Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: AMD Athlon(tm) Processor Percentage of Memory in Use: 55% Physical Memory (total/avail): 639.55 MiB / 281.6 MiB Pagefile Memory (total/avail): 1564.53 MiB / 1221.77 MiB Virtual Memory (total/avail): 2047.88 MiB / 1940.13 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 37.27 GiB total, 11.88 GiB free. D: is CDROM (No Media) \\.\PHYSICALDRIVE0 - QUANTUM FIREBALLlct20 40 - 37.27 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 37.27 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. FW: Bitdefender Firewall v8.0 (BitDefender) [COLOR=RED]Disabled[/COLOR] FW: Sygate Personal Firewall v4.6 (Sygate Technologies, Inc.) FW: COMODO Firewall Pro v3.0 (COMODO) AV: Bitdefender Antivirus v8.0 (BitDefender) [COLOR=RED]Disabled[/COLOR] [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:TaskPanl" "C:\\Program Files\\America Online 9.0\\aol.exe"="C:\\Program Files\\America Online 9.0\\aol.exe:*:Enabled:America Online 9.0" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer" "C:\\Program Files\\Opera\\Opera.exe"="C:\\Program Files\\Opera\\Opera.exe:LocalSubNet:Enabled:Opera" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Bill Duke\Application Data CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=DUKE-A20MD19XF2 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Bill Duke LOGONSERVER=\\DUKE-A20MD19XF2 NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Common Files\GTK\2.0\bin PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 4 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0402 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\BILLDU~1\LOCALS~1\Temp TMP=C:\DOCUME~1\BILLDU~1\LOCALS~1\Temp USERDOMAIN=DUKE-A20MD19XF2 USERNAME=Bill Duke USERPROFILE=C:\Documents and Settings\Bill Duke windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Bill Duke [I](admin)[/I] Administrator [I](admin)[/I] Guest [I](new local, guest)[/I] -- Add/Remove Programs --------------------------------------------------------- --> "C:\Program Files\mcafee.com\personal firewall\aol\uninst.exe" /PopUpMsgBox="N" /CheckMutx="N" /S --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> MsiExec.exe /I{0CDCA5CD-C404-41FD-9216-9B4B3D24A7AA} --> MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Adobe Acrobat PDFWriter 3.03 --> C:\WINDOWS\uninst.exe -fC:\Acrobat3\DeIsL1.isu Adobe Atmosphere Player for Acrobat and Adobe Reader --> C:\WINDOWS\atmoUn.exe Adobe Photoshop CS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x9 Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7646-A00000000001} AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe Apple Mobile Device Support --> MsiExec.exe /I{8FC46258-0843-4D79-B7F0-F2B82FE6173B} Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4} Blaze Media Pro --> "C:\Documents and Settings\All Users\Application Data\{4C2CB1B6-C45E-4307-ACEE-27BE65138599}\setup_blazemp.exe" REMOVE=TRUE MODIFY=FALSE CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe" EarthLink Software --> "C:\Program Files\EarthLink TotalAccess\uninstll.exe" /W EarthLink Toolbar --> MsiExec.exe /X{B8C2A83F-20B0-49D9-BA2B-6495DD8639ED} Entriq MediaSphere 3.5.2.2 --> "C:\Program Files\Entriq\MediaSphere\unins000.exe" Final Draft 7 --> MsiExec.exe /I{78D62D17-D970-42DA-B8CF-5E5576293B33} FreeAgent Go Tools --> C:\Program Files\InstallShield Installation Information\{ECD43B7A-CB3B-4AF8-91F6-C460A575E411}\setup.exe -runfromtemp -l0x0409 GTK+ 2.10.13 runtime environment --> "C:\Program Files\Common Files\GTK\2.0\setup\unins000.exe" hp deskjet 5100 --> msiexec /x{15C165F1-1DAE-4476-AFB6-8723729B41E7} HP Image Zone 4.2 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat HP Software Update --> MsiExec.exe /X{64FC0C98-B035-4530-B15D-3D30610B6DF1} iPod for Windows 2006-01-10 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3D047C15-C859-45F7-81CE-F2681778069B} /l1033 iPod Updater 2004-08-06 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2F8C106A-7DFC-45DE-8006-F9145AADF1D8} /l1033 iTunes --> MsiExec.exe /I{85B90D8C-70F3-4E84-BD31-5E9489C0F9FB} J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030} Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft Text-to-Speech Engine 4.0 (English) --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTS.inf, Uninstall Microsoft Word 2000 --> MsiExec.exe /I{00170409-78E1-11D2-B60F-006097C998E7} MP3 Player Utilities --> MsiExec.exe /I{5BBFB0E4-2250-49C3-A8A3-65BE2197D13B} Opera 9.25 --> MsiExec.exe /X{C619B312-19F3-460A-9F7B-443248379F18} PaperPort 8.0 SE --> MsiExec.exe /I{AEF2D1F3-0696-11D5-8E6A-00C04F7FA234} QuickTime --> MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328} RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Registry Mechanic 6.0 --> "C:\Program Files\Registry Mechanic\unins000.exe" Safari --> MsiExec.exe /X{0CD7D421-C850-4271-8533-0269A3D39FAA} SBC Yahoo! Applications --> C:\PROGRA~1\Yahoo!\Common\uninstall.exe Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Sibelius Scorch (ActiveX Only) --> MsiExec.exe /I{C8E4455F-0F70-4DA2-A9F9-2D56C80E10AD} Sygate Personal Firewall --> MsiExec.exe /I{F34D9A5F-484A-4E31-A9D3-908CB265B289} The GIMP 2.2.17 --> "C:\Program Files\GIMP-2.0\unins000.exe" TotalAccess Smart Installer --> C:\Program Files\EarthLink\TotalAccess Smart Installer\UnSMI.exe Ultra iPod Movie Converter 3.2.0607 --> "C:\Program Files\Ultra iPod Movie Converter\unins000.exe" Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u Windows Installer Clean Up --> MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52} WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall -- Application Event Log ------------------------------------------------------- Event Record #/Type1975 / Error Event Submitted/Written: 02/18/2008 10:11:37 AM Event ID/Source: 1000 / Application Error Event Description: Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000. Processing media-specific event for [!ws!] Event Record #/Type1867 / Error Event Submitted/Written: 02/11/2008 02:42:22 PM Event ID/Source: 1002 / Application Hang Event Description: Hanging application Safari.exe, version 3.523.15.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Event Record #/Type1866 / Error Event Submitted/Written: 02/11/2008 02:42:21 PM Event ID/Source: 1002 / Application Hang Event Description: Hanging application Safari.exe, version 3.523.15.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Event Record #/Type1856 / Error Event Submitted/Written: 02/11/2008 01:06:23 PM Event ID/Source: 11704 / MsiInstaller Event Description: Product: Apple Software Update -- Error 1704. An installation for BitDefender Total Security 2008 is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes? Event Record #/Type1855 / Error Event Submitted/Written: 02/11/2008 01:06:23 PM Event ID/Source: 1013 / MsiInstaller Event Description: Product: Safari -- An installation for BitDefender Total Security 2008 is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes? -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type2892 / Error Event Submitted/Written: 02/18/2008 10:19:22 AM Event ID/Source: 31012 / ipnathlp Event Description: The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code. Event Record #/Type2890 / Error Event Submitted/Written: 02/18/2008 10:11:53 AM Event ID/Source: 31012 / ipnathlp Event Description: The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code. Event Record #/Type2889 / Error Event Submitted/Written: 02/18/2008 10:11:53 AM Event ID/Source: 31012 / ipnathlp Event Description: The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code. Event Record #/Type2883 / Error Event Submitted/Written: 02/18/2008 10:11:41 AM Event ID/Source: 31012 / ipnathlp Event Description: The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code. Event Record #/Type2879 / Error Event Submitted/Written: 02/18/2008 10:11:30 AM Event ID/Source: 7016 / Service Control Manager Event Description: The BrSplService service has reported an invalid current state 0. -- End of Deckard's System Scanner: finished at 2008-02-18 10:41:37 ------------