I am logged in with admin rights
DSS main:
Deckard's System Scanner v20071014.68
Run by Tharrick on 2008-01-15 18:42:20
Computer is in Safe Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
5: 2008-01-15 15:39:17 UTC - RP167 - Scheduled Checkpoint
4: 2008-01-14 08:12:05 UTC - RP166 - Removed GameSpy Comrade.
3: 2008-01-14 07:33:59 UTC - RP165 - Installed AVG 7.5
2: 2008-01-14 07:32:51 UTC - RP164 - Removed AVG 7.5
1: 2008-01-13 21:19:15 UTC - RP163 - Last known good configuration
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Tharrick.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:43:14, on 15/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Safe mode
Running processes:
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\Explorer.EXE
C:\Users\Tharrick\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Tharrick.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F3 - REG:win.ini: load=C:\Windows\system32\vtstu.exe
O1 - Hosts: ::1 localhost
O1 - Hosts: 207.210.93.28 game01.us.segaonline.jp
O1 - Hosts: 207.210.93.28 patch01.us.segaonline.jp
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {66864F97-6734-498F-A7FC-EDAC30BDC519} - C:\Windows\system32\vtstu.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\Windows\system32\zylgenpe.dll
O2 - BHO: (no name) - {ED3A9DB2-FB68-4C21-9B00-F3A404EE0B0E} - C:\Windows\system32\vtstu.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O20 - Winlogon Notify: zylgenpe - C:\Windows\SYSTEM32\zylgenpe.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\Windows\system32\drivers\CDAC11BA.EXE
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\Windows\system32\windows
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
--
End of file - 5099 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080114-220437-276 O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\jkhhh.dll,#1
backup-20080114-220437-359 F3 - REG:win.ini: load=C:\Windows\system32\vtstu.exe
backup-20080114-221438-684 O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\jkhhh.dll,#1
backup-20080114-221438-967 F3 - REG:win.ini: load=C:\Windows\system32\vtstu.exe
backup-20080114-224607-426 O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\Windows\system32\windows
backup-20080114-224607-509 F3 - REG:win.ini: load=C:\Windows\system32\vtstu.exe
backup-20080114-224940-178 F3 - REG:win.ini: load=C:\Windows\system32\vtstu.exe
backup-20080114-224940-364 O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\Windows\system32\windows
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S3 DNIMp50 (DNIMp50 NDIS Protocol Driver) - c:\windows\system32\drivers\dnimp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); >
S3 DNISp50 (DNISp50 NDIS Protocol Driver) - c:\windows\system32\drivers\dnisp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); >
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 C-DillaCdaC11BA - c:\windows\system32\drivers\cdac11ba.exe <Not Verified; C-Dilla Ltd; SafeCast Windows NT>
S3 MSControlService (Microsoft cache control) - c:\windows\system32\windows
S3 VundoFixSvc (VundoFix Service) - vundofixsvc.exe <Not Verified; Atribune.org; Vundofix Service>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2007-12-15 and 2008-01-15 -----------------------------
2008-01-15 13:31:25 8081 --a------ C:\Windows\system32\second.bat
2008-01-15 13:18:46 334336 --a------ C:\Windows\system32\vtstu.exe
2008-01-14 23:29:43 126976 --a------ C:\Windows\system32\zip.exe
2008-01-14 23:29:43 175616 --a------ C:\Windows\system32\strings.exe
2008-01-14 23:29:43 16384 --a------ C:\Windows\system32\restart.exe <Not Verified; WareSoft Software; restart>
2008-01-14 23:29:43 53248 --a------ C:\Windows\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-01-14 23:29:43 39184 --a------ C:\Windows\system32\Ntrights.exe
2008-01-14 23:29:43 11254 --a------ C:\Windows\system32\locate.com
2008-01-14 18:02:39 7168 --a------ C:\Windows\system32\windows
2008-01-14 17:42:41 7810 --ahs---- C:\Windows\system32\utstv.ini2
2008-01-14 08:02:29 24576 --a------ C:\Windows\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2008-01-14 07:46:31 330752 -----n--- C:\Windows\system32\vtstu.dll
2008-01-14 07:44:34 0 d-------- C:\VundoFix Backups
2008-01-14 07:20:45 163904 --a------ C:\Windows\system32\zylgenpe.dll
2008-01-14 07:20:45 163904 --a------ C:\Windows\system32\tiyahaih.dll
2008-01-14 07:17:50 0 d-------- C:\Program Files\Trend Micro
2008-01-13 21:13:27 39936 --a------ C:\Windows\system32\mljjjhf.dll
2008-01-12 13:29:01 0 d-------- C:\Program Files\Wizards of the Coast
2008-01-10 00:15:41 0 d-------- C:\Program Files\VRtainment
2008-01-09 21:15:41 0 d-------- C:\WebCam
2008-01-06 18:25:30 0 d-------- C:\Program Files\Fairy Dust
2008-01-06 18:24:24 304128 --a------ C:\Windows\IsUn0411.exe <Not Verified; InstallShield Software Corporation; InstallShield (r) unInstaller>
2008-01-06 18:24:22 0 -rahs---- C:\MSDOS.SYS
2008-01-06 18:24:22 0 -rahs---- C:\IO.SYS
2008-01-05 00:26:39 0 d-------- C:\Program Files\Citrus Alarm Clock
2008-01-04 23:05:54 0 d-------- C:\Program Files\Wireshark
2008-01-04 21:49:19 0 d-------- C:\Program Files\WinPcap
2008-01-04 21:49:09 0 d-------- C:\Program Files\Cain
2008-01-01 17:51:30 0 d-------- C:\Program Files\DOOM 3
2007-12-27 14:10:19 0 d-------- C:\Program Files\Electronic Arts
2007-12-27 13:40:28 0 d-------- C:\Windows\system32\URTTEMP
2007-12-27 13:38:49 669184 --a------ C:\Windows\system32\pbsvc.exe
2007-12-27 09:12:27 20480 --a------ C:\Windows\system32\drivers\DNISP50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); >
2007-12-27 09:12:27 21504 --a------ C:\Windows\system32\drivers\DNIMP50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); >
2007-12-26 18:42:54 0 d-------- C:\Program Files\NETGEAR
2007-12-24 17:22:05 0 d-------- C:\Program Files\Belkin
-- Find3M Report ---------------------------------------------------------------
2008-01-15 00:53:23 0 d-------- C:\Program Files\Steam
2008-01-14 08:08:41 0 d-------- C:\Program Files\Common Files\Steam
2008-01-14 07:32:28 0 d-------- C:\Program Files\DAEMON Tools
2008-01-09 19:33:37 0 d-------- C:\Program Files\Windows Mail
2008-01-09 19:33:36 0 d-------- C:\Program Files\Windows Sidebar
2008-01-05 10:38:24 0 d-------- C:\Documents and Settings\ReleaseEngineer.MACROVISION\Application Data\Macromedia
2008-01-01 18:40:57 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-27 09:51:57 0 d-------- C:\Program Files\Messenger Plus! Live
2007-12-27 09:51:55 0 d-------- C:\Program Files\MSN Messenger
2007-12-27 08:58:45 0 d-------- C:\Program Files\Minitab 15
2007-12-27 08:58:44 0 d-------- C:\Program Files\Guitar Pro 5
2007-12-27 08:58:44 0 d-------- C:\Program Files\DCrafter3
2007-12-26 18:42:38 0 d-------- C:\Program Files\Common Files\InstallShield
2007-12-11 19:06:09 0 d-------- C:\Program Files\Common Files
2007-11-29 17:35:55 0 d-------- C:\Program Files\Microsoft Works
2007-11-29 17:35:27 0 d-------- C:\Program Files\MSBuild
2007-11-29 17:33:57 0 d-------- C:\Program Files\Microsoft.NET
2007-11-29 17:32:21 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2007-11-20 07:33:55 0 d-------- C:\Program Files\Microsoft Games
2007-11-06 20:19:28 53299 --a------ C:\Windows\system32\pthreadVC.dll
2007-10-27 14:26:42 671 --a------ C:\Windows\mozver.dat
2007-10-20 21:49:31 174 --ahs---- C:\Program Files\desktop.ini
2007-10-20 17:50:27 0 --a------ C:\Windows\nsreg.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66864F97-6734-498F-A7FC-EDAC30BDC519}]
14/01/2008 07:46 330752 --------- C:\Windows\system32\vtstu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
14/01/2008 07:20 163904 --a------ C:\Windows\system32\zylgenpe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED3A9DB2-FB68-4C21-9B00-F3A404EE0B0E}]
14/01/2008 07:46 330752 --------- C:\Windows\system32\vtstu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [20/10/2007 21:35]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [11/09/2007 21:28]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [11/09/2007 21:28]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [11/09/2007 21:28]
"RTHDCPL"="RTHDCPL.EXE" [14/08/2006 06:00 C:\Windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [16/05/2006 10:04 C:\Windows\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [03/05/2005 10:43 C:\Windows\Alcmtr.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [15/01/2008 18:39]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [09/01/2008 10:41]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [02/11/2006 12:33]
"Steam"="C:\Program Files\Steam\Steam.exe" []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [14/11/2007 12:52:32]
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [27/12/2007 09:12:26]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{3F1CE1D3-7143-4BB1-80A3-0190A52CDF48}"= C:\Windows\system32\jkhhh.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zylgenpe]
zylgenpe.dll 14/01/2008 07:20 163904 C:\Windows\System32\zylgenpe.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\Windows\system32\vtstu
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{19391db4-7f5a-11dc-8c04-806e6f6e6963}]
AutoRun\command- J:\Setup\rsrc\Autorun.exe
dinstall\command- J:\Directx\dxsetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ab01299-a89e-11dc-be94-001558905760}]
AutoRun\command- H:\RavMon.exe
explore\Command- H:\RavMon.exe -e
open\Command- H:\RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51421a46-bac9-11dc-9b09-001558905760}]
AutoRun\command- J:\LaunchU3.exe -a
*Newly Created Service* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- Hosts -----------------------------------------------------------------------
207.210.93.28 game01.us.segaonline.jp
207.210.93.28 patch01.us.segaonline.jp
-- End of Deckard's System Scanner: finished at 2008-01-15 18:44:19 ------------
DSS extra:
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft® Windows Vista™ Ultimate (build 6000)
Architecture: X86; Language: English
CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 4600+
Percentage of Memory in Use: 14%
Physical Memory (total/avail): 3070.94 MiB / 2628.23 MiB
Pagefile Memory (total/avail): 6326.84 MiB / 6017.08 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1930 MiB
C: is Fixed (NTFS) - 465.76 GiB total, 333.56 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
I: is Removable (FAT32)
J: is CDROM (CDFS)
\\.\PHYSICALDRIVE0 - ST350083 0AS SCSI Disk Device - 465.76 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 465.76 GiB - C:
\\.\PHYSICALDRIVE1 - SanDisk U3 Cruzer Micro USB Device - 3.81 GiB - 1 partition
\PARTITION0 (bootable) - Unknown - 3.82 GiB - I:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
AS: AVG Anti-Spyware v7, 5, 1, 43 (GRISOFT s.r.o.)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
Disabled
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Tharrick\AppData\Roaming
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AMUN-RAII
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Tharrick
LOCALAPPDATA=C:\Users\Tharrick\AppData\Local
LOGONSERVER=\\AMUN-RAII
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4b02
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
SAFEBOOT_OPTION=MINIMAL
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Tharrick\AppData\Local\Temp
TMP=C:\Users\Tharrick\AppData\Local\Temp
USERDOMAIN=Amun-RaII
USERNAME=Tharrick
USERPROFILE=C:\Users\Tharrick
windir=C:\Windows
-- User Profiles ---------------------------------------------------------------
Tharrick
(admin)
L2MFIX
(new local, admin, net ready)
-- Add/Remove Programs ---------------------------------------------------------
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Cain & Abel v4.9.10 --> C:\PROGRA~1\Cain\UNINSTAL.EXE C:\PROGRA~1\Cain\Install.log
CapturePad 1.0 --> "C:\Program Files\VRtainment\CapturePad\unins000.exe"
CC Get MAC Address 2.3 --> "C:\CC Get MAC Address\unins000.exe"
CDisplay 1.8 --> "C:\Program Files\CDisplay\unins000.exe"
Citrus Alarm Clock 1.0.5 --> "C:\Program Files\Citrus Alarm Clock\unins000.exe"
Creative WebCam Live! Pro/Effects Driver (1.02.05.0506) --> C:\Windows\CtDrvIns.exe -uninstall -script VF0080.uns -unsext NT -plugin V0080Pin.dll -pluginres CtCamPin.crl
Crysis(R) --> MsiExec.exe /I{000E79B7-E725-4F01-870A-C12942B7F8E4}
Dawn Of War --> MsiExec.exe /X{83F12F73-D52E-40C0-93B1-463C311C4E17}
Dawn of War - Dark Crusade --> C:\Program Files\InstallShield Installation Information\{FF39FC01-819B-42E4-AE49-1968AF12DDD4}\setup.exe -runfromtemp -l0x0009 -removeonly
Dawn Of War - Winter Assault --> MsiExec.exe /X{DD8408E9-9421-484F-979D-DB6361E3E828}
Doom 3 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}
Dual-Core Optimizer --> MsiExec.exe /X{BCA02FAD-2C86-4C8C-A815-51C09F4E51FF}
Dungeon Crafter III (remove only) --> "C:\Program Files\DCrafter3\DC3Uninstall.exe"
E-Tools --> C:\Program Files\Wizards of the Coast\eTools\uninstall.exe
Guitar Pro 5.0 --> "C:\Program Files\Guitar Pro 5\unins000.exe"
Haali Media Splitter --> "C:\Program Files\Matroska Pack\haali\uninstall.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Matroska Pack --> C:\Program Files\Matroska Pack\uninstall.exe
Messenger Plus! Live --> "C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1 --> msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1 --> MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1 Hotfix (KB929729) --> "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp"
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007 --> MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Minitab 15 English --> MsiExec.exe /I{4AAC5AE8-EDE6-44D4-AA87-E90870178FDC}
Mozilla Firefox (2.0.0.11) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111 --> C:\Program Files\InstallShield Installation Information\{582E9125-32B6-4CBA-AB48-3E33CE3DB389}\setup.exe -runfromtemp -l0x0009 -removeonly
NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
Painkiller --> C:\Windows\unvise32.exe C:\Program Files\DreamCatcher\Painkiller\uninstal.log
Painkiller - Battle Out Of Hell --> C:\Windows\unvise32.exe c:\program files\dreamcatcher\painkiller\uninstal.log
Pen Tablet --> C:\Program Files\Tablet\Pen\Remove.exe /u
PHANTASY STAR ONLINE Blue Burst --> "C:\Program Files\SEGA\PHANTASY STAR ONLINE Blue Burst\uninst\unins000.exe"
PHANTASY STAR UNIVERSE --> "C:\Program Files\SEGA\PHANTASY STAR UNIVERSE\uninst\unins002.exe"
PunkBuster Services --> C:\Windows\system32\pbsvc.exe -u
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Stubbs the Zombie --> "C:\Program Files\Steam\steam.exe"
steam://uninstall/7800
SyncToy --> MsiExec.exe /I{B5688129-7595-4E5B-9990-CEF981A31264}
System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe
The Core Media Player 4.0 --> "C:\Program Files\CoreCodec\The Core Media Player\uninstall-tcmp4.exe"
Titan Quest --> "C:\Program Files\Steam\steam.exe"
steam://uninstall/4540
Titan Quest: Immortal Throne --> "C:\Program Files\Steam\steam.exe"
steam://uninstall/4550
Update for Outlook 2007 Junk Email Filter (kb943597) --> msiexec /package {90120000-0011-0000-0000-0000000FF1CE} /uninstall {A751F0DB-8476-4207-956E-20AEBBA4B1DA}
VideoLAN VLC media player 0.8.6c --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
WinPcap 4.0.2 --> C:\Program Files\WinPcap\uninstall.exe
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
Wireshark 0.99.7 --> "C:\Program Files\Wireshark\uninstall.exe"
-- Application Event Log -------------------------------------------------------
Event Record #/Type10114 / Error
Event Submitted/Written: 01/15/2008 06:41:55 PM
Event ID/Source: 4609 / EventSystem
Event Description:
d:\vistartm\com\complus\src\events\tier1\eventsystemobj.cpp458007043c
Event Record #/Type10111 / Warning
Event Submitted/Written: 01/15/2008 06:41:46 PM
Event ID/Source: 6000 / Wlclntfy
Event Description:
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.
Event Record #/Type10109 / Success
Event Submitted/Written: 01/15/2008 06:41:42 PM
Event ID/Source: 5617 / WinMgmt
Event Description:
Event Record #/Type10107 / Success
Event Submitted/Written: 01/15/2008 06:41:31 PM
Event ID/Source: 5615 / WinMgmt
Event Description:
Event Record #/Type10102 / Success
Event Submitted/Written: 01/15/2008 06:40:04 PM
Event ID/Source: 903 / Software Licensing Service
Event Description:
The Software Licensing service has stopped.
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type30656 / Error
Event Submitted/Written: 01/15/2008 06:42:56 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Network List ServiceNetwork Location Awareness%%1068
Event Record #/Type30655 / Error
Event Submitted/Written: 01/15/2008 06:42:56 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Network List ServiceNetwork Location Awareness%%1068
Event Record #/Type30653 / Error
Event Submitted/Written: 01/15/2008 06:42:56 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Network List ServiceNetwork Location Awareness%%1068
Event Record #/Type30652 / Error
Event Submitted/Written: 01/15/2008 06:42:56 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Network List ServiceNetwork Location Awareness%%1068
Event Record #/Type30651 / Error
Event Submitted/Written: 01/15/2008 06:42:56 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
AFD
AVG Anti-Spyware Driver
CSC
DfsC
NetBIOS
netbt
nsiproxy
PSched
RasAcd
rdbss
Smb
spldr
Tcpip
tdx
Wanarpv6
-- End of Deckard's System Scanner: finished at 2008-01-15 18:44:19 ------------