I am operating a government computer on a "push" security network. All updates are handled centrally. I have also locally loaded a few authorized programs provided by my civilian education institution.
Before the system crashes, I receive an error message that includes the statement that memory cannot be "read." Then, I can close all my open windows (and save my work, thank God), but as soon as I take any action with the error message (select "OK", "cancel", or "close (X) in upper right corner of window"), the system crashes to a "blue screen of death." At that point, I must hold the power button for 5 seconds to do a "hard shutdown", then power back up.
During my rooting around, I noticed that I appear to have spyware (MSSoap) in my Common Files folder, although I don't see it in either the
HJT or DSS log files below:
Deckard's System Scanner v20071014.68
Run by army.doogie on 2008-06-19 12:20:37
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-06-19 19:20:43 UTC - RP720 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as army.doogie.exe) --------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:27 PM, on 6/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ActivIdentity\ActivClient\acachsrv.exe
C:\Program Files\ActivIdentity\ActivClient\acautoup.exe
C:\Program Files\ActivIdentity\ActivClient\accoca.exe
C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\system32\srvany.exe
C:\pvsw\bin\w3dbsmgr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CA\Unicenter Asset Management\Agents\SWMSvc.exe
C:\PROGRAM FILES\CA\UNICENTER ASSET MANAGEMENT\AGENTS\SWMW32.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\CA\Unicenter Software Delivery\BIN\TRIGGAG.EXE
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.ex e
C:\Program Files\CA\Unicenter DSM\Bin\caf.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\CA\Unicenter DSM\Bin\cfsmsmd.exe
C:\Program Files\CA\Unicenter DSM\Bin\ccnfagent.exe
C:\Program Files\CA\Unicenter DSM\Bin\cfnotsrvd.exe
C:\Program Files\CA\Unicenter DSM\Bin\ccsmagtd.exe
C:\Program Files\CA\Unicenter DSM\Bin\rcHost.exe
C:\Program Files\CA\Unicenter DSM\PMAgent\capmuamagt.exe
C:\Program Files\CA\Unicenter DSM\Bin\cfftplugin.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\WINDOWS\MouPter.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Documents and Settings\doogie.burkey\Desktop\dss.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\james.r.burkey.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
Live Search:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://jump.altavista.com/cpcg_kbd_bsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.compaq.com/netsolutions
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.compaq.com/netsolutions
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [mMouse] MouPter.exe
O4 - HKLM\..\Run: [SetMou] SetMou.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [SDJobCheck] triggusr.exe
O4 - HKLM\..\Run: [CA-AMAgent]
\\HUACFSMCE035203\amagents$\amagent.exe /SILENT
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.5\masqform.exe -RunOnce
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CAF_SystemTray] "C:\Program Files\CA\Unicenter DSM\Bin\cfSysTray.exe"
O4 - HKLM\..\Run: [DsmSxplog] "C:\Program Files\CA\Unicenter DSM\Bin\sxpstub.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AprvRemoveLegacyExcelKeys] "C:\Program Files\ApproveIt\Support\Tools\AprvClean.exe" -k HKCU SOFTWARE\Microsoft\Office\Excel\Addins\OfficeAddIn .OfficeAddIn
O4 - HKLM\..\Run: [AprvRemoveLegacyWordKeys] "C:\Program Files\ApproveIt\Support\Tools\AprvClean.exe" -k HKCU SOFTWARE\Microsoft\Office\Word\Addins\OfficeAddIn. OfficeAddIn
O4 - HKLM\..\Run: [ApproveItForOfficeSetup] C:\Program Files\ApproveIt\Support\Tools\ApproveItForOfficeSe tup.exe C:\Program Files\ApproveIt\
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.v bs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.v bs" (User 'Default user')
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: ApproveIt StartUp.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {2CA2C9B8-E4F6-4BE9-8601-52ED0AFBA79D} (Pearson Accounting Player) -
http://asp.mathxl.com/books/_Players...tingPlayer.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
http://asp.mathxl.com/wizmodules/tes...enXInstall.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsof...?1190225254150
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1190225232116
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) -
http://asp.mathxl.com/books/_Players...stallAsst2.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nasw.ds.army.mil
O17 - HKLM\Software\..\Telephony: DomainName = nasw.ds.army.mil
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D29AADE-DE80-4447-883F-61806CB9FCED}: NameServer = 150.180.9.30,150.180.9.27,155.214.134.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = nasw.ds.army.mil
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = nasw.ds.army.mil
O20 - Winlogon Notify: ackpbsc - C:\WINDOWS\system32\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O20 - Winlogon Notify: CAF - C:\Program Files\CA\Unicenter DSM\Bin\cfwlogon.dll
O20 - Winlogon Notify: rcHostExt - C:\Program Files\CA\Unicenter DSM\Bin\rcLoginExt.dll
O23 - Service: ActivClient Authentication Service (acachsrv) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acachsrv.exe
O23 - Service: ActivClient Auto-Update Service (acautoup) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acautoup.exe
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: CA Message Queuing Server (CA-MessageQueuing) - CA, Inc. - C:\Program Files\CA\SharedComponents\CAM\bin\cam.exe
O23 - Service: CA Unicenter DSM r11 Common Application Framework. (caf) - CA - C:\Program Files\CA\Unicenter DSM\Bin\caf.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pervasive.SQL Workgroup Engine - Unknown owner - C:\WINDOWS\system32\srvany.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Unicenter Software Delivery (SDService) - Computer Associates International, Inc. - C:\Program Files\CA\Unicenter Software Delivery\BIN\SDSERV.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Asset Management SW Meter Agent (SWMSVC) - Computer Associates International, Inc. - C:\Program Files\CA\Unicenter Asset Management\Agents\SWMSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 12402 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71
.inf - inffile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69
.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys (file missing)
S3 ProcObsrv (Process creation detector.) - c:\program files\questionmark\qs\procobsrv.sys
S3 Scr110 (SCR110 Serial Smart Card Reader) - c:\windows\system32\drivers\scr110.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 acachsrv (ActivClient Authentication Service) - "c:\program files\actividentity\activclient\acachsrv.exe" <Not Verified; ActivIdentity; ActivClient Services>
R2 acautoup (ActivClient Auto-Update Service) - "c:\program files\actividentity\activclient\acautoup.exe" <Not Verified; ActivIdentity; ActivClient Services>
R2 accoca (ActivClient Middleware Service) - "c:\program files\actividentity\activclient\accoca.exe" <Not Verified; ActivIdentity; ActivClient Services>
R2 CA-MessageQueuing (CA Message Queuing Server) - "c:\program files\ca\sharedcomponents\cam\bin\cam.exe" <Not Verified; CA, Inc.; CA Message Queuing>
R2 MaxBackServiceInt - "c:\program files\maxtor\maxtor backup\maxbackserviceint.exe" <Not Verified; ; MaxBackServiceInt Module>
R2 NTService1 (MaxSyncService) - "c:\program files\maxtor\onetouch\utils\syncservices.exe" <Not Verified; ; SyncServices>
R2 Pervasive.SQL Workgroup Engine - c:\windows\system32\srvany.exe
R2 SDService (Unicenter Software Delivery) - "c:\program files\ca\unicenter software delivery\bin\sdserv.exe" <Not Verified; Computer Associates International, Inc.; Unicenter Software Delivery>
R2 SWMSVC (Asset Management SW Meter Agent) - "c:\program files\ca\unicenter asset management\agents\swmsvc.exe" <Not Verified; Computer Associates International, Inc.; Unicenter Asset Management - Software Metering Agent as Service>
R2 Wuser32 (SMS Remote Control Agent) - c:\windows\system32\ccm\clicomp\remctrl\wuser32.ex e <Not Verified; Microsoft Corporation; Systems Management Server>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: PS/2 Compatible Mouse
Device ID: ACPI\PNP0F13\4&369939D9&0
Manufacturer: Microsoft
Name: PS/2 Compatible Mouse
PNP Device ID: ACPI\PNP0F13\4&369939D9&0
Service: i8042prt
Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Compaq Easy Access PS2 Internet Keyboard
Device ID: ACPI\PNP0303\4&369939D9&0
Manufacturer: Compaq Computer Corporation
Name: Compaq Easy Access PS2 Internet Keyboard
PNP Device ID: ACPI\PNP0303\4&369939D9&0
Service: i8042prt
Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318}
Description: Unicenter r11 Remote Control Secure Control Adapter
Device ID: ROOT\DISPLAY\0001
Manufacturer: Computer Associates Intl., Inc.
Name: Unicenter r11 Remote Control Secure Control Adapter
PNP Device ID: ROOT\DISPLAY\0001
Service: rcVidCap
-- Files created between 2008-05-19 and 2008-06-19 -----------------------------
2008-06-19 12:23:09 0 d-------- C:\Program Files\Trend Micro
2008-06-19 11:43:45 0 d-------- C:\Documents and Settings\doogie.burkey\.housecall6.6
2008-06-18 20:01:51 0 d-------- C:\WINDOWS\ms
2008-05-29 12:12:42 0 d-------- C:\Documents and Settings\doogie.burkey\Application Data\UnicenterRemoteControl
2008-05-28 01:06:05 714682 --a------ C:\s8g
-- Find3M Report ---------------------------------------------------------------
2008-06-18 21:28:58 0 d-------- C:\Program Files\Symantec AntiVirus
2008-06-18 21:19:43 0 d-------- C:\Program Files\Common Files
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [01/31/2003 05:49 PM]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [05/28/2002 03:37 AM]
"srmclean"="C:\Cpqs\Scom\srmclean.exe" [07/24/2001 02:34 PM]
"SetRefresh"="C:\Program Files\Compaq\SetRefresh\SetRefresh.exe" [08/07/2002 09:24 AM]
"mMouse"="MouPter.exe" [02/14/2003 12:02 PM C:\WINDOWS\MouPter.exe]
"SetMou"="SetMou.exe" [01/22/2003 12:26 PM C:\WINDOWS\SetMou.exe]
"CPQEASYACC"="C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe" [12/14/2001 03:01 PM]
"SDJobCheck"="triggusr.exe" [09/07/2004 08:17 AM C:\Program Files\CA\Unicenter Software Delivery\BIN\triggusr.exe]
"CA-AMAgent"="
\\HUACFSMCE035203\amagents$\amagent.exe" []
"masqform.exe"="C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" [07/04/2005 09:50 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"CAF_SystemTray"="C:\Program Files\CA\Unicenter DSM\Bin\cfSysTray.exe" [10/28/2007 03:45 AM]
"DsmSxplog"="C:\Program Files\CA\Unicenter DSM\Bin\sxpstub.exe" [10/28/2007 08:00 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [11/21/2006 05:38 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [03/14/2007 07:49 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/20/2005 09:35 AM]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 09:32 AM]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/20/2005 09:36 AM]
"@"="" []
"accrdsub"="C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe" [09/28/2006 06:27 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"AprvRemoveLegacyExcelKeys"="C:\Program Files\ApproveIt\Support\Tools\AprvClean.exe" [07/26/2006 05:43 PM]
"AprvRemoveLegacyWordKeys"="C:\Program Files\ApproveIt\Support\Tools\AprvClean.exe" [07/26/2006 05:43 PM]
"ApproveItForOfficeSetup"="C:\Program Files\ApproveIt\Support\Tools\ApproveItForOfficeSe tup.exe" [07/26/2006 05:43 PM]
"MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [03/27/2006 03:04 PM]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [10/17/2005 04:24 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/18/2008 09:35 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"TSClientMSIUninstaller"=cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.v bs"
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ActivClient Agent.lnk - C:\Program Files\ActivIdentity\ActivClient\acsagent.exe [9/28/2006 6:27:46 PM]
ApproveIt StartUp.lnk - C:\WINDOWS\Installer\{D96B3C48-13AE-41D8-895B-56A8B08DC1F3}\Icon9557F1BC1.ico [2/8/2008 11:41:14 AM]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2/5/2007 3:40:46 PM]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [12/6/2005 10:40:45 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"disablecad"=0 (0x0)
"scforceoption"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"LogonType"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoWelcomeScreen"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
"ForceStartMenuLogOff"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [02/05/2007 03:39 PM 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
C:\WINDOWS\system32\ackpbsc.dll 09/28/2006 06:28 PM 189952 C:\WINDOWS\system32\ackpbsc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
C:\Program Files\ActivIdentity\ActivClient\acunlock.dll 09/28/2006 06:28 PM 262144 C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\CAF]
C:\Program Files\CA\Unicenter DSM\Bin\cfwlogon.dll 10/28/2007 03:45 AM 27400 C:\Program Files\CA\Unicenter DSM\bin\cfWlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rcHostExt]
C:\Program Files\CA\Unicenter DSM\Bin\rcLoginExt.dll 10/28/2007 03:47 AM 11528 C:\Program Files\CA\Unicenter DSM\bin\rcLoginExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=MachLO.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\Machine\Scripts\Startup\0\1]
"Script"=SDStart.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=StartUp.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-4101780369-38368224-130243791-134471\Scripts\Logon\0\0]
"Script"=\\150.180.145.111\usaicscripts\userlo .cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-4101780369-38368224-130243791-151408\Scripts\Logon\0\0]
"Script"=\\150.180.145.111\usaicscripts\userlo .cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-4101780369-38368224-130243791-196171\Scripts\Logon\0\0]
"Script"=\\150.180.145.111\usaicscripts\userlo .cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-4101780369-38368224-130243791-272592\Scripts\Logon\0\0]
"Script"=\\150.180.145.111\usaicscripts\userlo .cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\group policy\state\S-1-5-21-4101780369-38368224-130243791-441536\Scripts\Logon\0\0]
"Script"=\\150.180.145.111\usaicscripts\userlo .cmd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{5451cbe1-07d2-11dd-a5c4-000f20fe707a}]
AutoRun\command- F:\JDSecure\Windows\JDSecure20.exe
*Newly Created Service* - TMCOMM
-- End of Deckard's System Scanner: finished at 2008-06-19 12:26:21 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) 4
CPU 2.80GHz
Percentage of Memory in Use: 66%
Physical Memory (total/avail): 1015.48 MiB / 336.19 MiB
Pagefile Memory (total/avail): 2446.25 MiB / 1865.31 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1922.69 MiB
A: is Removable (No Media)
B: is Network (NTFS)
C: is Fixed (NTFS) - 74.52 GiB total, 52.01 GiB free.
D: is CDROM (No Media)
E: is Fixed (NTFS) - 298.09 GiB total, 296.01 GiB free.
P: is Network (NTFS)
U: is Network (NTFS)
Y: is Network (Unformatted)
\\.\PHYSICALDRIVE0 - ST380011A - 74.53 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - C:
\\.\PHYSICALDRIVE1 - Maxtor OneTouch III USB Device - 298.09 GiB - 1 partition
\PARTITION0 - Installable File System - 298.09 GiB - E:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: Symantec AntiVirus Corporate Edition v10.1.6.6000 (Symantec Corporation)
[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\DomainProfile\Authoriz edApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\doogie.burkey\Application Data
ASMROOT=C:\Program Files\CA\Unicenter Software Delivery\SD
CAI_CAFT=C:\Program Files\CA\SharedComponents\CAM
CAI_MSQ=C:\Program Files\CA\SharedComponents\CAM
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HUACWKM68103189
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\doogie.burkey
JAVA_PLUGIN_WEBCONTROL_ENABLE=1
LOGONSERVER=\\HUACA1100000001
MOZ_PLUGIN_PATH=C:\PROGRA~1\GRADKE~1\DBSIGN~1\lib;
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\pvsw\bin;C:\Program Files\ActivCard\ActivCard Gold\resources;C:\PROGRA~1\GRADKE~1\DBSIGN~1\lib;C :\Program Files\CA\Dcs\DMScripting\;C:\Program Files\CA\DCS\CAWIN\;C:\WINDOWS\system32;C:\WINDOWS ;C:\WINDOWS\System32\Wbem;C:\Program Files\CA\Unicenter Software Delivery\BIN;C:\PROGRA~1\CA\SHARED~1\CAM\bin;C:\
Pr ogram Files\CA\Unicenter DSM\bin;C:\Program Files\ActivIdentity\ActivClient\;C:\Program Files\ApproveIt\;C:\Program Files\ApproveIt\ThirdParty\Bin\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WS F;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0304
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SDROOT=C:\Program Files\CA\Unicenter DSM\SD
SESSIONNAME=Console
SMARTCARD=ActivCard ActivClient (Axalto Cyberflex Access 64K V1 SM 4.1);SCM Microsystems Inc. SCRx31 USB Reader 0
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ARMY~1.DOO\LOCALS~1\Temp
TMP=C:\DOCUME~1\ARMY~1.DOO\LOCALS~1\Temp
USERDNSDOMAIN=NASW.DS.ARMY.MIL
USERDOMAIN=NASW
USERNAME=army.doogie
USERPROFILE=C:\Documents and Settings\army.doogie
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Administrator
(admin)
user 1
(admin)
user 2
(new local, net ready)
user 3
(admin)
user 4
(admin)
user 5
user 6
(new local, admin, net ready)
army.doogie
(admin)
user 7
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ActivClient for CAC - PKI Only --> MsiExec.exe /I{79BE7375-9061-48E0-94E5-C8ABF5DC376C}
Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activ eX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player 11 --> C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
APPLYMOC --> C:\WINDOWS\ST5UNST.EXE -n "c:\applymoc\ST5UNST.LOG"
APPLYMOC (c:\) --> C:\WINDOWS\ST5UNST.EXE -n "c:\ST5UNST.LOG"
ApproveIt Desktop 5.7.3 --> MsiExec.exe /I{D96B3C48-13AE-41D8-895B-56A8B08DC1F3}
Broadcom Management Programs --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{750DFF5E-C559-11D4-A441-00B0D0436EE7}\Setup.exe"
CA Unicenter DSM Agent + Asset Management Plugin --> MsiExec.exe /X{624FA386-3A39-4EBF-9CB9-C2B484D78B29}
CA Unicenter DSM Agent + Basic Inventory Plugin --> MsiExec.exe /X{501C99B9-1644-4FC2-833B-E675572F8929}
CA Unicenter DSM Agent + Remote Control Plugin --> MsiExec.exe /X{84288555-A79E-4ABD-BA53-219C4D2CA20B}
CA Unicenter DSM Agent + Software Delivery Plugin --> MsiExec.exe /X{62ADA55C-1B98-431F-8618-CDF3CE4CFEEC}
CA Unicenter Software Delivery --> "C:\Program Files\CA\Unicenter Software Delivery\BIN\sdgoaway.exe"
DBsign Web Signer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\070 1\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{44D21B77-D4FC-49E8-A726-CD00D5016703}\Setup.exe" -l0x9
Easy Access Button Support --> C:\Program Files\COMPAQ\Easy Access Button Support\Uninst.exe
FormFlow 2.24 Filler --> C:\WINDOWS\IsUninst.exe -fC:\FormFlow\UsrUnins.isu
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spunins t.exe"
HP Wireless Mouse --> Uninstit.exe CpqMus.ini
Intel(R) Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL
J2SE Runtime Environment 5.0 Update 12 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150120}
Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LiveUpdate 3.1 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Maxtor Backup --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{9C3F9580-F5CF-4288-894E-9FF0EB24A21C} /l1033
Maxtor OneTouch III --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{60EEB642-E9E0-45A2-A676-B9D8FE17C4A9} /l1033
MediaTickets by OIN --> "C:\Program Files\Common Files\EliteMediaGroupOinUninstaller.exe"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst .exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spu ninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spunin st.exe"
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Peachtree Complete Accounting Educational Version 2007 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1 \IDriver.exe /M{FA6CBCB0-FA05-4406-9AEA-614FF8E18FE5}
PeachTree Signature Ready Forms --> MsiExec.exe /I{8BCB844B-0814-4354-A413-1063DB4618E9}
Pervasive Software PSQL v9.1 Client --> "C:\pvsw\unins000.exe"
Pervasive System Analyzer v9.1 --> "C:\Program Files\Common Files\Pervasive Software Shared\unins000.exe"
PureEdge Viewer 6.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E0000650-0650-0650-0650-000000000650}\Setup.exe" -l0x9 -uninst
Questionmark Secure Browser --> C:\Program Files\InstallShield Installation Information\{4004E7A9-C6AF-4A1C-A4D9-FE63F163964C}\setup.exe -runfromtemp -l0x0409
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
QWS3270 Secure --> C:\PROGRA~1\QWS327~1\UNWISE.EXE C:\PROGRA~1\QWS327~1\INSTALL.LOG
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Rhapsody Player Engine --> MsiExec.exe /I{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}
SCR111 PC/SC Drivers Installation --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{093CFFEC-7616-480E-91F4-ED6E8421FF25}\Setup.exe" -l0x9
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SkillSoft Course Manager --> C:\Program Files\SkillSoft\client\OCMStart.exe uninstall
Software Setup --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\COMPAQ\Software Setup\Uninst.isu" -c"C:\Program Files\COMPAQ\Software Setup\CPQUNST.DLL"
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ct or.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.EXE"
Spybot - Search & Destroy 1.3 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Symantec AntiVirus --> MsiExec.exe /X{50E125D1-88E5-48CE-80AE-98EC9698E639}
Unicenter Asset Management SW Metering Agent --> MsiExec.exe /X{A01E1C30-EBC6-406A-90E2-4C19D0AAFEB3}
Windows Desktop Search 3.01 --> "C:\WINDOWS\$NtUninstallKB917013$\spuninst\spunins t.exe"
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe "
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spunin st.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
XML Paper Specification Shared Components Pack 1.0 -->
-- Application Event Log -------------------------------------------------------
Event Record #/Type37151 / Error
Event Submitted/Written: 06/19/2008 10:50:03 AM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (A socket operation was attempted to an unreachable host. ). Group Policy processing aborted.
Event Record #/Type36995 / Error
Event Submitted/Written: 06/19/2008 07:20:27 AM
Event ID/Source: 3050 / Windows Search Service
Event Description:
Unvisited items cannot be deleted from the history after a full update.
Context: Windows Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Event Record #/Type36994 / Error
Event Submitted/Written: 06/19/2008 06:59:01 AM
Event ID/Source: 3050 / Windows Search Service
Event Description:
Unvisited items cannot be deleted from the history after a full update.
Context: Windows Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Event Record #/Type36993 / Error
Event Submitted/Written: 06/19/2008 06:58:47 AM
Event ID/Source: 3050 / Windows Search Service
Event Description:
Unvisited items cannot be deleted from the history after a full update.
Context: Windows Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Event Record #/Type36989 / Error
Event Submitted/Written: 06/18/2008 09:33:44 PM
Event ID/Source: 51 / Symantec AntiVirus
Event Description:
Security Risk Found!Risk: Adware.Purityscan in File: Unavailable by: Invalid : (15) scan. Action: Delete failed : Leave Alone failed. Action Description:
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type38830 / Warning
Event Submitted/Written: 06/19/2008 11:43:50 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type38828 / Error
Event Submitted/Written: 06/19/2008 10:50:02 AM
Event ID/Source: 10010 / DCOM
Event Description:
The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register with DCOM within the required timeout.
Event Record #/Type38796 / Error
Event Submitted/Written: 06/18/2008 09:28:43 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
i8042prt
Event Record #/Type38746 / Error
Event Submitted/Written: 06/18/2008 03:13:54 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
i8042prt
Event Record #/Type38674 / Error
Event Submitted/Written: 06/18/2008 00:08:33 PM
Event ID/Source: 20 / Windows Update Agent
Event Description:
Installation Failure: Windows failed to install the following update with error 0x80070643: Windows Internet Explorer 7 for Windows XP.
-- End of Deckard's System Scanner: finished at 2008-06-19 12:26:21 ------------
Any assistance would be appreciated. Thank you for your time and trouble.