Hi,
System is sluggish and 4 messages appear re: missing files.
Edit note: attached files posted by Corrine
Logfile of random's system information tool 1.06 (written by random/random)
Run by david marks at 2009-12-03 16:44:11
Microsoft Windows XP Professional Service Pack 3
System drive C: has 20 GB (25%) free of 78 GB
Total RAM: 255 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:45:26 PM, on 12/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS.000\System32\smss.exe
C:\WINDOWS.000\system32\winlogon.exe
C:\WINDOWS.000\system32\services.exe
C:\WINDOWS.000\system32\lsass.exe
C:\WINDOWS.000\system32\svchost.exe
C:\WINDOWS.000\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS.000\system32\spoolsv.exe
C:\WINDOWS.000\Explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Airlink101\PVR-PLUS\TVR\Scheduled.exe
C:\WINDOWS.000\SYSTEM32\rundll32.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS.000\system32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS.000\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS.000\system32\rundll32.exe
C:\Documents and Settings\david marks\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Runner.EXE
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS.000\system32\wscntfy.exe
C:\WINDOWS.000\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\My Download Files\RSIT.exe
C:\WINDOWS.000\msa.exe
C:\Program Files\Trend Micro\HijackThis\david marks.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customize/nero/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.earthlink.net/search/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/nero/defaults/su/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.000\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by EarthLink Network, Inc.
F2 - REG:system.ini: Shell=Explorer.exe rundll32.exe dckp.suo printer
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.127.227 winsecurepro2009.microsoft.com
O1 - Hosts: 91.212.127.227 winsecurepro2009.com
O1 - Hosts: 91.212.127.227
www.winsecurepro2009.comO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS.000\SYSTEM32\NZDD.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS.000\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [PVR Agent] C:\Program Files\Airlink101\PVR-PLUS\TVR\Scheduled.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS.000\system32\calc.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [puqlvkku] C:\Documents and Settings\david marks\Local Settings\Application Data\cusqmm\kbkwsysguard.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\DAVIDM~1\ntuser.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\david marks\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NordBull] C:\WINDOWS.000\msa.exe
O4 - HKCU\..\Run: [puqlvkku] C:\Documents and Settings\david marks\Local Settings\Application Data\cusqmm\kbkwsysguard.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: scandisk.lnk = ?
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Runner.EXE
O4 - Global Startup: PowerReg Scheduler.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS.000\SYSTEM32\SHDOCVW.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.000\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.000\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://download.windowsupdate.comO16 - DPF: Win32 Classes -
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) -
http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258018013640O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258017904753O17 - HKLM\System\CCS\Services\Tcpip\..\{0357C02F-4361-42F5-BA08-4AC0AAF7B7BE}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS2\Services\Tcpip\..\{0357C02F-4361-42F5-BA08-4AC0AAF7B7BE}: NameServer = 207.69.188.187 207.69.188.186
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS.000\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS.000\system32\Ati2evxx.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 8741 bytes
======Scheduled tasks folder======
C:\WINDOWS.000\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
C:\WINDOWS.000\tasks\AppleSoftwareUpdate.job
C:\WINDOWS.000\tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-1060284298-1957994488-1003Core.job
C:\WINDOWS.000\tasks\Ad-Aware Update (Weekly).job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-10-17 308856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-11-10 1475864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 501400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-24 652784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EBCDDA60-2A68-11D3-8A43-0060083CFB9C}]
BrowserHelper Class - C:\WINDOWS.000\SYSTEM32\NZDD.DLL [2001-03-05 1150976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-07-11 342600]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"=C:\WINDOWS.000\system32\SysTray.Exe [2004-08-04 3072]
"NeroFilterCheck"=C:\WINDOWS.000\system32\NeroCheck.exe [2001-07-09 155648]
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe [2006-03-23 1398272]
"PVR Agent"=C:\Program Files\Airlink101\PVR-PLUS\TVR\Scheduled.exe [2004-05-10 730112]
"Creative WebCam Tray"=C:\Program Files\Creative\Shared Files\CAMTRAY.EXE [2005-10-27 299008]
"OpwareSE2"=C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [2003-05-08 49152]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-01-31 385024]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-02-19 267048]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-10-17 185896]
"calc"=C:\WINDOWS.000\system32\calc.dll,_IWMPEvents@0 []
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-11-12 2020120]
"puqlvkku"=C:\Documents and Settings\david marks\Local Settings\Application Data\cusqmm\kbkwsysguard.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Creative WebCam Tray"=C:\Program Files\Creative\Shared Files\CamTray.exe [2005-10-27 299008]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"calc"=C:\DOCUME~1\DAVIDM~1\ntuser.dll,_IWMPEvents@0 []
"Google Update"=C:\Documents and Settings\david marks\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-04 135664]
"NordBull"=C:\WINDOWS.000\msa.exe [2009-11-04 120832]
"puqlvkku"=C:\Documents and Settings\david marks\Local Settings\Application Data\cusqmm\kbkwsysguard.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
[]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Runner.EXE
PowerReg Scheduler.exe
C:\Documents and Settings\david marks\Start Menu\Programs\Startup
PowerReg Scheduler.exe
scandisk.lnk - C:\WINDOWS.000\SYSTEM32\rundll32.exe
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS.000\system32\avgrsstx.dll [2009-11-04 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS.000\system32\WgaLogon.dll [2006-06-19 702768]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoDesktop"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS.000\System32\dpvsetup.exe"="C:\WINDOWS.000\System32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-12-03 16:44:11 ----D---- C:\rsit
2009-12-03 16:40:30 ----D---- C:\WINDOWS.000\ERDNT
2009-12-03 16:39:14 ----D---- C:\Program Files\ERUNT
2009-12-03 11:35:41 ----D---- C:\Program Files\Trend Micro
2009-11-20 15:55:18 ----SHD---- C:\FOUND.008
2009-11-19 16:36:30 ----D---- C:\WINDOWS.000\system32\LogFiles
2009-11-12 17:45:55 ----SHD---- C:\Config.Msi
2009-11-12 17:39:49 ----D---- C:\WINDOWS.000\system32\XPSViewer
2009-11-12 17:39:39 ----D---- C:\Program Files\MSBuild
2009-11-12 17:39:24 ----D---- C:\Program Files\Reference Assemblies
2009-11-12 17:38:23 ----N---- C:\WINDOWS.000\system32\prntvpt.dll
2009-11-12 17:38:22 ----N---- C:\WINDOWS.000\system32\xpsshhdr.dll
2009-11-12 17:38:20 ----N---- C:\WINDOWS.000\system32\xpssvcs.dll
2009-11-12 17:38:19 ----D---- C:\f8f68a9cc0a6807ddf
2009-11-12 17:12:49 ----A---- C:\WINDOWS.000\system32\wuapi.dll.mui
2009-11-12 17:07:04 ----A---- C:\WINDOWS.000\system32\wmpns.dll
2009-11-12 17:03:24 ----D---- C:\WINDOWS.000\Prefetch
2009-11-12 04:15:19 ----A---- C:\WINDOWS.000\setuplog.txt
2009-11-12 04:07:45 ----D---- C:\WINDOWS.000\system32\en-us
2009-11-12 04:07:40 ----D---- C:\WINDOWS.000\system32\scripting
2009-11-12 04:07:25 ----D---- C:\WINDOWS.000\l2schemas
2009-11-12 04:07:23 ----D---- C:\Program Files\msn
2009-11-12 04:07:22 ----D---- C:\WINDOWS.000\system32\en
2009-11-12 04:07:21 ----D---- C:\WINDOWS.000\system32\bits
2009-11-12 03:53:16 ----D---- C:\WINDOWS.000\ServicePackFiles
2009-11-12 03:43:38 ----D---- C:\WINDOWS.000\network diagnostic
2009-11-12 03:22:36 ----HD---- C:\WINDOWS.000\$NtServicePackUninstall$
2009-11-12 01:27:48 ----A---- C:\WINDOWS.000\system32\wucltui.dll.mui
2009-11-12 01:27:47 ----A---- C:\WINDOWS.000\system32\wuaueng.dll.mui
2009-11-06 10:56:48 ----SHD---- C:\FOUND.007
2009-11-04 23:49:00 ----HD---- C:\$AVG
2009-11-04 23:37:52 ----A---- C:\WINDOWS.000\system32\avgrsstx.dll
2009-11-04 23:36:22 ----D---- C:\Program Files\AVG
2009-11-04 23:36:11 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2009-11-04 23:28:15 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-11-04 22:51:56 ----A---- C:\WINDOWS.000\msa.exe
2009-11-04 22:51:30 ----D---- C:\Documents and Settings\All Users\Application Data\53581628
======List of files/folders modified in the last 1 months======
2009-12-03 11:47:02 ----A---- C:\WINDOWS.000\SchedLog.Txt
2009-12-01 17:18:02 ----A---- C:\WINDOWS.000\ModemLog_Standard 56000 bps Modem #2.txt
2009-12-01 17:17:56 ----A---- C:\WINDOWS.000\ModemLog_Standard 56000 bps Modem.txt
2009-12-01 14:48:14 ----A---- C:\WINDOWS.000\IMGFOLIO.INI
2009-12-01 14:47:38 ----A---- C:\WINDOWS.000\PLFILE.INI
2009-11-29 22:01:02 ----A---- C:\WINDOWS.000\NeroDigital.ini
2009-11-17 13:17:42 ----A---- C:\WINDOWS.000\U3DEDIT3.INI
2009-11-12 17:48:26 ----A---- C:\WINDOWS.000\system32\PerfStringBackup.INI
2009-11-12 17:05:16 ----A---- C:\WINDOWS.000\OEWABLog.txt
2009-11-12 17:04:50 ----A---- C:\WINDOWS.000\Reg Save Log.txt
2009-11-04 22:45:54 ----SH---- C:\boot.ini
2009-11-04 22:45:54 ----A---- C:\WINDOWS.000\win.ini
2009-11-04 22:45:54 ----A---- C:\WINDOWS.000\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Asapi;Asapi; C:\WINDOWS.000\system32\drivers\Asapi.sys [2000-01-08 10240]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS.000\System32\Drivers\avgldx86.sys [2009-11-04 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS.000\System32\Drivers\avgmfx86.sys [2009-11-04 28424]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS.000\System32\Drivers\avgtdix.sys [2009-11-10 360584]
R1 InCDPass;InCDPass; C:\WINDOWS.000\System32\DRIVERS\InCDPass.sys [2006-03-23 29440]
R1 incdrm;InCD Reader; C:\WINDOWS.000\system32\drivers\incdrm.sys [2006-03-23 33536]
R1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS.000\system32\DRIVERS\p3.sys [2008-04-13 42752]
R2 Nsynas32;Nsynas32; C:\WINDOWS.000\system32\drivers\Nsynas32.sys [2000-06-16 17784]
R3 ac97intc;Intel(r) 82801 Audio Driver Install Service (WDM); C:\WINDOWS.000\system32\drivers\ac97intc.sys [2001-08-17 96256]
R3 admjoy;Aureal Game Port Enumerator; C:\WINDOWS.000\system32\DRIVERS\admjoy.sys [2004-08-03 10880]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter; C:\WINDOWS.000\system32\DRIVERS\AN983.sys [2004-08-03 36224]
R3 ati2mtaa;ati2mtaa; C:\WINDOWS.000\system32\DRIVERS\ati2mtaa.sys [2001-09-26 285088]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS.000\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 mf;mf; C:\WINDOWS.000\system32\DRIVERS\mf.sys [2008-04-13 63744]
R3 motubus;MOTU Audio MIDI Extension; C:\WINDOWS.000\system32\drivers\MotuBus.sys [2003-07-10 15488]
R3 MotuMidi;MOTU MIDI Device; C:\WINDOWS.000\system32\drivers\MotuMidi.sys [2004-07-21 26752]
R3 MotuPar;MOTU Parallel MIDI Interface; C:\WINDOWS.000\system32\drivers\MotuPar.sys [2004-09-17 20992]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS.000\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS.000\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS.000\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS.000\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS.000\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS.000\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 w324drvr;w324drvr; C:\WINDOWS.000\system32\drivers\w324drvr.sys [2001-11-09 141236]
R3 Wave324;Wave Driver for PCI-324; C:\WINDOWS.000\system32\drivers\Wave324.sys [2001-11-29 44760]
R3 wdm_au8820;Aureal Vortex 8820 Audio Driver (WDM); C:\WINDOWS.000\system32\drivers\adm8820.sys [2001-10-05 508032]
R3 WpdUsb;WpdUsb; C:\WINDOWS.000\System32\Drivers\wpdusb.sys [2005-01-28 18944]
R4 InCDfs;InCD File System; C:\WINDOWS.000\system32\drivers\InCDfs.sys [2006-03-23 102016]
S3 61883;61883 Unit Device; C:\WINDOWS.000\system32\DRIVERS\61883.sys [2008-04-13 48128]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS.000\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 Avc;AVC Device; C:\WINDOWS.000\system32\DRIVERS\avc.sys [2008-04-13 38912]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS.000\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 daqdrv;daqdrv; \??\C:\WINDOWS.000\system32\daqdrv.sys []
S3 DCamUSBEMPIA;Airlink101 ATVUSB01 2800; C:\WINDOWS.000\system32\DRIVERS\emDevice.sys [2004-08-11 108845]
S3 FiltUSBEMPIA;USB Device Lower Filter; C:\WINDOWS.000\system32\DRIVERS\emFilter.sys [2004-08-20 19328]
S3 hidgame;Microsoft Hid to Joystick Port Enabler; C:\WINDOWS.000\system32\DRIVERS\hidgame.sys [2001-08-17 8576]
S3 MSDV;Microsoft DV Camera and VCR; C:\WINDOWS.000\system32\DRIVERS\msdv.sys [2008-04-13 51200]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS.000\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS.000\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS.000\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS.000\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 NtApm;NT Apm/Legacy Interface Driver; C:\WINDOWS.000\system32\DRIVERS\NtApm.sys [2001-08-17 9344]
S3 ScanUSBEMPIA;USB Still Image Capture Device; C:\WINDOWS.000\system32\DRIVERS\emScan.sys [2004-08-11 4857]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS.000\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS.000\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 StillCam;Still Serial Digital Camera Driver; C:\WINDOWS.000\system32\DRIVERS\serscan.sys [2001-08-17 6784]
S3 streamip;BDA IPSink; C:\WINDOWS.000\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS.000\system32\DRIVERS\usbohci.sys []
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS.000\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vsdatant;vsdatant; \??\C:\WINDOWS.000\system32\vsdatant.sys []
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS.000\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-02-18 110592]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-11-04 285392]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-24 168432]
R2 InCDsrv;InCD Helper; C:\Program Files\Ahead\InCD\InCDsrv.exe [2006-03-23 880128]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS.000\system32\wdfmgr.exe [2005-01-28 38912]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-02-19 504104]
S2 6to4;Network Security; C:\WINDOWS.000\System32\svchost.exe [2008-04-13 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS.000\system32\Ati2evxx.exe [2000-11-30 57344]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS.000\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS.000\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.000\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; c:\WINDOWS.000\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WMConnectCDS;Windows Media Connect Service; C:\Program Files\Windows Media Connect 2\wmccds.exe [2005-10-06 855552]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS.000\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-12-03 16:45:34
======Uninstall list======
-->"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /UNINSTALL /PROMPT
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS.000\INF\PCHealth.inf
Adobe Flash Player 10 ActiveX-->C:\WINDOWS.000\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS.000\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ArcSoft PhotoStudio 5.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2261C4B-4D9B-4149-8472-31B7A2FEAB91}\setup.exe" -l0x9
ASAPI Update-->C:\PROGRA~1\VOB\ASAPIU~1\IWUNIN~1.EXE -uninstall C:\WINDOWS.000\ISUNINST.EXE -fC:\PROGRA~1\VOB\ASAPIU~1\ASAPI.isu
ATI Display Driver-->rundll32 C:\WINDOWS.000\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Canon CanoScan Toolbox 4.6-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{088A077A-8028-408C-AE7B-4512AE2A65A0}\setup.exe" -l0x9 anything
CD-Writer Plus software-->C:\Program Files\CD-Writer Plus\hpremove.exe
Conexant HCF V.90/56K Modem-->infunist.exe
Creative WebCam Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E5ABA5FD-EE3D-4F15-895D-B32321E6C96B}\setup.exe" -l0x9 /remove
Creative WebCam Live! Pro User's Guide (English)-->C:\WINDOWS.000\IsUninst.exe -f"C:\Program Files\Creative\Creative WebCam Live! Pro\Creative WebCam Live! Pro User's Guide\English\CTManual.isu"
Cubase VST Score-->C:\PROGRA~1\STEINB~1\CUBASE~1.0\UNINST~1.EXE C:\PROGRA~1\STEINB~1\CUBASE~1.0\INSTALL.LOG
EarthLink MailBox-->"C:\Program Files\EarthLink MailBox\MCUninst.exe"
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
GalleryPlayer Images-->C:\WINDOWS.000\GalleryPlayer Images Uninstaller.exe
Get Yahoo! Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC067AB0-2594-4A7E-A1DE-ADEB7D15EB4B}\setup.exe" -l0x9 /remove
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2-->"C:\My Download Files\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS.000\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS.000\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format SDK (KB902344)-->"C:\WINDOWS.000\$NtUninstallKB902344$\spuninst\spuninst.exe"
HP CD-Writer Plus Toolbox-->C:\PROGRA~1\CD-WRI~1\DIAGNOSE\UNWISE.EXE /S C:\PROGRA~1\CD-WRI~1\DIAGNOSE\INSTALL.LOG
HP DeskJet 930C Series (Remove only)-->C:\Program Files\HP DeskJet 930C Series\hpfiui.exe -c -vdivid=HPF -vpnum=93 -vinstport=USB/DeskJet 930C/MY05B182MRJL -vproduct=930C -huninstall
HP Instant Delivery-->C:\PROGRA~1\HEWLET~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HEWLET~1\HPINST~1\INSTALL.LOG
InCD-->C:\WINDOWS.000\NuNInst.exe /UNINSTALL
Instant Image Voyager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{77137676-87F7-410C-8DC7-000A9DD44C96}\setup.exe"
iTunes-->MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
KODAK Camera Connection Software Help-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\ENGINE\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{884CE4D3-71D7-494A-8206-1317201AAE04}\SETUP.EXE"
Kodak Memory Albums-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A8F1CA0-9085-11D4-B869-0050DA73F204}\Setup.exe"
KODAK Picture Software-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{51661BCF-F22A-11D4-82B4-00500494EF5C}\setup.exe"
Manual CanoScan 4200F-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9C54C44-BB5A-4B03-8907-C01A9790195A}\setup.exe" -l0x9
Microsoft .NET Framework 1.1 Hotfix (KB886903)-->"C:\WINDOWS.000\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS.000\Microsoft.NET\Framework\v1.1.4322\Updates\M886903\M886903Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS.000\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Base Smart Card Cryptographic Service Provider Package-->"C:\WINDOWS.000\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669-->C:\WINDOWS.000\muninst.exe C:\WINDOWS.000\INF\KB870669.inf
Microsoft Office 2000 SR-1 Standard-->MsiExec.exe /I{00020409-78E1-11D2-B60F-006097C998E7}
Microsoft Publisher 98-->C:\Program Files\Microsoft Office\Office\Setup\Setup.exe /m
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
MOTU 324-->C:\WINDOWS.000\IsUninst.exe -f"C:\Program Files\MOTU\324\Uninst.isu"
MOTU MIDI-->C:\WINDOWS.000\IsUninst.exe -f"C:\Program Files\MOTU\Uninst.isu"
NEATO MediaFACE-->C:\PROGRA~1\MEDIAF~1\UNWISE.EXE C:\PROGRA~1\MEDIAF~1\INSTALL.LOG
Nero Digital-->C:\WINDOWS.000\UNNeroVision.exe /UNINSTALL
Nero Media Player-->C:\WINDOWS.000\UNNMP.exe /UNINSTALL
Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Netscape (7.2)-->C:\WINDOWS.000\NSUninst.exe /ua "7.2 (en)"
OmniPage SE 2.0-->MsiExec.exe /I{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}
Professor Franklin-->C:\Program Files\Professor Franklin\Uninstal.exe
PVR-PLUS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5B893587-00A8-4A4E-83F0-8AFA7BFC7C1A}\setup.exe" -l0x9
QuickTime-->MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealDownload-->C:\Program Files\Real\RealDownload\REALDOWNLOAD.EXE -u
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
ReBirth ModPacker-->C:\PROGRA~1\PROPEL~1\MODPAC~1\UNWISE.EXE C:\PROGRA~1\PROPEL~1\MODPAC~1\INSTALL.LOG
ReBirth RB-338 2.0-->C:\PROGRA~1\PROPEL~1\REBIRT~1.0\UNWISE.EXE C:\PROGRA~1\PROPEL~1\REBIRT~1.0\INSTALL.LOG
ReBirth RB-338-->C:\PROGRA~1\REBIRT~1\UNWISE.EXE C:\PROGRA~1\REBIRT~1\INSTALL.LOG
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS.000\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
Solar System Explorer-->C:\WINDOWS.000\IsUninst.exe -f"c:\program files\Uninst.isu"
Sony USB Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\ENGINE\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}\SETUP.EXE" UNINSTALL
Steinberg Cubase VST Score-->C:\PROGRA~1\STEINB~1\CUBASE~1.0\UNINST~1.EXE C:\PROGRA~1\STEINB~1\CUBASE~1.0\Install.log
Steinberg Cubase VST32-->D:\PROGRA~1\STEINB~1\CUBASE~1.1\UNINST~1.EXE D:\PROGRA~1\STEINB~1\CUBASE~1.1\INSTALL.LOG
Steinberg LM·4-->C:\PROGRA~1\STEINB~1\VSTPLU~1\LM-4\UNWISE.EXE C:\PROGRA~1\STEINB~1\VSTPLU~1\LM-4\INSTALL.LOG
Steinberg Model·E-->C:\PROGRA~1\STEINB~1\VSTPLU~1\MODEL-E\UNWISE.EXE C:\PROGRA~1\STEINB~1\VSTPLU~1\MODEL-E\INSTALL.LOG
TBS Montego Drivers-->ASP4SETP.EXE 9
The Weather Channel Desktop-->C:\Program Files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
Ulead COOL 3D 3.5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA1BE991-D723-41BE-AD16-42EAFDA794EA}\Setup.exe"
Ulead VideoStudio 5.0-->MsiExec.exe /I{27113CA3-36B8-48AB-A419-79CF1FC0ECED}
Ulead VideoStudio 8.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RUNTIME\0701\INTEL32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4F1DA6BF-3614-48A1-9970-9E90F646789E}\SETUP.EXE" -l0x9
ViewSonic Monitor Drivers-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\Setup.exe" -l0x9
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS.000\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
WaveLab-->"C:\Program Files\Steinberg\WaveLab\Unwise.exe" C:\PROGRA~1\STEINB~1\WAVELAB\Install.log
Weather Services-->C:\WINDOWS.000\system32\control.exe C:\PROGRA~1\THEWEA~1\Framework\wxfw.cpl,4
Windows Media Connect-->"C:\WINDOWS.000\$NtUninstallWMCSetup$\spuninst\spuninst.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS.000\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS.000\$NtServicePackUninstall$\spuninst\spuninst.exe"
Windows XP Uninstall-->%SYSTEMROOT%\system32\osuninst.exe
WinSCP 3.8.2-->"C:\Program Files\WinSCP3\unins000.exe"
WinZip-->C:\WINZIP\WINZIP32.EXE /uninstall
Yahoo! Toolbar-->C:\PROGRA~1\YAHOO!\COMMON\unyt.exe
ZoneAlarm-->C:\PROGRA~1\Zone Labs\ZoneAlarm\zauninst.exe
======Hosts File======
127.0.0.1 localhost
::1 localhost
91.212.127.227 winsecurepro2009.microsoft.com
91.212.127.227 winsecurepro2009.com
91.212.127.227
www.winsecurepro2009.com======Security center information======
AV: AVG Anti-Virus Free
======System event log======
Computer Name: HAL
Event Code: 51
Message: An error was detected on device \Device\Harddisk2\D during a paging operation.
Record Number: 45360
Source Name: Disk
Time Written: 20091104222134.000000-480
Event Type: warning
User:
Computer Name: HAL
Event Code: 26
Message: The driver has detected that device \Device\Scsi\ultra1 has old or out-of-date firmware.
Reduced performance may result.
Record Number: 45359
Source Name: ultra
Time Written: 20091104222134.000000-480
Event Type: warning
User:
Computer Name: HAL
Event Code: 51
Message: An error was detected on device \Device\Harddisk2\D during a paging operation.
Record Number: 45357
Source Name: Disk
Time Written: 20091104222128.000000-480
Event Type: warning
User:
Computer Name: HAL
Event Code: 26
Message: The driver has detected that device \Device\Scsi\ultra1 has old or out-of-date firmware.
Reduced performance may result.
Record Number: 45356
Source Name: ultra
Time Written: 20091104222128.000000-480
Event Type: warning
User:
Computer Name: HAL
Event Code: 51
Message: An error was detected on device \Device\Harddisk2\D during a paging operation.
Record Number: 45355
Source Name: Disk
Time Written: 20091104222127.000000-480
Event Type: warning
User:
=====Application event log=====
Computer Name: HAL
Event Code: 1102
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Utilities, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Record Number: 2643
Source Name: .NET Runtime Optimization Service
Time Written: 20060515115845.000000-420
Event Type:
User:
Computer Name: HAL
Event Code: 1102
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Tasks, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Record Number: 2641
Source Name: .NET Runtime Optimization Service
Time Written: 20060515115844.000000-420
Event Type:
User:
Computer Name: HAL
Event Code: 1102
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Framework, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Record Number: 2639
Source Name: .NET Runtime Optimization Service
Time Written: 20060515115837.000000-420
Event Type:
User:
Computer Name: HAL
Event Code: 1102
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Engine, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Record Number: 2637
Source Name: .NET Runtime Optimization Service
Time Written: 20060515115837.000000-420
Event Type:
User:
Computer Name: HAL
Event Code: 1102
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: CustomMarshalers, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Record Number: 2635
Source Name: .NET Runtime Optimization Service
Time Written: 20060515115833.000000-420
Event Type:
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\system32;C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG;%SYSTEMROOT%;%SYSTEMROOT%\system32\WBEM;C:\Program Files\QuickTime\QTSystem\
"windir"=C:\WINDOWS.000
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0803
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=C:\WINDOWS.000\TEMP
"TMP"=C:\WINDOWS.000\TEMP
"CLASSPATH"=.;C:\PROGRA~1\PHOTOD~1.1\ADOBEC~1;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
"PROMPT"=$p$g
"winbootdir"=C:\WINDOWS.000
"QTJAVA"=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
-----------------EOF-----------------