Greetings Silver!
Here's the stuff you requested for
|| Autoruns ||
cdoMicrosoft SharePoint Portal Server Object Model (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\pkmcdo.dll
0 File not found: About:Home
Web FoldersMicrosoft Web Folders (Not verified) Microsoft Corporation c:\program files\common files\microsoft shared\web folders\msonsext.dll
Symantec Drmc.jobSymantec Shared File (Not verified) Symantec Corporation c:\program files\common files\symantec shared\symdrmc.exe
Uniblue SpeedUpMyPC Nag.jobSpeedUpMyPC (Not verified) Uniblue Software d:\program files\uniblue\speedupmypc 3\speedupmypc.exe
Changer File not found: C:\WINDOWS\System32\Drivers\Changer.sys
i2omgmt File not found: C:\WINDOWS\System32\Drivers\i2omgmt.sys
lbrtfdc File not found: C:\WINDOWS\System32\Drivers\lbrtfdc.sys
MAPMEM c:\program files\checkit\diagnostics\mapmem.sys
PCIDump File not found: C:\WINDOWS\System32\Drivers\PCIDump.sys
PDCOMP File not found: C:\WINDOWS\System32\Drivers\PDCOMP.sys
PDFRAME File not found: C:\WINDOWS\System32\Drivers\PDFRAME.sys
PDRELI File not found: C:\WINDOWS\System32\Drivers\PDRELI.sys
PDRFRAME File not found: C:\WINDOWS\System32\Drivers\PDRFRAME.sys
WDICA File not found: C:\WINDOWS\System32\Drivers\WDICA.sys
apitrap.dllApitrap (Not verified) Symantec Corporation c:\windows\system32\apitrap.dll
|| DSS Main.txt ||
Deckard's System Scanner v20071014.68
Run by Ben on 2008-01-24 19:24:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-01-24 11:24:50 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Ben.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:52 PM, on 24-Jan-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\acer\epm\epm-dm.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\MediaSource\Detector\CTDetect.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
D:\Program Files\a-squared Free\a2service.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
D:\Program Files\Spyware Doctor\svcntaux.exe
D:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Ben\Desktop\dss.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Ben.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vcdplayx] "C:\WINDOWS\vcdplayx.exe"
O4 - HKLM\..\Run: [SDTray] "D:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Creative Detector] "D:\Program Files\MediaSource\Detector\CTDetect.exe" /R
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\PROGRA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - D:\PROGRA~1\FLASHD~1\iebt.dll (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windows ... 0431177000O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 0485742375O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/aol ... _en_dl.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{EE63B60B-82A8-4D01-9FF0-9268881D5D4F}: NameServer = 218.186.1.88,202.156.1.68
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - D:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Ad-Aware 2007\aawservice.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component AutorunsDisabled: (no name) - (no file)
--
End of file - 12021 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 GBDevice - c:\windows\system32\drivers\gbdevice.sys <Not Verified; Symantec Corporation; Norton GoBack>
R0 GoBack2K - c:\windows\system32\drivers\goback2k.sys <Not Verified; Symantec Corporation; Norton GoBack>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R2 BCMNTIO - c:\program files\checkit\diagnostics\bcmntio.sys
R2 BTSERIAL (Bluetooth Serial Driver) - c:\windows\system32\drivers\btserial.sys <Not Verified; WIDCOMM, Inc.; Bluetooth Software 3.0.1.904>
R2 BTSLBCSP (Bluetooth Port Client Driver) - c:\windows\system32\drivers\btslbcsp.sys <Not Verified; WIDCOMM, Inc.; Bluetooth Software 3.0.1.904>
R2 EpmPsd (Acer EPM Power Scheme Driver) - c:\windows\system32\drivers\epm-psd.sys <Not Verified; Acer Value Labs, USA; Acer EPM Power Scheme Driver>
R2 EpmShd (Acer EPM System Hardware Driver) - c:\windows\system32\drivers\epm-shd.sys <Not Verified; Acer Value Labs, USA; Acer EPM System Hardware Driver>
R2 GBFSHook - c:\windows\system32\drivers\gbfshook.sys <Not Verified; Symantec Corporation; Norton GoBack>
R2 osaio - c:\windows\system32\drivers\osaio.sys <Not Verified; Avocent/OSA Technologies Inc.; Windows (R) Server 2003 DDK driver>
R2 osanbm - c:\windows\system32\drivers\osanbm.sys <Not Verified; Windows (R) 2000 DDK provider; OSA int15 Driver>
R3 DKbFltr (Dritek HotKey Keyboard Filter Driver) - c:\windows\system32\drivers\dkbfltr.sys <Not Verified; Dritek System Inc.; Dritek Keyboard Filter>
R3 FsHotKey - c:\windows\system32\drivers\fshotkey.sys <Not Verified; Farstone Inc.; fshotkey>
S3 QDFSDRV - c:\windows\system32\drivers\qdfsdrv.sys <Not Verified; Symantec Corporation; Norton CleanSweep>
S3 SDdriver - c:\windows\system32\drivers\sddriver.sys <Not Verified; Symantec Corporation; Norton Speed Disk>
S4 MAPMEM - c:\program files\checkit\diagnostics\mapmem.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 anbmService (Notebook Manager Service) - c:\acer\emanager\anbmserv.exe <Not Verified; OSA Technologies Inc.; Acer eManager for Notebook>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E977-E325-11CE-BFC1-08002BE10318}
Description: Generic CardBus Controller
Device ID: PCI\VEN_104C&DEV_8031&SUBSYS_00661025&REV_00\4&1D3F0FBB&0&08F0
Manufacturer: Microsoft
Name: Texas Instruments PCIxx21/x515 Cardbus Controller
PNP Device ID: PCI\VEN_104C&DEV_8031&SUBSYS_00661025&REV_00\4&1D3F0FBB&0&08F0
Service: pcmcia
Class GUID: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
Description: Texas Instruments OHCI Compliant IEEE 1394 Host Controller
Device ID: PCI\VEN_104C&DEV_8032&SUBSYS_00661025&REV_00\4&1D3F0FBB&0&0AF0
Manufacturer: Texas Instruments
Name: Texas Instruments OHCI Compliant IEEE 1394 Host Controller
PNP Device ID: PCI\VEN_104C&DEV_8032&SUBSYS_00661025&REV_00\4&1D3F0FBB&0&0AF0
Service: ohci1394
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_00661025&REV_04\3&B1BFB68&0&F3
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_00661025&REV_04\3&B1BFB68&0&F3
Service:
Class GUID: {4D36E97B-E325-11CE-BFC1-08002BE10318}
Description: FarStone CDAWDM2001 SCSI Host Adapter
Device ID: ROOT\FARSTONE\0000
Manufacturer: Far Stone.
Name: FarStone CDAWDM2001 SCSI Host Adapter
PNP Device ID: ROOT\FARSTONE\0000
Service: CDAWDM
-- Scheduled Tasks -------------------------------------------------------------
2008-01-21 18:36:11 266 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
2008-01-21 18:36:11 304 --a------ C:\WINDOWS\Tasks\Symantec Drmc.job
2008-01-20 02:54:24 496 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Ben.job
2008-01-19 07:01:09 388 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
-- Files created between 2007-12-24 and 2008-01-24 -----------------------------
2008-01-23 21:57:34 0 dr-h----- C:\Documents and Settings\Ben\Recent
2008-01-23 21:49:55 0 d-------- C:\Documents and Settings\Ben\Application Data\vlc
2008-01-23 01:13:28 0 d-------- C:\WINDOWS\system32\Adobe
2008-01-22 23:12:59 0 d-------- C:\Program Files\mIRC
2008-01-22 23:12:59 0 d-------- C:\Documents and Settings\Ben\Application Data\mIRC
2008-01-22 17:55:43 25088 -----n--- C:\WINDOWS\system32\CTSVCCTL.EXE <Not Verified; Creative Technology Ltd; Creative Service Control>
2008-01-22 17:55:43 44032 -----n--- C:\WINDOWS\system32\CTSVCCDA.EXE <Not Verified; Creative Technology Ltd; Creative Service for CDROM Access>
2008-01-22 17:52:29 0 d-------- C:\Program Files\Creative
2008-01-22 17:45:06 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-01-21 13:48:37 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe <Not Verified; Sysinternals -
http://www.sysinternals.com; Page File Defragmenter>
2008-01-19 16:45:14 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-01-19 07:26:31 0 d-------- C:\Program Files\Common Files\DirectX
2008-01-19 07:25:50 0 d-------- C:\Documents and Settings\Ben\Application Data\FarStone
2008-01-19 07:23:45 5501 --a------ C:\WINDOWS\system32\rtclcmg32.dll
2008-01-19 07:20:01 0 d-------- C:\WINDOWS\system32\appmgmt
2008-01-18 02:10:41 0 d-------- C:\Documents and Settings\Ben\Application Data\Apple Computer
2008-01-18 02:08:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-18 02:08:06 0 d-------- C:\Program Files\Apple Software Update
2008-01-18 02:08:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-18 00:54:58 0 d-------- C:\WINDOWS\Sun
2008-01-18 00:54:58 0 d-------- C:\Documents and Settings\Ben\Application Data\Sun
2008-01-18 00:53:56 0 d-------- C:\Program Files\Java
2008-01-18 00:53:03 0 d-------- C:\Program Files\Common Files\Java
2008-01-18 00:41:34 0 d-------- C:\Documents and Settings\Ben\Application Data\Uniblue
2008-01-17 22:40:45 0 d-------- C:\Documents and Settings\Ben\Application Data\WinRAR
2008-01-17 22:30:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-17 22:29:17 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-17 00:47:33 24496 --a------ C:\Documents and Settings\Ben\Application Data\GDIPFONTCACHEV1.DAT
2008-01-17 00:11:03 0 d-------- C:\Documents and Settings\Ben\Contacts
2008-01-17 00:09:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-01-17 00:09:14 0 d-------- C:\Program Files\StuffPlug3
2008-01-17 00:06:13 0 d-------- C:\Documents and Settings\Ben\Application Data\Macromedia
2008-01-17 00:06:09 0 d-------- C:\Program Files\Messenger Plus! Live
2008-01-16 23:58:09 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-01-16 23:48:27 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-16 23:48:03 0 d-------- C:\Documents and Settings\Ben\Application Data\PC Tools
2008-01-16 23:27:13 0 d-------- C:\Documents and Settings\Ben\Application Data\Google
2008-01-16 23:27:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-01-16 23:24:30 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-16 23:24:02 0 d-------- C:\Program Files\Windows Live
2008-01-16 23:23:36 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-16 23:23:30 0 d-------- C:\Program Files\Google
2008-01-16 20:25:16 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-01-16 20:23:43 0 d-------- C:\WINDOWS\ShellNew
2008-01-16 20:18:57 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-16 12:11:19 0 d-------- C:\Program Files\MSXML 6.0
2008-01-16 12:08:22 0 d-------- C:\Program Files\Windows Media Connect 2
2008-01-16 12:06:47 0 d-------- C:\WINDOWS\system32\LogFiles
2008-01-16 12:06:47 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-16 11:41:45 0 d-------- C:\WINDOWS\network diagnostic
2008-01-16 11:35:13 0 d-------- C:\Program Files\MSBuild
2008-01-16 11:31:51 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-01-16 11:31:04 0 d-------- C:\Program Files\Reference Assemblies
2008-01-16 11:14:34 0 d--hs---- C:\WINDOWS\CSC
2008-01-16 10:27:03 0 d-------- C:\WINDOWS\RegisteredPackages
2008-01-16 09:35:03 0 d-------- C:\WINDOWS\system32\URTTemp
2008-01-16 09:18:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-01-16 07:02:15 0 d-------- C:\WINDOWS\system32\PreInstall
2008-01-16 07:02:14 0 d--h----- C:\WINDOWS\$hf_mig$
2008-01-16 05:06:49 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-01-16 05:05:26 0 d--hs---- C:\Documents and Settings\Ben\UserData
2008-01-16 01:15:18 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-01-16 01:13:30 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-01-16 01:13:14 0 d-------- C:\WINDOWS\Prefetch
2008-01-16 01:00:03 0 d-------- C:\WINDOWS\peernet
2008-01-16 01:00:01 0 d-------- C:\WINDOWS\provisioning
2008-01-16 00:55:55 0 d-------- C:\WINDOWS\ServicePackFiles
2008-01-16 00:49:12 0 d-------- C:\WINDOWS\EHome
2008-01-16 00:16:35 0 d-------- C:\Program Files\Norton Internet Security
2008-01-16 00:16:11 0 d-------- C:\Program Files\SymNetDrv
2008-01-15 23:45:58 0 d-------- C:\Program Files\Common Files\Smith Micro Shared
2008-01-15 23:45:56 0 d-------- C:\Program Files\CheckIt
2008-01-15 23:41:49 0 d-------- C:\Program Files\Norton SystemWorks
2008-01-15 23:41:09 0 d-------- C:\Documents and Settings\Ben\Application Data\Symantec
2008-01-15 23:41:01 0 d-------- C:\Program Files\Symantec
2008-01-15 23:40:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-15 23:40:43 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-15 21:28:25 0 d-------- C:\Documents and Settings\Ben\Application Data\AdobeUM
2008-01-15 21:27:27 0 d-------- C:\Documents and Settings\Ben\Application Data\Adobe
2008-01-15 21:27:26 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-15 21:27:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-01-15 21:25:11 0 d-------- C:\WINDOWS\Cache
2008-01-15 21:24:38 0 d-------- C:\Program Files\Acer Inc
2008-01-15 21:24:17 221258 --a------ C:\WINDOWS\system32\Epm-Po.dll <Not Verified; Acer Labs USA; EPM-PO Dynamic Link Library>
2008-01-15 21:24:17 78208 --a------ C:\WINDOWS\system32\drivers\epm-shd.sys <Not Verified; Acer Value Labs, USA; Acer EPM System Hardware Driver>
2008-01-15 21:24:17 4096 --a------ C:\WINDOWS\system32\drivers\epm-psd.sys <Not Verified; Acer Value Labs, USA; Acer EPM Power Scheme Driver>
2008-01-15 21:23:52 0 d-------- C:\Acer
2008-01-15 21:23:43 0 d-------- C:\WINDOWS\Downloaded Installations
2008-01-15 21:23:20 0 d-------- C:\Program Files\Launch Manager
2008-01-15 21:22:44 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-01-15 21:22:32 0 d-------- C:\Program Files\WIDCOMM
2008-01-15 21:21:54 0 d-------- C:\WINDOWS\tiinst
2008-01-15 21:20:35 1654784 --a------ C:\WINDOWS\system32\W29MLRES.DLL <Not Verified; Intel Corporation; Intel(R) PRO/Wireless 2915ABG Network Connection>
2008-01-15 21:16:20 0 d-------- C:\Program Files\Synaptics
2008-01-15 21:11:57 0 d-------- C:\Program Files\ATI Technologies
2008-01-15 21:01:51 0 d-------- C:\Program Files\Intel
2008-01-15 20:59:22 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-01-15 20:59:16 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-15 20:59:03 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-13 10:50:43 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-13 10:50:39 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-01-13 10:50:38 0 dr------- C:\Program Files
2008-01-13 10:50:38 0 d-------- C:\Program Files\Common Files
2008-01-13 10:50:05 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-01-13 10:50:05 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-01-13 10:50:05 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-01-13 10:50:05 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-01-13 10:50:05 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-01-13 10:50:05 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-01-13 10:50:05 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-01-13 10:50:05 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-01-13 10:50:05 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-01-13 10:50:05 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-01-13 10:50:05 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-01-13 10:50:05 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-01-13 10:50:05 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-01-13 10:50:05 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-01-13 10:50:05 0 dr------- C:\Documents and Settings\All Users\Documents
2008-01-13 10:50:05 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-01-13 10:49:51 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-01-13 10:49:51 0 d-------- C:\WINDOWS\system32\CatRoot
2008-01-13 10:49:46 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-01-13 10:49:46 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-01-13 10:49:45 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-01-13 10:49:45 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-01-13 10:49:26 0 d-------- C:\Documents and Settings
2008-01-13 10:42:41 0 d-------- C:\WINDOWS
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\WinSxS
2008-01-13 10:42:41 0 dr------- C:\WINDOWS\Web
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\twain_32
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\wins
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\wbem
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\usmt
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\spool
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\ShellExt
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\Setup
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\ras
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\oobe
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\npp
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\mui
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\inetsrv
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\IME
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\icsxml
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\ias
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\export
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\drivers
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-01-13 10:42:41 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\dhcp
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\config
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\3076
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\2052
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1054
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1042
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1041
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1037
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1033
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1031
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1028
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system32\1025
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\system
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\security
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Resources
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\repair
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\mui
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\msapps
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\msagent
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Media
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\java
2008-01-13 10:42:41 0 d--h----- C:\WINDOWS\inf
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\ime
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Help
2008-01-13 10:42:41 0 dr--s---- C:\WINDOWS\Fonts
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Driver Cache
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Debug
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Cursors
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Connection Wizard
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\Config
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\AppPatch
2008-01-13 10:42:41 0 d-------- C:\WINDOWS\addins
2008-01-13 07:50:34 0 d--hs---- C:\WINDOWS\Installer
2008-01-13 07:50:30 0 d-------- C:\Documents and Settings\Ben\Application Data\Identities
2008-01-13 07:50:19 0 d--h----- C:\Documents and Settings\Ben\Templates
2008-01-13 07:50:19 0 dr------- C:\Documents and Settings\Ben\Start Menu
2008-01-13 07:50:19 0 dr-h----- C:\Documents and Settings\Ben\SendTo
2008-01-13 07:50:19 0 d--h----- C:\Documents and Settings\Ben\PrintHood
2008-01-13 07:50:19 2621440 --a------ C:\Documents and Settings\Ben\NTUSER.DAT
2008-01-13 07:50:19 0 d--h----- C:\Documents and Settings\Ben\NetHood
2008-01-13 07:50:19 0 dr------- C:\Documents and Settings\Ben\My Documents
2008-01-13 07:50:19 0 d--h----- C:\Documents and Settings\Ben\Local Settings
2008-01-13 07:50:19 0 dr------- C:\Documents and Settings\Ben\Favorites
2008-01-13 07:50:19 0 d-------- C:\Documents and Settings\Ben\Desktop
2008-01-13 07:50:19 0 d--hs---- C:\Documents and Settings\Ben\Cookies
2008-01-13 07:50:19 0 dr-h----- C:\Documents and Settings\Ben\Application Data
2008-01-13 07:49:24 0 d--hs---- C:\System Volume Information
2008-01-13 07:49:21 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-01-13 07:49:21 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-01-13 07:49:21 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-01-13 07:49:21 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-01-13 07:49:21 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-01-13 07:49:20 233472 --a------ C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-01-13 07:49:20 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-01-13 07:49:20 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-01-13 07:49:20 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-01-13 07:49:20 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-01-13 07:46:16 0 d-------- C:\WINDOWS\system32\xircom
2008-01-13 07:46:16 0 d-------- C:\Program Files\microsoft frontpage
2008-01-13 07:46:03 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-01-13 07:45:56 0 -rahs---- C:\MSDOS.SYS
2008-01-13 07:45:56 0 -rahs---- C:\IO.SYS
2008-01-13 07:45:56 0 --a------ C:\CONFIG.SYS
2008-01-13 07:45:56 0 --a------ C:\AUTOEXEC.BAT
2008-01-13 07:45:03 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-01-13 07:44:52 0 dr------- C:\WINDOWS\Offline Web Pages
2008-01-13 07:44:52 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-01-13 07:44:26 0 d-------- C:\WINDOWS\srchasst
2008-01-13 07:44:18 0 d-------- C:\WINDOWS\system32\Macromed
2008-01-13 07:44:18 0 d-------- C:\WINDOWS\system32\DirectX
2008-01-13 07:44:01 0 d-------- C:\Program Files\Movie Maker
2008-01-13 07:43:25 0 d-------- C:\WINDOWS\system32\Restore
2008-01-13 07:43:18 0 d-------- C:\WINDOWS\PCHEALTH
2008-01-13 07:43:10 0 d---s---- C:\WINDOWS\Tasks
2008-01-13 07:43:05 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-13 07:42:34 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-01-13 07:42:13 0 d-------- C:\WINDOWS\Registration
2008-01-13 07:42:05 0 d--h----- C:\Program Files\WindowsUpdate
2008-01-13 07:42:04 0 d-------- C:\Program Files\Online Services
2008-01-13 07:41:58 0 d-------- C:\Program Files\Messenger
2008-01-13 07:41:45 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-13 07:41:34 0 d-------- C:\Program Files\Windows NT
2008-01-13 07:41:19 0 d-------- C:\WINDOWS\system32\MsDtc
2008-01-13 07:41:15 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2008-01-13 10:50:05 62 --ahs---- C:\Documents and Settings\Ben\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [03-Aug-04 10:32 PM]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [03-Aug-04 10:32 PM]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [03-Aug-04 10:32 PM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [08-Feb-05 09:05 PM]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [08-Oct-04 02:44 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [08-Oct-04 02:43 PM]
"LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [28-Mar-05 12:20 PM]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [28-Mar-05 06:04 PM]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [24-Mar-05 09:13 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08-Jan-07 05:03 PM]
"QD FastAndSafe"="" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [16-Jan-08 01:24 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25-Sep-07 01:11 AM]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [10-Jan-08 03:27 PM]
"vcdplayx"="C:\WINDOWS\vcdplayx.exe" [04-Jan-02 03:47 PM]
"@"="" []
"SDTray"="D:\Program Files\Spyware Doctor\SDTrayApp.exe" [02-Oct-07 04:27 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04-Aug-04 12:56 AM]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [10-Sep-04 10:12 AM]
"Creative Detector"="D:\Program Files\MediaSource\Detector\CTDetect.exe" [02-Dec-04 06:23 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [25-May-04 3:38:42 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13-Feb-01 1:01:04 AM]
Norton GoBack.lnk - C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe [21-Dec-04 10:19:00 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\AUTORUN.EXE
-- End of Deckard's System Scanner: finished at 2008-01-24 19:27:50 ------------
|| DSS Extra.txt ||
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) M processor 1.73GHz
Percentage of Memory in Use: 46%
Physical Memory (total/avail): 1021.99 MiB / 551.55 MiB
Pagefile Memory (total/avail): 3071.08 MiB / 2485.08 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1904.03 MiB
C: is Fixed (NTFS) - 20 GiB total, 4 GiB free.
D: is Fixed (NTFS) - 54.53 GiB total, 24.76 GiB free.
E: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - IC25N080ATMR04-0 - 74.53 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 20 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 54.53 GiB - D:
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
Windows Internal Firewall is disabled.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
FW: Norton Internet Security v2005 (Symantec Corporation)
AV: Norton Internet Security v2005 (Symantec Corporation)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"D:\\Program Files\\mIRC\\mirc.exe"="D:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Ben\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SILVER-ARROW
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Ben
LOGONSERVER=\\SILVER-ARROW
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;D:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0d08
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Ben\LOCALS~1\Temp
TMP=C:\DOCUME~1\Ben\LOCALS~1\Temp
USERDOMAIN=SILVER-ARROW
USERNAME=Ben
USERPROFILE=C:\Documents and Settings\Ben
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Ben
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9 /remove
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\setup.exe" -l0x9
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DAAC5938-8026-4D0C-A476-D1954917B7F5}\setup.exe" -l0x9 /remove
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
a-squared Free 3.1 --> "D:\Program Files\a-squared Free\unins000.exe"
Acer eManager for Notebook --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{827289F5-B44F-4E49-9993-840741585A62}
Acer ePowerManagement --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58E5844B-7CE2-413D-83D1-99294BF6C74F}\Setup.exe" -l0x9
Acer GridVista --> C:\WINDOWS\UnInst32.exe GridV.UNI
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 6.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-000000000001}
Adobe SVG Viewer 3.0 --> C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
Advanced GIF Animator 2.22 --> "D:\Program Files\Advanced GIF Animator\unins000.exe"
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver --> rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
CC_ccProxyExt --> MsiExec.exe /I{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919}
ccCommon --> MsiExec.exe /I{D8F6834B-D5E7-4451-8681-B051ABD8561D}
ccCommon --> MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
ccPxyCore --> MsiExec.exe /I{FC08587A-4F01-4188-819F-F55880022917}
CheckIt Diagnostics --> C:\PROGRA~1\CheckIt\DIAGNO~1\UNWISE.EXE C:\PROGRA~1\CheckIt\DIAGNO~1\INSTALL.LOG
Conexant AC-Link Audio --> CIAunwdm.exe
Counter-Strike: Condition Zero --> D:\CONDIT~1\UNWISE.EXE D:\CONDIT~1\INSTALL.LOG
Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}\setup.exe" -l0x9 /remove
Flash Decompiler --> "D:\Program Files\Flash Decompiler\unins000.exe"
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
HijackThis 2.0.2 --> "D:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
Intel(R) PROSet/Wireless Software --> C:\WINDOWS\Installer\iProInst.exe
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Launch Manager --> C:\WINDOWS\UnInst32.exe QtZgAcer.UNI
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
LiveUpdate 3.0 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
mDriver --> MsiExec.exe /I{28DA872A-0848-48CF-B749-19A198157A2A}
Messenger Plus! Live --> "C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
mIRC --> C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
MSRedist --> MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
MSRedist --> MsiExec.exe /I{D1725BDB-BA2B-4503-A8CB-F5C835D743FA}
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Norton AntiSpam --> MsiExec.exe /I{3B29A786-5803-4e9e-9B58-3014A5B4E519}
Norton AntiSpam --> MsiExec.exe /I{5677563D-0CB1-485f-9E18-C5025306BB3F}
Norton AntiVirus 2005 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
Norton CleanSweep --> MsiExec.exe /I{634B01DF-A45B-4623-80E1-E15FF82A4979}
Norton GoBack 4.02 (Symantec Corporation) --> MsiExec.exe /I{1F76ACFA-22FE-49F6-BC05-F4EC835F48CC}
Norton Internet Security --> MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
Norton Internet Security --> MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
Norton Internet Security --> MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
Norton Internet Security --> MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
Norton Internet Security --> MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Internet Security --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Norton Internet Security --> MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
Norton Internet Security 2005 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe /X
Norton SystemWorks --> MsiExec.exe /I{9E23C48E-5483-4971-BA50-089F2FABCD66}
Norton SystemWorks 2005 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{71E7B3F5-CFAF-4C1E-B494-528E28707937}.exe /X
Norton Utilities --> MsiExec.exe /I{6A7867BA-B7CA-4CC9-ACAB-85BA46865EE5}
Norton WMI Update --> MsiExec.exe /X{E85FA9A1-C241-4698-893B-DD99509B8DB0}
Norton WMI Update --> MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
NSW_DRM_COLLECTION --> MsiExec.exe /I{900B1884-2D6F-4a70-A3C7-C3F4DA873FDB}
PowerISO --> "D:\Program Files\PowerISO\uninstall.exe"
QuickTime --> MsiExec.exe /I{6EC874C2-F950-4B7E-A5B7-B1066D6B74AA}
Registry Mechanic 7.0 --> "D:\Program Files\Registry Mechanic\unins000.exe"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SPBBC --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Spyware Doctor 5.1 --> D:\Program Files\Spyware Doctor\unins000.exe /LOG
StuffPlug 3 --> C:\Program Files\StuffPlug3\Uninstall.exe
Symantec Script Blocking Installer --> MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
SymNet --> MsiExec.exe /I{3AE089E4-6EAA-4527-A013-648D8EAAB8D2}
Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Texas Instruments PCIxx21/x515 drivers. --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8E50332B-772C-4AEA-BF56-94DE6A1D5F10} /l1033
Uniblue RegistryBooster 2 --> "D:\Program Files\Uniblue\RegistryBooster 2\unins000.exe"
Uniblue SpeedUpMyPC 3 --> "D:\Program Files\Uniblue\SpeedUpMyPC 3\unins000.exe"
VideoLAN VLC media player 0.8.6d --> D:\Program Files\VLC\uninstall.exe
VirtualDrive --> "D:\Program Files\VirtualDrive\Setup.exe"
WIDCOMM Bluetooth Software --> MsiExec.exe /X{90535871-81B9-4D99-8A13-A7EE97F2D7FE}
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
WinRAR archiver --> D:\Program Files\WinRAR\uninstall.exe
XML Paper Specification Shared Components Pack 1.0 -->
-- Application Event Log -------------------------------------------------------
Event Record #/Type1714 / Success
Event Submitted/Written: 01/24/2008 07:07:01 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type1623 / Success
Event Submitted/Written: 01/23/2008 10:12:44 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type1583 / Success
Event Submitted/Written: 01/22/2008 10:20:20 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type1413 / Success
Event Submitted/Written: 01/22/2008 01:07:03 AM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type1389 / Error
Event Submitted/Written: 01/22/2008 00:40:23 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application ccapp.exe, version 103.5.10.3, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00011f52.
Processing media-specific event for [ccapp.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type2263 / Warning
Event Submitted/Written: 01/24/2008 02:47:43 AM
Event ID/Source: 4 / b57w2k
Event Description:
Broadcom NetXtreme Gigabit Ethernet: The network link is down. Check to make sure the network cable is properly connected.
Event Record #/Type2259 / Warning
Event Submitted/Written: 01/23/2008 11:50:26 PM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.
Event Record #/Type2195 / Error
Event Submitted/Written: 01/23/2008 03:42:52 AM
Event ID/Source: 10010 / DCOM
Event Description:
The server {F3A614DC-ABE0-11D2-A441-00C04F795683} did not register with DCOM within the required timeout.
Event Record #/Type2128 / Warning
Event Submitted/Written: 01/20/2008 09:32:44 PM / 01/20/2008 09:33:41 PM
Event ID/Source: 4 / b57w2k
Event Description:
Broadcom NetXtreme Gigabit Ethernet: The network link is down. Check to make sure the network cable is properly connected.
Event Record #/Type2120 / Warning
Event Submitted/Written: 01/20/2008 05:07:03 PM
Event ID/Source: 4 / b57w2k
Event Description:
Broadcom NetXtreme Gigabit Ethernet: The network link is down. Check to make sure the network cable is properly connected.
-- End of Deckard's System Scanner: finished at 2008-01-24 19:27:50 ------------
I have also been noting a few quirks.. my firewall, Norton Internet Security, has been consistently detecting both inbound and outbound traffic mostly from my router (192.168.1.1) to my computer (192.168.1.50). These appear about a minute after I login. Funny thing is, the ports used are always random.
I've extracted some entries from norton's log. These were taken from the 21st Jan to 23rd Jan.
|| Firewall Log (extract) ||
21-Jan-08 12:35:59 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (localhost,1044).
Remote address,service is (SILVER-ARROW(192.168.1.50),1044).
Process name is "N/A".
21-Jan-08 5:03:33 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (localhost,1044).
Remote address,service is (SILVER-ARROW(192.168.1.50),1044).
Process name is "N/A".
21-Jan-08 5:04:40 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (SILVER-ARROW(192.168.1.50),41746).
Remote address,service is (192.168.1.1,ssdp(1900)).
Process name is "N/A".
21-Jan-08 10:02:32 PM
This one time, the user has chosen to "block" communications.
Inbound TCP connection.
Local address,service is (SILVER-ARROW(192.168.1.50),2027).
Remote address,service is (59.189.154.105,1232).
Process name is "N/A".
21-Jan-08 10:02:36 PM
This one time, the user has chosen to "block" communications.
Inbound TCP connection.
Local address,service is (SILVER-ARROW(192.168.1.50),2040).
Remote address,service is (218.212.12.194,4615).
Process name is "N/A".
22-Jan-08 1:07:15 AM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (SILVER-ARROW(192.168.1.50),39700).
Remote address,service is (192.168.1.1,ssdp(1900)).
Process name is "N/A".
22-Jan-08 2:05:56 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (localhost,4513).
Remote address,service is (SILVER-ARROW(192.168.1.50),4513).
Process name is "N/A".
22-Jan-08 2:06:05 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (SILVER-ARROW(192.168.1.50),58698).
Remote address,service is (192.168.1.1,ssdp(1900)).
Process name is "N/A".
23-Jan-08 10:12:20 AM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (localhost,1039).
Remote address,service is (SILVER-ARROW(192.168.1.50),1039).
Process name is "N/A".
23-Jan-08 2:49:45 PM
This one time, the user has chosen to "block" communications.
Inbound TCP connection.
Local address,service is (SILVER-ARROW(192.168.1.50),40433).
Remote address,service is (210.72.227.170,32429).
Process name is "N/A".
23-Jan-08 4:49:17 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (SILVER-ARROW(192.168.1.50),42737).
Remote address,service is (192.168.1.1,ssdp(1900)).
Process name is "N/A".
23-Jan-08 9:14:20 PM
This one time, the user has chosen to "block" communications.
Inbound UDP packet.
Local address,service is (SILVER-ARROW(192.168.1.50),44071).
Remote address,service is (192.168.1.1,ssdp(1900)).
Process name is "N/A".
Yup yup.. thanks so much for helping!
(note: I noticed that DSS turned System Restore back on, I have had bad experiences with System Restore and actually use Norton Goback for recovery purposes. Do let me know when I can disable System Restore again, its eating up disk space!!)