This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

2 explorer.exe on vista

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

well i have been infected by many trojans and viruses,my kis7 and spybot didn't work so i made an online scan with kaspersky then with trendmicro,i removed some bagles,trojans,viruses…then i installed avg8 and it has removed other viruses after that i removed avg8,now i can't install any av, and i'm always thinking that i have other viruses especialy when i have seen 2 explorer.exe process's.
this is my hijackthis log:(i have renamed hijackthis.exe to jack_this.exe)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16, on 2008-11-11
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Windows\explorer.exe
C:\Users\MED PROD\Desktop\jack_this.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: Download by easyMule - C:\Program Files\easyMule\IE2EM.htm
O8 - Extra context menu item: Download with Rapget - C:\Users\MEDPRO~1\Desktop\RAPGET~1\rapget.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (file missing) (HKCU)
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Advanced Software Technologies - C:\Windows\SYSTEM32\astsrv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Steganos AntiTheft (SatSrv) - Unknown owner - C:\Windows\system32\\SatSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

–
End of file - 4484 bytes
Hello helpmeouthere

Welcome to the Whatthetech Malware Removal Forum


C:\Program Files\easyMule <— This is most likely where you picking up the infections as P2P (File Sharing Programs ) are the latest avenue of attack by malware writers, read this please.

We have noticed that many people seeking help from us are coming with infections contracted from the use of P2P programs.

Because of this, we changed our malware forum's policy on the use of P2P file sharing programs.

  • If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.
  • If we clean your computer of infection, and you return to us a short time later with an infection contracted by the use of P2P programs, volunteer analysts will refuse their help.

We do not ask you to do this without reason.


P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realise. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.


Uninstall EasyMule via the Add Remove Programs and post a new HJT log please
ok ,thanks ! i had deleted it with revo uninstaller…and i have noticed something..its when i open a folder that the second explorer.exe appear and when i close all folders it disappear…hope you can help me now

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:23, on 2008-11-13
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\Explorer.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\MED PROD\Desktop\jack_this.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Advanced Software Technologies - C:\Windows\SYSTEM32\astsrv.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Steganos AntiTheft (SatSrv) - Unknown owner - C:\Windows\system32\\SatSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

–
End of file - 5178 bytes
Hello,

You basically have a clean log, no virus or malware that I can see.


Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank




Lets run Malwarebytes and a virus scanner and if they come up clean I will link you to some windows support forums for your issue as we just do malware removal in this one.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.<– Don't forget this
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a New Hijackthis log.





Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic




Post both reports please
well…i launched malwarebyte on windows normal mode and it comes clean,but in this mode i couldn't start the online scanner so i made it on safe mode and this is the log from eset scanner:

# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3619 (20081117)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=dfbf6c4f17bc3c45970a3117685af0a2
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-11-18 01:53:06
# local_time=2008-11-18 02:53:06 (+0100, Paris, Madrid)
# country="France"
# osver=6.0.6001 NT Service Pack 1
# scanned=1159813
# found=55
# scan_time=12271
C:\Program Files\Image-Line\FL Studio 8\fl_date_trick_by_JJohnny.dll Win32/Agent.OFV trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Program Files\Image-Line\FL Studio 8\FL_Studio_date_trick.rar Win32/Agent.OFV trojan (deleted) 00000000000000000000000000000000
C:\Program Files\Image-Line\FL Studio 8\FL_Studio_date_trick.rar »RAR »fl_date_trick_by_JJohnny.dll Win32/Agent.OFV trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Program Files\VIR\Vocal Imitation Demo\Crack.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Desktop\just using\mail extractor\Craigslist Mail Harvester System Patch.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Desktop\just using\mail extractor\CLrSoftMailHarvesterDEMO\Craigslist Mail Harvester System Patch.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Craigslist.Mail.Harvester.System.-.CBP.zip Win32/Agent.OBH trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Craigslist.Mail.Harvester.System.-.CBP.zip »ZIP »Craigslist Mail Harvester System Patch.exe Win32/Agent.OBH trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.0.7.-.Cracked.by.PutterPlace(2).zip Win32/Agent.OBH trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.0.7.-.Cracked.by.PutterPlace(2).zip »ZIP »FriendBlasterPro v10.0.7 Patch.exe Win32/Agent.OBH trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.0.8.-.Cracked.by.PutterPlace.zip Win32/Agent.OBH trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.0.8.-.Cracked.by.PutterPlace.zip »ZIP »FriendBlasterPro v10.0.8 Patch.exe Win32/Agent.OBH trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.1.0.-.Cracked.by.PutterPlace.zip Win32/Agent.OBH trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.1.0.-.Cracked.by.PutterPlace.zip »ZIP »FriendBlasterPro v10.1.0 Patch.exe Win32/Agent.OBH trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v1.1(2).zip multiple infiltrations (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v1.1(2).zip »ZIP »Client/SubSeven.exe SubSeven.1_1 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v1.1(2).zip »ZIP »Server/SubSeven v1.1.exe Win32/Subseven.1_1 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v1.1.zip SubSeven.1_1 trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v1.1.zip »ZIP »Client/SubSeven.exe SubSeven.1_1 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.1.5 Legends.zip Win32/SubSeven.215 trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.1.5 Legends.zip »ZIP »editserver.exe Win32/SubSeven.215 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.1.5 Legends.zip »ZIP »server.exe Win32/SubSeven.215 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.1.5 Legends.zip »ZIP »SubSeven.exe Win32/SubSeven.215 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip multiple infiltrations (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »cgi/setup.cgi Win32/SubSeven.22 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »cgi/subseven.cgi Win32/SubSeven.22 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/matrix.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/recmic.dll Win32/SubSeven.22.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/icqpwsteal.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7advanced.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7capture.dll Win32/SubSeven.22.B2 trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7fun1.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7fun2.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7takeover.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7keys.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7moreinfo.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7passwords.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7scanner.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »plugins/s7sniffer.dll Win32/SubSeven.2_2.Plugin trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »EditServer.exe Win32/SubSeven.2_2.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »server.exe Win32/SubSeven.2_2.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »sin.exe Win32/SubSeven.2_2.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\Sub7 v2.2(3).zip »ZIP »sub7.exe Win32/SubSeven.2_2.A trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\IMAGE LINE 2008\more\more.zip Win32/Agent.OFV trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\IMAGE LINE 2008\more\more.zip »ZIP »Tools/FL Studio date trick - You can chance your Date Time for FL Studio/FL_Studio_date_trick.rar Win32/Agent.OFV trojan (error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\IMAGE LINE 2008\more\more.zip »ZIP »Tools/FL Studio date trick - You can chance your Date Time for FL Studio/FL_Studio_date_trick.rar »RAR »fl_date_trick_by_JJohnny.dll Win32/Agent.OFV trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\IMAGE LINE 2008\more\Tools\FL Studio date trick - You can chance your Date Time for FL Studio\FL_Studio_date_trick.rar Win32/Agent.OFV trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\IMAGE LINE 2008\more\Tools\FL Studio date trick - You can chance your Date Time for FL Studio\FL_Studio_date_trick.rar »RAR »fl_date_trick_by_JJohnny.dll Win32/Agent.OFV trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\BURAU $$$$$\VocalImitation101_ByMechoDownload\Vocal.Imitation.v1.0.1\Crack.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\bureau memoire\fbp\FriendBlasterPro v10.0.8 Patch.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\FriendBlasterPro.v10.0.7.-.Cracked.by.PutterPlace(2)\FriendBlasterPro v10.0.7 Patch.exe Win32/Agent.OBH trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\serial 2000 up\s2k.7.1.plus.zip Win32/Adware.BHO.AA application (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Documents\serial 2000 up\s2k.7.1.plus.zip »ZIP »setup.exe Win32/Adware.BHO.AA application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000
C:\Users\MED PROD\Downloads\Incoming\Adobe Illustrator Cs3 Keygen.rar probably a variant of Win32/Agent trojan (deleted) 00000000000000000000000000000000
C:\Users\MED PROD\Downloads\Incoming\Adobe Illustrator Cs3 Keygen.rar »RAR »readme.bat probably a variant of Win32/Agent trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000



THIS IS THE HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15, on 2008-11-18
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\MED PROD\Desktop\jack_this.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.turkojan.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Unknown owner - C:\Windows\SYSTEM32\astsrv.exe (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

–
End of file - 5013 bytes
Hello,

Nod32 removed some other garbage. There may be more.


Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
  • Click on the "Options" icon at the left side of the window, then click on "Advanced."
    deselect "Only delete files in Windows Temp folders older than 48 hours."
  • Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
  • After CCleaner has completed its process, click Exit.

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
**Note** Go to Options> Cookies and any you want to keep move them to The Keep window





  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
RSIT.exe log files

———————————————————————-log.txt———————————————————————-

Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-11-18 18:04:51
Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
System drive C: has 45 GB (15%) free of 299 GB
Total RAM: 2046 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:06, on 2008-11-18
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.exe
C:\Users\MED PROD\Desktop\RSIT.exe
C:\Program Files\trend micro\MED PROD.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.turkojan.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Outil de notification Live Search.lnk = C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - (no file)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AST Service (astcc) - Unknown owner - C:\Windows\SYSTEM32\astsrv.exe (file missing)
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

–
End of file - 5009 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Maintenance en 1 clic.job
C:\Windows\tasks\RegCure Program Check.job
C:\Windows\tasks\RegCure.job
C:\Windows\tasks\User_Feed_Synchronization-{A75AE6BD-2818-45FE-8BC4-3356699205ED}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll [2008-07-29 62728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 401968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KBD"=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2007-04-19 151552]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe [2008-07-29 206088]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-08-04 36352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"=C:\Program Files\CCleaner\CCleaner.exe [2008-10-23 1336560]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]

C:\Users\MED PROD\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Outil de notification Live Search.lnk - C:\Users\MED PROD\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\Windows\system32\klogon.dll [2008-07-29 218376]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe"="C:\Program Files\FlashGet Network\FlashGet universal\FlashGet.exe:*:Enabled:Flashget2"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdate.exe:*:Enabled:FGLiveUpdate"
"C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe"="C:\Program Files\FlashGet Network\FlashGet universal\LiveUpdateEx.exe:*:Enabled:FGLiveUpdateEx"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2008-11-18 18:04:51 —-D—- C:\rsit
2008-11-17 23:19:24 —-D—- C:\Program Files\EsetOnlineScanner
2008-11-17 21:57:37 —-D—- C:\Program Files\Winamp
2008-11-17 21:53:26 —-D—- C:\Users\MED PROD\AppData\Roaming\Winamp med
2008-11-17 21:53:26 —-D—- C:\Users\MED PROD\AppData\Roaming\Winamp
2008-11-17 21:53:26 —-D—- C:\Program Files\Winamp med
2008-11-16 21:34:12 —-A—- C:\Windows\system32\pngfilt.dll
2008-11-16 21:34:12 —-A—- C:\Windows\system32\mshtmler.dll
2008-11-16 21:34:12 —-A—- C:\Windows\system32\mshtmled.dll
2008-11-16 21:34:12 —-A—- C:\Windows\system32\jsproxy.dll
2008-11-16 21:34:12 —-A—- C:\Windows\system32\ieui.dll
2008-11-16 21:34:12 —-A—- C:\Windows\system32\admparse.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\PrivacIE.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\msls31.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\imgutil.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\iernonce.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\ieapfltr.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\corpol.dll
2008-11-16 21:34:11 —-A—- C:\Windows\system32\advpack.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\msrating.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\msfeedsbs.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\msfeeds.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\licmgr10.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\inseng.dll
2008-11-16 21:34:10 —-A—- C:\Windows\system32\iesetup.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\webcheck.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\occache.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\mstime.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\ieaksie.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\ieakeng.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\dxtrans.dll
2008-11-16 21:34:09 —-A—- C:\Windows\system32\dxtmsft.dll
2008-11-16 21:34:08 —-A—- C:\Windows\system32\WinFXDocObj.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\wextract.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\url.dll
2008-11-16 21:34:08 —-A—- C:\Windows\system32\SetIEInstalledDate.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\SetDepNx.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\PDMSetup.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\msfeedssync.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\ieUnatt.exe
2008-11-16 21:34:08 —-A—- C:\Windows\system32\iedkcs32.dll
2008-11-16 21:34:08 —-A—- C:\Windows\system32\ieakui.dll
2008-11-16 21:34:07 —-A—- C:\Windows\system32\jscript.dll
2008-11-16 21:34:07 —-A—- C:\Windows\system32\iertutil.dll
2008-11-16 21:34:07 —-A—- C:\Windows\system32\ie4uinit.exe
2008-11-16 21:34:06 —-A—- C:\Windows\system32\wininet.dll
2008-11-16 21:34:06 —-A—- C:\Windows\system32\mshta.exe
2008-11-16 21:34:06 —-A—- C:\Windows\system32\iexpress.exe
2008-11-16 21:34:06 —-A—- C:\Windows\system32\iepeers.dll
2008-11-16 21:34:06 —-A—- C:\Windows\system32\icardie.dll
2008-11-16 21:34:05 —-A—- C:\Windows\system32\urlmon.dll
2008-11-16 21:34:04 —-A—- C:\Windows\system32\mshtml.dll
2008-11-16 21:34:04 —-A—- C:\Windows\system32\ieframe.dll
2008-11-16 18:29:39 —-D—- C:\Program Files\Windows Live Safety Center
2008-11-16 09:30:00 —-D—- C:\films
2008-11-16 00:01:17 —-D—- C:\Program Files\WinPcap
2008-11-16 00:00:45 —-D—- C:\Program Files\Nmap
2008-11-15 12:11:00 —-D—- C:\Program Files\vLite
2008-11-12 20:19:49 —-D—- C:\Program Files\AviSynth 2.5
2008-11-12 18:06:52 —-D—- C:\Users\MED PROD\AppData\Roaming\vlc
2008-11-12 18:05:31 —-D—- C:\Users\MED PROD\AppData\Roaming\Red Kawa
2008-11-12 15:55:49 —-D—- C:\Program Files\Microsoft
2008-11-12 15:55:19 —-D—- C:\Program Files\Windows Live
2008-11-12 15:17:08 —-D—- C:\Program Files\Common Files\Windows Live
2008-11-12 12:53:59 —-A—- C:\Windows\system32\msxml3.dll
2008-11-12 12:20:52 —-A—- C:\Windows\system32\msxml6.dll
2008-11-12 10:24:11 —-A—- C:\Windows\system32\cmd.execf
2008-11-12 10:23:58 —-D—- C:\32788R22FWJFW
2008-11-12 09:34:36 —-A—- C:\Windows\system32\gpprefcl.dll
2008-11-11 23:28:18 —-D—- C:\ProgramData\Kaspersky Lab
2008-11-11 23:28:18 —-D—- C:\Program Files\Kaspersky Lab
2008-11-11 18:13:44 —-D—- C:\ProgramData\Kaspersky Lab Setup Files
2008-11-11 16:01:46 —-A—- C:\Windows\system32\sfcdetails.txt
2008-11-11 12:41:37 —-D—- C:\Program Files\RegCure
2008-11-11 09:45:29 —-A—- C:\Windows\system32\msvcsv60.dll
2008-11-10 07:06:39 —-D—- C:\Program Files\VS Revo Group
2008-11-10 00:54:31 —-HD—- C:\$AVG8.VAULT$
2008-11-10 00:32:49 —-A—- C:\Windows\system32\avgrsstx.dll
2008-11-10 00:32:35 —-D—- C:\Program Files\AVG
2008-11-09 21:48:13 —-D—- C:\ProgramData\pernov russcov
2008-11-09 12:40:33 —-D—- C:\VundoFix Backups
2008-11-09 12:09:00 —-A—- C:\Windows\VFIND.exe
2008-11-09 12:09:00 —-A—- C:\Windows\SWXCACLS.exe
2008-11-09 12:09:00 —-A—- C:\Windows\SWSC.exe
2008-11-09 12:09:00 —-A—- C:\Windows\SWREG.exe
2008-11-09 12:09:00 —-A—- C:\Windows\sed.exe
2008-11-09 12:09:00 —-A—- C:\Windows\NIRCMD.exe
2008-11-09 12:09:00 —-A—- C:\Windows\grep.exe
2008-11-09 12:09:00 —-A—- C:\Windows\fdsv.exe
2008-11-09 12:08:56 —-D—- C:\cpolod
2008-11-09 12:08:56 —-A—- C:\Windows\system32\swsc.exe
2008-11-09 12:08:56 —-A—- C:\Windows\system32\CF32636.exe
2008-11-09 12:07:40 —-D—- C:\ComboFix
2008-11-09 08:08:31 —-A—- C:\InfoSat.txt
2008-11-09 04:26:00 —-D—- C:\Users\MED PROD\AppData\Roaming\Malwarebytes
2008-11-09 04:20:29 —-D—- C:\Windows\temp
2008-11-09 03:58:01 —-D—- C:\Windows\ERDNT
2008-11-09 03:58:01 —-D—- C:\Qoobox
2008-11-09 03:50:13 —-A—- C:\Windows\gmer.ini
2008-11-09 03:50:06 —-A—- C:\Windows\gmer_uninstall.cmd
2008-11-09 03:50:06 —-A—- C:\Windows\gmer.exe
2008-11-09 03:50:06 —-A—- C:\Windows\gmer.dll
2008-11-09 03:21:14 —-D—- C:\ProgramData\Malwarebytes
2008-11-09 03:21:14 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-09 03:12:08 —-A—- C:\starvir.txt
2008-11-07 17:04:08 —-D—- C:\Program Files\Trend Micro
2008-11-06 00:48:53 —-D—- C:\Program Files\Flash Website Design
2008-11-05 19:29:15 —-D—- C:\Users\MED PROD\AppData\Roaming\NeroDCTemplates
2008-11-05 19:24:53 —-D—- C:\Users\MED PROD\AppData\Roaming\Nero
2008-11-05 19:10:19 —-D—- C:\ProgramData\LightScribe
2008-11-05 19:04:40 —-A—- C:\Windows\system32\TwnLib4.dll
2008-11-05 19:04:40 —-A—- C:\Windows\system32\imagXRA7.dll
2008-11-05 19:04:40 —-A—- C:\Windows\system32\imagXR7.dll
2008-11-05 19:04:40 —-A—- C:\Windows\system32\imagXpr7.dll
2008-11-05 19:04:39 —-A—- C:\Windows\system32\imagX7.dll
2008-11-05 19:04:37 —-D—- C:\ProgramData\Nero
2008-11-05 19:04:37 —-D—- C:\Program Files\Nero
2008-11-05 19:04:37 —-D—- C:\Program Files\Common Files\Nero
2008-11-04 22:59:35 —-D—- C:\Easy Uploader
2008-11-02 13:38:40 —-D—- C:\AtomPark
2008-10-31 17:29:54 —-D—- C:\Program Files\Mixmaster
2008-10-31 17:28:10 —-D—- C:\Windows\desktop
2008-10-31 17:28:09 —-D—- C:\Program Files\QuickSilver
2008-10-30 01:51:56 —-D—- C:\Program Files\Red Kawa
2008-10-30 00:17:28 —-A—- C:\Windows\system32\ss2uinst.exe
2008-10-29 16:18:27 —-D—- C:\Program Files\Email Sender Deluxe
2008-10-29 09:40:55 —-A—- C:\Windows\system32\Faultrep.dll
2008-10-29 09:40:54 —-A—- C:\Windows\system32\wersvc.dll
2008-10-29 09:40:50 —-A—- C:\Windows\system32\win32spl.dll
2008-10-28 19:55:03 —-A—- C:\Windows\system32\GEARAspi.dll
2008-10-28 19:54:41 —-D—- C:\Program Files\iPod
2008-10-28 19:54:40 —-D—- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-28 19:54:40 —-D—- C:\Program Files\iTunes
2008-10-28 19:48:52 —-D—- C:\Program Files\QuickTime
2008-10-26 16:08:35 —-D—- C:\Program Files\Ubisoft
2008-10-26 15:33:07 —-D—- C:\Intel
2008-10-26 15:32:54 —-D—- C:\Drivers
2008-10-26 13:31:22 —-D—- C:\Users\MED PROD\AppData\Roaming\Uniblue
2008-10-26 13:31:22 —-D—- C:\ProgramData\DriverScanner
2008-10-26 13:31:22 —-D—- C:\Program Files\Uniblue
2008-10-26 13:24:46 —-HDC—- C:\ProgramData\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2008-10-26 12:48:01 —-A—- C:\Windows\system32\XAudio2_1.dll
2008-10-26 12:48:01 —-A—- C:\Windows\system32\XAPOFX1_0.dll
2008-10-26 12:48:01 —-A—- C:\Windows\system32\xactengine3_1.dll
2008-10-26 12:48:00 —-A—- C:\Windows\system32\X3DAudio1_4.dll
2008-10-26 12:48:00 —-A—- C:\Windows\system32\d3dx10_38.dll
2008-10-26 12:48:00 —-A—- C:\Windows\system32\D3DCompiler_38.dll
2008-10-26 12:47:59 —-A—- C:\Windows\system32\XAudio2_0.dll
2008-10-26 12:47:59 —-A—- C:\Windows\system32\D3DX9_38.dll
2008-10-26 12:47:58 —-A—- C:\Windows\system32\xactengine3_0.dll
2008-10-26 12:47:58 —-A—- C:\Windows\system32\X3DAudio1_3.dll
2008-10-26 12:47:58 —-A—- C:\Windows\system32\D3DCompiler_37.dll
2008-10-26 12:47:57 —-A—- C:\Windows\system32\xactengine2_10.dll
2008-10-26 12:47:57 —-A—- C:\Windows\system32\D3DX9_37.dll
2008-10-26 12:47:57 —-A—- C:\Windows\system32\d3dx10_37.dll
2008-10-26 12:47:56 —-A—- C:\Windows\system32\d3dx10_36.dll
2008-10-26 12:47:56 —-A—- C:\Windows\system32\D3DCompiler_36.dll
2008-10-26 12:47:55 —-A—- C:\Windows\system32\d3dx9_36.dll
2008-10-26 12:47:54 —-A—- C:\Windows\system32\xactengine2_9.dll
2008-10-26 12:47:53 —-A—- C:\Windows\system32\d3dx10_35.dll
2008-10-26 12:47:53 —-A—- C:\Windows\system32\D3DCompiler_35.dll
2008-10-26 12:47:52 —-A—- C:\Windows\system32\d3dx9_35.dll
2008-10-26 12:47:51 —-A—- C:\Windows\system32\xactengine2_8.dll
2008-10-26 12:47:51 —-A—- C:\Windows\system32\X3DAudio1_2.dll
2008-10-26 12:47:50 —-A—- C:\Windows\system32\d3dx10_34.dll
2008-10-26 12:47:50 —-A—- C:\Windows\system32\D3DCompiler_34.dll
2008-10-26 12:47:49 —-A—- C:\Windows\system32\d3dx9_34.dll
2008-10-26 12:47:48 —-A—- C:\Windows\system32\xinput1_3.dll
2008-10-26 12:47:47 —-A—- C:\Windows\system32\xactengine2_7.dll
2008-10-26 12:47:46 —-A—- C:\Windows\system32\d3dx10_33.dll
2008-10-26 12:47:46 —-A—- C:\Windows\system32\D3DCompiler_33.dll
2008-10-26 12:47:45 —-A—- C:\Windows\system32\d3dx9_33.dll
2008-10-26 12:47:44 —-A—- C:\Windows\system32\xactengine2_6.dll
2008-10-26 12:47:43 —-A—- C:\Windows\system32\xactengine2_5.dll
2008-10-26 12:47:43 —-A—- C:\Windows\system32\d3dx10.dll
2008-10-26 12:47:42 —-A—- C:\Windows\system32\d3dx9_32.dll
2008-10-26 12:47:41 —-A—- C:\Windows\system32\xactengine2_4.dll
2008-10-26 12:47:41 —-A—- C:\Windows\system32\x3daudio1_1.dll
2008-10-26 12:47:40 —-A—- C:\Windows\system32\d3dx9_31.dll
2008-10-26 12:47:39 —-A—- C:\Windows\system32\xactengine2_3.dll
2008-10-26 12:47:38 —-A—- C:\Windows\system32\xinput1_2.dll
2008-10-26 12:47:38 —-A—- C:\Windows\system32\xactengine2_2.dll
2008-10-26 12:47:37 —-A—- C:\Windows\system32\xinput1_1.dll
2008-10-26 12:47:36 —-A—- C:\Windows\system32\xactengine2_1.dll
2008-10-26 12:47:21 —-A—- C:\Windows\system32\xactengine2_0.dll
2008-10-26 12:47:21 —-A—- C:\Windows\system32\d3dx9_30.dll
2008-10-26 12:47:20 —-A—- C:\Windows\system32\x3daudio1_0.dll
2008-10-26 12:47:19 —-A—- C:\Windows\system32\d3dx9_29.dll
2008-10-26 12:47:18 —-A—- C:\Windows\system32\d3dx9_28.dll
2008-10-26 12:47:18 —-A—- C:\Windows\system32\d3dx9_27.dll
2008-10-26 12:47:17 —-A—- C:\Windows\system32\d3dx9_26.dll
2008-10-26 12:47:16 —-A—- C:\Windows\system32\d3dx9_25.dll
2008-10-26 12:47:14 —-A—- C:\Windows\system32\d3dx9_24.dll
2008-10-25 14:33:20 —-SHD—- C:\found.000
2008-10-24 01:31:37 —-A—- C:\Windows\system32\netapi32.dll
2008-10-23 13:34:13 —-D—- C:\Program Files\My-Proxy
2008-10-23 01:35:45 —-A—- C:\Windows\system32\EncDec.dll
2008-10-23 01:35:40 —-A—- C:\Windows\system32\psisdecd.dll
2008-10-21 22:20:42 —-D—- C:\Program Files\MFB-MySpace Friend Bomber
2008-10-19 05:11:27 —-A—- C:\Windows\system32\javaws.exe
2008-10-19 05:11:27 —-A—- C:\Windows\system32\javaw.exe
2008-10-19 05:11:27 —-A—- C:\Windows\system32\java.exe
2008-10-19 05:09:54 —-D—- C:\Program Files\Email-Business
2008-10-19 00:48:30 —-D—- C:\Program Files\Power Email Harvester

======List of files/folders modified in the last 1 months======

2008-11-18 18:05:48 —-D—- C:\Windows\Prefetch
2008-11-18 18:03:54 —-D—- C:\Windows
2008-11-18 15:29:58 —-SHD—- C:\System Volume Information
2008-11-17 23:19:24 —-RD—- C:\Program Files
2008-11-17 23:19:18 —-SD—- C:\Windows\Downloaded Program Files
2008-11-17 23:19:18 —-D—- C:\Windows\System32
2008-11-17 22:17:27 —-D—- C:\Windows\inf
2008-11-17 22:17:27 —-A—- C:\Windows\system32\PerfStringBackup.INI
2008-11-17 10:53:47 —-D—- C:\Program Files\ASIO4ALL v2
2008-11-17 10:14:53 —-D—- C:\Windows\rescache
2008-11-17 09:55:10 —-D—- C:\Windows\system32\fr-FR
2008-11-17 09:55:04 —-D—- C:\Windows\system32\WDI
2008-11-17 09:55:04 —-D—- C:\Windows\system32\migration
2008-11-17 09:55:04 —-D—- C:\Windows\system32\en-US
2008-11-17 09:55:04 —-D—- C:\Windows\PolicyDefinitions
2008-11-17 09:55:04 —-D—- C:\Program Files\Internet Explorer
2008-11-16 21:36:18 —-D—- C:\Windows\winsxs
2008-11-16 21:36:13 —-D—- C:\Windows\system32\catroot
2008-11-16 21:34:46 —-D—- C:\Windows\system32\catroot2
2008-11-16 21:33:31 —-D—- C:\Windows\SoftwareDistribution
2008-11-16 18:37:51 —-SHD—- C:\Windows\Installer
2008-11-16 00:47:07 —-D—- C:\Users\MED PROD\AppData\Roaming\gtk-2.0
2008-11-16 00:01:19 —-D—- C:\Windows\system32\drivers
2008-11-15 12:26:39 —-D—- C:\ProgramData\WLInstaller
2008-11-15 02:26:15 —-D—- C:\Windows\Tasks
2008-11-13 21:19:39 —-D—- C:\Program Files\Equis
2008-11-13 21:18:31 —-D—- C:\Program Files\Common Files
2008-11-13 16:20:09 —-D—- C:\Program Files\Mozilla Firefox
2008-11-12 17:57:35 —-D—- C:\Program Files\VideoLAN
2008-11-12 15:16:33 —-SD—- C:\ProgramData\Microsoft
2008-11-12 15:16:31 —-SD—- C:\Users\MED PROD\AppData\Roaming\Microsoft
2008-11-12 00:38:49 —-D—- C:\Windows\Debug
2008-11-11 23:29:57 —-D—- C:\Program Files\Mozilla Thunderbird
2008-11-11 23:28:18 —-HD—- C:\ProgramData
2008-11-11 18:15:09 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-11-11 18:15:08 —-D—- C:\ProgramData\Spybot - Search & Destroy
2008-11-11 12:41:43 —-D—- C:\Windows\system32\Tasks
2008-11-11 12:12:38 —-D—- C:\ProgramData\Avg8
2008-11-10 23:05:58 —-D—- C:\Windows\Minidump
2008-11-10 08:40:40 —-HD—- C:\Program Files\InstallShield Installation Information
2008-11-10 08:40:40 —-D—- C:\Program Files\IK Multimedia
2008-11-10 08:36:53 —-D—- C:\Program Files\Stardock
2008-11-10 08:29:40 —-D—- C:\Program Files\DSP-worx
2008-11-10 08:16:55 —-D—- C:\Program Files\Steinberg
2008-11-10 08:16:41 —-D—- C:\Program Files\GForce
2008-11-10 08:05:42 —-D—- C:\Program Files\NeoTracePro
2008-11-10 07:54:51 —-D—- C:\Program Files\Logitech
2008-11-10 07:45:04 —-D—- C:\Program Files\Common Files\Colasoft Shared
2008-11-10 07:36:13 —-D—- C:\Program Files\GameHouse
2008-11-10 07:20:53 —-D—- C:\Program Files\WinamaxPoker
2008-11-10 01:07:27 —-D—- C:\Program Files\Proxy Switcher Standard
2008-11-10 00:55:42 —-D—- C:\Program Files\Hi5Robot
2008-11-09 21:43:18 —-D—- C:\Users\MED PROD\AppData\Roaming\DMCache
2008-11-09 21:41:14 —-D—- C:\Program Files\GnuTLS-2.4.1
2008-11-09 21:40:59 —-D—- C:\Program Files\Gmail Account Creator
2008-11-09 21:40:50 —-D—- C:\Users\MED PROD\AppData\Roaming\Alchemy Mindworks
2008-11-09 21:40:50 —-D—- C:\Program Files\Alchemy Mindworks
2008-11-09 21:38:45 —-D—- C:\Windows\uninstall
2008-11-09 21:38:43 —-A—- C:\Windows\system32\msjet35.dll
2008-11-09 21:36:10 —-D—- C:\Program Files\CDXTRACT4
2008-11-09 21:36:03 —-D—- C:\Program Files\CD Audio Reader Filter
2008-11-09 21:35:17 —-HD—- C:\Program Files\Uninstall Information
2008-11-09 21:32:45 —-D—- C:\Users\MED PROD\AppData\Roaming\Adobe
2008-11-09 21:32:44 —-D—- C:\ProgramData\Adobe
2008-11-09 21:32:44 —-D—- C:\Program Files\Adobe
2008-11-09 21:32:10 —-D—- C:\Program Files\Common Files\Adobe
2008-11-09 04:03:47 —-N—- C:\Windows\system.ini
2008-11-09 04:00:12 —-D—- C:\Windows\AppPatch
2008-11-08 00:15:51 —-D—- C:\Windows\system32\Macromed
2008-11-07 03:53:26 —-D—- C:\temp
2008-11-07 01:58:34 —-ASH—- C:\Program Files\desktop.ini
2008-11-07 01:23:38 —-D—- C:\ProgramData\Roxio
2008-11-07 00:33:12 —-D—- C:\Program Files\VistaOSX
2008-11-06 21:30:06 —-D—- C:\Users\MED PROD\AppData\Roaming\BITS
2008-11-06 00:51:19 —-A—- C:\Windows\system32\BASSMOD.dll
2008-11-05 19:08:51 —-ASHD—- C:\Program Files\Common Files\LightScribe
2008-11-05 00:49:35 —-AD—- C:\ProgramData\TEMP
2008-11-03 16:10:26 —-A—- C:\Windows\system32\mrt.exe
2008-10-28 19:55:03 —-DC—- C:\Windows\system32\DRVSTORE
2008-10-28 19:49:02 —-D—- C:\Program Files\Common Files\Apple
2008-10-26 16:18:12 —-RSD—- C:\Windows\assembly
2008-10-26 15:52:35 —-D—- C:\ProgramData\NVIDIA
2008-10-26 15:44:21 —-D—- C:\Windows\system32\RTCOM
2008-10-26 15:33:44 —-D—- C:\Program Files\Intel
2008-10-26 12:46:14 —-D—- C:\Windows\Logs
2008-10-24 19:33:58 —-D—- C:\Program Files\Microsoft Silverlight
2008-10-23 14:50:08 —-D—- C:\Program Files\Accessdiver
2008-10-23 14:13:28 —-D—- C:\Windows\Microsoft.NET
2008-10-23 14:02:15 —-D—- C:\Windows\ehome
2008-10-21 00:59:39 —-RD—- C:\Downloads
2008-10-19 23:37:33 —-D—- C:\Users\MED PROD\AppData\Roaming\Steganos
2008-10-19 05:11:20 —-D—- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2008-11-11 97928]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2008-11-10 26824]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-19 350720]
R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2008-07-21 121872]
R1 KLIF;Kaspersky Lab Driver; C:\Windows\system32\DRIVERS\klif.sys [2008-11-11 216080]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter; C:\Windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R1 sK9Ou0s;sK9Ou0s; \??\C:\Windows\system32\drivers\srosa2.sys [2008-11-07 7168]
R2 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2006-12-26 15440]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\Windows\system32\DRIVERS\mdc8021x.sys [2008-03-22 15781]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 npf;NetGroup Packet Filter Driver; C:\Windows\system32\drivers\npf.sys [2008-06-01 34064]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-18 8704]
R3 3xHybrid;ASUSTek SAA713x PCI Card; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-01-26 2831232]
R3 E100B;Pilote de carte Intel ® PRO; C:\Windows\system32\DRIVERS\e100b325.sys [2008-01-19 159744]
R3 ElbyCDFL;ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [2006-12-26 34760]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 gmer;gmer; C:\Windows\System32\DRIVERS\gmer.sys [2008-11-09 85969]
R3 HSF_DP;HSF_DP; C:\Windows\system32\DRIVERS\HSX_DP.sys [2008-05-08 980992]
R3 HSXHWBS2;HSXHWBS2; C:\Windows\system32\DRIVERS\HSXHWBS2.sys [2008-05-08 266752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-09-09 2167128]
R3 KLFLTDEV;Kaspersky Lab KLFltDev; C:\Windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; C:\Windows\system32\DRIVERS\LVPr2Mon.sys [2007-07-18 25624]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\Windows\system32\DRIVERS\mcdbus.sys [2008-02-18 96256]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-01-10 8237120]
R3 TMPassthruMP;TMPassthruMP; C:\Windows\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-05-08 661504]
S3 af5rrn2s;af5rrn2s; C:\Windows\system32\drivers\af5rrn2s.sys []
S3 AvgWfpX;AVG8 Firewall Driver x86; C:\Windows\System32\Drivers\avgwfpx.sys [2008-11-10 69128]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-07-20 2109592]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-07-20 2142488]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys []
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pepifilter;Volume Adapter; C:\Windows\system32\DRIVERS\lv302af.sys []
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2006-11-06 1119616]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\Windows\system32\DRIVERS\LV302V32.SYS []
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys [2002-11-25 16896]
S3 tap0801;TAP-Win32 Adapter V8; C:\Windows\system32\DRIVERS\tap0801.sys [2007-02-15 26624]
S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S3 TMPassthru;Trend Micro Passthru Ndis Service; C:\Windows\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]
S3 TSP;TSP; C:\Windows\system32\DRIVERS\klif.sys [2008-11-11 216080]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbaudio;Pilote USB audio (WDM); C:\Windows\system32\drivers\usbaudio.sys [2008-01-19 73088]
S3 VMnetAdapter;VMware Virtual Ethernet Adapter Driver; C:\Windows\system32\DRIVERS\vmnetadapter.sys []
S3 VST_DPV;VST_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 VSTHWBS2;VSTHWBS2; C:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe [2008-07-29 206088]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-04-19 81920]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-04-19 75304]
R2 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2007-07-20 137752]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 RUBotted;Trend Micro RUBotted Service; C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe [2008-11-06 582992]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 astcc;AST Service; C:\Windows\SYSTEM32\astsrv.exe []
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-19 523776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 TuneUp.Defrag;@%SystemRoot%\System32\TuneUpDefragService.exe,-1; C:\Windows\System32\TuneUpDefragService.exe [2008-03-21 306432]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-01-19 917504]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-03-25 654848]
S4 LVCOMSer;LVCOMSer; C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe [2007-07-20 186904]
S4 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-07-20 141848]
S4 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-11-01 78752]
S4 WinTaskAdmin;WinTaskAdmin; C:\Program Files\WinTask\Bin\TaskAdmin.exe []
S4 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-18 386560]

—————–EOF—————–

————————————————————————info.txt————————————————————————

info.txt logfile of random's system information tool 1.04 2008-11-18 18:06:07

======Uninstall list======

AccessDiver v4.402–>"C:\Program Files\Accessdiver\unins000.exe"
Adam Van Baker FM7 Soundset–>C:\PROGRA~1\NATIVE~1\FM7\Presets\UNWISE.EXE C:\PROGRA~1\NATIVE~1\FM7\Presets\INSTALL.LOG
Adobe Anchor Service CS3–>MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3–>MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3–>MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting–>MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0–>MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps–>MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific–>MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings–>MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings–>MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings–>MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings–>MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3–>MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3–>MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2–>MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX–>C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin–>C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All–>MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3–>MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3–>MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files–>MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3–>C:\Program Files\Common Files\Adobe\Installers\719d6f144d0c086a0dfa7ff76bb9ac1\Setup.exe
Adobe Photoshop CS3–>MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
Adobe Reader 7.0.8 - Français–>MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70800000002}
Adobe Setup–>MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
Adobe Stock Photos CS3–>MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support–>MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3–>MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client–>MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin–>MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3–>MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
Antares Auto-Tune v4.39–>C:\PROGRA~1\ANTARE~1\AUTO-T~1\AIRLOG~1\AT4\UNWISE.EXE C:\PROGRA~1\ANTARE~1\AUTO-T~1\AIRLOG~1\AT4\INSTALL.LOG
Antares Filter VST DX v1.01–>C:\PROGRA~1\Antares\UNINST~1\UNWISE.EXE C:\PROGRA~1\Antares\UNINST~1\INSTALL.LOG
Antares Harmony Engine VST RTAS v1.0–>"C:\Program Files\Antares Audio Technologies\unins000.exe"
Antares kantos Factory Presets (Extras #1)–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96C00E68-0C52-45D1-A6BF-8B82CEFD4107}\setup.exe" -l0x9
Antares Kantos v1.0–>C:\PROGRA~1\Antares\kantos\UNINST~1\UNWISE.EXE C:\PROGRA~1\Antares\kantos\UNINST~1\INSTALL.LOG
Antares Kantos v1.02 VST & RTAS–>C:\PROGRA~1\Antares\UNWISE.EXE C:\PROGRA~1\Antares\INSTALL.LOG
Antares Tube v1.0–>C:\PROGRA~1\Antares\TUBEUN~1\UNWISE.EXE C:\PROGRA~1\Antares\TUBEUN~1\INSTALL.LOG
Apple Mobile Device Support–>MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Applied Accoustics String Studio VS 1 VST DX v1.0–>C:\PROGRA~1\AAS\STRING~1.0\UNWISE.EXE C:\PROGRA~1\AAS\STRING~1.0\INSTALL.LOG
Applied Accoustics UltraAnalog VA-1 v1.01–>C:\PROGRA~1\AAS\ULTRAA~1.0\UNWISE.EXE C:\PROGRA~1\AAS\ULTRAA~1.0\INSTALL.LOG
Applied Acoustics Lounge Lizard EP VSTi DXi v3.0–>C:\PROGRA~1\AAS\LOUNGE~1.0\UNWISE.EXE C:\PROGRA~1\AAS\LOUNGE~1.0\INSTALL.LOG
ARP2600 V–>C:\Windows\unvise32.exe C:\PROGRAM FILES\Arturia\ARP2600 V\uninstal.log
Arturia Minimoog V v1.0–>C:\PROGRA~1\Arturia\MINIMO~1\UNWISE.EXE C:\PROGRA~1\Arturia\MINIMO~1\INSTALL.LOG
Arturia Moog Modular V2 v1.0–>C:\PROGRA~1\Arturia\MOOGMO~1\UNWISE.EXE C:\PROGRA~1\Arturia\MOOGMO~1\INSTALL.LOG
ASIO4ALL–>C:\Program Files\ASIO4ALL v2\uninstall.exe
Assistant de connexion Windows Live–>MsiExec.exe /I{8984E374-6C93-427C-A3B9-AD92472FDCA0}
ASUS Hybrid Capture Device–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6FB17451-D5A4-4651-AC17-A6713F7234BA}\Setup.exe" -l0x9
AviSynth 2.5–>"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bibliothèques GTK+ 2.12.8 rev a (supprimer uniquement)–>C:\Program Files\Common Files\GTK\2.0\uninst.exe
Bonjour–>MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CCleaner (remove only)–>"C:\Program Files\CCleaner\uninst.exe"
Choice Guard–>MsiExec.exe /I{EBD5E7A9-DBB8-4E24-AE3A-CF9390AF1CCB}
CloneCD–>"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
Compatibility Pack for the 2007 Office system–>MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
CS-80V beta4–>C:\Windows\unvise32.exe C:\PROGRAM FILES\Arturia\CS-80V beta4\uninstal.log
CS-80V–>C:\Windows\unvise32.exe C:\PROGRAM FILES\Arturia\CS-80V\uninstal.log
CSR–>C:\Program Files\InstallShield Installation Information\{648C1BFD-6A70-46D8-B855-F84D95C2DC34}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
DAEMON Tools Toolbar–>C:\Program Files\DAEMON Tools Toolbar\uninst.exe
DreamStation DXi2–>C:\WINDOWS\DSDXIRMV.EXE C:\PROGRAM FILES\CAKEWALK\SHARED DXI\AUDIO SIMULATION\DREAMSTATION DXI2
DScaler 5 Mpeg Decoders–>"C:\Program Files\DScaler5\unins000.exe"
DSL Speed V3.9–>"C:\Program Files\DSL Speed\DSL Speed V3.9\unins000.exe"
ESET Online Scanner–>C:\Windows\system32\OnlineScannerUninstaller.exe
EVEREST Home Edition v2.20–>"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
FabFilter Volcano 1.11–>C:\Program Files\FabFilter\Volcano\Uninst.exe
Far Cry 2–>"C:\Program Files\InstallShield Installation Information\{F2835483-37F2-4123-B4FE-0E77D58447F2}\setup.exe" -runfromtemp -l0x040c -removeonly
FFB - Facebook Friend Bomber–>MsiExec.exe /I{23DE8054-C6B2-43FD-A103-882B1747E10D}
ffdshow [rev 1685] [2007-12-06]–>"C:\Program Files\ffdshow\unins000.exe"
Filter Forge 1.012–>"C:\Program Files\Filter Forge\unins000.exe"
FL Studio 8–>C:\Program Files\Image-Line\FL Studio 8\uninstall.exe
GForce - impOSCar–>C:\Windows\unvise32.exe C:\Program Files\GForce\impOSCar\uninstal.log
GForce - Oddity–>C:\Windows\unvise32.exe C:\Program Files\GForce\Oddity\uninstal.log
GFORCE_SOFTWARE_MINIMONSTA_RTAS_VSTi_v1.06-PLZ–>C:\PROGRA~1\GFORCE~1\MINIMO~1\UNWISE.EXE C:\PROGRA~1\GFORCE~1\MINIMO~1\INSTALL.LOG
HijackThis 2.0.2–>"C:\Users\MED PROD\Desktop\HijackThis.exe" /uninstall
HP Picasso Media Center Add-In–>MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
IK Multimedia Miroslav Philharmonik ST2 Reg. User Presets–>C:\Miroslav\UNWISE.EXE C:\Miroslav\INSTALL.LOG
IL Download Manager–>C:\Program Files\Image-Line\Downloader\uninstall.exe
Image Line Morphine v1.1 VSTi–>C:\PROGRA~1\Morphine\UNWISE.EXE C:\PROGRA~1\Morphine\INSTALL.LOG
Intel® Matrix Storage Manager–>C:\Windows\System32\Imsmudlg.exe
iTunes–>MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
iZotope iDrum Factory Content–>"C:\Program Files\iZotope\iZotope iDrum Content\unins000.exe"
iZotope iDrum–>"C:\Program Files\iZotope\iDrum\unins000.exe"
iZotope Mastering Effects Bundle DX v1.0–>"C:\Program Files\iZotope\Mastering Effects Bundle\Uninstall\unins000.exe"
Java™ 6 Update 4–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java™ 6 Update 6–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Kaspersky Internet Security 2009–>MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
Kaspersky Internet Security 2009–>MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
KORG Legacy Collection - ANALOG EDITION 2007–>MsiExec.exe /I{94CBA610-3D68-40F1-ACDE-6592829E225A}
KORG Legacy Collection - DIGITAL EDITION v1.0.0 –>C:\PROGRA~1\KORG\KORGLE~2\UNWISE.EXE C:\PROGRA~1\KORG\KORGLE~2\INSTALL.LOG
KORG Legacy Collection - DIGITAL EDITION VST–>MsiExec.exe /I{A0F5885A-D757-45AB-9C60-6656C0F8C509}
KORG Legacy Collection - DIGITAL EDITION–>MsiExec.exe /I{4EB1D8CF-DC61-4315-B7DE-75C6B24D7FDB}
Korg Legacy Collection v1.0.0.2–>C:\PROGRA~1\KORG\KORGLE~1\UNWISE.EXE C:\PROGRA~1\KORG\KORGLE~1\INSTALL.LOG
Lexicon Pantheon Reverb DX–>C:\Windows\unvise32.exe C:\Program Files\Lexicon Pantheon Reverb DX\uninstal.log
MachFive–>C:\Windows\unvise32.exe C:\Program Files\uninstal.log
Magic ISO Maker v5.4 (build 0256)–>C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MagicDisc 2.6.93–>C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
MainConcept for Software Encoder–>C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{E7A02A01-C75A-4490-A168-5CA709A3D862}
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Maximus–>C:\Program Files\Image-Line\Maximus\uninstall.exe
MFB-MySpace Friend Bomber–>MsiExec.exe /I{EEB08268-8A0D-4D39-8110-27DE42391401}
Microsoft .NET Framework 3.5 Language Pack - fra–>MsiExec.exe /I{5B76AEA2-D4E5-3B55-B965-ACC36AE0EAFC}
Microsoft .NET Framework 3.5–>C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5–>MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight–>MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022–>MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework–>MsiExec.exe /X{AB47EEE8-507B-331F-AA28-B7C7257F014C}
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32–>MsiExec.exe /X{07FCBED5-94C3-4F94-B9D3-360FA27C7B06}
minimoog V–>C:\Windows\unvise32.exe C:\PROGRAM FILES\Arturia\minimoog V\uninstal.log
Miroslav Philharmonik Instruments–>C:\Program Files\InstallShield Installation Information\{9FCCC8D1-3152-4699-8793-6CB0B9E26EBB}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
Miroslav Philharmonik–>C:\Program Files\InstallShield Installation Information\{BA0D0121-A3BA-487D-9C78-7AB0E676C722}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
MobileMe Control Panel–>MsiExec.exe /I{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}
Module linguistique Microsoft .NET Framework 3.5 - fra–>c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - fra\setup.exe
Moog Modular V 2.2–>"C:\Program Files\Arturia\Moog Modular V 2\unins000.exe"
Mozilla Firefox (3.0.4)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.14)–>C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)–>MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)–>MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Multimedia Builder 4.9.6a–>"C:\Program Files\Multimedia Builder496\unins000.exe"
N.I Pro-53 v3.0-OxYGeN–>C:\PROGRA~1\Pro-53\UNWISE.EXE C:\PROGRA~1\Pro-53\INSTALL.LOG
Native Instruments Absynth 4–>C:\PROGRA~1\NATIVE~1\ABSYNT~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\ABSYNT~1\INSTALL.LOG
Native Instruments B4 v1.11–>C:\PROGRA~1\NATIVE~1\B4\UNWISE.EXE C:\PROGRA~1\NATIVE~1\B4\INSTALL.LOG
Native Instruments Elektrik Piano 1.5–>C:\PROGRA~1\NATIVE~1\ELEKTR~1.5\UNWISE.EXE C:\PROGRA~1\NATIVE~1\ELEKTR~1.5\INSTALL.LOG
Native Instruments FM7 VSTi DXI RTAS v1.1.3.4–>C:\PROGRA~1\NATIVE~1\FM7\UNWISE.EXE C:\PROGRA~1\NATIVE~1\FM7\INSTALL.LOG
Native Instruments FM8–>C:\PROGRA~1\NATIVE~1\FM8\UNWISE.EXE C:\PROGRA~1\NATIVE~1\FM8\INSTALL.LOG
Native Instruments Kontakt 3–>C:\PROGRA~1\NATIVE~1\KONTAK~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\KONTAK~1\INSTALL.LOG
Native Instruments Kore–>C:\PROGRA~1\NATIVE~1\Kore\UNWISE.EXE C:\PROGRA~1\NATIVE~1\Kore\INSTALL.LOG
Native Instruments Massive–>C:\PROGRA~1\NATIVE~1\Massive\UNWISE.EXE C:\PROGRA~1\NATIVE~1\Massive\INSTALL.LOG
Native Instruments Reaktor 5–>C:\PROGRA~1\NATIVE~1\REAKTO~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\REAKTO~1\INSTALL.LOG
Native Instruments Reaktor v5.1.0–>C:\PROGRA~1\NATIVE~1\REAKTO~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\REAKTO~1\INSTALL.LOG
Native Instruments Vokator–>C:\PROGRA~1\NATIVE~1\Vokator\UNWISE.EXE C:\PROGRA~1\NATIVE~1\Vokator\INSTALL.LOG
Native Instruments Xpress Keyboards–>C:\PROGRA~1\NATIVE~1\XPRESS~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\XPRESS~1\INSTALL.LOG
Native.Instruments Battery v3.0.1.005 VSTi DXi RTAS–>C:\PROGRA~1\NATIVE~1\BATTER~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\BATTER~1\INSTALL.LOG
Native_Instruments_Reaktor_v5_User_Library_SYNTHESIZERS_ADDON-PLZ–>C:\PROGRA~1\NATIVE~1\REAKTO~1\Library\Users\Synths\\UNWISE.EXE C:\PROGRA~1\NATIVE~1\REAKTO~1\Library\Users\Synths\\INSTALL.LOG
Nero 8 Lite 8.1.1.4–>"C:\Program Files\Nero\unins000.exe"
Nmap 4.76–>"C:\Program Files\Nmap\uninstall.exe"
No-IP.com DUC (remove only)–>"C:\Program Files\No-IP\DUC20.exe" -uninstall
Nomad Factory Analog Signature Pack –>C:\PROGRA~1\NOMADF~1\UNWISE.EXE C:\PROGRA~1\NOMADF~1\INSTALL.LOG
NomadFactory Analog Mastering Tools VST RTAS v1.0–>"C:\Program Files\Nomad Factory\Uninstall\unins000.exe"
NomadFactory Blue Tubes Dynamics Pack VST RTAS v3.2–>"C:\Program Files\Nomad Factory\Blue Tubes Dynamics Pack\Uninstall\unins000.exe"
NomadFactory Essential Studio Suite VST RTAS v1.5–>"C:\Program Files\Nomad Factory\Essential Studio Suite\Uninstall\unins000.exe"
NVIDIA Drivers–>C:\Windows\system32\NVUNINST.EXE UninstallGUI
Ohm Force - Symptohm VST2–>C:\Windows\unvise32.exe C:\Program Files\Steinberg\VstPlugIns\Ohm Force\Symptohm VST2\uninstal.log
OpenOffice.org Installer 1.0–>MsiExec.exe /X{3A2AF807-9F9F-43C9-A24A-17B617238B74}
Paint Shop Pro 4.12 Shareware–>C:\PROGRA~1\PAINTS~1\UNWISE.EXE C:\PROGRA~1\PAINTS~1\INSTALL.LOG
PDF Settings–>MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Pianoteq v2.3.0–>"C:\Program Files\Pianoteq 2.3\uninstall.exe"
PoiZone–>C:\Program Files\Image-Line\PoiZone\uninstall.exe
Postman Professional 8–>"C:\Program Files\Email-Business\PostmanPro\unins000.exe"
Power Email Harvester–>C:\PROGRA~1\POWERE~1\UNWISE.EXE C:\PROGRA~1\POWERE~1\INSTALL.LOG
Prophet V–>C:\Windows\unvise32.exe C:\PROGRAM FILES\Arturia\Prophet V\uninstal.log
ProxySwitcher Standard–>"C:\Program Files\Proxy Switcher Standard\unins000.exe"
PSP 84 v1.0–>C:\PROGRA~1\PSP84~1\UNWISE.EXE C:\PROGRA~1\PSP84~1\INSTALL.LOG
PSP Neon 1.5.0–>"C:\Program Files\PSPaudioware\PSP Neon\uninstall.exe" "/U:C:\Program Files\PSPaudioware\PSP Neon\irunin.xml"
PSP VintageWarmer 1.1–>C:\PROGRA~1\PSPVIN~1\UNWISE.EXE C:\PROGRA~1\PSPVIN~1\INSTALL.LOG
PSP VintageWarmer2 2.1.4–>"C:\Program Files\PSPaudioware\PSP VintageWarmer2\uninstall.exe" "/U:C:\Program Files\PSPaudioware\PSP VintageWarmer2\irunin.xml"
QuickTime–>MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Rapture 1.1–>"C:\Program Files\Cakewalk\Rapture\unins000.exe"
Realtek High Definition Audio Driver–>RtlUpd.exe -r -m -nrg2709
Reason 4.0–>"C:\Program Files\Propellerhead\Reason\Uninstall Reason\unins000.exe"
RegCure 1.5.0.1–>C:\Program Files\RegCure\uninst.exe
ResponseAnalizer 9–>"C:\Program Files\Email-Business\ResponseAnalizer\unins000.exe"
Revo Uninstaller 1.75–>C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
Roger Nichols Digital DYNAM-IZER VST RTAS v1.2–>"C:\Program Files\Roger Nichols Digital, Inc\Uninstall\unins000.exe"
Roxio Activation Module–>MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Roxio Creator Audio–>MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator Basic v9–>MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Copy–>MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data–>MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator EasyArchive–>MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
Roxio Creator Tools–>MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler 3–>MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
SampleTank 2.5–>C:\Program Files\InstallShield Installation Information\{6559654F-2F38-491F-8411-211517C3E635}\setup.exe -runfromtemp -l0x0009 uninstall -removeonly
SampleTron–>C:\Program Files\InstallShield Installation Information\{81974750-D4B1-4690-B168-D31F9A599542}\setup.exe -runfromtemp -l0x0009 -removeonly
Security Update for CAPICOM (KB931906)–>MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)–>MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Soft Data Fax Modem with SmartCP–>C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\UIU32m.exe -U -ITrx200Cz.INF
Solution de clavier multimédia amélioré–>C:\HP\KBD\Install.exe /u
Sonalksis Plug-Ins for Windows 2.04–>"C:\Windows\unins000.exe"
Sonnox Oxford Inflator Native VST v1.5.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford Inflator Native VST\unins000.exe"
Sonnox Oxford Inflator PowerCore VST v1.5.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford Inflator PowerCore VST\unins000.exe"
Sonnox Oxford Limiter Native VST v1.1.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford Limiter Native VST\unins000.exe"
Sonnox Oxford R3 Dynamics Native VST v1.3.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford R3 Dynamics Native VST\unins000.exe"
Sonnox Oxford R3 Dynamics PowerCore VST v1.3.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford R3 Dynamics PowerCore VST\unins000.exe"
Sonnox Oxford R3 EQ Native VST v1.6.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford R3 EQ Native VST\unins000.exe"
Sonnox Oxford R3 EQ PowerCore VST v1.6.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford R3 EQ PowerCore VST\unins000.exe"
Sonnox Oxford Reverb Native VST v1.0–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford Reverb Native VST\unins000.exe"
Sonnox Oxford TransMod Native VST v1.3.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford TransMod Native VST\unins000.exe"
Sonnox Oxford TransMod PowerCore VST v1.3.1–>"C:\Program Files\Sonnox\Uninstall\Sonnox Oxford TransMod PowerCore VST\unins000.exe"
Steinberg HALionOne GM Drum Set–>MsiExec.exe /I{AC997F93-0757-4ED4-A701-F40C2D654D09}
Steinberg HALionOne GM Set–>MsiExec.exe /I{F057965A-D974-4C64-ADB1-4381CD4B8956}
Steinberg HALionOne Studio Drum Set–>MsiExec.exe /I{865D9ED1-EAC2-436D-AFA7-0B750EB5AAAB}
Steinberg HALionOne Studio Set–>MsiExec.exe /I{D23CBFDA-C46B-4920-BA70-FC7878A3F05A}
Synth1–>"C:\Program Files\Synth1\setup.exe" /u
Tassman 4.0–>C:\PROGRA~1\AAS\TASSMA~1.0\UNWISE.EXE C:\PROGRA~1\AAS\TASSMA~1.0\INSTALL.LOG
Toxic Biohazard–>C:\Program Files\Image-Line\Toxic Biohazard\uninstall.exe
Trend Micro RUBotted–>C:\Program Files\InstallShield Installation Information\{12650598-D7B9-4FB5-91B2-2CAA641AC589}\setup.exe -runfromtemp -l0x0009 -removeonly
Trilogy–>"C:\Program Files\Spectrasonics\Trilogy\unins000.exe"
TuneUp Utilities 2008–>MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
Uniblue DriverScanner 2009–>"C:\ProgramData\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe" REMOVE=TRUE MODIFY=FALSE
Uniblue DriverScanner 2009–>C:\ProgramData\{D5ABFFAD-D592-4F98-B02B-587125B4801F}\DriverScanner_Setup.exe
Universal Document Converter–>"C:\Program Files\Universal Document Converter\unins000.exe"
URS Classic Console EQ Bundle VST Native–>"C:\Windows\URS Classic Console EQ Bundle VST Native\uninstall.exe" "/U:C:\Program Files\URS\Uninstall\uninstall.xml"
VideoLAN VLC media player 0.8.6c–>C:\Program Files\VideoLAN\VLC\uninstall.exe
Videora iPod Converter 4.02–>C:\Program Files\Red Kawa\Video Converter App\uninstaller.exe
vLite–>"C:\Program Files\vLite\unins000.exe"
Waves API Collection–>C:\PROGRA~1\Waves\Logs\WAVESA~1\UNWISE.EXE C:\PROGRA~1\Waves\Logs\WAVESA~1\INSTALL.LOG
Waves L3 16–>C:\PROGRA~1\Waves\Logs\WAVESL~1\UNWISE.EXE C:\PROGRA~1\Waves\Logs\WAVESL~1\INSTALL.LOG
Waves L3 LL–>C:\PROGRA~1\Waves\Logs\WAVESL~2\UNWISE.EXE C:\PROGRA~1\Waves\Logs\WAVESL~2\INSTALL.LOG
Waves Mercury Bundle–>C:\PROGRA~1\Waves\Logs\WAVESM~1\UNWISE.EXE C:\PROGRA~1\Waves\Logs\WAVESM~1\INSTALL.LOG
Waves SSL Collection v1.2–>C:\PROGRA~1\Waves\AIRLOG~1\WAVESS~1.2\UNWISE.EXE C:\PROGRA~1\Waves\AIRLOG~1\WAVESS~1.2\INSTALL.LOG
Winamax Poker (remove only)–>"C:\Program Files\WinamaxPoker\uninst.exe"
Winamp–>"C:\Program Files\Winamp\UninstWA.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail–>MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger–>MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Live OneCare safety scanner–>"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner–>MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
Windows Live Writer–>MsiExec.exe /X{3DFF4274-EBB0-4356-9692-972965018954}
winpcap-nmap 4.02–>"C:\Program Files\WinPcap\uninstall.exe"
WinRAR archiver–>C:\Program Files\WinRAR\uninstall.exe
XAMPP 1.6.7–>"c:\xampp\uninstall.exe"
Yahoo! Toolbar avec bloqueur de fenêtres pop-up–>C:\PROGRA~1\Yahoo!\Common\unyt.exe
YouTube Downloader App 1.01–>C:\Program Files\Red Kawa\Downloader App\uninstaller.exe
Zoom Player (remove only)–>"C:\Program Files\Zoom Player\uninstall.exe"

======Hosts File======

127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com

======Security center information======

AV: AVG (disabled) (outdated)
AV: Kaspersky Internet Security (disabled)
FW: Kaspersky Internet Security (disabled)
AS: AVG (disabled) (outdated)
AS: AVG Anti-Spyware (disabled) (outdated)
AS: Windows Defender
AS: Kaspersky Internet Security (disabled)

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\iZotope\Runtimes;C:\Program Files\WinTask\Bin;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 2, GenuineIntel
"PROCESSOR_REVISION"=0f02
"NUMBER_OF_PROCESSORS"=2
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

—————–EOF—————–
Hello,

Your logs look fine, no malware or viruses I can see.

  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment (JRE) 6 Update 7 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future




  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken
thanks you so much for your help and your fast reply. but can you tel me if this two explorer.exe is normal or not ? about the java:i have already java 6 update 4 &5&6 on my pc,now i deleted them all and installed update 10,any suggestion. thanks
The reason your computer was so heavily infected is on account of these

Cracked
Keygens
Bots


These are illegal, so at this point I won't be able to help you any longer.

Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI