Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-10-16 07:44:04
Microsoft Windows XP Professional Service Pack 2
System drive C: has 65 GB (85%) free of 76 GB
Total RAM: 2046 MB (67% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:44:15, on 2008-10-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Lotus\Notes\nslsvice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
C:\WINDOWS\system32\SgLogPlayer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Lotus\Notes\NLNOTES.EXE
C:\Program Files\Lotus\Notes\ntaskldr.EXE
C:\Program Files\AR System\aruser.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\totalcmd\TOTALCMD.EXE
c:\Download\RSIT.exe
C:\Program Files\trend micro\a683791.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://inside.ispartner.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://inside.ispartner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://inside.ispartner.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://inside.ispartner.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://proxycf.net.ispartner.com/pac
O2 - BHO: {40a906b8-ac8e-4b49-a3f4-414372c751a7} - {7a157c27-3414-4f3a-94b4-e8ca8b609a04} - C:\WINDOWS\system32\wnjnhq.dll
O2 - BHO: (no name) - {81236011-4154-4E9F-BE9A-A07B2DDCBB9B} - C:\WINDOWS\system32\awturSJa.dll
O2 - BHO: (no name) - {EC22E79C-7702-4C38-9691-C139D6C359C9} - C:\WINDOWS\system32\pmnoPgfc.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PSUtility] C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
O4 - HKLM\..\Run: [TvOutSwitch] C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe
O4 - HKLM\..\Run: [LoadFUJ02E3] C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [RunOSSettings] C:\Program Files\Hydro\Image\2ndRegSett.vbs
O4 - HKLM\..\Run: [BinD Manager] C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe
O4 - HKLM\..\Run: [BinD Maintenance Run Scripts] C:\WINDOWS\system32\wscript.exe "C:\PROGRA~1\Hydro\BinD\B_RunHook.vbs"
O4 - HKLM\..\Run: [BinD Scheduler] "C:\PROGRA~1\Hydro\BinD\B_Sched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SgeEcView] "C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe"
O4 - HKLM\..\Run: [EdWizard] "C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe" as
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [FFAKNNVF] %systemroot%\FFAKNNVF.exe
O4 - HKLM\..\Run: [bivfffcz] %systemroot%\bivfffcz.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [b4472bb5] rundll32.exe "C:\WINDOWS\system32\qhhkjwam.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd…b?1189737859843
O16 - DPF: {759FD3DE-F0EF-4A76-909C-88CF840D4173} (DmDragDrop Class) -
https://webtop.hda.hydro.com/webtop/wdk/nat…dkPluginCab.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) -
https://isadmin.hydroispartner.com/dana-cac…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\Software\..\Telephony: DomainName = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = adi.ispartner.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = adi.ispartner.com,ispartner.com,hydro.com,nh.ad.hydro.com
O20 - AppInit_DLLs: wnjnhq.dll
O20 - Winlogon Notify: FJWSEL - C:\WINDOWS\SYSTEM32\FJWSWNP.dll
O20 - Winlogon Notify: NotLog - C:\WINDOWS\SYSTEM32\SGLogEx.dll
O20 - Winlogon Notify: pmnoPgfc - C:\WINDOWS\SYSTEM32\pmnoPgfc.dll
O20 - Winlogon Notify: PSUTY - C:\WINDOWS\SYSTEM32\PSUWNP.dll
O20 - Winlogon Notify: SGLogNotification - C:\WINDOWS\SYSTEM32\SGLogNotification.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\Program Files\Lotus\Notes\nslsvice.exe
O23 - Service: O2Micro Flash Memory (O2Flash) - O2Micro International - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINDOWS\system32\SgLogPlayer.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: SafeGuard Easy Workstation Server (WksCfgSrv) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
–
End of file - 13036 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7a157c27-3414-4f3a-94b4-e8ca8b609a04}]
C:\WINDOWS\system32\wnjnhq.dll [2008-10-15 109056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{81236011-4154-4E9F-BE9A-A07B2DDCBB9B}]
C:\WINDOWS\system32\awturSJa.dll [2008-10-15 267776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EC22E79C-7702-4C38-9691-C139D6C359C9}]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-02-16 161352]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google; - c:\program files\google\googletoolbar2.dll [2008-08-31 2403392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-03-12 16125440]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2007-03-12 69632]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2006-06-29 89541]
"IndicatorUtility"=C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe [2006-04-20 90112]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-07-12 794713]
"PSUtility"=C:\Program Files\Fujitsu\PSUtility\TrayManager.exe [2007-07-12 118784]
"TvOutSwitch"=C:\Program Files\Fujitsu\DispSwitch\DispSwitchLauncher.exe [2007-07-12 81920]
"LoadFUJ02E3"=C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe [2006-11-18 80688]
"LoadFujitsuQuickTouch"=C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe [2005-11-02 353792]
"LoadBtnHnd"=C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe [2005-11-02 61440]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2006-01-03 45056]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-13 155648]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2008-02-15 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2008-02-15 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2008-02-15 131072]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
"RunOSSettings"=C:\Program Files\Hydro\Image\2ndRegSett.vbs [2006-08-10 1907]
"BinD Manager"=C:\Program Files\Hydro\BinD\B_Manager\B_Manager.exe [2007-03-19 20480]
"BinD Maintenance Run Scripts"=C:\WINDOWS\system32\wscript.exe [2004-08-04 114688]
"BinD Scheduler"=C:\PROGRA~1\Hydro\BinD\B_Sched.exe [2002-12-02 650752]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"SgeEcView"=C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe [2007-09-05 24576]
"EdWizard"=C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe [2007-09-05 245760]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2006-11-22 52840]
"vptray"=C:\PROGRA~1\SYMANT~2\SYMANT~1\VPTray.exe [2006-12-20 125632]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"FFAKNNVF"=C:\WINDOWS\FFAKNNVF.exe []
"bivfffcz"=C:\WINDOWS\bivfffcz.exe []
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"b4472bb5"=C:\WINDOWS\system32\qhhkjwam.dll [2008-10-15 71168]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-08-11 1124352]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe [2008-06-17 1249280]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-01 39408]
"Google Update"=C:\Documents and Settings\a683791\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 133104]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Documents and Settings\a683791\Start Menu\Programs\Startup
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wnjnhq.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-08-10 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\FJWSEL]
C:\WINDOWS\system32\FJWSWNP.dll [2007-07-12 32768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-15 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINDOWS\system32\NavLogon.dll [2006-12-20 43712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NotLog]
C:\WINDOWS\system32\SGLogEx.dll [2002-01-22 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnoPgfc]
C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PSUTY]
C:\WINDOWS\system32\PSUWNP.dll [2007-07-12 32768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SGLogNotification]
C:\WINDOWS\system32\SGLogNotification.dll [2005-03-31 69632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-19 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0574D50F-C261-490D-BF39-4E91183C4EFB}"= []
"{EC22E79C-7702-4C38-9691-C139D6C359C9}"=C:\WINDOWS\system32\pmnoPgfc.dll [2008-10-14 37376]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\awturSJa
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0
"DisableTaskMgr"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"disablecad"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe"="C:\Program Files\Hydro\Image\GetSiteInfo\B_GetSiteInfo.exe:*:Enabled:B_GetSiteInfo Configuration Setting Utility"
"C:\Program Files\Hydro\Image\ntpdate.exe"="C:\Program Files\Hydro\Image\ntpdate.exe:*:Enabled:ntpdate"
"C:\Program Files\InterVideo\DVD7\WinDVD.exe"="C:\Program Files\InterVideo\DVD7\WinDVD.exe:*:Enabled:WinDVD"
"C:\Program Files\InterVideo\DVD8\WinDVD.exe"="C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======File associations======
.bat - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.cmd - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.inf - open - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.ini - open - notepad.exe %1
.reg - edit - "C:\Program Files\UltraEdit\uedit32.exe" "%1"
.txt - open - notepad.exe %1
======List of files/folders created in the last 1 months======
2008-10-16 07:44:05 —-D—- C:\Program Files\trend micro
2008-10-16 07:44:04 —-D—- C:\rsit
2008-10-15 22:17:37 —-D—- C:\_OTMoveIt
2008-10-15 21:57:37 —-A—- C:\WINDOWS\system32\wnjnhq.dll
2008-10-15 21:57:36 —-A—- C:\WINDOWS\system32\xaoawvju.dll
2008-10-15 21:55:19 —-SH—- C:\WINDOWS\system32\mawjkhhq.ini
2008-10-15 21:55:16 —-A—- C:\WINDOWS\system32\qhhkjwam.dll
2008-10-15 21:54:36 —-ASH—- C:\WINDOWS\system32\aJSrutwa.ini2
2008-10-15 21:54:36 —-ASH—- C:\WINDOWS\system32\aJSrutwa.ini
2008-10-15 21:54:32 —-A—- C:\WINDOWS\system32\awturSJa.dll
2008-10-15 21:21:55 —-A—- C:\lopR.txt
2008-10-15 21:21:12 —-D—- C:\Lop SD
2008-10-15 17:46:22 —-A—- C:\WINDOWS\system32\akchgl.dll
2008-10-15 17:46:21 —-A—- C:\WINDOWS\system32\gojcxhkj.dll
2008-10-15 14:07:19 —-D—- C:\Program Files\Hijackthis
2008-10-15 07:34:43 —-A—- C:\WINDOWS\system32\tpaylrvh.dll
2008-10-15 07:34:43 —-A—- C:\WINDOWS\system32\oegrjj.dll
2008-10-14 20:50:06 —-D—- C:\Program Files\Lavasoft
2008-10-14 20:50:06 —-D—- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-14 20:18:30 —-A—- C:\WINDOWS\system32\hdkxtc.dll
2008-10-14 20:18:29 —-A—- C:\WINDOWS\system32\lclcvsrq.dll
2008-10-14 12:43:12 —-ASH—- C:\WINDOWS\system32\thfwryvd.ini
2008-10-14 12:40:48 —-A—- C:\WINDOWS\system32\pvemwg.dll
2008-10-14 12:40:48 —-A—- C:\WINDOWS\system32\bgalxkua.dll
2008-10-14 11:53:23 —-D—- C:\WINDOWS\system32\%APPDATA%
2008-10-14 11:25:03 —-A—- C:\WINDOWS\system32\myumtr.dll
2008-10-14 11:25:02 —-A—- C:\WINDOWS\system32\lugfjvhk.dll
2008-10-14 09:37:23 —-A—- C:\WINDOWS\system32\hbbvzh.dll
2008-10-14 09:37:22 —-A—- C:\WINDOWS\system32\xrggvrtq.dll
2008-10-14 09:30:07 —-D—- C:\Documents and Settings\a683791\Application Data\Malwarebytes
2008-10-14 08:31:17 —-D—- C:\Program Files\Windows Defender
2008-10-14 08:31:08 —-A—- C:\WINDOWS\system32\zabhqd.dll
2008-10-14 08:31:07 —-A—- C:\WINDOWS\system32\ghmkgxfx.dll
2008-10-14 08:30:40 —-A—- C:\WINDOWS\system32\bf64efcb-.txt
2008-10-14 08:26:22 —-A—- C:\WINDOWS\system32\wini104552664.exe
2008-10-14 08:21:09 —-D—- C:\Documents and Settings\All Users\Application Data\fkpshuri
2008-10-14 08:20:44 —-A—- C:\WINDOWS\system32\pmnoPgfc.dll
2008-10-14 08:20:44 —-A—- C:\WINDOWS\system32\khfFUMGv.dll
2008-10-13 10:47:36 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-13 10:47:36 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-13 10:46:43 —-D—- C:\WINDOWS\ERDNT
2008-10-13 10:46:24 —-D—- C:\Program Files\ERUNT
2008-10-13 10:07:55 —-A—- C:\WINDOWS\VPC32.INI
2008-10-10 21:34:34 —-A—- C:\WINDOWS\ntbtlog.txt
2008-10-10 21:28:35 —-D—- C:\WINDOWS\Minidump
2008-10-10 21:21:07 —-A—- C:\WINDOWS\system32\isiefwfo.tmp
2008-10-10 21:20:35 —-A—- C:\WINDOWS\system32\4jQhIhF4.exe
2008-09-29 16:48:33 —-D—- C:\Documents and Settings\a683791\Application Data\InterVideo
2008-09-25 09:07:04 —-D—- C:\lotus
2008-09-23 07:30:38 —-HDC—- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-09-23 07:30:26 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
======List of files/folders modified in the last 1 months======
2008-10-16 07:44:05 —-RD—- C:\Program Files
2008-10-16 07:43:07 —-A—- C:\WINDOWS\wincmd.ini
2008-10-16 07:42:51 —-D—- C:\Download
2008-10-16 07:35:42 —-D—- C:\WINDOWS\Temp
2008-10-16 07:18:36 —-SD—- C:\WINDOWS\Tasks
2008-10-16 07:15:53 —-D—- C:\WINDOWS\security
2008-10-16 07:15:40 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-10-15 22:30:57 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-10-15 21:57:38 —-D—- C:\WINDOWS\Prefetch
2008-10-15 21:57:37 —-D—- C:\WINDOWS\system32
2008-10-15 21:52:01 —-A—- C:\BinD.mif.txt
2008-10-15 21:51:25 —-D—- C:\WINDOWS
2008-10-15 21:51:18 —-A—- C:\WINDOWS\Bridge.ini
2008-10-15 21:50:50 —-D—- C:\WINDOWS\system32\CatRoot2
2008-10-15 21:48:00 —-D—- C:\WINDOWS\system32\drivers
2008-10-15 17:47:31 —-D—- C:\Program Files\Clue
2008-10-15 17:41:03 —-A—- C:\BinD.mif.bak
2008-10-15 14:56:21 —-A—- C:\WINDOWS\Notes.ini
2008-10-15 13:45:02 —-D—- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-14 20:50:49 —-SHD—- C:\WINDOWS\Installer
2008-10-14 20:49:25 —-D—- C:\Program Files\Common Files
2008-10-14 16:05:59 —-D—- C:\Program Files\2321_Remote Access
2008-10-14 12:36:51 —-SHD—- C:\System Volume Information
2008-10-14 12:36:51 —-D—- C:\WINDOWS\system32\Restore
2008-10-14 09:11:17 —-D—- C:\Documents and Settings\a683791\Application Data\Adobe
2008-10-14 08:31:18 —-HD—- C:\WINDOWS\inf
2008-10-14 08:31:17 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-10-14 08:21:09 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-10-13 09:00:02 —-D—- C:\Tmp
2008-10-13 08:58:15 —-SHD—- C:\RECYCLER
2008-10-10 21:21:58 —-D—- C:\Privat
2008-10-10 13:31:42 —-A—- C:\WINDOWS\Uedit32.ini
2008-09-30 09:40:04 —-D—- C:\SOL
2008-09-29 17:03:10 —-D—- C:\MyDocs
2008-09-23 07:30:31 —-A—- C:\WINDOWS\imsins.BAK
2008-09-23 07:30:26 —-D—- C:\WINDOWS\WinSxS
2008-09-23 07:30:25 —-HD—- C:\WINDOWS\$hf_mig$
2008-09-23 07:29:36 —-D—- C:\WINDOWS\system32\CatRoot
2008-09-19 12:11:14 —-D—- C:\Program Files\Citrix
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-08-31 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys []
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2006-08-07 195776]
R1 Tosrfcom;Bluetooth RFCOMM; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-02 64896]
R2 BtnHnd;BtnHnd; \??\C:\Program Files\Fujitsu\BtnHnd\BtnHnd.sys []
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2006-11-29 1161888]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-08-10 1578496]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 Eacfilt;Eacfilt Miniport; C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2004-01-26 9817]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys []
R3 FUJ02B1;Fujitsu FUJ02B1 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02B1.sys [2001-08-01 5248]
R3 FUJ02E1;%FUJ02E1.DeviceDesc%; C:\WINDOWS\System32\Drivers\FUJ02E1.sys [2004-10-18 5632]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver; C:\WINDOWS\system32\DRIVERS\FUJ02E3.sys [2004-01-17 4864]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-08 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-12 4486144]
R3 IPSECSHM;Nortel IPSECSHM Adapter; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081015.003\navex15.sys []
R3 NETw4x32;Intel® Wireless WiFi Link Adapter Driver for Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw4x32.sys [2008-03-18 2236032]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-08-17 35913]
R3 SymEvent;SymEvent; \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS []
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-07-12 193120]
R3 tosporte;Bluetooth COM Port; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2006-10-11 41600]
R3 Tosrfbd;Bluetooth RFBUS; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2007-04-24 113920]
R3 Tosrfhid;Bluetooth RFHID; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2007-03-02 73728]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2007-06-11 41856]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-10-23 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-10-23 59264]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2006-10-23 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-03-18 286336]
S2 IPSECEXT;Nortel Extranet Access Protocol; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2004-01-26 117696]
S3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-15 5854752]
S3 OZSCR;O2Micro SmartCardBus Smartcard Reader; C:\WINDOWS\system32\DRIVERS\ozscr.sys [2006-12-08 92552]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
S3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2006-08-07 12992]
S3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2006-08-07 110784]
S3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2006-08-07 31936]
S3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20081010.002\symidsco.sys []
S3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2006-08-07 28352]
S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2006-08-07 24768]
S3 tosrfbnp;Bluetooth RFBNEP; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2006-11-21 36480]
S3 tosrfnds;Bluetooth Personal Area Network; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio; C:\WINDOWS\system32\drivers\tosrfsnd.sys [2007-01-22 53376]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\C:\WINDOWS\system32\DRIVERS\sr.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\WINDOWS\system32\agrsmsvc.exe [2006-10-06 9216]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-08-10 409600]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2006-11-22 192104]
R2 ccProxy;Symantec Network Proxy; C:\Program Files\Common Files\Symantec Shared\ccProxy.exe [2006-11-22 202344]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2006-11-22 169576]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe [2006-12-20 31424]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-01 137200]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 ISSVC;IS Service; C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe [2006-12-14 87680]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-05 112152]
R2 Lotus Notes Single Logon;Lotus Notes Single Logon; C:\Program Files\Lotus\Notes\nslsvice.exe [2007-09-27 8192]
R2 O2Flash;O2Micro Flash Memory; C:\WINDOWS\system32\o2flash.exe [2005-09-13 57344]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 radexecd;Radia Notify Daemon; C:\Program Files\Novadigm\radexecd.exe [2005-05-04 217268]
R2 radsched;Radia Scheduler Daemon; C:\Program Files\Novadigm\radsched.exe [2004-08-25 245940]
R2 SavRoam;SAVRoam; C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2006-12-20 116928]
R2 SgeCtl;SafeGuard Easy Control; C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe [2007-09-05 90112]
R2 SgLogPlayer;SafeGuard SGLOG Player; C:\WINDOWS\system32\SgLogPlayer.exe [2005-03-31 61440]
R2 SPBBCSvc;Symantec SPBBCSvc; C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2006-04-11 1160848]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe [2006-12-20 1814720]
R2 SymSecurePort;Symantec SecurePort; C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [2006-12-14 173696]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-26 125048]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WksCfgSrv;SafeGuard Easy Workstation Server; C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe [2007-09-05 155648]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-14 611664]
R3 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2006-08-07 214720]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-08-25 2528960]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-08-07 575488]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-19 913408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]
—————–EOF—————–
info.txt logfile of random's system information tool 1.04 2008-10-16 07:44:17
======Uninstall list======
–>"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
–>"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
–>C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
–>C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
–>C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
–>C:\WINDOWS\UNNeroVision.exe /UNINSTALL
–>C:\WINDOWS\UNRecode.exe /UNINSTALL
–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF964A78-078C-11D1-B7A7-0000C0134CE6}\setup.exe" Uninstall
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware–>MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adjustments for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIEOP15000 remove
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)–>MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Reader–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ADOBEREADER8 remove
Adobe Shockwave Player–>C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Agere Systems HDA Modem–>agrsmdel
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>MsiExec.exe /I{A7F2E70B-BB00-47F7-B7FA-6D8892478FD2}
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Bluetooth Stack for Windows by Toshiba–>MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
Clue 7.0 License for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CLUE709OP15000L remove
Clue 7.0–>MsiExec.exe /I{4FF5AA69-144E-445F-AAFB-231106E5E13A}
Clue–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CLUE709 remove
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Configurations for MS Office 2003–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PROCFG remove
Copy IS Partner Remote Access installation locally–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACCLOCALCOPY remove
Digital Certificates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" Cert remove
Domino.Doc Desktop Enabler Configuration for OP15000–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DDOCDTENOP15000 remove
DVD Shrink 3.2–>"C:\Program Files\DVD Shrink\unins000.exe"
EMC Archive Services for Email MRE–>MsiExec.exe /I{C99CB077-30C0-4587-A322-CD1E1D85163F}
ERUNT 1.1j–>"C:\Program Files\ERUNT\unins000.exe"
Fiberlink Global Remote–>MsiExec.exe /X{CD96CA48-FA2F-410E-8994-E635DDED0E0D}
Fujitsu Display Manager–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{FCCDD334-D813-4FD7-B3F7-F5410EB90EB1}
Fujitsu Hotkey Utility–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{272979FC-6D4A-4C25-B71A-32DD4974A022}\setup.exe"
Fujitsu System Extension Utility–>C:\Program Files\InstallShield Installation Information\{E8A5B78F-4456-4511-AB3D-E7BFFB974A7A}\setup.exe -runfromtemp -l0x0409
Google Earth–>MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Gears–>MsiExec.exe /I{552171BC-30F8-3B29-9C4F-E3FE590B7CAC}
Google Toolbar for Internet Explorer–>regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
Google Updater–>"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Hijackthis 1.99.1–>"C:\Program Files\Hijackthis\unins000.exe"
HijackThis 2.0.2–>"C:\Program Files\trend micro\HijackThis.exe" /uninstall
HISP Configuration for Microsoft Office Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PROOP15000 remove
HP Color LaserJet 4700 PS (02/24/2007 61.071.661.41)–>"C:\Program Files\Common Files\Hewlett-Packard\HPDIU 2.0\HPDIU_Uninstall.exe" /d "C:\Program Files\Common Files\Hewlett-Packard\HPDIU 2.0\DriverInf\hpc4700d.inx"
Hydro CPSS Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" CPSSCLIENT remove
Intel® Graphics Media Accelerator Driver–>C:\WINDOWS\system32\igxpun.exe -uninstall
Internet Explorer Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIEUpdates remove
Internet Explorer–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSIE remove
InterVideo WinDVD 8–>C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
IS Partner Remote access transition–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACCTRANS remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_131_16 remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_142_10 remove
Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_150_06 remove
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lifebook Application Panel–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C5BCA32-C81D-4063-B036-6C085A1D333E}\setup.exe"
LiveUpdate 3.1 (Symantec Corporation)–>"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Lotus Notes (English)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" NOTES7EN remove
Lotus Notes 7.0.3–>MsiExec.exe /I{F10572FA-588C-4653-AD22-96AC843D5733}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MDAC, JET and ODBC drivers–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MDAC remove
MetaFrame Presentation Server Web Client for Win32–>C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
METRO Configuration–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_CONFIG remove
Metro Extension Library–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MELIBRARY remove
METRO InfoScan Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" INFOSCAN remove
METRO Initialization–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BinD remove
METRO OS Configuration–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BinDOsConfig remove
METRO Shared Data Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_SDC remove
METRO Shared Data Provider–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" B_SDP remove
Metro Update configuration (HISP)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BindUpdateHISP remove
Metro Update Engine–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" BindUpdateEngine remove
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0–>c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0–>MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft .NET Framework–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DOTNETFW20 remove
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Java Virtual Machine–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSJVM remove
Microsoft Office CD Source–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003COMMON remove
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSO2003PRO remove
Microsoft Office Visio Professional 2003–>MsiExec.exe /I{90510409-6000-11D3-8CFE-0150048383C9}
Microsoft OS Security Source–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SECURITYSOURCE remove
Microsoft User-Mode Driver Framework Feature Pack 1.5–>"C:\WINDOWS\$NtUninstallWudf01005$\spuninst\spuninst.exe"
Microsoft Visio Professional–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MSVISIO remove
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
MSVC80_x86–>MsiExec.exe /I{212748BB-0DA5-46DE-82A1-403736DC9F27}
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)–>MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Nero 7 Essentials–>MsiExec.exe /I{D34D82E0-4600-407B-9478-8506C1DD1033}
Nokia Connectivity Cable Driver–>MsiExec.exe /X{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}
Nokia Map Loader–>MsiExec.exe /I{18B5996A-643E-4176-9BEB-27C45C9F1FC3}
Nokia PC Suite–>C:\Documents and Settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Nokia_PC_Suite_rel_7_0_8_2_nor.exe
Nokia PC Suite–>MsiExec.exe /I{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}
Notes adjustments (OP15000)–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" NOTES7OP15000 remove
O2Micro Flash Memory Card Windows Driver–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{E1E58954-D885-44E7-B8C2-F0E9A6DA1652} /l1033
OZ711 SCR Driver V3.0.0.9A–>C:\Program Files\InstallShield Installation Information\{33E6FA96-31C0-4CEF-B385-C20D51C0FA06}\setup.exe -runfromtemp -l0x0409
PC Connectivity Solution–>MsiExec.exe /I{1A524CFE-DF85-4555-8BC2-0C89DBD8BC2C}
PDF-XChange 3.0 Pro–>"C:\Program Files\Tracker Software\PDF-XChange 3 Pro\unins000.exe"
Power Saving Utility–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{79821CAD-999C-443D-B420-96F914C84E27}
Radia Agent for ISP–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" RADIAAGENTISP remove
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m
Remedy User 6.3–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{437B532F-EB2B-40A2-8585-DEFA15F92C76}\Setup.exe" -l0x9 Useruninstall
Remote Access Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ISPREMACC remove
SafeGuard Easy–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SGE440EN remove
SafeGuard® Easy Client 4.40.2 –>MsiExec.exe /I{43216FBE-D869-489D-90DE-87D22E816757}
Sap Common Files–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_COMMON remove
Sap Custom Package for all–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPCUSTOM_ALL remove
Sap Custom Package for Hydro–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPCUSTOM_HYDRO remove
SAP Front End–>"C:\WINDOWS\SAPwksta\setup\sapsetup.exe" /uninstall
SAP GUI, SAP R/3 Frontend–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAPGUI640 remove
Sap Patch, BW 3.x - Web Application Designer,–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_WEBAPPLICATIONDESIGNER640 remove
Sap Patch, GUI640_–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_GUI640LVL20 remove
Sap Patch, SETUP640_–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_PATCH_SETUP640 remove
SAPlogon Language Selector–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SAP_LANGUAGE remove
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" Security remove
Service Pack 1 for Microsoft .NET Framework–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" DOTNETFW11SP1 remove
SGE Admin domain 005 for IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SGE440EN_005 remove
ShockWave, Flash and MediaPlayer–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" MultiMed remove
SnagIt 8–>MsiExec.exe /I{B6F0BE9B-41D7-45A2-9A76-D3DB1A89EC6A}
SnagIT License For HISP–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SNAGIT8OP15000L remove
SnagIt–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SNAGIT8 remove
Sun Java configurations for Hydro IS Partner–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_CONFIG_ONH12924 remove
Sun Java configurations–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE_CONFIG remove
Sun Java Runtime Environment–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SUNJRE remove
Symantec Client Security Config for SN–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN_SN remove
Symantec Client Security Config Selector–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN_CFG_SELECT remove
Symantec Client Security–>MsiExec.exe /I{0698CECB-9072-47B1-AEA1-94CA350989B8}
Symantec Client Security–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" SCS30EN remove
Synaptics Pointing Device Driver–>rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Tight Virtual Network Computing–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" TIGHTVNC remove
Total Commander (Remove or Repair)–>c:\totalcmd\tcuninst.exe
UltraEdit Configuration for IS Partner Client–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ULTRAEDITOP15000 remove
UltraEdit–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" ULTRAEDIT remove
UltraEdit-32–>"C:\Program Files\UltraEdit\Uninstall.exe" "C:\Program Files\UltraEdit\ueinstall.log"
Update for Windows XP (KB912945)–>"C:\WINDOWS\$NtUninstallKB912945$\spuninst\spuninst.exe"
Webshots Desktop–>"C:\Program Files\Webshots\unins000.exe"
Windows Automatic Updates Config–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WSUSCLNT_CONFIG remove
Windows Automatic Updates–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WSUSCLNT remove
Windows Communication Foundation–>MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Defender–>MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Driver Package - Intel (NETw4x32) net (09/26/2007 11.5.0.32)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\netw4x32_B0AEEEEDA759744D7D2AC236F54CA6D4CFC0961C\netw4x32.inf
Windows Driver Package - Intel (w29n51) net (07/25/2007 9.0.4.37)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\w29n51_E99959A506B0423451BFDD2FE3C8B527B6AF45BD\w29n51.inf
Windows Driver Package - Intel net (09/26/2007 11.5.0.32)–>C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst32.EXE /u C:\WINDOWS\system32\DRVSTORE\netw4k32_4CD46BE21BE74C8D663C65B8DC2D7EEA091E50F5\netw4k32.inf
Windows Driver Package - Nokia Modem (05/22/2008 3.8)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokia_blue_6F90B0F4A73A2F780A1010B5D6CB5DDFB098181E\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\nokbtmdm_E68D50F7E25BFE399D47C864C3B52557346242A9\nokbtmdm.inf
Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)–>C:\PROGRA~1\DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32\DRVSTORE\pccsmcfd_4A1E30386F4D0DEC8F5DF262CFBD8845EEBAB175\pccsmcfd.inf
Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation–>MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Servicepack–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WXPSP2 remove
Windows XP SP2 adjustments–>WScriptB.exe "C:\PROGRA~1\Hydro\BinD\b_inst.vbs" WXPSP2ADJUST remove
Wireless Selector–>C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BF91B0A2-52DC-4230-B44F-7C34FA861D41}
======Security center information======
AV: Symantec AntiVirus Corporate Edition
FW: Symantec Client Firewall (disabled)
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=C:\Program Files\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\;c:\util;C:\Program Files\Utimaco\SafeGuard Easy\;C:\Program Files\UltraEdit;C:\Program Files\Common Files\EMC
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0f06
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
—————–EOF—————–