Hi, guys. I'm looking for some help on getting rid of two trojans which I suspect are the cause for my PC's extreme slowness and general testiness. I tried running Norton in Safe mode, and came up with two instances of Downloader: counter.exe and counter.inf, both located in c:\counter.cab. Norton can't remove them, however. Any help you can give would be greatly appreciated. Here's my Hijackthis log:
Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-13 17:56:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 5 Restore Point(s) --
36: 2008-05-13 19:11:23 UTC - RP79 - Deckard's System Scanner Restore Point
35: 2008-05-13 07:30:09 UTC - RP78 - Installed Ad-Aware 2007
34: 2008-05-13 07:15:13 UTC - RP77 - Spybot-S&D Spyware removal
33: 2008-05-13 04:18:47 UTC - RP76 - Software Distribution Service 3.0
32: 2008-05-12 19:15:54 UTC - RP75 - Removed Google Toolbar for Internet Explorer
-- First Restore Point --
1: 2008-05-08 18:41:48 UTC - RP44 - Installed Windows XP KB833407.
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 79% (more than 75%).
Total Physical Memory: 247 MiB (512 MiB recommended).
System Drive C: has 2.71 GiB (less than 15%) free.
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:00:57 PM, on 5/13/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\HP\KBD\KBD.EXE
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\defrag.exe
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\Owner.JEFFSCOMPUTER\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Memeo AutoBackup Launcher.lnk = ?
O4 - Startup: Memeo AutoSync Launcher.lnk = C:\Program Files\Memeo\AutoSync\MemeoLauncher.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0a\aoltray.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as...abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1210207161848
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1210224814976
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driveragent.com/files/driveragent.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 11467 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys <Not Verified; VERITAS Software, Inc.; >
R0 fasttx2k - c:\windows\system32\drivers\fasttx2k.sys <Not Verified; Promise Technology, Inc.; Promise FastTrak Series Driver>
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S4 AutoSyncService (Memeo AutoSync ) - "c:\program files\memeo\autosync\memeoservice.exe" <Not Verified; Memeo; Memeo AutoBackup>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-11 15:28:22 622 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
2008-05-09 19:14:42 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-03-17 21:21:04 272 --a------ C:\WINDOWS\Tasks\easy Internet sign-up.job
-- Files created between 2008-04-13 and 2008-05-13 -----------------------------
2008-05-13 17:59:57 0 d-------- C:\Program Files\Trend Micro
2008-05-13 06:02:22 0 d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-13 02:57:15 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-05-13 02:56:26 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-05-13 02:55:43 0 d-------- C:\WINDOWS\Internet Logs
2008-05-13 02:41:58 0 d-------- C:\Program Files\SpywareGuard
2008-05-13 02:40:30 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Mozilla
2008-05-13 02:39:40 0 d-------- C:\Program Files\SpywareBlaster
2008-05-13 02:30:25 0 d-------- C:\Program Files\Lavasoft
2008-05-13 02:30:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-13 00:42:09 2062665 --a------ C:\Program Files\spywareguardsetup.exe
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Favorites
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Desktop
2008-05-12 17:32:15 0 d--hs---- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Cookies
2008-05-12 17:32:15 0 dr-h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Symantec
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Sonic
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Share-to-Web Upload Folder
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\SampleView
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Real
2008-05-12 17:32:15 0 d---s---- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Microsoft
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\InterTrust
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\interMute
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Identities
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Apple Computer
2008-05-12 17:32:15 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Application Data\Adobe
2008-05-12 17:32:14 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\WINDOWS
2008-05-12 17:32:14 0 d--h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Templates
2008-05-12 17:32:14 0 dr------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Start Menu
2008-05-12 17:32:14 0 dr-h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\SendTo
2008-05-12 17:32:14 0 d--h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Recent
2008-05-12 17:32:14 0 d--h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\PrintHood
2008-05-12 17:32:14 786432 --ah----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\NTUSER.DAT
2008-05-12 17:32:14 0 d--h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\NetHood
2008-05-12 17:32:14 0 d-------- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\My Documents
2008-05-12 17:32:14 0 d--h----- C:\Documents and Settings\Administrator.JEFFSCOMPUTER\Local Settings
2008-05-12 00:45:36 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer
2008-05-11 14:53:22 0 d-------- C:\Program Files\Norton Internet Security
2008-05-11 14:40:46 0 d-------- C:\Program Files\Symantec
2008-05-11 05:03:22 667648 --a------ C:\Program Files\Norton_Removal_Tool.exe
2008-05-11 00:01:57 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Corel
2008-05-10 02:13:23 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Google
2008-05-10 01:58:20 0 d-------- C:\Program Files\Picasa2
2008-05-10 01:51:48 0 d-------- C:\Program Files\Western Digital
2008-05-10 01:51:13 0 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-05-10 01:49:30 0 d-------- C:\Program Files\Common Files\eSellerate
2008-05-10 01:44:53 0 d-------- C:\Program Files\Memeo
2008-05-10 01:43:55 0 d---s---- C:\Documents and Settings\All Users\Application Data\Memeo
2008-05-10 01:12:47 0 d-------- C:\Program Files\Western Digital Technologies
2008-05-10 00:30:07 0 d-------- C:\Program Files\Norton AntiVirus2007
2008-05-10 00:27:31 0 d-------- C:\Program Files\Norton Antivirus 2007 + KeyGen
2008-05-09 20:35:53 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-09 19:20:22 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Apple Computer
2008-05-09 18:44:41 7036686 --a------ C:\Program Files\klcodec390s.exe <Not Verified; ; K-Lite Codec Pack>
2008-05-09 17:48:27 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
2008-05-09 00:10:47 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\WinRAR
2008-05-08 22:05:30 0 d-------- C:\WINDOWS\Prefetch
2008-05-08 21:38:29 0 d-------- C:\WINDOWS\system32\scripting
2008-05-08 21:38:25 0 d-------- C:\WINDOWS\l2schemas
2008-05-08 21:38:23 0 d-------- C:\WINDOWS\system32\en
2008-05-08 19:12:55 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Aim
2008-05-08 13:10:21 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:20 171280 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:17 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:17 6550 --a------ C:\WINDOWS\jautoexp.dat
2008-05-08 13:10:16 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
2008-05-08 13:10:08 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-05-08 13:10:07 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-05-08 13:10:07 171792 --a------ C:\WINDOWS\system32\wjview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:06 286992 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:06 21264 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:01 947472 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:10:00 154384 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:59 172304 --a------ C:\WINDOWS\system32\jview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:59 15120 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:58 404752 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:57 63248 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:57 187152 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-08 13:09:55 49424 --a------ C:\WINDOWS\system32\clspack.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2008-05-07 21:58:33 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Macromedia
2008-05-07 19:42:37 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Station
2008-05-07 19:38:41 0 d--hs---- C:\Documents and Settings\Owner.JEFFSCOMPUTER\UserData
2008-05-07 19:32:15 0 dr-hs---- C:\cmdcons
2008-05-07 19:25:49 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Lavasoft
2008-05-07 19:20:00 0 dr-h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Recent
2008-05-07 19:18:12 0 d-------- C:\WINDOWS\setupupd
2008-05-07 19:04:07 0 dr------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Favorites
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Desktop
2008-05-07 19:04:07 0 d--hs---- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Cookies
2008-05-07 19:04:07 0 d--h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Sonic
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Share-to-Web Upload Folder
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\SampleView
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Real
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\InterTrust
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\interMute
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Identities
2008-05-07 19:04:07 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Adobe
2008-05-07 19:04:06 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\WINDOWS
2008-05-07 19:04:06 0 d--h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Templates
2008-05-07 19:04:06 0 d-------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Start Menu
2008-05-07 19:04:06 0 dr-h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\SendTo
2008-05-07 19:04:06 0 d--h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\PrintHood
2008-05-07 19:04:06 0 d--h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\NetHood
2008-05-07 19:04:06 0 dr------- C:\Documents and Settings\Owner.JEFFSCOMPUTER\My Documents
2008-05-07 19:04:06 0 d--h----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\Local Settings
2008-05-07 19:04:05 3407872 --ah----- C:\Documents and Settings\Owner.JEFFSCOMPUTER\NTUSER.DAT
2008-05-07 17:25:36 0 d-------- C:\temp
2008-04-24 05:41:27 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-24 05:31:19 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-24 05:31:18 0 d-------- C:\WINDOWS\system32\LogFiles
-- Find3M Report ---------------------------------------------------------------
2008-05-13 14:37:33 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-05-13 02:28:28 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-12 14:22:10 0 d-------- C:\Program Files\Google
2008-05-11 22:37:32 0 d-------- C:\Program Files\Common Files
2008-05-11 00:02:25 61678 --a------ C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\PFP100JPR.{PB
2008-05-11 00:02:25 12358 --a------ C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\PFP100JCM.{PB
2008-05-10 01:51:33 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-10 01:49:09 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-09 18:54:53 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-05-09 18:07:06 0 d-------- C:\Program Files\hj-join
2008-05-08 22:04:44 0 d-------- C:\Program Files\Messenger
2008-05-08 21:38:21 0 d-------- C:\Program Files\Movie Maker
2008-05-08 21:29:45 0 d-------- C:\Program Files\Windows NT
2008-05-08 17:44:19 0 d-------- C:\Program Files\2Wire
2008-05-07 19:46:17 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-29 04:35:26 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-03-21 00:54:03 3698120 --a------ C:\Program Files\daemon4122-lite.exe <Not Verified; DT Soft Ltd.; DAEMON Tools Lite>
2008-03-18 21:22:44 0 d-------- C:\Program Files\Microsoft.NET
2008-03-18 21:22:06 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-03-18 20:28:25 0 d-------- C:\Program Files\Microsoft Office 2003 Professional (Word, Excel, Powerpoint, Access, Frontpage, Outlook, Infopath, Visio, Project)
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 06:04 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [08/20/2004 03:51 PM]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [06/22/2002 09:27 AM]
"Share-to-Web Namespace Daemon"="c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [04/17/2002 07:42 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 09:02 PM]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [02/13/2003 10:01 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/10/2003 01:36 AM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/13/2002 11:42 PM]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [03/18/2003 03:50 AM]
"PS2"="C:\WINDOWS\system32\ps2.exe" [10/16/2002 05:57 PM]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 01:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [08/20/2004 03:55 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/10/2008 04:27 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 04:22 AM]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [03/20/2006 05:34 PM]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [02/20/2007 08:18 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/10/2007 12:59 AM]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [01/14/2007 02:11 AM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 05:38 PM]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [11/28/2004 05:22 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [04/14/2008 05:42 AM]
"AIM"="C:\Program Files\AIM\aim.exe" [08/10/2004 10:37 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/14/2008 05:42 AM]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [01/22/2003 08:10 PM]
C:\Documents and Settings\Owner.JEFFSCOMPUTER\Start Menu\Programs\Startup\
Memeo AutoBackup Launcher.lnk - C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data\Microsoft\Installer\{6BCEB97B-F315-455D-BC2D-565A1A6781E8}\NewShortcut4_51A847D327C24F7797772AF2A4E486ED.exe [5/10/2008 1:46:03 AM]
Memeo AutoSync Launcher.lnk - C:\Program Files\Memeo\AutoSync\MemeoLauncher.exe [7/6/2007 5:28:44 PM]
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 8.0 Tray Icon.lnk - C:\Program Files\America Online 8.0a\aoltray.exe [1/14/2008 1:55:47 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 02/21/2003 05:50 AM 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d214465c-1c9e-11dd-90c9-806d6172696f}]
AutoRun\command- D:\Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee1d65f8-1e57-11dd-90d7-00402b614b6e}]
AutoRun\command- G:\wd_windows_tools\setup.exe
*Newly Created Service* - COMHOST
-- End of Deckard's System Scanner: finished at 2008-05-13 18:08:41 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel® Celeron® CPU 2.40GHz
Percentage of Memory in Use: 73%
Physical Memory (total/avail): 246.98 MiB / 66.48 MiB
Pagefile Memory (total/avail): 710.68 MiB / 237.12 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1875.68 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 33.74 GiB total, 2.7 GiB free.
D: is Fixed (FAT32) - 4.53 GiB total, 0.76 GiB free.
E: is CDROM (No Media)
F: is Fixed (FAT32) - 111.76 GiB total, 109.25 GiB free.
G: is Fixed (FAT32) - 465.65 GiB total, 354.48 GiB free.
\\.\PHYSICALDRIVE0 - Maxtor 2F040L0 - 38.28 GiB - 2 partitions
\PARTITION0 - Unknown - 4.53 GiB - D:
\PARTITION1 (bootable) - Installable File System - 33.74 GiB - C:
\\.\PHYSICALDRIVE2 - WD 1200BB External USB Device - 111.79 GiB - 1 partition
\PARTITION0 - Unknown - 111.79 GiB - F:
\\.\PHYSICALDRIVE1 - WD 5000AAV External USB Device - 465.76 GiB - 1 partition
\PARTITION0 - Unknown - 465.76 GiB - G:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Owner.JEFFSCOMPUTER\Application Data
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=JEFFSCOMPUTER
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Owner.JEFFSCOMPUTER
LOGONSERVER=\\JEFFSCOMPUTER
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PCToolsDir=C:\Documents and Settings\All Users\Start Menu\Programs\Hewlett-Packard\HP Pavilion PC Tools
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\OWNER~1.JEF\LOCALS~1\Temp
TMP=C:\DOCUME~1\OWNER~1.JEF\LOCALS~1\Temp
tvdumpflags=10
USERDOMAIN=JEFFSCOMPUTER
USERNAME=Owner
USERPROFILE=C:\Documents and Settings\Owner.JEFFSCOMPUTER
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Owner.JEFFSCOMPUTER (admin)
Administrator.JEFFSCOMPUTER (new local, admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\System32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
--> C:\WINDOWS\System32\\MSIEXEC.EXE /x {60E971B7-51A0-48CA-8687-C6B8F094A409}
--> c:\WINDOWS\System32\\MSIEXEC.EXE /x {8214CC02-6271-4DC8-B8DD-779933450264}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{39DA87A1-0B26-4562-A70C-2A6147366E47}\setup.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F765BD0-B900-4EDE-A90B-61C8A9E95C42}\Setup.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD59025-5B73-4E12-B789-0028C5A573C2}\Setup.exe"
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ArcSoft Picture Software --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\Software Suite\Uninst.isu"
AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
Blackhawk Striker from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\5415BC25-6D6C-46C4-B34C-EA8470FE56D5\Uninstall.exe"
Blasterball 2 from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\357ECB62-CD36-4B63-B57E-769D0CA174F4\Uninstall.exe"
BlasterBall Wild from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\28BA89E7-2F60-4BE7-BAA2-7949EB3FE527\Uninstall.exe"
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
Dark Orbit from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\7841B68B-B7DD-408E-8B45-D5CA39608185\Uninstall.exe"
Disney`s Lilo and Stitch Pinball from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\63272979-21F0-48EF-9B97-A83DBC05BE39\Uninstall.exe"
easy Internet sign-up --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{0613467F-A45E-4CB1-9ECE-1F3DD79FB927} /l1033
Excavation from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\DF479CEA-34C0-460F-9B56-93BCE4CD4086\Uninstall.exe"
GemMaster 3 from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC\Uninstall.exe"
HP Deskjet printer preloaded drivers --> MsiExec.exe /X{48BD24F5-13DE-493A-A7CE-28A85113FF0C}
HP Digital Imaging Album Printing 1.0 --> MsiExec.exe /X{47D4AF7B-EDE6-4ADB-8D2F-0BDA25C7321F}
HP Instant Support --> C:\PROGRA~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HPINST~1\INSTALL.LOG
HP Memories Disc --> MsiExec.exe /X{35E90FA5-2CB4-4039-A8BB-BE1B9DB94E21}
HP Photo and Imaging 1.2 - Photosmart Cameras --> MsiExec.exe /X{4F5FC172-F0E7-4EA5-902F-8D005DF9F000}
HP Photosmart printers preloaded drivers --> MsiExec.exe /X{9E88DAA4-1352-4272-BA3A-897668408400}
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
IntelliMover Data Transfer Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9
iTunes --> MsiExec.exe /I{B85C4D19-6CEB-48CF-BD98-C887AC8C6F94}
K-Lite Codec Pack 3.9.0 Standard --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
KBD --> C:\HP\KBD\KBD.EXE uninstalled
Lernout & Hauspie TruVoice American English TTS Engine --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tv_enua.inf, Uninstall
LiveUpdate 3.2 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
LiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
Memeo AutoBackup --> C:\Program Files\InstallShield Installation Information\{6BCEB97B-F315-455D-BC2D-565A1A6781E8}\setup.exe -runfromtemp -l0x0409
Memeo AutoSync --> C:\Program Files\InstallShield Installation Information\{FECA6067-869C-4F32-9F6E-574E1496CE44}\setup.exe -runfromtemp -l0x0409
Men In Black II CROSSFIRE from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\3EA6838C-5C34-4F9C-A8DA-434D65DD1356\Uninstall.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSRedist --> MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
MUSICMATCH® Jukebox --> C:\PROGRA~1\MUSICM~1\MUSICM~1\unmatch.exe
Norton AntiVirus --> MsiExec.exe /X{830D8CBD-C668-49e2-A969-C2C2106332E0}
Norton Confidential Browser Component --> MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
Norton Confidential Web Protection Component --> MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
Norton Internet Security --> MsiExec.exe /I{48185814-A224-447A-81DA-71BD20580E1B}
Norton Internet Security --> MsiExec.exe /I{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}
Norton Internet Security --> MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Internet Security --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Norton Internet Security (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_2_0_30\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}.exe" /X
Norton Protection Center --> MsiExec.exe /I{9A129ABC-A53A-4209-A21E-D5DEDFB7CCA8}
NVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvhp.inf
OmniPass --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}\Setup.exe" -l0x9
PC-Doctor for Windows --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F7CCFA3-D926-4882-B2A5-A0217ED25597}\Setup.exe"
Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
PS2 --> C:\WINDOWS\system32\ps2.exe uninstall
Python 2.2 combined Win32 extensions --> C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log
Python 2.2.1 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
Quicken 2003 New User Edition --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{F61F2821-694C-475F-99AB-6AF2EFDF40FD} anything
QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
RealOne Player --> C:\Program Files\Common Files\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
RecordNow --> MsiExec.exe /I{8214CC02-6271-4DC8-B8DD-779933450264}
RingMaster from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\8c9c48d7-2d03-4a1f-a303-5bd22ccabae1\Uninstall.exe"
S3Display --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display'
S3Gamma2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2'
S3Info2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2'
S3Overlay --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay'
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Simple Backup for My Pictures --> MsiExec.exe /I{60E971B7-51A0-48CA-8687-C6B8F094A409}
Simple Installer - Multilanguage Version --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}\setup.exe"
Snowboard Extreme from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\753FE96B-D926-4B6C-BCFB-CC59153D004A\Uninstall.exe"
Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
Space Rocks from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\9FA01E11-9015-4140-B10A-5C6AA949B2FC\Uninstall.exe"
SpamSubtract --> C:\PROGRA~1\INTERM~1\SPAMSU~1\UNWISE.EXE /U C:\PROGRA~1\INTERM~1\SPAMSU~1\INSTALL.LOG
SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SpywareGuard v2.2 --> "C:\Program Files\SpywareGuard\unins000.exe"
SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
toolkit --> c:\Windows\HPTK\unhptkit.exe
Updates from HP --> C:\WINDOWS\BWUnin-6.2.3.66.exe -AppId 137903
Virtual Warfare from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\4F0AE1FB-4082-4A27-8363-05D292D92FB0\Uninstall.exe"
WD Diagnostics --> MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
WeatherBug --> C:\PROGRA~1\AWS\WEATHE~1\REMOVE.EXE /S
Weblink --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4FCC384C-18EA-4E25-9281-A06AE006D219}\setup.exe" -l0x9
WildTangent GameChannel (remove only) --> "C:\Program Files\WildTangent\Apps\uninstallgamechannel.exe"
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WordPerfect Productivity Pack --> c:\WINDOWS\Corel\Uninst32.exe
WordPerfect Productivity Pack --> C:\WINDOWS\Corel\uninst32.exe
ZoneAlarm --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type970 / Error
Event Submitted/Written: 05/13/2008 02:14:35 PM / 05/13/2008 02:14:36 PM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
Information Level: error
Initialization of the COM subsystem failed. Error code: 0x8007041D
Event Record #/Type966 / Error
Event Submitted/Written: 05/13/2008 01:03:21 PM / 05/13/2008 01:03:23 PM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
Information Level: error
Initialization of the COM subsystem failed. Error code: 0x8007041D
Event Record #/Type959 / Error
Event Submitted/Written: 05/13/2008 06:13:58 AM / 05/13/2008 06:13:59 AM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
Information Level: error
Initialization of the COM subsystem failed. Error code: 0x8007041D
Event Record #/Type955 / Error
Event Submitted/Written: 05/13/2008 05:02:17 AM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
Information Level: error
Initialization of the COM subsystem failed. Error code: 0x8007041D
Event Record #/Type952 / Error
Event Submitted/Written: 05/13/2008 04:49:43 AM
Event ID/Source: 101 / Automatic LiveUpdate Scheduler
Event Description:
Information Level: error
Initialization of the COM subsystem failed. Error code: 0x8007041D
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1972 / Warning
Event Submitted/Written: 05/13/2008 04:31:46 PM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the
DHCP Server) for the Network Card with network address 00402B614B6E. The following
error occurred:
%%121.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.
Event Record #/Type1965 / Error
Event Submitted/Written: 05/13/2008 02:14:57 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The LiveUpdate service failed to start due to the following error:
%%1053
Event Record #/Type1964 / Error
Event Submitted/Written: 05/13/2008 02:14:57 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.
Event Record #/Type1963 / Error
Event Submitted/Written: 05/13/2008 02:14:30 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1053" attempting to start the service LiveUpdate with arguments ""
in order to run the server:
{03E0E6C2-363B-11D3-B536-00902771A435}
Event Record #/Type1962 / Error
Event Submitted/Written: 05/13/2008 01:13:36 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {FFF2D28F-E4EE-44D9-8104-8E71556757F6} did not register with DCOM within the required timeout.
-- End of Deckard's System Scanner: finished at 2008-05-13 18:08:41 ------------
Thanks in advance.