Thank you so much for the help, here are the logs:
Malwarebytes' Anti-Malware 1.24
Database version: 1028
Windows 5.1.2600 Service Pack 2
8:33:59 PM 8/5/2008
mbam-log-8-5-2008 (20-33-59).txt
Scan type: Quick Scan
Objects scanned: 47186
Time elapsed: 21 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 9
Files Infected: 305
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{70004d5d-3bf6-4d51-43b2-02fc0002cdb5} (Rogue.Errorsafe) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\error nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Error Nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Error Nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\backup (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\bin (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\config (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\doc (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\startup_log (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Error Nuker (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Error Nuker\uninstall.exe (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\bin\ErrorNuker.exe (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\bin\StartupManager.exe (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\config\drr_conf.ini (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\config\drr_english.ini (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\config\drr_support.ini (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\doc\errornuker.chm (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\doc\license.rtf (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\doc\readme.txt (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\doc\vssver.scc (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\drr_hist_date.dat (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\drr_hist_desc.dat (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\drr_hist_entries.dat (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\drr_hist_files.dat (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\Error Nuker Log File.txt (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000007 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000008 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000009 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000010 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000011 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000012 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000013 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000014 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000015 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203556_000000016 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000017 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000018 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000019 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000020 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000021 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000022 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000023 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000024 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000025 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000026 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000027 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000028 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080114_203557_000000029 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000001 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000002 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000003 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000004 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000005 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000006 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000007 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000008 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080122_162206_000000009 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080217_194349_000000003 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080217_194349_000000004 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091939_000000007 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091939_000000008 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091940_000000009 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091940_000000010 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091940_000000011 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080229_091940_000000012 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134408_000000026 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134408_000000027 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134408_000000028 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134408_000000029 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000030 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000031 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000032 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000033 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000034 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000035 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000036 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000037 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000038 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000039 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000040 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000041 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000042 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000043 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000044 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000045 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000046 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000047 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080404_134409_000000048 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000015 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000016 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000017 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000018 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000019 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000020 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000021 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\shortcut20080511_102236_000000022 (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000001.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000002.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000003.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000004.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000005.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203556_000000006.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000030.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000031.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000032.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000033.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000034.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000035.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000036.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000037.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000038.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000039.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000040.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000041.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000042.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000043.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000044.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000045.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000046.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000047.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000048.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000049.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000050.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000051.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000052.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000053.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000054.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000055.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000056.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000057.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000058.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000059.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000060.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000061.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000062.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000063.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000064.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000065.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000066.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000067.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000068.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000069.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000070.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000071.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000072.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000073.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000074.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000075.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000076.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000077.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000078.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000079.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203826_000000080.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000081.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000082.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000083.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000084.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000085.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000086.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000087.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000088.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000089.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000090.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000091.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000092.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000093.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000094.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000095.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000096.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000097.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000098.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000099.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000100.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000101.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000102.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000103.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000104.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000105.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000106.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000107.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000108.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000109.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000110.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000111.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000112.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000113.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000114.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000115.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000116.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000117.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000118.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000119.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000120.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000121.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000122.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000123.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000124.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000125.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000126.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000127.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000128.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000129.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000130.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000131.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000132.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000133.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000134.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000135.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000136.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000137.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000138.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000139.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000140.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000141.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000142.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000143.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000144.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000145.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000146.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000147.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000148.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000149.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000150.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000151.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000152.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000153.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000154.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000155.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000156.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000157.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000158.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000159.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000160.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000161.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000162.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000163.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000164.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000165.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000166.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000167.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000168.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000169.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000170.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000171.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000172.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000173.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000174.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000175.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000176.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000177.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000178.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080114_203827_000000179.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080122_162206_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080217_194349_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080217_194349_000000001.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080217_194349_000000002.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000001.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000002.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000003.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000004.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000005.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080229_091939_000000006.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000001.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000002.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000003.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000004.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000005.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000006.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000007.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000008.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000009.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000010.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000011.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000012.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000013.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000014.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000015.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000016.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000017.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000018.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000019.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000020.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000021.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000022.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000023.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000024.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080404_134408_000000025.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000000.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000001.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000002.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000003.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000004.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000005.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000006.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000007.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000008.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000009.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000010.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000011.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000012.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000013.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\log\undo20080511_102236_000000014.reg (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\error_nuker.ico (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\startup.ico (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\uninst.ico (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\vssver.scc (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\~trash.ico (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Program Files\Error Nuker\res\~xpinstall.ico (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Error Nuker\Error Nuker.lnk (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Error Nuker\Startup Manager.lnk (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Error Nuker\Uninstall Error Nuker.lnk (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Error Nuker\Web Home.lnk (Rogue.ErrorNuker) -> Quarantined and deleted successfully.
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, August 5, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, August 06, 2008 03:54:45
Records in database: 1059184
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
G:\
S:\
Scan statistics:
Files scanned: 89621
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 00:38:26
No malware has been detected. The scan area is clean.
The selected area was scanned.
Deckard's System Scanner v20071014.68
Run by SavannaE on 2008-08-05 20:36:01
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
55: 2008-08-06 03:36:44 UTC - RP579 - Deckard's System Scanner Restore Point
54: 2008-08-05 22:00:35 UTC - RP578 - System Checkpoint
53: 2008-08-04 18:54:15 UTC - RP577 - Installed Adobe Audition 3.0
52: 2008-08-04 15:29:12 UTC - RP576 - System Checkpoint
51: 2008-08-02 07:25:06 UTC - RP575 - System Checkpoint
-- First Restore Point --
1: 2008-06-05 03:53:37 UTC - RP525 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as SavannaE.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:38:31 PM, on 8/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\PatchLink\Update Agent\GRAVITIXSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\VLFDF8.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\savannae\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\SavannaE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.packtrack.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [Client Access PC5250 Sound] "C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe"
O4 - HKLM\..\Run: [Google IME Autoupdater] "C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\savannae\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.wsc-plus.westmarine.net (HKLM)
O15 - ESC Trusted Zone: *.wsc-plus.westmarine.net (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1188201923896
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1188201872015
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
http://www.live365.com/players/play365.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://4thgenerationsystems.webex.com/clie...ing/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = westmarine.net
O17 - HKLM\Software\..\Telephony: DomainName = westmarine.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{73648FD4-812F-48AA-BB4F-C4C023BE847E}: NameServer = 192.168.2.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = westmarine.net
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = westmarine.net
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = westmarine.net
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PatchLink Update - Patchlink Corporation - C:\Program Files\PatchLink\Update Agent\GRAVITIXSERVICE.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe (file missing)
--
End of file - 8781 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080404-145108-139 O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
backup-20080404-145108-282 O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
backup-20080404-145108-744 O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
backup-20080404-145108-901 O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
backup-20080404-145108-964 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080405-192321-522 O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
backup-20080727-094046-846 O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
backup-20080731-143136-412 O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 giveio - c:\windows\system32\giveio.sys
R0 speedfan - c:\windows\system32\speedfan.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R2 CP_OMDRV (Check Point Office Mode Module) - c:\windows\system32\drivers\omdrv.sys <Not Verified; Check Point Software Technologies; vna>
R2 PMEM - c:\windows\system32\drivers\pmemnt.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R2 TM_CFW (Common Firewall Driver) - c:\program files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>
R2 VPN-1 (VPN-1 Module) - c:\windows\system32\drivers\vpn.sys <Not Verified; Check Point Software Technologies; vpn1>
S3 vmfilter303 - c:\windows\system32\drivers\vmfilter303.sys <Not Verified; Vimicro Corporation; Filter for VM303 with Face Tracking>
S3 ZSMC303 (USB PC Camera (Vimicro301 Neptune)) - c:\windows\system32\drivers\usbvm303.sys <Not Verified; Vimicro Corporation; >
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 ntrtscan (OfficeScanNT RealTime Scan) - "c:\program files\trend micro\officescan client\ntrtscan.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 OfcPfwSvc (OfficeScanNT Personal Firewall) - "c:\program files\trend micro\officescan client\ofcpfwsvc.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 PatchLink Update - c:\program files\patchlink\update agent\gravitixservice.exe <Not Verified; Patchlink Corporation; Patchlink Update>
R2 ProtexisLicensing - c:\windows\system32\psiservice.exe <Not Verified; ; PSIService>
R2 SR_Service (Check Point SecuRemote Service) - "c:\program files\checkpoint\securemote\bin\sr_service.exe" <Not Verified; Check Point Software Technologies; VPN-1 SecuRemote/SecureClient>
R2 SR_WatchDog (Check Point SecuRemote WatchDog) - "c:\program files\checkpoint\securemote\bin\sr_watchdog.exe" <Not Verified; Check Point Software Technologies; desktop>
R2 tmlisten (OfficeScanNT Listener) - "c:\program files\trend micro\officescan client\tmlisten.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
S2 winvnc (VNC Server) - "c:\program files\ultravnc\winvnc.exe" -service (file missing)
S3 Cwbrxd (iSeries Access for Windows Remote Command) - c:\windows\cwbrxd.exe <Not Verified; IBM Corporation; IBM® iSeries Access for Windows>
S3 OnePointDomainAdminService (Active Directory Migration Agent) - c:\windows\onepointdomainagent\dctagentservice.exe <Not Verified; Microsoft Corporation; Active Directory Migration Tool>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: U.S. Robotics 56K Faxmodem Win 1807
Device ID: PCI\VEN_12B9&DEV_1007&SUBSYS_00C712B9&REV_00\4&3A321F38&0&50F0
Manufacturer: U.S. Robotics Corporation
Name: U.S. Robotics 56K Faxmodem Win 1807
PNP Device ID: PCI\VEN_12B9&DEV_1007&SUBSYS_00C712B9&REV_00\4&3A321F38&0&50F0
Service: Modem
-- Files created between 2008-07-05 and 2008-08-05 -----------------------------
2008-08-05 20:01:46 0 d-------- C:\Documents and Settings\savannae\Application Data\Malwarebytes
2008-08-05 20:01:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 20:01:40 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-04 13:43:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-08-04 11:57:03 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-30 21:05:58 0 d-------- C:\Program Files\SpeedFan
2008-07-23 13:52:47 0 d-------- C:\Documents and Settings\savannae\Tracing
2008-07-23 13:51:08 0 d-------- C:\Program Files\DIFX
2008-07-23 13:50:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Applications
-- Find3M Report ---------------------------------------------------------------
2008-08-05 13:18:58 0 d-------- C:\Documents and Settings\savannae\Application Data\Corel
2008-08-05 13:17:28 2828 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-08-04 13:48:40 0 d-------- C:\Documents and Settings\savannae\Application Data\LimeWire
2008-08-04 13:43:52 0 d-------- C:\Documents and Settings\savannae\Application Data\Adobe
2008-08-04 11:57:03 0 d-------- C:\Program Files\Common Files
2008-08-04 11:56:42 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-31 14:17:08 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-31 14:17:05 0 d-------- C:\Program Files\PC-Doctor for Windows
2008-07-27 09:55:57 0 d-------- C:\Documents and Settings\savannae\Application Data\Image Zone Express
2008-06-13 14:08:43 0 d-------- C:\Documents and Settings\savannae\Application Data\IMVU
2008-06-13 13:58:49 0 d-------- C:\Program Files\IMVU
2008-06-12 08:07:59 0 d-------- C:\Program Files\SecondLife
2008-06-09 14:28:06 0 d-------- C:\Program Files\MSECache
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE84A6AA-A333-4B92-B276-C11E2212E4FE}]
12/15/2006 06:34 PM 599472 --a------ C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [06/05/2005 05:30 AM]
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" [06/05/2005 05:30 AM]
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" [06/05/2005 05:30 AM]
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" [06/05/2005 05:30 AM]
"Client Access PC5250 Sound"="C:\Program Files\IBM\Client Access\Emulator\pcssnd.exe" [06/05/2005 05:30 AM]
"Google IME Autoupdater"="C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe" [01/07/2008 03:15 AM]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/03/2004 10:32 PM]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [08/18/2001 02:00 AM]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/03/2004 10:31 PM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/03/2004 10:32 PM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/03/2004 10:32 PM]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [10/02/2007 12:34 PM]
"BigDog303"="C:\WINDOWS\VM303_STI.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
ckpNotify.dll 04/09/2006 08:59 PM 24674 C:\WINDOWS\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
"Script"=PST_disable.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
"Script"=pushprinterconnections.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\1]
"Script"=addlocaladmins.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-4069712820-383745501-364879-10025\Scripts\Logon\0\0]
"Script"=WSC_LogIn.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-4069712820-383745501-364879-10025\Scripts\Logon\1\0]
"Script"=pushprinterconnections.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Error Nuker]
C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
"C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
ICO.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfficeScanNT Monitor]
"C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartSoft PDF Printer (demo) Agent]
"C:\Program Files\Smart PDF Creator\sspdfagentd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartSoft PDF Printer (demo) virtual printer agent]
"C:\Program Files\Smart PDF Creator\sspdfagentd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt hpqcxs08 hpqddsvc
*Newly Created Service* - WINVNC
-- End of Deckard's System Scanner: finished at 2008-08-05 20:41:42 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 3.00GHz
CPU 1: Intel® Pentium® 4 CPU 3.00GHz
Percentage of Memory in Use: 66%
Physical Memory (total/avail): 758.98 MiB / 251.81 MiB
Pagefile Memory (total/avail): 1857.46 MiB / 1189.74 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1932.22 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 34.96 GiB total, 16.9 GiB free.
D: is CDROM (No Media)
G: is Network (Unformatted)
S: is Network (Unformatted)
\\.\PHYSICALDRIVE0 - WDC WD400BB-23JHA1 - 37.27 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 34.96 GiB - C:
\PARTITION1 - Unknown - 2.3 GiB
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
Windows Internal Firewall is disabled.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
UpdatesDisableNotify is set.
FW: Trend Micro OfficeScan Enterprise Client Firewall v7.3 (TrendFirewall)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe:*:Enabled:VPN-1 SecuRemote/SecureClient service"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe:*:Enabled:VPN-1 SecuRemote/SecureClient application"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe:*:Enabled:VPN-1 SecuRemote/SecureClient command line"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe:*:Enabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe:*:Enabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Symantec\\pcAnywhere\\awhost32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awhost32.exe:*:Disabled:pcAnywhere Host Service"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe:*:Disabled:VPN-1 SecuRemote/SecureClient application"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe:*:Disabled:VPN-1 SecuRemote/SecureClient command line"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe:*:Disabled:VPN-1 SecuRemote/SecureClient diagnostics"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe:*:Disabled:VPN-1 SecuRemote/SecureClient SDS agent"
"C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"="C:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe:*:Disabled:VPN-1 SecuRemote/SecureClient service"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\savannae\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SAVANNAHE
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\savannae
LOGONSERVER=\\CAMARO
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\PROGRA~1\Java\JRE16~3.0_0\bin;C:\PROGRA~1\Java\JRE16~3.0_0\bin;C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\PROGRA~1\IBM\CLIENT~1;C:\PROGRA~1\IBM\CLIENT~1\Shared;C:\PROGRA~1\IBM\CLIENT~1\Emulator;C:\Program Files\QuickTime\QTSystem\;.
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\savannae\LOCALS~1\Temp
TMP=C:\DOCUME~1\savannae\LOCALS~1\Temp
USERDNSDOMAIN=westmarine.net
USERDOMAIN=WESTMARINE
USERNAME=SavannaE
USERPROFILE=C:\Documents and Settings\savannae
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
davidg
(admin)
admin
(admin)
Administrator
(admin)
savannae
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> "C:\Program Files\InstallShield Installation Information\{F37167DD-4436-4641-90B6-329D60632DDA}\Setup.exe" REMOVEALL --u:{F37167DD-4436-4641-90B6-329D60632DDA}
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\AFPViewr\DeIsL4.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL10.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL101.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL11.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL15.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL42.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL43.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL46.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL47.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL48.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL49.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL50.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL51.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL52.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL53.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL54.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL55.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\DeIsL56.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\Emulator\DeIsL7.isu"
--> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\IBM\Client Access\Emulator\DeIsL8.isu"
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
32 Bit HP CIO Components Installer --> MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Access IBM --> MsiExec.exe /X{B5599ECB-DA72-43EE-8A30-2C80396FF8BB}
Access IBM Cleanup Utility --> MsiExec.exe /I{CF44C7A5-5705-41E4-BE84-A9A42977AB05}
Access IBM Message Center --> MsiExec.exe /X{710C0BB2-FE39-484E-BB23-C9B96835A14A}
Access IBM Tools --> C:\Program Files\IBM\Access IBM\IBMUINST.EXE
Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Audition 3.0 --> msiexec /I {53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
CamStudio --> C:\Program Files\CamStudio\uninstall.exe
Check Point VPN-1 SecureClient NGX R60 HFA1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FCF2FC0-8268-11D4-A313-0006290D766E}\setup.exe" ADD_REMOVE
Chinese (Simplified) Language Support --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\cn.inf, Uninstall
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Corel Paint Shop Pro Photo XI --> MsiExec.exe /X{93A1B09E-BAFA-4628-A5B6-921CB026955A}
Easy GIF Animator 4.1 --> "C:\Program Files\Easy GIF Animator\unins000.exe"
FAXCOM Suite for Windows Client --> MsiExec.exe /I{D220020F-7647-4831-AA43-E6E44B323CF1}
FTPEdit 3.10 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A360A441-D521-4BB3-878F-47DB79412919}\Setup.exe" -l0x9
Google Pinyin IME --> "C:\Program Files\Google\Google Pinyin\Uninstall.exe"
GoToMeeting/GoToWebinar 3.0.0.190 --> C:\Program Files\Citrix\GoToMeeting\190\G2MUninstall.exe /uninstall
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Homestead SiteBuilder --> C:\Program Files\Homestead\Homestead Professional\Editor\hkuninst.exe -path C:\Program Files\Homestead\Homestead Professional
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
HP Photosmart Essential --> MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Smart Web Printing 1.0 --> MsiExec.exe /X{E3030F57-9E6B-4E36-95B6-F7B4DBDEB8FB}
HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HPSSupply --> MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
IBM iSeries Access for Windows --> "C:\Program Files\IBM\Client Access\cwbinarp.exe"
IBM iSeries Access for Windows SI18651 --> "C:\Program Files\IBM\Client Access\cwbunsp.exe"
IBM Update Connector --> MsiExec.exe /X{31C2FBAC-67CF-4093-8F36-15A146613747}
ijji --> C:\ijji\ENGLISH\ijjiUninstall.exe
ijji Auto Installer --> "C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly
ijji FireFox Launcher 1.0 --> C:\Documents and Settings\All Users\Application Data\IJJIGame\uninst.exe
IMVU Avatar Chat Software --> C:\Program Files\IMVU\Uninstall.exe
Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
Intel® PRO Network Connections Drivers --> Prounstl.exe
Intel® PROSet --> MsiExec.exe /I{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}
InterVideo WinDVD 8 --> C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
iTunes --> MsiExec.exe /I{02DFB3FD-CF52-4183-8BCA-2A127D4888F4}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Last.fm 1.4.2.58376 --> "C:\Program Files\Last.fm\unins000.exe"
LimeWire 4.16.7 --> "C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Office Live Meeting 2007 --> MsiExec.exe /I{E3CD4EA8-68BB-46E8-9E79-20A417A82C53}
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Microsoft XML 4.0 SP 2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D6E92BCC-717B-4B2A-A82E-8368D4B5F45F}\setup.exe" -l0x9
Morpheus Photo Compressor v2.00 --> "C:\Program Files\Morpheus Photo Compressor\unins000.exe"
Mouse Suite --> PMUninst.exe MouseSuite98
Mozilla Firefox (2.0.0.16) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
PatchLink Update Agent --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F060A75A-9D6E-46F5-A9E6-7B513F4F44FB}\setup.exe" -l0x9
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Rapid PHP 2007 v8.31 --> "C:\Program Files\Rapid PHP 2007\unins000.exe"
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Smart PDF Creator 3.1.5 --> "C:\Program Files\Smart PDF Creator\unins000.exe"
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.EXE"
SpeedFan (remove only) --> "C:\Program Files\SpeedFan\uninstall.exe"
ThinkCentre Wallpaper --> MsiExec.exe /I{80380166-A872-4B78-B98A-33447A032BDF}
Trend Micro OfficeScan Client --> "C:\Program Files\Trend Micro\OfficeScan Client\ntrmv.exe"
USB PC Camera (Vimicro301 Neptune) --> C:\Program Files\InstallShield Installation Information\{CE3B8E96-B0AF-4871-9178-1519B58E3A93}\setup.exe -runfromtemp -l0x0009 -removeonly
VobSub v2.23 (Remove Only) --> "C:\Program Files\Gabest\VobSub\uninstall.exe"
WebEx --> C:\PROGRA~1\MOZILL~1\plugins\atcliun.exe
Windows Driver Package - Microsoft Corporation (usbvideo) Image (05/25/2007 1.0.3656.0) --> rundll32.exe C:\PROGRA~1\DIFX\7AA84A78695B31A503D9537A76801D74E0FD14BD\DIFxAppA.dll, DIFxARPUninstallDriverPackage C:\WINDOWS\system32\DRVSTORE\RoundTable_F29D632BDCC1844B9B7688A0A4B4DA9E716B76FF\RoundTable.inf
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Connect --> "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$hf_mig$\KB900485\spuninst.exe"
Windows NT Messaging --> RunDll32 setupapi.dll,InstallHinfSection Uninstall 4 MSMail.inf
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
XviD MPEG4 Video Codec (remove only) --> "C:\WINDOWS\system32\xvid-uninstall.exe"
-- Application Event Log -------------------------------------------------------
Event Record #/Type15555 / Error
Event Submitted/Written: 08/05/2008 07:26:11 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.
Event Record #/Type15554 / Error
Event Submitted/Written: 08/05/2008 07:23:39 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.
Event Record #/Type15553 / Error
Event Submitted/Written: 08/05/2008 05:53:36 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.
Event Record #/Type15552 / Error
Event Submitted/Written: 08/05/2008 05:37:05 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.
Event Record #/Type15551 / Error
Event Submitted/Written: 08/05/2008 04:20:04 PM
Event ID/Source: 1054 / Userenv
Event Description:
Windows cannot obtain the domain controller name for your computer network. (An unexpected network error occurred. ). Group Policy processing aborted.
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type8941 / Warning
Event Submitted/Written: 08/05/2008 08:14:58 PM
Event ID/Source: 10 / Kerberos
Event Description:
The kerberos subsystem is having problems fetching tickets from
your domain controller using the UDP network protocol. This is
typically due to network problems. Please contact your system
administrator.
Event Record #/Type8939 / Warning
Event Submitted/Written: 08/05/2008 07:58:21 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type8938 / Warning
Event Submitted/Written: 08/05/2008 07:13:46 PM
Event ID/Source: 10 / Kerberos
Event Description:
The kerberos subsystem is having problems fetching tickets from
your domain controller using the UDP network protocol. This is
typically due to network problems. Please contact your system
administrator.
Event Record #/Type8937 / Warning
Event Submitted/Written: 08/05/2008 06:13:05 PM
Event ID/Source: 10 / Kerberos
Event Description:
The kerberos subsystem is having problems fetching tickets from
your domain controller using the UDP network protocol. This is
typically due to network problems. Please contact your system
administrator.
Event Record #/Type8936 / Warning
Event Submitted/Written: 08/05/2008 04:43:34 PM
Event ID/Source: 10 / Kerberos
Event Description:
The kerberos subsystem is having problems fetching tickets from
your domain controller using the UDP network protocol. This is
typically due to network problems. Please contact your system
administrator.
-- End of Deckard's System Scanner: finished at 2008-08-05 20:41:42 ------------