The Infection:
I was minding my own business today when a popup appeared, it was plainly a virus posing as an anti virus tool specifically VirusRemoval2008.
I clicked the X and cancel but there was a gauntlet of warnings and in the meantime the pop up had a progress bar going and once it reached 100 clicking X finally worked.
I had thought I had escaped but immediately afterward my computer reset.
The Effects:
Once up and running again, windows explorer, internet explorer and windows explorer will not open.
The Task Manager shows they are running yet they don't come up.
Although Windows Explorer does function enough to let the Menu come up, just not the browsing window.
Opened Windows Media Player, and ESET NOD32 Antivirus said it had blocked and deleted: win32/TrojanDownloader.Zlob.SK
However, Windows media player doesn't fully open still.
It opens so you can see content but becomes unresponsive.
Windows+E says its unassigned.
The sound icon in the tray doesn't come up.
The Virus:
I managed to get the link of the popup that infected me.
The Odditty:
I searched for info on VirusRemoval2008, but the removal options such as using task manager to stop it running aren't relevant as the program they suggest is running (VR2008.exe and variants) dont seem to be running. The regedit files don't seem relevant either.
And since I can't use W. Explorer i can't search for the files on my computer either.
So as far as I can see could this perhaps be a Virus posing as a different Virus posing as a AntiVirus?
The Quarantine:
I have run SpyBot, NOD32Antivirus and currently running MBAM(Done, found nothing, but previously had found two things and deleted them.).
The Logs:
Malwarebytes' Anti-Malware 1.28
Database version: 1134
Windows 5.1.2600 Service Pack 3
9/29/2008 5:00:59 PM
mbam-log-2008-09-29 (17-00-59).txt
Scan type: Full Scan (C:\|)
Objects scanned: 193591
Time elapsed: 2 hour(s), 17 minute(s), 11 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Logfile of random's system information tool 1.02 (written by random/random)
Run by [removed] at 2008-09-29 15:28:15
Microsoft Windows XP Professional Service Pack 3
System drive C: has 62 GB (43%) free of 145 GB
Total RAM: 1023 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:28:39 PM, on 9/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
c:\windows\mHotkey.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\*****\Desktop\RSIT(2).exe
C:\Program Files\Trend Micro\HijackThis\*****.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: AmsServer
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O3 - Toolbar: xtramsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CHotkey] C:\APPS\Chicony\chicony.bat
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [JoyMouse] "C:\Program Files\JoyMouse\JoyMouse.exe" "minimize"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKLM\..\Policies\Explorer\Run: [kernel32.dll] C:\WINDOWS\system32\
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\*****\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\*****\My Documents\Projexts\Background\time.html
–
End of file - 9039 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{502C3BA4-2C3E-4317-BC29-C0445E82B1F9}]
PaltalkWebLogin - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll [2006-01-27 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 853672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
ST - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll [2004-08-13 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
MSNToolBandBHO - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll [2006-01-17 282624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - xtramsn - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-nz\msntb.dll [2006-01-17 282624]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-10 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-10 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-10 455168]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"ATIPTA"=C:\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-08-05 344064]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-05-17 77824]
"CHotkey"=C:\APPS\Chicony\chicony.bat [2005-09-28 54]
"Logitech Utility"=C:\WINDOWS\Logi_MwX.Exe [2003-12-17 19968]
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe [2004-03-10 406016]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-03-21 155648]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"SSBkgdUpdate"=C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-10-25 210472]
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [2007-01-29 30248]
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [2007-01-29 46632]
"PPort11reminder"=C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [2007-02-01 255528]
"BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2007-03-12 663552]
"ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2007-01-26 65536]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-03-13 1443072]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-07-16 61440]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"kernel32.dll"=C:\WINDOWS\system32\ []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"JoyMouse"=C:\Program Files\JoyMouse\JoyMouse.exe minimize []
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2006-02-23 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\APPS\CyberLink\PowerDVD\PDVDServ.exe [2004-07-15 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe [2007-09-20 132624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2007-09-26 734264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-08-01 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 49152]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableCAD"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe"="C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\NetMeeting\conf.exe"="C:\Program Files\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\Valve\hl.exe"="C:\Program Files\Valve\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe"="C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe:*:Enabled:Media Player Classic"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\dCut\DCutService.exe"="C:\Program Files\dCut\DCutService.exe:*:Enabled:DCut Service"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\WINDOWS\system32\rtcshare.exe"="C:\WINDOWS\system32\rtcshare.exe:*:Enabled:RTC App Sharing"
"C:\Program Files\Morpheus\Morpheus.exe"="C:\Program Files\Morpheus\Morpheus.exe:*:Disabled:M5Shell"
"C:\Documents and Settings\*****\Desktop\bin\Contact.Launcher.exe"="C:\Documents and Settings\*****\Desktop\bin\Contact.Launcher.exe:*:Enabled:Contact.NET Launcher"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\Program Files\nanoCom Corporation\iSpQ VideoChat\iSpQVideoChat8.exe"="C:\Program Files\nanoCom Corporation\iSpQ VideoChat\iSpQVideoChat8.exe:*:Enabled:Video chat software for desktop computers."
"C:\Program Files\EA GAMES\Battlefield Vietnam\BfVietnam.exe"="C:\Program Files\EA GAMES\Battlefield Vietnam\BfVietnam.exe:*:Enabled:BfVietnam"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\xampp\apache\bin\apache.exe"="C:\Program Files\xampp\apache\bin\apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\xampp\mysql\bin\mysqld.exe"="C:\Program Files\xampp\mysql\bin\mysqld.exe:*:Enabled:mysqld"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Java\jdk1.6.0_01\jre\bin\java.exe"="C:\Program Files\Java\jdk1.6.0_01\jre\bin\java.exe:*:Enabled:Java™ Platform SE binary"
"C:\Program Files\Combined Community Codec Pack\MPC\mplayerc.exe"="C:\Program Files\Combined Community Codec Pack\MPC\mplayerc.exe:*:Enabled:Media Player Classic"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb9e2a52-a342-11da-98e3-0013d3bfa046}]
shell\AutoRun\command - E:\AUTORUN.EXE
======List of files/folders created in the last 1 months======
2008-09-29 14:47:12 —-D—- C:\Program Files\trend micro
2008-09-29 14:47:07 —-D—- C:\rsit
2008-09-29 12:53:17 —-D—- C:\Documents and Settings\*****\Application Data\Malwarebytes
2008-09-29 12:53:08 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-29 12:53:07 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-11 03:02:36 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-09-11 03:01:51 —-HDC—- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-05 16:41:34 —-D—- C:\Documents and Settings\*****\Application Data\SPORE
2008-09-05 16:41:16 —-RHD—- C:\Documents and Settings\*****\Application Data\SecuROM
2008-09-05 16:39:50 —-D—- C:\ProgramData
2008-09-05 16:28:44 —-D—- C:\Program Files\Electronic Arts
2008-09-05 04:00:55 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-09-03 21:58:08 —-D—- C:\WINDOWS\Prefetch
2008-09-03 21:45:42 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-09-03 21:45:33 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-09-03 21:45:24 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-09-03 21:45:16 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-09-03 21:45:09 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-09-03 21:44:59 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-09-03 21:44:51 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-09-03 21:44:43 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-09-03 21:44:33 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-09-03 21:39:29 —-A—- C:\WINDOWS\setuplog.txt
2008-09-03 21:37:50 —-D—- C:\WINDOWS\system32\scripting
2008-09-03 21:37:49 —-D—- C:\WINDOWS\l2schemas
2008-09-03 21:37:48 —-D—- C:\WINDOWS\system32\en
2008-09-03 21:37:48 —-D—- C:\WINDOWS\system32\bits
2008-09-03 21:34:25 —-D—- C:\WINDOWS\ServicePackFiles
2008-09-03 21:25:48 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-09-03 12:34:34 —-D—- C:\Documents and Settings\*****\Application Data\ATI
2008-09-03 12:34:34 —-D—- C:\Documents and Settings\All Users\Application Data\ATI
2008-09-03 12:27:09 —-HDC—- C:\WINDOWS\$NtUninstallKB952954_0$
2008-09-03 12:27:01 —-HDC—- C:\WINDOWS\$NtUninstallKB946648_0$
2008-09-03 12:26:53 —-HDC—- C:\WINDOWS\$NtUninstallKB953839$
2008-09-03 12:26:39 —-HDC—- C:\WINDOWS\$NtUninstallKB950974_0$
2008-09-03 12:23:11 —-HDC—- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-09-03 12:22:21 —-HDC—- C:\WINDOWS\$NtUninstallKB952287_0$
2008-09-03 12:21:09 —-HDC—- C:\WINDOWS\$NtUninstallKB951066_0$
2008-09-03 10:54:00 —-N—- C:\WINDOWS\system32\wmphoto.dll
2008-09-03 10:53:59 —-N—- C:\WINDOWS\system32\wlanapi.dll
2008-09-03 10:53:56 —-N—- C:\WINDOWS\system32\windowscodecsext.dll
2008-09-03 10:53:56 —-N—- C:\WINDOWS\system32\windowscodecs.dll
2008-09-03 10:53:46 —-N—- C:\WINDOWS\system32\tspkg.dll
2008-09-03 10:53:46 —-N—- C:\WINDOWS\system32\tsgqec.dll
2008-09-03 10:53:35 —-N—- C:\WINDOWS\system32\spupdwxp.exe
2008-09-03 10:53:33 —-A—- C:\WINDOWS\system32\spdwnwxp.exe
2008-09-03 10:53:32 —-N—- C:\WINDOWS\system32\slrundll.exe
2008-09-03 10:53:31 —-N—- C:\WINDOWS\system32\slcoinst.dll
2008-09-03 10:53:27 —-N—- C:\WINDOWS\system32\setupn.exe
2008-09-03 10:53:24 —-N—- C:\WINDOWS\system32\s3gnb.dll
2008-09-03 10:53:23 —-N—- C:\WINDOWS\system32\rhttpaa.dll
2008-09-03 10:53:21 —-N—- C:\WINDOWS\system32\rasqec.dll
2008-09-03 10:53:20 —-N—- C:\WINDOWS\system32\qutil.dll
2008-09-03 10:53:18 —-N—- C:\WINDOWS\system32\qcliprov.dll
2008-09-03 10:53:18 —-N—- C:\WINDOWS\system32\qagentrt.dll
2008-09-03 10:53:18 —-N—- C:\WINDOWS\system32\qagent.dll
2008-09-03 10:53:16 —-N—- C:\WINDOWS\system32\photometadatahandler.dll
2008-09-03 10:53:13 —-N—- C:\WINDOWS\system32\onex.dll
2008-09-03 10:53:09 —-N—- C:\WINDOWS\system32\nv4_disp.dll
2008-09-03 10:53:02 —-N—- C:\WINDOWS\system32\napstat.exe
2008-09-03 10:53:02 —-N—- C:\WINDOWS\system32\napmontr.dll
2008-09-03 10:53:02 —-N—- C:\WINDOWS\system32\napipsec.dll
2008-09-03 10:53:01 —-N—- C:\WINDOWS\system32\mtxparhd.dll
2008-09-03 10:52:57 —-N—- C:\WINDOWS\system32\msshavmsg.dll
2008-09-03 10:52:57 —-N—- C:\WINDOWS\system32\mssha.dll
2008-09-03 10:52:37 —-N—- C:\WINDOWS\system32\mmcperf.exe
2008-09-03 10:52:37 —-N—- C:\WINDOWS\system32\mmcfxcommon.dll
2008-09-03 10:52:37 —-N—- C:\WINDOWS\system32\mmcex.dll
2008-09-03 10:52:37 —-N—- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-09-03 10:52:34 —-N—- C:\WINDOWS\system32\mdmxsdk.dll
2008-09-03 10:52:18 —-N—- C:\WINDOWS\system32\l2gpstore.dll
2008-09-03 10:52:18 —-N—- C:\WINDOWS\system32\kmsvc.dll
2008-09-03 10:52:18 —-N—- C:\WINDOWS\system32\kbdpash.dll
2008-09-03 10:52:18 —-N—- C:\WINDOWS\system32\kbdnepr.dll
2008-09-03 10:52:17 —-N—- C:\WINDOWS\system32\kbdiultn.dll
2008-09-03 10:52:17 —-N—- C:\WINDOWS\system32\kbdbhc.dll
2008-09-03 10:52:06 —-N—- C:\WINDOWS\system32\smtpapi.dll
2008-09-03 10:52:06 —-N—- C:\WINDOWS\system32\rwnh.dll
2008-09-03 10:52:01 —-N—- C:\WINDOWS\system32\comsdupd.exe
2008-09-03 10:51:57 —-N—- C:\WINDOWS\system32\hsfcisp2.dll
2008-09-03 10:51:51 —-A—- C:\WINDOWS\003225_.tmp
2008-09-03 10:51:50 —-N—- C:\WINDOWS\system32\faxpatch.exe
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eapsvc.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eapqec.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eappprxy.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eapphost.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eappgnui.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eappcfg.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eapp3hst.dll
2008-09-03 10:51:49 —-N—- C:\WINDOWS\system32\eapolqec.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3ui.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3svc.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3msm.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3gpclnt.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3dlg.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3cfg.dll
2008-09-03 10:51:46 —-N—- C:\WINDOWS\system32\dot3api.dll
2008-09-03 10:51:45 —-N—- C:\WINDOWS\system32\dimsroam.dll
2008-09-03 10:51:45 —-N—- C:\WINDOWS\system32\dimsntfy.dll
2008-09-03 10:51:44 —-N—- C:\WINDOWS\system32\dhcpqec.dll
2008-09-03 10:51:42 —-N—- C:\WINDOWS\system32\credssp.dll
2008-09-03 10:51:37 —-N—- C:\WINDOWS\system32\bitsprx4.dll
2008-09-03 10:51:37 —-N—- C:\WINDOWS\system32\azroles.dll
2008-09-03 10:51:36 —-N—- C:\WINDOWS\system32\ativtmxx.dll
2008-09-03 10:51:35 —-N—- C:\WINDOWS\system32\ati3d1ag.dll
2008-09-03 10:51:35 —-N—- C:\WINDOWS\system32\ati2dvaa.dll
2008-09-03 10:51:33 —-N—- C:\WINDOWS\system32\aaclient.dll
2008-09-02 17:59:02 —-D—- C:\Program Files\ATI
2008-09-02 17:56:48 —-N—- C:\WINDOWS\system32\ati2sgag.exe
2008-09-02 17:56:06 —-D—- C:\Program Files\ATI Technologies
2008-09-02 17:55:12 —-D—- C:\ATI
======List of files/folders modified in the last 1 months======
2008-09-29 15:28:27 —-D—- C:\WINDOWS\Temp
2008-09-29 14:47:12 —-RD—- C:\Program Files
2008-09-29 14:18:44 —-D—- C:\Program Files\Mozilla Firefox
2008-09-29 14:15:12 —-A—- C:\WINDOWS\ModemLog_Smart Link 56K Modem.txt
2008-09-29 14:14:31 —-D—- C:\WINDOWS
2008-09-29 14:13:18 —-D—- C:\WINDOWS\Registration
2008-09-29 14:13:15 —-D—- C:\WINDOWS\system32\CatRoot2
2008-09-29 14:11:16 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-09-29 12:54:24 —-D—- C:\Program Files\Metal Gear Solid
2008-09-29 12:53:11 —-D—- C:\WINDOWS\system32\drivers
2008-09-29 12:11:39 —-D—- C:\WINDOWS\system32
2008-09-29 12:11:38 —-AC—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-09-28 15:09:47 —-D—- C:\Documents and Settings\*****\Application Data\Simple Sudoku
2008-09-27 16:19:51 —-A—- C:\WINDOWS\DVDRegionFree.INI
2008-09-14 16:28:27 —-SD—- C:\WINDOWS\Tasks
2008-09-14 16:27:10 —-A—- C:\WINDOWS\BRWMARK.INI
2008-09-11 03:03:56 —-SHD—- C:\WINDOWS\Installer
2008-09-11 03:02:38 —-SHD—- C:\WINDOWS\system32\ShellDHCP
2008-09-11 03:02:38 —-HD—- C:\WINDOWS\inf
2008-09-11 03:02:36 —-D—- C:\WINDOWS\WinSxS
2008-09-11 03:02:02 —-A—- C:\WINDOWS\imsins.BAK
2008-09-09 21:40:10 —-D—- C:\WINDOWS\Minidump
2008-09-07 16:52:54 —-HD—- C:\Program Files\InstallShield Installation Information
2008-09-05 16:41:15 —-A—- C:\WINDOWS\system32\CmdLineExt.dll
2008-09-05 04:00:59 —-RSHD—- C:\WINDOWS\system32\dllcache
2008-09-04 16:34:15 —-HD—- C:\WINDOWS\$hf_mig$
2008-09-03 23:18:05 —-AC—- C:\WINDOWS\OEWABLog.txt
2008-09-03 21:57:24 —-D—- C:\WINDOWS\system32\Setup
2008-09-03 21:57:24 —-D—- C:\WINDOWS\ime
2008-09-03 21:57:24 —-D—- C:\WINDOWS\AppPatch
2008-09-03 21:57:23 —-D—- C:\WINDOWS\system32\wbem
2008-09-03 21:57:22 —-RSD—- C:\WINDOWS\Fonts
2008-09-03 21:56:26 —-D—- C:\WINDOWS\security
2008-09-03 21:45:43 —-D—- C:\WINDOWS\system32\CatRoot
2008-09-03 21:44:35 —-D—- C:\Program Files\Messenger
2008-09-03 21:42:43 —-RSD—- C:\WINDOWS\assembly
2008-09-03 21:38:06 —-D—- C:\WINDOWS\system32\inetsrv
2008-09-03 21:38:06 —-D—- C:\WINDOWS\network diagnostic
2008-09-03 21:38:06 —-D—- C:\WINDOWS\Help
2008-09-03 21:37:51 —-D—- C:\WINDOWS\system32\usmt
2008-09-03 21:37:51 —-D—- C:\WINDOWS\system32\en-US
2008-09-03 21:37:48 —-D—- C:\WINDOWS\PeerNet
2008-09-03 21:37:47 —-D—- C:\Program Files\Movie Maker
2008-09-03 21:34:08 —-D—- C:\WINDOWS\system32\Restore
2008-09-03 21:34:07 —-D—- C:\WINDOWS\system32\npp
2008-09-03 21:34:07 —-D—- C:\WINDOWS\mui
2008-09-03 21:34:05 —-D—- C:\WINDOWS\msagent
2008-09-03 21:34:04 —-D—- C:\WINDOWS\srchasst
2008-09-03 21:34:01 —-D—- C:\Program Files\NetMeeting
2008-09-03 21:33:59 —-D—- C:\WINDOWS\system32\Com
2008-09-03 21:33:56 —-D—- C:\Program Files\Windows NT
2008-09-03 21:33:56 —-D—- C:\Program Files\Outlook Express
2008-09-03 21:33:53 —-D—- C:\Program Files\Common Files\System
2008-09-03 21:33:31 —-D—- C:\WINDOWS\system32\oobe
2008-09-03 21:33:27 —-D—- C:\WINDOWS\system
2008-09-03 21:29:26 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-09-03 21:25:44 —-D—- C:\WINDOWS\ehome
2008-09-03 12:34:40 —-D—- C:\WINDOWS\system32\config
2008-09-03 12:22:06 —-D—- C:\Program Files\Internet Explorer
2008-09-03 12:18:45 —-A—- C:\WINDOWS\win.ini
2008-09-03 03:34:51 —-D—- C:\WINDOWS\Debug
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-13 40456]
R2 RTWTKRNL;Real-Time Windows Target; \??\C:\WINDOWS\system32\drivers\RTWTKRNL.sys []
R2 WFPVRENC;WinFast PVR2000 MPEG Encoder(PAL); C:\WINDOWS\system32\drivers\wfpvrenc.sys [2005-05-12 298496]
R2 WFPVRTUNER;WinFast PVR2000 WDM Tuner; C:\WINDOWS\system32\drivers\wfpvrtun.sys [2005-05-12 32640]
R2 WFPVRVIDEO;WinFast PVR2000 WDM Video Capture; C:\WINDOWS\system32\drivers\wfpvrcap.sys [2005-05-12 163968]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-05-18 2319680]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2004-03-10 11264]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-08-01 3266560]
R3 BrScnUsb;Brother USB Still Image driver; C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 15295]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2005-02-02 14408]
R3 HidIr;Microsoft Infrared HID Driver; C:\WINDOWS\system32\DRIVERS\hidir.sys [2008-04-14 19200]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IrBus;Infrared bus filter driver for eHome remote controls; C:\WINDOWS\system32\DRIVERS\IrBus.sys [2008-04-14 46592]
R3 LHidFlt2;Logitech HID/USB Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFlt2.Sys [2003-12-17 25505]
R3 LHidUsb;Logitech USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsb.Sys [2003-12-17 37887]
R3 LMouFlt2;Logitech Mouse Class Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFlt2.Sys [2003-12-17 70801]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 Mtlmnt5;Mtlmnt5; C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys [2004-08-03 126686]
R3 Mtlstrm;Mtlstrm; C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys [2004-08-03 1309184]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-12-02 70912]
R3 Slntamr;SmartLink AMR_PCI Driver; C:\WINDOWS\system32\DRIVERS\slntamr.sys [2004-08-03 404990]
R3 SlNtHal;SlNtHal; C:\WINDOWS\system32\DRIVERS\Slnthal.sys [2004-08-03 95424]
R3 SlWdmSup;SlWdmSup; C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys [2003-07-02 39348]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 WFPVRBAR;WinFast PVR2000 WDM Crossbar; C:\WINDOWS\system32\drivers\WFPVRBAR.sys [2005-05-12 9600]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 10144]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 22240]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 45504]
S1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 gUSBSTOi;gUSBSTOi; \??\C:\DOCUME~1\*****\LOCALS~1\Temp\gUSBSTOi.sys []
S3 HVWINDR.SYS;HVWINDR.SYS; \??\C:\Documents and Settings\*****\Desktop\Sky Crack\hardwired10064\HVWINDR.SYS []
S3 HWIONT;HWIONT; \??\C:\Documents and Settings\\Desktop\Sky Crack\hVCP100\HWIONT.sys []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NPF;WinPcap Packet Driver (NPF); C:\WINDOWS\system32\drivers\NPF.sys []
S3 NtMtlFax;NtMtlFax; C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys [2004-08-03 180360]
S3 RecAgent;recagent; \??\C:\WINDOWS\system32\DRIVERS\RecAgent.sys []
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS\system32\drivers\screamingbdriver.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 5600]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-08-01 573440]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 SLService;SmartLinkService; C:\WINDOWS\system32\slserv.exe [2008-04-14 73796]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2006-07-11 126976]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-07-31 593920]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2006-05-10 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-03-13 19200]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPodService;iPodService; C:\Program Files\iPod\bin\iPodService.exe [2006-02-23 323584]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
—————–EOF—————–
info.txt logfile of random's system information tool 1.02 2008-09-29 15:28:46
======Uninstall list======
–>MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
–>C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
–>C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x9
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7-Zip 4.32–>"C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware SE Personal–>C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Bridge 1.0–>MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}
Adobe Common File Installer–>MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 9 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Help Center 1.0–>MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2–>msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader 7.1.0–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe Stock Photos 1.0–>MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x575c
ATI Control Panel–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Auto Gordian Knot 2.40–>C:\Program Files\AutoGK\uninst.exe
AviSynth 2.5–>"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Battlefield 1942–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}\setup.exe" -l0x9
Battlefield 2™–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}\setup.exe" -l0x9 -removeonly
Battlefield Vietnam™–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E35B3C63-E958-4E31-A178-95D22024109A}\setup.exe" -l0x9
BeeThink MusicHandle 3.0–>"C:\Program Files\BeeThink MusicHandle 3.0\unins000.exe"
Bink and Smacker–>C:\PROGRA~1\RADVideo\UNWISE.EXE C:\PROGRA~1\RADVideo\INSTALL.LOG
BitTorrent 5.0.9–>"C:\Program Files\BitTorrent\uninstall.exe"
BlueJ 2.2.0–>"C:\BlueJ\uninst\unins000.exe"
Brother MFL-Pro Suite–>"C:\Program Files\InstallShield Installation Information\{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}\Setup.exe" -runfromtemp -l0x0009 Brunin03.dll -removeonly
Catalyst Control Center - Branding–>MsiExec.exe /I{FA3A247D-437A-455E-A88F-7EB6E5F9E799}
Combined Community Codec Pack 2007-07-22–>"C:\Program Files\Combined Community Codec Pack\unins000.exe"
ControlMK 0.232–>C:\Program Files\ControlMK\uninst.exe
DivX Content Uploader–>C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Web Player–>C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DVD Decrypter (Remove Only)–>"C:\Program Files\DVD Decrypter\uninstall.exe"
DVD Region+CSS Free 5.9.7.2–>"C:\Program Files\DVD Region+CSS Free\unins000.exe"
DVD Shrink 3.2–>"C:\Program Files\DVD Shrink\unins000.exe"
EA Download Manager–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
Endless Online 0.25 pre–>C:\Program Files\EndlessOnline\Uninstall.exe
EndNote X Volume License Edition–>MsiExec.exe /I{FE4BD9BD-4A26-4F39-B12C-19336204B102}
ESET NOD32 Antivirus–>MsiExec.exe /I{86A6E235-C08F-4A14-B14C-793C7D8844A0}
Flash Decompiler–>"C:\Program Files\Eltima Software\Flash Decompiler\unins000.exe"
Google Talk (remove only)–>"C:\Program Files\Google\Google Talk\uninstall.exe"
Google Video Player–>"C:\Program Files\Google\Google Video Player\Uninstall.exe"
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)–>"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)–>"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
ISI ResearchSoft - Export Helper–>C:\PROGRA~1\COMMON~1\Risxtd\_UNINST.EXE
ISIS Draw 2.3 Standalone–>C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ISIS Draw 2.3\uninst.isu"
iTunes–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{59C4F14F-7590-45FC-BE9F-A67AB3590709} /l1033
J2SE Runtime Environment 5.0 Update 10–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
J2SE Runtime Environment 5.0 Update 11–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
J2SE Runtime Environment 5.0 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
J2SE Runtime Environment 5.0 Update 9–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150090}
Java 2 Runtime Environment, SE v1.4.2_05–>MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050}
Java™ 6 Update 2–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java™ SE Development Kit 6 Update 1–>MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160010}
Java™ SE Runtime Environment 6 Update 1–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Jitbit Macro Recorder–>MsiExec.exe /I{2D57FB4E-6277-4A6D-8739-304C38051B89}
Lame ACM MP3 Codec–>"C:\WINDOWS\IFinst26.exe" -UC:\Program Files\Lame MP3 Codec\IFU17.inf
Logitech Gaming Software–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C1DA723-24FC-48AD-93BA-925695C3EF26}\setup.exe" -l0x9 -removeonly
Macromedia Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marsu-Fix–>C:\WINDOWS\Marsu-Fix Uninstaller.exe
Metal Gear Solid–>"C:\Program Files\Metal Gear Solid\UNINSTAL.EXE" /runtemp /addremove
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Document Explorer 2005–>C:\Program Files\Common Files\Microsoft Shared\Help 8\Microsoft Document Explorer 2005\install.exe
Microsoft Document Explorer 2005–>MsiExec.exe /X{44D4AF75-6870-41F5-9181-662EA05507E1}
Microsoft Encarta Encyclopedia Standard 2005–>MsiExec.exe /I{05410044-64A6-4248-A026-9745C1E9E159}
Microsoft GIF Animator–>C:\Program Files\Microsoft GIF Animator\setup\GifACME.exe
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual J# 2.0 Redistributable Package–>C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft Visual J# 2.0 Redistributable Package\install.exe
Microsoft Visual Studio 2005 Academic Edition - ENU–>C:\Program Files\Microsoft Visual Studio 8\Microsoft Visual Studio 2005 Standard Edition - ENU\setup.exe
Microsoft Visual Studio 2005 Standard Edition - ENU–>MsiExec.exe /X{D407F7C0-579E-4CCB-91FD-855CE5084E86}
Microsoft Works–>MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Microsoft Xbox 360 Accessories 1.1–>MsiExec.exe /X{66F0AC35-4805-44BC-A3D4-347D4196F9B3}
Morrowind–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\MWUninstall\Setup.exe" -l0x9
Mozilla Firefox (3.0.3)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mp3 File Editor 5.11 (standard)–>C:\WINDOWS\iun506.exe C:\Program Files\Mp3 File Editor\irunin_mp3fe.ini
MSDN Library for Visual Studio 2005–>msiexec /i {23959E96-A80F-4172-A655-210E9BB7BFBE}
MSDN Library for Visual Studio 2005–>MsiExec.exe /X{23959E96-A80F-4172-A655-210E9BB7BFBE}
MSN–>C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSXML 4.0 SP2 (KB927978)–>MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)–>MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Multimedia Keyboard Driver Ver1.0 (KB-0108)–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF262740-C85A-11D5-BBEC-00D0B740900A}\Setup.exe"
Oblivion - Construction Set–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{23D683DD-93C6-48E6-B84E-78B57778F126}\setup.exe" -l0x9 -removeonly
Oblivion–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35CB6715-41F8-4F99-8881-6FC75BF054B0}\setup.exe" -l0x9 -removeonly
PaperPort Image Printer–>MsiExec.exe /X{332CC6BF-E6C7-48EE-BA3D-435E576AD67F}
Pinnacle Hollywood FX–>C:\WINDOWS\unvise32.exe C:\Program Files\Pinnacle\Hollywood FX for Studio\5.5\uninstal.log
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\SETUP.EXE" -uninstall
Project64 1.6–>MsiExec.exe /X{9559F7CA-5E34-4237-A2D9-D856464AD727}
PunkBuster for Battlefield Vietnam–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D07643A3-CE41-4286-8C78-EB9C83E76DDB}\setup.exe" -l0x9
QuickTime–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{929408E6-D265-4174-805F-81D1D914E2A4} /l1033
Real Alternative 1.8.0–>"C:\Program Files\Real Alternative\unins000.exe"
Realtek AC'97 Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe" -l0x9 REMOVE -removeonly
Real-Time Windows Target–>%windir%\rtwintgt -uninstall
Samsung Media Studio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\Setup.exe" -l0x9
ScanSoft PaperPort 11–>MsiExec.exe /I{B6C89654-A6A2-477C-873B-724EC1C56407}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Visual Studio 2005 Standard Edition - ENU (KB925674)–>C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {124D38C7-5BE5-4D4E-8D6D-9F10DC6B6D11} /package {D407F7C0-579E-4CCB-91FD-855CE5084E86}
Security Update for Step By Step Interactive Training (KB898458)–>"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)–>"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)–>"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)–>"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)–>"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)–>"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)–>"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)–>"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)–>"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)–>"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)–>"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Shockwave–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Simple Sudoku 4.1–>"C:\Program Files\Simple Sudoku\unins000.exe"
Smart Link 56K Modem–>C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove
SmartSound Quicktracks Plugin–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Sonic MyDVD LE–>MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow!–>MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
SPORE™–>"C:\Program Files\InstallShield Installation Information\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}\setup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy 1.4–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Studio 9.4 Patch–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16E217EA-C3E0-402D-8D4F-6189DB74497A}\setup.exe" -l0x9 UNINSTALL
Studio 9–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E491AB7-4589-48CA-9CBB-874CB2788391}\setup.exe" -l0x9 UNINSTALL
SUPER © Version 2007.bld.21 (Jan 4, 2007)–>C:\PROGRA~1\ERIGHT~1\SUPER\Setup.exe /remove /q0
TallStick TS-AudioToMIDI 3.20 (remove only)–>"C:\Program Files\TallStick\TS-AudioToMIDI 3.20\Uninstall.exe"
TeamSpeak 2 RC2–>"C:\Program Files\Teamspeak2_RC2\unins000.exe"
TES Construction Set–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\CSUninstall\Setup.exe" -l0x9
Ulead PhotoImpact XL SE–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CADA6C4C-3EF2-43FC-8E5B-E89E3880A399}\setup.exe" -l0x9
Update for Windows Media Player 10 (KB910393)–>"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB913800)–>"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
Update for Windows Media Player 10 (KB926251)–>"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005–>C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
VobSub v2.23 (Remove Only)–>"C:\Program Files\Gabest\VobSub\uninstall.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin–>MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Media Center Edition 2005 KB925766–>"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
World of Warcraft FREE Trial–>MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2}
XAMPP 1.5.5–>"C:\Program Files\xampp\uninstall.exe"
xtramsn Toolbar–>C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-nz\mtbs.exe c
XviD MPEG4 Video Codec (remove only)–>"C:\WINDOWS\system32\xvid-uninstall.exe"
XviD MPEG-4 Video Codec–>"C:\Program Files\XviD\unins000.exe"
======Hosts File======
127.0.0.1 support.alcohol-soft.com
127.0.0.1 serial.alcohol-soft.com
AmsServer
======Security center information======
AV: ESET NOD32 Antivirus 3.0
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Adobe\AGL;;C:\Program Files\Common Files\MDL Shared\ISIS;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"VS80COMNTOOLS"=C:\Program Files\Microsoft Visual Studio 8\Common7\Tools\
"CLASSPATH"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.5.0_06\lib\ext\QTJava.zip
—————–EOF—————–