The way I got safe mode to work was in my last topic. "the skeptic" advised me to....
Try to run System File Checker. In normal mode click Start > Run. Type sfc /scannow and press enter. Let the process run to the end, at which the dialog box just disappears. You will be asked, most probably, to insert the XP installation CD, so keep it ready.
Try to boot into safe mode.
After i ran the system file checker
I restarted computer and pressed F8.
I then selected Safe Mode (not with networking or anything)
And then i pressed enter.
Safe mode booted up correctly. and still boots up when ever i select it.
An i just ran the DSS scan. here are the details.
Deckard's System Scanner v20071014.68
Run by Muffin on 2008-04-26 19:42:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
90: 2008-04-27 02:42:33 UTC - RP728 - Deckard's System Scanner Restore Point
89: 2008-04-25 18:33:56 UTC - RP727 - System Checkpoint
88: 2008-04-21 19:22:21 UTC - RP726 - Deckard's System Scanner Restore Point
87: 2008-04-21 17:42:52 UTC - RP725 - System Checkpoint
86: 2008-04-20 02:31:52 UTC - RP724 - Removed Adobe® Photoshop® Album Starter Edition 3.0
-- First Restore Point --
1: 2008-01-27 04:38:47 UTC - RP639 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Muffin.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:02 PM, on 4/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
G:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Documents and Settings\Muffin\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Muffin.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\mspaint.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://go.microsoft....k/?LinkId=54843R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - G:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HP Software Update] G:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] G:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - Startup: SpywareGuard.lnk = G:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = G:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - G:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP chain gap (#2 in chain of 6 missing)
O15 - Trusted Zone:
http://connect.aaa.calif.comO15 - Trusted Zone:
http://www.nps.govO15 - Trusted Zone:
http://*.windowsupdate.comO16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akama...ex/qtplugin.cabO16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) -
https://h20364.www2....DataManager.CABO16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) -
http://www.trendsecu...vex/TmHcmsX.CABO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.t...ivex/hcImpl.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....aceUploader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1151277926046O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://192.168.0.253...sCamControl.ocxO16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -
http://www.trendmicr...scan/as4web.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) -
https://connect.aaa-...perSetupSP1.cabO16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30155.www3.h.../qdiagh.cab?326O20 - Winlogon Notify: !SASWinLogon - G:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - G:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - G:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - G:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
--
End of file - 11808 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-153.hlp - hlpfile - DefaultIcon - C:\WINDOWS\hh.exe,0.inf - inffile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151.ini - inifile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,-151.js - JSFile - DefaultIcon - "G:\Program Files\Macromedia Studio 8\Dreamweaver 8\dreamweaver.exe",2.reg - regfile - DefaultIcon - C:\WINDOWS\regedit.exe,1.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,-152-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys <Not Verified; IVT Corporation; BlueSoleil©>
R1 NEOFLTR_530_11531 (Juniper Networks TDI Filter Driver (NEOFLTR_530_11531)) - c:\windows\system32\drivers\neofltr_530_11531.sys <Not Verified; Neoteris; Secure Application Manager>
R2 SIODRV - c:\windows\system32\drivers\siodrv.sys <Not Verified; Intel Corporation; Intel® Active Monitor>
R3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 SMBios (Intel ® System Management BIOS Service) - c:\windows\system32\drivers\smbios.sys <Not Verified; Intel Corporation; Intel ® System Management BIOS Driver>
R3 smbusp (Intel® SMBus 2.0 Driver) - c:\windows\system32\drivers\smb.sys <Not Verified; Intel Corporation; Intel® SMBus Controller>
R3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys <Not Verified; IVT Corporation; BlueSoleil>
S2 nvtvSND (MSI8928 nVidia WDM TVAudio Crossbar) - c:\windows\system32\drivers\nvtvsnd.sys (file missing)
S3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys <Not Verified; IVT Corporation; Windows ® 2000 DDK driver>
S3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys <Not Verified; IVT Corporation; BlueSoleil>
S3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys <Not Verified; IVT Corporation; Bluetooth USB Device Driver>
S3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys
S3 BTNetFilter (Bluetooth Network Filter) - c:\windows\system32\drivers\btnetfilter.sys
S3 jfdcd - c:\docume~1\muffin\locals~1\temp\jfdcd.sys (file missing)
S3 MPCSYS - c:\windows\system32\drivers\mpcsys.sys
S3 PCANDIS5 (PCANDIS5 Protocol Driver) - c:\program files\smartstation\station adapter utility\pcandis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 SASENUM - g:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys <Not Verified; IVT Corporation; BlueSoleil>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 imonNT (Intel® Active Monitor) - g:\program files\intel\intel® active monitor\imonnt.exe <Not Verified; Intel Corp.; Intel® Active Monitor>
S2 sshd (CYGWIN sshd) - c:\cygwin\bin\cygrunsrv.exe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: VMware Virtual Ethernet Adapter for VMnet1
Device ID: ROOT\VMWARE\0000
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet1
PNP Device ID: ROOT\VMWARE\0000
Service: VMnetAdapter
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: VMware Virtual Ethernet Adapter for VMnet8
Device ID: ROOT\VMWARE\0001
Manufacturer: VMware, Inc.
Name: VMware Virtual Ethernet Adapter for VMnet8
PNP Device ID: ROOT\VMWARE\0001
Service: VMnetAdapter
-- Scheduled Tasks -------------------------------------------------------------
2008-04-26 19:40:48 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-04-25 12:11:30 256 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-04-25 12:00:00 274 --ah----- C:\WINDOWS\Tasks\A89A0A709399B8AC.job
-- Files created between 2008-03-26 and 2008-04-26 -----------------------------
2008-04-25 10:35:23 0 d-------- C:\Documents and Settings\Administrator\Application Data\ATI
2008-04-19 19:38:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-04-19 19:37:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-19 19:31:47 0 d-------- C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-04-19 19:28:19 0 d--h----- C:\Documents and Settings\Administrator\InstallAnywhere
2008-04-19 19:27:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\Real
2008-04-18 12:12:55 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-18 12:08:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-18 11:10:32 0 d-------- C:\Program Files\Windows Defender
2008-04-18 10:56:04 0 d-------- C:\Documents and Settings\Muffin\Application Data\Malwarebytes
2008-04-18 10:55:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-06 00:10:15 0 d-------- C:\Documents and Settings\Galdys\Application Data\uTorrent
2008-04-05 23:27:28 58340 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-04-01 20:45:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-31 15:54:38 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-31 15:54:30 0 d-------- C:\Documents and Settings\Muffin\Application Data\SUPERAntiSpyware.com
-- Find3M Report ---------------------------------------------------------------
2008-04-19 19:35:21 0 d-------- C:\Program Files\Common Files
2008-04-19 19:28:34 0 d--h----- C:\Program Files\Zero G Registry
2008-04-19 19:27:54 0 d-------- C:\Program Files\Canon
2008-04-19 19:27:13 0 d-------- C:\Program Files\Common Files\Real
2008-04-19 19:18:37 0 d-------- C:\Program Files\Nikon
2008-04-19 19:17:08 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-19 19:16:41 0 d-------- C:\Program Files\Total Video Converter
2008-04-19 19:13:55 0 d-------- C:\Program Files\Skype
2008-04-19 19:02:58 0 d-------- C:\Program Files\Macromedia
2008-04-19 18:58:13 0 d-------- C:\Program Files\Greeting Card Creator 32
2008-04-19 18:55:16 0 d-------- C:\Program Files\Corel
2008-04-03 21:00:01 0 d-------- C:\Program Files\Trend Micro
2008-04-02 22:02:13 0 d-------- C:\Program Files\FLAC Converter
2008-03-24 18:57:25 0 d-------- C:\Documents and Settings\Muffin\Application Data\uTorrent
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32winlogonpc.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32temp#01.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32taack.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32taack.dat
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32ssurf022.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32sncntr.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32psoft1.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32psof1.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32ps1.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32netode.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32mwin32.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32mtr2.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32msnbho.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32msgp.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32medup020.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32medup012.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32hxiwlgpm.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32hoproxy.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-03-24 18:54:54 4096 --a------ C:\WINDOWS\a.bat
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\winsystem.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32WINWGPX.EXE
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32winsystem.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32vcatchpi.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32vbsys2.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32thun32.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32thun.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32sysreq.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32ssvchost.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32Rundl1.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32regm64.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32regc64.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32newsd32.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32msvchost.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32mssecu.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32emesx.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32dpcproxy.exe
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32bdn.com
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32awtoolb.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32anticipator.dll
2008-03-24 18:54:53 4096 --a------ C:\WINDOWS\system32akttzn.exe
2008-03-24 17:43:21 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-23 10:41:34 0 d-------- C:\Documents and Settings\Muffin\Application Data\Adobe
2008-03-22 15:34:16 230432 --a------ C:\PA7311.DAT
2008-03-22 15:27:47 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-22 15:27:04 0 d-------- C:\Program Files\Common Files\PAC7311
2008-03-22 15:27:02 0 d-------- C:\Program Files\Micro Innovations
2008-03-14 17:01:26 0 d-------- C:\Documents and Settings\Muffin\Application Data\Macromedia
2008-03-13 21:27:40 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-03-13 21:19:40 0 d-------- C:\Program Files\Common Files\Macromedia
2008-03-10 11:46:18 0 d-------- C:\Program Files\Google
2008-03-03 10:21:19 0 d-------- C:\Documents and Settings\Muffin\Application Data\U3
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [05/30/2003 09:42 AM]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" []
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [05/29/2003 04:28 PM]
"QuickTime Task"="G:\Program Files\QuickTime\qttask.exe" [02/01/2008 12:13 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [08/11/2005 04:30 PM]
"HP Software Update"="G:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [01/02/2006 04:41 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" []
"ISUSPM Startup"="c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [08/11/2005 04:30 PM]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [02/16/2008 12:56 AM]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM]
"avast!"="G:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [03/29/2008 11:37 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" []
"NBJ"="C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe" [04/14/2005 04:56 PM]
"STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" []
"OE"="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [02/15/2008 11:39 PM]
C:\Documents and Settings\Muffin\Start Menu\Programs\Startup\
SpywareGuard.lnk - G:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [5/15/2003 1:19:50 AM]
HP Photosmart Premier Fast Start.lnk - G:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2/10/2006 7:56:20 AM]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [6/21/2007 4:22:26 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= G:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
G:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 G:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe "G:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
"c:\Program Files\Zune\ZuneLauncher.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8ae4f07-308c-11dc-a534-00e07ddb66ac}]
AutoRun\command- J:\LaunchU3.exe -a
-- Hosts -----------------------------------------------------------------------
192.168.0.105 isd
-- End of Deckard's System Scanner: finished at 2008-04-26 19:49:30 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 36%
Physical Memory (total/avail): 1534.67 MiB / 981.86 MiB
Pagefile Memory (total/avail): 3436.03 MiB / 3042.02 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1934.29 MiB
C: is Fixed (NTFS) - 189.91 GiB total, 41.76 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is Fixed (NTFS) - 279.46 GiB total, 9.82 GiB free.
G: is Fixed (NTFS) - 74.52 GiB total, 36.93 GiB free.
H: is Fixed (NTFS) - 74.52 GiB total, 6.95 GiB free.
I: is Fixed (NTFS) - 279.45 GiB total, 274.05 GiB free.
\\.\PHYSICALDRIVE0 - Maxtor 6L200P0 - 189.92 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 189.91 GiB - C:
\\.\PHYSICALDRIVE3 - ST3300622AS - 279.46 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 279.45 GiB - I:
\\.\PHYSICALDRIVE2 - ST3300631AS - 279.46 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 279.46 GiB - F:
\\.\PHYSICALDRIVE1 - WDC WD1600JB-00GVA0 - 149.05 GiB - 1 partition
\PARTITION0 - Logical Disk Manager - 149.05 GiB - G: - H:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FirstRunDisabled is set.
AntivirusOverride is set.
FW: Trend Micro Personal Firewall v5.2 (Trend Micro Inc.)
AV: AVG 7.5.519 v7.5.519 (Grisoft)
OutdatedAV: Trend Micro Internet Security v16.10.1079 ()
Outdated[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\InterVideo\\MSIPVS\\WinDvr.exe"="C:\\Program Files\\InterVideo\\MSIPVS\\WinDvr.exe:*:Enabled:InterVideo?WinDVR Application"
"G:\\Program Files\\AIM\\aim.exe"="G:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"G:\\Games\\Steam\\steamapps\\
[email protected]\\day of defeat\\hl.exe"="G:\\Games\\Steam\\steamapps\\
[email protected]\\day of defeat\\hl.exe:*:Enabled:Half-Life Launcher"
"G:\\Games\\Steam\\steamapps\\
[email protected]\\counter-strike\\hl.exe"="G:\\Games\\Steam\\steamapps\\
[email protected]\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"G:\\Program Files\\3CServer.exe"="G:\\Program Files\\3CServer.exe:*:Enabled:3CServer TFTP/FTP Server"
"C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe"="C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy"
"G:\\Program Files\\Torrent101\\Torrent101.exe"="G:\\Program Files\\Torrent101\\Torrent101.exe:*:Disabled:Torrent P2P application"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Disabled:AOL Loader"
"C:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe"="C:\\Program Files\\Yahoo! Games\\Bejeweled 2 Deluxe\\WinBej2.exe:*:Disabled:Bejeweled2"
"G:\\Program Files\\BitLord\\BitLord.exe"="G:\\Program Files\\BitLord\\BitLord.exe:*:Disabled:BitLord"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Disabled:BitTorrent"
"G:\\Games\\Lionhead Studios\\runblack.exe"="G:\\Games\\Lionhead Studios\\runblack.exe:*:Disabled:lh"
"C:\\Program Files\\GameHouse\\Collapse II\\Relapse.exe"="C:\\Program Files\\GameHouse\\Collapse II\\Relapse.exe:*:Disabled:Super Collapse! II"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Disabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Disabled:Windows Messenger"
"G:\\Games\\Guild Wars\\Gw.exe"="G:\\Games\\Guild Wars\\Gw.exe:*:Enabled:Guild Wars"
"G:\\Games\\Microsoft\\Age of Empires III\\age3.exe"="G:\\Games\\Microsoft\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires III"
"G:\\Games\\Microsoft\\Age of Empires III\\age3x.exe"="G:\\Games\\Microsoft\\Age of Empires III\\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"
"G:\\Games\\Microsoft\\Age of Empires III\\age3y.exe"="G:\\Games\\Microsoft\\Age of Empires III\\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"G:\\Games\\Microsoft\\Age Of Empires II\\age2_x1\\AGE2_X1.ICD"="G:\\Games\\Microsoft\\Age Of Empires II\\age2_x1\\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\WoW-2.0.0.5991-enUS-Installer-downloader.exe"="C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\WoW-2.0.0.5991-enUS-Installer-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\wowclient-downloader.exe"="C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\wowclient-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\WoW-BurningCrusade-enUS-Installer-downloader.exe"="C:\\Documents and Settings\\Muffin\\Desktop\\WOW\\WoW-BurningCrusade-enUS-Installer-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"="C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"G:\\Games\\Steam\\Steam.exe"="G:\\Games\\Steam\\Steam.exe:*:Disabled:Steam"
"C:\\Documents and Settings\\Mark\\Local Settings\\Temp\\Rar$EX01.750\\SuperScan4.exe"="C:\\Documents and Settings\\Mark\\Local Settings\\Temp\\Rar$EX01.750\\SuperScan4.exe:*:Disabled:SuperScan 4 Beta 1"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Disabled:Yahoo! FT Server"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Muffin\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MTB001
ComSpec=C:\WINDOWS\system32\cmd.exe
CYGWIN=ntsec tty
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Muffin
LOGONSERVER=\\MTB001
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\ATI Technologies\ATI.ACE\;c:\cygwin\bin;G:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0303
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Muffin\LOCALS~1\Temp
TMP=C:\DOCUME~1\Muffin\LOCALS~1\Temp
USERDOMAIN=MTB001
USERNAME=Muffin
USERPROFILE=C:\Documents and Settings\Muffin
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Mark
(admin)Diane
(admin)Muffin
(admin)Joey
(admin)Friend
ASPNET
(new local)Galdys
(admin)Administrator
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
3CServer --> C:\WINDOWS\IsUninst.exe -f"g:\program files\Uninst.isu"
Adobe Acrobat 6.0 Professional --> MsiExec.exe /I{AC76BA86-1033-0000-7760-000000000001}
Adobe Atmosphere Player for Acrobat and Adobe Reader --> C:\WINDOWS\atmoUn.exe
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
Age of Empires III --> C:\Program Files\InstallShield Installation Information\{70F8B183-99EB-4304-BA35-080E2DFFD2A3}\setup.exe -runfromtemp -l0x0409
Age of Empires III - The Asian Dynasties --> C:\Program Files\InstallShield Installation Information\{C43C1415-3DFC-4089-9A32-0BECF28A6046}\setup.exe -runfromtemp -l0x0409
Age of Empires III - The WarChiefs --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{1C08A24C-B168-407E-A826-68FAF5F20710}
AOL Instant Messenger --> G:\Program Files\AIM\uninstll.exe -LOG= G:\Program Files\AIM\install.log -OEM=
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center --> MsiExec.exe /I{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
avast! Antivirus --> G:\Program Files\Alwil Software\Avast4\aswRunDll.exe "G:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Black and White --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E51B4CD9-A0A6-4324-B26A-31B3F2DE26CE}\setup.exe"
Blaze Media Pro --> "C:\Documents and Settings\Muffin\Local Settings\Application Data\{137E54F6-3421-4EAC-89EB-A08622409B6F}\setup_blazemp.exe" REMOVE=TRUE MODIFY=FALSE
Canon PhotoRecord --> MsiExec.exe /X{D958FAC4-BAE0-4B1D-A42E-DE9BFDE7DDEE}
Canon PIXMA iP4000 --> C:\WINDOWS\system32\CNMCP64.exe "-PRINTERNAMECanon PIXMA iP4000" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP4000 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon PIXMA iP4000 Installer\Inst2\cnmi0409.dll"
Canon Utilities Easy-PhotoPrint --> C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
CDex extraction audio --> "G:\Program Files\CDex_170b2\uninstall.exe"
CiD Help --> C:\DOCUME~1\Muffin\APPLIC~1\LOADVI~1\Barb warn style.exe -uninstall
DeadAIM --> MsiExec.exe /I{0F8F3415-CB0A-49A6-A23A-D8390444B127}
Deathmatch Classic --> "G:\Games\Steam\steam.exe" steam://uninstall/40
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD Decrypter (Remove Only) --> "G:\Program Files\DVD Decrypter\uninstall.exe"
DVD Shrink 3.2 --> "G:\DVD Shrink\unins000.exe"
Form Fill (Windows Live Toolbar) --> MsiExec.exe /X{548B3DC6-2300-47E1-BA7B-74AD25F8DEBF}
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Guild Wars --> "G:\Games\Guild Wars\Gw.exe" -uninstall
Half-Life: Blue Shift --> "G:\Games\Steam\steam.exe" steam://uninstall/130
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Imaging Device Functions 7.0 --> G:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Premier Software 6.5 --> G:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Scanjet G4000 series 8.0 --> G:\Program Files\HP\Digital Imaging\{38D56396-298F-4874-B4EC-16B530B07879}\setup\hpzscr01.exe -datfile hpgscr17.dat
HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
HP Solution Center 7.0 --> G:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
IC 445C Webcam --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C19BDB2-7456-40A5-8832-237A78827AF1} /l1033
Intel® Active Monitor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E861EC9-FCB8-11D3-939A-00A0C9BA5A55}\setup.exe"
InterVideo MSIPVS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CC9D60B8-B270-4AE0-8208-CCB01C42CD6A}\setup.exe" REMOVEALL
InterVideo WinDVDX --> "C:\Program Files\InstallShield Installation Information\{1A91D1FA-B9B3-4556-9878-5C61059A19B2}\setup.exe" REMOVEALL
InterVideo WinDVRX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{89AD2814-AFA2-46AF-AE53-C27196D9FBE6}\setup.exe" REMOVEALL
J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Juniper Networks Secure Application Manager --> C:\Program Files\Neoteris\Secure Application Manager\UninstallSAM.exe
Macromedia Dreamweaver 8 --> MsiExec.exe /I{0837A661-FEC3-48B3-876C-91E7D32048A9}
Macromedia Dreamweaver MX 2004 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{05BB2EC5-6BEF-4DDC-9E75-BEE7B161157A}\Setup.exe" -l0x9 mmUninstall
Macromedia Extension Manager --> MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
Macromedia Fireworks 8 --> MsiExec.exe /I{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}
Macromedia Flash 8 --> MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}
Macromedia Flash 8 Video Encoder --> MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}
Macromedia Flash MX 2004 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F353D44-73BB-4971-B31D-F7642E9E9531}\Setup.exe" -l0x9 UNINSTALL
Macromedia Flash Player 8 --> MsiExec.exe /X{885A63EA-382B-4DD4-A755-14809B8557D6}
Malwarebytes' Anti-Malware --> "G:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Map Button (Windows Live Toolbar) --> MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
Microsoft Age of Empires II --> "G:\Games\Microsoft\Age Of Empires II\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Age of Empires II: The Conquerors Expansion --> "G:\Games\Microsoft\Age Of Empires II\UNINSTALX.EXE" /runtemp /addremove
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Move Networks Player for Firefox --> "G:\Program Files\Mozilla Firefox\plugins\unins000.exe"
Mozilla Firefox (2.0.0.13) --> G:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
MSI Media Center Deluxe II --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12808370-8A8B-4A0A-8A96-385C309A58D6}\setup.exe"
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
NEC DISPLAY SOLUTIONS: Monitor Installer --> C:\Program Files\NEC DISPLAY SOLUTIONS\Drivers\Uninstall.exe
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nikon Message Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\Setup.exe" -l0x9 UNINSTALL
OCR Software by I.R.I.S 8.0 --> G:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{53B2CFE9-A508-4457-B2CA-5D253536BFB7}
Opera --> G:\PROGRA~1\Opera\uninst\unwise.exe G:\PROGRA~1\Opera\uninst\install.log
Opposing Force --> "G:\Games\Steam\steam.exe" steam://uninstall/50
Picasa 2 --> "G:\Program Files\Picasa2\Uninstall.exe"
PictureProject --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}\Setup.exe" -l0x9 UNINSTALL
Popup Blocker (Windows Live Toolbar) --> MsiExec.exe /X{66A7A386-6F35-41A7-A731-101F0C0153C8}
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
Ricochet --> "G:\Games\Steam\steam.exe" steam://uninstall/60
SimCity 3000 --> C:\WINDOWS\IsUninst.exe -f"g:\games\Maxis\SimCity 3000\Uninst.isu"
Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
SpywareBlaster 4.0 --> "G:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "G:\Program Files\SpywareGuard\unins000.exe"
Starcraft --> C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
Station Adapter Utility --> RunDll32 C:\PROGRA~1\COMM