Page 1 of 4 1234 LastLast
Results 1 to 10 of 35

Thread: Win32.Fraudload.edt

  1. #1
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default Win32.Fraudload.edt

    Hey guys Win32.Fraudload.edt got my system. Spybot caught it but can't get rid of it, even on startup. My cpu usage is amped up and video playback pauses occationally (not sure if that is related). This is the first time I've posted to this forum (or any like it), so if you can include detailed instructions that would be great! Thanks guys!


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:55:54 PM, on 9/17/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    C:\Program Files\Dell\QuickSet\Quickset.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Epson Stylus NX510(Network)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFIA.EXE /FU "C:\WINDOWS\TEMP\E_S7C.tmp" /EF "HKCU"
    O4 - Global Startup: HPZRCV01.LNK = C:\Program Files\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzrcv01.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://www.amazon.com
    O15 - Trusted Zone: http://abc.go.com
    O15 - Trusted Zone: http://fep.abc.go.com
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1246088876562
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/...osticsxp2k.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...nt/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Media Center Scheduler Service (ehSched) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SlingAgentService - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
    O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 11240 bytes

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi aasnowbird

    Are both avast! and Trend up-to-date?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    yes. They both auto-update. Should they take care of this?
    THANK YOU for jumping in on this!!!
    Amy

  4. #4
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    Wait, Avast had an update for me. I just downloaded it, but will wait to run the scan until I hear back from you. Here is the info it gave me on the update...

    Information about current update:
    Total time: 1:58

    - Program: Updated
    (previous version: 4.8.1335, updated version: 4.8.1351)
    - Vps: Already up to date
    (current version 090919-0)
    - Setup: Updated
    (previous version: 4.8.1335, updated version: 4.8.1351)

  5. #5
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Thanks for information.

    You should use only one antivirus so one of them should be uninstalled.

    As Trend has firewall I recommend that you uninstall avast!

    Please post a fresh HijackThis log afterwards.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #6
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    okay, i uninstalled avast. What is next? : )


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:01:22 AM, on 9/22/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    C:\Program Files\Dell\QuickSet\Quickset.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [EEventManager] C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Epson Stylus NX510(Network)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFIA.EXE /FU "C:\WINDOWS\TEMP\E_S7C.tmp" /EF "HKCU"
    O4 - Global Startup: HPZRCV01.LNK = C:\Program Files\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzrcv01.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://www.amazon.com
    O15 - Trusted Zone: http://abc.go.com
    O15 - Trusted Zone: http://fep.abc.go.com
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1246088876562
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/...osticsxp2k.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...nt/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: Media Center Scheduler Service (ehSched) - Unknown owner - C:\Program Files\tinyproxy\tinyproxy.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SlingAgentService - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
    O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    --
    End of file - 10313 bytes

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please post next spybot report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #8
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    Okay, I ran spybot and published the report below. I did not ask it to try and fix fraudload (although based on my past experience I doubt it will fix it). Should I run spybot again and ask it to try and fix the problem?
    Again, thank you for your time!
    Amy
    Wait, it says my post is 307275 characters and it needs to be shortened to 64000 characters... what should I do? Break this up to six posts?

  9. #9
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    Here is the first part...

    --- Search result list ---
    Win32.FraudLoad.edt: [SBI $7312D32F] Type library (Registry key, nothing done)
    HKEY_CLASSES_ROOT\TypeLib\{E24211B3-A78A-C6A9-D317-70979ACE5058}


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-08-09 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-09-08 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-09-08 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-09-08 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-09-08 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-09-08 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-09-08 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-09-08 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-09-08 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-09-08 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
    / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB887998)
    / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Hotfix (KB930494)
    / .NETFramework / 1.0: Microsoft .NET Framework 1.0 Service Pack 3
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / Media Center 2005 / SP4: Update Rollup 2 for Windows XP Media Center Edition 2005
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player: Security Update for Windows Media Player (KB968816)
    / Windows Media Player: Security Update for Windows Media Player (KB973540)
    / Windows Media Player 10: Update for Windows Media Player 10 (KB913800)
    / Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
    / Windows Media Player 10: Update for Windows Media Player 10 (KB926251)
    / Windows Media Player 10: Security Update for Windows Media Player 10 (KB936782)
    / Windows Media Player 10 / SP0: Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
    / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
    / Windows Media Player 11: Critical Update for Windows Media Player 11 (KB959772)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB972260)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP3: Security Update for Windows XP (KB929969)
    / Windows XP / SP3: Windows XP Service Pack 3
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Update for Windows XP (KB951072-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Update for Windows XP (KB951978)
    / Windows XP / SP4: Security Update for Windows XP (KB952004)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Security Update for Windows XP (KB953839)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954459)
    / Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956572)
    / Windows XP / SP4: Security Update for Windows XP (KB956744)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB956844)
    / Windows XP / SP4: Security Update for Windows XP (KB957095)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB958690)
    / Windows XP / SP4: Security Update for Windows XP (KB959426)
    / Windows XP / SP4: Security Update for Windows XP (KB960225)
    / Windows XP / SP4: Security Update for Windows XP (KB960715)
    / Windows XP / SP4: Security Update for Windows XP (KB960803)
    / Windows XP / SP4: Security Update for Windows XP (KB960859)
    / Windows XP / SP4: Hotfix for Windows XP (KB961118)
    / Windows XP / SP4: Security Update for Windows XP (KB961371)
    / Windows XP / SP4: Security Update for Windows XP (KB961373)
    / Windows XP / SP4: Security Update for Windows XP (KB961501)
    / Windows XP / SP4: Update for Windows XP (KB967715)
    / Windows XP / SP4: Update for Windows XP (KB968389)
    / Windows XP / SP4: Security Update for Windows XP (KB968537)
    / Windows XP / SP4: Security Update for Windows XP (KB969898)
    / Windows XP / SP4: Security Update for Windows XP (KB970238)
    / Windows XP / SP4: Hotfix for Windows XP (KB970653-v3)
    / Windows XP / SP4: Security Update for Windows XP (KB971557)
    / Windows XP / SP4: Security Update for Windows XP (KB971633)
    / Windows XP / SP4: Security Update for Windows XP (KB971657)
    / Windows XP / SP4: Security Update for Windows XP (KB971961)
    / Windows XP / SP4: Security Update for Windows XP (KB973346)
    / Windows XP / SP4: Security Update for Windows XP (KB973354)
    / Windows XP / SP4: Security Update for Windows XP (KB973507)
    / Windows XP / SP4: Update for Windows XP (KB973815)
    / Windows XP / SP4: Security Update for Windows XP (KB973869)
    / Windows XP OOB / SP10: High Definition Audio Driver Package - KB835221


    --- Startup entries list ---
    Located: HK_LM:Run, AppleSyncNotifier
    command: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    file: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    size: 177440
    MD5: 633B66014DDEDA70C21CFD327BDC214A

    Located: HK_LM:Run, Dell QuickSet
    command: C:\Program Files\Dell\QuickSet\Quickset.exe
    file: C:\Program Files\Dell\QuickSet\Quickset.exe
    size: 1036288
    MD5: 48242949EFADA54F5F405C653A0C4F30

    Located: HK_LM:Run, EEventManager
    command: C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    file: C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    size: 669520
    MD5: 2B5CB6B9ED2DB19F23C26E9BAE652052

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 305440
    MD5: 819892199645F33A680E50F1D5271879

    Located: HK_LM:Run, KernelFaultCheck
    command: %systemroot%\system32\dumprep 0 -k
    file: C:\WINDOWS\system32\dumprep 0 -k
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, NvCplDaemon
    command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    file: C:\WINDOWS\system32\NvCpl.dll
    size: 7557120
    MD5: 05F3C17A97F53853A90611E95DF522C6

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
    file: C:\Program Files\QuickTime\qttask.exe
    size: 417792
    MD5: 8CBD57D84729DEBEE1E83CB5FA3E3D7A

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-939458585-3273499022-1882887361-1005...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: HK_CU:Run, Epson Stylus NX510(Network)
    where: S-1-5-21-939458585-3273499022-1882887361-1005...
    command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFIA.EXE /FU "C:\WINDOWS\TEMP\E_S7C.tmp" /EF "HKCU"
    file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFIA.EXE
    size: 199680
    MD5: 8BE7AF668EDC9C65C11FB367F4B74942

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-939458585-3273499022-1882887361-500...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: Startup (common), HPZRCV01.LNK
    where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
    command: C:\Program Files\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzrcv01.exe
    file: C:\Program Files\HP\Temp\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzrcv01.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), Amazon Unbox (DISABLED)
    command: C:\PROGRA~1\Amazon\AMAZON~1\ADVWIN~2.EXE
    file: C:\PROGRA~1\Amazon\AMAZON~1\ADVWIN~2.EXE
    size: 97320
    MD5: 7A7A703DA9FEF2833AFF6A63FAC266F1

    Located: Startup (disabled), Digital Line Detect (DISABLED)
    command: C:\PROGRA~1\DIGITA~1\DLG.exe
    file: C:\PROGRA~1\DIGITA~1\DLG.exe
    size: 24576
    MD5: B66E56733E2CD6A10FDA5919625FBF46

    Located: Startup (disabled), HP Digital Imaging Monitor (DISABLED)
    command: C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
    file: C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), HP Photosmart Premier Fast Start (DISABLED)
    command: C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe -s
    file: C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), Microsoft Office (DISABLED)
    command: C:\PROGRA~1\MI1933~1\Office10\OSA.EXE -b -l
    file: C:\PROGRA~1\MI1933~1\Office10\OSA.EXE
    size: 83360
    MD5: 5BC65464354A9FD3BEAA28E18839734A

    Located: Startup (disabled), Perstray (DISABLED)
    command: C:\PROGRA~1\PerSono\perstray.exe
    file: C:\PROGRA~1\PerSono\perstray.exe
    size: 40960
    MD5: 6597A8DEF10A1758774737EDA95C3E64

    Located: Startup (disabled), DING! (DISABLED)
    command: C:\PROGRA~1\SOUTHW~1\Ding\Ding.exe
    file: C:\PROGRA~1\SOUTHW~1\Ding\Ding.exe
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Startup (disabled), WKCALREM (DISABLED)
    command: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\WkCalRem.exe
    file: C:\PROGRA~1\COMMON~1\MICROS~1\WORKSS~1\WkCalRem.exe
    size: 21504
    MD5: 2DF216F6E6C2D7DB53CD6098B496D9F6

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, dimsntfy
    command: %SystemRoot%\System32\dimsntfy.dll
    file: %SystemRoot%\System32\dimsntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, GoToAssist
    command: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    file: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    size: 10536
    MD5: 715CAAE7D5128B6EFF34D31E18C94BA7

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: AcroIEHelperStub
    CLSID name: Adobe PDF Link Helper
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelperShim.dll
    Short name: ACROIE~2.DLL
    Date (created): 2/27/2009 12:07:26 PM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 2/27/2009 12:07:26 PM
    Filesize: 75128
    Attributes: archive
    MD5: 5CF6190CD875DA6B35256FEE573E7908
    CRC32: 764BA81B
    Version: 9.1.0.163

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\PROGRA~1\SPYBOT~1\
    Long name: SDHelper.dll
    Short name:
    Date (created): 8/9/2009 5:24:16 PM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 1/26/2009 3:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: DriveLetterAccess
    description: Hewlett-Packard's DLA software
    classification: Unknown
    known filename: tfswshx.dll
    info link:
    info source: TonyKlein
    Path: C:\WINDOWS\System32\DLA\
    Long name: DLASHX_W.DLL
    Short name:
    Date (created): 5/20/2007 5:13:30 PM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 9/8/2005 3:20:00 AM
    Filesize: 110652
    Attributes: archive
    MD5: 8EF6619212E5500022AB22FF11E68D3B
    CRC32: 132215F0
    Version: 5.20.8.0

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: SSVHelper Class
    Path: C:\Program Files\Java\jre1.5.0_06\bin\
    Long name: ssv.dll
    Short name:
    Date (created): 3/2/2006 11:53:00 AM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 11/10/2005 11:22:12 AM
    Filesize: 184423
    Attributes: archive
    MD5: F01726F7CA8538FDD4663C9DB8FEAEDC
    CRC32: 0111B892
    Version: 5.0.60.5



    --- ActiveX list ---
    {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5)
    DPF name:
    CLSID name: Facebook Photo Uploader 5
    Installer: C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf
    Codebase: http://upload.facebook.com/controls/...oUploader5.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: ImageUploader5.ocx
    Short name: IMAGEU~1.OCX
    Date (created): 4/9/2008 3:27:42 PM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 4/9/2008 3:27:42 PM
    Filesize: 3175136
    Attributes: archive
    MD5: C34D0189E37CDE86947B889FBEB81C7A
    CRC32: DAEE829D
    Version: 5.1.11.0

    {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia)
    DPF name:
    CLSID name: Snapfish Activia
    Installer: C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.inf
    Codebase: http://www1.snapfish.com/SnapfishActivia.cab
    description:
    classification: Legitimate
    known filename: SnapfishActivia1000.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: SnapfishActivia1000.ocx
    Short name: SNAPFI~1.OCX
    Date (created): 6/3/2005 1:24:32 PM
    Date (last access): 9/22/2009 12:50:40 PM
    Date (last write): 6/3/2005 1:24:32 PM
    Filesize: 286720
    Attributes: archive
    MD5: F5C79C45F1ADF877DC3AFDFF3565AE7B
    CRC32: F118547A
    Version: 1.0.0.10

    {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object)
    DPF name:
    CLSID name: DivXBrowserPlugin Object
    Installer: C:\WINDOWS\Downloaded Program Files\DivXPlugin.inf
    Codebase: http://download.divx.com/player/DivXBrowserPlugin.cab
    description:
    classification: Legitimate
    known filename: npdivx32.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\DivX\DivX Web Player\
    Long name: npdivx32.dll
    Short name:
    Date (created): 6/10/2008 5:03:12 PM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 6/10/2008 5:03:12 PM
    Filesize: 1335600
    Attributes: archive
    MD5: 56E18C09654020009012A53FD332D397
    CRC32: 56B7CC16
    Version: 1.4.0.233

    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
    DPF name:
    CLSID name: MUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
    Codebase: http://update.microsoft.com/microsof...?1246088876562
    description:
    classification: Legitimate
    known filename: muweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: muweb.dll
    Short name:
    Date (created): 10/16/2008 2:07:48 PM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 10/16/2008 2:07:48 PM
    Filesize: 208744
    Attributes: archive
    MD5: 90058C2AD9FC43A3B3D59F82FFC6AEA7
    CRC32: 7D5F90FA
    Version: 7.2.6001.788

    {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager)
    DPF name:
    CLSID name: HP Download Manager
    Installer: C:\WINDOWS\Downloaded Program Files\HPDEXAXO.inf
    Codebase: https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: HPDEXAXO.dll
    Short name:
    Date (created): 10/18/2007 10:04:16 AM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 10/18/2007 10:04:16 AM
    Filesize: 341296
    Attributes: archive
    MD5: CDE357CD3FC047F5C7D8B8345B6A42BF
    CRC32: 7ABDC22F
    Version: 1.0.5.1

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_06
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre1.5.0_06\bin\
    Long name: NPJPI150_06.dll
    Short name: NPJPI1~1.DLL
    Date (created): 3/2/2006 11:52:58 AM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 11/10/2005 11:22:12 AM
    Filesize: 69746
    Attributes: archive
    MD5: D2CF6BB5E9020E6707B62575F8083954
    CRC32: 7F39DC54
    Version: 5.0.60.5

    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class)
    DPF name:
    CLSID name: DDRevision Class
    Installer: C:\WINDOWS\Downloaded Program Files\setup.inf
    Codebase: http://h20264.www2.hp.com/ediags/dd/...osticsxp2k.cab
    Path: C:\Program Files\Hp\Common\
    Long name: HPDDRev.dll
    Short name:
    Date (created): 7/29/2008 10:13:46 AM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 7/29/2008 10:13:46 AM
    Filesize: 98096
    Attributes: archive
    MD5: 328D304127C392783F91572FB5152306
    CRC32: D579362F
    Version: 8.4.11.0

    {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_06
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.5.0_06\bin\
    Long name: NPJPI150_06.dll
    Short name: NPJPI1~1.DLL
    Date (created): 3/2/2006 11:52:58 AM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 11/10/2005 11:22:12 AM
    Filesize: 69746
    Attributes: archive
    MD5: D2CF6BB5E9020E6707B62575F8083954
    CRC32: 7F39DC54
    Version: 5.0.60.5

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
    DPF name: Java Runtime Environment 1.5.0
    CLSID name: Java Plug-in 1.5.0_06
    Installer:
    Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre1.5.0_06\bin\
    Long name: NPJPI150_06.dll
    Short name: NPJPI1~1.DLL
    Date (created): 3/2/2006 11:52:58 AM
    Date (last access): 9/22/2009 12:50:42 PM
    Date (last write): 11/10/2005 11:22:12 AM
    Filesize: 69746
    Attributes: archive
    MD5: D2CF6BB5E9020E6707B62575F8083954
    CRC32: 7F39DC54
    Version: 5.0.60.5

    {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} ()
    DPF name:
    CLSID name:
    Installer:
    Codebase:

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload2.macromedia.com/ge...nt/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash10c.ocx
    Short name:
    Date (created): 7/17/2009 8:12:12 PM
    Date (last access): 9/22/2009 12:41:32 PM
    Date (last write): 7/17/2009 8:12:12 PM
    Filesize: 3979680
    Attributes: readonly archive
    MD5: 43C6ACDFB92A18C3E516E6BD5F1ACD51
    CRC32: D6F40D46
    Version: 10.0.32.18

  10. #10
    Junior Member
    Join Date
    Sep 2009
    Posts
    23

    Default

    Part 2...
    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 800 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 856 ( 800) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 880 ( 800) \??\C:\WINDOWS\system32\winlogon.exe
    size: 507904
    PID: 924 ( 880) C:\WINDOWS\system32\services.exe
    size: 110592
    MD5: 65DF52F5B8B6E9BBD183505225C37315
    PID: 936 ( 880) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: BF2466B3E18E970D8A976FB95FC1CA85
    PID: 1148 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1216 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1360 ( 924) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1396 ( 924) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    size: 434176
    MD5: 788C72B145C75A7EE5F5D6A32542D912
    PID: 1624 ( 924) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    size: 946176
    MD5: C17C3A529CE14012F9731A6E264C1911
    PID: 1648 ( 924) C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    size: 290816
    MD5: 22516ED8E0D89323D4E0D9CCC2848819
    PID: 1692 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1824 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 156 ( 924) C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    size: 1029456
    MD5: CC7D978C4F56FB434E841D35788A7F3C
    PID: 248 ( 924) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    PID: 300 ( 924) C:\WINDOWS\System32\SCardSvr.exe
    size: 95744
    MD5: 86D007E7A654B9A71D1D7D856B104353
    PID: 376 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 484 ( 924) C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    size: 94208
    MD5: ABDD5AD016AFFD34AD40E944CE94BF59
    PID: 636 ( 924) C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
    size: 25640
    MD5: E111E51C5FB8627A61E76BDE63B5D810
    PID: 680 ( 924) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    size: 144672
    MD5: 4B5AE15E5C73EB4DC8DBEC2788230D41
    PID: 696 ( 924) C:\Program Files\Bonjour\mDNSResponder.exe
    size: 238888
    MD5: 3F56903E124E820AEECE6D471583C6C1
    PID: 724 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 736 ( 924) C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    size: 69632
    MD5: 7DB5E3F44D797BD38B8E336CCC2E49D5
    PID: 760 ( 924) C:\WINDOWS\system32\CTsvcCDA.exe
    size: 44032
    MD5: 3C8B6609712F4FF78E521F6DCFC4032B
    PID: 1296 ( 924) C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    size: 380928
    MD5: 20841C9F01CE3201748A0351380E1B56
    PID: 1464 ( 924) C:\WINDOWS\system32\nvsvc32.exe
    size: 143428
    MD5: D54292149E9ED49AD149879B67EC24D1
    PID: 1504 ( 924) C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    size: 880722
    MD5: 30974C7E29CB115A89FFB2CCB5F89F88
    PID: 1732 ( 924) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    size: 327680
    MD5: D8894ACEFE1A607DE7D0E628285BFFF4
    PID: 2300 (2164) C:\WINDOWS\Explorer.EXE
    size: 1033728
    MD5: 12896823FB95BFB3DC9B46BCAEDC9923
    PID: 2744 ( 924) C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe
    size: 93960
    MD5: E4C52BEDD357C68A91B500959CEC9F5E
    PID: 2788 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 2800 ( 924) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 2828 ( 924) C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
    size: 867328
    MD5: 9196FEE3A02D16F2726813BDA31957E0
    PID: 2944 ( 924) C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    size: 290889
    MD5: 37C406BAC6896D504E054BBFAA120D79
    PID: 3032 ( 924) C:\WINDOWS\ehome\mcrdsvc.exe
    size: 99328
    MD5: DF0A511F38F16016BF658FCA0090CB87
    PID: 3464 ( 924) C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    size: 585792
    MD5: 70EE53C6E1B5402C5CE0F12D038B0F4C
    PID: 3540 (2300) C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
    size: 669520
    MD5: 2B5CB6B9ED2DB19F23C26E9BAE652052
    PID: 3552 (2300) C:\Program Files\Dell\QuickSet\Quickset.exe
    size: 1036288
    MD5: 48242949EFADA54F5F405C653A0C4F30
    PID: 3668 (2300) C:\Program Files\iTunes\iTunesHelper.exe
    size: 305440
    MD5: 819892199645F33A680E50F1D5271879
    PID: 3676 (2300) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
    PID: 3884 (1148) C:\WINDOWS\system32\wbem\wmiprvse.exe
    size: 227840
    MD5: 798A9E6828997EEF4517ADA8A2259831
    PID: 2900 ( 924) C:\Program Files\iPod\bin\iPodService.exe
    size: 545568
    MD5: DC434081FBFD27C719473CB0CCE8DECA
    PID: 2920 (1148) C:\WINDOWS\system32\wbem\unsecapp.exe
    size: 16896
    MD5: C7000F2DB2A5515C64C257478769A481
    PID: 3320 (1504) C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
    size: 823362
    MD5: 1DA0FDF5EE35C39145D464F06DC798AE
    PID: 3612 ( 924) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: 8C515081584A38AA007909CD02020B3D
    PID: 2148 (1148) C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    size: 479232
    MD5: 7F78688D56C1A1E5B8FEF897AE1F83FD
    PID: 2872 ( 156) C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    size: 520024
    MD5: 2CD3C21B57B2B1E5CC4C82519461C9D2
    PID: 1912 (2300) C:\Program Files\Internet Explorer\iexplore.exe
    size: 634632
    MD5: 3CFC56F73D494FC1AA2B6E981DF15ACD
    PID: 2396 (2300) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 9/22/2009 1:14:36 PM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.google.com
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
    http://www.google.com/ie
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://www.google.com/ie
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://www.google.com/search?q=%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    %SystemRoot%\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    about:blank
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 3: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP



    --- Uninstall list ---
    Panda ActiveScan 2.0 01.03.00.0000 (ActiveScan 2.0)
    estimated size: 4000
    install location: C:\Program Files\Panda Security\ActiveScan 2.0
    uninstall cmd: C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
    publisher: Panda Security
    help link: http://www.pandasecurity.com/activescan/help/

    Ad-Aware (Ad-Aware)
    install location: C:\Program Files\Lavasoft\Ad-Aware
    uninstall cmd: "C:\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
    publisher: Lavasoft
    comments: All rights reserved
    help link: http://www.lavasoft.com/support/supportcenter

    Adobe AIR 1.5.0.7220 (Adobe AIR)
    install location: C:\
    uninstall cmd: C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
    publisher: Adobe Systems Inc.

    Adobe Flash Player 10 ActiveX 10.0.32.18 (Adobe Flash Player ActiveX)
    uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    publisher: Adobe Systems Incorporated
    help link: http://www.adobe.com/go/flashplayer_support/

    Adobe Flash Player 10 Plugin 10.0.22.87 (Adobe Flash Player Plugin)
    uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    publisher: Adobe Systems Incorporated

    (AudioPlugin.dll)
    uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}

    Otto (B3EE3001-DC24-4cd1-8743-5692C716659F)
    uninstall cmd: "C:\Program Files\EnglishOtto\uninstallotto.exe"

    BlackBerry Desktop Software 4.3 4.3.0.17 (BlackBerry_{C178B38F-613A-4EFE-B718-A675BD27A1E1})
    version: 67108864
    version (major): 4
    install location: C:\Program Files\Research In Motion\BlackBerry\
    install source: D:\files\exec\bbinstaller\
    uninstall cmd: MsiExec.exe /i{C178B38F-613A-4EFE-B718-A675BD27A1E1}
    publisher: Research In Motion Ltd.

    (CADI)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove

    Conexant HDA D110 MDC V.92 Modem (CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3)
    uninstall cmd: C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3\HXFSETUP.EXE -U -Idel1028p.inf

    (CopyNow.dll)
    uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}

    Creative Audio Pack (Creative Audio Pack)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5EEE551B-7692-4D68-91BF-DAD745243AFB}\setup.exe" -l0x9 /remove

    (Creative MediaSource Go!)
    uninstall cmd: "C:\Program Files\Creative Installation Information\CTCMSGO\Setup.exe" /remove /l0x0009

    (Creative MediaSource Net Content Plugin Unicode)
    uninstall cmd: "C:\Program Files\Creative Installation Information\E-CENTER_NET_CONTENT_U\Setup.exe" /remove /l0x0009

    (Creative MediaSource Unicode)
    uninstall cmd: "C:\Program Files\Creative Installation Information\CREATIVE_MEDIASOURCE_U\Setup.exe" /remove /l0x0009

    (Creative Restore Defaults)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34EBD418-B8E6-4E86-89C4-33B72CF5663F}\setup.exe" -l0x9 /remove

    (Creative WaveStudio)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{569A9538-86EC-44C3-8EE4-C68B165F2A75}\setup.exe" -l0x9 /remove

    (DataPlugin.dll)
    uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}

    (DirectDrawEx)

    (dlatray.exe)
    uninstall cmd: C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}

    Personal License Update Wizard for Windows Media Player (drmtool.inf)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\drmtool.inf,DefaultUninstall

    (DXM_Runtime)

    (EAXSet)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C64409FA-42A7-49C6-837A-D2E5D813BD57}\setup.exe" -l0x9 /remove

    Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] (EmeraldQFE2)
    uninstall cmd: C:\WINDOWS\$NtUninstallEmeraldQFE2$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=2

    EPSON NX510 Series Printer Uninstall (EPSON NX510 Series)
    uninstall cmd: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FINSFIA.EXE /R /APD /P:"EPSON NX510 Series"
    publisher: SEIKO EPSON Corporation

    (EPSON Printer and Utilities)

    EPSON Scan (EPSON Scanner)
    uninstall cmd: C:\Program Files\epson\escndv\setup\setup.exe /r

    (Equalizer)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{52338F65-A1C3-4CDC-B733-50051682B297}\setup.exe" -l0x9 /remove

    ERUNT 1.1j (ERUNT_is1)
    install location: C:\Program Files\ERUNT\
    uninstall cmd: "C:\Program Files\ERUNT\unins000.exe"
    publisher: Lars Hederer
    help link: http://www.larshederer.homepage.t-online.de/erunt

    (Fontcore)

    GoToAssist 8.0.0.514 (GoToAssist)
    uninstall cmd: C:\Program Files\Citrix\GoToAssist\514\G2AUninstaller.exe /uninstall

    Guitar Pro 5.2 (Guitar Pro 5_is1)
    install location: C:\Program Files\Guitar Pro 5\
    uninstall cmd: "C:\Program Files\Guitar Pro 5\unins000.exe"
    publisher: Arobas Music
    help link: http://www.guitar-pro.com

    HijackThis 2.0.2 2.0.2 (HijackThis)
    uninstall cmd: "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    publisher: TrendMicro

    OCR Software by I.R.I.S 7.0 7.0 (HPOCR)
    uninstall cmd: C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
    publisher: HP
    help link: http://www.hp.com/support

    Microsoft Internationalized Domain Names Mitigation APIs (IDNMitigationAPIs)
    install date: 20070617
    uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation

    (IE40)

    (IE4Data)

    (IE5BAKEX)

    Windows Internet Explorer 7 20061107.210142 (ie7)
    install date: 20070617
    publisher: Microsoft Corporation
    help link: http://www.microsoft.com/ie

    (IEData)

    (InstallShield Uninstall Information)

    XTV2.0 2.0.4.9 (InstallShield_{07637294-FDF0-4D20-8591-C5D1B1908FD5})
    version: 33554436
    version (major): 2
    estimated size: 22743
    install date: 20080228
    install source: C:\WINDOWS\Downloaded Installations\{00419BDB-6F92-473D-89BF-C35E911873A0}\
    uninstall cmd: C:\Program Files\InstallShield Installation Information\{07637294-FDF0-4D20-8591-C5D1B1908FD5}\setup.exe -runfromtemp -l0x0409
    publisher: VideoHome
    comments: Your Comments
    contact: Customer Support Department
    help link: http://www.yourcompany.com/help
    help telephone: 1-555-555-4505
    readme: Readme.txt

    AVerDVD EZMaker USB 2.0 Driver 1.00.0000 (InstallShield_{1A22C818-D44D-4691-BF27-8884CB5B44B1})
    version: 16777216
    version (major): 1
    estimated size: 4736
    install date: 20080222
    install source: C:\DOCUME~1\AMYBAB~1\LOCALS~1\Temp\_is6B\
    uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1A22C818-D44D-4691-BF27-8884CB5B44B1} /l1033
    publisher: AVerMedia
    comments: Your Comments
    contact: Customer Support Department
    help link: http://www.aver.com.tw
    help telephone: 886-2-2226-3630

    Movie Magic Screenwriter 4.6.05 (InstallShield_{2D8A75A0-6097-41EC-AE41-AB5505DC3384})
    version: 67502085
    version (major): 4
    version (minor): 6
    estimated size: 35838
    install date: 20070520
    install source: D:\
    uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2D8A75A0-6097-41EC-AE41-AB5505DC3384}
    publisher: Write Brothers, Inc.
    comments: Support Hours: 8:30 am to 12:00 pm and 1:30 pm to 5:00pm PT, Mon-Fri except holidays
    contact: Customer Support Department
    help link: http://www.screenplay.com/support
    help telephone: 1-818-843-7819
    readme: http://www.screenplay.com/support

    SlingPlayer 2.0.3508 (InstallShield_{3D08333C-C366-425D-8C2D-D05630D68A46})
    version: 33557940
    version (major): 2
    estimated size: 32524
    install date: 20090913
    install location: C:\Program Files\Sling Media\SlingPlayer\
    install source: C:\WINDOWS\Downloaded Installations\{6A3296C3-6F01-424A-8634-CC7DDC4D7105}\
    uninstall cmd: "C:\Program Files\InstallShield Installation Information\{3D08333C-C366-425D-8C2D-D05630D68A46}\setup.exe" -runfromtemp -l0x0409 -removeonly
    publisher: Sling Media
    help link: http://www.slingmedia.com/support/

    Amazon Unbox Video 2.0.0.59 (InstallShield_{54A4839E-87F8-4BD1-9682-A349E9943F0A})
    version: 33554432
    version (major): 2
    estimated size: 6816
    install date: 20071207
    install location: C:\Program Files\Amazon\Amazon Unbox Video\
    install source: C:\WINDOWS\Downloaded Installations\{BB7CFAD4-0F7B-4900-AC68-8D343552178A}\
    uninstall cmd: C:\Program Files\InstallShield Installation Information\{54A4839E-87F8-4BD1-9682-A349E9943F0A}\setup.exe -runfromtemp -l0x0409
    publisher: Amazon.com
    help link: http://www.amazon.com

    InterActual Player (InterActual Player)
    uninstall cmd: C:\Program Files\InterActual\InterActual Player\inuninst.exe

    High Definition Audio Driver Package - KB835221 20040219.000000 (KB835221WXP)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=KB835221

    (KB885884)

    Windows Media Format SDK Hotfix - KB891122 (KB891122)
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=891122

    Update Rollup 2 for Windows XP Media Center Edition 2005 (KB900325)
    uninstall cmd: C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=900325

    Hotfix for Windows Media Player 10 (KB903157) (KB903157)
    install date: 20050816
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=903157

    Windows XP Media Center Edition 2005 KB908246 (KB908246)
    install date: 20070520
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB908246$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=908246

    Update for Windows Media Player 10 (KB913800) (KB913800)
    install date: 20070601
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=913800

    Security Update for Windows Media Player 10 (KB917734) (KB917734_WMP10)
    install date: 20070601
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=917734

    Windows XP Media Center Edition 2005 KB925766 (KB925766)
    install date: 20070921
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=925766

    Update for Windows Media Player 10 (KB926251) (KB926251)
    install date: 20070601
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=926251

    Hotfix for Windows Media Format 11 SDK (KB929399) (KB929399)
    install date: 20070922
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=929399

    Security Update for CAPICOM (KB931906) 2.1.0.2 (KB931906)
    uninstall cmd: MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=931906

    Security Update for Windows Internet Explorer 7 (KB933566) 1 (KB933566-IE7)
    install date: 20070618
    uninstall cmd: "C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=933566

    Security Update for Windows Media Player 10 (KB936782) (KB936782_WMP10)
    install date: 20070815
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=936782

    Security Update for Windows Media Player 11 (KB936782) (KB936782_WMP11)
    install date: 20070922
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=936782

    Security Update for Windows Internet Explorer 7 (KB937143) 1 (KB937143-IE7)
    install date: 20070815
    uninstall cmd: "C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=937143

    Security Update for Windows Internet Explorer 7 (KB938127) 1 (KB938127-IE7)
    install date: 20070815
    uninstall cmd: "C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=938127

    Security Update for Windows XP (KB938464) 1 (KB938464)
    install date: 20080910
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=938464

    Security Update for Windows Internet Explorer 7 (KB939653) 1 (KB939653-IE7)
    install date: 20071010
    uninstall cmd: "C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=939653

    Hotfix for Windows Media Player 11 (KB939683) (KB939683)
    install date: 20070922
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=939683

    Security Update for Windows XP (KB941569) (KB941569)
    install date: 20071212
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=941569

    Security Update for Windows Internet Explorer 7 (KB942615) 1 (KB942615-IE7)
    install date: 20071212
    uninstall cmd: "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=942615

    Security Update for Windows Internet Explorer 7 (KB944533) 1 (KB944533-IE7)
    install date: 20080213
    uninstall cmd: "C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=944533

    Security Update for Windows XP (KB946648) 1 (KB946648)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=946648

    Security Update for Windows XP (KB950762) 1 (KB950762)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=950762

    Security Update for Windows XP (KB950974) 1 (KB950974)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=950974

    Security Update for Windows XP (KB951066) 1 (KB951066)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951066

    Update for Windows XP (KB951072-v2) 2 (KB951072-v2)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951072

    Security Update for Windows XP (KB951376-v2) 2 (KB951376-v2)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951376

    Security Update for Windows XP (KB951698) 1 (KB951698)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951698

    Security Update for Windows XP (KB951748) 1 (KB951748)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951748

    Update for Windows XP (KB951978) 1 (KB951978)
    install date: 20080908
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=951978

    Security Update for Windows XP (KB952004) 1 (KB952004)
    install date: 20090415
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=952004

    Security Update for Windows Media Player (KB952069) (KB952069_WM9)
    install date: 20090115
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=952069

    Hotfix for Windows XP (KB952287) 1 (KB952287)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=952287

    Security Update for Windows XP (KB952954) 1 (KB952954)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=952954

    Security Update for Windows Internet Explorer 7 (KB953838) 1 (KB953838-IE7)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=953838

    Security Update for Windows XP (KB953839) 1 (KB953839)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=953839

    Security Update for Windows Media Player 11 (KB954154) (KB954154_WM11)
    install date: 20080910
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=954154

    Security Update for Windows XP (KB954211) 1 (KB954211)
    install date: 20081015
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954211

    Security Update for Windows XP (KB954459) 1 (KB954459)
    install date: 20081113
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954459

    Hotfix for Windows XP (KB954550-v5) 5 (KB954550-v5)
    install date: 20090331
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954550

    Security Update for Windows XP (KB954600) 1 (KB954600)
    install date: 20090115
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=954600

    Security Update for Windows XP (KB955069) 1 (KB955069)
    install date: 20081113
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=955069

    Update for Windows XP (KB955839) 1 (KB955839)
    install date: 20090115
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=955839

    Security Update for Windows Internet Explorer 7 (KB956390) 1 (KB956390-IE7)
    install date: 20081016
    uninstall cmd: "C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956390

    Security Update for Windows XP (KB956391) 1 (KB956391)
    install date: 20081015
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956391

    Security Update for Windows XP (KB956572) 1 (KB956572)
    install date: 20090415
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956572

    Security Update for Windows XP (KB956744) 1 (KB956744)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956744

    Security Update for Windows XP (KB956802) 1 (KB956802)
    install date: 20090115
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956802

    Security Update for Windows XP (KB956803) 1 (KB956803)
    install date: 20081015
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956803

    Security Update for Windows XP (KB956841) 1 (KB956841)
    install date: 20081016
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956841

    Security Update for Windows XP (KB956844) 1 (KB956844)
    install date: 20090909
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=956844

    Security Update for Windows XP (KB957095) 1 (KB957095)
    install date: 20081015
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=957095

    Security Update for Windows XP (KB957097) 1 (KB957097)
    install date: 20081113
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=957097

    Security Update for Windows XP (KB958644) 1 (KB958644)
    install date: 20081024
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958644

    Security Update for Windows XP (KB958687) 1 (KB958687)
    install date: 20090115
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958687

    Security Update for Windows XP (KB958690) 1 (KB958690)
    install date: 20090323
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=958690

    Security Update for Windows XP (KB959426) 1 (KB959426)
    install date: 20090415
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=959426

    Critical Update for Windows Media Player 11 (KB959772) (KB959772_WM11)
    install date: 20090323
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=959772

    Security Update for Windows XP (KB960225) 1 (KB960225)
    install date: 20090323
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=960225

    Security Update for Windows XP (KB960715) 1 (KB960715)
    install date: 20090211
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=960715

    Security Update for Windows XP (KB960803) 1 (KB960803)
    install date: 20090415
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=960803

    Security Update for Windows XP (KB960859) 1 (KB960859)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=960859

    Hotfix for Windows XP (KB961118) 1 (KB961118)
    install date: 20090401
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=961118

    Security Update for Windows XP (KB961371) 1 (KB961371)
    install date: 20090715
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=961371

    Security Update for Windows XP (KB961373) 1 (KB961373)
    install date: 20090415
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=961373

    Security Update for Windows XP (KB961501) 1 (KB961501)
    install date: 20090611
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=961501

    Update for Windows XP (KB967715) 1 (KB967715)
    install date: 20090225
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=967715

    Update for Windows XP (KB968389) 1 (KB968389)
    install date: 20090822
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=968389

    Security Update for Windows XP (KB968537) 1 (KB968537)
    install date: 20090611
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=968537

    Security Update for Windows Media Player (KB968816) (KB968816_WM9)
    install date: 20090909
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=968816

    Security Update for Windows Internet Explorer 7 (KB969897) 1 (KB969897-IE7)
    install date: 20090627
    uninstall cmd: "C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=969897

    Security Update for Windows XP (KB969898) 1 (KB969898)
    install date: 20090611
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=969898

    Security Update for Windows XP (KB970238) 1 (KB970238)
    install date: 20090611
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=970238

    Hotfix for Windows XP (KB970653-v3) 3 (KB970653-v3)
    install date: 20090826
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=970653

    Security Update for Windows XP (KB971557) 1 (KB971557)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=971557

    Security Update for Windows XP (KB971633) 1 (KB971633)
    install date: 20090715
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=971633

    Security Update for Windows XP (KB971657) 1 (KB971657)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=971657

    Security Update for Windows XP (KB971961) 1 (KB971961)
    install date: 20090909
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=971961

    Security Update for Windows Internet Explorer 7 (KB972260) 1 (KB972260-IE7)
    install date: 20090729
    uninstall cmd: "C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=972260

    Security Update for Windows XP (KB973346) 1 (KB973346)
    install date: 20090715
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973346

    Security Update for Windows XP (KB973354) 1 (KB973354)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973354

    Security Update for Windows XP (KB973507) 1 (KB973507)
    install date: 20090813
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973507

    Security Update for Windows Media Player (KB973540) (KB973540_WM9)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com/?kbid=973540

    Windows XP Media Center Edition 2005 KB973768 (KB973768)
    install date: 20090909
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973768$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973768

    Update for Windows XP (KB973815) 1 (KB973815)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973815

    Security Update for Windows XP (KB973869) 1 (KB973869)
    install date: 20090812
    uninstall cmd: "C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=973869

    K-Lite Codec Pack 3.4.5 Standard 3.45 (KLiteCodecPack_is1)
    install date: 20070923
    install location: C:\Program Files\K-Lite Codec Pack\
    uninstall cmd: "C:\Program Files\K-Lite Codec Pack\unins000.exe"

    Microsoft .NET Framework 1.1 Hotfix (KB928366) (M928366)
    uninstall cmd: "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"

    Macromedia Shockwave Player (Macromedia Shockwave Player)
    uninstall cmd: C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log

    MasterWriter (MasterWriter)
    uninstall cmd: C:\WINDOWS\unvise32.exe C:\Program Files\MasterWriter\uninstal.log

    Microsoft .NET Framework 1.1 (Microsoft .NET Framework 1.1 (1033))
    uninstall cmd: msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    readme: file://C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\1033\RepairRedist.htm

    Microsoft .NET Framework 3.5 SP1 (Microsoft .NET Framework 3.5 SP1)
    install location: C:\WINDOWS\Microsoft.NET\Framework\v3.5\
    uninstall cmd: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=120337

    Windows Media Tools 4.0 (Microsoft NetShow Tools 2.0)
    uninstall cmd: C:\Program Files\Windows Media Components\Tools\_insttoo.exe /U

    Movie Maker Background Music Files (mmmusic)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmmusic.inf,DefaultUninstall

    Movie Maker Sound Effects (mmsounds)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmsounds.inf,DefaultUninstall

    Movie Maker Title Images (mmtitle)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmtitle.inf,DefaultUninstall

    (MobileOptionPack)

    Mozilla Firefox (3.0.14) 3.0.14 (en-US) (Mozilla Firefox (3.0.14))
    install location: C:\Program Files\Mozilla Firefox
    uninstall cmd: C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    publisher: Mozilla
    comments: Mozilla Firefox

    (MPlayer2)

    Media Library Management Wizard (mplibwiz.inf)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplibwiz.inf,DefaultUninstall

    Windows Media Player Playlist Import to Excel Wizard (mpxlswiz.inf)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mpxlswiz.inf,DefaultUninstall

    Windows Media Player Tray Control (mpxptray.inf)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mpxptray.inf,DefaultUninstall

    Microsoft Compression Client Pack 1.0 for Windows XP 1 (MSCompPackV1)
    install date: 20070921
    uninstall cmd: "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?LinkId=74087

    Microsoft Text-to-Speech Engine 4.0 (English) (MSTTS)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTS.inf, Uninstall

    Microsoft National Language Support Downlevel APIs (NLSDownlevelMapping)
    install date: 20070617
    uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation

    NVIDIA Drivers (NVIDIA Drivers)
    uninstall cmd: C:\WINDOWS\system32\nvudisp.exe UninstallGUI

    (PCHealth)
    uninstall cmd: rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf

    Microsoft Digital Image Standard 2006 11.0.0422 (PictureItPrem_v11)
    install location: C:\Program Files\Microsoft Digital Image 2006\
    install source: d:\pip\pod\
    uninstall cmd: "C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM VERSION=11
    publisher: Microsoft Corporation
    help link: http://go.microsoft.com/fwlink/?prd=...&sar=PictureIt

    Intel(R) PROSet/Wireless Software 10.5.1.0 (ProInst)
    install location: C:\WINDOWS\Installer\iProInst.exe
    uninstall cmd: C:\WINDOWS\Installer\iProInst.exe
    publisher: Intel Corporation
    comments: Intel(R) PROSet/Wireless installation package
    contact: Intel Customer Support
    help link: http://support.intel.com

    Microsoft Office Professional 2007 Trial 12.0.6425.1000 (PROR)
    install location: C:\Program Files\Microsoft Office
    uninstall cmd: "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
    publisher: Microsoft Corporation

    Sound Blaster ADVANCED MB Drivers (SAMB_ADVMB_FILTER_DRV)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{943884D4-B604-496F-B132-DFA9C63FAF6A}\setup.exe" -l0x9 /remove

    (SchedulingAgent)

    (SFBM)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{73919E2B-725C-4FAA-8473-45E063A3575F}\setup.exe" -l0x9 /remove

    Sound Blaster Audigy ADVANCED MB Product Registration (Sound Blaster Audigy ADVANCED MB Product Registration)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EEEF992E-270C-4B4C-8389-4B3DEEE33190}\Setup.exe" -l0x9 /remove

    (Sound Blaster Audigy ADVANCED MB Windows Drivers)
    uninstall cmd: "C:\Program Files\Creative\SBAudigy\Program\CTZapxx.EXE" ctsbmb.ini /U /N /S /W

    (SPEAKER)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{32B4B536-4443-42F0-9676-98373BE9114F}\setup.exe" -l0x9 /remove

    Ss Registry Fixer 2.0 (Ss Registry Fixer_is1)
    install date: 20081129
    install location: C:\Program Files\Ss-Tools\Registry Fixer\
    uninstall cmd: "C:\Program Files\Ss-Tools\Registry Fixer\unins000.exe"
    publisher: Ss-Tools, Inc
    help link: http://www.ss-tools.com/registry-fixer/

    (SURMIXER)
    uninstall cmd: RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE4A4C48-2232-4CCB-AD61-490ACD29BA85}\setup.exe" -l0x9 /remove

    Synaptics Pointing Device Driver 8.2.4.6 (SynTPDeinstKey)
    uninstall cmd: rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    publisher: Synaptics

    Windows Media Player Skin Importer (wa2wmp)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wa2wmp.inf,DefaultUninstall

    Windows Genuine Advantage Validation Tool (KB892130) 1.7.0069.2 (WGA)
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=892130

    (WIC)

    Windows Media Format 11 runtime (Windows Media Format Runtime)
    uninstall cmd: "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    help link: http://go.microsoft.com/fwlink/?LinkId=62768

    Windows Media Player 11 (Windows Media Player)
    uninstall cmd: "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall

    Windows XP Service Pack 3 20080414.031525 (Windows XP Service Pack)
    install date: 20080906
    uninstall cmd: "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http://support.microsoft.com?kbid=936929

    Windows Media Bonus Pack for Windows XP (WMBK2)
    uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmbonus.inf,DefaultUninstall

    Windows Media Format 11 runtime (WMFDist11)
    install date: 20070921
    uninstall cmd: "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http:

    Windows Media Player 11 (wmp11)
    install date: 20070921
    uninstall cmd: "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
    publisher: Microsoft Corporation
    help link: http:

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •