec.exe /I{9E1BC481-AE76-49D3-913C-D901D8CFDFCA}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Sony Noise Reduction Plug-In 2.0h --> MsiExec.exe /X{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}
Sony Sound Forge 9.0 --> MsiExec.exe /X{CCA51496-49D4-4FBF-9866-A2E2F40FAC7A}
Speedsoft VSampler 3 --> C:\Program Files\Speedsoft\VSampler3\bin\UnInstall.exe "C:\Program Files\Speedsoft\VSampler3\bin\uninstall.dat"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Tiger Woods PGA TOUR 06 --> C:\Program Files\EA SPORTS\Tiger Woods PGA TOUR 06\EAUninstall.exe
Tiger Woods PGA TOUR 07 --> C:\Program Files\EA SPORTS\Tiger Woods PGA TOUR 07\EAUninstall.exe
Tiger Woods PGA TOUR 08 --> C:\Program Files\EA Sports\Tiger Woods PGA TOUR 08\EAUninstall.exe
Vanguard 1.03 --> "C:\Program Files\VstPlugins\unins000.exe"
VeryPDF PDF2Word v3.0 --> "C:\Program Files\VeryPDF PDF2Word v3.0\unins000.exe"
VIA Platform Device Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
Virtools 3D Life Player --> C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB898549 --> "C:\WINDOWS\$NtUninstallKB898549$\spuninst\spuninst.exe"
WinPatrol 2007 --> C:\PROGRA~1\BILLPS~1\WINPAT~1\Setup.exe /remove /q0
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WISE-FTP 5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D21C9D95-DDBA-4962-899D-D1D350186555}\setup.exe" -l0x9 -removeonly
-- Application Event Log -------------------------------------------------------
Event Record #/Type1136 / Error
Event Submitted/Written: 02/13/2008 08:47:28 AM
Event ID/Source: 455 / ESENT
Event Description:
wuaueng.dll (1224) SUS20ClientDataStore: Error -1032 (0xfffffbf8) occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Event Record #/Type1135 / Error
Event Submitted/Written: 02/13/2008 08:47:28 AM
Event ID/Source: 489 / ESENT
Event Description:
wuauclt (1224) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Event Record #/Type1134 / Error
Event Submitted/Written: 02/13/2008 08:47:13 AM
Event ID/Source: 455 / ESENT
Event Description:
wuaueng.dll (1224) SUS20ClientDataStore: Error -1032 (0xfffffbf8) occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
Event Record #/Type1133 / Error
Event Submitted/Written: 02/13/2008 08:47:13 AM
Event ID/Source: 489 / ESENT
Event Description:
wuauclt (1224) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Event Record #/Type1087 / Warning
Event Submitted/Written: 02/11/2008 05:25:11 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x8007043C
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type5416 / Error
Event Submitted/Written: 02/13/2008 08:28:55 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {97D90E0F-6AF7-46F9-A8A3-9047200D5A0A} did not register with DCOM within the required timeout.
Event Record #/Type5361 / Error
Event Submitted/Written: 02/13/2008 09:45:42 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Event Record #/Type5360 / Error
Event Submitted/Written: 02/13/2008 09:45:32 AM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
AFD
easdrv
epfwtdir
Fips
IPSec
MRxSmb
NetBIOS
NetBT
Processor
RasAcd
Rdbss
SASDIFSV
SASKUTIL
Tcpip
Event Record #/Type5359 / Error
Event Submitted/Written: 02/13/2008 09:45:32 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31
Event Record #/Type5358 / Error
Event Submitted/Written: 02/13/2008 09:45:32 AM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31
-- End of Deckard's System Scanner: finished at 2008-02-13 20:48:50 ------------