SDFix: Version 1.165 Run by hamik on Thu 04/03/2008 at 08:02 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\a.bat - Deleted
C:\WINDOWS\system32\TFTP146780 - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-03 20:09:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\WINDOWS\\System32\\mozillaexplore.exe"="C:\\WINDOWS\\system32\\mozillaexplore.exe:*:Enabled:Office Printer"
"C:\\WINDOWS\\System32\\dllcache\\winppa.exe"="C:\\WINDOWS\\System32\\dllcache\\winppa.exe:*:Enabled:Microsoft PowerPoint Application"
"<=>?@ABCDEFGHIJKLMNOXf8"="<=>?@ABCDEFGHIJKLMNOXf8:*:Enabled:Offical Disc"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"<=>?@ABCDEFGHIJKLMNOPQRS."="<=>?@ABCDEFGHIJKLMNOPQRS.:*:Enabled:Offical Disc"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Windows Doctor\\1.7\\WindowsDoctor.exe"="C:\\Program Files\\Windows Doctor\\1.7\\WindowsDoctor.exe:*:Enabled:Windows Doctor"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 16 Jul 2003 246,867 ..SHR --- "C:\WINDOWS\system32\atdypypfro.exe"
Wed 26 Mar 2008 125,952 ..SHR --- "C:\WINDOWS\system32\mozillaexplore.exe"
Sat 29 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT5.tmp"
Finished!Deckard's System Scanner v20071014.68
Run by hamik on 2008-04-03 20:33:26
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 5 Restore Point(s) --
65: 2008-04-04 03:24:12 UTC - RP65 - Deckard's System Scanner Restore Point
64: 2008-04-02 04:30:47 UTC - RP64 - Installed Microsoft Office Professional Edition 2003
63: 2008-04-01 23:13:29 UTC - RP63 - Software Distribution Service 3.0
62: 2008-04-01 03:57:08 UTC - RP62 - Installed hp deskjet 5100
61: 2008-03-30 22:25:24 UTC - RP61 - Installed Steganos Internet Anonym VPN
-- First Restore Point --
1: 2008-03-26 03:07:33 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).-- HijackThis (run as hamik.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:33:53 PM, on 4/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\hamik\Desktop\dss.exe
C:\DOCUME~1\hamik\Desktop\hamik.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 202.99.204.66:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\RunServices: [Office Printer] mozillaexplore.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxerdrv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1206761197062O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 5889 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R3 catchme - c:\docume~1\hamik\locals~1\temp\catchme.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-29 14:22:24 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-03-03 and 2008-04-03 -----------------------------
2008-04-03 19:59:41 0 d-------- C:\WINDOWS\ERUNT
2008-04-02 19:40:43 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-04-02 19:40:29 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-04-02 19:40:12 0 d-------- C:\Program Files\Common Files\AOL
2008-04-02 19:40:10 0 d-------- C:\Program Files\AIM6
2008-04-02 19:38:04 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-04-01 21:31:49 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-04-01 21:30:57 0 d-------- C:\WINDOWS\SHELLNEW
2008-04-01 21:30:56 0 d-------- C:\Program Files\Microsoft.NET
2008-04-01 16:13:39 0 d-------- C:\Program Files\MSXML 4.0
2008-04-01 16:08:49 82432 -ra------ C:\WINDOWS\system32\MSXML4r.dll <Not Verified; Microsoft Corporation; Microsoft® MSXML 4.0 SP1>
2008-04-01 16:08:49 44544 -ra------ C:\WINDOWS\system32\MSXML4a.dll <Not Verified; Microsoft Corporation; Microsoft® MSXML 4.0 SP1>
2008-04-01 16:08:48 626960 -ra------ C:\WINDOWS\system32\hpvaut32.dll <Not Verified; Microsoft Corporation; >
2008-03-31 20:57:13 0 d-------- C:\Program Files\HP
2008-03-31 20:57:13 0 d-------- C:\Program Files\Hewlett-Packard
2008-03-31 18:08:37 11264 --a------ C:\WINDOWS\system32\SPORDER.DLL <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-03-31 18:08:36 61440 --a------ C:\WINDOWS\system32\PrxerNsp.dll <Not Verified; ; PrxerNsp>
2008-03-31 18:08:36 73728 --a------ C:\WINDOWS\system32\PrxerDrv.dll <Not Verified; Initex Software; Proxifier LSP>
2008-03-31 18:08:36 0 d-------- C:\Program Files\Proxifier
2008-03-30 15:23:28 0 d-------- C:\Program Files\VMNetSrv
2008-03-30 15:23:25 0 d-------- C:\Documents and Settings\hamik\Application Data\Steganos VPN
2008-03-30 15:23:07 0 d-------- C:\Program Files\Steganos Internet Anonym VPN
2008-03-30 15:18:35 0 d-------- C:\Program Files\PRIAMOS
2008-03-30 11:03:51 0 d-------- C:\Documents and Settings\hamik\Application Data\OpenOffice.org2
2008-03-30 10:57:12 0 d-------- C:\Program Files\OpenOffice.org 2.4
2008-03-29 22:50:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-29 14:25:24 0 d-------- C:\Documents and Settings\hamik\Application Data\Apple Computer
2008-03-29 14:24:44 0 d-------- C:\Program Files\iPod
2008-03-29 14:24:25 0 d-------- C:\Program Files\iTunes
2008-03-29 14:24:02 0 d-------- C:\Program Files\Bonjour
2008-03-29 14:22:52 0 d-------- C:\Program Files\QuickTime
2008-03-29 14:22:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-29 14:22:16 0 d-------- C:\Program Files\Apple Software Update
2008-03-29 14:22:05 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-03-29 14:21:37 0 d-------- C:\Program Files\Common Files\Apple
2008-03-29 14:21:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-29 14:14:16 0 d-------- C:\DOWNLOADS
2008-03-29 14:14:16 0 d-------- C:\!Temp
2008-03-29 13:57:28 0 d-------- C:\Program Files\Audible
2008-03-29 13:36:51 0 d-------- C:\Program Files\My-Proxy
2008-03-29 11:39:18 91700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-03-29 11:39:18 85860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-03-29 11:38:37 0 d-------- C:\Program Files\Kaspersky Lab
2008-03-29 11:38:35 116000 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-29 11:38:35 2005280 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-28 23:36:37 0 d-------- C:\WINDOWS\system32\PreInstall
2008-03-28 23:01:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-28 23:01:00 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-28 20:32:15 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-03-28 17:41:29 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-03-28 17:39:59 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-03-28 17:39:55 0 d-------- C:\WINDOWS\Prefetch
2008-03-28 17:27:02 0 d-------- C:\WINDOWS\provisioning
2008-03-28 17:27:02 0 d-------- C:\WINDOWS\peernet
2008-03-28 17:24:55 0 d-------- C:\WINDOWS\ServicePackFiles
2008-03-28 17:18:33 0 d-------- C:\WINDOWS\EHome
2008-03-27 21:59:56 0 d-------- C:\DVDVideoSoft
2008-03-27 21:59:40 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-03-27 21:59:37 0 d-------- C:\Program Files\DVDVideoSoft
2008-03-27 20:26:06 0 d-------- C:\Program Files\BearShare Pro
2008-03-27 10:54:12 0 d-------- C:\WINDOWS\.jagex_cache_32
2008-03-27 10:54:07 0 d-------- C:\WINDOWS\Sun
2008-03-27 10:54:07 0 d-------- C:\Documents and Settings\hamik\Application Data\Sun
2008-03-27 10:52:49 0 d-------- C:\Program Files\Java
2008-03-27 10:50:59 0 d-------- C:\Program Files\Common Files\Java
2008-03-26 20:18:03 0 d-------- C:\Program Files\Red Kawa
2008-03-26 20:17:15 0 d--h---c- C:\WINDOWS\$MSI30UninstallMSI30-KB884016$
2008-03-26 20:05:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-03-26 19:56:26 0 d--h----- C:\WINDOWS\$hf_mig$
2008-03-26 19:55:32 13312 --a------ C:\WINDOWS\system32\ntvdmd.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-26 19:50:15 0 d-------- C:\WINDOWS\RegisteredPackages
2008-03-26 19:47:02 125952 -r-hs---- C:\WINDOWS\system32\mozillaexplore.exe
2008-03-26 19:35:31 0 d-------- C:\Program Files\Windows Doctor
2008-03-26 19:35:05 0 d-------- C:\Documents and Settings\hamik\Application Data\Macromedia
2008-03-26 19:35:05 0 d-------- C:\Documents and Settings\hamik\Application Data\Adobe
2008-03-26 19:31:37 0 d-------- C:\Documents and Settings\hamik\Application Data\WinRAR
2008-03-26 19:29:27 335 --a------ C:\WINDOWS\nsreg.dat
2008-03-26 19:29:26 0 d-------- C:\Documents and Settings\hamik\Application Data\Mozilla
2008-03-26 19:18:42 0 d-------- C:\Documents and Settings\hamik\Application Data\Aim
2008-03-26 19:18:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-26 19:18:35 0 d-------- C:\Program Files\Viewpoint
2008-03-26 19:18:35 0 d-------- C:\Program Files\AOD
2008-03-26 19:18:30 0 d-------- C:\Program Files\AIM
2008-03-26 19:17:02 0 d---s---- C:\Documents and Settings\hamik\UserData
2008-03-25 20:53:02 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-03-25 20:50:45 0 d-------- C:\Program Files\Common Files\SureThing Shared
2008-03-25 20:50:44 0 d-------- C:\Program Files\Sonic
2008-03-25 20:45:56 26768 -----n--- C:\WINDOWS\system32\CTL3D.DLL <Not Verified; Microsoft Corporation; 3D Windows Control>
2008-03-25 20:45:56 40960 -----n--- C:\WINDOWS\system32\AC3API.DLL <Not Verified; Creative Technology Ltd; AC3 API Library>
2008-03-25 20:45:56 53552 -----n--- C:\WINDOWS\CTCCW.DLL <Not Verified; Creative® Technology Ltd.; Custom Control for Windows>
2008-03-25 20:45:55 1048576 -----n--- C:\WINDOWS\system32\SFMAN.DAT
2008-03-25 20:45:55 24576 --a------ C:\WINDOWS\system32\CTDevCRes.dll <Not Verified; Creative Technology Ltd; Audio Device Control>
2008-03-25 20:45:24 0 d-------- C:\WINDOWS\system32\Data
2008-03-25 20:45:24 20480 --a------ C:\WINDOWS\INRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-25 20:45:22 24576 --a------ C:\WINDOWS\MIXERDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-25 20:45:21 61440 --a------ C:\WINDOWS\MIDIDEF.EXE <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-25 20:44:58 25088 -----n--- C:\WINDOWS\system32\CTsvcCtl.EXE <Not Verified; Creative Technology Ltd; Creative Service Control>
2008-03-25 20:44:58 44032 -----n--- C:\WINDOWS\system32\CTsvcCDA.EXE <Not Verified; Creative Technology Ltd; Creative Service for CDROM Access>
2008-03-25 20:44:57 0 d-------- C:\Media
2008-03-25 20:44:56 54784 -----n--- C:\WINDOWS\system32\INETWH32.DLL <Not Verified; Blue Sky Software Corporation.; Blue Sky Software - INETWH32>
2008-03-25 20:44:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Creative
2008-03-25 20:43:12 0 d-------- C:\Program Files\Creative
2008-03-25 20:19:06 0 d-------- C:\Program Files\Intel
2008-03-25 20:18:37 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-03-25 20:11:51 0 d-------- C:\drvrtmp
2008-03-25 20:09:00 176128 --a------ C:\WINDOWS\system32\RcdScan.dll <Not Verified; Dell Computer Corporation; RcdScan Module>
2008-03-25 20:09:00 446464 -ra------ C:\WINDOWS\system32\hhactivex.dll <Not Verified; Blue Sky Software Corporation.; RoboHELP HTML 2000>
2008-03-25 20:08:58 13632 -----n--- C:\WINDOWS\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
2008-03-25 20:08:58 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-25 20:08:40 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-25 20:07:24 0 d--hs---- C:\WINDOWS\Installer
2008-03-25 20:07:21 0 d-------- C:\Documents and Settings\hamik\Application Data\Identities
2008-03-25 20:07:12 0 d--h----- C:\Documents and Settings\hamik\Templates
2008-03-25 20:07:12 0 dr------- C:\Documents and Settings\hamik\Start Menu
2008-03-25 20:07:12 0 dr-h----- C:\Documents and Settings\hamik\SendTo
2008-03-25 20:07:12 0 dr-h----- C:\Documents and Settings\hamik\Recent
2008-03-25 20:07:12 0 d--h----- C:\Documents and Settings\hamik\PrintHood
2008-03-25 20:07:12 2097152 --ah----- C:\Documents and Settings\hamik\NTUSER.DAT
2008-03-25 20:07:12 0 d--h----- C:\Documents and Settings\hamik\NetHood
2008-03-25 20:07:12 0 dr------- C:\Documents and Settings\hamik\My Documents
2008-03-25 20:07:12 0 d--h----- C:\Documents and Settings\hamik\Local Settings
2008-03-25 20:07:12 0 dr------- C:\Documents and Settings\hamik\Favorites
2008-03-25 20:07:12 0 d-------- C:\Documents and Settings\hamik\Desktop
2008-03-25 20:07:12 0 d---s---- C:\Documents and Settings\hamik\Cookies
2008-03-25 20:07:12 0 dr-h----- C:\Documents and Settings\hamik\Application Data
2008-03-25 20:05:36 0 d--hs---- C:\System Volume Information
2008-03-25 20:05:34 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-03-25 20:05:34 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-03-25 20:05:34 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-03-25 20:05:34 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-03-25 20:05:34 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-03-25 20:05:34 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-03-25 20:05:34 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-03-25 20:05:34 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-03-25 20:05:34 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-03-25 20:05:34 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-03-25 19:55:52 0 d-------- C:\WINDOWS\system32\xircom
2008-03-25 19:55:52 0 d-------- C:\Program Files\microsoft frontpage
2008-03-25 19:55:49 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-03-25 19:55:49 0 d-------- C:\DELL
2008-03-25 19:53:27 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-25 19:52:24 0 -rahs---- C:\MSDOS.SYS
2008-03-25 19:52:24 0 -rahs---- C:\IO.SYS
2008-03-25 19:52:24 0 --a------ C:\CONFIG.SYS
2008-03-25 19:52:24 0 --a------ C:\AUTOEXEC.BAT
2008-03-25 19:51:39 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-03-25 19:51:31 0 dr------- C:\WINDOWS\Offline Web Pages
2008-03-25 19:51:31 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-03-25 19:51:07 0 d-------- C:\WINDOWS\system32\DirectX
2008-03-25 19:50:33 0 d---s---- C:\WINDOWS\Tasks
2008-03-25 19:50:28 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-25 19:50:25 0 d-------- C:\WINDOWS\system32\Macromed
2008-03-25 19:50:25 0 d-------- C:\WINDOWS\srchasst
2008-03-25 19:50:24 0 d-------- C:\Program Files\Movie Maker
2008-03-25 19:50:21 0 d-------- C:\WINDOWS\system32\Restore
2008-03-25 19:50:21 0 d-------- C:\WINDOWS\PCHealth
2008-03-25 19:50:11 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-25 19:49:58 0 d-------- C:\WINDOWS\Registration
2008-03-25 19:49:34 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-25 19:49:34 0 d-------- C:\Program Files\Online Services
2008-03-25 19:49:30 0 d-------- C:\Program Files\Messenger
2008-03-25 19:49:26 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-25 19:48:59 0 d-------- C:\Program Files\Windows NT
2008-03-25 19:48:57 0 d-------- C:\WINDOWS\system32\MsDtc
2008-03-25 19:48:56 0 d-------- C:\WINDOWS\system32\Com
2008-03-25 11:45:26 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-25 11:45:23 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-03-25 11:45:22 0 dr------- C:\Program Files
2008-03-25 11:45:22 0 d-------- C:\Program Files\Common Files
2008-03-25 11:45:00 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-03-25 11:45:00 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-03-25 11:45:00 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-03-25 11:45:00 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-03-25 11:45:00 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-03-25 11:45:00 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-03-25 11:45:00 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-03-25 11:45:00 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-03-25 11:45:00 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-03-25 11:45:00 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-03-25 11:45:00 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-03-25 11:45:00 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-03-25 11:45:00 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-03-25 11:45:00 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-03-25 11:45:00 0 dr------- C:\Documents and Settings\All Users\Documents
2008-03-25 11:45:00 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-03-25 11:44:50 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-03-25 11:44:50 0 d-------- C:\WINDOWS\system32\CatRoot
2008-03-25 11:44:45 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-03-25 11:44:45 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-03-25 11:44:44 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-03-25 11:44:44 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-03-25 11:44:30 0 d-------- C:\Documents and Settings
2008-03-25 11:39:19 0 d-------- C:\WINDOWS
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\WinSxS
2008-03-25 11:39:19 0 dr------- C:\WINDOWS\Web
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\twain_32
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\wins
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\wbem
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\usmt
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\spool
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\ShellExt
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\Setup
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\ras
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\oobe
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\npp
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\mui
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\inetsrv
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\IME
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\icsxml
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\ias
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\export
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\drivers
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-03-25 11:39:19 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\dhcp
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\config
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\3076
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\2052
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1054
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1042
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1041
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1037
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1033
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1031
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1028
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system32\1025
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\system
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\security
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Resources
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\repair
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\mui
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\msapps
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\msagent
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Media
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\java
2008-03-25 11:39:19 0 d--h----- C:\WINDOWS\inf
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\ime
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Help
2008-03-25 11:39:19 0 dr--s---- C:\WINDOWS\Fonts
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Driver Cache
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Debug
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Cursors
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Connection Wizard
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\Config
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\AppPatch
2008-03-25 11:39:19 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-03-31 18:47:03 112 --a------ C:\Documents and Settings\hamik\Application Data\Current.prx
2008-03-25 11:45:00 62 --ahs---- C:\Documents and Settings\hamik\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [10/17/2003 01:52 PM]
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" [04/03/2002 02:01 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 01:51 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [02/01/2008 12:13 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 02:10 PM]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [06/25/2003 11:24 AM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [10/23/2003 07:51 PM]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [01/12/2006 11:58 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Office Printer"=mozillaexplore.exe
C:\Documents and Settings\hamik\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [1/21/2008 3:41:28 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2008-04-03 20:35:33 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 2.80GHz
CPU 1: Intel® Pentium® 4 CPU 2.80GHz
Percentage of Memory in Use: 59%
Physical Memory (total/avail): 511 MiB / 207.29 MiB
Pagefile Memory (total/avail): 1249.7 MiB / 1027.3 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1917.77 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 37.24 GiB total, 22.31 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - ST340014A - 37.25 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 37.24 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FW: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)
DisabledAV: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)
Disabled[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\System32\\mozillaexplore.exe"="C:\\WINDOWS\\system32\\mozillaexplore.exe:*:Enabled:Office Printer"
"C:\\WINDOWS\\System32\\dllcache\\winppa.exe"="C:\\WINDOWS\\System32\\dllcache\\winppa.exe:*:Enabled:Microsoft PowerPoint Application"
"<=>?@ABCDEFGHIJKLMNOXf8"="<=>?@ABCDEFGHIJKLMNOXf8:*:Enabled:Offical Disc"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"<=>?@ABCDEFGHIJKLMNOPQRS."="<=>?@ABCDEFGHIJKLMNOPQRS.:*:Enabled:Offical Disc"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Windows Doctor\\1.7\\WindowsDoctor.exe"="C:\\Program Files\\Windows Doctor\\1.7\\WindowsDoctor.exe:*:Enabled:Windows Doctor"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\hamik\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HAMIK-CL4Q0HYV3
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\hamik
LOGONSERVER=\\HAMIK-CL4Q0HYV3
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\hamik\LOCALS~1\Temp
TMP=C:\DOCUME~1\hamik\LOCALS~1\Temp
USERDOMAIN=HAMIK-CL4Q0HYV3
USERNAME=hamik
USERPROFILE=C:\Documents and Settings\hamik
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
hamik
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> "C:\Program Files\Creative\SBLive\Program\Ctzapxx.EXE" /X /U /S /R
--> C:\WINDOWS\System32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44DC86A0-248D-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48E3A9E6-FA13-11D5-8CC9-00A0C98192B6}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{48E3A9E6-FA13-11D5-8CC9-00A0C98192B6}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51F5239C-197B-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51F5239C-197B-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7337A45-3FE5-4392-ABBB-26B794D060C9}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7337A45-3FE5-4392-ABBB-26B794D060C9}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F865C2FE-25E7-11D6-9BAF-0090271AF8A4}\setup.exe" -l0x9 /remove
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
AIM 6.0 --> C:\Program Files\AIM6\uninst.exe
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Audible Download Manager --> C:\Program Files\Audible\Bin\AudibleDM_iTunesSetup.exe /Uninstall
AudibleManager --> C:\Program Files\Audible\Bin\Upgrade.exe /Uninstall
BearShare Pro 5.3.0.0 --> "C:\Program Files\BearShare Pro\unins000.exe"
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Dell ResourceCD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Elite Proxy Switcher 1.05 --> "C:\Program Files\My-Proxy\Elite Proxy Switcher\unins000.exe"
Free YouTube to Mp3 Converter version 2.5 --> "C:\Program Files\DVDVideoSoft\Free YouTube to Mp3 Converter\unins000.exe"
HijackThis 2.0.2 --> "C:\Documents and Settings\hamik\Desktop\HijackThis.exe" /uninstall
hp deskjet 5100 --> msiexec /x{15C165F1-1DAE-4476-AFB6-8723729B41E7}
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
Internet Explorer Q903235 --> C:\WINDOWS\ieuninst.exe C:\WINDOWS\INF\Q903235.inf
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
Java 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
NVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvdd.inf
OpenOffice.org 2.4 --> MsiExec.exe /I{F87A8E11-02A4-4875-A3A5-5961081B0E4E}
PRIAMOS.v1.0 --> "C:\Program Files\PRIAMOS\unins000.exe"
Proxifier version 2.7 --> "C:\Program Files\Proxifier\unins000.exe"
PSP Video 9 2.25 --> C:\Program Files\Red Kawa\Video Converter\uninstaller.exe
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sound Blaster Live! --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}\SETUP.EXE" -l0x9
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steganos Internet Anonym VPN --> C:\Program Files\Steganos Internet Anonym VPN\uninstall.exe
Uninstall 1.0.0.0 --> "C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Virtual Machine Network Services Driver --> MsiExec.exe /I{A1795AC0-9B6A-40D9-8E07-A82662268D9F}
Windows Doctor 1.7 --> "C:\Program Files\Windows Doctor\1.7\unins000.exe"
-- Application Event Log -------------------------------------------------------
Event Record #/Type314 / Error
Event Submitted/Written: 04/02/2008 10:26:33 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type307 / Error
Event Submitted/Written: 04/02/2008 08:47:53 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application eps.exe, version 1.0.0.1, faulting module eps.exe, version 1.0.0.1, fault address 0x0000c001.
Processing media-specific event for [eps.exe!ws!]
Event Record #/Type306 / Error
Event Submitted/Written: 04/02/2008 05:40:54 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type305 / Error
Event Submitted/Written: 04/02/2008 05:40:52 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type284 / Error
Event Submitted/Written: 03/31/2008 09:06:24 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1259 / Error
Event Submitted/Written: 04/03/2008 07:59:11 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}
Event Record #/Type1258 / Error
Event Submitted/Written: 04/03/2008 07:58:33 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}
Event Record #/Type1257 / Error
Event Submitted/Written: 04/03/2008 07:55:50 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
AFD
Fips
intelppm
IPSec
kl1
klif
MRxSmb
NetBIOS
NetBT
OMCI
RasAcd
Rdbss
Tcpip
WS2IFSL
Event Record #/Type1256 / Error
Event Submitted/Written: 04/03/2008 07:55:50 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31
Event Record #/Type1255 / Error
Event Submitted/Written: 04/03/2008 07:55:50 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31
-- End of Deckard's System Scanner: finished at 2008-04-03 20:35:33 ------------