Sorry again for the late reply ive been super busy with finals coming up + my internet got taken way 4 a bit.. heres the files
my Vundofilog is
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.7
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Scan started at 5:46:42 PM 11/28/2007
Listing files found while scanning….
C:\windows\system32\kcwbtbwj.dll
C:\WINDOWS\system32\ohyecqpw.dll
C:\windows\system32\ohyecqpw.dllbox
Beginning removal…
Beginning removal…
Attempting to delete C:\windows\system32\kcwbtbwj.dll
C:\windows\system32\kcwbtbwj.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ohyecqpw.dll
C:\WINDOWS\system32\ohyecqpw.dll Has been deleted!
Attempting to delete C:\windows\system32\ohyecqpw.dllbox
C:\windows\system32\ohyecqpw.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.0
Checking Java version…
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.7
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Scan started at 18:37:46 2007-12-05
Listing files found while scanning….
C:\windows\system32\ayandopv.dllbox
C:\windows\system32\blynuevb.dll
C:\windows\system32\fefejoqf.dll
C:\windows\system32\fmlpeumt.dll
C:\windows\system32\icghqhqp.dllbox
C:\windows\system32\iyikyjdi.dll
C:\windows\system32\krsccapc.exe
C:\windows\system32\lypxfekd.dllbox
C:\windows\system32\nuufblzm.dllbox
C:\windows\system32\qthstyla.dllbox
C:\windows\system32\qxsqdciv.exe
C:\windows\system32\rfypwrfm.exe
C:\windows\system32\susxcjxa.exe
C:\windows\system32\synpcjos.dll
C:\windows\system32\xhpxghpl.exe
Beginning removal…
Attempting to delete C:\windows\system32\ayandopv.dllbox
C:\windows\system32\ayandopv.dllbox Has been deleted!
Attempting to delete C:\windows\system32\blynuevb.dll
C:\windows\system32\blynuevb.dll Has been deleted!
Attempting to delete C:\windows\system32\fefejoqf.dll
C:\windows\system32\fefejoqf.dll Has been deleted!
Attempting to delete C:\windows\system32\fmlpeumt.dll
C:\windows\system32\fmlpeumt.dll Has been deleted!
Attempting to delete C:\windows\system32\icghqhqp.dllbox
C:\windows\system32\icghqhqp.dllbox Has been deleted!
Attempting to delete C:\windows\system32\iyikyjdi.dll
C:\windows\system32\iyikyjdi.dll Has been deleted!
Attempting to delete C:\windows\system32\krsccapc.exe
C:\windows\system32\krsccapc.exe Has been deleted!
Attempting to delete C:\windows\system32\lypxfekd.dllbox
C:\windows\system32\lypxfekd.dllbox Has been deleted!
Attempting to delete C:\windows\system32\nuufblzm.dllbox
C:\windows\system32\nuufblzm.dllbox Has been deleted!
Attempting to delete C:\windows\system32\qthstyla.dllbox
C:\windows\system32\qthstyla.dllbox Has been deleted!
Attempting to delete C:\windows\system32\qxsqdciv.exe
C:\windows\system32\qxsqdciv.exe Has been deleted!
Attempting to delete C:\windows\system32\rfypwrfm.exe
C:\windows\system32\rfypwrfm.exe Has been deleted!
Attempting to delete C:\windows\system32\susxcjxa.exe
C:\windows\system32\susxcjxa.exe Has been deleted!
Attempting to delete C:\windows\system32\synpcjos.dll
C:\windows\system32\synpcjos.dll Has been deleted!
Attempting to delete C:\windows\system32\xhpxghpl.exe
C:\windows\system32\xhpxghpl.exe Has been deleted!
Performing Repairs to the registry.
Done!
the extra.txt and main.txt are
VundoFix V6.6.2
Checking Java version…
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.7
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Scan started at 5:46:42 PM 11/28/2007
Listing files found while scanning….
C:\windows\system32\kcwbtbwj.dll
C:\WINDOWS\system32\ohyecqpw.dll
C:\windows\system32\ohyecqpw.dllbox
Beginning removal…
Beginning removal…
Attempting to delete C:\windows\system32\kcwbtbwj.dll
C:\windows\system32\kcwbtbwj.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ohyecqpw.dll
C:\WINDOWS\system32\ohyecqpw.dll Has been deleted!
Attempting to delete C:\windows\system32\ohyecqpw.dllbox
C:\windows\system32\ohyecqpw.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.0
Checking Java version…
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.7
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Scan started at 18:37:46 2007-12-05
Listing files found while scanning….
C:\windows\system32\ayandopv.dllbox
C:\windows\system32\blynuevb.dll
C:\windows\system32\fefejoqf.dll
C:\windows\system32\fmlpeumt.dll
C:\windows\system32\icghqhqp.dllbox
C:\windows\system32\iyikyjdi.dll
C:\windows\system32\krsccapc.exe
C:\windows\system32\lypxfekd.dllbox
C:\windows\system32\nuufblzm.dllbox
C:\windows\system32\qthstyla.dllbox
C:\windows\system32\qxsqdciv.exe
C:\windows\system32\rfypwrfm.exe
C:\windows\system32\susxcjxa.exe
C:\windows\system32\synpcjos.dll
C:\windows\system32\xhpxghpl.exe
Beginning removal…
Attempting to delete C:\windows\system32\ayandopv.dllbox
C:\windows\system32\ayandopv.dllbox Has been deleted!
Attempting to delete C:\windows\system32\blynuevb.dll
C:\windows\system32\blynuevb.dll Has been deleted!
Attempting to delete C:\windows\system32\fefejoqf.dll
C:\windows\system32\fefejoqf.dll Has been deleted!
Attempting to delete C:\windows\system32\fmlpeumt.dll
C:\windows\system32\fmlpeumt.dll Has been deleted!
Attempting to delete C:\windows\system32\icghqhqp.dllbox
C:\windows\system32\icghqhqp.dllbox Has been deleted!
Attempting to delete C:\windows\system32\iyikyjdi.dll
C:\windows\system32\iyikyjdi.dll Has been deleted!
Attempting to delete C:\windows\system32\krsccapc.exe
C:\windows\system32\krsccapc.exe Has been deleted!
Attempting to delete C:\windows\system32\lypxfekd.dllbox
C:\windows\system32\lypxfekd.dllbox Has been deleted!
Attempting to delete C:\windows\system32\nuufblzm.dllbox
C:\windows\system32\nuufblzm.dllbox Has been deleted!
Attempting to delete C:\windows\system32\qthstyla.dllbox
C:\windows\system32\qthstyla.dllbox Has been deleted!
Attempting to delete C:\windows\system32\qxsqdciv.exe
C:\windows\system32\qxsqdciv.exe Has been deleted!
Attempting to delete C:\windows\system32\rfypwrfm.exe
C:\windows\system32\rfypwrfm.exe Has been deleted!
Attempting to delete C:\windows\system32\susxcjxa.exe
C:\windows\system32\susxcjxa.exe Has been deleted!
Attempting to delete C:\windows\system32\synpcjos.dll
C:\windows\system32\synpcjos.dll Has been deleted!
Attempting to delete C:\windows\system32\xhpxghpl.exe
C:\windows\system32\xhpxghpl.exe Has been deleted!
Performing Repairs to the registry.
Done!
and my extra is
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
——————————————————————————–
– System Information ———————————————————-
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlon™ 64 Processor 3500+
Percentage of Memory in Use: 47%
Physical Memory (total/avail): 958.48 MiB / 498.57 MiB
Pagefile Memory (total/avail): 2312.25 MiB / 1570.54 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1924.4 MiB
C: is Fixed (NTFS) - 178.37 GiB total, 130.73 GiB free.
D: is Fixed (FAT32) - 7.91 GiB total, 0.55 GiB free.
E: is CDROM (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
\\.\PHYSICALDRIVE0 - WDC WD2000JS-60MHB1 - 186.31 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 178.37 GiB - C:
\PARTITION1 - Unknown - 7.93 GiB - D:
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
– Security Center ————————————————————-
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FirstRunDisabled is set.
AntiVirusDisableNotify is set.
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Activision\\Empires Dawn of the Modern World\\Empires_DMW.exe"="C:\\Program Files\\Activision\\Empires Dawn of the Modern World\\Empires_DMW.exe:*:Enabled:Empires_DMW"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:RTC App Sharing"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\\Program Files\\Bots\\bots.dat"="C:\\Program Files\\Bots\\bots.dat:*:Enabled:Bout_d"
"C:\\Program Files\\Darkeden International\\DarkEden.exe"="C:\\Program Files\\Darkeden International\\DarkEden.exe:*:Enabled:DarkEden"
"C:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"="C:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe:*:Enabled:W40kWA"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"="C:\\Program Files\\THQ\\Dawn Of War\\W40k.exe:*:Enabled:W40k"
"C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\NEXON\\MapleStory\\Patcher.exe"="C:\\Program Files\\NEXON\\MapleStory\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\Knight Online\\Launcher.exe"="C:\\Program Files\\Knight Online\\Launcher.exe:*:Enabled:Knight Online"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\ijji\\ENGLISH\\u_sf\\soldierfront.exe"="C:\\ijji\\ENGLISH\\u_sf\\soldierfront.exe:*:Enabled:soldierfront"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temporary Internet Files\\Content.IE5\\UOCW419E\\wowclient-downloader[1].exe"="C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temporary Internet Files\\Content.IE5\\UOCW419E\\wowclient-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. The whole world can talk for free."
"C:\\Program Files\\NEXON\\MapleStory\\NewPatcher.exe"="C:\\Program Files\\NEXON\\MapleStory\\NewPatcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\EGunZ Beta 2.1\\Gunz.exe"="C:\\Program Files\\EGunZ Beta 2.1\\Gunz.exe:*:Enabled:Gunz"
"C:\\Program Files\\EGunZ Beta 2.4.1\\Gunz.exe"="C:\\Program Files\\EGunZ Beta 2.4.1\\Gunz.exe:*:Enabled:Gunz"
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"="C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe:*:Enabled:Gunz"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\AhnQiraj_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\AhnQiraj_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Arathi_Basin_new_EG-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Arathi_Basin_new_EG-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\DarkmooneFaire_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\DarkmooneFaire_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\EPL_Trailer_EG.avi-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\EPL_Trailer_EG.avi-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Naxxramas_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Naxxramas_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\WoW_Coke-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\WoW_Coke-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Zul'Gurub_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Zul'Gurub_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\KRU\\NexusTK\\NexusTK.exe"="C:\\Program Files\\KRU\\NexusTK\\NexusTK.exe:*:Enabled:NexusTK"
"C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temp\\nsv28F.tmp\\utorrent.exe"="C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temp\\nsv28F.tmp\\utorrent.exe:*:Enabled:µTorrent"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\hcrjjjvh.exe"="C:\\WINDOWS\\system32\\hcr"
"C:\\WINDOWS\\system32\\wkfiqcqu.exe"="C:\\WINDOWS\\system32\\wkf"
"C:\\WINDOWS\\system32\\motinvbs.exe"="C:\\WINDOWS\\system32\\mot"
"C:\\WINDOWS\\system32\\odntuhim.exe"="C:\\WINDOWS\\system32\\odn"
"C:\\WINDOWS\\system32\\bqojolhl.exe"="C:\\WINDOWS\\system32\\bqo"
"C:\\WINDOWS\\system32\\xgfbrvqa.exe"="C:\\WINDOWS\\system32\\xgf"
– Environment Variables ——————————————————-
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Compaq_Administrator\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BRYCE
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Compaq_Administrator
LOGONSERVER=\\BRYCE
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\;c:\Program Files\Microsoft SQL Server\90\Tools\binn\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2f02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
SESSIONNAME=Console
SonicCentral=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
USERDOMAIN=BRYCE
USERNAME=Compaq_Administrator
USERPROFILE=C:\Documents and Settings\Compaq_Administrator
VS80COMNTOOLS=C:\Program Files\Microsoft Visual Studio 8\Common7\Tools\
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
– User Profiles —————————————————————
Compaq_Administrator
(admin)
Administrator
(admin)
Guest
(guest)
– Add/Remove Programs ———————————————————
–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX –> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 7.0 –> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Agere Systems PCI-SV92PP Soft Modem –> agrsmdel
Alive MP3 WAV Converter version 3.9.6.6 –> "C:\Program Files\AliveMedia\MP3 WAV Converter\unins000.exe"
Apple Software Update –> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
ATI Control Panel –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver –> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Brothers In Arms EiB –> C:\Program Files\Ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe uninstall "BrothersInArmsEiB"
Browser MOUSE –> C:\Program Files\Browser MOUSE\uninst00.exe
CCleaner (remove only) –> "C:\Program Files\CCleaner\uninst.exe"
Cheat Engine 5.3 –> "C:\Program Files\Cheat Engine\unins000.exe"
Compaq Multimedia Keyboard Software –> C:\HP\KBD\Install.exe /remove
Customer Experience Enhancement –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1033
Darkeden –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5109FC1B-2250-4EDE-903A-1662B69F2001}\Setup.exe" -l0x9
DivX Content Uploader –> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Web Player –> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DotColor 3.0 –> "C:\WINDOWS\UNISTB32.EXE" /U "C:\Program Files\DotColor\UNINST0.000" "C:\Program Files\DotColor\UNINST1.000"
Drift City –> "C:\Program Files\DriftCity\uninstall.exe"
Easy Internet Sign-up –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033
eGames GameButler –> C:\PROGRA~1\eGames\GAMEBU~1\UNWISE.EXE C:\PROGRA~1\eGames\GAMEBU~1\INSTALL.LOG
Encyclopædia Britannica Deluxe Edition –> "C:\Program Files\Britannica 2003\Deluxe Edition CD\Uninstaller.exe"
Enemy Territory Example Maps –> MsiExec.exe /I{D2644618-A31F-4DBE-91C0-9561B22764CE}
FLAC 1.2.1a (remove only) –> C:\Program Files\FLAC\uninstall.exe
Fraps –> "C:\Fraps\uninstall.exe"
G-Force –> C:\Program Files\SoundSpectrum\G-Force\Uninstall.exe
Google Toolbar for Internet Explorer –> regsvr32 /u /s "c:\program files\google\googletoolbar4.dll"
GtkRadiant 1.5.0 –> MsiExec.exe /I{EC2F741D-308C-42B4-BD04-9A4853F2E402}
Heavyweight Thunder –> C:\PROGRA~1\eGames\HEAVYW~1\UNWISE.EXE C:\PROGRA~1\eGames\HEAVYW~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111 –> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 –> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Boot Optimizer –> C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe /uninstall
HP Deskjet 5400 series –> C:\Program Files\HP\Digital Imaging\{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}\setup\hpzscr01.exe -datfile hpfscr05.dat
HP DigitalMedia Archive –> MsiExec.exe /X{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP DVD Play 1.0 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP Extended Capabilities 5.0 –> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 6.0 –> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Premier Software 6.0 –> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Software Update –> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
HP Software Update –> MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center & Imaging Support Tools 5.0 –> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Support Overview –> "C:\WINDOWS\unins000.exe"
HP Web Helper –> regsvr32 /u /s "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll"
ijji –> C:\ijji\ENGLISH\ijjiUninstall.exe
ijji - Gunz –> C:\ijji\ENGLISH\Gunz\Uninstall.exe
ijji Auto Installer –> "C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly
iTunes –> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
Java DB 10.2.2.0 –> MsiExec.exe /X{0ECB59D5-A3FC-4D61-AD3B-6CE679B3F852}
Java™ 6 Update 3 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ SE Development Kit 6 Update 3 –> MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160030}
JCreator Pro 4.00 –> "C:\Program Files\Xinox Software\JCreatorV4\unins000.exe"
LimeWire 4.12.6 –> "C:\Program Files\LimeWire\uninstall.exe"
LiveUpdate 3.0 (Symantec Corporation) –> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
MapleStory –> MsiExec.exe /I{99217575-1F9D-438A-A2E9-D8FC1D96A04F}
Microsoft Away Mode –>
Microsoft Office 2003 Edition 60 Days Trial Welcome Tour –> MsiExec.exe /I{A01FC76F-CC09-4658-9E37-5C2F635EE708}
Microsoft Office Standard Edition 2003 –> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight –> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 –> "c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) –> MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005 Tools Express Edition –> MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
Microsoft SQL Server Compact 3.5 Design Tools ENU –> MsiExec.exe /X{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}
Microsoft SQL Server Compact 3.5 ENU –> MsiExec.exe /I{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}
Microsoft SQL Server Native Client –> MsiExec.exe /I{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}
Microsoft SQL Server Setup Support Files (English) –> MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer –> MsiExec.exe /I{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}
Microsoft Visual Basic 2005 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU –> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual Basic 2008 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Basic 2008 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2008 Express Edition - ENU –> MsiExec.exe /X{9C2DC81B-8114-37D9-A922-95E460A1FAFB}
Microsoft Visual C# 2008 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual C# 2008 Express Edition - ENU\setup.exe
Microsoft Visual C# 2008 Express Edition - ENU –> MsiExec.exe /X{2D07422C-CA35-375A-A3A8-3631AB85BFE5}
Microsoft Visual C++ 2005 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual C++ 2005 Express Edition - ENU\setup.exe
Microsoft Visual C++ 2005 Express Edition - ENU –> MsiExec.exe /X{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}
Microsoft Web Publishing Wizard 1.52 –> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie4x86.inf,WebPostUninstall
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework –> MsiExec.exe /X{B4C0A315-07FB-39F9-85CD-8CE20C019350}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32 –> MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
Microsoft Works –> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Microsoft XNA Framework Redistributable 1.0 Refresh –> MsiExec.exe /I{311F799A-FCE9-4D9E-B5D2-CBB8859B40BB}
Mozilla Firefox (2.0.0.2) –> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSDN Library for Microsoft Visual Studio 2008 Express Editions –> C:\Program Files\Microsoft Visual Studio 9.0\MSDN Library for Microsoft Visual Studio 2008 Express Editions\install.exe
MSN –> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 6.0 Parser (KB933579) –> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MSXML4 Parser –> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Netscape Browser (remove only) –> "C:\Program Files\Netscape\Netscape Browser\NSUninst.exe"
NexusTK –> C:\PROGRA~1\KRU\NexusTK\UNWISE.EXE C:\PROGRA~1\KRU\NexusTK\INSTALL.LOG
OpenMG AAC Add-on Module 1.0.00 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3} UNINSTALL
OpenMG Limited Patch 4.5-06-05-12-01 –> C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.5-06-05-12-01\HotFixSetup\setup.exe /u
OpenMG Secure Module 4.5.01 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{3633BA28-67CE-4AC8-A677-3406CA84C3D8} UNINSTALL
Otto –> "C:\Program Files\EnglishOtto\uninstallotto.exe"
PC-Doctor 5 for Windows –> C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
PCFriendly –> C:\Program Files\PCFriendly\inuninst.exe
Performance Optimizer –> C:\Program Files\Performanceoptimizer (Free)\uninstpo.exe
Power Tab Editor 1.7 –> C:\PROGRA~1\PTSOFT~1\PTEDIT~1\UNWISE.EXE C:\PROGRA~1\PTSOFT~1\PTEDIT~1\INSTALL.LOG
PS2 –> C:\WINDOWS\system32\ps2.exe uninstall
QuickTime –> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RegCure 1.5.0.0 –> C:\Program Files\RegCure\uninst.exe
Remove WeatherBug Installer –> c:\hp\bin\cloaker.exe c:\hp\bin\commands.exe /c c:\hp\bin\wbug\clean.bat
Security Update for Step By Step Interactive Training (KB898458) –> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) –> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Shockwave –> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
slipknot.zip –> C:\PROGRA~1\FILESU~1\slipknot.zip\UNWISE.EXE C:\PROGRA~1\FILESU~1\slipknot.zip\INSTALL.LOG
slipknot2.zip –> C:\PROGRA~1\FILESU~1\SLIPKN~1.ZIP\UNWISE.EXE C:\PROGRA~1\FILESU~1\SLIPKN~1.ZIP\INSTALL.LOG
Sonic Express Labeler –> MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic RecordNow Audio –> MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy –> MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data –> MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager –> MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spyware Doctor 5.1 –> C:\Program Files\Spyware Doctor\unins000.exe /LOG
Sun Download Manager 2.0 (web) –> C:\WINDOWS\system32\javaws.exe -uninstall -prompt "
http://javadl-esd.sun.com/update/sdm20/sdm20.jnlp"
TeamSpeak 2 RC2 –> "C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamViewer 3 –> C:\Program Files\TeamViewer3\uninstall.exe
The Weather Channel Desktop –> C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
Update Rollup 2 for Windows XP Media Center Edition 2005 –>
Ventrilo Client –> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Viewpoint Media Player –> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Virtual FlashCards 2.1 –> "C:\Program Files\Virtual FlashCards\unins000.exe"
Weather Services –> C:\WINDOWS\system32\control.exe C:\PROGRA~1\THEWEA~1\Framework\wxfw.cpl,4
Windows Imaging Component –> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Messenger –> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant –> MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
Windows XP Media Center Edition 2005 KB908250 –> "C:\WINDOWS\$NtUninstallKB908250$\spuninst\spuninst.exe"
WinRAR archiver –> C:\Program Files\WinRAR\uninstall.exe
WordPerfect Office 2002 –> C:\WINDOWS\Corel\uninst32.exe
WordPerfect Office 2002 –> C:\WINDOWS\Corel\Uninst32.exe
World of Warcraft Desktop –> C:\PROGRA~1\Stardock\OBJECT~1\THEMEM~1\thememgr.exe /uninstallwise
XML Paper Specification Shared Components Pack 1.0 –>
XoftSpySE –> C:\Program Files\XoftSpySE\uninstall.exe
Zboard ™ Software –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B5658E-5E34-45C1-AAFA-8AF997684928}\Setup.exe" -l0x9
– Application Event Log ——————————————————-
Event Record #/Type3782 / Error
Event Submitted/Written: 12/11/2007 06:05:15 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application vbexpress.exe, version 9.0.21022.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3781 / Error
Event Submitted/Written: 12/11/2007 06:05:15 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application vbexpress.exe, version 9.0.21022.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3775 / Error
Event Submitted/Written: 12/11/2007 06:01:58 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3772 / Error
Event Submitted/Written: 12/11/2007 05:55:01 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application realplay.exe, version 6.0.12.1483, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3771 / Error
Event Submitted/Written: 12/11/2007 05:39:13 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application realplay.exe, version 6.0.12.1483, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
– Security Event Log ———————————————————-
No Errors/Warnings found.
– System Event Log ————————————————————
Event Record #/Type171574 / Error
Event Submitted/Written: 12/11/2007 03:19:46 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Automatic LiveUpdate Scheduler service failed to start due to the following error:
%%1053
Event Record #/Type171573 / Error
Event Submitted/Written: 12/11/2007 03:19:46 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate Scheduler service to connect.
Event Record #/Type171548 / Error
Event Submitted/Written: 12/11/2007 06:08:30 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Automatic LiveUpdate Scheduler service failed to start due to the following error:
%%1053
Event Record #/Type171547 / Error
Event Submitted/Written: 12/11/2007 06:08:30 AM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate Scheduler service to connect.
Event Record #/Type171541 / Error
Event Submitted/Written: 12/10/2007 09:33:05 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register with DCOM within the required timeout.
– End of Deckard's System Scanner: finished at 2007-12-11 18:13:30 ————
and my new hijack this file is
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
——————————————————————————–
– System Information ———————————————————-
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlon™ 64 Processor 3500+
Percentage of Memory in Use: 47%
Physical Memory (total/avail): 958.48 MiB / 498.57 MiB
Pagefile Memory (total/avail): 2312.25 MiB / 1570.54 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1924.4 MiB
C: is Fixed (NTFS) - 178.37 GiB total, 130.73 GiB free.
D: is Fixed (FAT32) - 7.91 GiB total, 0.55 GiB free.
E: is CDROM (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
\\.\PHYSICALDRIVE0 - WDC WD2000JS-60MHB1 - 186.31 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 178.37 GiB - C:
\PARTITION1 - Unknown - 7.93 GiB - D:
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
– Security Center ————————————————————-
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FirstRunDisabled is set.
AntiVirusDisableNotify is set.
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Activision\\Empires Dawn of the Modern World\\Empires_DMW.exe"="C:\\Program Files\\Activision\\Empires Dawn of the Modern World\\Empires_DMW.exe:*:Enabled:Empires_DMW"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\rtcshare.exe"="C:\\WINDOWS\\system32\\rtcshare.exe:*:Enabled:RTC App Sharing"
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\\Program Files\\Bots\\bots.dat"="C:\\Program Files\\Bots\\bots.dat:*:Enabled:Bout_d"
"C:\\Program Files\\Darkeden International\\DarkEden.exe"="C:\\Program Files\\Darkeden International\\DarkEden.exe:*:Enabled:DarkEden"
"C:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"="C:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe:*:Enabled:W40kWA"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"="C:\\Program Files\\THQ\\Dawn Of War\\W40k.exe:*:Enabled:W40k"
"C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\NEXON\\MapleStory\\Patcher.exe"="C:\\Program Files\\NEXON\\MapleStory\\Patcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\Knight Online\\Launcher.exe"="C:\\Program Files\\Knight Online\\Launcher.exe:*:Enabled:Knight Online"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\ijji\\ENGLISH\\u_sf\\soldierfront.exe"="C:\\ijji\\ENGLISH\\u_sf\\soldierfront.exe:*:Enabled:soldierfront"
"C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temporary Internet Files\\Content.IE5\\UOCW419E\\wowclient-downloader[1].exe"="C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temporary Internet Files\\Content.IE5\\UOCW419E\\wowclient-downloader[1].exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. The whole world can talk for free."
"C:\\Program Files\\NEXON\\MapleStory\\NewPatcher.exe"="C:\\Program Files\\NEXON\\MapleStory\\NewPatcher.exe:*:Enabled:Patcher MFC ?? ????"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\EGunZ Beta 2.1\\Gunz.exe"="C:\\Program Files\\EGunZ Beta 2.1\\Gunz.exe:*:Enabled:Gunz"
"C:\\Program Files\\EGunZ Beta 2.4.1\\Gunz.exe"="C:\\Program Files\\EGunZ Beta 2.4.1\\Gunz.exe:*:Enabled:Gunz"
"C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe"="C:\\ijji\\ENGLISH\\Gunz\\Gunz.exe:*:Enabled:Gunz"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\AhnQiraj_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\AhnQiraj_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Arathi_Basin_new_EG-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Arathi_Basin_new_EG-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\DarkmooneFaire_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\DarkmooneFaire_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\EPL_Trailer_EG.avi-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\EPL_Trailer_EG.avi-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Naxxramas_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Naxxramas_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\WoW_Coke-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\WoW_Coke-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Zul'Gurub_English-downloader.exe"="C:\\Documents and Settings\\Compaq_Administrator\\My Documents\\New Folder (3)\\Zul'Gurub_English-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\KRU\\NexusTK\\NexusTK.exe"="C:\\Program Files\\KRU\\NexusTK\\NexusTK.exe:*:Enabled:NexusTK"
"C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temp\\nsv28F.tmp\\utorrent.exe"="C:\\Documents and Settings\\Compaq_Administrator\\Local Settings\\Temp\\nsv28F.tmp\\utorrent.exe:*:Enabled:µTorrent"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Remote Assistance - Windows Messenger and Voice"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\hcrjjjvh.exe"="C:\\WINDOWS\\system32\\hcr"
"C:\\WINDOWS\\system32\\wkfiqcqu.exe"="C:\\WINDOWS\\system32\\wkf"
"C:\\WINDOWS\\system32\\motinvbs.exe"="C:\\WINDOWS\\system32\\mot"
"C:\\WINDOWS\\system32\\odntuhim.exe"="C:\\WINDOWS\\system32\\odn"
"C:\\WINDOWS\\system32\\bqojolhl.exe"="C:\\WINDOWS\\system32\\bqo"
"C:\\WINDOWS\\system32\\xgfbrvqa.exe"="C:\\WINDOWS\\system32\\xgf"
– Environment Variables ——————————————————-
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Compaq_Administrator\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BRYCE
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Compaq_Administrator
LOGONSERVER=\\BRYCE
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\;c:\Program Files\Microsoft SQL Server\90\Tools\binn\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2f02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
SESSIONNAME=Console
SonicCentral=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp
USERDOMAIN=BRYCE
USERNAME=Compaq_Administrator
USERPROFILE=C:\Documents and Settings\Compaq_Administrator
VS80COMNTOOLS=C:\Program Files\Microsoft Visual Studio 8\Common7\Tools\
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
– User Profiles —————————————————————
Compaq_Administrator
(admin)
Administrator
(admin)
Guest
(guest)
– Add/Remove Programs ———————————————————
–> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
–> c:\WINDOWS\system32\\MSIEXEC.EXE /x {F80239D8-7811-4D5E-B033-0D0BBFE32920}
–> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX –> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Reader 7.0 –> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Agere Systems PCI-SV92PP Soft Modem –> agrsmdel
Alive MP3 WAV Converter version 3.9.6.6 –> "C:\Program Files\AliveMedia\MP3 WAV Converter\unins000.exe"
Apple Software Update –> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
ATI Control Panel –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver –> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Brothers In Arms EiB –> C:\Program Files\Ubisoft\Gearbox Software\BrothersInArmsEiB\System\Setup.exe uninstall "BrothersInArmsEiB"
Browser MOUSE –> C:\Program Files\Browser MOUSE\uninst00.exe
CCleaner (remove only) –> "C:\Program Files\CCleaner\uninst.exe"
Cheat Engine 5.3 –> "C:\Program Files\Cheat Engine\unins000.exe"
Compaq Multimedia Keyboard Software –> C:\HP\KBD\Install.exe /remove
Customer Experience Enhancement –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1033
Darkeden –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5109FC1B-2250-4EDE-903A-1662B69F2001}\Setup.exe" -l0x9
DivX Content Uploader –> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Web Player –> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DotColor 3.0 –> "C:\WINDOWS\UNISTB32.EXE" /U "C:\Program Files\DotColor\UNINST0.000" "C:\Program Files\DotColor\UNINST1.000"
Drift City –> "C:\Program Files\DriftCity\uninstall.exe"
Easy Internet Sign-up –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033
eGames GameButler –> C:\PROGRA~1\eGames\GAMEBU~1\UNWISE.EXE C:\PROGRA~1\eGames\GAMEBU~1\INSTALL.LOG
Encyclopædia Britannica Deluxe Edition –> "C:\Program Files\Britannica 2003\Deluxe Edition CD\Uninstaller.exe"
Enemy Territory Example Maps –> MsiExec.exe /I{D2644618-A31F-4DBE-91C0-9561B22764CE}
FLAC 1.2.1a (remove only) –> C:\Program Files\FLAC\uninstall.exe
Fraps –> "C:\Fraps\uninstall.exe"
G-Force –> C:\Program Files\SoundSpectrum\G-Force\Uninstall.exe
Google Toolbar for Internet Explorer –> regsvr32 /u /s "c:\program files\google\googletoolbar4.dll"
GtkRadiant 1.5.0 –> MsiExec.exe /I{EC2F741D-308C-42B4-BD04-9A4853F2E402}
Heavyweight Thunder –> C:\PROGRA~1\eGames\HEAVYW~1\UNWISE.EXE C:\PROGRA~1\eGames\HEAVYW~1\INSTALL.LOG
High Definition Audio Driver Package - KB888111 –> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 –> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Boot Optimizer –> C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe /uninstall
HP Deskjet 5400 series –> C:\Program Files\HP\Digital Imaging\{EB57A16E-500D-43d7-85B9-FBE279EBBA6E}\setup\hpzscr01.exe -datfile hpfscr05.dat
HP DigitalMedia Archive –> MsiExec.exe /X{F80239D8-7811-4D5E-B033-0D0BBFE32920}
HP DVD Play 1.0 –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\Setup.exe" -uninstall
HP Extended Capabilities 5.0 –> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Imaging Device Functions 6.0 –> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Premier Software 6.0 –> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Software Update –> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
HP Software Update –> MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
HP Solution Center & Imaging Support Tools 5.0 –> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Support Overview –> "C:\WINDOWS\unins000.exe"
HP Web Helper –> regsvr32 /u /s "C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll"
ijji –> C:\ijji\ENGLISH\ijjiUninstall.exe
ijji - Gunz –> C:\ijji\ENGLISH\Gunz\Uninstall.exe
ijji Auto Installer –> "C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly
iTunes –> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
Java DB 10.2.2.0 –> MsiExec.exe /X{0ECB59D5-A3FC-4D61-AD3B-6CE679B3F852}
Java™ 6 Update 3 –> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ SE Development Kit 6 Update 3 –> MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160030}
JCreator Pro 4.00 –> "C:\Program Files\Xinox Software\JCreatorV4\unins000.exe"
LimeWire 4.12.6 –> "C:\Program Files\LimeWire\uninstall.exe"
LiveUpdate 3.0 (Symantec Corporation) –> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
MapleStory –> MsiExec.exe /I{99217575-1F9D-438A-A2E9-D8FC1D96A04F}
Microsoft Away Mode –>
Microsoft Office 2003 Edition 60 Days Trial Welcome Tour –> MsiExec.exe /I{A01FC76F-CC09-4658-9E37-5C2F635EE708}
Microsoft Office Standard Edition 2003 –> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight –> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 –> "c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) –> MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005 Tools Express Edition –> MsiExec.exe /I{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}
Microsoft SQL Server Compact 3.5 Design Tools ENU –> MsiExec.exe /X{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}
Microsoft SQL Server Compact 3.5 ENU –> MsiExec.exe /I{BCC899FE-2DAA-460C-A5FB-60291E73D9C3}
Microsoft SQL Server Native Client –> MsiExec.exe /I{F9B3DD02-B0B3-42E9-8650-030DFF0D133D}
Microsoft SQL Server Setup Support Files (English) –> MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer –> MsiExec.exe /I{E9F44C98-B8B6-480F-AF7B-E42A0A46F4E3}
Microsoft Visual Basic 2005 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Basic 2005 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2005 Express Edition - ENU –> MsiExec.exe /X{577AD794-8B34-40B4-9E7A-BE4CFFE396E6}
Microsoft Visual Basic 2008 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Basic 2008 Express Edition - ENU\setup.exe
Microsoft Visual Basic 2008 Express Edition - ENU –> MsiExec.exe /X{9C2DC81B-8114-37D9-A922-95E460A1FAFB}
Microsoft Visual C# 2008 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual C# 2008 Express Edition - ENU\setup.exe
Microsoft Visual C# 2008 Express Edition - ENU –> MsiExec.exe /X{2D07422C-CA35-375A-A3A8-3631AB85BFE5}
Microsoft Visual C++ 2005 Express Edition - ENU –> C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual C++ 2005 Express Edition - ENU\setup.exe
Microsoft Visual C++ 2005 Express Edition - ENU –> MsiExec.exe /X{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}
Microsoft Web Publishing Wizard 1.52 –> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie4x86.inf,WebPostUninstall
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework –> MsiExec.exe /X{B4C0A315-07FB-39F9-85CD-8CE20C019350}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32 –> MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
Microsoft Works –> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Microsoft XNA Framework Redistributable 1.0 Refresh –> MsiExec.exe /I{311F799A-FCE9-4D9E-B5D2-CBB8859B40BB}
Mozilla Firefox (2.0.0.2) –> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSDN Library for Microsoft Visual Studio 2008 Express Editions –> C:\Program Files\Microsoft Visual Studio 9.0\MSDN Library for Microsoft Visual Studio 2008 Express Editions\install.exe
MSN –> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 6.0 Parser (KB933579) –> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MSXML4 Parser –> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Netscape Browser (remove only) –> "C:\Program Files\Netscape\Netscape Browser\NSUninst.exe"
NexusTK –> C:\PROGRA~1\KRU\NexusTK\UNWISE.EXE C:\PROGRA~1\KRU\NexusTK\INSTALL.LOG
OpenMG AAC Add-on Module 1.0.00 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3} UNINSTALL
OpenMG Limited Patch 4.5-06-05-12-01 –> C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.5-06-05-12-01\HotFixSetup\setup.exe /u
OpenMG Secure Module 4.5.01 –> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1150\INTEL3~1\IDriver.exe /M{3633BA28-67CE-4AC8-A677-3406CA84C3D8} UNINSTALL
Otto –> "C:\Program Files\EnglishOtto\uninstallotto.exe"
PC-Doctor 5 for Windows –> C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
PCFriendly –> C:\Program Files\PCFriendly\inuninst.exe
Performance Optimizer –> C:\Program Files\Performanceoptimizer (Free)\uninstpo.exe
Power Tab Editor 1.7 –> C:\PROGRA~1\PTSOFT~1\PTEDIT~1\UNWISE.EXE C:\PROGRA~1\PTSOFT~1\PTEDIT~1\INSTALL.LOG
PS2 –> C:\WINDOWS\system32\ps2.exe uninstall
QuickTime –> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
RealPlayer –> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RegCure 1.5.0.0 –> C:\Program Files\RegCure\uninst.exe
Remove WeatherBug Installer –> c:\hp\bin\cloaker.exe c:\hp\bin\commands.exe /c c:\hp\bin\wbug\clean.bat
Security Update for Step By Step Interactive Training (KB898458) –> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) –> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Shockwave –> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
slipknot.zip –> C:\PROGRA~1\FILESU~1\slipknot.zip\UNWISE.EXE C:\PROGRA~1\FILESU~1\slipknot.zip\INSTALL.LOG
slipknot2.zip –> C:\PROGRA~1\FILESU~1\SLIPKN~1.ZIP\UNWISE.EXE C:\PROGRA~1\FILESU~1\SLIPKN~1.ZIP\INSTALL.LOG
Sonic Express Labeler –> MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic RecordNow Audio –> MsiExec.exe /X{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
Sonic RecordNow Copy –> MsiExec.exe /X{B12665F4-4E93-4AB4-B7FC-37053B524629}
Sonic RecordNow Data –> MsiExec.exe /X{075473F5-846A-448B-BCB3-104AA1760205}
Sonic Update Manager –> MsiExec.exe /X{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Spyware Doctor 5.1 –> C:\Program Files\Spyware Doctor\unins000.exe /LOG
Sun Download Manager 2.0 (web) –> C:\WINDOWS\system32\javaws.exe -uninstall -prompt "
http://javadl-esd.sun.com/update/sdm20/sdm20.jnlp"
TeamSpeak 2 RC2 –> "C:\Program Files\Teamspeak2_RC2\unins000.exe"
TeamViewer 3 –> C:\Program Files\TeamViewer3\uninstall.exe
The Weather Channel Desktop –> C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
Update Rollup 2 for Windows XP Media Center Edition 2005 –>
Ventrilo Client –> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Viewpoint Media Player –> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Virtual FlashCards 2.1 –> "C:\Program Files\Virtual FlashCards\unins000.exe"
Weather Services –> C:\WINDOWS\system32\control.exe C:\PROGRA~1\THEWEA~1\Framework\wxfw.cpl,4
Windows Imaging Component –> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Messenger –> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant –> MsiExec.exe /I{22B3CC30-77B8-419C-AA4B-F571FDF5D66D}
Windows XP Media Center Edition 2005 KB908250 –> "C:\WINDOWS\$NtUninstallKB908250$\spuninst\spuninst.exe"
WinRAR archiver –> C:\Program Files\WinRAR\uninstall.exe
WordPerfect Office 2002 –> C:\WINDOWS\Corel\uninst32.exe
WordPerfect Office 2002 –> C:\WINDOWS\Corel\Uninst32.exe
World of Warcraft Desktop –> C:\PROGRA~1\Stardock\OBJECT~1\THEMEM~1\thememgr.exe /uninstallwise
XML Paper Specification Shared Components Pack 1.0 –>
XoftSpySE –> C:\Program Files\XoftSpySE\uninstall.exe
Zboard ™ Software –> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{12B5658E-5E34-45C1-AAFA-8AF997684928}\Setup.exe" -l0x9
– Application Event Log ——————————————————-
Event Record #/Type3782 / Error
Event Submitted/Written: 12/11/2007 06:05:15 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application vbexpress.exe, version 9.0.21022.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3781 / Error
Event Submitted/Written: 12/11/2007 06:05:15 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application vbexpress.exe, version 9.0.21022.8, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3775 / Error
Event Submitted/Written: 12/11/2007 06:01:58 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3772 / Error
Event Submitted/Written: 12/11/2007 05:55:01 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application realplay.exe, version 6.0.12.1483, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type3771 / Error
Event Submitted/Written: 12/11/2007 05:39:13 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application realplay.exe, version 6.0.12.1483, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
– Security Event Log ———————————————————-
No Errors/Warnings found.
– System Event Log ————————————————————
Event Record #/Type171574 / Error
Event Submitted/Written: 12/11/2007 03:19:46 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Automatic LiveUpdate Scheduler service failed to start due to the following error:
%%1053
Event Record #/Type171573 / Error
Event Submitted/Written: 12/11/2007 03:19:46 PM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate Scheduler service to connect.
Event Record #/Type171548 / Error
Event Submitted/Written: 12/11/2007 06:08:30 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Automatic LiveUpdate Scheduler service failed to start due to the following error:
%%1053
Event Record #/Type171547 / Error
Event Submitted/Written: 12/11/2007 06:08:30 AM
Event ID/Source: 7009 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate Scheduler service to connect.
Event Record #/Type171541 / Error
Event Submitted/Written: 12/10/2007 09:33:05 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {DC0C2640-1415-4644-875C-6F4D769839BA} did not register with DCOM within the required timeout.
– End of Deckard's System Scanner: finished at 2007-12-11 18:13:30 ————