smittypig24

Members
  • Content Count

    4
  • Joined

  • Last visited

Posts posted by smittypig24

  1. Here it is...

    -------------------------------------------------------------------------------

    KASPERSKY ONLINE SCANNER REPORT

    Thursday, May 15, 2008 3:42:55 PM

    Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)

    Kaspersky Online Scanner version: 5.0.98.0

    Kaspersky Anti-Virus database last update: 15/05/2008

    Kaspersky Anti-Virus database records: 774093

    -------------------------------------------------------------------------------

    Scan Settings:

    Scan using the following antivirus database: extended

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    C:\

    D:\

    E:\

    Scan Statistics:

    Total number of scanned objects: 49181

    Number of viruses found: 0

    Number of infected objects: 0

    Number of suspicious objects: 0

    Duration of the scan process: 00:37:50

    Infected Object Name / Virus Name / Last Action

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

    C:\Documents and Settings\Matt Smith\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Matt Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Matt Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Matt Smith\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Matt Smith\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Matt Smith\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\Matt Smith\ntuser.dat.LOG Object is locked skipped

    C:\WINNT\CSC0000001 Object is locked skipped

    C:\WINNT\Debug\ipsecpa.log Object is locked skipped

    C:\WINNT\Debug\oakley.log Object is locked skipped

    C:\WINNT\Debug\PASSWD.LOG Object is locked skipped

    C:\WINNT\SchedLgU.Txt Object is locked skipped

    C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINNT\Sti_Trace.log Object is locked skipped

    C:\WINNT\system32\CatRoot\SYSMAST.cbd Object is locked skipped

    C:\WINNT\system32\CatRoot\SYSMAST.cbk Object is locked skipped

    C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbd Object is locked skipped

    C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbk Object is locked skipped

    C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINNT\system32\config\default Object is locked skipped

    C:\WINNT\system32\config\default.LOG Object is locked skipped

    C:\WINNT\system32\config\SAM Object is locked skipped

    C:\WINNT\system32\config\SAM.LOG Object is locked skipped

    C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINNT\system32\config\SECURITY Object is locked skipped

    C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINNT\system32\config\software Object is locked skipped

    C:\WINNT\system32\config\software.LOG Object is locked skipped

    C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINNT\system32\config\system Object is locked skipped

    C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped

    C:\WINNT\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  2. Thanks for helping. Here are the logs you requested.

    What's next?

    -Matt

    Deckard's System Scanner v20071014.68

    Run by Matt Smith on 2008-05-12 19:33:56

    Computer is in Normal Mode.

    --------------------------------------------------------------------------------

    Backed up registry hives.

    Performed disk cleanup.

    -- HijackThis (run as Matt Smith.exe) ------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 7:34:26 PM, on 5/12/2008

    Platform: Windows 2000 SP4 (WinNT 5.00.2195)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Boot mode: Normal

    Running processes:

    C:\WINNT\System32\smss.exe

    C:\WINNT\system32\winlogon.exe

    C:\WINNT\system32\services.exe

    C:\WINNT\system32\lsass.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\system32\spoolsv.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

    C:\WINNT\System32\svchost.exe

    C:\WINNT\system32\hidserv.exe

    C:\WINNT\system32\nvsvc32.exe

    C:\WINNT\system32\regsvc.exe

    C:\WINNT\system32\MSTask.exe

    C:\WINNT\system32\stisvc.exe

    C:\WINNT\System32\WBEM\WinMgmt.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\Explorer.EXE

    C:\Program Files\Creative\ShareDLL\CtNotify.exe

    C:\WINNT\Mixer.exe

    C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9TA.EXE

    C:\Program Files\Creative\ShareDLL\MediaDet.Exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINNT\system32\Rundll32.exe

    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

    C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe

    C:\Program Files\WinZip\WZQKPICK.EXE

    C:\Documents and Settings\Matt Smith\Desktop\dss.exe

    C:\PROGRA~1\TRENDM~1\HIJACK~1\Matt Smith.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nickjr.com/

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll (file missing)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe

    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

    O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O5 "LPT1:" /M "PictureMate"

    O4 - HKLM\..\Run: [EPSON PictureMate (Copy 1)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P26 "EPSON PictureMate (Copy 1)" /O5 "LPT1:" /M "PictureMate"

    O4 - HKLM\..\Run: [EPSON PictureMate Deluxe] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9TA.EXE /P24 "EPSON PictureMate Deluxe" /O6 "USB001" /M "PictureMate Deluxe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork

    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')

    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

    O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe

    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O16 - DPF: Yahoo! Cribbage - http://download2.games.yahoo.com/games/clients/y/it1_x.cab

    O16 - DPF: Yahoo! Spades - http://download2.games.yahoo.com/games/clients/y/st3_x.cab

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1168788609937

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1168789797390

    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab

    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

    --

    End of file - 6862 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R2 pmem - c:\winnt\system32\drivers\pmemnt.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>

    S3 NTSIM - c:\winnt\system32\ntsim.sys <Not Verified; VIA Networking, Inc.; Network Device Monitor Utility>

    S3 USB-100 (Linksys EtherFast 10/100 Compact USB Network Adapter) - c:\winnt\system32\drivers\usb100m.sys <Not Verified; Linksys; Linksys Compact USB Network Adapter>

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 AntiVirScheduler (Avira AntiVir Personal – Free Antivirus Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>

    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.

    -- Files created between 2008-04-12 and 2008-05-12 -----------------------------

    2008-05-12 19:02:46 0 d-------- C:\Program Files\Avira

    2008-05-12 19:02:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira

    2008-05-12 19:01:56 0 d-------- C:\Program Files\Java

    2008-05-12 19:01:55 0 d-------- C:\Program Files\Common Files\Java

    2008-05-12 19:01:46 0 d-------- C:\Documents and Settings\Matt Smith\Application Data\Sun

    2008-05-11 07:48:40 0 d-------- C:\Program Files\Trend Micro

    2008-05-10 15:21:10 0 d-------- C:\Documents and Settings\Matt Smith\.housecall6.6

    2008-05-10 11:12:52 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_1cc.dat

    -- Find3M Report ---------------------------------------------------------------

    2008-05-12 19:04:53 1288860 ---h----- C:\WINNT\ShellIconCache

    2008-05-12 19:01:55 0 d-a------ C:\Program Files\Common Files

    2008-04-21 20:40:05 0 d-------- C:\Program Files\World of Warcraft

    2008-04-21 01:31:20 0 d-------- C:\Program Files\Full Tilt Poker

    2008-03-26 01:43:02 0 d-------- C:\Documents and Settings\Matt Smith\Application Data\IGN_DLM

    2008-03-25 01:41:12 0 d-------- C:\Program Files\IGN

    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "Synchronization Manager"="mobsync.exe" [06/19/03 03:05p C:\WINNT\system32\mobsync.exe]

    "NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [08/02/04 09:03p]

    "nwiz"="nwiz.exe" [07/12/06 02:19p C:\WINNT\system32\nwiz.exe]

    "NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [07/12/06 02:19p]

    "Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [12/16/98 02:53a]

    "C-Media Mixer"="Mixer.exe" [07/12/02 04:33p C:\WINNT\mixer.exe]

    "EPSON PictureMate"="C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2P1.exe" [09/19/03 03:00a]

    "EPSON PictureMate (Copy 1)"="C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I0P1.exe" [10/10/03 03:00a]

    "EPSON PictureMate Deluxe"="C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9TA.exe" [10/17/04 03:00a]

    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06/05/07 09:55p]

    "P17Helper"="P17.dll" [05/03/05 07:38a C:\WINNT\system32\P17.dll]

    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/08 04:28a]

    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/08 10:06a]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/30/07 05:58p]

    "igndlm.exe"="C:\Program Files\IGN\Download Manager\DLM.exe" [03/05/07 02:57p]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]

    "^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [1/4/2008 10:56:43 PM]

    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [10/23/2006 1:48:20 AM]

    Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [10/23/2006 12:01:50 AM]

    EPSON CardMonitor.lnk - C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe [6/5/2007 9:53:08 PM]

    WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [1/15/2007 10:04:56 PM]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]

    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]

    @="Driver"

    *Newly Created Service* - SSMDRV

    -- End of Deckard's System Scanner: finished at 2008-05-12 19:35:10 ------------

    Deckard's System Scanner v20071014.68

    Extra logfile - please post this as an attachment with your post.

    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows 2000 Professional (build 2195) SP 4.0

    Architecture: X86; Language: English

    CPU 0: Intel® Pentium® 4 CPU 3.00GHz

    Percentage of Memory in Use: 25%

    Physical Memory (total/avail): 1023.48 MiB / 760.78 MiB

    Pagefile Memory (total/avail): 2462.56 MiB / 2215.49 MiB

    Virtual Memory (total/avail): 2047.88 MiB / 1960.26 MiB

    C: is Fixed (NTFS) - 189.9 GiB total, 167.61 GiB free.

    D: is CDROM (CDFS)

    E: is CDROM (CDFS)

    \\.\PHYSICALDRIVE0 - Maxtor 6Y200P0 - 128 GiB - 1 partition

    \PARTITION0 (bootable) - Installable File System - 189.9 GiB - C:

    -- Security Center -------------------------------------------------------------

    AUOptions is scheduled to auto-install.

    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users

    APPDATA=C:\Documents and Settings\Matt Smith\Application Data

    CommonProgramFiles=C:\Program Files\Common Files

    COMPUTERNAME=FRANK2

    ComSpec=C:\WINNT\system32\cmd.exe

    HOMEDRIVE=C:

    HOMEPATH=\Documents and Settings\Matt Smith

    LOGONSERVER=\\FRANK2

    NUMBER_OF_PROCESSORS=1

    OS=Windows_NT

    Os2LibPath=C:\WINNT\system32\os2\dll;

    Path=C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem

    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH

    PROCESSOR_ARCHITECTURE=x86

    PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 3, GenuineIntel

    PROCESSOR_LEVEL=15

    PROCESSOR_REVISION=0303

    ProgramFiles=C:\Program Files

    PROMPT=$P$G

    SystemDrive=C:

    SystemRoot=C:\WINNT

    TEMP=C:\DOCUME~1\MATTSM~1\LOCALS~1\Temp

    TMP=C:\DOCUME~1\MATTSM~1\LOCALS~1\Temp

    USERDOMAIN=FRANK2

    USERNAME=Matt Smith

    USERPROFILE=C:\Documents and Settings\Matt Smith

    windir=C:\WINNT

    -- User Profiles ---------------------------------------------------------------

    Matt Smith (admin)

    -- Add/Remove Programs ---------------------------------------------------------

    3D Groove Playback Engine --> RunDll32 C:\WINNT\DOWNLO~1\GrooveAX.dll,_RemoveGroove@16

    Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}

    Adobe Flash Player 9 ActiveX --> C:\WINNT\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete

    Adobe Photoshop 7.0 --> C:\WINNT\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"

    Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}

    Adobe Shockwave Player --> C:\WINNT\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINNT\system32\Macromed\SHOCKW~1\Install.log

    Age of Mythology --> "C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove

    Avira AntiVir Personal – Free Antivirus --> C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE

    BiAdmin --> C:\WINNT\IsUninst.exe -f"C:\Program Files\Print Server\Uninst.isu"

    Canon Camera TWAIN Driver 6.6 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3519A06E-33A4-4910-BB14-7BCE133BF46F} /l1033

    Cars - Radiator Springs Adventures --> "C:\Program Files\THQ\Disney-PIXAR\Cars\Radiator Springs Adventures\Uninstall_Cars - Radiator Springs Adventures\Uninstall Cars - Radiator Springs Adventures.exe"

    Creative Launcher --> C:\WINNT\CTDELLAU.EXE -[Creative Launcher

    Creative PlayCenter --> C:\WINNT\uninst.exe -f"C:\Program Files\Creative\PlayCenter\DeIsL2.isu"

    EPSON CardMonitor --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{109D28C7-FB38-483A-9C91-001CB59E2699}\Setup.exe" -l0x9 uninst

    EPSON PhotoStarter3.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5983C895-DDA4-45D9-A8D1-877D5DE7693E}\Setup.exe" uninst

    EPSON PictureMate Deluxe User's Guide --> C:\Program Files\epson\guide\picturemate_dlx_e\uninstall.exe

    EPSON Printer Software --> C:\WINNT\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R

    Film Factory --> C:\WINNT\IsUninst.exe -f"C:\Program Files\EPSON Software\Film Factory\Uninst.isu"

    Full Tilt Poker --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -l0x9 -removeonly

    Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"

    HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall

    IGN Download Manager 2.3.0 --> C:\Program Files\IGN\Download Manager\uninst.exe

    Java 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}

    Medal of Honor Pacific Assault --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\101\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}\Setup.exe" -l0x9 -removeonly

    Microsoft .NET Framework 1.1 --> msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

    Microsoft .NET Framework 1.1 --> MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

    Microsoft .NET Framework 1.1 Hotfix (KB928366) --> "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"

    Microsoft .NET Framework 2.0 Service Pack 1 --> MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}

    Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINNT\$NtUninstallbasecsp$\spuninst\spuninst.exe"

    Mozilla Firefox (2.0.0.9) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe

    MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}

    MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}

    MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}

    MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}

    NVIDIA Drivers --> C:\WINNT\system32\nvudisp.exe UninstallGUI

    PCI Audio Driver --> cmuninst.exe

    QuickTime --> C:\WINNT\unvise32qt.exe C:\WINNT\system32\QuickTime\Uninstall.log

    Reader Rabbit's Toddler --> C:\WINNT\IsUninst.exe -fC:\Tlcwin\Rrt\Uninst\DeIsL2.isu

    SCRABBLE --> C:\PROGRA~1\YAHOO!~1\Scrabble\UNWISE.EXE /U C:\PROGRA~1\YAHOO!~1\Scrabble\INSTALL.LOG

    Security Update for DirectX 9 (KB941568) --> "C:\WINNT\$NtUninstallKB941568_DX9$\spuninst\spuninst.exe"

    Security Update for Windows 2000 (KB904706) -->

    Security Update for Windows 2000 (KB923689) --> "C:\WINNT\$NtUninstallKB923689$\spuninst\spuninst.exe"

    Security Update for Windows 2000 (KB941569) --> "C:\WINNT\$NtUninstallKB941569$\spuninst\spuninst.exe"

    Sportsbook.com Poker --> C:\Program Files\Sportsbook Poker\uninstall.exe

    Ventrilo Client --> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}

    VIA Rhine-Family Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA

    Virtools 3D Life Player --> C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u

    Windows Media Player system update (9 Series) --> C:\PROGRA~1\WINDOW~2\setup_wm.exe /Uninstall

    WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall

    World of Warcraft --> C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe

    ZIP Reader 8.00.0018 --> MsiExec.exe /I{856C155E-4A74-4041-B026-04F96FFD1BCD}

    -- Application Event Log -------------------------------------------------------

    Event Record #/Type871 / Warning

    Event Submitted/Written: 05/12/2008 07:06:46 PM

    Event ID/Source: 35 / WinMgmt

    Event Description:

    WMI ADAP was unable to load the ASP.NET_2.0.50727 performance library because it returned invalid data: 0x0

    Event Record #/Type870 / Warning

    Event Submitted/Written: 05/12/2008 07:06:45 PM

    Event ID/Source: 35 / WinMgmt

    Event Description:

    WMI ADAP was unable to load the ASP.NET performance library because it returned invalid data: 0x0

    Event Record #/Type863 / Warning

    Event Submitted/Written: 05/10/2008 04:59:58 PM

    Event ID/Source: 35 / WinMgmt

    Event Description:

    WMI ADAP was unable to load the ASP.NET_2.0.50727 performance library because it returned invalid data: 0x0

    Event Record #/Type862 / Warning

    Event Submitted/Written: 05/10/2008 04:59:57 PM

    Event ID/Source: 35 / WinMgmt

    Event Description:

    WMI ADAP was unable to load the ASP.NET performance library because it returned invalid data: 0x0

    Event Record #/Type859 / Warning

    Event Submitted/Written: 05/09/2008 07:47:03 AM

    Event ID/Source: 35 / WinMgmt

    Event Description:

    WMI ADAP was unable to load the ASP.NET_2.0.50727 performance library because it returned invalid data: 0x0

    -- Security Event Log ----------------------------------------------------------

    No Errors/Warnings found.

    -- System Event Log ------------------------------------------------------------

    Event Record #/Type2024 / Error

    Event Submitted/Written: 05/12/2008 07:32:34 PM

    Event ID/Source: 10010 / DCOM

    Event Description:

    The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout.

    Event Record #/Type2023 / Error

    Event Submitted/Written: 05/12/2008 07:32:04 PM

    Event ID/Source: 10010 / DCOM

    Event Description:

    The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout.

    Event Record #/Type2022 / Error

    Event Submitted/Written: 05/12/2008 07:31:34 PM

    Event ID/Source: 10010 / DCOM

    Event Description:

    The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout.

    Event Record #/Type2016 / Error

    Event Submitted/Written: 05/12/2008 03:50:46 PM

    Event ID/Source: 10010 / DCOM

    Event Description:

    The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout.

    Event Record #/Type2015 / Error

    Event Submitted/Written: 05/12/2008 03:50:16 PM

    Event ID/Source: 10010 / DCOM

    Event Description:

    The server {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} did not register with DCOM within the required timeout.

    -- End of Deckard's System Scanner: finished at 2008-05-12 19:35:10 ------------

  3. Hello computer gurus,

    My computer has a problem. When I click the internet explorer button, it takes about a minute before it pops up to my homepage. Also, if my browser automatically opens a new window upon clicking on a link, it does the same thing. It seems like my browser is hijacked. Could you look at my log and tell me if you see anything bad in there? I did a recent adaware scan and housecall scan, but neither helped. This computer is primarily used for the internet (my 3yr to 6yr old kids play on kids sites) and world of warcraft. That's about it.

    Thanks in advance for your help! I'll be checking back every 15 mins or so as i'm desperate to get this fixed.

    -Matt

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 8:14:27 AM, on 5/11/2008

    Platform: Windows 2000 SP4 (WinNT 5.00.2195)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Boot mode: Normal

    Running processes:

    C:\WINNT\System32\smss.exe

    C:\WINNT\system32\winlogon.exe

    C:\WINNT\system32\services.exe

    C:\WINNT\system32\lsass.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\system32\spoolsv.exe

    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    C:\WINNT\System32\svchost.exe

    C:\WINNT\system32\hidserv.exe

    C:\WINNT\system32\nvsvc32.exe

    C:\WINNT\system32\regsvc.exe

    C:\WINNT\system32\MSTask.exe

    C:\WINNT\system32\stisvc.exe

    C:\WINNT\System32\WBEM\WinMgmt.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\Explorer.EXE

    C:\Program Files\Creative\ShareDLL\CtNotify.exe

    C:\WINNT\Mixer.exe

    C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9TA.EXE

    C:\Program Files\QuickTime\qttask.exe

    C:\WINNT\system32\Rundll32.exe

    C:\Program Files\Creative\ShareDLL\MediaDet.Exe

    C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe

    C:\Program Files\WinZip\WZQKPICK.EXE

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nickjr.com/

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll (file missing)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe

    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

    O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O5 "LPT1:" /M "PictureMate"

    O4 - HKLM\..\Run: [EPSON PictureMate (Copy 1)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P26 "EPSON PictureMate (Copy 1)" /O5 "LPT1:" /M "PictureMate"

    O4 - HKLM\..\Run: [EPSON PictureMate Deluxe] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9TA.EXE /P24 "EPSON PictureMate Deluxe" /O6 "USB001" /M "PictureMate Deluxe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork

    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')

    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

    O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe

    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

    O16 - DPF: Yahoo! Cribbage - http://download2.games.yahoo.com/games/clients/y/it1_x.cab

    O16 - DPF: Yahoo! Spades - http://download2.games.yahoo.com/games/clients/y/st3_x.cab

    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab

    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1168788609937

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1168789797390

    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab

    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exe

    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe

    --

    End of file - 5728 bytes