Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Closed Thread
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old July 18th, 2008, 07:19 AM
srisa srisa is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2006
Location: I'm sneaking up behind you.
Posts: 873 srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 7 h 1 m 51 sec
Reputation Power: 68
SpywareCleanerSerice : service failed to start.

Hello,
I get the entry "SpywareCleanerService service failed to start due to the following error:
The system cannot find the file specified."
in the event logs every time I boot the system.
I didn't install anything with that name. I checked the services list and found "SpywareCleanerService". It is pointing to a file in C:\program files\spyware cleaner\SC service.exe.
There isn't any such directory much less a file with that name.
I disabled the service.
How do I delete that service?

Thank you.
__________________
What you get is either what you desired or what you deserved.
Death seems to be such an abominable thing, but do we really want to live for ever?

Reply With Quote
  #2  
Old July 18th, 2008, 11:38 AM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,889 Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 19 h 11 m 32 sec
Reputation Power: 675
Hi there, This needs further investigation for now do this...

Click Start > Run and copy and paste these commands hitting enter after each one:..


sc stop SpywareCleanerService

sc delete SpywareCleanerService


I will get this topic moved to the virus section for a better look.
__________________
Neera: The wraith will not allow us to escape.
Sheppard: Yeah, well I try not to let them tell me what I can and can't do.
Neera: You do not fear them?
Sheppard: The wraith, nah. Now clowns that's another story. They scare the crap out of me.


Reply With Quote
  #3  
Old July 19th, 2008, 04:55 AM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,542 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 7 h 2 m 26 sec
Reputation Power: 1952
Thread moved from Windows Help to Antivirus Protection.
__________________
The No Ma'am commandments:

1.) It is O.K. to call hooters 'knockers' and sometimes snack trays
2.) It is wrong to be French
3.) It is O.K. to put all bad people in a giant meat grinder
4.) Lawyers, see rule 3
5.) It is O.K. to drive a gas guzzler if it helps you get babes
6.) Everyone should car pool but me
7.) Bring back the word 'stewardesses'
8.) Synchronized swimming is not a sport
9.) Mud wrestling is a sport

Reply With Quote
  #4  
Old July 19th, 2008, 01:12 PM
srisa srisa is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2006
Location: I'm sneaking up behind you.
Posts: 873 srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 7 h 1 m 51 sec
Reputation Power: 68
Quote:
Originally Posted by Porthos
Hi there, This needs further investigation for now do this...
Click Start > Run and copy and paste these commands hitting enter after each one:..

sc stop SpywareCleanerService
sc delete SpywareCleanerService

I will get this topic moved to the virus section for a better look.

I ran the commands as told by you and here is the output.
Code:
sc stop SpywareCleanerService
	[SC] ControlService FAILED 1062:
	The service has not been started.
sc delete SpywareCleanerService
	[SC] DeleteService SUCCESS.

Let me know if anything else is needed.
Thanks.

Reply With Quote
  #5  
Old July 19th, 2008, 03:24 PM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,889 Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 19 h 11 m 32 sec
Reputation Power: 675
Lets take a deeper look at you system.

Download Deckard's System Scanner. HERE

1. Close all applications and windows.
2. Double-click on dss.exe to run it, and follow the prompts.
3. When the scan is complete, a text file will open - Main.txt
4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt in your thread here.
5. A folder, C:\Deckard, will also open. In it will be another text file, Extra.txt.
6. Attach Extra.txt to your post.

Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.

What Deckard's System Scanner will do:

* create a new System Restore point in Windows XP and Vista.
* clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
* check some important areas of your system and produce a report for your analyst to review. Deckard's System Scanner automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.


When you get the two notepad documents, click somewhere inside the notepad document and hold CTRL/Control and press A then C. This will "select all" and "copy" the text.

Please post both of the logs.

Reply With Quote
  #6  
Old July 20th, 2008, 08:46 AM
srisa srisa is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2006
Location: I'm sneaking up behind you.
Posts: 873 srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 7 h 1 m 51 sec
Reputation Power: 68
I have avg8. Can I install dss alongside avg8?

Reply With Quote
  #7  
Old July 20th, 2008, 09:22 AM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,889 Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 19 h 11 m 32 sec
Reputation Power: 675
DSS is not an antivirus it just produces logs that tell me whats going on in your system.

Reply With Quote
  #8  
Old July 20th, 2008, 10:20 AM
srisa srisa is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2006
Location: I'm sneaking up behind you.
Posts: 873 srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 7 h 1 m 51 sec
Reputation Power: 68
Can I post the logs as they are or should I remove any lines from those logs? Thanks.

Reply With Quote
  #9  
Old July 20th, 2008, 01:55 PM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,889 Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level)Porthos User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 19 h 11 m 32 sec
Reputation Power: 675
Post them as-is and use as many posts as you need.

Reply With Quote
  #10  
Old July 21st, 2008, 05:19 AM
srisa srisa is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2006
Location: I'm sneaking up behind you.
Posts: 873 srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level)srisa User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 7 h 1 m 51 sec
Reputation Power: 68
Extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel(R) Pentium(R) 4 CPU 2.66GHz
Percentage of Memory in Use: 70%
Physical Memory (total/avail): 502.73 MiB / 147.14 MiB
Pagefile Memory (total/avail): 1228.02 MiB / 843.79 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1920.13 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 9.77 GiB total, 1.39 GiB free.
D: is Fixed (NTFS) - 39.06 GiB total, 9.65 GiB free.
E: is Fixed (NTFS) - 14.92 GiB total, 0.34 GiB free.
F: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - SAMSUNG HD080HJ - 74.53 GiB - 6 partitions
\PARTITION0 (bootable) - Installable File System - 9.77 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 64.75 GiB - D: - E:
\PARTITION2 - Unknown - 7.84 MiB



-- Security Center -------------------------------------------------------------

AUOptions is set to notify before install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

AV: AVG Anti-Virus Free v8.0 (AVG Technologies)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Authoriz edApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*isabled:Internet Explorer"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1133871972\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1133871972\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1133871972\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1133871972\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\narin\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SARIN
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\narin
include=C:\Program Files\Microsoft Visual Studio\VC98\atl\include;C:\Program Files\Microsoft Visual Studio\VC98\mfc\include;C:\Program Files\Microsoft Visual Studio\VC98\include
lib=C:\Program Files\Microsoft Visual Studio\VC98\mfc\lib;C:\Program Files\Microsoft Visual Studio\VC98\lib
LOGONSERVER=\\SARIN
MSDevDir=C:\Program Files\Microsoft Visual Studio\Common\MSDev98
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=D:\perl\bin\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\BINN;d:\php;C:\Program Files\MySQL\MySQL Server 5.0\bin;c:\program files\java\jre1.6.0_05\bin;c:\program files\java\jre1.6.0_05\bin\client\classes.jsa;C:\Program Files\Microsoft Visual Studio\Common\Tools\WinNT;C:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin;C:\Program Files\Microsoft Visual Studio\Common\Tools;C:\Program Files\Microsoft Visual Studio\VC98\bin;C:\Program Files\CVSNT\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PHPRC=d:\php
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\narin\LOCALS~1\Temp
TMP=C:\DOCUME~1\narin\LOCALS~1\Temp
USERDOMAIN=SARIN
USERNAME=narin
USERPROFILE=C:\Documents and Settings\narin
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

narin (admin)
tester (new local)
Administrator.SARIN (admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ActivePerl 5.8.8 Build 817 --> MsiExec.exe /I{D406F819-C4E6-4578-B1C7-8C34602D6FB0}
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0.5 Language Support --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-7050000000A7}
Adobe Reader 7.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
Adobe® Photoshop® Album Starter Edition 3.0.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9618743-1A5C-461E-91C4-E013A3D70F3C}\Setup.exe" -l0x9
Agent Ransack Version 1.7.3 --> "D:\Program Files\Mythicsoft\Agent Ransack\unins000.exe"
Apache HTTP Server 2.2.8 --> MsiExec.exe /I{85262A06-2D8C-4BC1-B6ED-5A705D09CFFC}
API-Guide (remove only) --> "D:\Program Files\API-Guide\uninstall.exe"
AVG Free 8.0 --> C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
CVSNT 2.5.03.2382 --> MsiExec.exe /I{7C480BB2-42A9-40C6-AA5F-7AA20FC7C7F3}
D-Link PCI Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $D-Link
DameWare Mini Remote Control --> MsiExec.exe /I{30C24778-71F2-4CC7-ACF3-AD33E0019154}
DFE-520TX --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{FCACC379-FEC9-49FE-8FD9-8CD9D6A4F46F}
DVD Suite --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
FileZilla Client 3.0.3 --> D:\Program Files\FileZilla Client\uninstall.exe
FlashGet(JetCar) --> D:\PROGRA~1\FlashGet\UNWISE.EXE D:\PROGRA~1\FlashGet\INSTALL.LOG
Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
Google Talk (remove only) --> "C:\Program Files\Google\Google Talk\uninstall.exe"
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Intel(R) Graphics Media Accelerator Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2782 PCI\VEN_8086&DEV_2582
Intel(R) PRO Network Adapters and Drivers --> Prounstl.exe
Internet Explorer Developer Toolbar --> MsiExec.exe /I{E7081891-BC7F-43F9-9CE6-B5DD2F497156}
Introduction to Visual Basic 2005 --> MsiExec.exe /I{638C1D72-FFAD-4EC3-B1AD-ABA96BB15B0B}
Introduction to Visual Basic 2005 Code Samples --> MsiExec.exe /I{5FB8673A-9B8C-4FA1-AB04-9B28F860DC92}
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE
LiveUpdate 1.80 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Magic ISO Maker v5.3 (build 0229) --> D:\PROGRA~1\MagicISO\UNWISE.EXE D:\PROGRA~1\MagicISO\INSTALL.LOG
Maxtor Manager --> "C:\Program Files\InstallShield Installation Information\{ED01D958-AEDC-40C8-93FD-0C08E8AA9530}\setup.exe" -runfromtemp -l0x0409 -removeonly
Maxtor Manager --> MsiExec.exe /I{ED01D958-AEDC-40C8-93FD-0C08E8AA9530}
MCSE Training Kit - Microsoft Windows XP Professional eBook --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A929BD3D-A45B-41DB-8124-4BA15AF46371}\setup.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Encyclopedia of Networking eBook --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MSPress\BooksOnline\Microsoft Encyclopedia of Networking eBook\Uninst.isu"
Microsoft Office 2000 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft SQL Server 2000 --> C:\WINDOWS\IsUninst.exe -f"d:\Program Files\Microsoft SQL Server\MSSQL\Uninst.isu" -c"d:\Program Files\Microsoft SQL Server\MSSQL\sqlsun.dll" -msql.mif i=MSSQLSERVER
Microsoft Text-to-Speech Engine 4.0 (English) --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTSf22.inf, Uninstall
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual Basic 2005 Express Edition - ENU --> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU --> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual Studio 6.0 Enterprise Edition --> "C:\Program Files\Microsoft Visual Studio\Common\Setup\1033\Setup.exe"
Microsoft Web Publishing Wizard 1.53 --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
Mozilla Firefox (2.0.0.1) --> C:\Program Files\Mozilla Firefox\uninstall\uninst.exe
Mozilla Firefox (2.0.0.16) --> D:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MySQL Server 5.0 --> MsiExec.exe /I{3CB15F63-7D48-4694-B68E-3D6E25D5C932}
Nero 7 Essentials --> MsiExec.exe /X{AAB93551-3FFE-42B2-8315-96252BBC1033}
Nero Suite --> C:\Program Files\Common Files\Nero\Uninstall\Setupx.exe /uninstall ExtraUninstallID=""
Opera 9.10 --> MsiExec.exe /X{5D582D33-EB35-4D77-B7AF-403322D947E6}
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
PuTTY version 0.59 --> "D:\Program Files\PuTTY\unins000.exe"
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" REMOVE
Rediff Bol v7.0 --> "C:\Program Files\Rediff Bol\unins000.exe"
RockN Wave Editor --> C:\WINDOWS\uninst.exe -f"d:\program files\rocknaudio\DeIsL1.isu" -c"d:\program files\rocknaudio\_ISREG32.DLL"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Sify Broadband 3.22 --> "C:\Program Files\Sify Broadband\unins000.exe"
SmartFTP Client --> MsiExec.exe /I{C169D3BB-9A27-43F5-9979-09A0D65FE95C}
SmartFTP Client 2.0 Setup Files (remove only) --> "D:\Program Files\SmartFTP Client 2.0 Setup Files\uninst-sftp.exe"
TextAloud --> "D:\Program Files\TextAloud\unins000.exe"
TortoiseCVS 1.10.3 --> "D:\Program Files\TortoiseCVS\unins000.exe"
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
ViewSonic Monitor Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\Setup.exe" -l0x9
win32 online help --> "C:\WINDOWS\UNISTB32.EXE" /U "D:\lcc\UNINST0.000" "D:\lcc\UNINST1.000"
Winamp (remove only) --> "D:\Program Files\Winamp\UninstWA.exe"
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> d:\Program Files\WinRAR\uninstall.exe
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
WordWeb Pro --> D:\Program Files\WordWeb\uninst.exe
XMLinst --> MsiExec.exe /I{EA23971F-2CEE-48FC-B64D-7F74A6EF90F0}
Xvid 1.1.3 final uninstall --> "D:\Program Files\Xvid\unins000.exe"
Yahoo! Extras --> C:\PROGRA~1\Yahoo!\Common\unyext.exe
Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI~1.DLL


-- Application Event Log -------------------------------------------------------

Event Record #/Type22456 / Warning
Event Submitted/Written: 07/20/2008 05:45:07 PM
Event ID/Source: 32068 / Microsoft Fax
Event Description:
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
Country/region code: '*'
Area code: '*'

Event Record #/Type22455 / Warning
Event Submitted/Written: 07/20/2008 05:45:07 PM
Event ID/Source: 32026 / Microsoft Fax
Event Description:
Fax Service failed to initialize any assigned fax devices (virtual or TAPI).
No faxes can be sent or received until a fax device is installed.

Event Record #/Type22436 / Warning
Event Submitted/Written: 07/19/2008 09:34:31 PM
Event ID/Source: 32068 / Microsoft Fax
Event Description:
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
Country/region code: '*'
Area code: '*'

Event Record #/Type22435 / Warning
Event Submitted/Written: 07/19/2008 09:34:31 PM
Event ID/Source: 32026 / Microsoft Fax
Event Description:
Fax Service failed to initialize any assigned fax devices (virtual or TAPI).
No faxes can be sent or received until a fax device is installed.

Event Record #/Type22421 / Warning
Event Submitted/Written: 07/19/2008 06:38:13 PM
Event ID/Source: 32068 / Microsoft Fax
Event Description:
The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
Country/region code: '*'
Area code: '*'



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type4654 / Error
Event Submitted/Written: 07/18/2008 06:10:15 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The World Wide Web Publishing service terminated unexpectedly. It has done this 1 time(s).

Event Record #/Type4653 / Error
Event Submitted/Written: 07/18/2008 06:10:15 PM
Event ID/Source: 7031 / Service Control Manager
Event Description:
The IIS Admin service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1 milliseconds: Run the configured recovery program.

Event Record #/Type4626 / Error
Event Submitted/Written: 07/18/2008 04:38:43 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The SpywareCleanerService service failed to start due to the following error:
%%2

Event Record #/Type4587 / Error
Event Submitted/Written: 07/18/2008 10:09:55 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The SpywareCleanerService service failed to start due to the following error:
%%2

Event Record #/Type4555 / Error
Event Submitted/Written: 07/17/2008 10:04:46 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The SpywareCleanerService service failed to start due to the following error:
%%2



-- End of Deckard's System Scanner: finished at 2008-07-20 20:10:38 ------------