Logfile of random's system information tool 1.05 (written by random/random)
Run by Sukanth at 2009-02-06 14:09:28
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 53 GB (22%) free of 238 GB
Total RAM: 2814 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09, on 2009-02-06
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Sukanth\Desktop\Desktop\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\trend micro\Sukanth.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: GammaTray.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
--
End of file - 9166 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2009-01-20 134344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-02-02 1078552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-13 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 322368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-02 1968920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2007-08-21 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-13 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll [2008-12-16 429816]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-02 1968920]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-03-24 4423680]
"Skytel"=C:\Windows\Skytel.exe [2007-03-16 1822720]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-13 136600]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-04-11 56080]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-01-12 488984]
"LVCOMSX"=C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe [2007-01-12 244512]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-01-31 385024]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-02-19 267048]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-09-17 13580832]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-09-17 92704]
"BrMfcWnd"=C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2006-10-30 622592]
"ControlCenter3"=C:\Program Files\Brother\ControlCenter3\brctrcen.exe [2006-07-19 65536]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-02 1601304]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2007-04-04 81920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"VeohPlugin"=C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2008-12-16 3528440]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-12-29 687560]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
GammaTray.lnk - C:\Program Files\MagicTune Premium\GammaTray.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Users\Sukanth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{180e7920-7a75-11dc-b5d9-806e6f6e6963}]
shell\AutoRun\command - E:\AutorunPlayer.exe RightAutorunPro.dat
======List of files/folders created in the last 2 months======
2009-02-06 14:09:28 ----D---- C:\rsit
2009-02-06 14:09:28 ----D---- C:\Program Files\trend micro
2009-02-05 22:31:18 ----D---- C:\worksnow
2009-02-05 22:31:17 ----A---- C:\Windows\system32\CF25929.exe
2009-02-05 22:26:51 ----A---- C:\Windows\system32\CF25060.exe
2009-02-05 22:09:37 ----A---- C:\Windows\system32\CF21683.exe
2009-02-05 21:37:52 ----D---- C:\ProgramData\NortonInstaller
2009-02-05 21:21:35 ----A---- C:\Windows\system32\CF12246.exe
2009-02-05 21:16:22 ----A---- C:\Windows\zip.exe
2009-02-05 21:16:22 ----A---- C:\Windows\VFIND.exe
2009-02-05 21:16:22 ----A---- C:\Windows\SWXCACLS.exe
2009-02-05 21:16:22 ----A---- C:\Windows\SWSC.exe
2009-02-05 21:16:22 ----A---- C:\Windows\SWREG.exe
2009-02-05 21:16:22 ----A---- C:\Windows\sed.exe
2009-02-05 21:16:22 ----A---- C:\Windows\NIRCMD.exe
2009-02-05 21:16:22 ----A---- C:\Windows\grep.exe
2009-02-05 21:16:22 ----A---- C:\Windows\fdsv.exe
2009-02-05 21:16:21 ----D---- C:\Windows\ERDNT
2009-02-05 21:16:21 ----D---- C:\Qoobox
2009-02-05 21:16:20 ----A---- C:\Windows\system32\swsc.exe
2009-02-05 21:16:20 ----A---- C:\Windows\system32\CF11276.exe
2009-02-02 22:03:08 ----D---- C:\Users\Sukanth\AppData\Roaming\Malwarebytes
2009-02-02 22:03:03 ----D---- C:\ProgramData\Malwarebytes
2009-02-02 08:22:40 ----HD---- C:\$AVG8.VAULT$
2009-02-02 07:57:54 ----A---- C:\Windows\system32\avgrsstx.dll
2009-02-01 20:01:46 ----D---- C:\ProgramData\avg8
2009-01-30 16:57:59 ----A---- C:\Windows\MegaManager.INI
2009-01-30 16:48:53 ----A---- C:\Windows\system32\un2065.txt
2009-01-30 16:48:53 ----A---- C:\Windows\system32\2065.txt
2009-01-30 15:53:20 ----D---- C:\Windows\system32\logs
2009-01-30 15:53:09 ----D---- C:\Program Files\Common Files\MSSoap
2009-01-30 15:50:50 ----D---- C:\Windows\system32\URTTEMP
2009-01-30 15:50:06 ----D---- C:\Program Files\Common Files\BitDefender
2009-01-30 14:56:14 ----D---- C:\Program Files\DAMN NFO Viewer
2009-01-24 22:31:23 ----A---- C:\Windows\system32\avgrsstx.dll.old
2009-01-24 22:31:14 ----D---- C:\Program Files\AVG
2009-01-24 22:05:18 ----D---- C:\Users\Sukanth\AppData\Roaming\Orbit
2009-01-24 22:05:17 ----D---- C:\Program Files\Orbitdownloader
2009-01-21 18:24:46 ----D---- C:\Users\Sukanth\AppData\Roaming\PC-FAX TX
2009-01-21 18:15:32 ----A---- C:\Windows\Brpfx04a.ini
2009-01-21 18:15:32 ----A---- C:\Windows\brpcfx.ini
2009-01-21 18:13:11 ----A---- C:\Windows\system32\brinsstr.dll
2009-01-21 18:13:03 ----N---- C:\Windows\system32\BrWiaNCp.dll
2009-01-21 18:13:03 ----N---- C:\Windows\system32\Brnsplg.dll
2009-01-21 18:13:03 ----N---- C:\Windows\system32\BrNetSti.dll
2009-01-21 18:13:03 ----A---- C:\Windows\system32\BrWia06c.dll
2009-01-21 18:13:02 ----N---- C:\Windows\system32\NSSearch.dll
2009-01-21 18:13:02 ----N---- C:\Windows\system32\BrMuSNMP.dll
2009-01-21 18:13:02 ----N---- C:\Windows\system32\BrfxD05a.dll
2009-01-21 18:13:02 ----N---- C:\Windows\brunin03.dll
2009-01-21 18:13:02 ----D---- C:\Program Files\Brother
2009-01-21 18:13:02 ----D---- C:\Brother
2009-01-21 18:12:24 ----D---- C:\ProgramData\Brother
2009-01-17 14:46:11 ----D---- C:\Users\Sukanth\AppData\Roaming\Megaupload
2009-01-17 14:45:48 ----D---- C:\ProgramData\Megaupload
2009-01-17 14:45:47 ----D---- C:\ProgramData\EmailNotifier
2009-01-17 13:07:21 ----A---- C:\Windows\NeroDigital.ini
2009-01-17 13:05:48 ----D---- C:\Program Files\AviSynth 2.5
2008-12-30 20:22:52 ----D---- C:\Program Files\DAEMON Tools Lite
2008-12-29 16:28:33 ----D---- C:\Program Files\Activision
2008-12-29 15:55:51 ----A---- C:\Windows\system32\d3dx9_34.dll
2008-12-29 15:55:51 ----A---- C:\Windows\system32\d3dx10_34.dll
2008-12-29 15:55:51 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2008-12-29 15:55:50 ----A---- C:\Windows\system32\xinput1_3.dll
2008-12-29 15:55:50 ----A---- C:\Windows\system32\xactengine2_7.dll
2008-12-29 15:55:50 ----A---- C:\Windows\system32\d3dx10_33.dll
2008-12-29 15:55:50 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2008-12-29 15:55:49 ----A---- C:\Windows\system32\xactengine2_6.dll
2008-12-29 15:55:49 ----A---- C:\Windows\system32\xactengine2_5.dll
2008-12-29 15:55:49 ----A---- C:\Windows\system32\d3dx9_33.dll
2008-12-29 15:55:49 ----A---- C:\Windows\system32\d3dx10.dll
2008-12-29 15:55:48 ----A---- C:\Windows\system32\xactengine2_4.dll
2008-12-29 15:55:48 ----A---- C:\Windows\system32\x3daudio1_1.dll
2008-12-29 15:55:48 ----A---- C:\Windows\system32\d3dx9_32.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\xinput1_2.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\xinput1_1.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\xactengine2_3.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\xactengine2_2.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\xactengine2_1.dll
2008-12-29 15:55:47 ----A---- C:\Windows\system32\d3dx9_31.dll
2008-12-29 15:55:42 ----A---- C:\Windows\system32\d3dx9_30.dll
2008-12-29 15:55:41 ----A---- C:\Windows\system32\xactengine2_0.dll
2008-12-29 15:55:41 ----A---- C:\Windows\system32\x3daudio1_0.dll
2008-12-29 15:55:41 ----A---- C:\Windows\system32\d3dx9_29.dll
2008-12-29 15:55:41 ----A---- C:\Windows\system32\d3dx9_28.dll
2008-12-29 15:55:40 ----A---- C:\Windows\system32\d3dx9_27.dll
2008-12-29 15:55:40 ----A---- C:\Windows\system32\d3dx9_26.dll
2008-12-29 15:55:40 ----A---- C:\Windows\system32\d3dx9_25.dll
2008-12-29 15:55:39 ----A---- C:\Windows\system32\d3dx9_24.dll
2008-12-29 15:53:09 ----A---- C:\Windows\system32\PnkBstrB.exe
2008-12-29 15:53:09 ----A---- C:\Windows\system32\PnkBstrA.exe
2008-12-29 15:53:08 ----A---- C:\Windows\game.ini
2008-12-29 15:28:39 ----D---- C:\Users\Sukanth\AppData\Roaming\DAEMON Tools Pro
2008-12-29 15:28:39 ----D---- C:\Users\Sukanth\AppData\Roaming\DAEMON Tools
2008-12-29 15:28:01 ----D---- C:\ProgramData\DAEMON Tools Lite
2008-12-29 15:22:33 ----D---- C:\Users\Sukanth\AppData\Roaming\DAEMON Tools Lite
2008-12-24 19:55:41 ----D---- C:\Program Files\danny_kay1710
2008-12-23 00:04:29 ----D---- C:\Users\Sukanth\AppData\Roaming\DivX
2008-12-21 22:56:10 ----D---- C:\Program Files\Common Files\PX Storage Engine
2008-12-19 14:18:33 ----D---- C:\Program Files\Veoh Networks
2008-12-19 11:25:30 ----A---- C:\Windows\system32\mshtml.dll
2008-12-13 11:07:19 ----A---- C:\Windows\system32\javaws.exe
2008-12-13 11:07:19 ----A---- C:\Windows\system32\javaw.exe
2008-12-13 11:07:19 ----A---- C:\Windows\system32\java.exe
2008-12-13 11:07:19 ----A---- C:\Windows\system32\deploytk.dll
2008-12-12 19:04:11 ----A---- C:\Windows\system32\tzres.dll
2008-12-11 21:31:19 ----A---- C:\Windows\system32\gdi32.dll
2008-12-11 21:31:18 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-12-11 21:31:18 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-12-11 21:30:55 ----A---- C:\Windows\system32\shell32.dll
2008-12-11 21:30:49 ----A---- C:\Windows\explorer.exe
2008-12-11 21:30:47 ----A---- C:\Windows\system32\urlmon.dll
2008-12-11 21:30:47 ----A---- C:\Windows\system32\ieframe.dll
2008-12-11 21:30:46 ----A---- C:\Windows\system32\wininet.dll
2008-12-11 21:30:46 ----A---- C:\Windows\system32\mstime.dll
2008-12-11 21:30:46 ----A---- C:\Windows\system32\jsproxy.dll
2008-12-11 21:30:46 ----A---- C:\Windows\system32\iertutil.dll
2008-12-11 21:30:45 ----A---- C:\Windows\system32\WMVCORE.DLL
2008-12-11 21:30:45 ----A---- C:\Windows\system32\mf.dll
2008-12-11 21:30:44 ----A---- C:\Windows\system32\WMNetMgr.dll
2008-12-11 21:30:44 ----A---- C:\Windows\system32\logagent.exe
======List of files/folders modified in the last 2 months======
2009-02-06 14:09:40 ----D---- C:\Windows\Prefetch
2009-02-06 14:09:28 ----D---- C:\Program Files
2009-02-06 14:08:46 ----D---- C:\Windows\Temp
2009-02-06 13:57:42 ----D---- C:\Windows\System32
2009-02-06 13:57:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-02-06 13:57:41 ----D---- C:\Windows\inf
2009-02-06 13:56:03 ----SHD---- C:\System Volume Information
2009-02-06 13:51:36 ----D---- C:\Windows\Minidump
2009-02-06 13:51:29 ----D---- C:\Windows
2009-02-06 13:49:37 ----D---- C:\Program Files\WordWeb
2009-02-06 10:48:16 ----D---- C:\Windows\system32\drivers
2009-02-06 07:17:07 ----SHD---- C:\Windows\Installer
2009-02-05 22:32:08 ----A---- C:\Windows\ntbtlog.txt
2009-02-05 22:31:17 ----D---- C:\Windows\system32\en-US
2009-02-05 21:38:42 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-02-05 21:38:40 ----D---- C:\ProgramData\Symantec
2009-02-05 21:37:52 ----HD---- C:\ProgramData
2009-02-04 21:49:17 ----A---- C:\Windows\BRWMARK.INI
2009-02-04 18:52:51 ----D---- C:\Users\Sukanth\AppData\Roaming\uTorrent
2009-02-02 22:02:40 ----D---- C:\Downloads
2009-02-02 11:03:35 ----SHD---- C:\RECYCLER
2009-02-02 07:10:32 ----D---- C:\Windows\system32\catroot
2009-02-01 12:04:55 ----D---- C:\Windows\system32\catroot2
2009-01-30 16:58:44 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-30 15:54:13 ----D---- C:\Windows\winsxs
2009-01-30 15:53:09 ----D---- C:\Program Files\Common Files
2009-01-30 15:51:34 ----D---- C:\Windows\Registration
2009-01-30 15:51:21 ----RSD---- C:\Windows\assembly
2009-01-30 15:50:50 ----D---- C:\Program Files\Internet Explorer
2009-01-21 18:16:15 ----A---- C:\Windows\BRPP2KA.INI
2009-01-21 18:15:50 ----D---- C:\Windows\twain_32
2009-01-18 00:46:31 ----D---- C:\Users\Sukanth\AppData\Roaming\Free Download Manager
2009-01-17 13:05:47 ----D---- C:\Program Files\Red Kawa
2009-01-14 17:04:52 ----D---- C:\Program Files\Windows Mail
2009-01-10 01:35:28 ----A---- C:\Windows\system32\mrt.exe
2008-12-29 15:53:08 ----D---- C:\Windows\system32\LogFiles
2008-12-23 13:52:56 ----D---- C:\Program Files\ImgBurn
2008-12-22 20:07:01 ----SD---- C:\Users\Sukanth\AppData\Roaming\Microsoft
2008-12-21 22:56:19 ----D---- C:\Program Files\DivX
2008-12-21 21:17:08 ----D---- C:\Windows\system32\WDI
2008-12-20 15:14:31 ----D---- C:\Program Files\Mozilla Firefox
2008-12-19 14:18:38 ----D---- C:\Windows\system32\Tasks
2008-12-14 16:13:18 ----SD---- C:\ProgramData\Microsoft
2008-12-14 16:13:14 ----D---- C:\Program Files\Microsoft.NET
2008-12-14 10:46:57 ----D---- C:\Program Files\Adobe
2008-12-13 11:07:04 ----D---- C:\Program Files\Java
2008-12-12 19:34:10 ----D---- C:\Windows\rescache
2008-12-12 19:11:38 ----D---- C:\Windows\AppPatch
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-02-02 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-02-02 27656]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-02-02 107272]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-19 350720]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\Windows\system32\DRIVERS\AegisP.sys [2007-10-14 17801]
R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-03-27 1761696]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2007-04-11 34832]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2007-04-11 36112]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-11-18 1040544]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-09-17 7379872]
R3 NVR0Dev;NVR0Dev; \??\C:\Windows\nvoclock.sys [2007-04-04 6912]
R3 StillCam;Still Serial Digital Camera Driver; C:\Windows\system32\DRIVERS\serscan.sys [2008-01-19 9216]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service; C:\Windows\system32\DRIVERS\WPN111v.sys [2008-08-04 904192]
S3 a866qiy0;a866qiy0; C:\Windows\system32\drivers\a866qiy0.sys []
S3 catchme;catchme; \??\C:\Users\Sukanth\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 usb_rndisx;USB RNDIS Adapter; C:\Windows\system32\DRIVERS\usb8023x.sys [2008-01-19 15872]
S4 dwshd;dwshd; C:\Windows\System32\drivers\dwshd.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-02 298264]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 MagicTuneEngine;MagicTuneEngine; C:\Program Files\MagicTune Premium\MagicTuneEngine.exe [2007-03-23 45056]
R2 nTuneService;nTune Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2007-04-04 126976]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-09-17 196608]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2008-12-30 66872]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-02-19 504104]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-01-05 33800]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-19 523776]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-19 21504]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-01-19 917504]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.05 2009-02-06 14:09:41
======Uninstall list======
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL
-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL
-->C:\Windows\UNNeroShowTime.exe /UNINSTALL
-->C:\Windows\UNNeroVision.exe /UNINSTALL
-->C:\Windows\UNRecode.exe /UNINSTALL
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player-->C:\Windows\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Adobe\SHOCKW~1\Install.log
Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
AviSynth 2.5-->"C:\Program Files\AviSynth 2.5\Uninstall.exe"
Brother MFL-Pro Suite-->"C:\Program Files\InstallShield Installation Information\{51E89658-5D6B-4F0D-B72B-57863C3AD06C}\Setup.exe" -runfromtemp -l0x0009 Brunin03.dll -removeonly
Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch-->C:\Program Files\InstallShield Installation Information\{5D7767FA-7FE8-4627-9F09-AEF7A25F1E07}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{E5141379-B2D9-4BBC-BB2A-5805541571DD}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch-->C:\Program Files\InstallShield Installation Information\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0409
CDDRV_Installer-->MsiExec.exe /I{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
FLVhosting Desktop FLV Player Ver 2.00-->"C:\Program Files\FLVHosting\Desktop FLV Player 2.00\unins000.exe"
Free Download Manager 2.5-->"C:\Program Files\Free Download Manager\unins000.exe"
GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
Halo 2 for Windows Vista-->C:\Program Files\Microsoft Games\Halo 2\StartUp.exe /tnp:/remove
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
hp LaserJet-all-in-one-->C:\Program Files\hp\Digital Imaging\{1B4B2D13-BA87-4c7c-8B67-0EE7CE698415}\setup\hpzscr01.exe -datfile hpbscr01.dat
ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
iTunes-->MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
IZArc 3.81-->"C:\Program Files\IZArc\unins000.exe"
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
KhalInstallWrapper-->MsiExec.exe /I{56918C0C-0D87-4CA6-92BF-4975A43AC719}
K-Lite Codec Pack 3.4.5 Standard-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
LaserAIO-->MsiExec.exe /I{DD23CAA4-8872-4B95-B263-EA46FD82CF19}
LIVE gaming on Windows Runtime Version 1.0.6027-->MsiExec.exe /X{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}
Logitech Communications Manager-->MsiExec.exe /I{BD202930-5F70-4B35-B875-1E28604F328D}
Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe -runfromtemp -l0x0009 -removeonly
MagicTune Premium-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D6044256-A309-43B5-9833-D3FAFE2AD24D}\setup.exe" -l0x9
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Halo-->"C:\Program Files\Microsoft Games\Halo\UNINSTAL.EXE" /runtemp /addremove
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
Nero 7 Premium-->MsiExec.exe /X{CF097717-F174-4144-954A-FBC4BF301033}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
NVIDIA nTune-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF} /l1033
Orbit Downloader-->"C:\Program Files\Orbitdownloader\unins000.exe"
PC Inspector File Recovery-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}\Setup.exe" -l0x9
PSP ISO Compressor-->MsiExec.exe /X{D47087E7-AA15-4D1D-8C0A-60F7E446D597}
PSP Video 9 4.04-->C:\Program Files\Red Kawa\Video Converter App\uninstaller.exe
QuickTime-->MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Undelete Plus 2.9-->"C:\Program Files\FDRLab\Undelete Plus\unins000.exe"
Veoh Web Player Beta-->"C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe"
VideoLAN VLC media player 0.8.6f-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows Mobile Device Center Driver Update-->MsiExec.exe /X{E7044E25-3038-4A76-9064-344AC038043E}
Windows Mobile Device Center-->MsiExec.exe /X{904CCF62-818D-4675-BC76-D37EB399F917}
WordWeb-->C:\Program Files\WordWeb\uninst.exe
======Hosts File======
127.0.0.1 matrix.bitdefender.com
======Security center information======
AV: BitDefender Antivirus (disabled) (outdated)
FW: BitDefender Firewall (disabled)
AS: BitDefender Antispyware (disabled) (outdated)
AS: Windows Defender (disabled)
System event log
Computer Name: Sukanth-PC
Event Code: 7036
Message: The Volume Shadow Copy service entered the stopped state.
Record Number: 116631
Source Name: Service Control Manager
Time Written: 20090206135926.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 7036
Message: The Microsoft Software Shadow Copy Provider service entered the stopped state.
Record Number: 116632
Source Name: Service Control Manager
Time Written: 20090206140226.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 7036
Message: The Problem Reports and Solutions Control Panel Support service entered the running state.
Record Number: 116633
Source Name: Service Control Manager
Time Written: 20090206140454.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 7036
Message: The Problem Reports and Solutions Control Panel Support service entered the stopped state.
Record Number: 116634
Source Name: Service Control Manager
Time Written: 20090206140454.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 7036
Message: The Windows Modules Installer service entered the stopped state.
Record Number: 116635
Source Name: Service Control Manager
Time Written: 20090206140625.000000-000
Event Type: Information
User:
Application event log
Computer Name: Sukanth-PC
Event Code: 8194
Message: Successfully created restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update).
Record Number: 33935
Source Name: System Restore
Time Written: 20090206135604.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 8194
Message: Successfully created restore point (Process = C:\Windows\system32\svchost.exe -k netsvcs; Description = Windows Update).
Record Number: 33936
Source Name: System Restore
Time Written: 20090206135614.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 1001
Message: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.
Record Number: 33937
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20090206135741.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 1000
Message: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.
Record Number: 33938
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20090206135742.000000-000
Event Type: Information
User:
Computer Name: Sukanth-PC
Event Code: 8224
Message: The VSS service is shutting down due to idle timeout.
Record Number: 33939
Source Name: VSS
Time Written: 20090206135926.000000-000
Event Type: Information
User:
Security event log
Computer Name: Sukanth-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 51453
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206140939.911662-000
Event Type: Audit Failure
User:
Computer Name: Sukanth-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 51454
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206140939.935098-000
Event Type: Audit Failure
User:
Computer Name: Sukanth-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 51455
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206140939.957557-000
Event Type: Audit Failure
User:
Computer Name: Sukanth-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 51456
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206140939.980993-000
Event Type: Audit Failure
User:
Computer Name: Sukanth-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 51457
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090206140940.003453-000
Event Type: Audit Failure
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=2
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
-----------------EOF-----------------