Deckards Scan:
Deckard’s System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
– System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlon™ XP 3000+
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 447.48 MiB / 109.57 MiB
Pagefile Memory (total/avail): 1055.93 MiB / 695.47 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1931.77 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 144.89 GiB total, 129.76 GiB free.
D: is Fixed (FAT32) - 4.14 GiB total, 0.61 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
J: is Removable (No Media)
\.\PHYSICALDRIVE0 - SAMSUNG SP1604N - 149.05 GiB - 2 partitions
\PARTITION0 - Unknown - 4.15 GiB - D:
\PARTITION1 (bootable) - Installable File System - 144.89 GiB - C:
\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
– Security Center ---------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: avast! antivirus 4.7.1043 [VPS 071207-0] v4.7.1043 (ALWIL Software)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=“%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019"
“C:\Program Files\MSN Messenger\msnmsgr.exe”="C:\Program Files\MSN Messenger\msnmsgr.exe::Enabled:MSN Messenger 7.5”
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”="%windir%\system32\sessmgr.exe::enabled:@xpsp2res.dll,-22019”
“C:\Program Files\Yahoo!\Messenger\YPager.exe”=“C:\Program Files\Yahoo!\Messenger\YPager.exe::Enabled:Yahoo! Messenger"
“C:\Program Files\WinMX\WinMX.exe”="C:\Program Files\WinMX\WinMX.exe::Enabled:WinMX Application”
“C:\Program Files\Canasis\canasis.exe”=“C:\Program Files\Canasis\canasis.exe::Enabled:Canasis"
“C:\Program Files\WildTangent\Blasterball 2\BB2.exe”="C:\Program Files\WildTangent\Blasterball 2\BB2.exe::Enabled:BB2”
“C:\Program Files\Yahoo!\Messenger\YServer.exe”=“C:\Program Files\Yahoo!\Messenger\YServer.exe::Enabled:YServer Module"
“C:\WINDOWS\system32\rtcshare.exe”="C:\WINDOWS\system32\rtcshare.exe::Enabled:RTC App Sharing”
“C:\Program Files\NetMeeting\conf.exe”=“C:\Program Files\NetMeeting\conf.exe::Enabled:Windows® NetMeeting®"
“C:\Program Files\Real\RealOne Player\realplay.exe”="C:\Program Files\Real\RealOne Player\realplay.exe::Enabled:RealOne Player”
“C:\Program Files\Yahoo! Games\Boggle Supreme\BoggleSupreme.exe”=“C:\Program Files\Yahoo! Games\Boggle Supreme\BoggleSupreme.exe::Enabled:Boggle Supreme"
“C:\WINDOWS\system32\rundll32.exe”="C:\WINDOWS\system32\rundll32.exe::Disabled:Run a DLL as an App”
“C:\WINDOWS\system32\dpvsetup.exe”=“C:\WINDOWS\system32\dpvsetup.exe::Enabled:Microsoft DirectPlay Voice Test"
“C:\Program Files\MSN Messenger\msnmsgr.exe”="C:\Program Files\MSN Messenger\msnmsgr.exe::Enabled:MSN Messenger 7.5”
“%windir%\Network Diagnostic\xpnetdiag.exe”=“%windir%\Network Diagnostic\xpnetdiag.exe::Enabled:@xpsp3res.dll,-20000"
“C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe”="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe::Enabled:Yahoo! Messenger”
“C:\Program Files\Bonjour\mDNSResponder.exe”=“C:\Program Files\Bonjour\mDNSResponder.exe::Enabled:Bonjour"
“C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe”="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe::Enabled:EasyShare”
“C:\Program Files\BearShare Applications\BearShare\BearShare.exe”=“C:\Program Files\BearShare Applications\BearShare\BearShare.exe::Enabled:BearShare"
“C:\Program Files\U.S. Robotics\Instant Update\InstUpDt.exe”="C:\Program Files\U.S. Robotics\Instant Update\InstUpDt.exe::Disabled:Instant Update Configuration EXE”
“C:\WINDOWS\io43mvuiw4kj.exe”=“C:\WINDOWS\io43mvuiw4kj.exe::Disabled:io43mvuiw4kj"
“C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe”="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe::Disabled:Kodak Software Updater”
“C:\Program Files\LimeWire\LimeWire.exe”=“C:\Program Files\LimeWire\LimeWire.exe::Disabled:LimeWire"
“C:\StubInstaller.exe”="C:\StubInstaller.exe::Disabled:LimeWire swarmed installer”
“C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe”=“C:\Program Files\Yahoo! Games\Magic Ball\MagicBall.exe:*:Disabled:MagicBall”
“C:\WINDOWS\system32\ckvqeaym.exe”=“C:\WINDOWS\system32\ckv”
“C:\WINDOWS\system32\bwpvvsjk.exe”=“C:\WINDOWS\system32\bwp”
“C:\WINDOWS\system32\dtbyqqxg.exe”=“C:\WINDOWS\system32\dtb”
– Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Owner\Application Data
CLASSPATH=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=JORDAN
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Owner
LD_LIBRARY_PATH=c:\Corel\Office7\Shared\TrueDoc\Bin
LOGONSERVER=\JORDAN
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\PC-Doctor for Windows\services;C:\Program Files\QuickTime\QTSystem;;c:\Corel\Office7\Shared\TrueDoc\Bin
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
USERDOMAIN=JORDAN
USERNAME=Owner
USERPROFILE=C:\Documents and Settings\Owner
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI