Ugh, stupid program..

Discussion in 'Software' started by Balbanebeoulve, Sep 27, 2003.

  1. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Well, I tried using P2P share spy demo, it didn't work, saying it's been disabled due to crackers. So I closed it, uninstalled it and tried going on. Well now anytime I try installing any new program or try running some programs it'll jump and try to install itself, without an installer....asking me to locate the installer.

    So I have to repeatedly press cancel like 10 times before it'll go away. So I thought, maybe it didn't uninstall properly. So I re-download it, reinstall and uninstall. But no, it still won't leave me alone.

    What do I have to delete/clean/remove to get rid of this thing for good?
     
  2. mr_flea

    mr_flea First Sergeant

    do you have a restore point that worked before you installed it? (windows xp automatically creates one). If you do, restore it back to that point.
     
  3. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    No, I sort of disabled system restore, and anyway, I installed the program awhile ago. It now just started to annoy me.
     
  4. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    =/

    I tried to do it manually with rededit and deleted any keys, value or data that looked suspicious. I used 3 regcleaners to no avail, sadly.

    Thanks for the suggestion guys, but you have anymore?
     
  5. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I went into regedit and manually deleted keys, and tried more regcleaners..

    I'm going to try some uninstaller programs too....but any suggestions would really help. It's becoming really frustrating.

    Thanks in advance.
     
  6. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I'll get back to you with the uninstaller (downloading now)

    But regsupreme hates me. When I first tried it (a long time ago) I didn't install the translation, because I didn't think I would need it. Little did I know, the translations were for english. So I try reinstalling it, automatically ending my trial. =/

    Meh, the authors own fault, I guess I'll never see the chance of it in action. :p He lost one customer this way.
     
  7. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Reinstalled P2P share spy demo, used McAfee, and the damned product still lives...

    I don't know where it's hiding...but God..

    Hmm, any other suggestions my fellow geeks? I'll try JV16 tomorrow...but other than that...?

    Thanks for the help guys.
     
  8. muskybob

    muskybob Fish Tickler

    Not to worry, others had this same problem. Go to the jv16 website & contact them & explain what happened. They will surely give you the fix to reinstall regsupreme. It is definetely worth it. One great program.
     
  9. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Well, I've emailed him, but I do not want to solely rely on one registry program, is there any other suggestions?
     
  10. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Emailed the author, he told me I can't do anything about it. Well, I don't really care, it's really his loss. Anyway, can no one help me? I'm sure of you guru's can help >.<
     
  11. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve What i think we have here is some spy ware or possibly a Trojan.Try running a scan with ad ware follow up with spy bot.Then download a Trojan remover program called Trojan remover it is very fast.I am hoping this will help you out..Should it not then post back as i have some more idea's?You have not stated the name of the software causing you this problem ?
    http://www.majorgeeks.com/download.php?det=903
     
  12. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I have done spyware scans and I have a great antivirus. Anyway, I ran Tauscan trojan remover recently, so...it's not a spyware or trojan, just a poorly configured program. And the name was stated in the first post:

    "Well, I tried using P2P share spy demo, it didn't work, saying it's been disabled due to crackers."

    Anyway, the name is "P2P share spy demo."

    You can try it out on downlods.com...

    Good luck and thanks for the help.
     
  13. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

  14. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Thanks, but the problem is, I don't know where the sneaky program is hiding....

    I've checked my processes when it appears. But it just shows the program I was trying to load. It shows no traces of anything else....

    Thanks anyway =/
     
  15. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve Have a look in regedit again? Go to H/KEY /LOCAL-MACHINE/SOFTWARE.Take a good look throughout this hive your offending program must be in here somewhere?If you should come across a program you can not recall just post back and i am sure one of us here will be able to determine what it is :)
     
  16. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Yeah, like I said, I've manually gone through, I've tried to delete EVERY trace possible. Still popups...

    Hmm, any other ideas?
     
  17. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Thank God there isn't any hammers near by or it would have already been tried...x.x...

    Hmm, if anybody is willing to take the risk for me, they could use a program to analyze what components are installed when P2P Share Spy Demo is installed. Give me a list of the components and...maybe, just maybe if I delete them manually it would work...
     
  18. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve could you please supply the link for downloading this file.Thanks :)
     
  19. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

  20. Warcat14

    Warcat14 Private E-2

    yes try norton system works. it has some handy functions of deleting problems and also get a startup changer. maby it starts by itself after a reboot. try ad-aware because it may be an add. and if nothing works and it bothers you so much that you want to throw the pc out of the window, try installing windows over again.
     
  21. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve i have made en-quires in to this software and it is very complicated.I myself am not a expert in this field.The big problem that we have here is that this file is not showing up in the registry nor in the program files and in reality does not exist?Having said that there are Trojans which can be buried deep within files that will start when you try to open another program.I will continue to look in to this for you to try to find the answer but it will take time.I am sorry that i have not been able to help you further at this time.I am present waiting for some expert to look at your problem and will post back as and when i have a answer
     
    Last edited: Oct 2, 2003
  22. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Warcat14, I've tried adaware already and I don't know what to delete...

    And NICK ADSL UK, thanks for all the effort. This program is really getting on my nerves, hehe. I hope I can resolve this with your help.

    Thanks again.
     
  23. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve i have had some feedback into your problem.If you can go to start/run and type in MSCONFIG Then tick on start up then tick disable all then reboot.At this point there should be no icons in the system tray after rebooting?Now try to get this file to play up with this message appearing?If it does not play up at this point all you have to do is to delete all the software that was in the tray and download fresh copies?Then download a copy of xp smoker what you need to do now is while in msconfig everything is disabled is to open up xp smoker and click on the tab disk cleaner then reboot come back to the desktop open up xp smoker again this time you wont to tick on the INTERNET explorer icon then tick on erase INTERNET temporary files then tick on flash DNS cache then reboot come back to the desk top.Now see if things have improved.What we have done here is to try to determine if this file has merged into one of your pieces of software at start up.Hopefully this will prove to be the case.On the other hand through this file may have merged with a windows file and prove much more difficult to remove.Please let me know how you get on
    Hi Balbanebeoulve I forgot to add only use xp smoker if your OS is xp if not use mru blaster Link here
    http://www.wilderssecurity.net/mrublaster.html


    __________________
     
    Last edited: Oct 2, 2003
  24. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Sorry about the lack of reply...

    Err, well I did what you asked me to, but the file still appeared :(

    Any more suggestions? And thanks for bearing with me.
     
  25. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve Well we will have to move on to the next stage which is to download a piece of software called belarc.this is a piece of software that will tell you what is on your computer.Post the full report here so that i will be able to identify the offending software.If not myself one of the other members here will be able to help you.This is the last resort but should work because this piece of software causing trouble is not on its own you will find at the end of the day you have other software causing incompatibility with this particular piece of software.There are many instances of incompatible software.When you post the report do remember to leave out all PERSONAL DETAILS
    http://www.majorgeeks.com/download.php?det=1385
     
  26. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Computer Profile Summary
    Profile Date: Sunday, October 05, 2003 16:01:39
    Advisor Version: 6.0j


    Operating System System Model
    Windows XP Home Edition Service Pack 1 (build 2600) Compaq Presario C04BDABB
    System Serial Number: ***********
    Asset Tag: ***********
    Chassis Serial Number: ****************
    Processor a Main Circuit Board b
    1.60 gigahertz Intel Pentium 4
    8 kilobyte primary memory cache
    256 kilobyte secondary memory cache Board: Compaq 0784h
    Serial Number: 2H22KKLR40CS
    Bus Clock: 400 megahertz
    BIOS: Compaq 686Y2 v2.06 12/03/2001
    Drives Memory Modules c,d
    60.01 Gigabytes Usable Hard Drive Capacity
    9.80 Gigabytes Hard Drive Free Space

    COMPAQ DVD-ROM GDR8160B [CD-ROM drive]
    HL-DT-ST CD-RW GCE-8240B [CD-ROM drive]
    3.5" format removeable media [Floppy drive]

    Maxtor 4D060H3 [Hard drive] (60.02 GB) -- drive 0, s/n D3H9H2ZE, rev DAH017K0, SMART Status: Healthy 256 Megabytes Installed Memory

    Slot 'XMM1' has 256 MB (serial number *******)
    Slot 'XMM2' is Empty
    Local Drive Volumes

    c: (on drive 0) 52.68 GB 5.95 GB free
    d: (on drive 0) 7.33 GB 3.85 GB free

    Logins Network Drives

    NT AUTHORITY\LOCAL SERVICE
    NT AUTHORITY\NETWORK SERVICE
    NT AUTHORITY\SYSTEM

    Installed Microsoft Hotfixes Printers
    DataAccess
    Q823718 (details...) on 08/25/03
    DirectX
    DX819696 (details...)
    Internet Explorer
    Q330994 (details...)
    Q813489 (details...)
    Q818529 (details...)
    Q822925 (details...)
    Q828750 (details...)
    SP1 (SP1)
    Windows Media Player
    WM817787 (details...)
    WM819639 (details...)
    WM828026 (details...)
    SP0
    Q828026 (details...) on 10/04/03
    Windows XP
    SP1
    Q324720[SP] (details...) on 05/16/03
    SP2
    KB282010 (details...) on 09/29/03
    KB817778 (details...) on 09/18/03
    KB820291 (details...) on 06/29/03
    KB821253 (details...) on 07/15/03
    KB821557 (details...) on 07/18/03
    KB822603 (details...) on 09/29/03
    KB823559 (details...) on 07/15/03
    KB823980 (details...) on 07/18/03
    KB824105 (details...) on 09/04/03
    KB824146 (details...) on 09/13/03
    Q322011 (details...) on 05/16/03
    Q323255 (details...) on 05/16/03
    Q327979 (details...) on 05/16/03
    Q328310 (details...) on 05/16/03
    Q329048 (details...) on 05/16/03
    Q329115 (details...) on 05/16/03
    Q329170 (details...) on 05/16/03
    Q329390 (details...) on 05/16/03
    Q329441 (details...) on 05/16/03
    Q329834 (details...) on 05/16/03
    Q331953 (details...) on 05/16/03
    Q810243 (details...) on 05/16/03
    Q810565 (details...) on 05/16/03
    Q810577 (details...) on 05/16/03
    Q810833 (details...) on 05/16/03
    Q811493 (details...) on 05/16/03
    Q811630 (details...) on 05/16/03
    Q814033 (details...) on 05/16/03
    Q814995 (details...) on 05/16/03
    Q815021 (details...) on 05/29/03
    Q817287 (details...) on 05/16/03
    Q817606 (details...) on 07/15/03


    Click here to see all available security Hotfixes.

    Marks a HotFix that verifies correctly
    Marks a HotFix that fails verification
    (Failing hotfixes need to be reinstalled)
    An unmarked HotFix lacks the data to allow verification Canon S200 on USB001

    Controllers Display
    Standard floppy disk controller
    Intel(r) 82801BA Bus Master IDE Controller
    Primary IDE Channel [Controller]
    Secondary IDE Channel [Controller] NVIDIA GeForce2 MX/MX 400 [Display adapter]
    Compaq FS740 [Monitor] (15.7"vis, March 2001)
    Bus Adapters Multimedia
    Intel(r) 82801BA/BAM USB Universal Host Controller - 2442
    Intel(r) 82801BA/BAM USB Universal Host Controller - 2444 SoundMAX Integrated Digital Audio
    Communications Other Devices
    HSP56 MicroModem
    Intel(R) PRO/100 VM Network Connection
    Network Card MAC Address: 00:08:02:1A:E3:E2
    Network IP Address: 24.42.218.46 / 23 HID-compliant consumer control device
    HID-compliant consumer control device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    USB Human Interface Device
    USB Human Interface Device
    HID Keyboard Device
    Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    PS/2 Compatible Mouse
    USB Composite Device
    USB Printing Support
    USB Root Hub
    USB Root Hub
    Software Licenses

    Adobe - Photoshop 104518347515566207324988
    Adobe Systems, Inc. - Adobe Photoshop 7.0 10451834751556620732XXXX
    Microsoft - Internet Explorer 55277-OEM-*************(Key: *************)e
    Microsoft - MediaPlayer ****************
    Microsoft - Office 2000 Premium ****************
    Microsoft - WebFldrs XP 12345-******************
    Microsoft - Windows XP Home Edition 55277-OEM-0*******3-00101 (Key: ****************)e

    Software Versions
    Awesome Computing - RPG Toolkit Translator (Version 2) Version 2.20.0143 *
    3ivx.com - 3ivx D4 4.0.4 Version 4, 0, 4, 0 *
    adi DrvLsnr Version 1, 0, 0, 3 *
    Adobe ImageReady (tm) 7.0 Version 7.0 *
    Adobe Photoshop Version 7.0 *
    Adobe Reader Version 6.0.0.2003051900 *
    Adobe Systems AdobeDownloadManager Version 1.2 *
    AGENTIX Software - SystemReport Utility Version 0.93b *
    AIDA32 *
    Aldo Vargas - http://www.aldostools.com - Kazaa Lite K++ Version 1.02 *
    Amaze Soft - FlashGet Version 1, 4, 0, 0 *
    America Online, Inc. - AOL Instant Messenger Version 5.5.3415 *
    Analog Devices, Inc. - DLSLoader Application Version 3, 2, 0, 0 *
    Analog Devices, Inc. - SoundMAX service agent Version 3, 2, 6, 0 *
    AviC (FourCC Changer) *
    AVIPreview Version 0, 0, 0, 1a *
    Awesome Computing - RPG Toolkit Development System, Version 2 Version 2.20.0100 *
    Belarc, Inc. - BelManage Client Version 6.0j *
    blindman.exe *
    bradfitz.com, inc. (original) | liquified.visions (current) - LiveJournal Version 1, 4, 7, 0 *
    BST - BSPlayer v0.8 Version 0.86 *
    btdownloadgui.exe *
    Cerulean Studios - Trillian Version 2.0.0.0 *
    Cinematronics - 3D Pinball Version 5.1.2600.0 *
    config.exe *
    Configuration Editor *
    DivX Player *
    DivXNetworks, Inc. - DivX EKG Version 1.0.0.0 *
    Fake Mailer Version 1.0.907.19032 *
    FourCC Code Changer *
    Gabest - Media Player Classic Version 6, 4, 6, 5 *
    GSpot Codec Information Appliance Version 2, 1, 0, 0 *
    GSpot Codec Information Appliance Version 2, 2, 1, 4 *
    Guide *
    GunBound (r) Version 1, 0, 0, 1 *
    GunBound Startup Application Version 1, 0, 0, 1 *
    http://www.emule-project.net - eMule Version 0.30.1 *
    iolo DriveScrubber Version 2.0.1.0 *
    iolo technologies, LLC - Search and Recover Version 1.0.2.0 *
    iolo technologies, LLC - System Mechanic 4 Utility Bar Version 4.0.1.0 *
    iolo technologies, LLC - System Mechanic ® Version 4.0.2.0 *
    iolo technologies, LLC - System Shield ® Version 2.1.1.0 *
    Java Web Start *
    javaw.exe *
    Jordan Russell - GunBound Uninstall *
    Jordan Russell - If you want to undo changes made by Spybot-S&D, use the Recovery instead! *
    K-Dat Version 1.2.0.0 *
    K-Sig Version 1.2.0.0 *
    KMCS Computer Software - REGCOMP Version 1.00 *
    KsL Software - Registry Healer Version 4.0.1.134 *
    Lavasoft Ad-aware Plus Version 6.0.0.0 *
    Macromedia Extension Manager Version 1.5.041 *
    Macromedia Flash Version 7, 0, 0, 470 *
    Macromedia Inc. - Fireworks Version 6.0 *
    Macromedia Licensing Service *
    Macromedia, Inc. - Shockwave Flash Version 7,0,14,0 * Matt's Computer Solutions [MCS] - ZoneLog Analyser Version 1.01.0008 *
    Mercedes - QuickSFV Version 2, 2, 2, 0 *
    Microsoft (R) .NET Framework Version 1.1.4322.573 *
    Microsoft Clip Gallery Version 5.1.00.1221 *
    Microsoft Corporation - Internet Explorer Version 6.00.2800.1106 *
    Microsoft Corporation - Messenger Version 6.0 *
    Microsoft Corporation - Windows Installer - Unicode Version 2.0.2600.1106 *
    Microsoft Corporation - Windows Movie Maker Version 1.1.2427.1 *
    Microsoft Corporation - Windows® NetMeeting® Version 3.01 *
    Microsoft Corporation - Zone.com Version 1.2.626.1 *
    Microsoft Office 2000 Version 9.0.2719 *
    Microsoft Open Database Connectivity Version 3.520.9030.0 *
    Microsoft Outlook Version 9.0.2416 *
    Microsoft PowerPoint for Windows Version 9.0.2716 *
    Microsoft Windows Media Player Version 6.4.09.1125 *
    Microsoft(R) Windows Media Player Version 9.00.00.2980 *
    Microsoft® Access Version 9.0.2719 *
    Microsoft® FrontPage® 2000 Version 4.0.2.2717 *
    Microsoft® Visual Basic for Windows Version 6.00.8450 *
    Microsoft® Windows(TM) Shell PowerToys Version 96.02.06 *
    MindVision Software - Installer VISE Version 3.6.0 *
    MiniCalc *
    mIRC Version 6.03 *
    MySoft - MyIE2 Application Version 0, 8, 2070, 0 *
    NOD32 *
    NOD32 Control Center *
    NOD32 Kernel Service *
    Nullsoft - Winamp Version 2.80 *
    NVIDIA Driver Helper Service, Version 45.23 Version 6.14.10.4523 *
    O&O Software GmbH - O&O Defrag Version 4.0.508 *
    OGMCalc Application Version 0, 1, 0, 1 *
    Outer Technologies - Cacheman Version 5 *
    pctvoice Application Version 1, 0, 0, 1 *
    PepiMK Software - SpyBot-S&D Version 1.2 *
    Process RAR, ZIP and other archive formats *
    Recover memory now *
    REGSCRUBXP Application Version 3.25 *
    RegSupreme Version 1.0.0.0 *
    ResHacker Version 3.0.0.0 *
    Rocko - KL Extensions Version 1.20 *
    Rocko - KL Extensions Version 1.40 *
    Rocko - KLConfigWizard Version 1, 3, 2, 0 *
    Roxio - Easy CD Creator Version 5.1 (53) *
    Roxio Inc. - IMAPI Module Version 1, 0, 0, 4 *
    Sheep Design - nVidia Refresh Rate Fix MKII v2.20 E Version 2.02 *
    SmartFTP Version 1.0.979.1 *
    StatsReader Version 2, 0, 1, 1 *
    System Mechanic 4 PopupStopper Version 1.0.0.0 *
    TR-Software - xp-AntiSpy Version 3, 7, 2, 0 *
    WildTangent, Inc. - Wild Tangent wcmdmgrl Version 1.6.1.2 *
    Wizards to adjust .NET Framework security, assign trust to assemblies, and fix broken .NET applications. Version 1.0.5000.0 *
    Xteq Systems X-Setup Version 6.2 *
    YourWare Solutions (TM) - FRXPRO Version 1.0.0.0 *
    Zone Labs Client Version 4.0.196.000 *
    Zone Labs Inc. - Internet Access Monitor Version 4.0.196.000 *
    Zone Labs Inc. - TrueVector Service Version 4.0.196.000 *
     
  27. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve i have had a quick look as it stands at present these pieces of software do cause problems
    Roxio - Easy CD Creator Version 5.1 (53) *
    Roxio Inc. - IMAPI Module Version 1, 0, 0, 4 *

    DivX Player *
    DivXNetworks, Inc. - DivX EKG Version 1.0.0.0 *

    YOU SHOULD REMOVE THIS PIECE OF SOFTWARE BELOW THIS DOES SPELL TROUBLE

    Aldo Vargas - http://www.aldostools.com - Kazaa Lite K++ Version 1.02 *
    I would remove all of the above and try again you will have to then use your registry cleaner when you have removed the above when you post back i will advise you better on your choice of music software.I am sure i have identified the offending software but will to continue to look at the other files to find out more about them as there are a couple which are new to me.Good luck
     
  28. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    So you want me to remove K-Lite divx and roxio? Just making sure...

    But I haven't had any trouble with kazaa lite and I;ve been using it for about 2 years now. But alrighty, I can always try some new techniques.
     
  29. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve Yes if you could your computer has been very seriously compromised with kazza and kazza light still causes a big concern in the UK.By removing what i have suggested is very quick but do not put these programs back on until we have a fix.

    :)
     
  30. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I uninstalled Kazaa and Divx but Roxio does not have an uninstaller, so I can't uninstall it. Umm, now what shall I do?
     
  31. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I have an idea to fix this, but it requires someone else to help me.

    Somebody who has never installed "P2P share spy demo" should get a monitoring software such as ...system mechanic and then take a snapshot of their system. Then install the program and take another snapshot. You can then compare what registry keys have been added and then I can use that list to clean my registry of the software...

    Does anybody think this will work?
     
  32. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member


    Hi Balbanebeoulve use this for uninstalling Roxio
    http://www.majorgeeks.com/download.php?det=2439
     
  33. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Okay they're all uninstalled, now what do you suggest?
     
  34. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve we will have to stop meeting like this otherwise people will talk :D
    Is this file still playing up ?
    IF it is you will have to uninstall some more of your program's I will get back to you tomorrow night as i will have to work on this during the day .It will turn out OK in the end i am sure :)
     
  35. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Hawhaw ;)

    But, I must uninstall more of my children?

    Isn't it possible the software just has some hidden registry keys?
     
  36. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi again Balbanebeoulve I do not think so JV power tools is very through you may have to uninstall some more yet when i post tomorrow i will put further software forward for you to remove. i will spend all day on it.Most of your software is solid?It is just a few that will need to come out.Do not forget to use JV each time you remove a piece of software
     
  37. Maxwell

    Maxwell Folgers

    It seems that the way Nick is going by uninstalling software you may as well rebuild your system from scratch. It's a thought, if you have a spare disk.

    However, you could try using something like HijackThis to find any auto-start items or one of the other startup tools on this web site.
     
  38. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi
    Balbanebeoulve That is a good suggestion from maxwell Please post any details here also you can try this tool BHODemon if anything should show up you could delete it ?
    http://www.majorgeeks.com/download.php?det=3550
    This tool will make sure your browser is not the cause of your problem
     
    Last edited: Oct 5, 2003
  39. InYearsToCome

    InYearsToCome MajorGeek

    I know the old system mechanic had a feature called "safe installer" which let you see exactly where a program installs itself and what it modifies, could come in handy when you need to undo everything it did. if you cant find the older 3.x verison online, i have the 30-day trial installation of it on my system, so let me know. good luck!


    also
    this may be way off, but is there any chance the software could have entered itself into windows sysoc.inf file and hidden its uninstall feature?

    its worth a check i suppose.

    go to C:\WINDOWS\inf and open sysoc.inf

    look around at all the gibberish, and you'll notice program names in the differnt strings. at the end of the strings, you'll notice 'HIDE' between comma's. remove that hide and leave the commas, this will allow windows add/remove programs to recognize this program and offer an uninstall.

    for example, by default the msmsgs (microsoft windows messenger) looks like this

    msmsgs=msgrocm.dll,OcEntry,msmsgs.inf,hide,7

    to be able to uninstall it, modify the string to read

    msmsgs=msgrocm.dll,OcEntry,msmsgs.inf,,7


    once again, i doubt it made it in there as those are windows components... but you've done so much already... who knows
     
  40. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Alright my HiJack this log is:

    Logfile of HijackThis v1.97.2
    Scan saved at 9:26:11 PM, on 05/10/2003
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\System32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\embarkexplorer.exe
    C:\WINDOWS\System32\pctspk.exe
    C:\WINDOWS\wt\updater\wcmdmgr.exe
    C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
    C:\PROGRA~1\ZONELA~1\ZoneAlarm\zlclient.exe
    C:\Program Files\FreeRAM XP Pro 1.40.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\MYIE2\MyIE.exe
    C:\WINDOWS\System32\msiexec.exe
    C:\Documents and Settings\Reza\Desktop\Downloads\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.231.226.21:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F0 - system.ini: Shell=embarkexplorer.exe
    F2 - REG:system.ini: Shell=embarkexplorer.exe
    O1 - Hosts: 203.161.127.141 www.dcsresearch.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\MSDXM.OCX
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
    O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZoneAlarm\zlclient.exe
    O4 - HKCU\..\Run: [Windows Runtime Help] C:\WINDOWS\System32\WinRunHelp.wrh
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\FreeRAM XP Pro 1.40.exe" -win
    O4 - HKLM\..\RunOnce: [System Mechanic Cache Cleanup] C:\Program Files\iolo\System Mechanic 4 Professional\SysMech4.exe /COMPLETECACHE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Add to Ad Hunter - C:\Program Files\MYIE2\config/blacklist.htm
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: TREND MICRO HouseCall (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: AIM (HKLM)
    O9 - Extra button: FlashGet (HKLM)
    O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} - http://www.drivershq.com/DD_v4.CAB
    O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/01b04dcae75314c28d20/netzip/RdxIE601.cab
    O16 - DPF: {5CE8C9BE-B561-4311-8C03-D6F6C1CAF7E1} - http://h71025.www7.hp.com/support/sndetect/CSND_AX.CAB
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} - http://de.trendmicro-europe.com/file_downloads/common/housecall/HouseCallButton.CAB
    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37861.8615046296
    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq.com/falco/SysQuery.cab
    O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab

    ============================================


    Okay, now that's done...

    InYearsToCome: Sorry, it wasn't there. Also, if you could try installing that product "P2P Share Spy Demo" and letting me know the results with system mechanic, that would be so helpful. If I do it, it won't work because system mechanic won't notice the files that are causing this problem getting replaced if I try reinstalling it. I hope you understand what I mean.

    NICK ADSL UK: Only 3 BHO's appeared and all three I know. They were Flashget, Spybot S&D and uhh google toolbar.
     
  41. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    These next two "ProxyServer" entries are conflicting, if you use a proxy, decide which one is correct and fix the other.

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.231.226.21:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

    I have never seen these two before either, fix it unless you installed it on purpose.
    F0 - system.ini: Shell=embarkexplorer.exe
    F2 - REG:system.ini: Shell=embarkexplorer.exe

    O1 - Hosts: 203.161.127.141 www.dcsresearch.com

    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)

    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch

    O4 - HKCU\..\Run: [Windows Runtime Help] C:\WINDOWS\System32\WinRunHelp.wrh

    O10 - Broken Internet access because of LSP provider 'imon.dll' missing

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/01b04dcae75314...ip/RdxIE601.cab

    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.c...eX/FileXfer.cab

    You have a backdoor trojan designed to capture AIM passwords. Change your Instant Messenger passwords immediately, and follow these steps to remove the virus:
    C:\WINDOWS\System32\WinRunHelp.wrh

    Delete the following Registry Keys
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Runtime Help"

    HKEY_CLASSES_ROOT\Windows Runtime Help 4.881.1208\shell\open\command "(Default)"
    and reboot.

    Please get back to me and let me know if you now have fixed this file that has been a problem
     
  42. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    This is the company that made it and what you have is the Demo Version. http://www.rebrandsoftware.com/showsoftware.asp?soft_id=8
    ALSO TRY BELOW

    Open regedit and do a search first for P2P Share Spy and delete all entries found. Then search for RebrandSoftware and delete all entries found. If you don't know how to do a search of the registry, post back and I'll post a detailed description of the process.

    A Google search for info on this led me to CNET.com where a users survey had a 0% + opinion and a 100% - opinion. Need I say more ???
    PLEASE DO LET US KNOW HOW YOU ARE GETTING ON?
     
    Last edited: Oct 6, 2003
  43. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I deleted the trojan, but I think I put it there by accident, myself...

    Also, err...

    My shell is customized so that's what the name is like that.

    I have no clue what to do for the proxy...

    And I am confused about:

    "O1 - Hosts: 203.161.127.141 www.dcsresearch.com

    O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)

    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch

    O4 - HKCU\..\Run: [Windows Runtime Help] C:\WINDOWS\System32\WinRunHelp.wrh

    O10 - Broken Internet access because of LSP provider 'imon.dll' missing

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/01b04dcae75314...ip/RdxIE601.cab

    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.c...eX/FileXfer.cab "

    ==================================

    What did you want me to do?

    And I did already delete all keys manually by searching for them.

    Thanks again for all the help.
     
  44. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve is your computer still OK? What you could do now if the computer is working OK.Is to remove those BHOs you do not really need them?Also i Hope you have removed flash get the goggle tool bar and Aim and all traces of it?Do not forget to look in the windows folder also look in system32.This will probably be your last chance of getting rid of this dodgy p2p file.The rest of your software seams OK so it would be pointless removing any other software.When you have removed the above just have another clean up but this time download stinger this will do the following
    Stinger is a stand-alone utility used to detect and remove specific viruses. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system. Stinger utilizes next generation scan engine technology, including process scanning, digitally signed DAT files, and scan performance optimizations.
    I do hope this will fix things for you and once again GOOD LUCK

    :)
    http://us.mcafee.com/virusInfo/default.asp?id=stinger
     
    Last edited: Oct 7, 2003
  45. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    I didn't remove the BHO's because I don't think are related with my browser...

    And do you really think that this file hosted on downloads.com has a virus?

    By the way the stinger link didn't work.
     
  46. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve
    The BHOs are related to the browser and can be in a big way?
    This file from downloads.com has defied all logic and now stinger is all that is left.This link is for the stinger download direct.Give it a go and keep your fingers crossed
    http://download.nai.com/products/mcafee-avert/stinger.exe




    This version of Stinger includes detection for all known variants, as of September 19, 2003:
    BackDoor-AQJ Bat/Mumu.worm Exploit-DcomRpc
    IPCScan IRC/Flood.ap IRC/Flood.bi
    IRC/Flood.cd NTServiceLoader PWS-Narod
    PWS-Sincom W32/Bugbear@MM W32/Deborm.worm.gen
    W32/Dumaru@MM W32/Elkern.cav W32/Fizzer.gen@MM
    W32/FunLove W32/Klez W32/Lirva
    W32/Lovgate W32/Lovsan.worm W32/Mimail@MM
    W32/MoFei.worm W32/Mumu.b.worm W32/Nachi.worm
    W32/Nimda W32/Sdbot.worm.gen W32/SirCam@MM
    W32/Sobig W32/SQLSlammer.worm W32/Swen@MM
    W32/Yaha@MM
     
    Last edited: Oct 7, 2003
  47. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    "I didn't remove the BHO's because I don't think are related with my browser... "

    Sorry, I was tired, what I meant to say was I didn't think the browser was related to my problem.

    And the stinger scan didn't mention any virus..

    "McAfee AVERT Stinger Version 1.8.7 built on Oct 1 2003

    Copyright (C) 2002-2003 Networks Associates Technology, Inc. All Rights Reserved.

    Virus data file v1000 created on Sep 25 2003.

    Ready to scan for 31 viruses, trojans and variants.



    Scan initiated on Tue Oct 07 19:05:20 2003

    Number of clean files: 98795"
     
  48. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi Balbanebeoulve
    What is the current situation with the computer?Is the behavior of the P2P file still the same?Could you please post another belarc report so that i can see where we are at?Remembering not to post any personal details.There is one more thing you should have a loot at
    Description of Windows XP and Windows Server 2003 System File Checker (Sfc.exe)
    You could also post back here the resaults of the check?

    http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q310747
     
    Last edited: Oct 8, 2003
  49. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    Hi again Balbanebeoulve
    A friend of mine has given me this for you to look at as a last resort.When you have followed the post above and this post then you will know that all avenues have been closed and you most probably will have to reformat your drive.Good luck with this


    If the ultimate solution is to reformat the HD and start fresh, then it certainly can't hurt to give this a go before taking such a drastic and time consuming step as reformatting

    How to start Registry Editor
    1. Exit all open programs.
    2. Click Start, and then click Run. The Run dialog box appears.
    3. Type regedit and then click OK. The Registry Editor window appears.

    What is Regedit?
    The Registry Editor is an advanced tool that enables you to change settings in your system registry, which contains information about how your computer runs. You should not edit your registry unless it is absolutely necessary. Generally, it is best to use Windows controls to change your system settings. If an error is made in the registry, your computer may become nonfunctional. If this happens, you can restore the registry to its previous state when you last successfully started your computer.
    Caution before editing the Registry
    It is strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified.

    How to Search The Registry & Delete Unwanted Entries
    1. Open the Registry Editor
    2. Click on Edit / Find and type in the item you want to search for and click Find Next.
    3. When a matching entry is found it will be highlighted.
    4. Right click on it and choose “Delete” to remove the entry.
    5. Go back to Edit and click “Find Next” or hit the F3 key
    6. Follow steps 4 & 5 until the message “Windows has finished searching the registry” appears.

    How to exit the Registry Editor
    1. Click File and click Exit to save the changes and close the Registry Editor.
    Restart the computer
     
  50. Balbanebeoulve

    Balbanebeoulve Bal. Balba. Babalabawhosemawhutsie

    Hmm, alright. I can't do sfc scan because you need a CD for that and sadly I don't have a CD.

    Reformatting is not an option, I guess I'll have to suffer with this for now.

    And I'll post Berlacs profileagain.

    Computer Profile Summary
    Computer Name: ********(in WORKGROUP)
    Profile Date: Wednesday, October 08, 2003 16:32:54
    Advisor Version: 6.0j
    Windows Logon: *****


    Click here for Belarc's PC Management products, for large and small companies.

    Operating System System Model
    Windows XP Home Edition Service Pack 1 (build 2600) Compaq Presario ***********
    System Serial Number: ***************
    Asset Tag: *************
    Chassis Serial Number: *****************
    Processor a Main Circuit Board b
    1.60 gigahertz Intel Pentium 4
    8 kilobyte primary memory cache
    256 kilobyte secondary memory cache Board: Compaq 0784h
    Serial Number: *************
    Bus Clock: 400 megahertz
    BIOS: Compaq 686Y2 v2.06 12/03/2001
    Drives Memory Modules c,d
    60.01 Gigabytes Usable Hard Drive Capacity
    10.12 Gigabytes Hard Drive Free Space

    COMPAQ DVD-ROM GDR8160B [CD-ROM drive]
    HL-DT-ST CD-RW GCE-8240B [CD-ROM drive]
    3.5" format removeable media [Floppy drive]

    Maxtor 4D060H3 [Hard drive] (60.02 GB) -- drive 0, s/n D3H9H2ZE, rev DAH017K0, SMART Status: Healthy 256 Megabytes Installed Memory

    Slot 'XMM1' has 256 MB (serial number ***********)
    Slot 'XMM2' is Empty
    Local Drive Volumes

    c: (on drive 0) 52.68 GB 6.58 GB free
    d: (on drive 0) 7.33 GB 3.54 GB free

    Logins Network Drives
    **********\****
    NT AUTHORITY\LOCAL SERVICE
    NT AUTHORITY\NETWORK SERVICE
    NT AUTHORITY\SYSTEM

    Installed Microsoft Hotfixes Printers
    DataAccess
    Q823718 (details...) on 08/25/03
    DirectX
    DX819696 (details...)
    Internet Explorer
    Q330994 (details...)
    Q813489 (details...)
    Q818529 (details...)
    Q822925 (details...)
    Q828750 (details...)
    SP1 (SP1)
    Windows Media Player
    WM817787 (details...)
    WM819639 (details...)
    WM828026 (details...)
    SP0
    Q828026 (details...) on 10/04/03
    Windows XP
    SP1
    Q324720[SP] (details...) on 05/16/03
    SP2
    KB282010 (details...) on 09/29/03
    KB817778 (details...) on 09/18/03
    KB820291 (details...) on 06/29/03
    KB821253 (details...) on 07/15/03
    KB821557 (details...) on 07/18/03
    KB822603 (details...) on 09/29/03
    KB823559 (details...) on 07/15/03
    KB823980 (details...) on 07/18/03
    KB824105 (details...) on 09/04/03
    KB824146 (details...) on 09/13/03
    Q322011 (details...) on 05/16/03
    Q323255 (details...) on 05/16/03
    Q327979 (details...) on 05/16/03
    Q328310 (details...) on 05/16/03
    Q329048 (details...) on 05/16/03
    Q329115 (details...) on 05/16/03
    Q329170 (details...) on 05/16/03
    Q329390 (details...) on 05/16/03
    Q329441 (details...) on 05/16/03
    Q329834 (details...) on 05/16/03
    Q331953 (details...) on 05/16/03
    Q810243 (details...) on 05/16/03
    Q810565 (details...) on 05/16/03
    Q810577 (details...) on 05/16/03
    Q810833 (details...) on 05/16/03
    Q811493 (details...) on 05/16/03
    Q811630 (details...) on 05/16/03
    Q814033 (details...) on 05/16/03
    Q814995 (details...) on 05/16/03
    Q815021 (details...) on 05/29/03
    Q817287 (details...) on 05/16/03
    Q817606 (details...) on 07/15/03


    Click here to see all available security Hotfixes.

    Marks a HotFix that verifies correctly
    Marks a HotFix that fails verification
    (Failing hotfixes need to be reinstalled)
    An unmarked HotFix lacks the data to allow verification Canon S200 on USB001
    Microsoft Office Document Image Writer Driver on Microsoft Document Imaging Writer Port:

    Controllers Display
    Standard floppy disk controller
    Intel(r) 82801BA Bus Master IDE Controller
    Primary IDE Channel [Controller]
    Secondary IDE Channel [Controller] NVIDIA GeForce2 MX/MX 400 [Display adapter]
    Compaq FS740 [Monitor] (15.7"vis, March 2001)
    Bus Adapters Multimedia
    Intel(r) 82801BA/BAM USB Universal Host Controller - 2442
    Intel(r) 82801BA/BAM USB Universal Host Controller - 2444 SoundMAX Integrated Digital Audio
    Communications Other Devices
    HSP56 MicroModem
    Intel(R) PRO/100 VM Network Connection
    Network Card MAC Address: 00:08:02:1A:E3:E2
    Network IP Address: 24.42.218.46 / 23 HID-compliant consumer control device
    HID-compliant consumer control device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    HID-compliant device
    USB Human Interface Device
    USB Human Interface Device
    HID Keyboard Device
    Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
    PS/2 Compatible Mouse
    USB Composite Device
    USB Printing Support
    USB Root Hub
    USB Root Hub
    Software Licenses

    Adobe - Photoshop ***********
    Adobe Systems, Inc. - Adobe Photoshop 7.0 104518***********20732XXXX
    Microsoft - Internet Explorer 55277-OEM-0011903-00101 (Key: **************)e
    Microsoft - MediaPlayer 69808-467-******04478
    Microsoft - Office 2000 Premium 501****06-**********-02351
    Microsoft - Office Professional Edition *********640-0000106-57278 (Key: ***-****-P6RC4-****-3HFDY)
    Microsoft - WebFldrs XP ******-111-****-***********
    Microsoft - Windows XP Home Edition *******-OEM-****-00101 (Key: *****-JV9M6-****-****-HF2BQ)e

    Software Versions
    Awesome Computing - RPG Toolkit Translator (Version 2) Version 2.20.0143 *
    3ivx.com - 3ivx D4 4.0.4 Version 4, 0, 4, 0 *
    adi DrvLsnr Version 1, 0, 0, 3 *
    Adobe ImageReady (tm) 7.0 Version 7.0 *
    Adobe Photoshop Version 7.0 *
    Adobe Reader Version 6.0.0.2003051900 *
    Adobe Systems AdobeDownloadManager Version 1.2 *
    AGENTIX Software - SystemReport Utility Version 0.93b *
    AIDA32 *
    Amaze Soft - FlashGet Version 1, 4, 0, 0 *
    America Online, Inc. - AOL Instant Messenger Version 5.5.3415 *
    Analog Devices, Inc. - DLSLoader Application Version 3, 2, 0, 0 *
    Analog Devices, Inc. - SoundMAX service agent Version 3, 2, 6, 0 *
    AviC (FourCC Changer) *
    Awesome Computing - RPG Toolkit Development System, Version 2 Version 2.20.0100 *
    Belarc, Inc. - BelManage Client Version 6.0j *
    blindman.exe *
    bradfitz.com, inc. (original) | liquified.visions (current) - LiveJournal Version 1, 4, 7, 0 *
    BST - BSPlayer v0.8 Version 0.86 *
    btdownloadgui.exe *
    Cerulean Studios - Trillian Version 2.0.0.0 *
    Cinematronics - 3D Pinball Version 5.1.2600.0 *
    config.exe *
    Configuration Editor *
    DivXNetworks, Inc. - DivX EKG Version 1.0.0.0 *
    Fake Mailer Version 1.0.907.19032 *
    FourCC Code Changer *
    Gabest - Media Player Classic Version 6, 4, 6, 5 *
    GSpot Codec Information Appliance Version 2, 1, 0, 0 *
    GSpot Codec Information Appliance Version 2, 2, 1, 4 *
    Guide *
    GunBound (r) Version 1, 0, 0, 1 *
    GunBound Startup Application Version 1, 0, 0, 1 *
    http://www.emule-project.net - eMule Version 0.30.1 *
    iolo DriveScrubber Version 2.0.1.0 *
    iolo technologies, LLC - Search and Recover Version 1.0.2.0 *
    iolo technologies, LLC - System Mechanic 4 Utility Bar Version 4.0.1.0 *
    iolo technologies, LLC - System Mechanic ® Version 4.0.2.0 *
    iolo technologies, LLC - System Shield ® Version 2.1.1.0 *
    Java Web Start *
    javaw.exe *
    Jordan Russell - GunBound Uninstall *
    Jordan Russell - If you want to undo changes made by Spybot-S&D, use the Recovery instead! *
    KMCS Computer Software - REGCOMP Version 1.00 *
    KsL Software - Registry Healer Version 4.0.1.134 *
    Lavasoft Ad-aware Plus Version 6.0.0.0 *
    Macromedia Extension Manager Version 1.5.041 *
    Macromedia Flash Version 7, 0, 0, 470 *
    Macromedia Inc. - Fireworks Version 6.0 *
    Macromedia Licensing Service *
    Macromedia, Inc. - Shockwave Flash Version 7,0,14,0 *
    Matt's Computer Solutions [MCS] - ZoneLog Analyser Version 1.01.0008 *
    Mercedes - QuickSFV Version 2, 2, 2, 0 *
    Microsoft (R) .NET Framework Version 1.1.4322.573 * Microsoft Application Error Reporting Version 11.0.5515 *
    Microsoft Clip Gallery Version 5.1.00.1221 *
    Microsoft Clip Organizer Version 11.0.5510 *
    Microsoft Corporation - Internet Explorer Version 6.00.2800.1106 *
    Microsoft Corporation - Messenger Version 6.0 *
    Microsoft Corporation - Office Source Engine Version 11.0.5525 *
    Microsoft Corporation - Windows Installer - Unicode Version 2.0.2600.1106 *
    Microsoft Corporation - Windows Movie Maker Version 1.1.2427.1 *
    Microsoft Corporation - Windows® NetMeeting® Version 3.01 *
    Microsoft Corporation - Zone.com Version 1.2.626.1 *
    Microsoft Office 2000 Version 9.0.2702 *
    Microsoft Office 2003 Version 11.0.5614 *
    Microsoft Office Document Imaging Version 11.0.1897.0 *
    Microsoft Office InfoPath Version 11.0.5531 *
    Microsoft Office Outlook Version 11.0.5510 *
    Microsoft Office Picture Manager Version 11.0.5510 *
    Microsoft Office Save My Settings/Profile Wizard Version 11.0.5510 *
    Microsoft Open Database Connectivity Version 3.520.9030.0 *
    Microsoft Windows Media Player Version 6.4.09.1125 *
    Microsoft(R) Windows Media Player Version 9.00.00.2980 *
    Microsoft® FrontPage® 2000 Version 4.0.2.2717 *
    Microsoft® Visual Basic for Windows Version 6.00.8450 *
    Microsoft® Windows(TM) Shell PowerToys Version 96.02.06 *
    MindVision Software - Installer VISE Version 3.6.0 *
    MiniCalc *
    mIRC Version 6.03 *
    MySoft - MyIE2 Application Version 0, 8, 2070, 0 *
    NOD32 *
    NOD32 Control Center *
    NOD32 Kernel Service *
    Nullsoft - Winamp Version 2.80 *
    NVIDIA Driver Helper Service, Version 45.23 Version 6.14.10.4523 *
    O&O Software GmbH - O&O Defrag Version 4.0.508 *
    OGMCalc Application Version 0, 1, 0, 1 *
    Outer Technologies - Cacheman Version 5 *
    pctvoice Application Version 1, 0, 0, 1 *
    PepiMK Software - SpyBot-S&D Version 1.2 *
    Process RAR, ZIP and other archive formats *
    Recover memory now *
    REGSCRUBXP Application Version 3.25 *
    RegSupreme Version 1.0.0.0 *
    ResHacker Version 3.0.0.0 *
    Sheep Design - nVidia Refresh Rate Fix MKII v2.20 E Version 2.02 *
    SmartFTP Version 1.0.979.1 *
    StatsReader Version 2, 0, 1, 1 *
    System Mechanic 4 PopupStopper Version 1.0.0.0 *
    TR-Software - xp-AntiSpy Version 3, 7, 2, 0 *
    WildTangent, Inc. - Wild Tangent wcmdmgrl Version 1.6.1.2 *
    Wizards to adjust .NET Framework security, assign trust to assemblies, and fix broken .NET applications. Version 1.0.5000.0 *
    Xteq Systems X-Setup Version 6.2 *
    YourWare Solutions (TM) - FRXPRO Version 1.0.0.0 *
    Zone Labs Client Version 4.0.196.000 *
    Zone Labs Inc. - Internet Access Monitor Version 4.0.196.000 *
    Zone Labs Inc. - TrueVector Service Version 4.0.196.000 *
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds