Diagnosis - Page 2
Solved
Previous
- 1
- 2
No, the crack that I can't remove is vista7 slic 1.9.1.0
I don't know what it is, I posted on the Windows forum and they told me it's a crack, it doesn't show up in uninstall a program.
I don't know what it is, I posted on the Windows forum and they told me it's a crack, it doesn't show up in uninstall a program.
It is mandatory; otherwise, the tool does not work properly:
Disable UAC for me as indicated in post 6.
Delete this crack:
C:\Users\didi\AppData\Local\VirtualStore\Program Files\Agatha Christie - Death on the Nile\gameres\images\bonus_rosary\bead_crack.png
Then restart toolbar s&d and post a new report.
--
*>flo-91<*®
Don't hesitate to take a look at the forum's FAQ (tips section),
there might already be a solution to your problem =)
Disable UAC for me as indicated in post 6.
Delete this crack:
C:\Users\didi\AppData\Local\VirtualStore\Program Files\Agatha Christie - Death on the Nile\gameres\images\bonus_rosary\bead_crack.png
Then restart toolbar s&d and post a new report.
--
*>flo-91<*®
Don't hesitate to take a look at the forum's FAQ (tips section),
there might already be a solution to your problem =)
HELLO. I have disabled UAC and removed the crack
here is the report
-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft® Windows Vista™ Home Basic Edition ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) Dual Core Processor 4450e )
BIOS : BIOS Date: 11/05/08 15:51:14 Ver: 5.03
USER : didi ( Not Administrator ! )
BOOT : Normal boot
Antivirus : VirusScan Enterprise + AntiSpyware Enterprise 8.5.0.781 (Activated)
C:\ (Local Disk) - NTFS - Total:454 Go (Free:295 Go)
D:\ (Local Disk) - NTFS - Total:11 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( LAST UPDATED : 22-08-2009|18:42 )
Option : [1] ( 22/12/2009|11:41 )
[ UAC => 0 ]
-----------\\ Searching for Files / Folders ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search bar"="http://go.microsoft.com/fwlink/?linkid=54896"
"Url"="http://go.microsoft.com/fwlink/?LinkID=68928"
"Url"="http://go.microsoft.com/fwlink/?LinkID=44406"
"Url"="http://go.microsoft.com/fwlink/?LinkID=68929"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\Windows\\System32\\blank.htm"
"Search bar"="http://www.bing.com/spresults.aspx"
--------------------\\ Looking for other infections
No other infections found!
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 22/12/2009|11:42 - Option : [1]
-----------\\ End of report at 11:42:26,19
here is the report
-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft® Windows Vista™ Home Basic Edition ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) Dual Core Processor 4450e )
BIOS : BIOS Date: 11/05/08 15:51:14 Ver: 5.03
USER : didi ( Not Administrator ! )
BOOT : Normal boot
Antivirus : VirusScan Enterprise + AntiSpyware Enterprise 8.5.0.781 (Activated)
C:\ (Local Disk) - NTFS - Total:454 Go (Free:295 Go)
D:\ (Local Disk) - NTFS - Total:11 Go (Free:1 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( LAST UPDATED : 22-08-2009|18:42 )
Option : [1] ( 22/12/2009|11:41 )
[ UAC => 0 ]
-----------\\ Searching for Files / Folders ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search bar"="http://go.microsoft.com/fwlink/?linkid=54896"
"Url"="http://go.microsoft.com/fwlink/?LinkID=68928"
"Url"="http://go.microsoft.com/fwlink/?LinkID=44406"
"Url"="http://go.microsoft.com/fwlink/?LinkID=68929"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\Windows\\System32\\blank.htm"
"Search bar"="http://www.bing.com/spresults.aspx"
--------------------\\ Looking for other infections
No other infections found!
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 22/12/2009|11:42 - Option : [1]
-----------\\ End of report at 11:42:26,19
You can restore the file that I considered a crack; it is not one but an image of a game.
Restore it if it is useful to you.
You will do this for me:
•/!\ Vista users: Don't forget to disable UAC just for the time of disinfecting your PC, it will need to be reactivated later:
Tutorial: https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
Download OtmoveIT (by Old_Timer) to your Desktop
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
https://www.androidworld.fr/
(it's number 7 at the bottom of the page):
* Double-click on OTMoveIt.exe to run it.
/!\ Vista users: Right-click on the OtmoveIT logo, “run as Administrator”
* Make sure the Unregister Dll's and Ocx's box is checked.
* Copy the list that is in bold in the quote below and paste it into the left box of OTMoveIt under Paste List of Files/Folders to move.
:processes
explorer.exe
:files
C:\Windows\Temp\CTun.exe /remove
C:\Windows\Temp\CTun.exe
:Commands
[emptytemp]
[purity]
[start explorer]
[Reboot]
# click on MoveIt! to start the deletion.
# The result will appear in the "Results" box.
# Click on Exit to close it.
# Post the report located in C:\_OTMoveIt\MovedFiles.
# You may be asked to restart your PC to complete the deletion. If so, accept with Yes.
Then:
>Download and install the CCleaner Software here:
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
>Launch the program and set it up like this:
>Tab "options" click on "advanced" uncheck the box "delete Windows temporary files older than 48 hours".
>Cleaning<
>Tab "Cleaner" click on "analyze" then on "clean", repeat the operation until there is nothing left to delete
>Tab "registry" click on "search for errors" then "fix selected errors", repeat the operation until there is nothing left to repair.
>It is advisable to keep the tool on your PC and perform daily cleanings.
--
*>flo-91<*®
Feel free to visit the FAQ of the forum (tips section),
there may already be a solution to your problem =)
Restore it if it is useful to you.
You will do this for me:
•/!\ Vista users: Don't forget to disable UAC just for the time of disinfecting your PC, it will need to be reactivated later:
Tutorial: https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
Download OtmoveIT (by Old_Timer) to your Desktop
http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
https://www.androidworld.fr/
(it's number 7 at the bottom of the page):
* Double-click on OTMoveIt.exe to run it.
/!\ Vista users: Right-click on the OtmoveIT logo, “run as Administrator”
* Make sure the Unregister Dll's and Ocx's box is checked.
* Copy the list that is in bold in the quote below and paste it into the left box of OTMoveIt under Paste List of Files/Folders to move.
:processes
explorer.exe
:files
C:\Windows\Temp\CTun.exe /remove
C:\Windows\Temp\CTun.exe
:Commands
[emptytemp]
[purity]
[start explorer]
[Reboot]
# click on MoveIt! to start the deletion.
# The result will appear in the "Results" box.
# Click on Exit to close it.
# Post the report located in C:\_OTMoveIt\MovedFiles.
# You may be asked to restart your PC to complete the deletion. If so, accept with Yes.
Then:
>Download and install the CCleaner Software here:
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
>Launch the program and set it up like this:
>Tab "options" click on "advanced" uncheck the box "delete Windows temporary files older than 48 hours".
>Cleaning<
>Tab "Cleaner" click on "analyze" then on "clean", repeat the operation until there is nothing left to delete
>Tab "registry" click on "search for errors" then "fix selected errors", repeat the operation until there is nothing left to repair.
>It is advisable to keep the tool on your PC and perform daily cleanings.
--
*>flo-91<*®
Feel free to visit the FAQ of the forum (tips section),
there may already be a solution to your problem =)
I did as you told me with OtmoveIT
but there is no list in bold when I open it, the two pages are empty?
but there is no list in bold when I open it, the two pages are empty?
:processes
explorer.exe
:files
C:\Windows\Temp\CTun.exe /remove
C:\Windows\Temp\CTun.exe
:Commands
[emptytemp]
[purity]
[start explorer]
[Reboot]
Is it in bold?
Then copy it into the OTM box and click on "MoveIt"
--
*>flo-91<*®
Feel free to check out the forum FAQ (tips section),
there might already be a solution to your problem =)
I think I made a mistake
before copying and pasting in the left box I clicked on clean up
then I clicked on exit after that I copied the message you told me and I
pasted it on the left I clicked on moveIt and then it said
invalid time flag [remove] must be numerical
is this message normal?
before copying and pasting in the left box I clicked on clean up
then I clicked on exit after that I copied the message you told me and I
pasted it on the left I clicked on moveIt and then it said
invalid time flag [remove] must be numerical
is this message normal?
Restart the PC and start the correct operation again.
--
*>flo-91<*®
Feel free to check out the FAQ section of the forum (tips section),
there may already be a solution to your problem =)
--
*>flo-91<*®
Feel free to check out the FAQ section of the forum (tips section),
there may already be a solution to your problem =)
We'll do it differently:
>Download and install the CCleaner software here:
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
>Launch the program and set it up as follows:
>In the "Options" tab, click on "Advanced" and uncheck the box "Erase Windows temporary files older than 48 hours."
>Cleanup<
>In the "Cleaner" tab, click on "Analyze" then "Clean," repeat the operation until there is nothing left to delete.
>In the "Registry" tab, click on "Search for errors" then "Fix selected errors," repeat the operation until there is nothing left to repair.
>It is advisable to keep the tool on your PC and to perform a cleanup daily.
--
*>flo-91<*®
Feel free to take a look at the forum FAQ (Tips section),
there might already be a solution to your problem =)
>Download and install the CCleaner software here:
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
>Launch the program and set it up as follows:
>In the "Options" tab, click on "Advanced" and uncheck the box "Erase Windows temporary files older than 48 hours."
>Cleanup<
>In the "Cleaner" tab, click on "Analyze" then "Clean," repeat the operation until there is nothing left to delete.
>In the "Registry" tab, click on "Search for errors" then "Fix selected errors," repeat the operation until there is nothing left to repair.
>It is advisable to keep the tool on your PC and to perform a cleanup daily.
--
*>flo-91<*®
Feel free to take a look at the forum FAQ (Tips section),
there might already be a solution to your problem =)
OK, please repost an RSIT report.
--
*>flo-91<*®
Feel free to take a look at the forum's FAQ (tips section),
you might already find the solution to your problem = )
--
*>flo-91<*®
Feel free to take a look at the forum's FAQ (tips section),
you might already find the solution to your problem = )
Here is the first report
Logfile of random's system information tool 1.06 (written by random/random)
Run by didi at 2009-12-22 20:22:21
Microsoft® Windows Vista™ Home Basic Edition Service Pack 2
System drive C: has 305 GB (66%) free of 465 GB
Total RAM: 1790 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:22:32, on 12/22/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\VM303_STI.EXE
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\didi\Downloads\RSIT.exe
C:\Program Files\trend micro\didi.exe
C:\Windows\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live ID Connection Assistant Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [TSMAgent] "c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [DVDAgent] "c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -HPW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDog303] C:\Windows\VM303_STI.EXE VIMICRO USB PC Camera (VC0303)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MSN Gift Notification.lnk = C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
O4 - Startup: OneNote 2007 - Screen Capture and Launch.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B720FB4-C1DD-4887-B9B0-D6CE3D8E3392}: NameServer = 212.27.40.240
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca0df7759577b4) (gupdate1ca0df7759577b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
--
End of file - 10761 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\HPCeeScheduleFordidi.job
C:\Windows\tasks\PCConfidential.job
C:\Windows\tasks\PCDRScheduledMaintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-02-27 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Connection Assistant Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-30 263280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-30 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-30 263280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"hpsysdrv"=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
"KBD"=C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE [2008-07-21 12288]
"NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-10-03 203296]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"UpdateP2GoShortCut"=c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePDIRShortCut"=c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe [2008-09-11 210216]
"TSMAgent"=c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-10-17 1152296]
"CLMLServer for HP TouchSmart"=c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-10-17 189736]
"DVDAgent"=c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-09-26 1148200]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-09-23 912688]
"HP Software Update"=c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"DT HPW"=C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2007-09-28 81920]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-02-27 198160]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"BigDog303"=C:\Windows\VM303_STI.EXE [2006-01-24 61440]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2008-01-24 111952]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2007-10-25 136512]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-09-27 13539872]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-09-27 92704]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"HPAdvisor"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2009-08-05 1644088]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-23 39408]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-03-17 2387968]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-12-16 2002160]
C:\Users\didi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSN Gift Notification.lnk - C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
OneNote 2007 - Screen Capture and Launch.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoLogoff"=0
"NoClose"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b3f3f6c-04cb-11de-b59a-002354f17d26}]
shell\AutoRun\command - J:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2aec99a-0506-11de-838f-002354f17d26}]
shell\AutoRun\command - J:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6f77646-c922-11de-b33d-002354f0543d}]
shell\AutoRun\command - J:\USBAutoRun.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-12-22 20:14:23 ----D---- C:\rsit
2009-12-22 12:18:03 ----D---- C:\_OTM
2009-12-21 21:38:26 ----A---- C:\TB.txt
2009-12-21 19:45:27 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2009-12-21 19:44:08 ----D---- C:\Users\didi\AppData\Roaming\SUPERAntiSpyware.com
2009-12-21 19:44:08 ----D---- C:\Program Files\SUPERAntiSpyware
2009-12-21 19:42:33 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-21 18:50:17 ----A---- C:\cleannavi.txt
2009-12-21 18:49:25 ----D---- C:\Program Files\Navilog1
2009-12-21 12:57:09 ----D---- C:\Users\didi\AppData\Roaming\Malwarebytes
2009-12-21 12:57:03 ----D---- C:\ProgramData\Malwarebytes
2009-12-21 12:57:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-12-21 12:14:56 ----D---- C:\Program Files\Ad-Remover
2009-12-20 20:18:03 ----D---- C:\Program Files\trend micro
2009-12-17 19:00:17 ----D---- C:\Users\didi\AppData\Roaming\vlc
2009-12-15 15:41:12 ----D---- C:\FreePack
2009-12-10 19:53:35 ----SHD---- C:\Windows\system32\%APPDATA%
2009-12-10 13:08:31 ----A---- C:\Windows\system32\winhttp.dll
2009-12-10 13:08:28 ----A---- C:\Windows\system32\mshtml.dll
2009-12-10 13:08:27 ----A---- C:\Windows\system32\iertutil.dll
2009-12-10 13:08:27 ----A---- C:\Windows\system32\ieframe.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\wininet.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\urlmon.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\occache.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\msfeeds.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\iedkcs32.dll
2009-12-10 13:08:24 ----A---- C:\Windows\system32\ieui.dll
2009-12-10 13:08:24 ----A---- C:\Windows\system32\iepeers.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\jsproxy.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\ieUnatt.exe
2009-12-10 13:08:23 ----A---- C:\Windows\system32\iesysprep.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\ie4uinit.exe
2009-12-10 13:08:21 ----A---- C:\Windows\system32\msfeedssync.exe
2009-12-10 13:08:21 ----A---- C:\Windows\system32\iesetup.dll
2009-12-10 13:08:20 ----A---- C:\Windows\system32\iernonce.dll
2009-12-10 13:08:15 ----A---- C:\Windows\system32\httpapi.dll
2009-12-10 13:08:12 ----A---- C:\Windows\system32\nshhttp.dll
2009-12-10 13:07:49 ----A---- C:\Windows\system32\rastls.dll
2009-12-08 11:49:09 ----D---- C:\ProgramData\Real
2009-12-06 19:19:38 ----D---- C:\Program Files\Celestia
2009-12-04 17:36:47 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-12-04 17:36:47 ----D---- C:\Program Files\Spybot - Search & Destroy
Logfile of random's system information tool 1.06 (written by random/random)
Run by didi at 2009-12-22 20:22:21
Microsoft® Windows Vista™ Home Basic Edition Service Pack 2
System drive C: has 305 GB (66%) free of 465 GB
Total RAM: 1790 MB (30% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:22:32, on 12/22/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\VM303_STI.EXE
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\KBD\kbd.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\didi\Downloads\RSIT.exe
C:\Program Files\trend micro\didi.exe
C:\Windows\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live ID Connection Assistant Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe" "c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [TSMAgent] "c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe"
O4 - HKLM\..\Run: [CLMLServer for HP TouchSmart] "c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [DVDAgent] "c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe"
O4 - HKLM\..\Run: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe -HPW
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BigDog303] C:\Windows\VM303_STI.EXE VIMICRO USB PC Camera (VC0303)
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW,SYSTRAY
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MSN Gift Notification.lnk = C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
O4 - Startup: OneNote 2007 - Screen Capture and Launch.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B720FB4-C1DD-4887-B9B0-D6CE3D8E3392}: NameServer = 212.27.40.240
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate1ca0df7759577b4) (gupdate1ca0df7759577b4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
--
End of file - 10761 bytes
======Scheduled tasks folder======
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\HPCeeScheduleFordidi.job
C:\Windows\tasks\PCConfidential.job
C:\Windows\tasks\PCDRScheduledMaintenance.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-02-27 312928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Connection Assistant Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-30 263280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-30 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-30 263280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"hpsysdrv"=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
"KBD"=C:\Program Files\Hewlett-Packard\KBD\KbdStub.EXE [2008-07-21 12288]
"NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-10-03 203296]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"UpdateP2GoShortCut"=c:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePDIRShortCut"=c:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=c:\Program Files\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe [2008-09-11 210216]
"TSMAgent"=c:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe [2008-10-17 1152296]
"CLMLServer for HP TouchSmart"=c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe [2008-10-17 189736]
"DVDAgent"=c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe [2008-09-26 1148200]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2008-09-23 912688]
"HP Software Update"=c:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"DT HPW"=C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe [2007-09-28 81920]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-02-27 198160]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"BigDog303"=C:\Windows\VM303_STI.EXE [2006-01-24 61440]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2008-01-24 111952]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2007-10-25 136512]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-09-27 13539872]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-09-27 92704]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"HPAdvisor"=C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [2009-08-05 1644088]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-23 39408]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-03-17 2387968]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-12-16 2002160]
C:\Users\didi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MSN Gift Notification.lnk - C:\Users\didi\AppData\Roaming\Microsoft\MSN Gift Notification\lsnfier.exe
OneNote 2007 - Screen Capture and Launch.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"FilterAdministratorToken"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoLogoff"=0
"NoClose"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4b3f3f6c-04cb-11de-b59a-002354f17d26}]
shell\AutoRun\command - J:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2aec99a-0506-11de-838f-002354f17d26}]
shell\AutoRun\command - J:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6f77646-c922-11de-b33d-002354f0543d}]
shell\AutoRun\command - J:\USBAutoRun.exe
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 months======
2009-12-22 20:14:23 ----D---- C:\rsit
2009-12-22 12:18:03 ----D---- C:\_OTM
2009-12-21 21:38:26 ----A---- C:\TB.txt
2009-12-21 19:45:27 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2009-12-21 19:44:08 ----D---- C:\Users\didi\AppData\Roaming\SUPERAntiSpyware.com
2009-12-21 19:44:08 ----D---- C:\Program Files\SUPERAntiSpyware
2009-12-21 19:42:33 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-21 18:50:17 ----A---- C:\cleannavi.txt
2009-12-21 18:49:25 ----D---- C:\Program Files\Navilog1
2009-12-21 12:57:09 ----D---- C:\Users\didi\AppData\Roaming\Malwarebytes
2009-12-21 12:57:03 ----D---- C:\ProgramData\Malwarebytes
2009-12-21 12:57:00 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-12-21 12:14:56 ----D---- C:\Program Files\Ad-Remover
2009-12-20 20:18:03 ----D---- C:\Program Files\trend micro
2009-12-17 19:00:17 ----D---- C:\Users\didi\AppData\Roaming\vlc
2009-12-15 15:41:12 ----D---- C:\FreePack
2009-12-10 19:53:35 ----SHD---- C:\Windows\system32\%APPDATA%
2009-12-10 13:08:31 ----A---- C:\Windows\system32\winhttp.dll
2009-12-10 13:08:28 ----A---- C:\Windows\system32\mshtml.dll
2009-12-10 13:08:27 ----A---- C:\Windows\system32\iertutil.dll
2009-12-10 13:08:27 ----A---- C:\Windows\system32\ieframe.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\wininet.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\urlmon.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\occache.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\msfeeds.dll
2009-12-10 13:08:26 ----A---- C:\Windows\system32\iedkcs32.dll
2009-12-10 13:08:24 ----A---- C:\Windows\system32\ieui.dll
2009-12-10 13:08:24 ----A---- C:\Windows\system32\iepeers.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\jsproxy.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\ieUnatt.exe
2009-12-10 13:08:23 ----A---- C:\Windows\system32\iesysprep.dll
2009-12-10 13:08:23 ----A---- C:\Windows\system32\ie4uinit.exe
2009-12-10 13:08:21 ----A---- C:\Windows\system32\msfeedssync.exe
2009-12-10 13:08:21 ----A---- C:\Windows\system32\iesetup.dll
2009-12-10 13:08:20 ----A---- C:\Windows\system32\iernonce.dll
2009-12-10 13:08:15 ----A---- C:\Windows\system32\httpapi.dll
2009-12-10 13:08:12 ----A---- C:\Windows\system32\nshhttp.dll
2009-12-10 13:07:49 ----A---- C:\Windows\system32\rastls.dll
2009-12-08 11:49:09 ----D---- C:\ProgramData\Real
2009-12-06 19:19:38 ----D---- C:\Program Files\Celestia
2009-12-04 17:36:47 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-12-04 17:36:47 ----D---- C:\Program Files\Spybot - Search & Destroy
the second
info.txt logfile of random's system information tool 1.06 2009-12-22 20:15:24
======Uninstall list======
-->"C:\Program Files\eMachines Games\Kuros\Uninstall.exe"
-->"C:\Program Files\HP Games\10 Days Under The Sea\Uninstall.exe"
-->"C:\Program Files\HP Games\4 Elements\Uninstall.exe"
-->"C:\Program Files\HP Games\7 Wonders - Treasures of Seven\Uninstall.exe"
-->"C:\Program Files\HP Games\ABC Island\Uninstall.exe"
-->"C:\Program Files\HP Games\Adventure Chronicles\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Dead Man's Folly\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Peril at End House\Uninstall.exe"
-->"C:\Program Files\HP Games\Age of Oracles - Tara's Journey\Uninstall.exe"
-->"C:\Program Files\HP Games\Alabama Smith in the Quest of Fate\Uninstall.exe"
-->"C:\Program Files\HP Games\Alexandra Fortune - Mystery of the Lunar Archipelago\Uninstall.exe"
-->"C:\Program Files\HP Games\Amazing Adventures Around the World\Uninstall.exe"
-->"C:\Program Files\HP Games\Ancient Secrets\Uninstall.exe"
-->"C:\Program Files\HP Games\Annabel\Uninstall.exe"
-->"C:\Program Files\HP Games\Aveyond - Gates of Night\Uninstall.exe"
-->"C:\Program Files\HP Games\Azteca\Uninstall.exe"
-->"C:\Program Files\HP Games\Becky Brogan - The Mystery of Meane Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Book of Legends\Uninstall.exe"
-->"C:\Program Files\HP Games\Bookworm Adventures Volume 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Boulder Dash - Pirates Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Campfire Legends - The Hookman\Uninstall.exe"
-->"C:\Program Files\HP Games\Can You See What I See - Curfuffle's Collectibles\Uninstall.exe"
-->"C:\Program Files\HP Games\Can You See What I See - Dream Machine\Uninstall.exe"
-->"C:\Program Files\HP Games\Cate West - The Vanishing Files\Uninstall.exe"
-->"C:\Program Files\HP Games\Cate West - The Velvet Keys\Uninstall.exe"
-->"C:\Program Files\HP Games\City Sights - Hello Seattle!\Uninstall.exe"
-->"C:\Program Files\HP Games\CLUE Classic\Uninstall.exe"
-->"C:\Program Files\HP Games\Diego's Safari Adventure\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles - The Chosen Child\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day First Home\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Honeymoon\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding - Viva Las Vegas!\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding 2 - Married in Manhattan\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding\Uninstall.exe"
-->"C:\Program Files\HP Games\Fabulous Finds\Uninstall.exe"
-->"C:\Program Files\HP Games\Faerie Solitaire\Uninstall.exe"
-->"C:\Program Files\HP Games\Gardenscapes\Uninstall.exe"
-->"C:\Program Files\HP Games\Gemini Lost\Uninstall.exe"
-->"C:\Program Files\HP Games\Glyph 2\Uninstall.exe"
-->"C:\Program Files\HP Games\GO Diego GO! Dinosaur Rescue\Uninstall.exe"
-->"C:\Program Files\HP Games\Gold Rush - Treasure Hunt\Uninstall.exe"
-->"C:\Program Files\HP Games\Hidden Secrets - The Nightmare\Uninstall.exe"
-->"C:\Program Files\HP Games\Hidden World of Art\Uninstall.exe"
-->"C:\Program Files\HP Games\HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Hunting Unlimited 2008\Uninstall.exe"
-->"C:\Program Files\HP Games\Insider Tales - The Secret of Casanova\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest II\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest Mysteries 2 Trail of the Midnight Heart\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest Mysteries\Uninstall.exe"
-->"C:\Program Files\HP Games\Legacy - World Adventure\Uninstall.exe"
-->"C:\Program Files\HP Games\Liong - The Lost Amulets\Uninstall.exe"
-->"C:\Program Files\HP Games\Lost City of Aquatica\Uninstall.exe"
-->"C:\Program Files\HP Games\Lost Realms - Legacy of the Sun Princess\Uninstall.exe"
-->"C:\Program Files\HP Games\Magic Encyclopedia\Uninstall.exe"
-->"C:\Program Files\HP Games\Midnight Mysteries - The Edgar Allan Poe Conspiracy\Uninstall.exe"
-->"C:\Program Files\HP Games\Monopoly\Uninstall.exe"
-->"C:\Program Files\HP Games\Mortimer Beckett and the Secrets of Spooky Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Mortimer Beckett and the Time Paradox\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery Masterpiece - The Moonstone\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery of Shark Island\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery P.I. - Lost in Los Angeles\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery P.I. - The Vegas Heist\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - Curse of Blackmoor Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - Legend of the Crystal Skull\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - The Phantom of Venice\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew Dossier - Lights, Camera, Curses\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew Dossier - Resorting to Danger!\Uninstall.exe"
-->"C:\Program Files\HP Games\Natalie Brooks - The Treasures of the Lost Kingdom\Uninstall.exe"
-->"C:\Program Files\HP Games\Obulis\Uninstall.exe"
-->"C:\Program Files\HP Games\Pahelika - Secret Legends\Uninstall.exe"
-->"C:\Program Files\HP Games\Paparazzi\Uninstall.exe"
-->"C:\Program Files\HP Games\Paranormal Agency\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Pocahontas - Princess of the Powhatan\Uninstall.exe"
-->"C:\Program Files\HP Games\Princess Isabella - A Witch's Curse\Uninstall.exe"
-->"C:\Program Files\HP Games\Profitville\Uninstall.exe"
-->"C:\Program Files\HP Games\Samantha Swift and the Golden Touch\Uninstall.exe"
-->"C:\Program Files\HP Games\Save Our Spirit\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Mystery - Whos Gold\Uninstall.exe"
-->"C:\Program Files\HP Games\StoneLoops of Jurassica\Uninstall.exe"
-->"C:\Program Files\HP Games\The Ancient Quest of Saqqarah\Uninstall.exe"
-->"C:\Program Files\HP Games\The Clumsys\Uninstall.exe"
-->"C:\Program Files\HP Games\The Count of Monte Cristo\Uninstall.exe"
-->"C:\Program Files\HP Games\The Legend of Crystal Valley\Uninstall.exe"
-->"C:\Program Files\HP Games\The Lost Cases of Sherlock Holmes\Uninstall.exe"
-->"C:\Program Files\HP Games\The Lost Inca Prophecy\Uninstall.exe"
-->"C:\Program Files\HP Games\The Mushroom Age\Uninstall.exe"
-->"C:\Program Files\HP Games\The Nightshift Code\Uninstall.exe"
-->"C:\Program Files\HP Games\The Secret of Margrave Manor 2\Uninstall.exe"
-->"C:\Program Files\HP Games\The Wizard's Pen\Uninstall.exe"
-->"C:\Program Files\HP Games\TikiBar\Uninstall.exe"
-->"C:\Program Files\HP Games\Torchlight\Uninstall.exe"
-->"C:\Program Files\HP Games\Totem Tribe\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds Odyssey\Uninstall.exe"
-->"C:\Program Files\HP Games\Trapped - The Abduction\Uninstall.exe"
-->"C:\Program Files\HP Games\Treasures of the Serengeti\Uninstall.exe"
-->"C:\Program Files\HP Games\Undiscovered World - The Incan Sun\Uninstall.exe"
-->"C:\Program Files\HP Games\Wandering Willows\Uninstall.exe"
-->"C:\Program Files\HP Games\Wild West Quest 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Women's Murder Club - A Darker Shade of Grey\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma's Revenge\Uninstall.exe"
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
Ad-Remover By C_XX-->"C:\Program Files\Ad-Remover\Uninstall ADR.exe"
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
Windows Live Connection Assistant-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
Avanquest update-->"C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
Brutal Chess-->C:\Program Files\Brutal Chess\uninstall.exe
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Celestia 1.5.1-->"C:\Program Files\Celestia\unins000.exe"
CyberLink DVD Suite Deluxe-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" /z-uninstall
CyberLink DVD Suite Deluxe-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" /z-uninstall
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dream Aquarium-->"C:\Program Files\Dream Aquarium\UnInstall.exe"
eMachines Games-->"C:\Program Files\eMachines Games\Uninstall.exe"
FreePack-->c:\FreePack\Uninstal.exe
Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.38\Installer\setup.exe" --uninstall --system-level
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658}
HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}\setup.exe" -runfromtemp -l0x0409 -removeonly
HP Advisor-->MsiExec.exe /X{73A43E42-3658-4DD9-8551-FACDA3632538}
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64B9E2F5-558E-4C56-B419-A1679518F6E7}\setup.exe" -l0x9 -removeonly
HP Demo-->MsiExec.exe /X{97ABD26A-3249-46CB-B2E2-F66E64B2E480}
HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall /zMS
HP MediaSmart SmartMenu-->MsiExec.exe /I{EFC5939F-470F-454E-B3DA-F51FDD83F6CE}
HP My Display-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{15733AD1-1CEF-459A-9245-0924FC63BDD5}\setup.exe" -l0x40c -removeonly
HP Picasso Media Center Add-In-->MsiExec.exe /X{03BF5CB1-B72E-4CA6-A278-F65680F05420}
HP Recovery Manager RSS-->MsiExec.exe /X{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}
HP Total Care Setup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{38058455-8C21-4C2F-B2F6-14ED166039CB}\setup.exe" -l0x9 -removeonly
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
Windows Live Installation-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Installation-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Kuros-->"C:\Program Files\Kuros\Uninstall.exe"
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LG USB Modem driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
LightScribe System Software-->MsiExec.exe /X{7F10292C-A190-4176-A665-A1ED3478DF86}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee AntiSpyware Enterprise Module-->"C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe" /UninstallMAS
McAfee VirusScan Enterprise-->MsiExec.exe /X{35C03C04-3F1F-42C2-A989-A757EE691F65}
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
Update Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
Update Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
Update Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
Compatibility Module for Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Microsoft .NET Framework 3.5 SP1 Language Module- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
muvee Reveal-->MsiExec.exe /X{19506BDB-4EA7-491F-E8AB-E97109FDB296}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Google Update Tool-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Windows Live Download Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Hardware Diagnostic Tools-->C:\Program Files\PC-Doctor for Windows\uninst.exe
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
Python 2.5.2-->MsiExec.exe /I{6B976ADF-8AE8-434E-B282-A06C7F624D2F}
Real Chess-->"C:\Program Files\GameTop.com\Real Chess\unins000.exe"
RealArcade-->C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd.exe -r -m -nrg2709
SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
SDK-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}\setup.exe" -l0x9
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000000FF1CE}
info.txt logfile of random's system information tool 1.06 2009-12-22 20:15:24
======Uninstall list======
-->"C:\Program Files\eMachines Games\Kuros\Uninstall.exe"
-->"C:\Program Files\HP Games\10 Days Under The Sea\Uninstall.exe"
-->"C:\Program Files\HP Games\4 Elements\Uninstall.exe"
-->"C:\Program Files\HP Games\7 Wonders - Treasures of Seven\Uninstall.exe"
-->"C:\Program Files\HP Games\ABC Island\Uninstall.exe"
-->"C:\Program Files\HP Games\Adventure Chronicles\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Dead Man's Folly\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Death on the Nile\Uninstall.exe"
-->"C:\Program Files\HP Games\Agatha Christie - Peril at End House\Uninstall.exe"
-->"C:\Program Files\HP Games\Age of Oracles - Tara's Journey\Uninstall.exe"
-->"C:\Program Files\HP Games\Alabama Smith in the Quest of Fate\Uninstall.exe"
-->"C:\Program Files\HP Games\Alexandra Fortune - Mystery of the Lunar Archipelago\Uninstall.exe"
-->"C:\Program Files\HP Games\Amazing Adventures Around the World\Uninstall.exe"
-->"C:\Program Files\HP Games\Ancient Secrets\Uninstall.exe"
-->"C:\Program Files\HP Games\Annabel\Uninstall.exe"
-->"C:\Program Files\HP Games\Aveyond - Gates of Night\Uninstall.exe"
-->"C:\Program Files\HP Games\Azteca\Uninstall.exe"
-->"C:\Program Files\HP Games\Becky Brogan - The Mystery of Meane Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Book of Legends\Uninstall.exe"
-->"C:\Program Files\HP Games\Bookworm Adventures Volume 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Boulder Dash - Pirates Quest\Uninstall.exe"
-->"C:\Program Files\HP Games\Campfire Legends - The Hookman\Uninstall.exe"
-->"C:\Program Files\HP Games\Can You See What I See - Curfuffle's Collectibles\Uninstall.exe"
-->"C:\Program Files\HP Games\Can You See What I See - Dream Machine\Uninstall.exe"
-->"C:\Program Files\HP Games\Cate West - The Vanishing Files\Uninstall.exe"
-->"C:\Program Files\HP Games\Cate West - The Velvet Keys\Uninstall.exe"
-->"C:\Program Files\HP Games\City Sights - Hello Seattle!\Uninstall.exe"
-->"C:\Program Files\HP Games\CLUE Classic\Uninstall.exe"
-->"C:\Program Files\HP Games\Diego's Safari Adventure\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles - The Chosen Child\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Chronicles\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day First Home\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Honeymoon\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding - Viva Las Vegas!\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding 2 - Married in Manhattan\Uninstall.exe"
-->"C:\Program Files\HP Games\Dream Day Wedding\Uninstall.exe"
-->"C:\Program Files\HP Games\Fabulous Finds\Uninstall.exe"
-->"C:\Program Files\HP Games\Faerie Solitaire\Uninstall.exe"
-->"C:\Program Files\HP Games\Gardenscapes\Uninstall.exe"
-->"C:\Program Files\HP Games\Gemini Lost\Uninstall.exe"
-->"C:\Program Files\HP Games\Glyph 2\Uninstall.exe"
-->"C:\Program Files\HP Games\GO Diego GO! Dinosaur Rescue\Uninstall.exe"
-->"C:\Program Files\HP Games\Gold Rush - Treasure Hunt\Uninstall.exe"
-->"C:\Program Files\HP Games\Hidden Secrets - The Nightmare\Uninstall.exe"
-->"C:\Program Files\HP Games\Hidden World of Art\Uninstall.exe"
-->"C:\Program Files\HP Games\HP Game Console\Uninstall.exe"
-->"C:\Program Files\HP Games\Hunting Unlimited 2008\Uninstall.exe"
-->"C:\Program Files\HP Games\Insider Tales - The Secret of Casanova\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest II\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest Mysteries 2 Trail of the Midnight Heart\Uninstall.exe"
-->"C:\Program Files\HP Games\Jewel Quest Mysteries\Uninstall.exe"
-->"C:\Program Files\HP Games\Legacy - World Adventure\Uninstall.exe"
-->"C:\Program Files\HP Games\Liong - The Lost Amulets\Uninstall.exe"
-->"C:\Program Files\HP Games\Lost City of Aquatica\Uninstall.exe"
-->"C:\Program Files\HP Games\Lost Realms - Legacy of the Sun Princess\Uninstall.exe"
-->"C:\Program Files\HP Games\Magic Encyclopedia\Uninstall.exe"
-->"C:\Program Files\HP Games\Midnight Mysteries - The Edgar Allan Poe Conspiracy\Uninstall.exe"
-->"C:\Program Files\HP Games\Monopoly\Uninstall.exe"
-->"C:\Program Files\HP Games\Mortimer Beckett and the Secrets of Spooky Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Mortimer Beckett and the Time Paradox\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery Masterpiece - The Moonstone\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery of Shark Island\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery P.I. - Lost in Los Angeles\Uninstall.exe"
-->"C:\Program Files\HP Games\Mystery P.I. - The Vegas Heist\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - Curse of Blackmoor Manor\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - Legend of the Crystal Skull\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew - The Phantom of Venice\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew Dossier - Lights, Camera, Curses\Uninstall.exe"
-->"C:\Program Files\HP Games\Nancy Drew Dossier - Resorting to Danger!\Uninstall.exe"
-->"C:\Program Files\HP Games\Natalie Brooks - The Treasures of the Lost Kingdom\Uninstall.exe"
-->"C:\Program Files\HP Games\Obulis\Uninstall.exe"
-->"C:\Program Files\HP Games\Pahelika - Secret Legends\Uninstall.exe"
-->"C:\Program Files\HP Games\Paparazzi\Uninstall.exe"
-->"C:\Program Files\HP Games\Paranormal Agency\Uninstall.exe"
-->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
-->"C:\Program Files\HP Games\Pocahontas - Princess of the Powhatan\Uninstall.exe"
-->"C:\Program Files\HP Games\Princess Isabella - A Witch's Curse\Uninstall.exe"
-->"C:\Program Files\HP Games\Profitville\Uninstall.exe"
-->"C:\Program Files\HP Games\Samantha Swift and the Golden Touch\Uninstall.exe"
-->"C:\Program Files\HP Games\Save Our Spirit\Uninstall.exe"
-->"C:\Program Files\HP Games\Slingo Mystery - Whos Gold\Uninstall.exe"
-->"C:\Program Files\HP Games\StoneLoops of Jurassica\Uninstall.exe"
-->"C:\Program Files\HP Games\The Ancient Quest of Saqqarah\Uninstall.exe"
-->"C:\Program Files\HP Games\The Clumsys\Uninstall.exe"
-->"C:\Program Files\HP Games\The Count of Monte Cristo\Uninstall.exe"
-->"C:\Program Files\HP Games\The Legend of Crystal Valley\Uninstall.exe"
-->"C:\Program Files\HP Games\The Lost Cases of Sherlock Holmes\Uninstall.exe"
-->"C:\Program Files\HP Games\The Lost Inca Prophecy\Uninstall.exe"
-->"C:\Program Files\HP Games\The Mushroom Age\Uninstall.exe"
-->"C:\Program Files\HP Games\The Nightshift Code\Uninstall.exe"
-->"C:\Program Files\HP Games\The Secret of Margrave Manor 2\Uninstall.exe"
-->"C:\Program Files\HP Games\The Wizard's Pen\Uninstall.exe"
-->"C:\Program Files\HP Games\TikiBar\Uninstall.exe"
-->"C:\Program Files\HP Games\Torchlight\Uninstall.exe"
-->"C:\Program Files\HP Games\Totem Tribe\Uninstall.exe"
-->"C:\Program Files\HP Games\Tradewinds Odyssey\Uninstall.exe"
-->"C:\Program Files\HP Games\Trapped - The Abduction\Uninstall.exe"
-->"C:\Program Files\HP Games\Treasures of the Serengeti\Uninstall.exe"
-->"C:\Program Files\HP Games\Undiscovered World - The Incan Sun\Uninstall.exe"
-->"C:\Program Files\HP Games\Wandering Willows\Uninstall.exe"
-->"C:\Program Files\HP Games\Wild West Quest 2\Uninstall.exe"
-->"C:\Program Files\HP Games\Women's Murder Club - A Darker Shade of Grey\Uninstall.exe"
-->"C:\Program Files\HP Games\Zuma's Revenge\Uninstall.exe"
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
ActiveCheck component for HP Active Support Library-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.5 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
Ad-Remover By C_XX-->"C:\Program Files\Ad-Remover\Uninstall ADR.exe"
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
AOL Toolbar 5.0-->"C:\Program Files\AOL\AOL Toolbar 5.0\uninstall.exe"
Windows Live Connection Assistant-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
Avanquest update-->"C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -runfromtemp -l0x0009 -removeonly
Big Fish Games Client-->C:\Program Files\bfgclient\Uninstall.exe
Brutal Chess-->C:\Program Files\Brutal Chess\uninstall.exe
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Celestia 1.5.1-->"C:\Program Files\Celestia\unins000.exe"
CyberLink DVD Suite Deluxe-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" /z-uninstall
CyberLink DVD Suite Deluxe-->"C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" /z-uninstall
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dream Aquarium-->"C:\Program Files\Dream Aquarium\UnInstall.exe"
eMachines Games-->"C:\Program Files\eMachines Games\Uninstall.exe"
FreePack-->c:\FreePack\Uninstal.exe
Freeplayer-->C:\Program Files\Freeplayer\Uninstall.exe
Google Chrome-->"C:\Program Files\Google\Chrome\Application\3.0.195.38\Installer\setup.exe" --uninstall --system-level
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0E996B068B56FCA2.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658}
HP Active Support Library-->"C:\Program Files\InstallShield Installation Information\{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}\setup.exe" -runfromtemp -l0x0409 -removeonly
HP Advisor-->MsiExec.exe /X{73A43E42-3658-4DD9-8551-FACDA3632538}
HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{64B9E2F5-558E-4C56-B419-A1679518F6E7}\setup.exe" -l0x9 -removeonly
HP Demo-->MsiExec.exe /X{97ABD26A-3249-46CB-B2E2-F66E64B2E480}
HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart DVD-->"C:\Program Files\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall
HP MediaSmart Music/Photo/Video-->"C:\Program Files\InstallShield Installation Information\{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}\setup.exe" /z-uninstall /zMS
HP MediaSmart SmartMenu-->MsiExec.exe /I{EFC5939F-470F-454E-B3DA-F51FDD83F6CE}
HP My Display-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{15733AD1-1CEF-459A-9245-0924FC63BDD5}\setup.exe" -l0x40c -removeonly
HP Picasso Media Center Add-In-->MsiExec.exe /X{03BF5CB1-B72E-4CA6-A278-F65680F05420}
HP Recovery Manager RSS-->MsiExec.exe /X{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}
HP Total Care Setup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{38058455-8C21-4C2F-B2F6-14ED166039CB}\setup.exe" -l0x9 -removeonly
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
HPAsset component for HP Active Support Library-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
Windows Live Installation-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Installation-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
Kuros-->"C:\Program Files\Kuros\Uninstall.exe"
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LabelPrint-->"C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LG USB Modem driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3ABE126-2BB2-4246-BFE1-6797679B3579}\setup.exe" -l0x40c LG -removeonly
LightScribe System Software-->MsiExec.exe /X{7F10292C-A190-4176-A665-A1ED3478DF86}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee AntiSpyware Enterprise Module-->"C:\Program Files\McAfee\VirusScan Enterprise\scan32.exe" /UninstallMAS
McAfee VirusScan Enterprise-->MsiExec.exe /X{35C03C04-3F1F-42C2-A989-A757EE691F65}
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {B165D3C2-40AE-4D39-86F7-E5C87C4264C0}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {14809F99-C601-4D4A-9391-F1E8FAA964C5}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {A0516415-ED61-419A-981D-93596DA74165}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729-->MsiExec.exe /X{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}
Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
Update Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {B761869A-B85C-40E2-994C-A1CE78AC8F2C}
Update Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {C3DCA38E-005E-41BA-A52A-7C3429F351C3}
Update Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {81536A04-DBFB-4DB3-978F-0F284590C223}
Compatibility Module for Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
Microsoft .NET Framework 3.5 SP1 Language Module- fra-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
muvee Reveal-->MsiExec.exe /X{19506BDB-4EA7-491F-E8AB-E97109FDB296}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
Google Update Tool-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Windows Live Download Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Hardware Diagnostic Tools-->C:\Program Files\PC-Doctor for Windows\uninst.exe
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
Power2Go-->"C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
Python 2.5.2-->MsiExec.exe /I{6B976ADF-8AE8-434E-B282-A06C7F624D2F}
Real Chess-->"C:\Program Files\GameTop.com\Real Chess\unins000.exe"
RealArcade-->C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd.exe -r -m -nrg2709
SAMSUNG Mobile Modem Driver Set-->C:\Windows\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
Samsung Mobile phone USB driver Software-->C:\Windows\system32\Samsung_USB_Drivers\5\SSSDUninstall.exe
SAMSUNG Mobile USB Modem 1.0 Software-->C:\Windows\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
SAMSUNG Mobile USB Modem Software-->C:\Windows\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
SDK-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}\setup.exe" -l0x9
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002F-0000-0000000FF1CE}
Ok, that sounds good to me, and how about you, how's your PC?
Let's finish if that's okay with you:
Download Hijackthis then:
- Close all your applications (including the browser) and log out.
Run Hijackthis but click on "Do a scan only"
You will see the scan results appear: a multitude of lines, each preceded by an empty square.
You will click on the squares of the following lines:
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
Click on the FIX CHECKED button at the bottom and validate.
>Download Toolscleaner2 here:
https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/
>Install and run the program
>Click on "search" and let the scan finish
>Click on "delete" to finalize
>Click on "exit" so the report can be created
>Post the report
Purge the system restore
*Disable your restore:
Right-click on My Computer/properties/System Restore/check the box to disable restore, apply, OK
---> Restart the PC ...
*Re-enable your restore:
Right-click on My Computer/properties/System Restore/uncheck the box to disable restore, apply, OK
--->Restart the PC ...
Create a new restore point (this can be useful):
> Start
> All Programs
> Accessories
> System Tools
> System Restore.
In the welcome screen, choose "create a restore point", then give it a name like "restore point saint for example" and click on "create".
Update your Java console
>Download and install JavaRa here:
http://raproducts.org/click/click.php?id=1
>Extract the file with "extract here"
>Double-click on JavaRa.exe to run the program
>Select the language French
>Click on "check for updates"
>Choose the option "Update via jucheck.exe" then click on search
>Accept the installation of the new update
>Don't accept the yahoo toolbar which is a source of malware
>Return to the main interface and click on Delete old versions
>A confirmation will be requested, accept
A tutorial to help you:
http://www.libellules.ch/tuto_javara.php
Clean your disk
>Start, all programs
>Accessories, system tools
>Disk Cleanup
>Validate, then wait for the analysis to be fully completed
>Once the analysis is completed, a window will ask you which files you really want to delete, as well as the space they occupy on your disk
>You confirm and let the cleanup proceed
Defragment your disk
>Start, all programs
>Accessories, system tools
>Disk Defragmenter
For each of your disks, click "analyze" then defragment.
Improve your security
Tips to protect your PC:
A good antivirus:
Free: Avira Antivir or AVG free.
Paid: Kaspersky or Eset NOD32
Edit: try to avoid Avast at all costs.
A firewall:
The Windows one or a more effective one (uninstall the Windows one if you choose another):
Comodo or Kerio or Zone Alarm.
For COMODO, here is a little tutorial to configure it: https://www.malekal.com/tutorial-comodo-firewall/
An anti-spyware in addition: Spybot well
or Superantispyware
An anti-malware in addition: Malwarebytes
I recommend browsing with firefox if you haven't already, download the latest version here:
http://www.mozilla-europe.org/fr/firefox/
Coupled with good add-ons, you really improve your security, you couple it with:
Noscript >Tutorial to configure noscript: https://www.commentcamarche.net/faq/15677-noscript-un-bon-bouclier-et-obeissant
Wot
Adblock plus> http://www.6ma.fr/tuto/adblock-plus-bloquer-les-publicites-sur-firefox/
Avoid cracks and downloads with P2P (emule...) which are vectors of malware:
https://forum.malekal.com/viewtopic.php?t=893&start=
http://www.libellules.ch/
https://forum.malekal.com/viewtopic.php?t=3208&start=
--
*>flo-91<*®
Feel free to check out the forum's FAQ (tips section),
there may already be a solution to your problem =)
Let's finish if that's okay with you:
Download Hijackthis then:
- Close all your applications (including the browser) and log out.
Run Hijackthis but click on "Do a scan only"
You will see the scan results appear: a multitude of lines, each preceded by an empty square.
You will click on the squares of the following lines:
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
Click on the FIX CHECKED button at the bottom and validate.
>Download Toolscleaner2 here:
https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/
>Install and run the program
>Click on "search" and let the scan finish
>Click on "delete" to finalize
>Click on "exit" so the report can be created
>Post the report
Purge the system restore
*Disable your restore:
Right-click on My Computer/properties/System Restore/check the box to disable restore, apply, OK
---> Restart the PC ...
*Re-enable your restore:
Right-click on My Computer/properties/System Restore/uncheck the box to disable restore, apply, OK
--->Restart the PC ...
Create a new restore point (this can be useful):
> Start
> All Programs
> Accessories
> System Tools
> System Restore.
In the welcome screen, choose "create a restore point", then give it a name like "restore point saint for example" and click on "create".
Update your Java console
>Download and install JavaRa here:
http://raproducts.org/click/click.php?id=1
>Extract the file with "extract here"
>Double-click on JavaRa.exe to run the program
>Select the language French
>Click on "check for updates"
>Choose the option "Update via jucheck.exe" then click on search
>Accept the installation of the new update
>Don't accept the yahoo toolbar which is a source of malware
>Return to the main interface and click on Delete old versions
>A confirmation will be requested, accept
A tutorial to help you:
http://www.libellules.ch/tuto_javara.php
Clean your disk
>Start, all programs
>Accessories, system tools
>Disk Cleanup
>Validate, then wait for the analysis to be fully completed
>Once the analysis is completed, a window will ask you which files you really want to delete, as well as the space they occupy on your disk
>You confirm and let the cleanup proceed
Defragment your disk
>Start, all programs
>Accessories, system tools
>Disk Defragmenter
For each of your disks, click "analyze" then defragment.
Improve your security
Tips to protect your PC:
A good antivirus:
Free: Avira Antivir or AVG free.
Paid: Kaspersky or Eset NOD32
Edit: try to avoid Avast at all costs.
A firewall:
The Windows one or a more effective one (uninstall the Windows one if you choose another):
Comodo or Kerio or Zone Alarm.
For COMODO, here is a little tutorial to configure it: https://www.malekal.com/tutorial-comodo-firewall/
An anti-spyware in addition: Spybot well
or Superantispyware
An anti-malware in addition: Malwarebytes
I recommend browsing with firefox if you haven't already, download the latest version here:
http://www.mozilla-europe.org/fr/firefox/
Coupled with good add-ons, you really improve your security, you couple it with:
Noscript >Tutorial to configure noscript: https://www.commentcamarche.net/faq/15677-noscript-un-bon-bouclier-et-obeissant
Wot
Adblock plus> http://www.6ma.fr/tuto/adblock-plus-bloquer-les-publicites-sur-firefox/
Avoid cracks and downloads with P2P (emule...) which are vectors of malware:
https://forum.malekal.com/viewtopic.php?t=893&start=
http://www.libellules.ch/
https://forum.malekal.com/viewtopic.php?t=3208&start=
--
*>flo-91<*®
Feel free to check out the forum's FAQ (tips section),
there may already be a solution to your problem =)
Previous
- 1
- 2