Deckard's System Scanner v20071014.68
Run by Far-Q on 2008-07-23 01:05:39
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; System Restore is disabled (service is not running).
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Far-Q.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:06:05, on 23/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\SpeedBit\VideoAcceleratorService.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Far-Q\Desktop\dss.exe
C:\PROGRA~1\SpeedBit\VideoAcceleratorEngine.exe
C:\DOCUME~1\Far-Q\Desktop\HJT\Far-Q.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://localhost:9100/proxy.pac
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_1.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RegistryQuick.exe] C:\Program Files\RegistryQuick\RegistryQuick.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1205640783515
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205641385640
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: jkkiihh - jkkiihh.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SpeedBit\VideoAcceleratorService.exe
--
End of file - 5568 bytes
-- HijackThis Fixed Entries (C:\DOCUME~1\Far-Q\Desktop\HJT\backups\) -----------
backup-20080723-005913-541 O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdfhg.exe] C:\WINDOWS\system32\kdfhg.exe
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 sbbotdi - c:\program files\speedbit\sbbotdi.sys <Not Verified; SpeedBit Ltd.; Speedbit TDI Driver>
S1 vcdrom (Virtual CD-ROM Device Driver) - c:\documents and settings\far-q\desktop\vcdrom.sys (file missing)
S3 catchme - c:\docume~1\far-q\locals~1\temp\catchme.sys (file missing)
S3 gdrv - c:\windows\gdrv.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-06-16 14:00:00 486 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
-- Files created between 2008-06-23 and 2008-07-23 -----------------------------
2008-07-22 21:37:30 0 d-------- C:\WINDOWS\ERUNT
2008-07-20 16:00:39 0 dr-h----- C:\Documents and Settings\Far-Q\Recent
2008-07-20 00:41:38 0 d-------- C:\Program Files\john1701
2008-07-20 00:16:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-07-20 00:16:43 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-07-19 23:58:26 744 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-19 23:57:00 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-19 23:57:00 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-07-19 23:57:00 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-07-19 23:57:00 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-07-19 23:57:00 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-19 23:57:00 81920 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; 404Fix>
2008-07-19 23:56:59 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-07-19 23:56:59 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-07-19 22:59:56 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-19 22:42:35 0 d-------- C:\WINDOWS\system32\scripting
2008-07-19 22:42:34 0 d-------- C:\WINDOWS\system32\en
2008-07-19 22:42:34 0 d-------- C:\WINDOWS\system32\bits
2008-07-19 22:42:34 0 d-------- C:\WINDOWS\l2schemas
2008-07-19 22:41:35 0 d-------- C:\WINDOWS\ServicePackFiles
2008-07-19 22:38:09 0 d-------- C:\WINDOWS\EHome
2008-07-19 21:31:23 0 d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-07-19 21:31:05 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-07-19 20:38:00 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-07-19 20:36:15 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-19 20:36:15 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-19 20:36:15 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-19 20:36:15 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-19 20:36:15 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-19 20:36:15 2621440 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-19 20:36:15 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-19 20:36:15 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-19 20:36:15 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-19 20:36:15 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-19 20:36:15 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-19 20:36:15 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-19 20:36:15 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-19 20:36:15 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-19 17:53:44 0 d-------- C:\Program Files\Avast4
2008-07-19 16:33:41 0 d-------- C:\Documents and Settings\Far-Q\.housecall6.6
2008-07-19 14:01:59 0 d-------- C:\Program Files\RegistryQuick
2008-07-19 13:29:01 0 d-------- C:\USMT.TMP
2008-06-28 15:04:52 0 d-------- C:\Program Files\RegistryFix
-- Find3M Report ---------------------------------------------------------------
2008-07-23 00:59:22 2243 --a------ C:\Documents and Settings\Far-Q\Application Data\.googlewebacchosts
2008-07-23 00:09:28 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-07-22 23:00:12 0 d-------- C:\Program Files\SpywareBlaster
2008-07-19 22:59:56 0 d-------- C:\Program Files\Common Files
2008-07-19 22:42:41 0 d-------- C:\Program Files\Messenger
2008-07-19 22:42:34 0 d-------- C:\Program Files\Movie Maker
2008-06-16 14:38:17 0 d-------- C:\Documents and Settings\Far-Q\Application Data\TmpRecentIcons
2008-06-16 13:30:29 0 d-------- C:\Program Files\Need for Speed Most Wanted
2008-06-16 13:01:13 0 d-------- C:\Documents and Settings\Far-Q\Application Data\BitTorrent
2008-06-15 11:48:32 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-15 09:25:33 0 d-------- C:\Program Files\FreshDownload
2008-06-14 15:44:46 176128 --a------ C:\WINDOWS\efrs.exe
2008-06-12 17:39:49 0 d-------- C:\Documents and Settings\Far-Q\Application Data\LimeWire
2008-06-11 20:57:27 0 d-------- C:\Program Files\LimeWire
2008-06-11 14:58:08 0 d-------- C:\Program Files\BitTorrent
2008-06-01 17:03:55 298 --a------ C:\WINDOWS\EReg072.dat
2008-06-01 16:46:46 0 d-------- C:\Program Files\Electronic Arts
2008-06-01 16:45:50 0 d-------- C:\Program Files\DAEMON Tools Pro
2008-06-01 16:42:09 0 d-------- C:\Documents and Settings\Far-Q\Application Data\DAEMON Tools Pro
2008-05-17 20:37:15 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-05-17 20:28:23 0 --a------ C:\WINDOWS\nsreg.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/12/2007 01:41]
"RegistryQuick.exe"="C:\Program Files\RegistryQuick\RegistryQuick.exe" []
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [16/05/2008 07:19]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [14/04/2008 08:12]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [9/07/2007 10:24:38 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 11:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 11:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkiihh]
jkkiihh.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\pmkhg.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Far-Q^Start Menu^Programs^Startup^Deewoo.lnk]
path=C:\Documents and Settings\Far-Q\Start Menu\Programs\Startup\Deewoo.lnk
backup=C:\WINDOWS\pss\Deewoo.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"BM999769fd"=Rundll32.exe "C:\WINDOWS\system32\bmpyrume.dll",s
"ExploreUpdSched"=C:\WINDOWS\system32\ncntrkwd.exe DWram
"9aa45a61"=rundll32.exe "C:\WINDOWS\system32\jnikbebx.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- End of Deckard's System Scanner: finished at 2008-07-23 01:06:46 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
Percentage of Memory in Use: 31%
Physical Memory (total/avail): 1023.48 MiB / 706.2 MiB
Pagefile Memory (total/avail): 2460.33 MiB / 2206.46 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1934.65 MiB
A: is Removable (Unformatted)
C: is Fixed (NTFS) - 298.09 GiB total, 262.79 GiB free.
D: is CDROM (CDFS)
E: is Removable (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD3200AAKS-00YGA0 - 298.09 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 298.09 GiB - C:
\\.\PHYSICALDRIVE1 - Generic STORAGE DEVICE USB Device
\\.\PHYSICALDRIVE2 - Generic STORAGE DEVICE USB Device
\\.\PHYSICALDRIVE3 - Generic STORAGE DEVICE USB Device
\\.\PHYSICALDRIVE4 - Generic STORAGE DEVICE USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Far-Q\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=FRAGGLE
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Far-Q
LOGONSERVER=\\FRAGGLE
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Far-Q\LOCALS~1\Temp
TMP=C:\DOCUME~1\Far-Q\LOCALS~1\Temp
USERDOMAIN=FRAGGLE
USERNAME=Far-Q
USERPROFILE=C:\Documents and Settings\Far-Q
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
Far-Q
(admin)
Administrator
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{8E9DB7EF-5DD3-499E-BA2A-A1F3153A4DF8}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
altcompare --> C:\Program Files\altcmd\uninstall.bat
Attansic L1 Gigabit Ethernet Driver --> rundll32.exe C:\WINDOWS\system32\Attansic\L1\atcInst.dll,AtcUninst C:\WINDOWS\system32\Attansic\L1 x86 1969 1048 L1
avast! Antivirus --> C:\Program Files\Avast4\aswRunDll.exe "C:\Program Files\Avast4\Setup\setiface.dll",RunSetup
BitTorrent --> "C:\Program Files\BitTorrent\BitTorrent.exe" /UNINSTALL
Command And Conquer Red Alert 2 Yuri's Revenge 1.001 --> C:\WINDOWS\iun6002.exe "C:\Program Files\Command And Conquer Red Alert 2 Yuri's Revenge\irunin.ini"
EA Network Play System --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Electronic Arts\Network Play System\uninst.isu"
ExtractNow --> "C:\Program Files\ExtractNow\unins000.exe"
FireTune --> C:\WINDOWS\iun6002.exe "C:\Program Files\FireTune\irunin.ini"
Google Web Accelerator --> MsiExec.exe /X{6A1975EB-27E6-491D-94BC-6355FA25F40F}
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "C:\Documents and Settings\Far-Q\Desktop\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
J2SE Runtime Environment 5.0 Update 10 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150100}
Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
K-Lite Mega Codec Pack 1.01 --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
LimeWire PRO 4.18.2 --> "C:\Program Files\LimeWire\uninstall.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mozilla Firefox (2.0.0.16) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.14) --> C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
Need For Speed High Stakes --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Electronic Arts\Need For Speed High Stakes\Uninst.isu" -c"C:\Program Files\Electronic Arts\Need For Speed High Stakes\uninst.dll" E
Need for Speed™ Most Wanted --> C:\Program Files\Need for Speed Most Wanted\EAUninstall.exe
Nero 7 Essentials --> MsiExec.exe /X{B28B351F-1232-46EA-85EF-B8EA91641033}
NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
PowerDVD --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CyberLink\PowerDVD\Uninst.isu"
REALTEK GbE & FE Ethernet PCI-E NIC Driver --> C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\SETUP.EXE -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.EXE" -l0x9 -removeonly
SimCity 2000® Special Edition --> C:\WINDOWS\uninst.exe -f"C:\Program Files\SimCity 2000\DeIsL1.isu"
SpeedBit Video Accelerator --> C:\PROGRA~1\SpeedBit\UNWISE.EXE C:\PROGRA~1\SpeedBit\INSTALL.LOG
Spybot - Search & Destroy --> "C:\Program Files\SpybotSD\unins000.exe"
SpywareBlaster 4.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
System Requirements Lab --> C:\Program Files\SystemRequirementsLab\Uninstall.exe
Vista Codec Package --> MsiExec.exe /I{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}
Westnet Easy Signup Software 1.1 --> C:\Program Files\Westnet\uninst.exe
Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Wolfenstein 3D --> MsiExec.exe /I{69FDD4EA-9D68-11D5-8A28-005004D37F93}
Yahoo! Companion --> rundll32.exe C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YCOMP5~1.DLL,DllCommand ui
-- Application Event Log -------------------------------------------------------
Event Record #/Type1864 / Warning
Event Submitted/Written: 07/20/2008 01:12:48 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}', feature 'Complete' failed during request for component '{A6C8A50F-4808-43A4-A147-ACAA2598DE52}'
Event Record #/Type1863 / Warning
Event Submitted/Written: 07/20/2008 01:12:48 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}', feature 'Complete', component '{B2B6EDF3-22B8-47B3-8358-4D1976F0949D}' failed. The resource 'C:\Program Files\SUPERAntiSpyware\Quarantine\' does not exist.
Event Record #/Type1861 / Warning
Event Submitted/Written: 07/20/2008 01:12:10 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}', feature 'Complete' failed during request for component '{A6C8A50F-4808-43A4-A147-ACAA2598DE52}'
Event Record #/Type1860 / Warning
Event Submitted/Written: 07/20/2008 01:12:10 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}', feature 'Complete', component '{B2B6EDF3-22B8-47B3-8358-4D1976F0949D}' failed. The resource 'C:\Program Files\SUPERAntiSpyware\Quarantine\' does not exist.
Event Record #/Type1849 / Warning
Event Submitted/Written: 07/19/2008 11:54:15 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x8007043C
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type8903 / Error
Event Submitted/Written: 07/23/2008 01:01:23 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The System Restore Service service terminated with the following error:
%%2
Event Record #/Type8902 / Error
Event Submitted/Written: 07/23/2008 01:01:10 AM
Event ID/Source: 104 / SRService
Event Description:
The System Restore initialization process failed.
Event Record #/Type8882 / Error
Event Submitted/Written: 07/23/2008 00:33:07 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The System Restore Service service terminated with the following error:
%%2
Event Record #/Type8881 / Error
Event Submitted/Written: 07/23/2008 00:32:57 AM
Event ID/Source: 104 / SRService
Event Description:
The System Restore initialization process failed.
Event Record #/Type8858 / Error
Event Submitted/Written: 07/22/2008 11:51:25 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The System Restore Service service terminated with the following error:
%%2
-- End of Deckard's System Scanner: finished at 2008-07-23 01:06:46 ------------