Hi Shaba,
Hopefully I did everything correctly.
Malwarebytes' Anti-Malware 1.20
Database version: 957
Windows 6.0.6001 Service Pack 1
11:05:47 PM 16/07/2008
mbam-log-7-16-2008 (23-05-47).txt
Scan type: Full Scan (C:\|E:\|)
Objects scanned: 211257
Time elapsed: 38 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm3ba81fd7 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Malware.Trace) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\daxcshid.dll (Trojan.Agent) -> Delete on reboot.
Deckard's System Scanner v20071014.68
Run by David Luu on 2008-07-17 00:03:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as David Luu.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:22 AM, on 17/07/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
E:\Downl\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\DAVIDL~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.smh.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {14947672-ADEA-4253-AE57-944A72D18B32} - (no file)
O2 - BHO: {c020a586-252e-53f9-8014-8fd8244d68f1} - {1f86d442-8df8-4108-9f35-e252685a020c} - C:\Windows\system32\djofrc.dll
O2 - BHO: (no name) - {23344236-4D41-4664-90D0-1FEB91A987E1} - (no file)
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch_1.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6C81A71E-3691-430F-AF66-C9F70748BF36} - (no file)
O2 - BHO: (no name) - {6DFEE42F-5F3F-492D-AC50-766196FC3834} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9A710F8B-92DC-43F5-BBFB-EA83252BEDF2} - (no file)
O2 - BHO: (no name) - {AF6B8049-1323-4923-BEF2-ED0D43000A1B} - C:\Windows\system32\nnnmmjIB.dll (file missing)
O2 - BHO: (no name) - {C5AA5177-94B9-49C7-9677-74BE3F8D292A} - (no file)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {F1787032-2A95-4114-AC29-76DF55D833E2} - (no file)
O2 - BHO: (no name) - {F850ED84-441E-4620-A027-284A17A08224} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [servcrypt] C:\Windows\system32\svchost.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - Startup: New Text Document.txt
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JR1916~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JR1916~1.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FireDaemon Service: msagent (msagent) - Sublime Solutions Pty Ltd - C:\Windows\security\FireDaemon.exe
O23 - Service: FireDaemon Service: netclient (netclient) - Sublime Solutions Pty Ltd - C:\Windows\security\FireDaemon.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\Program Files\Stardock\Object Desktop\WindowBlinds\vistasrv.exe
--
End of file - 8521 bytes
-- Files created between 2008-06-17 and 2008-07-17 -----------------------------
2008-07-16 21:54:28 102400 --a------ C:\Windows\system32\djofrc.dll
2008-07-16 21:54:26 102400 --a------ C:\Windows\system32\oqciqjaq.dll
2008-07-16 19:56:18 0 d-------- C:\Users\All Users\Malwarebytes
2008-07-16 19:56:17 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-16 13:29:58 92160 -----n--- C:\Windows\system32\bfohmioc.dll
2008-07-13 21:35:54 412435 --ahs---- C:\Windows\system32\BIjmmnnn.ini2
2008-07-13 18:45:41 345 --ahs---- C:\Windows\system32\OXGgQqss.ini2
2008-07-13 16:05:07 91648 --a------ C:\Windows\system32\gqluwomw.dll
2008-07-13 16:04:26 413057 --ahs---- C:\Windows\system32\jjTBeMoq.ini2
2008-07-13 15:57:34 0 d-------- C:\Windows\pss
2008-07-13 14:55:27 91648 --a------ C:\Windows\system32\bxpckcmt.dll
2008-07-13 14:54:47 412842 --ahs---- C:\Windows\system32\PVEgPqss.ini2
2008-07-13 13:53:25 91648 --a------ C:\Windows\system32\fdkmxbfl.dll
2008-07-13 13:52:44 412163 --ahs---- C:\Windows\system32\OooprBeg.ini2
2008-07-13 11:55:46 0 d-------- C:\Program Files\Trend Micro
2008-07-13 11:52:51 91648 --a------ C:\Windows\system32\bsynmouw.dll
2008-07-13 11:52:08 406780 --ahs---- C:\Windows\system32\ybJSCcdd.ini2
2008-07-13 04:34:31 91648 --a------ C:\Windows\system32\vsucwfak.dll
2008-07-13 04:33:44 406705 --ahs---- C:\Windows\system32\XxEhRYxx.ini2
2008-07-13 04:09:17 0 d-------- C:\VundoFix Backups
2008-07-13 03:33:44 91648 --a------ C:\Windows\system32\nsxojlvx.dll
2008-07-13 02:40:01 91648 --a------ C:\Windows\system32\wfkwkope.dll
2008-07-12 18:54:33 0 d-------- C:\etax2008
2008-07-12 13:21:49 412163 --ahs---- C:\Windows\system32\QpqsDfhk.ini2
2008-07-12 01:08:09 413704 --ahs---- C:\Windows\system32\CdfiRXbc.ini2
2008-07-09 23:21:48 891448 --a------ C:\Windows\system32\drivers\tcpip.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-08 23:25:11 164352 --a------ C:\Windows\system32\unrar.dll
2008-07-08 23:25:06 217088 --a------ C:\Windows\system32\yv12vfw.dll <Not Verified;
www.helixcommunity.org; Helix YV12 YUV Codec>
2008-07-08 23:25:06 2045459 --a------ C:\Windows\system32\x264vfw.dll
2008-07-08 23:25:06 630784 --a------ C:\Windows\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2008-07-08 23:25:06 438272 --a------ C:\Windows\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-07-08 23:25:06 144384 --a------ C:\Windows\system32\Iacenc.dll <Not Verified; Intel Corporation; Indeo® audio software>
2008-07-08 23:25:06 39936 --a------ C:\Windows\system32\huffyuv.dll <Not Verified; Disappearing Inc.; Huffyuv>
2008-07-08 23:25:05 159839 --a------ C:\Windows\system32\xvidvfw.dll
2008-07-08 23:25:05 755027 --a------ C:\Windows\system32\xvidcore.dll
2008-07-08 23:25:05 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-07-08 23:25:05 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-07-08 23:25:00 683520 --a------ C:\Windows\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-07-08 23:24:59 7680 --a------ C:\Windows\system32\ff_vfw.dll
2008-07-08 23:24:58 0 d-------- C:\Users\All Users\Real
2008-07-08 23:24:58 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-07-08 23:21:48 0 d-------- C:\Users\All Users\Apple Computer
2008-07-08 23:21:45 0 d-------- C:\Program Files\QuickTime Alternative
2008-07-05 13:13:28 0 d-------- C:\Users\All Users\ashampoo
2008-07-05 13:13:17 0 d-------- C:\Program Files\Ashampoo
2008-07-05 11:57:07 0 d-------- C:\Program Files\DVDFab 5
2008-06-19 22:52:52 0 d-------- C:\Users\David Luu\dwhelper
-- Find3M Report ---------------------------------------------------------------
2008-07-16 19:56:22 0 d-------- C:\Users\David Luu\AppData\Roaming\Malwarebytes
2008-07-16 19:52:21 0 d-------- C:\Users\David Luu\AppData\Roaming\uTorrent
2008-07-16 17:08:19 0 d-------- C:\Program Files\FlashGet
2008-07-15 12:15:46 0 d-------- C:\Users\David Luu\AppData\Roaming\Vso
2008-07-13 13:19:37 0 d-------- C:\Program Files\Java
2008-07-12 00:08:39 0 d-------- C:\Program Files\Windows Mail
2008-07-08 23:24:58 0 d-------- C:\Users\David Luu\AppData\Roaming\Real
2008-07-05 21:42:41 0 d-------- C:\Program Files\Opera
2008-07-05 13:16:39 0 d-------- C:\Program Files\Foto2Avi
2008-07-05 13:14:14 0 d-------- C:\Users\David Luu\AppData\Roaming\Ashampoo
2008-07-05 11:57:22 34 --a------ C:\Users\David Luu\AppData\Roaming\pcouffin.log
2008-07-05 11:57:13 7887 --a------ C:\Users\David Luu\AppData\Roaming\pcouffin.cat
2008-06-18 21:58:09 0 d-------- C:\Users\David Luu\AppData\Roaming\Mozilla
2008-06-09 17:49:16 16254976 --a------ C:\Windows\system32\imageres.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-09 17:39:48 0 d-------- C:\Program Files\Common Files
2008-05-25 17:32:25 0 d-------- C:\Program Files\Subtitle Workshop
2008-05-25 17:30:26 1092117 --a------ C:\Program Files\sw4b3.zip
2008-05-20 20:05:18 0 d-------- C:\Users\David Luu\AppData\Roaming\DVDFab
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14947672-ADEA-4253-AE57-944A72D18B32}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f86d442-8df8-4108-9f35-e252685a020c}]
16/07/2008 09:54 PM 102400 --a------ C:\Windows\system32\djofrc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23344236-4D41-4664-90D0-1FEB91A987E1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6C81A71E-3691-430F-AF66-C9F70748BF36}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6DFEE42F-5F3F-492D-AC50-766196FC3834}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A710F8B-92DC-43F5-BBFB-EA83252BEDF2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF6B8049-1323-4923-BEF2-ED0D43000A1B}]
C:\Windows\system32\nnnmmjIB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5AA5177-94B9-49C7-9677-74BE3F8D292A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F1787032-2A95-4114-AC29-76DF55D833E2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F850ED84-441E-4620-A027-284A17A08224}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [28/11/2006 08:17 PM]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [11/04/2007 03:32 PM C:\Windows\KHALMNPR.Exe]
"servcrypt"="C:\Windows\system32\svchost.exe" [19/01/2008 05:33 PM]
"@"="" []
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [21/12/2007 07:21 AM]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [11/12/2007 04:06 PM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [11/12/2007 04:06 PM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [11/12/2007 04:06 PM]
"Persistence"="C:\Windows\system32\igfxpers.exe" [28/11/2006 08:13 PM]
"RtHDVCpl"="RtHDVCpl.exe" [12/12/2006 09:33 PM C:\Windows\RtHDVCpl.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [19/01/2008 05:33 PM]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [19/01/2008 05:33 PM]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [05/01/2008 06:52 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [19/01/2008 05:33 PM]
C:\Users\David Luu\Start Menu\Programs\Startup\
New Text Document.txt [16/07/2008 9:52:34 PM]
C:\ProgramData\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [21/07/2007 7:42:40 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"=0 (0x0)
"EnableLUA"=0 (0x0)
"EnableUIADesktopToggle"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 28/01/2008 11:53 AM 197912 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^David Luu^Start Menu^Programs^Startup^DUMeter.lnk]
path=C:\Users\David Luu\Start Menu\Programs\Startup\DUMeter.lnk
backup=C:\Windows\pss\DUMeter.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
"C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-07-17 00:03:55 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft® Windows Vista™ Home Premium (build 6001) SP 1.0
Architecture: X86; Language: English
CPU 0: Intel(R) Core(TM)2 Duo CPU E6850 @ 3.00GHz
Percentage of Memory in Use: 26%
Physical Memory (total/avail): 3070.58 MiB / 2248.74 MiB
Pagefile Memory (total/avail): 6038.74 MiB / 5286.1 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1875.5 MiB
C: is Fixed (NTFS) - 465.76 GiB total, 264.01 GiB free.
D: is CDROM (No Media)
E: is Fixed (NTFS) - 298.09 GiB total, 100.89 GiB free.
F: is CDROM (No Media)
\\.\PHYSICALDRIVE1 - ST3320620A ATA Device - 298.09 GiB - 1 partition
\PARTITION0 - Installable File System - 298.09 GiB - E:
\\.\PHYSICALDRIVE0 - WDC WD5000AAKS-00TMA0 ATA Device - 465.76 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 465.76 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before install.
Windows Internal Firewall is disabled.
FW: ESET Personal firewall v3.0.621.0 (ESET, spol. s r. o.)
AV: ESET Smart Security 3.0 v3.0 (ESET, spol. s r. o.)
AS: ESET Smart Security 3.0 v3.0 (ESET, spol. s r. o.)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
Disabled
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\David Luu\AppData\Roaming
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HOME-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\David Luu
LOCALAPPDATA=C:\Users\David Luu\AppData\Local
LOGONSERVER=\\HOME-PC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\PROGRA~1\DISKEE~1\DISKEE~1
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0b
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\DAVIDL~1\AppData\Local\Temp
TMP=C:\Users\DAVIDL~1\AppData\Local\Temp
USERDOMAIN=Home-PC
USERNAME=David Luu
USERPROFILE=C:\Users\David Luu
windir=C:\Windows
-- User Profiles ---------------------------------------------------------------
David Luu
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
--> MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
ACDSee 9 Photo Manager --> MsiExec.exe /X{B2D41883-3BFC-4BA0-A2F6-5A2C9836C238}
Adobe Acrobat 8.1.1 Professional --> msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player --> C:\Windows\System32\Macromed\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Macromed\SHOCKW~1\Install.log
AGEIA PhysX v7.11.13 --> MsiExec.exe /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
Ashampoo Burning Studio 8.02 --> "C:\Program Files\Ashampoo\Ashampoo Burning Studio 8\unins000.exe"
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
CDDRV_Installer --> MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
CloneDVD 4.1.0.2 --> "C:\Program Files\CloneDVD\unins000.exe"
Diskeeper 2008 Pro Premier --> MsiExec.exe /X{67A48ED5-0B6A-470A-995C-B8F1942E8AB9}
DU Meter --> "C:\Program Files\DU Meter\unins000.exe"
DVD-CLONER V5.00 Build 959 --> "C:\Program Files\Dvd-cloner\unins000.exe"
DVD X Player 4.1 Professional --> "C:\Program Files\DVD X Studios\DVD X Player 4.1 Professional\unins000.exe"
DVDFab (Platinum/Gold/HD Decrypter) (Option: Mobile) 5.0.5.0 --> "C:\Program Files\DVDFab 5\unins000.exe"
e-tax 2008 --> C:\etax2008\e-tax 2008_uninstall.exe
Easy Video Joiner 5.21 --> "C:\Program Files\Easy Video Joiner\unins000.exe"
ESET Smart Security --> MsiExec.exe /I{A1350B64-1AF8-497B-AC07-307DF67FB8D4}
FlashGet 1.9.6.1073 --> C:\Program Files\FlashGet\uninst.exe
FLV to AVI MPEG WMV 3GP MP4 iPod Converter 3.9.1108 --> "C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter\unins000.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
IconPackager --> "C:\ProgramData\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}\IconPackager.exe" REMOVE=TRUE MODIFY=FALSE
IconPackager --> C:\ProgramData\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}\IconPackager.exe
iriver plus 3 (remove only) --> "C:\Program Files\iriver\iriver plus 3\uninstall.exe"
Java(TM) 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
K-Lite Mega Codec Pack 4.0.0 --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
KhalInstallWrapper --> MsiExec.exe /I{56918C0C-0D87-4CA6-92BF-4975A43AC719}
LimeWire PRO 4.12.15 --> "C:\Program Files\LimeWire\uninstall.exe"
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe -runfromtemp -l0x0009 -removeonly
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Manga Reader --> MsiExec.exe /I{3ECBDD38-4E6A-4760-AD6F-BE09DF2509E2}
MCE Software Encoder 1.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7655E113-C306-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3tag v2.40 --> C:\Program Files\Mp3tag\Mp3tagUninstall.EXE
MSVC80_x86 --> MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
Nero 8 --> MsiExec.exe /X{5FCCD531-1B38-4A94-924C-127F722F1033}
neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050) --> "C:\Program Files\ESET\ESET Smart Security\unins000.exe"
Nokia Connectivity Cable Driver --> MsiExec.exe /X{0A3D3C54-2EC0-4D67-B265-FF17926E6D67}
Nokia PC Suite --> C:\ProgramData\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Nokia_PC_Suite_rel_6_85_14_1_eng.exe
Nokia PC Suite --> MsiExec.exe /I{29466F9C-7C6A-419C-B301-F440FAF78760}
NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
Opera 9.51 --> MsiExec.exe /X{1219497F-FA96-4D8E-9571-9C27A2A66B38}
PC Connectivity Solution --> MsiExec.exe /I{BA084E7C-8ABA-4670-BDE8-B85E689A5C1B}
QuickTime Alternative 2.6.0 --> "C:\Program Files\QuickTime Alternative\unins000.exe"
ReadyDriver Plus 1.1 --> "C:\BOOT\unins000.exe"
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
SpeedFan (remove only) --> "C:\Program Files\SpeedFan\uninstall.exe"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins001.exe"
System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe
TypingMaster Pro --> "C:\Program Files\TypingMaster\unins000.exe"
Unreal Tournament 3 --> "C:\Users\David Luu\AppData\Roaming\InstallShield Installation Information\{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}\SetupUT3.exe" -runfromtemp -l0x0409 -removeonly
Unreal Tournament 3 --> MsiExec.exe /X{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}
Update for Outlook 2007 Junk Email Filter (kb943597) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A751F0DB-8476-4207-956E-20AEBBA4B1DA}
VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Driver Package - Nokia Modem (08/03/2007 6.84.0.2) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_7837a5db\nokbtmdm.inf
Windows Driver Package - Nokia Modem (10/12/2007 3.6) --> C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_ee12375f\nokia_bluetooth.inf
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip 11.1 --> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}
-- Application Event Log -------------------------------------------------------
Event Record #/Type30895 / Success
Event Submitted/Written: 07/16/2008 09:57:05 PM
Event ID/Source: 5617 / WinMgmt
Event Description:
Event Record #/Type30891 / Success
Event Submitted/Written: 07/16/2008 09:57:03 PM
Event ID/Source: 5615 / WinMgmt
Event Description:
Event Record #/Type30888 / Success
Event Submitted/Written: 07/16/2008 09:57:02 PM
Event ID/Source: 902 / Software Licensing Service
Event Description:
The Software Licensing service has started.
Event Record #/Type30878 / Warning
Event Submitted/Written: 07/16/2008 09:55:59 PM
Event ID/Source: 1530 / profsvc
Event Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-2239309248-3206472011-774798463-1000_Classes:
Process 1424 (\Device\HarddiskVolume2\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000_CLASSES
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000_CLASSES
Event Record #/Type30877 / Warning
Event Submitted/Written: 07/16/2008 09:55:59 PM
Event ID/Source: 1530 / profsvc
Event Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
12 user registry handles leaked from \Registry\User\S-1-5-21-2239309248-3206472011-774798463-1000:
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 1424 (\Device\HarddiskVolume2\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\My
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\My
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\CA
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\trust
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Policies\Microsoft\SystemCertificates
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Policies\Microsoft\SystemCertificates
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\Root
Process 1564 (\Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\ekrn.exe) has opened key \REGISTRY\USER\S-1-5-21-2239309248-3206472011-774798463-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type2531430 / Error
Event Submitted/Written: 07/16/2008 10:00:00 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Remote Access Connection ManagerTelephony%%1297
Event Record #/Type2531429 / Error
Event Submitted/Written: 07/16/2008 10:00:00 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Telephony%%1297
Event Record #/Type2531428 / Error
Event Submitted/Written: 07/16/2008 10:00:00 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Remote Access Connection ManagerTelephony%%1297
Event Record #/Type2531427 / Error
Event Submitted/Written: 07/16/2008 10:00:00 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Telephony%%1297
Event Record #/Type2531426 / Error
Event Submitted/Written: 07/16/2008 09:59:40 PM
Event ID/Source: 7001 / Service Control Manager
Event Description:
Remote Access Connection ManagerTelephony%%1297
-- End of Deckard's System Scanner: finished at 2008-07-16 22:02:46 ------------