1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Several errors. HijackThis log attached.

Discussion in 'Malware and Virus Removal Archive' started by JulieS, 2008/01/10.

  1. 2008/01/10
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    I have been having problems for about a week. Computer runs slow, applications work but cannot access the internet. (I am using my work laptop to post info.) I have Trend Micro Internet Security 2008. No viruses have been detected. I can only run Trend if I start in safe mode. The Windows Fax Installer tries to run when I don't ask. The other major problem is in Internet Explorer, I am unable to access internet options. I get a message saying I don't have access. I keep getting a pop-up which errors: "Internet Explorer cannot download popup_behavior.htm from 127.0.0.1" Hoping someone can review my log and tell me what to do next.

    Thanks, Julie

    I am replacing HijackThis log file with Deckards log files both won't fit in one post. See reply for "extra" log file
    Deckard's System Scanner v20071014.68
    Run by Kevin on 2008-01-10 12:10:31
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    72: 2008-01-10 17:10:40 UTC - RP626 - Deckard's System Scanner Restore Point
    71: 2008-01-10 08:26:18 UTC - RP625 - Software Distribution Service 3.0
    70: 2008-01-10 01:40:43 UTC - RP624 - Installed Remote Desktop Connection
    69: 2008-01-10 00:32:49 UTC - RP623 - Installed Trend Micro Internet Security
    68: 2008-01-10 00:15:45 UTC - RP622 - Removed Trend Micro Internet Security


    -- First Restore Point --
    1: 2007-10-30 08:28:44 UTC - RP555 - System Checkpoint


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as Kevin.exe) -----------------------------------------------

    logfile has no content; running clone.
    -- HijackThis Clone ------------------------------------------------------------


    Emulating logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2008-01-10 12:13:27
    Platform: Windows XP Service Pack 2 (5.01.2600)
    MSIE: Internet Explorer (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\system32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\WLTRYSVC.EXE
    C:\WINDOWS\system32\BCMWLTRY.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\system32\WLTRAY.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Apoint\ApntEx.exe
    C:\Program Files\Apoint\hidfind.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\Documents and Settings\Kevin\Desktop\dss.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/hws/sb/dell-inc/en/side.html?channel=us
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.com/access/allinone.asp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe "
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.EXE AcRdB7_0_9
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: C:\WINDOWS\system32\nwprovau.dll
    O15 - Trusted Zone: https://online.musicmatch.com (HKLM)
    O15 - Trusted Zone: https://www.aftermarketrewards.com (HKCU)
    O15 - Trusted Zone: https://turbotax.com (HKCU)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175912041177
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0792.00.dll
    O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.0.0792.00.dll
    O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
    O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
    O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\ati2evxx.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\system32\WLTRYSVC.EXE
    O24 - Desktop Component 0: - http://pix.auctiva.com/pix/03/23/73/68fiberfabwouldyoubelieve.jpg

    --
    End of file - 8826 bytes

    -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

    backup-20080108-213528-907 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    backup-20080108-215220-315 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    backup-20080108-215220-535 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    backup-20080108-224556-802 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    backup-20080108-224609-125 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    backup-20080108-224609-230 O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
    backup-20080108-224609-246 O2 - BHO: BHO - {9125F250-EB4F-49fe-AE17-C17665873A5C} - C:\Program Files\BHO\plugin.dll
    backup-20080108-224609-280 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    backup-20080108-224609-371 O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe "
    backup-20080108-224609-425 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe "
    backup-20080108-224609-462 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    backup-20080108-224609-636 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    backup-20080108-224609-837 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    backup-20080108-224609-855 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    backup-20080109-231242-349 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    backup-20080109-231242-570 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    backup-20080109-231242-793 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    -- File Associations -----------------------------------------------------------

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
    R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
    R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>

    S3 Ser2pl (MAT Serial port driver) - c:\windows\system32\drivers\ser2pl.sys <Not Verified; Prolific Technology Inc.; Prolific USB-to-Serial Bridge Cable>
    S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
    R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>


    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.


    -- Scheduled Tasks -------------------------------------------------------------

    2008-01-10 07:01:43 438 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
    2008-01-10 06:51:45 372 --a------ C:\WINDOWS\Tasks\RegCure.job
    2008-01-06 20:34:11 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


    -- Files created between 2007-12-10 and 2008-01-10 -----------------------------

    2008-01-09 23:19:16 0 d-------- C:\RegSeeker
    2008-01-09 20:50:46 0 d-------- C:\Program Files\RegCure
    2008-01-08 20:00:29 0 d-------- C:\Program Files\Lavasoft
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Google
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Corel
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\Recent
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\NetHood
    2008-01-07 19:58:02 0 dr------- C:\Documents and Settings\Administrator\My Documents
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
    2008-01-07 19:58:02 0 dr------- C:\Documents and Settings\Administrator\Favorites
    2008-01-07 19:58:02 0 d-------- C:\Documents and Settings\Administrator\Desktop
    2008-01-07 19:58:02 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
    2008-01-07 19:58:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
    2008-01-07 19:58:02 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
    2008-01-07 19:58:01 0 d--h----- C:\Documents and Settings\Administrator\Templates
    2008-01-07 19:58:01 0 dr------- C:\Documents and Settings\Administrator\Start Menu
    2008-01-07 19:58:01 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
    2008-01-06 22:05:49 0 d-------- C:\i386
    2008-01-06 18:11:54 739328 --a------ C:\WINDOWS\system32\IR41_32.DLL <Not Verified; Intel Corporation; Intel Indeo(R) Video Interactive 32-bit Driver>
    2008-01-06 18:10:45 398416 --a------ C:\WINDOWS\system32\Vbrun300.dll <Not Verified; Microsoft Corporation; Visual Basic 3.0>
    2008-01-06 18:10:45 32768 --a------ C:\WINDOWS\system32\Svrapi.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows(R) Operating System>
    2008-01-06 18:10:43 640512 --a------ C:\WINDOWS\system32\oc30.dll <Not Verified; Microsoft Corporation; Microsoft® OLE Controls Development Kit>
    2008-01-06 18:10:29 0 d-------- C:\Program Files\Webster's World Encyclopedia 2001
    2008-01-06 18:10:06 0 d-------- C:\Documents and Settings\Kevin\WINDOWS


    -- Find3M Report ---------------------------------------------------------------

    2008-01-10 06:56:09 4 --a------ C:\Documents and Settings\Kevin\Application Data\QSWWShare
    2008-01-09 19:37:48 0 d-------- C:\Program Files\Trend Micro
    2008-01-08 22:46:43 0 d-------- C:\Program Files\BAE
    2008-01-08 20:55:08 0 d-------- C:\Program Files\Common Files
    2008-01-06 19:19:57 0 d-------- C:\Program Files\Java
    2008-01-06 18:55:01 0 d-------- C:\Program Files\Google
    2008-01-06 16:52:06 0 d-------- C:\Program Files\SpongeBob SquarePants Obstacle Odyssey 2
    2007-11-27 07:45:57 0 d-------- C:\Program Files\IncrediMail
    2007-11-10 23:31:02 0 d-------- C:\Program Files\Instant Messenger Names


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update "= "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/16/2005 10:11 PM]
    "HP Component Manager "= "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [01/12/2005 01:54 PM]
    "DVDLauncher "= "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [02/23/2005 04:19 PM]
    "DMXLauncher "= "C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [01/27/2005 01:02 AM]
    "dla "= "C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 01:05 AM]
    "Dell QuickSet "= "C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 05:24 PM]
    "Broadcom Wireless Manager UI "= "C:\WINDOWS\system32\WLTRAY.exe" [12/19/2005 03:08 PM]
    "ATIPTA "= "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [08/31/2004 09:10 PM]
    "Apoint "= "C:\Program Files\Apoint\Apoint.exe" [10/07/2005 06:13 AM]
    "UfSeAgnt.exe "= "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [09/17/2007 10:24 AM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
    "updateMgr "= "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.exe" [03/30/2006 03:45 PM]
    "DellSupport "= "C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 9:05:26 PM]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [4/8/2006 2:46:53 AM]
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [7/7/2003 12:20:40 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
    backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
    backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
    C:\Program Files\IncrediMail\bin\IncMail.exe /c

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
    "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
    "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe "

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
    C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
    "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe "

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Usnsvc usnsvc


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{225762b9-cbdb-11da-992c-00038a000015}]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa2c7d31-cbc3-11da-992a-806d6172696f}]




    -- End of Deckard's System Scanner: finished at 2008-01-10 12:16:23 ------------
     
    Last edited: 2008/01/10
  2. 2008/01/10
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    Deckards log "extra" below. Would not fit in first post.

    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.
    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows XP Home Edition (build 2600) SP 2.0
    Architecture: X86; Language: English

    CPU 0: Intel(R) Celeron(R) M processor 1.50GHz
    Percentage of Memory in Use: 75%
    Physical Memory (total/avail): 511.23 MiB / 127.58 MiB
    Pagefile Memory (total/avail): 1249.68 MiB / 923.45 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1933.79 MiB

    C: is Fixed (NTFS) - 34.1 GiB total, 17.88 GiB free.
    D: is CDROM (CDFS)
    E: is Removable (FAT)

    \\.\PHYSICALDRIVE0 - ST9408114A - 37.26 GiB - 3 partitions
    \PARTITION0 - Unknown - 47.03 MiB
    \PARTITION1 (bootable) - Installable File System - 34.1 GiB - C:
    \PARTITION2 - Unknown - 3.1 GiB

    \\.\PHYSICALDRIVE1 - Kingston DataTraveler 2.0 USB Device - 243.17 MiB - 1 partition
    \PARTITION0 (bootable) - Win95 w/Extended Int 13 - 245.97 MiB - E:



    -- Security Center -------------------------------------------------------------

    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is disabled.

    FirstRunDisabled is set.

    FW: Trend Micro Personal Firewall v5.0 (Trend Micro Inc.)
    AV: Trend Micro Internet Security v16.00.1645 ()

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "= "%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "= "%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "= "%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "= "%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe "= "C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax "
    "C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe "= "C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager "
    "C:\\Program Files\\iTunes\\iTunes.exe "= "C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes "
    "C:\\Documents and Settings\\Kevin\\Local Settings\\Temporary Internet Files\\Content.IE5\\EL1O4PQ1\\incredimail_install[1].exe "= "C:\\Documents and Settings\\Kevin\\Local Settings\\Temporary Internet Files\\Content.IE5\\EL1O4PQ1\\incredimail_install[1].exe:*:Enabled:IncrediMail Installer "
    "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe "= "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail "
    "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe "= "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail "
    "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe "= "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail "


    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Kevin\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
    CLIENTNAME=Console
    COLLECTIONID=COL8143
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=SHOPOFFICE
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HMSERVER=https://wwss1proa.cce.hp.com/wuss/servlet/WUSSServlet
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Kevin
    ITEMID=dj-22741-15
    LANG=1033
    LOGONSERVER=\\SHOPOFFICE
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    OSVER=winXPH
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0d08
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
    SESSIONID=1158353910480htx6060.cce.hp.com1c21524:10db2498ad5:36c9
    SESSIONNAME=Console
    SonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\
    SWUTVER=1.0.18.20030625
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\Kevin\LOCALS~1\Temp
    TIMEOUT=0
    TMP=C:\DOCUME~1\Kevin\LOCALS~1\Temp
    TOOLPATH=/C:\Program%20Files\HP\HP%20Software%20Update\install.htm
    UPDATEDIR=C:\DOCUME~1\Kevin\LOCALS~1\Temp\radD51CB.tmp
    USERDOMAIN=SHOPOFFICE
    USERNAME=Kevin
    USERPROFILE=C:\Documents and Settings\Kevin
    VERSION=3.0.5.001
    windir=C:\WINDOWS


    -- User Profiles ---------------------------------------------------------------

    Kevin (admin)
    Administrator (new local, admin)


    -- Add/Remove Programs ---------------------------------------------------------

    --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
    Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
    ALPS Touch Pad Driver --> C:\Program Files\Apoint\Uninstap.exe ADDREMOVE
    AOLIcon --> MsiExec.exe /I{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}
    Apple Mobile Device Support --> MsiExec.exe /I{8FC46258-0843-4D79-B7F0-F2B82FE6173B}
    Apple Software Update --> MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
    ATI Control Panel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Blasterball 2 --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\D1A6F3FD-7B40-443F-8767-BADB25A0D222\Uninstall.exe "
    Broadcom Management Programs 2 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{64A77F14-0E08-4A97-A859-E93CFF428756} /l1033
    Conexant D480 MDC V.9x Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1\HXFSETUP.EXE -U -Idel5422k.inf
    CutePDF Writer 2.7 --> C:\Program Files\Acro Software\CutePDF Writer\uninscpw.exe /uninstall
    Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
    Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
    Dell Game Console --> "C:\Program Files\WildTangent\Apps\Dell Game Console\Uninstall.exe "
    Dell Media Experience --> MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
    Dell Wireless WLAN Card --> "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey= "Software\Broadcom\802.11\UninstallInfo" /rootdir= "C:\Program Files\Dell\Dell Wireless WLAN Card "
    DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
    Digital Content Portal --> MsiExec.exe /I{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}
    Digital Line Detect --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
    EducateU --> MsiExec.exe /I{A683A2C0-821C-486F-858C-FA634DB5E864}
    ELIcon --> MsiExec.exe /I{4667B940-BB01-428B-986E-A0CC46497BF7}
    GdiplusUpgrade --> MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}
    HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    HP Photo & Imaging 3.1 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
    HP PSC & OfficeJet 3.0 --> "C:\Program Files\HP\Digital Imaging\{F38FA38A-7E5A-4209-88ED-4DE21CD20EEF}\setup\hpzscr01.exe" -datfile hposcr03.dat
    HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
    HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
    IncrediMail Xe --> C:\PROGRA~1\INCRED~1\bin\imsetup.exe /remove /addon:IncrediMail /log:IncMail.log
    Internal Network Card Power Management --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F528948-0E80-4C96-B455-DE4167CB1DF7}\setup.exe" -l0x9 UNINSTALL APPDRVNT4
    iTunes --> MsiExec.exe /I{85B90D8C-70F3-4E84-BD31-5E9489C0F9FB}
    J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
    J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
    Jasc Paint Shop Pro 8 --> MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
    Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
    Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
    Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    MCU --> MsiExec.exe /I{D2988E9B-C73F-422C-AD4B-A66EBE257120}
    Memories Disc Creator 2.0 --> MsiExec.exe /X{2E132061-C78A-48D4-A899-1D13B9D189FA}
    Microsoft Office FrontPage 2003 --> MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
    Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
    Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
    Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
    Modem Helper --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
    MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
    Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
    NetWaiting --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
    overland --> MsiExec.exe /I{766273C1-A39B-47EB-ACE8-DEBDD8094BCC}
    Photo Click --> MsiExec.exe /I{6E179C77-7335-458D-9537-4F4EAC0181ED}
    PowerDVD 5.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
    Quicken 2003 Premier Home & Business --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2A3E87C5-ED9D-427F-9E0F-C06E8EAD6351} anything
    QuickSet --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe" -l0x9 UNINSTALL APPDRVNT4 - ALL
    QuickTime --> MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328}
    RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    RegCure 1.3.0.2 --> C:\Program Files\RegCure\uninst.exe
    Search Assist --> MsiExec.exe /X{DF6A589A-7A1A-430C-9FF2-A0BDB42669DC}
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe "
    Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe "
    Sonic DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
    Sonic RecordNow Audio --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
    Sonic RecordNow Copy --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
    Sonic RecordNow Data --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
    Trend Micro Internet Security --> C:\Program Files\Trend Micro\Internet Security\remove.exe
    Trend Micro Internet Security --> MsiExec.exe /X{A621B45A-D138-4A95-BE10-7CABA05EF94E}
    TurboTax Home & Business 2006 --> C:\Program Files\TurboTax\Home & Business 2006\TaxUnst.EXE "C:\Program Files\TurboTax\Home & Business 2006\Uninstall.log" -NoGui
    TurboTax ItsDeductible 2005 --> MsiExec.exe /X{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}
    TurboTax ItsDeductible 2006 --> MsiExec.exe /X{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}
    TurboTax Premier 2005 --> C:\Program Files\TurboTax\Premier 2005\TaxUnst.EXE "C:\Program Files\TurboTax\Premier 2005\Uninstall.log" -NoGui
    Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
    WebCyberCoach 3.2 Dell --> "C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4 "
    Webster's World Encyclopedia 2001 --> C:\WINDOWS\uninst.exe -f "C:\Program Files\Webster's World Encyclopedia 2001\DeIsL1.isu" -c "C:\Program Files\Webster's World Encyclopedia 2001\_ISREG32.DLL "
    WexTech AnswerWorks --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}\SETUP.EXE" -l0x9 -eliminate
    WildTangent Web Driver --> C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
    Windows Live Messenger --> MsiExec.exe /I{7A837109-E671-470D-B489-F1EBE471D220}


    -- Application Event Log -------------------------------------------------------

    Event Record #/Type829 / Error
    Event Submitted/Written: 01/10/2008 09:34:25 AM
    Event ID/Source: 11706 / MsiInstaller
    Event Description:
    Product: Fax -- Error 1706.No valid source could be found for product Fax. The Windows Installer cannot continue.

    Event Record #/Type828 / Warning
    Event Submitted/Written: 01/10/2008 09:21:57 AM
    Event ID/Source: 1001 / MsiInstaller
    Event Description:
    Detection of product '{D40E4A88-EBC8-4D52-BE3C-A4917A057EF0}', feature 'Fax' failed during request for component '{662E9395-9291-11D6-8707-00B0D0236D7F}'

    Event Record #/Type827 / Warning
    Event Submitted/Written: 01/10/2008 09:21:57 AM
    Event ID/Source: 1004 / MsiInstaller
    Event Description:
    Detection of product '{D40E4A88-EBC8-4D52-BE3C-A4917A057EF0}', feature 'Fax', component '{E3D9F699-6C85-4711-BD37-169F53FE35D3}' failed. The resource 'C:\Program Files\HP\Digital Imaging\bin\lfplt13n.dll' does not exist.

    Event Record #/Type825 / Error
    Event Submitted/Written: 01/10/2008 09:21:22 AM
    Event ID/Source: 11706 / MsiInstaller
    Event Description:
    Product: Fax -- Error 1706.No valid source could be found for product Fax. The Windows Installer cannot continue.

    Event Record #/Type824 / Warning
    Event Submitted/Written: 01/10/2008 09:13:40 AM
    Event ID/Source: 1001 / MsiInstaller
    Event Description:
    Detection of product '{D40E4A88-EBC8-4D52-BE3C-A4917A057EF0}', feature 'Fax' failed during request for component '{662E9395-9291-11D6-8707-00B0D0236D7F}'



    -- Security Event Log ----------------------------------------------------------

    No Errors/Warnings found.


    -- System Event Log ------------------------------------------------------------

    Event Record #/Type39451 / Error
    Event Submitted/Written: 01/10/2008 00:14:06 PM
    Event ID/Source: 7 / Disk
    Event Description:
    The device, \Device\Harddisk0\D, has a bad block.

    Event Record #/Type39450 / Error
    Event Submitted/Written: 01/10/2008 00:13:57 PM
    Event ID/Source: 7 / Disk
    Event Description:
    The device, \Device\Harddisk0\D, has a bad block.

    Event Record #/Type39449 / Error
    Event Submitted/Written: 01/10/2008 00:13:36 PM
    Event ID/Source: 7 / Disk
    Event Description:
    The device, \Device\Harddisk0\D, has a bad block.

    Event Record #/Type39448 / Error
    Event Submitted/Written: 01/10/2008 00:13:05 PM
    Event ID/Source: 7 / Disk
    Event Description:
    The device, \Device\Harddisk0\D, has a bad block.

    Event Record #/Type39447 / Error
    Event Submitted/Written: 01/10/2008 00:12:59 PM
    Event ID/Source: 7 / Disk
    Event Description:
    The device, \Device\Harddisk0\D, has a bad block.



    -- End of Deckard's System Scanner: finished at 2008-01-10 12:16:23 ------------
     

  3. to hide this advert.

  4. 2008/01/11
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi JulieS
    Welcome to Windowsbbs :)

    Have you received help at another form?

    You have fixed entries using HJT, who told you to fix these entries and what other programs have you ran?

    Lets try this and see if your internet will come back.

    Open a command window and type the following commands, hitting enter after each.

    ipconfig /release

    ipconfig /flushdns

    ipconfig /renew

    See if the connection is restored. If not, proceed with the following.

    Download Winsock XP Fix. Close all open programs and connections. Run Winsock XP Fix and select Fix. Reboot.

    Let me know

    Geri
     
    Geri,
    #3
  5. 2008/01/12
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    ok. I did the ipconfig commands. No luck. Ran Winsock. No luck. I am attaching another Deckards scan log as I have been working on this thing all week. System no longer run slow, but internet explorer does not work. When I click to open, the address bar shows http://go.microsoft.com/fwlink/?LinkId=74005. However, the blue bar at the very top of the screen shows http://runonce.msn.com/runonce2.aspx - Windows Internet Explorer. Also, if I click on Tools/Internet Options, I get the message "This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator."

    Thanks for any help you can provide.

    My brother in law said I should give up on IE7 and download Mozilla Firefox...

    Deckard's System Scanner v20071014.68
    Run by Kevin on 2008-01-12 20:05:21
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------



    -- HijackThis (run as Kevin.exe) -----------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:05:30 PM, on 1/12/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Apoint\HidFind.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\INCRED~1\bin\ImNotfy.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\Documents and Settings\Kevin\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Kevin.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: BHO - {9125F250-EB4F-49fe-AE17-C17665873A5C} - C:\Program Files\BHO\plugin.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe "
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe "
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe "
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [updateMgr] C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.EXE AcRdB7_0_9
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1175912041177
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 9101 bytes

    -- Files created between 2007-12-12 and 2008-01-12 -----------------------------

    2008-01-12 10:31:04 0 d--hs---- C:\found.000
    2008-01-10 23:01:38 180 --a------ C:\Skiprunonce.reg
    2008-01-10 22:16:05 0 d-------- C:\WINDOWS\system32\NtmsData
    2008-01-10 22:15:40 278528 --a------ C:\WINDOWS\system32\hpdjaio <Not Verified; HP; HP DeskJet>
    2008-01-10 22:13:19 278528 --a------ C:\WINDOWS\system32\hpdj <Not Verified; HP; HP DeskJet>
    2008-01-10 20:57:47 2520 --a------ C:\WINDOWS\system32\tmp.reg
    2008-01-09 23:19:16 0 d-------- C:\RegSeeker
    2008-01-09 20:50:46 0 d-------- C:\Program Files\RegCure
    2008-01-08 20:00:29 0 d-------- C:\Program Files\Lavasoft
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Google
    2008-01-07 19:58:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Corel
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\Recent
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\NetHood
    2008-01-07 19:58:02 0 dr------- C:\Documents and Settings\Administrator\My Documents
    2008-01-07 19:58:02 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
    2008-01-07 19:58:02 0 dr------- C:\Documents and Settings\Administrator\Favorites
    2008-01-07 19:58:02 0 d-------- C:\Documents and Settings\Administrator\Desktop
    2008-01-07 19:58:02 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
    2008-01-07 19:58:02 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
    2008-01-07 19:58:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
    2008-01-07 19:58:02 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
    2008-01-07 19:58:01 0 d--h----- C:\Documents and Settings\Administrator\Templates
    2008-01-07 19:58:01 0 dr------- C:\Documents and Settings\Administrator\Start Menu
    2008-01-07 19:58:01 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
    2008-01-06 22:05:49 0 d-------- C:\i386
    2008-01-06 18:11:54 739328 --a------ C:\WINDOWS\system32\IR41_32.DLL <Not Verified; Intel Corporation; Intel Indeo(R) Video Interactive 32-bit Driver>
    2008-01-06 18:10:45 398416 --a------ C:\WINDOWS\system32\Vbrun300.dll <Not Verified; Microsoft Corporation; Visual Basic 3.0>
    2008-01-06 18:10:45 32768 --a------ C:\WINDOWS\system32\Svrapi.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows(R) Operating System>
    2008-01-06 18:10:43 640512 --a------ C:\WINDOWS\system32\oc30.dll <Not Verified; Microsoft Corporation; Microsoft® OLE Controls Development Kit>
    2008-01-06 18:10:06 0 d-------- C:\Documents and Settings\Kevin\WINDOWS


    -- Find3M Report ---------------------------------------------------------------

    2008-01-12 19:55:40 4 --a------ C:\Documents and Settings\Kevin\Application Data\QSWWShare
    2008-01-12 12:19:09 0 d--h----- C:\Program Files\BHO
    2008-01-09 19:37:48 0 d-------- C:\Program Files\Trend Micro
    2008-01-08 22:46:43 0 d-------- C:\Program Files\BAE
    2008-01-08 20:55:08 0 d-------- C:\Program Files\Common Files
    2008-01-06 19:19:57 0 d-------- C:\Program Files\Java
    2008-01-06 18:55:01 0 d-------- C:\Program Files\Google
    2008-01-06 16:52:06 0 d-------- C:\Program Files\SpongeBob SquarePants Obstacle Odyssey 2
    2007-11-27 07:45:57 0 d-------- C:\Program Files\IncrediMail


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9125F250-EB4F-49fe-AE17-C17665873A5C}]
    11/03/2006 10:49 AM 140496 --a------ C:\Program Files\BHO\plugin.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DVDLauncher "= "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [02/23/2005 04:19 PM]
    "DMXLauncher "= "C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [01/27/2005 01:02 AM]
    "dla "= "C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 01:05 AM]
    "Dell QuickSet "= "C:\Program Files\Dell\QuickSet\quickset.exe" [09/01/2005 05:24 PM]
    "Broadcom Wireless Manager UI "= "C:\WINDOWS\system32\WLTRAY.exe" [12/19/2005 03:08 PM]
    "ATIPTA "= "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [08/31/2004 09:10 PM]
    "Apoint "= "C:\Program Files\Apoint\Apoint.exe" [10/07/2005 06:13 AM]
    "UfSeAgnt.exe "= "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [09/17/2007 10:24 AM]
    "MSKDetectorExe "= "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [08/12/2005 03:16 PM]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [06/28/2007 08:14 AM]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 10:44 AM]
    "ISUSPM Startup "= "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 10:44 AM]
    "HP Software Update "= "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/16/2005 10:11 PM]
    "HP Component Manager "= "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [01/12/2005 01:54 PM]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [04/27/2007 08:41 AM]
    "TkBellExe "= "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/30/2006 04:22 PM]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [11/09/2006 02:07 PM]
    "MMTray "= "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [09/08/2005 07:20 PM]
    "MimBoot "= "C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [09/08/2005 07:20 PM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
    "updateMgr "= "C:\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.exe" [03/30/2006 03:45 PM]
    "DellSupport "= "C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]
    "IncrediMail "= "C:\Program Files\IncrediMail\bin\IncMail.exe" [11/19/2007 01:49 PM]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 9:05:26 PM]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [4/8/2006 2:46:53 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
    backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
    backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
    backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Usnsvc usnsvc


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{225762b9-cbdb-11da-992c-00038a000015}]




    -- End of Deckard's System Scanner: finished at 2008-01-12 20:05:56 ------------
     
  6. 2008/01/12
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi JulieS

    Please click Start > Run
    Copy and paste the command below into the run box and click OK.

    regedit /e "%userprofile%\desktop\IETools.txt
    "HKEY_CURRENT_USER/Software/Policies/Microsoft/Internet Explorer "

    A file IETools.txt should be on your desktop, Please post the contents here.

    Thanks
    Geri
     
    Geri,
    #5
  7. 2008/01/13
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    Hi Geri,

    Nothing comes up. Should the command include everything from regedit through Explorer "? Should it all be on one line? If so, is there a space between .txt and "HKEY? Is the command missing a "?

    Thanks.
     
  8. 2008/01/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Not to butt in, but to save a bit of time, pardon the interruption. ;) Yes, the command is missing a set of quotations. Corrected below.

    Code:
    regedit /e  "%userprofile%\desktop\IETools.txt"  "HKEY_CURRENT_USER/Software/Policies/Microsoft/Internet Explorer "
    
     
  9. 2008/01/13
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    ok. thanks for the clarification. I put in the command exactly as typed. Nothing comes up. If I just use command regedit, go to HKEY_CURRENT_USER/Software/Policies/Microsoft, my only two options below that are Conferencing RTC and SystemCertificates.

    What next?
     
  10. 2008/01/13
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi JulieS

    I don't believe this is a malware problem.

    I believe IE7 Is broken, There were no restrictions there and none show in the dss log.
    I would recommend you either reinstall IE7 or post in the Internet Explorer form. They may have a answer there. :)

    You can check here also, she has a lot of information.
    http://www.ie-vista.com/known_issues.html#tsie

    Geri
     
    Geri,
    #9
  11. 2008/01/13
    JulieS

    JulieS Inactive Thread Starter

    Joined:
    2008/01/10
    Messages:
    6
    Likes Received:
    0
    Thanks. I'll try there. I have tried to reinstall IE7 with no luck.

    Thanks again for your help. I'll come back and post if I get this resolved.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.