![]() Some months ago i downloaded limewire and i got the same problem that i also had with Kazza - everything starts ok - it connects fine then as soon as the screen opens it closes again - just minimises so the programe is still open and displaying an icon in the bottom right hand corner BUT if you try to reopen it - it opens then closes straight away I gave up and removed limewire (and kazza) from my computer - but i have now decided that i want to get to the bottom of this as i want to download some music Any help would be greatfully recieved thanks Helen |
![]() Did you want all of it ? because it is very long Code: BEARDIAG ISSUES - brief summary: (Extracted on 2006/07/24 17:04:45) Physical Memory size of 255.5Mb may be an issue. BearShare installation unable to be verified. Information extracted so far by BearDiag will be reported More technical diagnostic troubleshooting information follows: Code: BEARDIAG: Bearcare for BearShare. Details collected on 2006/07/24 17:03:40, BEARDIAG Version beta, expires 2006/11/30 (129 days), running from C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\BearDiag[1].exe System Hardware Information CPU Type is: Intel(R) Pentium(R) 4 CPU 2.80GHz, CPU speed is approx: 2800Mhz, System BIOS date is: 2004/05/13 OS Version is: WIN_XP, Service pack: Service Pack 2, OS Build: 2600, Computer Name: GREENHALGH Browser name: C:\Program Files\Internet Explorer\IEXPLORE.EXE, version: 7.0.5346.5, Admin user? YES System Memory Parameters: Memory in use: 89% Total Physical RAM: 255.5Mb Available Physical RAM: 26.3Mb Total Pagefile: 617.0Mb Available Pagefile: 194.0Mb Internet IP Address 84.66.xxx.xxx Sorry! It appears that BearShare is not correctly installed on your system. This may be due to other peer-to-peer file sharing software overwriting important information. This may also be due to rogue anti-spyware incorrectly giving a false positive detection on BearShare. (The beta tester version of Microsoft anti-spyware is one example) You should re-install the latest version of BearShare to fix this. This program will now exit Diagnostic code: INSTALL [/SIZE] Code: StartupList report, 24/07/2006, 17:04:15 StartupList version: 1.52 Started from : C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\StartupList.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.5346.0005) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\KService\KService.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\mHotkey.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Akidthaine\fss.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\DropBox\DropBox\DropBox.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe C:\WINDOWS\NCLAUNCH.EXe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\WINDOWS\kdx\KHost.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\RICTIQ34\HijackThis.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\BearDiag[1].exe C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\StartupList.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Documents and Settings\waggi\Start Menu\Programs\Startup] Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run CHotkey = mHotkey.exe NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe Cmaudio = RunDll32 cmicnfg.cpl,CMICtrlWnd ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe BTopenworld = "c:\program files\bt yahoo! internet\DialBTYahoo.exe" /ReInstallAutoDial Lexmark X1100 Series = "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" SpeedTouch USB Diagnostics = "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon Microsoft Works Update Detection = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe fss = C:\Program Files\Akidthaine\fss.exe Picasa Media Detector = C:\Program Files\Picasa2\PicasaMediaDetector.exe HP Component Manager = "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" CaISSDT = "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe" CaAvTray = "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe" CAVRID = "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe" QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run OnceEx (Default) = -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe MoneyAgent = "C:\Program Files\Microsoft Money\System\mnyexpr.exe" STManager = "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b NCLaunch = C:\WINDOWS\NCLAUNCH.EXe balamory screen saver = "C:\Program Files\balamory\Screen Saver\TaskTray.exe" IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c KazaGold = C:\Program Files\Kaza Gold 3.2\KazaGold3.2.exe /hide SweetIM = C:\Program Files\Macrogaming\SweetIM\SweetIM.exe kdx = C:\WINDOWS\kdx\KHost.exe -all BitTorrent = "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\THOMAS~1.SCR drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670} (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - C:\Program Files\Etomi\Plugins\RazaWebHook.dll (file missing) - {0EEDB912-C5FA-486F-8334-57288578C627} (no name) - C:\PROGRA~1\wanadoo1\wanadoo1.dll - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} (no name) - (no file) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} (no name) - (no file) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} (no name) - (no file) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} -------------------------------------------------- Enumerating Task Scheduler jobs: Disk Cleanup.job eTrust Antivirus.job Microsoft AntiSpyware.job MP Scheduled Scan.job -------------------------------------------------- Enumerating Download Program Files: [YExplorer1_8US.CAB] CODEBASE = http://photos.groups.yahoo.com/ocx/u...lorer1_8us.cab OSD = C:\WINDOWS\Downloaded Program Files\YExplorer1_8US.CAB.osd [Checkers Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\msgrchkr.dll CODEBASE = http://messenger.zone.msn.com/binary...r.cab31267.cab [Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\macromed\Shockwave 10\Download.dll CODEBASE = http://fpdownload.macromedia.com/get...irector/sw.cab [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204 [{205FF73B-CA67-11D5-99DD-444553540000}] CODEBASE = http://www.spywarestormer.com/files2/Install.cab [{233C1507-6A77-46A4-9443-F871F945D258}] CODEBASE = http://download.macromedia.com/pub/s...irector/sw.cab [Citrix ICA Client] InProcServer32 = C:\Progra~1\Citrix\icaweb32\WFICA.OCX CODEBASE = http://www.uclan.ac.uk/other/iss/remote/wficat.cab [YInstStarter Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\yinsthelper.dll CODEBASE = http://download.yahoo.com/dl/installs/yinst0401.cab [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeup...ntent/opuc.cab [MSN Photo Upload Tool] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll CODEBASE = http://spaces.msn.com//PhotoUpload/MsnPUpld.cab [MUWebControl Class] InProcServer32 = C:\WINDOWS\system32\muweb.dll CODEBASE = http://update.microsoft.com/microsof...?1125234078125 [MessengerStatsClient Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll CODEBASE = http://messenger.zone.msn.com/binary...t.cab31267.cab [Seekford Solutions, Inc.'s ssiPictureUploader Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\SSIPIC~1.OCX CODEBASE = http://img.funtigo.com/images/upload...reUploader.cab [Get_ActiveX Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\HPGETD~1.OCX CODEBASE = https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx [MsnMessengerSetupDownloadControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx CODEBASE = http://messenger.msn.com/download/Ms...Downloader.cab [{B9191F79-5613-4C76-AA2A-398534BB8999}] CODEBASE = http://us.dl1.yimg.com/download.yaho...tocomplete.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx CODEBASE = http://fpdownload.macromedia.com/get...sh/swflash.cab [QDiagHUpdateObj Class] InProcServer32 = C:\WINDOWS\system32\qdiagh.ocx CODEBASE = http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 [MSN Chat Control 4.5] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MSNChat45.ocx CODEBASE = http://chat.msn.com/controls/msnchat45.cab [Solitaire Showdown Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\solitaireshowdown.dll CODEBASE = http://messenger.zone.msn.com/binary...n.cab31267.cab -------------------------------------------------- Enumerating Winsock LSP files: Protocol #1: C:\WINDOWS\system32\VetRedir.dll Protocol #2: C:\WINDOWS\system32\VetRedir.dll Protocol #3: C:\WINDOWS\system32\VetRedir.dll Protocol #23: C:\WINDOWS\system32\VetRedir.dll -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: C:\DOCUME~1\waggi\LOCALS~1\Temp\~nsu.tmp\Au_.ex e||C:\DOCUME~1\waggi\LOCALS~1\Temp\nsd1B.tmp\Sy stem.dll||C:\DOCUME~1\waggi\LOCALS~1\Temp\nsd1B .tmp\||C:\Config.Msi\f898f.rbf||C:\Config.Msi\f8b9 a.rbf|||l -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll -------------------------------------------------- End of report, 12,529 bytes Report generated in 1.000 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only Last edited by AaronWalkhouse; July 24th, 2006 at 10:18 AM. |
![]() Code: Current task list information for waggi, running WIN_XP, Service Pack 2, build 2600 Details collected on 2006/07/24 17:03:50 PID Process Name File Version Peak Mem Usage. PageFaults. VM PageFileUsage.Handles.Threads.ReadOperations.WriteOperations.ReadTransferCount.WriteTransferCount.Command line that invoked task 0 System Idle Process 0Mb 0 0Mb 0 1 0 0 0 0 >< 4 System 2.01Mb 7621 0Mb 1139 62 46696 33492 72980165 270397365 >< 392 smss.exe 5.1.2600.2180 0.45Mb 237 0.16Mb 21 3 472 4 1377672 4 >\SystemRoot\System32\smss.exe< 444 csrss.exe 3.2Mb 24147 1.71Mb 707 17 1105172 0 57381826 0 >< 468 winlogon.exe 5.1.2600.2180 32.55Mb 28734 6.77Mb 425 16 107303 102007 54198437 10459836 >winlogon.exe< 516 services.exe 5.1.2600.2180 3.96Mb 8805 1.94Mb 317 15 1642 3364 3724204 523973 >C:\WINDOWS\system32\services.exe< 528 lsass.exe 5.1.2600.2180 5.79Mb 399254 4.87Mb 387 20 115888 85126 9400506 7542954 >C:\WINDOWS\system32\lsass.exe< 688 svchost.exe 5.1.2600.2180 4.4Mb 8539 2.93Mb 212 15 3070 91 6336879 6546 >C:\WINDOWS\system32\svchost -k DcomLaunch< 736 svchost.exe 4Mb 8384 2.1Mb 402 11 650 6 1731385 300 >< 792 MsMpEng.exe 1.1.1347.0 16.85Mb 241438 9.21Mb 289 18 183291 1004 1624577885 22457044 >"C:\Program Files\Windows Defender\MsMpEng.exe"< 852 svchost.exe 5.1.2600.2180 72.89Mb 748552 26.14Mb 1876 80 2029024 1752473 4683558001 4736615574 >C:\WINDOWS\System32\svchost.exe -k netsvcs< 912 svchost.exe 2.68Mb 6879 1.65Mb 93 6 423 4 1029956 92 >< 972 svchost.exe 4.41Mb 2148 2.88Mb 208 13 521 18 1398820 1024 >< 1064 LEXBCES.EXE 2.83Mb 882 1.14Mb 139 9 151 4 479032 12 >C:\WINDOWS\system32\LEXBCES.EXE< 1108 LEXPPS.EXE 3.16Mb 2541 1.14Mb 92 11 286 1 678153 72 >LEXPPS.EXE< 1112 spoolsv.exe 5.1.2600.2696 5.46Mb 6492 3.71Mb 150 13 678 4 2253163 156 >C:\WINDOWS\system32\spoolsv.exe< 1276 iSafe.exe 10.67Mb 8982 7.85Mb 97 7 1173 54 34563299 3185756 >"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe"< 1308 KodakCCS.exe 1.1.5100.4 2.93Mb 932 0.89Mb 52 2 174 3 549503 84 >C:\WINDOWS\system32\drivers\KodakCCS.exe< 1352 KService.exe 4.21.51215.0 10.64Mb 27336 7.9Mb 468 30 7335 1528678 35728907 17036526 >"C:\Program Files\KService\KService.exe"< 1376 LogWatNT.exe 1.32Mb 617 0.6Mb 21 2 65 4 160784 228 >"C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe"< 1400 mdm.exe 7.0.9466.0 2.55Mb 1854 0.93Mb 90 4 420 42 1201016 336 >"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"< 1456 svchost.exe 5.1.2600.2180 3.9Mb 5323 2.3Mb 127 5 302 15 928392 711 >C:\WINDOWS\System32\svchost.exe -k imgsvc< 1476 wdfmgr.exe 1.58Mb 520 1.44Mb 65 4 15 6 63764 172 >< 1676 fxssvc.exe 5.2.2600.2180 3.24Mb 1164 1.48Mb 98 15 196 5 684157 8955 >C:\WINDOWS\system32\fxssvc.exe< 1364 alg.exe 3.43Mb 1259 1.29Mb 102 5 459 4 1143248 156 >< 2080 explorer.exe 6.0.2900.2180 21.58Mb 422785 19.82Mb 578 15 387452 19792 403022360 41645952 >C:\WINDOWS\Explorer.EXE< 2396 mHotkey.exe 3.43Mb 2754 2.14Mb 59 2 361 86 2013750 860304 >"C:\WINDOWS\mHotkey.exe" < 2496 atiptaxx.exe 3.89Mb 4742 2.68Mb 100 2 1117 206 4930968 2355514 >"C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" < 2548 lxbkbmgr.exe 2.05Mb 2514 0.55Mb 28 1 314 98 1800821 1003520 >"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" < 2560 dragdiag.exe 301.0.0.12 2.4Mb 3050 1.07Mb 36 1 744 196 3889856 2007040 >"C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon< 2568 WkUFind.exe 9.0.609.0 0.62Mb 255 0.19Mb 8 1 0 0 0 0 >"C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" < 2576 fss.exe 3.37Mb 2706 0.87Mb 34 1 593 196 3235275 2007040 >"C:\Program Files\Akidthaine\fss.exe" < 2588 lxbkbmon.exe 1.93Mb 7795 0.36Mb 24 1 2574 146 6483403 3317762 >"C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe"< 2604 PicasaMediaDetector. 3.95Mb 2664 2.41Mb 104 3 344 86 1995175 860304 >"C:\Program Files\Picasa2\PicasaMediaDetector.exe" < 2612 hpcmpmgr.exe 6.93Mb 9128 4.93Mb 201 4 3907 270 6952687 1367068 >"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" < 2624 hpwuSchd2.exe 1.75Mb 2779 0.49Mb 24 1 282 98 1660318 1003520 >"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" < 2676 caissdt.exe 7.73Mb 7188 5.75Mb 181 3 1502 145 5550118 888528 >"C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe" < 2700 CAVTray.exe 35.63Mb 552127 3.36Mb 127 29 5397956 183709 3229228380 358989897 >"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe" < 2720 CAVRid.exe 2.64Mb 3569 0.74Mb 57 3 330 84 1816377 860160 >"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe" < 2744 qttask.exe 12.64Mb 32280 10.13Mb 188 5 38908 97 44915736 1247706 >"C:\Program Files\QuickTime\qttask.exe" -atboottime< 2768 DropBox.exe 7.91Mb 19634 4.95Mb 151 5 818 2063 3729445 1721387 >"C:\Program Files\DropBox\DropBox\DropBox.exe" /s< 2800 MSASCui.exe 1.1.1347.0 9.39Mb 37354 8.61Mb 540 20 1151 92 4278468 866287 >"C:\Program Files\Windows Defender\MSASCui.exe" -hide< 2920 ctfmon.exe 5.1.2600.2180 3.07Mb 16818 1.49Mb 197 1 853 196 4063206 2007040 >"C:\WINDOWS\system32\ctfmon.exe" < 2960 drst.exe 10.33Mb 21084 9.21Mb 449 5 1641 678 6410826 5171276 >"C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b< 2976 NCLAUNCH.EXe 1.77Mb 2090 0.48Mb 26 1 248 84 1454494 860160 >"C:\WINDOWS\NCLAUNCH.EXe" < 3024 SweetIM.exe 5.64Mb 10595 3.25Mb 160 4 989 146 3175111 868105 >"C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" < 3060 KHost.exe 4.20.51102.0 6.35Mb 7653 3.89Mb 144 4 672 173 3231775 1720467 >"C:\WINDOWS\kdx\KHost.exe" -all< 3356 EasyShare.exe 17.68Mb 18837 15.69Mb 265 4 6836 249 12725208 2726184 >"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" -h< 3476 Kodak Software Updat 8.11Mb 309693 6.21Mb 306 12 41700 4065 137838656 5112264 >"C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe" < 276 HijackThis.exe 5.21Mb 3562 1.84Mb 44 1 885 90 3602145 2760704 >"C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\RICTIQ34\HijackThis.exe" /autolog< 3264 VetMsg.exe 3.93Mb 1192 1.79Mb 134 8 1363 6 2983531 300 >"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe"< 2196 WINWORD.EXE 11.0.8026.0 43.82Mb 40133 20.1Mb 271 4 23362 3699 105585799 2528435 >"C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" < 4024 iexplore.exe 7.0.5346.5 41.68Mb 44449 33.59Mb 636 11 14815 3096 24546690 1812792 >"C:\Program Files\Internet Explorer\iexplore.exe" < 3624 iexplore.exe 7.0.5346.5 70.81Mb 70015 64.14Mb 795 25 31836 8279 54278460 13470380 >"C:\Program Files\Internet Explorer\iexplore.exe" < 3332 wuauclt.exe 6.58Mb 1774 6.27Mb 176 8 1609 28 5331422 124560 >"C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[354]SUSDS17ae2abaca7acd4cbbfe814fb62411d2< 3484 BearDiag[1].exe 9.57Mb 2993 5.74Mb 231 6 1809 136 11683605 11837489 >"C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\BearDiag[1].exe" < 2400 wmiprvse.exe 5.22Mb 1365 2.81Mb 140 6 1439 12 4135900 888 >< BearShare library folder information for waggi, running WIN_XP, Service Pack 2, build 2600 Details collected on 2006/07/24 17:04:47 Code: Firewall information for waggi, running WIN_XP, Service Pack 2, build 2600 Details collected on 2006/07/24 17:05:38 Domain profile configuration: ------------------------------------------------------------------- Operational mode = Enable Exception mode = Enable Multicast/broadcast response mode = Enable Notification mode = Enable Service configuration for Domain profile: Mode Customized Name ------------------------------------------------------------------- Enable No UPnP Framework Allowed programs configuration for Domain profile: Mode Name / Program ------------------------------------------------------------------- Enable Remote Assistance / C:\WINDOWS\system32\sessmgr.exe Enable Windows Live Messenger 8.0 / C:\Program Files\MSN Messenger\msnmsgr.exe Enable Windows Live Messenger 8.0 (Phone) / C:\Program Files\MSN Messenger\msncall.exe Port configuration for Domain profile: Port Protocol Mode Name ------------------------------------------------------------------- 1900 UDP Enable SSDP Component of UPnP Framework 2869 TCP Enable UPnP Framework over TCP Standard profile configuration (current): ------------------------------------------------------------------- Operational mode = Enable Exception mode = Enable Multicast/broadcast response mode = Enable Notification mode = Enable Service configuration for Standard profile: Mode Customized Name ------------------------------------------------------------------- Enable No UPnP Framework Allowed programs configuration for Standard profile: Mode Name / Program ------------------------------------------------------------------- Enable Remote Assistance / C:\WINDOWS\system32\sessmgr.exe Enable Dr SpeedTouch / C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe Enable Internet Explorer / C:\Program Files\Internet Explorer\iexplore.exe Enable Files and Settings Transfer Wizard / C:\WINDOWS\system32\usmt\migwiz.exe Enable Windows Messenger / C:\Program Files\Messenger\msmsgs.exe Enable AOL Instant Messenger / C:\Program Files\AIM\aim.exe Enable IncrediMail Installer / C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\CP6F0PEN\incredimail_install[1].exe Enable IncrediMail / C:\Program Files\IncrediMail\bin\IMApp.exe Enable IncrediMail / C:\Program Files\IncrediMail\bin\IncMail.exe Enable IncrediMail / C:\Program Files\IncrediMail\bin\ImpCnt.exe Enable IncrediMail Installer / C:\Documents and Settings\waggi\Local Settings\Temporary Internet Files\Content.IE5\BNTF7HGW\incredimail_install[1].exe Enable RealPlayer / C:\Program Files\Real\RealPlayer\realplay.exe Enable ossproxy.exe / c:\windows\system32\ossproxy.exe Enable Kaza Gold / C:\Program Files\Kaza Gold 3.2\gift\giFTl.exe Enable Windows© NetMeeting© / C:\Program Files\NetMeeting\conf.exe Enable Yahoo! Messenger / C:\Program Files\Yahoo!\Messenger\ypager.exe Enable Yahoo! FT Server / C:\Program Files\Yahoo!\Messenger\YServer.exe Enable giFT Loader for KCeasy (http://www.kceasy.com) / C:\Program Files\KGTunes 4.7\giFT\giFTl.exe Enable Kazaa / C:\Program Files\Kazaa\kazaa.exe Enable System Process / C:\WINDOWS\system32\ccapp.exe Enable P2P Networking / C:\WINDOWS\system32\P2P Networking\P2P Networking.exe Enable Trillian / C:\Program Files\Trillian\trillian.exe Enable Microsoft Fax Console / C:\WINDOWS\system32\fxsclnt.exe Enable LimeWire swarmed installer / C:\StubInstaller.exe Enable HP Software Update Client / C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe Enable LimeWire / C:\Program Files\LimeWire\LimeWire.exe Enable Kodak Software Updater / C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe Enable DropBox / C:\Program Files\DropBox\DropBox\DropBox.exe Enable Delivery Manager / C:\WINDOWS\kdx\KHost.exe Enable Delivery Manager Service / C:\Program Files\KService\KService.exe Enable Windows Live Messenger 8.0 / C:\Program Files\MSN Messenger\msnmsgr.exe Enable Windows Live Messenger 8.0 (Phone) / C:\Program Files\MSN Messenger\msncall.exe Enable BitTorrent / C:\Program Files\BitTorrent\bittorrent.exe Port configuration for Standard profile: Port Protocol Mode Name ------------------------------------------------------------------- 1900 UDP Enable SSDP Component of UPnP Framework 2869 TCP Enable UPnP Framework over TCP Log configuration: ------------------------------------------------------------------- File location = C:\WINDOWS\pfirewall.log Max file size = 4096 KB Dropped packets = Disable Connections = Disable Local Area Connection firewall configuration: ------------------------------------------------------------------- Operational mode = Enable 1394 Connection firewall configuration: ------------------------------------------------------------------- Operational mode = Enable PRPX firewall configuration: ------------------------------------------------------------------- Operational mode = Enable BTOW firewall configuration: ------------------------------------------------------------------- Operational mode = Enable Speedtouch Connection firewall configuration: ------------------------------------------------------------------- Operational mode = Enable Further firewall information for opened ports on: GREENHALGH Port configuration for Domain profile: Port Protocol Mode Name ------------------------------------------------------------------- 1900 UDP Enable SSDP Component of UPnP Framework 2869 TCP Enable UPnP Framework over TCP Port configuration for Standard profile: Port Protocol Mode Name ------------------------------------------------------------------- 1900 UDP Enable SSDP Component of UPnP Framework 2869 TCP Enable UPnP Framework over TCP Last edited by AaronWalkhouse; July 24th, 2006 at 10:32 AM. |
![]() Hoo boy! Have you got problems! ![]() ![]() What you have is 256 megs of memory overfilled with about 651.7 megs of software. No wonder your windows are closing themselves. Get a fresh copy of Hijackthis from here: http://www.merijn.org/files/hijackthis.zip Run it and push "Do a system scan and save a log file" then post it here. I'll pick a bunch of things for you to put a check mark on. |
![]() Logfile of HijackThis v1.99.1 Scan saved at 22:27:30, on 24/07/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5346.0005) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\KService\KService.exe C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\mHotkey.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Akidthaine\fss.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\DropBox\DropBox\DropBox.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe C:\WINDOWS\NCLAUNCH.EXe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\WINDOWS\kdx\KHost.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Helen Greenhalgh\Local Settings\Temporary Internet Files\Content.IE5\2GDZ5KWN\HijackThis.exe C:\DOCUME~1\HELENG~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID} R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo O1 - Hosts: www.winmx.com O1 - Hosts: err.winmx.com O1 - Hosts: c3310.z1301.winmx.com O1 - Hosts: c3311.z1301.winmx.com O1 - Hosts: c3312.z1301.winmx.com O1 - Hosts: c3313.z1301.winmx.com O1 - Hosts: c3314.z1301.winmx.com O1 - Hosts: c3315.z1301.winmx.com O1 - Hosts: c3316.z1301.winmx.com O1 - Hosts: c3317.z1301.winmx.com O1 - Hosts: c3318.z1301.winmx.com O1 - Hosts: c3319.z1301.winmx.com O1 - Hosts: c3310.z1302.winmx.com O1 - Hosts: c3311.z1302.winmx.com O1 - Hosts: c3312.z1302.winmx.com O1 - Hosts: c3313.z1302.winmx.com O1 - Hosts: c3314.z1302.winmx.com O1 - Hosts: c3315.z1302.winmx.com O1 - Hosts: c3316.z1302.winmx.com O1 - Hosts: c3317.z1302.winmx.com O1 - Hosts: c3318.z1302.winmx.com O1 - Hosts: c3319.z1302.winmx.com O1 - Hosts: c3310.z1303.winmx.com O1 - Hosts: c3311.z1303.winmx.com O1 - Hosts: c3312.z1303.winmx.com O1 - Hosts: c3313.z1303.winmx.com O1 - Hosts: c3314.z1303.winmx.com O1 - Hosts: c3315.z1303.winmx.com O1 - Hosts: c3316.z1303.winmx.com O1 - Hosts: c3317.z1303.winmx.com O1 - Hosts: c3318.z1303.winmx.com O1 - Hosts: c3319.z1303.winmx.com O1 - Hosts: c3310.z1304.winmx.com O1 - Hosts: c3311.z1304.winmx.com O1 - Hosts: c3312.z1304.winmx.com O1 - Hosts: c3313.z1304.winmx.com O1 - Hosts: c3314.z1304.winmx.com O1 - Hosts: c3315.z1304.winmx.com O1 - Hosts: c3316.z1304.winmx.com O1 - Hosts: c3317.z1304.winmx.com O1 - Hosts: c3318.z1304.winmx.com O1 - Hosts: c3319.z1304.winmx.com O1 - Hosts: c3310.z1305.winmx.com O1 - Hosts: c3311.z1305.winmx.com O1 - Hosts: c3312.z1305.winmx.com O1 - Hosts: c3313.z1305.winmx.com O1 - Hosts: c3314.z1305.winmx.com O1 - Hosts: c3315.z1305.winmx.com O1 - Hosts: c3316.z1305.winmx.com O1 - Hosts: c3317.z1305.winmx.com O1 - Hosts: c3318.z1305.winmx.com O1 - Hosts: c3319.z1305.winmx.com O1 - Hosts: c3310.z1306.winmx.com O1 - Hosts: c3311.z1306.winmx.com O1 - Hosts: c3312.z1306.winmx.com O1 - Hosts: c3313.z1306.winmx.com O1 - Hosts: c3314.z1306.winmx.com O1 - Hosts: c3315.z1306.winmx.com O1 - Hosts: c3316.z1306.winmx.com O1 - Hosts: c3317.z1306.winmx.com O1 - Hosts: c3318.z1306.winmx.com O1 - Hosts: c3319.z1306.winmx.com O1 - Hosts: c3520.z1301.winmx.com O1 - Hosts: c3521.z1301.winmx.com O1 - Hosts: c3522.z1301.winmx.com O1 - Hosts: c3523.z1301.winmx.com O1 - Hosts: c3524.z1301.winmx.com O1 - Hosts: c3525.z1301.winmx.com O1 - Hosts: c3526.z1301.winmx.com O1 - Hosts: c3527.z1301.winmx.com O1 - Hosts: c3528.z1301.winmx.com O1 - Hosts: c3529.z1301.winmx.com O1 - Hosts: c3520.z1302.winmx.com O1 - Hosts: c3521.z1302.winmx.com O1 - Hosts: c3522.z1302.winmx.com O1 - Hosts: c3523.z1302.winmx.com O1 - Hosts: c3524.z1302.winmx.com O1 - Hosts: c3525.z1302.winmx.com O1 - Hosts: c3526.z1302.winmx.com O1 - Hosts: c3527.z1302.winmx.com O1 - Hosts: c3528.z1302.winmx.com O1 - Hosts: c3529.z1302.winmx.com O1 - Hosts: c3520.z1303.winmx.com O1 - Hosts: c3521.z1303.winmx.com O1 - Hosts: c3522.z1303.winmx.com O1 - Hosts: c3523.z1303.winmx.com O1 - Hosts: c3524.z1303.winmx.com O1 - Hosts: c3525.z1303.winmx.com O1 - Hosts: c3526.z1303.winmx.com O1 - Hosts: c3527.z1303.winmx.com O1 - Hosts: c3528.z1303.winmx.com O1 - Hosts: c3529.z1303.winmx.com O1 - Hosts: c3520.z1304.winmx.com O1 - Hosts: c3521.z1304.winmx.com O1 - Hosts: c3522.z1304.winmx.com O1 - Hosts: c3523.z1304.winmx.com O1 - Hosts: c3524.z1304.winmx.com O1 - Hosts: c3525.z1304.winmx.com O1 - Hosts: c3526.z1304.winmx.com O1 - Hosts: c3527.z1304.winmx.com O1 - Hosts: c3528.z1304.winmx.com O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Etomi\Plugins\RazaWebHook.dll (file missing) O2 - BHO: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll O3 - Toolbar: Wanadoo - {4E7BD74F-2B8D-469E-A3F1-F068B59BBB2A} - C:\PROGRA~1\wanadoo1\wanadoo1.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [BTopenworld] "c:\program files\bt yahoo! internet\DialBTYahoo.exe" /ReInstallAutoDial O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [fss] C:\Program Files\Akidthaine\fss.exe O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe" O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe" O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe O4 - HKCU\..\Run: [balamory screen saver] "C:\Program Files\balamory\Screen Saver\TaskTray.exe" O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c O4 - HKCU\..\Run: [KazaGold] C:\Program Files\Kaza Gold 3.2\KazaGold3.2.exe /hide O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZZ O8 - Extra context menu item: Download with &Etomi - res://C:\Program Files\Etomi\Plugins\RazaWebHook.dll/3000 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm O8 - Extra context menu item: Wanadoo Search - file://C:\Program Files\WANADOO1\Cache\SelectedContextSearch.htm O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/u...lorer1_8us.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.uclan.ac.uk/other/iss/remote/wficat.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1125234078125 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/upload...reUploader.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yaho...tocomplete.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{3DA5D793-B847-45E2-8664-578226917391}: NameServer = O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe |
