Office 2003 Won't Uninstall
My PC Hell Forum
November 22, 2008, 08:44:17 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Moving to New Location Soon! Watch out for notification. 14th Dec 2007.
 
   Home   Help Search Calendar Login Register  
Pages: [1] 2 3
  Print  
Author Topic: Office 2003 Won't Uninstall  (Read 2430 times)
Kabith
Rising Star
***
Posts: 109



View Profile
« on: April 13, 2008, 10:22:34 AM »

Distress Signal to Essexboy. My dad's comp is nuts. MS Office 2003 is not uninstalling. I want to upgrade it. Another problem is that limewire is hanging far too often. It is supposed to be a fast comp. Recently, when I was playing a game, the computer just switched off. The nest thing i see is bios and a startup, there was a message saying that the computer has recovered from a serious damage. What do I do?
Logged

Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #1 on: April 13, 2008, 10:28:20 AM »

Hi Kabith I hear you 

Run this on your dads system - and I will see if there is anything that jumps out.  Have you considered overheating problems as that will cause re-boots (although they will rarely give that warning )

 Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt  -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #2 on: April 13, 2008, 11:00:24 AM »

Here is main.txt.
Deckard's System Scanner v20071014.68
Run by winxp on 2008-04-13 17:46:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
64: 2008-04-13 14:46:51 UTC - RP64 - Deckard's System Scanner Restore Point
63: 2008-04-13 14:32:17 UTC - RP63 - Software Distribution Service 3.0
62: 2008-04-13 11:24:41 UTC - RP62 - Software Distribution Service 3.0
61: 2008-04-13 08:14:51 UTC - RP61 - Software Distribution Service 3.0
60: 2008-04-13 07:42:21 UTC - RP60 - Installed Windows Live


-- First Restore Point --
1: 2008-03-11 22:07:40 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as winxp.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:47:23 PM, on 4/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nakido\nakido.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Documents and Settings\winxp\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\winxp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1561552
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE 4.x-6.x BHO for Internet Download Accelerator - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - C:\PROGRA~1\IDA\idaiehlp.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: IDA Bar - {C70E30C7-140A-4166-A2E8-43557E62B41A} - C:\Program Files\IDA\idabar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Arovax AntiSpyware] C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe /s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Download ALL with IDA - C:\Program Files\IDA\idaieall.htm
O8 - Extra context menu item: Download with IDA - C:\Program Files\IDA\idaie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207814076734
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Nakido - Nakido - C:\Program Files\Nakido\nakido.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 7931 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080410-100708-521 O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R3 tapvpn (TAP VPN Adapter) - c:\windows\system32\drivers\tapvpn.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>

S3 catchme - c:\docume~1\winxp\locals~1\temp\catchme.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Nakido - c:\program files\nakido\nakido.exe <Not Verified; Nakido; Nakido>

S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {36FC9E60-C465-11CF-8056-444553540000}
Description: USB Mass Storage Device
Device ID: USB\VID_04CF&PID_8819\100
Manufacturer: Compatible USB storage device
Name: USB Mass Storage Device
PNP Device ID: USB\VID_04CF&PID_8819\100
Service: USBSTOR


-- Scheduled Tasks -------------------------------------------------------------

2008-04-13 17:00:00       486 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job


Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #3 on: April 13, 2008, 11:01:45 AM »

-- Files created between 2008-03-13 and 2008-04-13 -----------------------------

2008-04-13 17:38:13         0 d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-13 17:37:50         0 d-------- C:\Documents and Settings\winxp\Application Data\GRETECH
2008-04-13 17:37:38         0 d-------- C:\Program Files\GRETECH
2008-04-13 17:33:45         0 d-------- C:\WINDOWS\network diagnostic
2008-04-13 17:25:32         0 d-------- C:\WINDOWS\LastGood
2008-04-13 17:10:49      3840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2008-04-13 17:10:49         0 d-------- C:\Program Files\Belarc
2008-04-13 16:50:04         0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-13 14:05:10         0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-13 10:34:04         0 d-------- C:\Program Files\Hotspot Shield
2008-04-13 09:26:38         0 d-------- C:\Documents and Settings\winxp\Application Data\Malwarebytes
2008-04-13 09:26:34         0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-13 09:26:33         0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 18:09:04         0 d-------- C:\Program Files\Conduit
2008-04-12 18:09:03         0 d-------- C:\Program Files\Hotspot_Shield
2008-04-12 16:37:36     68096 --a------ C:\WINDOWS\zip.exe
2008-04-12 16:37:36     49152 --a------ C:\WINDOWS\VFind.exe
2008-04-12 16:37:36    136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-12 16:37:36    161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-12 16:37:36     98816 --a------ C:\WINDOWS\sed.exe
2008-04-12 16:37:36     80412 --a------ C:\WINDOWS\grep.exe
2008-04-12 16:37:36     73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-12 16:37:35    212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-11 19:25:43         0 d-------- C:\Program Files\Wise Registry Cleaner 3
2008-04-11 19:23:50         0 d-------- C:\Program Files\Wise Disk Cleaner
2008-04-11 18:53:41         0 d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-04-11 18:40:55         0 dr-h----- C:\Documents and Settings\winxp\Recent
2008-04-11 09:49:29         0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-11 09:49:19         0 d-------- C:\Program Files\Windows Live
2008-04-11 09:49:12         0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-11 08:43:55         0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-04-11 08:37:52         0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-11 08:36:58         0 d-------- C:\WINDOWS\system32\LogFiles
2008-04-11 08:36:58         0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-10 14:55:29         0 d-------- C:\Program Files\VS Revo Group
2008-04-10 14:41:43         0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-10 14:24:43         0 d-------- C:\Program Files\Microsoft Silverlight
2008-04-10 13:53:20         0 d-------- C:\Documents and Settings\winxp\Application Data\TuneUp Software
2008-04-10 13:53:08         0 d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-04-10 13:53:03         0 d-------- C:\Program Files\TuneUp Utilities 2008
2008-04-10 13:52:49         0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-10 13:37:58         0 d-------- C:\Documents and Settings\winxp\Phone Browser
2008-04-10 13:22:41         0 d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2008-04-10 13:20:26         0 d-------- C:\Documents and Settings\winxp\Application Data\Nokia
2008-04-10 13:19:53         0 d-------- C:\Program Files\Common Files\PCSuite
2008-04-10 13:19:52         0 d-------- C:\Program Files\Common Files\Nokia
2008-04-10 13:19:44         0 d-------- C:\Program Files\DIFX
2008-04-10 13:19:42         0 d-------- C:\Documents and Settings\winxp\Application Data\PC Suite
2008-04-10 13:19:35         0 d-------- C:\Program Files\PC Connectivity Solution
2008-04-10 13:19:28         0 d-------- C:\Program Files\Nokia
2008-04-10 13:16:52         0 d-------- C:\Documents and Settings\All Users\Application Data\Installations
2008-04-10 12:48:26         0 d-------- C:\WINDOWS\system32\PreInstall
2008-04-10 12:48:23         0 d--h----- C:\WINDOWS\$hf_mig$
2008-04-10 12:44:53         0 d-------- C:\Documents and Settings\winxp\Application Data\Auslogics
2008-04-10 12:44:50         0 d-------- C:\Program Files\Auslogics
2008-04-10 12:42:47         0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-10 12:37:32    610304 --a------ C:\WINDOWS\uninstall-temp.exe <Not Verified; Auralis, Inc.; Auralis, Inc. Webshots32>
2008-04-10 12:26:02         0 d-------- C:\Program Files\Nakido
2008-04-10 11:25:46         0 d-------- C:\Program Files\CCleaner
2008-04-10 11:12:33         0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-04-10 11:10:50         0 d-------- C:\WINDOWS\Sun
2008-04-10 11:10:50         0 d-------- C:\Documents and Settings\winxp\Application Data\Sun
2008-04-10 10:06:35         0 d-------- C:\Program Files\Trend Micro
2008-04-10 10:04:30         0 d-------- C:\Program Files\SpywareBlaster
2008-04-10 09:56:36         0 d-------- C:\Documents and Settings\All Users\Application Data\Arovax
2008-04-10 09:56:35         0 d-------- C:\Program Files\Arovax AntiSpyware
2008-04-10 09:26:44         0 d-------- C:\Documents and Settings\winxp\Application Data\Help
2008-04-10 09:07:45         0 d-------- C:\Documents and Settings\winxp\Application Data\LimeWire
2008-04-10 09:07:05         0 d-------- C:\Program Files\LimeWire
2008-04-10 08:38:25         0 d-------- C:\Documents and Settings\winxp\Application Data\SiteAdvisor
2008-04-10 08:38:25         0 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-10 08:38:25         0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-10 08:36:34         0 d-------- C:\Downloads
2008-04-10 08:36:25         0 d-------- C:\Documents and Settings\winxp\Application Data\Internet Download Accelerator
2008-04-10 08:36:16         0 d-------- C:\Program Files\IDA
2008-04-10 08:26:23         0 d-------- C:\Documents and Settings\winxp\Application Data\Talkback
2008-04-10 08:26:13         0 --a------ C:\WINDOWS\nsreg.dat
2008-04-10 08:26:08         0 d-------- C:\Documents and Settings\winxp\Application Data\Mozilla
2008-04-10 07:36:36         0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-03-27 16:22:04         0 d-------- C:\Documents and Settings\winxp\Application Data\Adobe
2008-03-24 23:35:11         0 d-------- C:\Documents and Settings\winxp\Application Data\CyberLink
2008-03-19 13:35:41         0 d-------- C:\Documents and Settings\winxp\Application Data\Google
2008-03-19 00:02:49         0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-03-18 23:55:20         0 d-------- C:\Program Files\Google
2008-03-17 23:17:05         0 d-------- C:\Documents and Settings\winxp\Contacts
2008-03-17 23:11:00         0 d-------- C:\Documents and Settings\winxp\Application Data\Macromedia
2008-03-17 23:07:18         0 d-------- C:\Program Files\KSAFone
2008-03-16 00:13:38      4096 --a------ C:\WINDOWS\d3dx.dat
2008-03-16 00:13:35         0 d-------- C:\Documents and Settings\winxp\Application Data\Wildfire
2008-03-15 07:57:29         0 d--hs---- C:\Documents and Settings\winxp\UserData
2008-03-15 00:01:12         0 d-------- C:\Documents and Settings\winxp\Application Data\vlc
2008-03-13 05:38:28     27136 --a------ C:\WINDOWS\system32\drivers\tapvpn.sys <Not Verified; The OpenVPN Project; TAP-Win32 Virtual Network Driver>


-- Find3M Report ---------------------------------------------------------------

2008-04-13 16:51:12         0 d-------- C:\Program Files\Common Files
2008-04-12 19:49:40         0 d-------- C:\Program Files\Messenger
2008-04-11 07:58:29      5649 --a------ C:\Documents and Settings\winxp\Application Data\NMM-MetaData.db
2008-04-10 12:37:40         0 d-------- C:\Program Files\Webshots
2008-04-10 11:25:51         0 d-------- C:\Program Files\Yahoo!
2008-03-29 00:01:36         0 d-------- C:\Program Files\JetAudio
2008-03-29 00:01:36         0 d-------- C:\Documents and Settings\winxp\Application Data\COWON
2008-03-21 00:27:43         0 d-------- C:\Program Files\PhotoBrush
2008-03-12 03:50:22         0 d-------- C:\Program Files\Common Files\ODBC
2008-03-12 03:50:19         0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-03-12 03:49:57        62 --ahs---- C:\Documents and Settings\winxp\Application Data\desktop.ini
2008-03-12 01:07:30         0 d-------- C:\Documents and Settings\winxp\Application Data\Identities
2008-03-12 00:59:36         0 d-------- C:\Program Files\microsoft frontpage
2008-03-12 00:59:16         0 -rahs---- C:\MSDOS.SYS
2008-03-12 00:59:16         0 -rahs---- C:\IO.SYS
2008-03-12 00:59:16         0 --a------ C:\CONFIG.SYS
2008-03-12 00:59:16         0 --a------ C:\AUTOEXEC.BAT
2008-03-12 00:58:13         0 d--h----- C:\Program Files\WindowsUpdate
2008-03-12 00:57:32         0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-12 00:57:25         0 d-------- C:\Program Files\Movie Maker
2008-03-12 00:56:47     21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-12 00:56:25         0 d-------- C:\Program Files\Online Services
2008-03-12 00:56:17         0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-12 00:56:10         0 d-------- C:\Program Files\Windows NT
2008-03-11 21:48:39         0 d-------- C:\Documents and Settings\winxp\Application Data\Real
2008-03-11 21:37:49         0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-11 21:37:44         0 d-------- C:\Documents and Settings\winxp\Application Data\InstallShield
2008-03-11 21:36:44         0 d-------- C:\Program Files\CONEXANT
2008-03-11 21:34:27         0 d-------- C:\Program Files\Realtek
2008-03-11 21:34:19    315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-03-11 21:32:51         0 d-------- C:\Program Files\Intel
2008-03-11 21:32:05         0 d-------- C:\Program Files\Common Files\Ahead
2008-03-11 21:31:32         0 d-------- C:\Documents and Settings\winxp\Application Data\Ahead
2008-03-11 21:31:14         0 d-------- C:\Program Files\Common Files\Adobe
2008-03-11 21:29:57         0 d-------- C:\Program Files\Nero
2008-03-11 21:28:25         0 d-------- C:\Program Files\ImTOO
2008-03-11 20:28:10         0 d-------- C:\Program Files\Video Convert Master
2008-03-11 20:26:29         0 d-------- C:\Documents and Settings\winxp\Application Data\Yahoo!
2008-03-11 20:25:55         0 d-------- C:\Documents and Settings\winxp\Application Data\ACD Systems
2008-03-11 20:25:11         0 d-------- C:\Program Files\Common Files\ACD Systems
2008-03-11 20:25:11         0 d-------- C:\Program Files\ACD Systems
2008-03-11 20:24:46         0 d-------- C:\Program Files\Macromedia
2008-03-11 20:24:04         0 d-------- C:\Program Files\Microsoft SDK for Java 4.0
2008-03-11 20:22:28         0 d-------- C:\Program Files\Java
2008-03-11 20:21:58         0 d-------- C:\Program Files\Common Files\Java
2008-03-11 20:21:53         0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-11 20:21:19         0 d-------- C:\Program Files\Common Files\xing shared
2008-03-11 20:21:17         0 d-------- C:\Program Files\Common Files\Real
2008-03-11 20:21:09         0 d-------- C:\Program Files\Real
2008-03-11 20:20:50         0 d-------- C:\Program Files\CyberLink
2008-03-11 20:19:42         0 d-------- C:\Program Files\Winamp
2008-03-11 20:18:58         0 d-------- C:\Program Files\DivX
2008-03-11 20:18:29         0 d-------- C:\Program Files\mpegable
2008-03-11 20:18:27     47104 -----n--- C:\WINDOWS\AKDeInstall.exe <Not Verified; ; DeInstall>
2008-03-11 20:18:17         0 d-------- C:\Program Files\VideoLAN
2008-03-11 20:18:16         0 d-------- C:\Program Files\QuickTime Alternative
2008-03-11 20:18:14         0 d-------- C:\Program Files\Media Player Classic
2008-03-11 20:16:51         0 d-------- C:\Program Files\Common Files\L&H
2008-03-11 20:16:41         0 d-------- C:\Program Files\Microsoft.NET
2008-03-11 20:16:28         0 d-------- C:\Program Files\Microsoft ActiveSync
2008-03-11 20:15:35         0 d-------- C:\Program Files\Microsoft Works


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
03/13/2008 10:30 AM   1524248   --a------   C:\Program Files\Hotspot_Shield\tbHot0.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= C:\Program Files\Hotspot_Shield\tbHot0.dll [03/13/2008 10:30 AM 1524248]

[-HKEY_CLASSES_ROOT\CLSID\{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [07/05/2007 11:08 AM C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [06/15/2007 11:45 AM C:\WINDOWS\SkyTel.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [04/10/2008 12:19 PM]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [02/20/2008 11:06 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
"Arovax AntiSpyware"="C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe" [09/21/2007 03:56 PM]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 11:34 AM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"TSClientMSIUninstaller"=cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\winxp\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [10/20/2005 12:04:08 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Internet Download Accelerator"=C:\Program Files\IDA\ida.exe -autorun

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{114f8813-efcd-11dc-bdf7-806d6172696f}]
AutoRun\command- D:\setup.exe

*Newly Created Service* - BANTEXT



-- End of Deckard's System Scanner: finished at 2008-04-13 17:48:20 ------------

Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #4 on: April 13, 2008, 11:02:28 AM »

Here is Extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) Dual  CPU  E2180  @ 2.00GHz
CPU 1: Intel(R) Pentium(R) Dual  CPU  E2180  @ 2.00GHz
Percentage of Memory in Use: 64%
Physical Memory (total/avail): 1015.48 MiB / 356.53 MiB
Pagefile Memory (total/avail): 2442.73 MiB / 1851.26 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1920.54 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 48.83 GiB total, 38.04 GiB free.
D: is CDROM (No Media)
E: is Fixed (NTFS) - 100.21 GiB total, 99.68 GiB free.

\\.\PHYSICALDRIVE0 - WDC WD1600AVJS-63SWA0 - 149.05 GiB - 2 partitions
  \PARTITION0 (bootable) - Installable File System - 48.83 GiB - C:
  \PARTITION1 - Extended w/Extended Int 13 - 100.21 GiB - E:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.
AntiVirusDisableNotify is set.
UpdatesDisableNotify is set.
AntivirusOverride is set.

AV: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Nakido\\nakido.exe"="C:\\Program Files\\Nakido\\nakido.exe:*:Enabled:Nakido"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\winxp\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=WINXP-8D1D04266
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\winxp
LOGONSERVER=\\WINXP-8D1D04266
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\PC Connectivity Solution
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\winxp\LOCALS~1\Temp
TMP=C:\DOCUME~1\winxp\LOCALS~1\Temp
USERDOMAIN=WINXP-8D1D04266
USERNAME=winxp
USERPROFILE=C:\Documents and Settings\winxp
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

winxp (admin)


-- Add/Remove Programs ---------------------------------------------------------

 --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
 --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
 --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
 --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
 --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
 --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
 --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
 --> C:\WINDOWS\UNRecode.exe /UNINSTALL
 --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
3GP Video Converter 3 --> C:\Program Files\ImTOO\3GP Video Converter 3\Uninstall.exe
ACDSee 7.0 PowerPack --> MsiExec.exe /I{B0625F16-B742-4F75-9FD8-20B47ACC7DE2}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop CS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x9
Adobe Reader 7.0.7 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70700000002}
Arovax AntiSpyware 2.1.153 --> C:\Program Files\Arovax AntiSpyware\uninst.exe
AusLogics Disk Defrag --> "C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe"
Belarc Advisor 7.2 --> C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Conexant D850 56K V.9x DFVc Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter --> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
ERUNT 1.1j --> "C:\Program Files\ERUNT\unins000.exe"
ESET NOD32 Antivirus --> MsiExec.exe /I{7D974ACA-4EE5-412C-8E6A-A5B57B305727}
GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotspot Shield 1.03c --> C:\Program Files\Hotspot Shield\Uninstall.exe
Hotspot_Shield Toolbar --> C:\PROGRA~1\HOTSPO~2\UNWISE.EXE C:\PROGRA~1\HOTSPO~2\INSTALL.LOG
Intel(R) Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2776 PCI\VEN_8086&DEV_2772
Internet Download Accelerator version 5.6 --> "C:\Program Files\IDA\unins000.exe"
J2SE Runtime Environment 5.0 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
jetAudio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\Setup.exe" -l0x9
KSAFone --> "C:\Program Files\KSAFone\Uninstall.exe" "C:\Program Files\KSAFone\install.log"
LimeWire 4.16.6 --> "C:\Program Files\LimeWire\uninstall.exe"
Macromedia Flash MX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3BE480ED-E17A-431A-981C-5C2EDDBCD3BF}\Setup.exe" -l0x9 UNINSTALL
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft SDK for Java 4.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C67F0089-9929-42D0-BE04-EE8F82C1E9D3}\Setup.exe" -uninst
Microsoft SDK for Java 4.0 Documentation --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3E3757A2-D587-11D2-BB0C-0000F8050DD1}\setup.exe"  -uninst
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
mpegable Player --> C:\WINDOWS\AKDeInstall.exe "/C:\Program Files\mpegable\"
Nakido --> C:\Program Files\Nakido\Uninstall.exe
Nero 7 Ultra Edition --> MsiExec.exe /I{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}
Nokia Connectivity Cable Driver --> MsiExec.exe /X{11964613-805F-432D-A12B-169554B793E7}
Nokia PC Suite --> C:\Documents and Settings\All Users\Application Data\Installations\{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}\Nokia_PC_Suite_6_84_10_3_EA.exe
Nokia PC Suite --> MsiExec.exe /I{A982E6CC-9F0D-4948-9B18-BDFD55DE4A72}
PC Connectivity Solution --> MsiExec.exe /I{99A40651-0BC2-4095-8F9A-A40FAB224FEF}
Photo-Brush 1.98 --> "C:\Program Files\PhotoBrush\unins000.exe"
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe"  -uninstall
QuickTime Alternative 1.47 --> "C:\Program Files\QuickTime Alternative\unins000.exe"
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
REALTEK GbE & FE Ethernet PCI-E NIC Driver --> C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Revo Uninstaller 1.50 --> C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
SpywareBlaster 4.0 --> "C:\Program Files\SpywareBlaster\unins000.exe"
TuneUp Utilities 2008 --> MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
Video Convert Master v3.4 --> "C:\Program Files\Video Convert Master\unins000.exe"
VideoLAN VLC media player 0.8.4a --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Driver Package - Nokia (WUDFRd) WPD (06/01/2007 6.84.33.0) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccswpddri_044C8712DB44F83D9DE6C376991EE9254E0A69E4\pccswpddriver.inf
Windows Driver Package - Nokia Modem (02/15/2007 3.1) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_8B37DC72918CCD58A6EC20373AF6242B037A293B\pccs_bluetooth.inf
Windows Driver Package - Nokia Modem (02/15/2007 3.1) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccs_bluet_F12A08B6F776984A95553486F64C541356F86E38\pccs_bluetooth.inf
Windows Driver Package - Nokia Modem (05/24/2007 6.84.0.1) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_5E1541AFF1E1EA3554CE566743CCAD323ED1C108\nokbtmdm.inf
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{0ED47137-C071-46CC-A243-E5E33271E10E}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip 11.2 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B6}
Wise Disk Cleaner 3.2 --> "C:\Program Files\Wise Disk Cleaner\unins000.exe"
Wise Registry Cleaner 3 Free 3.2 --> "C:\Program Files\Wise Registry Cleaner 3\unins000.exe"
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type604 / Error
Event Submitted/Written: 04/13/2008 05:36:13 PM
Event ID/Source: 1024 / MsiInstaller
Event Description:
Product: Microsoft Office Professional Edition 2003 - Update 'Update for Outlook 2003: Junk E-mail Filter (KB949044): OUTLFLTR' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Event Record #/Type601 / Error
Event Submitted/Written: 04/13/2008 05:34:22 PM
Event ID/Source: 1024 / MsiInstaller
Event Description:
Product: Microsoft Office Professional Edition 2003 - Update 'Update for Office 2003 (KB907417): OTKLOADR' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Event Record #/Type600 / Error
Event Submitted/Written: 04/13/2008 05:15:55 PM
Event ID/Source: 1001 / Application Hang
Event Description:
Fault bucket 165456457.

Event Record #/Type599 / Error
Event Submitted/Written: 04/13/2008 05:15:48 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application LimeWire.exe, version 1.0.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type598 / Error
Event Submitted/Written: 04/13/2008 05:15:47 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application LimeWire.exe, version 1.0.0.2, hang module hungapp, version 0.0.0.0, hang address 0x00000000.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type2403 / Error
Event Submitted/Written: 04/13/2008 05:36:18 PM
Event ID/Source: 20 / Windows Update Agent
Event Description:
Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Microsoft Outlook Junk Email Filter 2003 (KB949044).

Event Record #/Type2397 / Error
Event Submitted/Written: 04/13/2008 05:34:27 PM
Event ID/Source: 20 / Windows Update Agent
Event Description:
Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Office 2003 (KB907417).

Event Record #/Type2375 / Error
Event Submitted/Written: 04/13/2008 05:13:02 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service upnphost with arguments ""
in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event Record #/Type2370 / Error
Event Submitted/Written: 04/13/2008 05:04:36 PM
Event ID/Source: 1002 / Dhcp
Event Description:
The IP address lease 10.180.144.107 for the Network Card with network address 00FFCB2E0B62 has been
denied by the DHCP server 10.180.143.254 (The DHCP Server sent a DHCPNACK message).

Event Record #/Type2368 / Warning
Event Submitted/Written: 04/13/2008 05:01:51 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.



-- End of Deckard's System Scanner: finished at 2008-04-13 17:48:20 ------------

Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #5 on: April 13, 2008, 11:03:43 AM »

Is it my imagination or am I being actually plagued by problems? (It is a rhetorical question.)
« Last Edit: April 13, 2008, 12:19:21 PM by Kabith » Logged

Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #6 on: April 13, 2008, 12:24:52 PM »

Well first the good news I can see no sign of malware

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of  Java Runtime Environment (JRE) 6 Update 5 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 5...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement". The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u5-windows-i586-p.exe to install the newest version.
.
.
.
You cannot uninstall office as it is hanging on an update.  Download and install the standalone version from here and you should then be able to uninstall   http://www.microsoft.com/downloads/details.aspx?familyid=1B0BFB35-C252-43CC-8A2A-6A64D6AC4670&displaylang=en
The other possible problem is that a registry cleaner has deleted the necessary info http://support.microsoft.com/?id=884298 this could be cured by re-installing office and then uninstalling.  Long winded I know

Limewire is now at version 4.16 you are hanging on version 1.02 files - so I would suggest a clean install from here http://www.limewire.com/


As for the crash I don't suppose you know what the warning was i.e. what file/driver was referenced - has it happened again ?
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #7 on: April 13, 2008, 12:26:46 PM »

Also check this link out for office problems http://support.microsoft.com/kb/903774
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Squeezebox
Administrator
******
Posts: 2756



View Profile
« Reply #8 on: April 13, 2008, 05:51:15 PM »

I'd like to split this latest problem into a separate topic - OK with you guys?
Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #9 on: April 14, 2008, 03:20:02 AM »

Go on Squeezebox. But EB, I just downloaded latest java a limewire. And look at my arovax antispyware. It is finding 45 unknown files. And two more images like this (I did not want to put toot many images)



Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #10 on: April 14, 2008, 03:36:23 AM »

As for the crash, it was referenced to two Temp files, one of which had been deleted by nod32. The update cannot be applied?? I think because it is not genuine. I want to upgrade due to the very same reason.
« Last Edit: April 14, 2008, 03:57:46 AM by Kabith » Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #11 on: April 16, 2008, 09:28:45 AM »

The serious error message has happened again. The file are these
C:\DOCUME~1\winxp\LOCALS~1\Temp\WER77e2.dir00\Mini041508-01.dmp
C:\DOCUME~1\winxp\LOCALS~1\Temp\WER77e2.dir00\sysdata.xml
This is what microsoft showed me. http://wer.microsoft.com/responses/Response.aspx/10/en-us/5.1.2600.2.00010100.2.0?SGD=6f3b4419-6775-447e-8f8d-dd7760c1ed06
When I opened photoshop, the screen showed that the monitor profile is invalid. I think that the spyware scan problem, the monitor profile problem and the stop error problems are related.
Logged

Kabith
Rising Star
***
Posts: 109



View Profile
« Reply #12 on: April 16, 2008, 10:13:33 AM »

COMP IS GOING NUTS
Deckard's System Scanner v20071014.68
Run by winxp on 2008-04-16 17:09:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as winxp.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:09:56 PM, on 4/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nakido\nakido.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Documents and Settings\winxp\My Documents\dss.exe
C:\Documents and Settings\winxp\My Documents\aresregular209_installer.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\winxp.exe
C:\Documents and Settings\winxp\My Documents\ComboFix.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1561552
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE 4.x-6.x BHO for Internet Download Accelerator - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - C:\PROGRA~1\IDA\idaiehlp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: IDA Bar - {C70E30C7-140A-4166-A2E8-43557E62B41A} - C:\Program Files\IDA\idabar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHot0.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Arovax AntiSpyware] C:\Program Files\Arovax AntiSpyware\arovaxantispyware.exe /s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Download ALL with IDA - C:\Program Files\IDA\idaieall.htm
O8 - Extra context menu item: Download with IDA - C:\Program Files\IDA\idaie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207814076734
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nakido - Nakido - C:\Program Files\Nakido\nakido.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 8337 bytes

Logged

Kabith
Rising Star
*