Hiyas folks!
Got a Dell Dimension 5100 w/XP I'm working on for a friend.
Startup is E X T R E ME L Y slow! Sometimes as long as 10 minutes. Yeah....The Windows balloon warning of spyware detected continually pops up. Once logged online, popups for various anti spyware programs keep coming in and if you try to close them, the program tries to d/l or just run. I don't know if they're legit or not so I kill 'em.
A restore was tried before I got here and the speed did improve, but obviously dropped dramatically again. I'm sure the bugs all got back in after that was done, but I tried one here myself today to no avail. I know Chiaz... I know better. LoL
Anyway, I'm sure you folks will find something and I'll check back as I can. The 2 logs that the dss generated are attached.
Thanks!
Deckard's System Scanner v20071014.68
Run by jim on 2008-06-18 20:26:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-06-19 03:26:43 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-06-18 21:05:07
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\DOCUME~1\jim\LOCALS~1\Temp\tmp1F.tmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\jim\LOCALS~1\Temp\tmp3F4.tmp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ISM\ISMModule3.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\jim\Desktop\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
Live Search:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O1 - Hosts: 91.184.6.104 pagead2.googlesyndication.com
O2 - BHO: (no name) - {1369F51F-F034-444E-BE7F-24BF93D8C767} - C:\WINDOWS\system32\geedd.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\geecyaw.dll
O2 - BHO: {7ae20446-fc22-a13a-d874-55addeb891c7} - {7c198bed-da55-478d-a31a-22cf64402ea7} - C:\WINDOWS\system32\ndyduacr.dll
O2 - BHO: (no name) - {BDE73FB4-A560-42AD-BE39-7842EB3151A2} - C:\WINDOWS\system32\esen.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\jim\cftmon.exe
O4 - HKLM\..\Run: [100be611] rundll32.exe "C:\WINDOWS\system32\bycpydbl.dll",b
O4 - HKLM\..\Run: [BM1338d58d] Rundll32.exe "C:\WINDOWS\system32\pjsuidht.dll",s
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [a7f6ac04.exe] C:\Documents and Settings\jim\Local Settings\Application Data\a7f6ac04.exe
O4 - HKCU\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [SysRestore] "C:\DOCUME~1\jim\LOCALS~1\Temp\tmp3F4.tmp.exe"
O4 - HKCU\..\Run: [A00FC3F2C7.exe] C:\DOCUME~1\jim\LOCALS~1\Temp\_A00FC3F2C7.exe
O4 - HKCU\..\Run: [A00FC3FF1C.exe] C:\DOCUME~1\jim\LOCALS~1\Temp\_A00FC3FF1C.exe
O4 - HKCU\..\Run: [A00FC3FF2B.exe] C:\DOCUME~1\jim\LOCALS~1\Temp\_A00FC3FF2B.exe
O4 - HKCU\..\Run: [A00FC3FF4B.exe] C:\DOCUME~1\jim\LOCALS~1\Temp\_A00FC3FF4B.exe
O4 - HKCU\..\Run: [A00F135E0.exe] C:\DOCUME~1\jim\LOCALS~1\Temp\_A00F135E0.exe
O4 - HKCU\..\Run: [ISMModule3] "C:\Program Files\ISM\ISMModule3.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\jim\cftmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'Default user')
O4 - Startup: .protected
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: .protected
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: ExifLauncher2.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
https://online.musicmatch.com (HKLM)
O15 - Trusted Zone:
https://turbotax.com (HKCU)
O16 - DPF: {177C4272-D66F-5FAE-6A07-48DC2C31A372} () -
http://85.255.115.229/1/gdnUS1402.exe
O16 - DPF: {62A8899F-D280-0295-10CD-4EFD0BC6AB55} () -
http://85.255.115.229/1/gdnUS1402.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: geecyaw - C:\WINDOWS\system32\geecyaw.dll
O20 - Winlogon Notify: __c00476CE - C:\WINDOWS\system32\__c00476CE.dat
O20 - Winlogon Notify: __c00B5062 - C:\WINDOWS\system32\__c00B5062.dat
O20 - Winlogon Notify: __c00B7859 - C:\WINDOWS\system32\__c00B7859.dat
O20 - Winlogon Notify: __c00E4AFC - C:\WINDOWS\system32\__c00E4AFC.dat
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPWDSVC.EXE
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
O23 - Service: DomainService - Unknown owner - C:\DOCUME~1\jim\LOCALS~1\Temp\tmp1F.tmp.exe /service
O23 - Service: ISSVC - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ieupdater22 (Microsoft IEUpdater22) - Unknown owner - C:\Documents and Settings\jim\ie_updater.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVSCAN.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBSERV.EXE
O23 - Service: Schedule - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe
--
End of file - 9582 bytes
-- File Associations -----------------------------------------------------------
.exe - exefile - shell\open\command - C:\WINDOWS\system32\drivers\spools.exe "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 Achernar (Achernar - SCSI Command Filters) - c:\windows\system32\drivers\achernar.sys <Not Verified; An Chen Computer Co., Ltd.; Achernar>
R0 xlbnvnvh - c:\windows\system32\drivers\gwsekhmr.dat
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R3 Aldebaran (Aldebaran - SCSI Command Filters) - c:\windows\system32\drivers\aldebaran.sys <Not Verified; An Chen Computer Co., Ltd.; Aldebaran>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 bgsvcgen (B's Recorder GOLD Library General Service) - c:\windows\system32\bgsvcgen.exe <Not Verified; B.H.A Corporation; B's Recorder GOLD8>
R2 DomainService - c:\docume~1\jim\locals~1\temp\tmp1f.tmp.exe /service (file missing)
S2 Microsoft IEUpdater22 (ieupdater22) - c:\documents and settings\jim\ie_updater.exe /start
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-04-27 09:00:00 350 --a------ C:\WINDOWS\Tasks\At58.job
2008-04-27 09:00:00 350 --a------ C:\WINDOWS\Tasks\At34.job
2008-04-27 09:00:00 350 --a------ C:\WINDOWS\Tasks\At10.job
2008-04-27 08:00:00 350 --a------ C:\WINDOWS\Tasks\At9.job
2008-04-27 08:00:00 350 --a------ C:\WINDOWS\Tasks\At57.job
2008-04-27 08:00:00 350 --a------ C:\WINDOWS\Tasks\At33.job
2008-04-27 07:00:00 350 --a------ C:\WINDOWS\Tasks\At8.job
2008-04-27 07:00:00 350 --a------ C:\WINDOWS\Tasks\At56.job
2008-04-27 07:00:00 350 --a------ C:\WINDOWS\Tasks\At32.job
2008-04-27 06:08:00 360 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-04-27 06:00:00 350 --a------ C:\WINDOWS\Tasks\At7.job
2008-04-27 06:00:00 350 --a------ C:\WINDOWS\Tasks\At55.job
2008-04-27 06:00:00 350 --a------ C:\WINDOWS\Tasks\At31.job
2008-04-27 05:00:00 350 --a------ C:\WINDOWS\Tasks\At6.job
2008-04-27 05:00:00 350 --a------ C:\WINDOWS\Tasks\At54.job
2008-04-27 05:00:00 350 --a------ C:\WINDOWS\Tasks\At30.job
2008-04-27 04:00:00 350 --a------ C:\WINDOWS\Tasks\At53.job
2008-04-27 04:00:00 350 --a------ C:\WINDOWS\Tasks\At5.job
2008-04-27 04:00:00 350 --a------ C:\WINDOWS\Tasks\At29.job
2008-04-27 03:00:00 350 --a------ C:\WINDOWS\Tasks\At52.job
2008-04-27 03:00:00 350 --a------ C:\WINDOWS\Tasks\At4.job
2008-04-27 03:00:00 350 --a------ C:\WINDOWS\Tasks\At28.job
2008-04-27 02:00:00 350 --a------ C:\WINDOWS\Tasks\At51.job
2008-04-27 02:00:00 350 --a------ C:\WINDOWS\Tasks\At3.job
2008-04-27 02:00:00 350 --a------ C:\WINDOWS\Tasks\At27.job
2008-04-27 01:00:00 350 --a------ C:\WINDOWS\Tasks\At50.job
2008-04-27 01:00:00 350 --a------ C:\WINDOWS\Tasks\At26.job
2008-04-27 01:00:00 350 --a------ C:\WINDOWS\Tasks\At2.job
2008-04-27 00:00:00 350 --a------ C:\WINDOWS\Tasks\At49.job
2008-04-27 00:00:00 350 --a------ C:\WINDOWS\Tasks\At25.job
2008-04-27 00:00:00 350 --a------ C:\WINDOWS\Tasks\At1.job
2008-04-26 23:00:00 350 --a------ C:\WINDOWS\Tasks\At72.job
2008-04-26 23:00:00 350 --a------ C:\WINDOWS\Tasks\At48.job
2008-04-26 23:00:00 350 --a------ C:\WINDOWS\Tasks\At24.job
2008-04-26 22:00:00 350 --a------ C:\WINDOWS\Tasks\At71.job
2008-04-26 22:00:00 350 --a------ C:\WINDOWS\Tasks\At47.job
2008-04-26 22:00:00 350 --a------ C:\WINDOWS\Tasks\At23.job
2008-04-26 21:00:00 350 --a------ C:\WINDOWS\Tasks\At70.job
2008-04-26 21:00:00 350 --a------ C:\WINDOWS\Tasks\At46.job
2008-04-26 21:00:00 350 --a------ C:\WINDOWS\Tasks\At22.job
2008-04-26 20:00:00 350 --a------ C:\WINDOWS\Tasks\At69.job
2008-04-26 20:00:00 350 --a------ C:\WINDOWS\Tasks\At45.job
2008-04-26 20:00:00 350 --a------ C:\WINDOWS\Tasks\At21.job
2008-04-26 19:00:00 350 --a------ C:\WINDOWS\Tasks\At68.job
2008-04-26 19:00:00 350 --a------ C:\WINDOWS\Tasks\At44.job
2008-04-26 19:00:00 350 --a------ C:\WINDOWS\Tasks\At20.job
2008-04-26 18:00:00 350 --a------ C:\WINDOWS\Tasks\At67.job
2008-04-26 18:00:00 350 --a------ C:\WINDOWS\Tasks\At43.job
2008-04-26 18:00:00 350 --a------ C:\WINDOWS\Tasks\At19.job
2008-04-26 17:00:00 350 --a------ C:\WINDOWS\Tasks\At66.job
2008-04-26 17:00:00 350 --a------ C:\WINDOWS\Tasks\At42.job
2008-04-26 17:00:00 350 --a------ C:\WINDOWS\Tasks\At18.job
2008-04-26 16:00:00 350 --a------ C:\WINDOWS\Tasks\At65.job
2008-04-26 16:00:00 350 --a------ C:\WINDOWS\Tasks\At41.job
2008-04-26 16:00:00 350 --a------ C:\WINDOWS\Tasks\At17.job
2008-04-26 15:00:00 350 --a------ C:\WINDOWS\Tasks\At64.job
2008-04-26 15:00:00 350 --a------ C:\WINDOWS\Tasks\At40.job
2008-04-26 15:00:00 350 --a------ C:\WINDOWS\Tasks\At16.job
2008-04-26 14:00:00 350 --a------ C:\WINDOWS\Tasks\At63.job
2008-04-26 14:00:00 350 --a------ C:\WINDOWS\Tasks\At39.job
2008-04-26 14:00:00 350 --a------ C:\WINDOWS\Tasks\At15.job
2008-04-26 13:00:00 350 --a------ C:\WINDOWS\Tasks\At62.job
2008-04-26 13:00:00 350 --a------ C:\WINDOWS\Tasks\At38.job
2008-04-26 13:00:00 350 --a------ C:\WINDOWS\Tasks\At14.job
2008-04-26 12:00:00 350 --a------ C:\WINDOWS\Tasks\At61.job
2008-04-26 12:00:00 350 --a------ C:\WINDOWS\Tasks\At37.job
2008-04-26 12:00:00 350 --a------ C:\WINDOWS\Tasks\At13.job
2008-04-20 11:01:00 350 --a------ C:\WINDOWS\Tasks\At60.job
2008-04-20 11:00:00 350 --a------ C:\WINDOWS\Tasks\At36.job
2008-04-20 11:00:00 350 --a------ C:\WINDOWS\Tasks\At12.job
2008-04-20 10:03:00 350 --a------ C:\WINDOWS\Tasks\At59.job
2008-04-20 10:00:00 350 --a------ C:\WINDOWS\Tasks\At35.job
2008-04-20 10:00:00 350 --a------ C:\WINDOWS\Tasks\At11.job
2008-03-28 20:00:00 544 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - jim.job
2008-03-10 20:30:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-18 and 2008-06-18 -----------------------------
2008-06-18 19:51:57 102464 --a------ C:\WINDOWS\system32\pjsuidht.dll
2008-06-18 19:07:21 94272 --a------ C:\WINDOWS\system32\bycpydbl.dll
2008-06-18 18:43:31 0 d-------- C:\Program Files\AOLDMX
2008-06-18 18:43:29 0 d-------- C:\Program Files\EarthLink Setup
2008-06-18 18:43:20 0 d-------- C:\Program Files\MyWaySA
2008-05-27 10:18:24 2961408 --a------ C:\Documents and Settings\jim\ntuser.dat
2008-05-27 10:15:52 9728 --a------ C:\Documents and Settings\jim\cftmon.exe
2008-05-27 10:15:51 5120 --a------ C:\Documents and Settings\jim\ftp34.dll
2008-05-27 09:34:51 5120 --a------ C:\Documents and Settings\LocalService\ftp34.dll
2008-05-26 16:50:46 5120 --a------ C:\Documents and Settings\donna\ftp34.dll
2008-05-26 12:35:54 94272 --a------ C:\WINDOWS\system32\wiayhbfb.dll
2008-05-26 12:32:58 2624 --a------ C:\WINDOWS\system32\oplbavgm.exe
2008-05-26 12:32:44 5120 --a------ C:\WINDOWS\system32\ftp34.dll
2008-05-23 20:16:26 104512 --a------ C:\WINDOWS\system32\ndyduacr.dll
2008-05-23 20:11:05 2624 --a------ C:\WINDOWS\system32\dyqrpidf.exe
2008-05-23 20:10:40 103488 --a------ C:\WINDOWS\system32\cdkfnhvc.dll
2008-05-23 20:07:14 28160 --a------ C:\Documents and Settings\donna\cftmon.exe
2008-05-23 20:06:52 9728 --a------ C:\Documents and Settings\LocalService\cftmon.exe
-- Find3M Report ---------------------------------------------------------------
2008-06-18 21:02:55 701407 --ahs---- C:\WINDOWS\system32\ddeeg.ini2
2008-06-18 19:05:40 35840 --a------ C:\WINDOWS\system32\__c00476CE.dat
2008-06-18 18:43:24 0 d-------- C:\Program Files\MSN Messenger
2008-06-18 18:22:32 0 d-------- C:\Program Files\Ultimate Cleaner
2008-06-17 07:29:00 0 d-------- C:\Program Files\FinePixViewer
2008-06-16 21:37:22 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-16 10:22:04 35840 --a------ C:\WINDOWS\system32\__c00B5062.dat
2008-06-12 10:14:59 1585 --a------ C:\xcrashdump.dat
2008-05-26 16:53:26 1682 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-05-26 16:53:26 56 -r-hs---- C:\WINDOWS\system32\A48530F679.sys
2008-05-08 19:22:06 99904 --a------ C:\WINDOWS\system32\nxicjmwp.dll
2008-04-26 11:18:32 37636 --a------ C:\WINDOWS\system32\__c00EA35A.exe
2008-04-25 13:29:57 107072 --a------ C:\WINDOWS\system32\apajnobt.dll
2008-04-25 13:29:31 105536 --a------ C:\WINDOWS\system32\xryevjvx.dll
2008-04-20 11:18:21 88128 --a------ C:\WINDOWS\system32\xsxprbpe.dll
2008-04-20 11:15:06 94272 --a------ C:\WINDOWS\system32\jqmjqmqy.dll
2008-04-20 11:12:35 96320 --a------ C:\WINDOWS\system32\uxghyiax.dll
2008-04-20 10:12:51 94272 --a------ C:\WINDOWS\system32\qqgxupow.dll
2008-04-20 10:10:25 95296 --a------ C:\WINDOWS\system32\habpyllw.dll
2008-04-19 09:32:33 92736 --a------ C:\WINDOWS\system32\ynyupdfs.dll
2008-04-19 09:32:10 95296 --a------ C:\WINDOWS\system32\ynhkbjln.dll
2008-04-19 08:45:15 34816 --a------ C:\WINDOWS\xpupdate.exe
2008-04-19 08:45:14 37636 --a------ C:\WINDOWS\system32\__c0034657.exe
2008-04-19 08:33:19 92736 --a------ C:\WINDOWS\system32\kmpturrt.dll
2008-04-19 08:30:18 88640 --a------ C:\WINDOWS\system32\invlwcov.dll
2008-04-19 08:27:38 87104 --a------ C:\WINDOWS\system32\odyiguob.dll
2008-04-04 11:10:24 83520 --a------ C:\WINDOWS\system32\gurvkhcg.dll
2008-04-04 11:07:36 90176 --a------ C:\WINDOWS\system32\efktfasu.dll
2008-04-04 11:04:24 87104 --a------ C:\WINDOWS\system32\hhbcojnx.dll
2008-04-03 10:05:00 89152 --a------ C:\WINDOWS\system32\pgpwvraf.dll
2008-04-03 10:01:54 88640 --a------ C:\WINDOWS\system32\ebfvxkwi.dll
2008-03-30 18:56:16 92224 --a------ C:\WINDOWS\system32\lnhtcvqt.dll
2008-03-30 18:54:33 276338 --ahs---- C:\WINDOWS\system32\jjjlm.ini2
2008-03-30 09:59:40 90176 --a------ C:\WINDOWS\system32\ytcfuiqh.dll
2008-03-30 07:56:06 324672 --a------ C:\WINDOWS\system32\mljjj.dll
2008-03-29 23:28:50 92224 --a------ C:\WINDOWS\system32\tdpjhsgi.dll
2008-03-29 23:25:17 92224 --a------ C:\WINDOWS\system32\nvxkrdgn.dll
2008-03-29 20:16:50 92224 --a------ C:\WINDOWS\system32\bxyyyeqx.dll
2008-03-29 20:13:50 92224 --a------ C:\WINDOWS\system32\somhngbs.dll
2008-03-29 18:13:50 93248 --a------ C:\WINDOWS\system32\kpouxxvd.dll
2008-03-29 18:11:53 92224 --a------ C:\WINDOWS\system32\kfewosvt.dll
2008-03-29 08:46:56 2560 --a------ C:\WINDOWS\system32\__c0082C3E.dat
2008-03-22 19:39:40 93248 --a------ C:\WINDOWS\system32\cejatnjj.dll
2008-03-22 19:39:15 92224 --a------ C:\WINDOWS\system32\xvimmbyp.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1369F51F-F034-444E-BE7F-24BF93D8C767}]
03/10/2008 09:45 PM 324672 --a------ C:\WINDOWS\system32\geedd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
03/02/2008 10:39 AM 365591 --a------ C:\WINDOWS\system32\geecyaw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7c198bed-da55-478d-a31a-22cf64402ea7}]
05/23/2008 08:16 PM 104512 --a------ C:\WINDOWS\system32\ndyduacr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDE73FB4-A560-42AD-BE39-7842EB3151A2}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ntuser"="C:\WINDOWS\system32\drivers\spools.e xe" [05/26/2008 12:32 PM]
"autoload"="C:\Documents and Settings\jim\cftmon.exe" [05/08/2008 07:21 PM]
"100be611"="C:\WINDOWS\system32\bycpydbl.dll" [06/18/2008 07:07 PM]
"BM1338d58d"="C:\WINDOWS\system32\pjsuidht.dll " [06/18/2008 07:52 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"a7f6ac04.exe"="C:\Documents and Settings\jim\Local Settings\Application Data\a7f6ac04.exe" [05/30/2006 04:34 PM]
"Ultimate Defender"="C:\Program Files\Ultimate Defender\App.exe" []
"SysRestore"="C:\DOCUME~1\jim\LOCALS~1\Temp\tmp3F4 .tmp.exe" []
"A00FC3F2C7.exe"="C:\DOCUME~1\jim\LOCALS~1\Temp\_A 00FC3F2C7.exe" []
"A00FC3FF1C.exe"="C:\DOCUME~1\jim\LOCALS~1\Temp\_A 00FC3FF1C.exe" []
"A00FC3FF2B.exe"="C:\DOCUME~1\jim\LOCALS~1\Temp\_A 00FC3FF2B.exe" []
"A00FC3FF4B.exe"="C:\DOCUME~1\jim\LOCALS~1\Temp\_A 00FC3FF4B.exe" []
"A00F135E0.exe"="C:\DOCUME~1\jim\LOCALS~1\Temp\_A0 0F135E0.exe" []
"ISMModule3"="C:\Program Files\ISM\ISMModule3.exe" [08/28/2007 10:08 AM]
"Windows update loader"="C:\Windows\xpupdate.exe" [04/19/2008 08:45 AM]
"ntuser"="C:\WINDOWS\system32\drivers\spools.e xe" [05/26/2008 12:32 PM]
"autoload"="C:\Documents and Settings\jim\cftmon.exe" [05/08/2008 07:21 PM]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
"ntuser"=C:\WINDOWS\system32\drivers\spools.ex e
"autoload"=C:\Documents and Settings\LocalService\cftmon.exe
C:\Documents and Settings\jim\Start Menu\Programs\Startup\
.protected [9/2/2006 1:34:14 PM]
PowerReg Scheduler V3.exe [4/24/2007 5:06:07 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
.protected [9/2/2006 1:34:14 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [7/27/2005 4:11:56 PM]
ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [5/13/2007 9:38:43 AM]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [11/11/2004 9:59:36 AM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= C:\WINDOWS\system32\geecyaw.dll [03/02/2008 10:39 AM 365591]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geecyaw]
geecyaw.dll 03/02/2008 10:39 AM 365591 C:\WINDOWS\system32\geecyaw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00476CE]
C:\WINDOWS\system32\__c00476CE.dat 06/18/2008 07:05 PM 35840 C:\WINDOWS\system32\__c00476CE.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00B5062]
C:\WINDOWS\system32\__c00B5062.dat 06/16/2008 10:22 AM 35840 C:\WINDOWS\system32\__c00B5062.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00B7859]
C:\WINDOWS\system32\__c00B7859.dat 05/27/2007 08:44 PM 35840 C:\WINDOWS\system32\__c00B7859.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c00E4AFC]
C:\WINDOWS\system32\__c00E4AFC.dat 08/16/1980 05:00 PM 35840 C:\WINDOWS\system32\__c00E4AFC.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geedd.dll
-- Hosts -----------------------------------------------------------------------
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
91.184.6.104 pagead2.googlesyndication.com
4 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-18 21:06:24 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) 4
CPU 3.00GHz
CPU 1: Intel(R) Pentium(R) 4
CPU 3.00GHz
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 510.07 MiB / 123.07 MiB
Pagefile Memory (total/avail): 1245.36 MiB / 940.87 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1908.34 MiB
C: is Fixed (NTFS) - 70.97 GiB total, 46.94 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD800JD-75JNC0 - 74.5 GiB - 3 partitions
\PARTITION0 - Unknown - 54.88 MiB
\PARTITION1 (bootable) - Installable File System - 70.97 GiB - C:
\PARTITION2 - Unknown - 3.47 GiB
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before download.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
FW: Norton Internet Security v2005 (Symantec Corporation)
AV: Norton Internet Security v2005 (Symantec Corporation)
Outdated
[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\DomainProfile\Authoriz edApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\TurboTax\\Premier 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Premier 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax "
"C:\\Program Files\\TurboTax\\Premier 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Premier 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:Tur boTax Update Manager"
"C:\\DOCUME~1\\jim\\LOCALS~1\\Temp\\tmp1F.tmp.exe" ="C:\\DOCUME~1\\jim\\LOCALS~1\\Temp"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\ system32\\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"C:\\WINDOWS\\Temp\\NT44932.exe"="C:\\WINDOWS\\Tem p\\NT44932.exe:*:Enabled:NT44932"
"C:\\WINDOWS\\system32\\drivers\\spools.exe"="C:\\ WINDOWS\\system32\\drivers\\spools.exe:*

isabled: spools"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\jim\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=D7MRK081
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\jim
LOGONSERVER=\\D7MRK081
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\Sys tem32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\ATI Technologies\ATI Control Panel
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WS F;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\jim\LOCALS~1\Temp
TMP=C:\DOCUME~1\jim\LOCALS~1\Temp
USERDOMAIN=D7MRK081
USERNAME=jim
USERPROFILE=C:\Documents and Settings\jim
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
jim
(admin)
donna
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\system32\UninstIPP.isu
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
--> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
--> MsiExec.exe /I{F543B12A-13F5-487E-9314-F7D25E1BBE3E}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3BB529C7-855D-11D7-8444-0050BA1D384D}\setup.exe" -l0x9
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 5.0 Sprint --> MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
Adobe Acrobat - Reader 6.0.2 Update --> MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
AOL Services Setup --> C:\PROGRA~1\AOLDMX\UNWISE.EXE C:\PROGRA~1\AOLDMX\INSTALL.LOG
AOLIcon --> MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallI NFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class

ISPLAY -clean
CC_ccProxyExt --> MsiExec.exe /I{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919}
ccCommon --> MsiExec.exe /I{D8F6834B-D5E7-4451-8681-B051ABD8561D}
ccPxyCore --> MsiExec.exe /I{FC08587A-4F01-4188-819F-F55880022917}
Command & Conquer The First Decade --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\ 00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{66D6F3BD-CA23-41A4-9FA3-96B26B32528C}\setup.exe" -l0x9 -removeonly
Conexant D850 56K V.9x DFVc Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SU BSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
DeductionPro 2005-06 --> C:\PROGRA~1\DEDUCT~1\UNWISE.EXE C:\PROGRA~1\DEDUCT~1\INSTALL.LOG
Deer Avenger 4 --> C:\DEERAV~1\UNWISE.EXE /U C:\DEERAV~1\INSTALL.LOG
Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Media Experience --> MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
Dell Picture Studio v3.0 --> MsiExec.exe /I{AF06CAE4-C134-44B1-B699-14FBDB63BD37}
Dell Support 3.1 --> MsiExec.exe /X{548EEA8E-8299-497F-8057-811D2D7097DC}
Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
DVC305 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1A3ADB5A-2491-4F7A-BD6D-5F8C9B4714B0}\Setup.exe"
EarthLink setup files --> MsiExec.exe /X{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}
FaxTools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F45298E5-0083-426F-A668-1A2C5F04B8A0}\setup.exe" -l0x9 ControlPanel
FinePix Studio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E3B3AB03-8ABC-46CF-8CA9-DB5581E1F368}\SETUP.EXE" -l0x9
FinePixViewer Resource --> C:\Program Files\InstallShield Installation Information\{B44529FF-501E-47CD-A06D-223C161BE058}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
FinePixViewer Ver.5.3 --> C:\Program Files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
FUJIFILM USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\SETUP.EXE"
GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
Get High Speed Internet! --> MsiExec.exe /I{7A3F0566-5E05-4919-9C98-456F6B5CF831}
GTAIII --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92B94569-6683-4617-8C54-EB27A1B51B30}\Setup.exe" -l0x9
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuni nst.exe
Hoyle Solitaire and Mahjong --> C:\WINDOWS\IsUninst.exe -fC:\SIERRA\SOLMAH00\Uninst.isu
ImageMixer VCD2 LE for FinePix --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\070 1\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B093990A-AAF2-44AC-9216-14BB7A2189B6}\SETUP.EXE" -l0x9
Intel(R) Integrated Performance Primitives RTI 4.0 --> MsiExec.exe /X{51C91B84-7B46-4FE7-8999-8228CFA75F89}
Intel(R) PRO Network Connections Software v9.2.4.11 --> C:\Program Files\Intel\DMIX\uninst\DxSetup.exe /x /qr /le C:\DOCUME~1\Owner\LOCALS~1\Temp\PROSetDX\DMIX\\DxU ninst.log
Intel(R) PROSafe for Wired Connections --> MsiExec.exe /I{36BD0774-6CD6-4FF9-A148-83CA09AC123E}
Intel(R) PROSafe for Wired Connections --> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
Internet Explorer Default Page --> MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
Internet Speed Monitor --> C:\Program Files\ISM\Uninstall.exe
Jasc Paint Shop Photo Album 5 --> MsiExec.exe /I{4192EAC0-6B36-4723-B216-D0E86E7757AC}
Jasc Paint Shop Pro Studio, Dell Editon --> MsiExec.exe /I{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}
Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Joint Operations: Typhoon Rising --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\ 01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\setup.exe" -l0x9
Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
Lexmark X1100 Series --> C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBKUN5 C.EXE -dLexmark X1100 Series
LimeWire 4.10.5 --> "C:\Program Files\LimeWire\uninstall.exe"
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
LiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Macromedia Flash Player --> MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
Marine Sharpshooter --> C:\PROGRA~1\GROOVE~1\MARINE~1\UNWISE.EXE C:\PROGRA~1\GROOVE~1\MARINE~1\INSTALL.LOG
Mavis Beacon Teaches Typing 8.0.1 --> C:\PROGRA~1\MINDSC~1\MAVISB~1\UNINST.EXE
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spu ninst.exe"
Microsoft Halo --> "C:\Program Files\Microsoft Games\Halo\UNINSTAL.EXE" /runtemp /addremove
Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spunin st.exe"
Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSN Messenger 7.5 --> MsiExec.exe /I{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}
MSN Toolbar --> C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbs.exe c
MSRedist --> MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
MSXML 6.0 Parser (KB927977) --> MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\ 01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
My Way Search Assistant --> rundll32 C:\PROGRA~1\MyWaySA\SrchAsDe\1.bin\desrcas.dll,O
NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
NetZeroInstallers --> MsiExec.exe /X{352310C3-E46B-42D3-8F32-54721FDD72D9}
Norton AntiSpam --> MsiExec.exe /I{3B29A786-5803-4e9e-9B58-3014A5B4E519}
Norton AntiSpam --> MsiExec.exe /I{5677563D-0CB1-485f-9E18-C5025306BB3F}
Norton AntiVirus 2005 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
Norton Internet Security --> MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
Norton Internet Security --> MsiExec.exe /I{449F3A9E-9903-4a0d-A209-08030D45A935}
Norton Internet Security --> MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
Norton Internet Security --> MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
Norton Internet Security --> MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
Norton Internet Security --> MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}
Norton Internet Security --> MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Internet Security --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Norton Internet Security --> MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
Norton Internet Security 2005 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe /X
Norton Security Center --> MsiExec.exe /X{503AA035-41E2-4858-B31F-1E49AC66C309}
Norton WMI Update --> MsiExec.exe /X{E85FA9A1-C241-4698-893B-DD99509B8DB0}
Norton WMI Update --> MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
Outerinfo --> "C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe"
Photo Click --> MsiExec.exe /I{6E179C77-7335-458D-9537-4F4EAC0181ED}
PowerDVD 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
Presto! VideoWorks 6 (VCD Version) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B0C0F5E6-10B1-11D6-9296-0050BA073EEC}\SETUP.EXE" -l0x9
Pro Bass Fishing 2003 --> C:\Program Files\Infogrames\Pro Bass Fishing 2003\Setup.exe /Uninstall
PunkBuster for Joint Operations: Typhoon Rising --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\ 01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFE6E3B6-8CA9-4837-B292-5F11A80339A9}\setup.exe" -l0x9
QuickBooks Simple Start Special Edition --> msiexec.exe /I {F543B12A-13F5-487E-9314-F7D25E1BBE3E} UNIQUE_NAME="atomlimited" QBFULLNAME="QuickBooks Simple Start Special Edition" ADDREMOVE=1
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spunins t.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spunins t.exe"
Sonic DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
Sonic RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
SPBBC --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Symantec Script Blocking Installer --> MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
TaxCut Deluxe 2005 --> C:\PROGRA~1\TaxCut05\Program\removetc.exe
Trophy Hunter 2003 - Rocky Mountain Adventures --> "C:\Program Files\Infogrames\Trophy Hunter 2003\unins000.exe"
TurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}
TurboTax ItsDeductible 2006 --> MsiExec.exe /X{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}
TurboTax Premier Investments 2006 --> C:\Program Files\TurboTax\Premier 2006\TaxUnst.EXE "C:\Program Files\TurboTax\Premier 2006\Uninstall.log" -NoGui
Ultimate Defender --> C:\Program Files\Ultimate Defender\Uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\070 1\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
Windows Driver Package - Microsoft WPD (8/28/2006 1.0.0.2) --> rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E 0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\Zune_9C3D37D5063B767B 2FEA1899B50894F1AC95FAA6\Zune.inf
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spunin st.exe"
WordPerfect Office 12 --> MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}
Zune --> MsiExec.exe /X{ED55BFEF-90F3-4926-9536-D94FDBBF65DC}
-- Application Event Log -------------------------------------------------------
Event Record #/Type9465 / Error
Event Submitted/Written: 06/18/2008 08:08:14 PM / 06/18/2008 08:08:15 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [!ws!]
Event Record #/Type9452 / Error
Event Submitted/Written: 06/18/2008 07:50:22 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type9438 / Error
Event Submitted/Written: 06/18/2008 06:53:27 PM
Event ID/Source: 4609 / EventSystem
Event Description:
The COM+ Event System detected a bad return code during its internal processing. HRESULT was 800706BF from line 44 of d:\qxp_slp\com\com1x\src\events\tier1\eventsystemo bj.cpp. Please contact Microsoft Product Support Services to report this error.
Event Record #/Type9435 / Error
Event Submitted/Written: 06/18/2008 06:46:28 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
Processing media-specific event for [!ws!]
Event Record #/Type9423 / Error
Event Submitted/Written: 06/18/2008 05:56:07 PM
Event ID/Source: 1004 / Application Error
Event Description:
Faulting application ie_updater.exe, version 0.0.0.0, faulting module ie_updater.exe, version 0.0.0.0, fault address 0x00005938.
Error in creating result PEAP-TLV in response to received PEAP-TLV (ie_updater.exe!ld!)
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type37937 / Error
Event Submitted/Written: 06/18/2008 08:39:26 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The Symantec Network Proxy service terminated unexpectedly. It has done this 1 time(s).
Event Record #/Type37935 / Error
Event Submitted/Written: 06/18/2008 08:39:17 PM / 06/18/2008 08:39:18 PM
Event ID/Source: 7031 / Service Control Manager
Event Description:
The Zune Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Event Record #/Type37934 / Error
Event Submitted/Written: 06/18/2008 08:39:12 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The SymWMI Service service terminated unexpectedly. It has done this 1 time(s).
Event Record #/Type37929 / Error
Event Submitted/Written: 06/18/2008 08:11:20 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The ieupdater22 service terminated unexpectedly. It has done this 1 time(s).
Event Record #/Type37909 / Error
Event Submitted/Written: 06/18/2008 08:08:43 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The FashionCam Video Camera Device service failed to start due to the following error:
%%1058
-- End of Deckard's System Scanner: finished at 2008-06-18 21:06:24 ----------