Here are the logs:
log.txt:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Moshe Spira at 2009-11-04 12:30:20
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 14 GB (24%) free of 57 GB
Total RAM: 382 MB (17% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:05 PM, on 11/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Stickies\stickies.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Moshe Spira\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Moshe Spira.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptopO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - S-1-5-18 Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - .DEFAULT Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1254513997062O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Blue Coat K9 Web Protection (bckwfs) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Desktop Manager 5.9.909.8267 (GoogleDesktopManager-090809-085438) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 8566 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2009-02-27 61816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-10-24 1471768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-28 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-28 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2005-02-17 233534]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2004-10-13 278528]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-10-02 98304]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-07-13 344064]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-11-14 815104]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-05 30192]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2009-10-19 1799952]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-10-26 2010904]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-28 149280]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
C:\Documents and Settings\Moshe Spira\Start Menu\Programs\Startup
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
Stickies.lnk - C:\Program Files\Stickies\stickies.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-07-14 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-10-24 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2009-11-04 12:30:20 ----D---- C:\rsit
2009-11-01 16:36:41 ----A---- C:\WINDOWS\system32\MRT.exe
2009-11-01 16:35:13 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-11-01 16:35:06 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-11-01 16:34:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-11-01 16:34:38 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-11-01 16:34:21 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-11-01 16:34:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-11-01 16:34:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-11-01 16:33:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-11-01 16:33:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-10-28 23:45:36 ----D---- C:\WINDOWS\Sun
2009-10-28 23:44:27 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-28 23:44:27 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-28 23:44:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-10-28 23:44:26 ----A---- C:\WINDOWS\system32\java.exe
2009-10-28 23:42:54 ----D---- C:\Program Files\Java
2009-10-28 23:38:49 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\Sun
2009-10-27 19:12:56 ----D---- C:\WINDOWS\temp
2009-10-27 19:12:50 ----A---- C:\ComboFix.txt
2009-10-27 19:12:48 ----A---- C:\log.txt
2009-10-27 18:48:04 ----A---- C:\WINDOWS\zip.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\SWSC.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\SWREG.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\sed.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\PEV.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\NIRCMD.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\MBR.exe
2009-10-27 18:48:04 ----A---- C:\WINDOWS\grep.exe
2009-10-27 18:47:10 ----D---- C:\Qoobox
2009-10-24 21:33:49 ----D---- C:\$AVG
2009-10-24 21:31:52 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2009-10-24 21:30:43 ----D---- C:\WINDOWS\SxsCaPendDel
2009-10-20 19:09:01 ----A---- C:\WINDOWS\cfplogvw.INI
2009-10-19 16:24:03 ----D---- C:\Documents and Settings\All Users\Application Data\Comodo
2009-10-19 16:23:57 ----A---- C:\WINDOWS\system32\guard32.dll
2009-10-19 16:23:36 ----D---- C:\Program Files\COMODO
2009-10-18 15:34:18 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-18 15:33:48 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-18 15:23:55 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-10-18 00:46:16 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\Mozilla
2009-10-18 00:46:01 ----D---- C:\Program Files\Mozilla Firefox
2009-10-17 20:56:23 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\stickies
2009-10-17 20:56:12 ----D---- C:\Program Files\Stickies
2009-10-14 14:01:42 ----D---- C:\RECYCLER
2009-10-12 01:49:21 ----A---- C:\Boot.bak
2009-10-12 01:49:16 ----RASHD---- C:\cmdcons
2009-10-12 01:45:56 ----D---- C:\WINDOWS\ERDNT
2009-10-09 17:37:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-10-09 13:54:21 ----D---- C:\Program Files\Trend Micro
2009-10-08 19:39:54 ----D---- C:\Config.Msi
2009-10-07 22:49:56 ----D---- C:\Program Files\Blue Coat K9 Web Protection
2009-10-07 10:47:09 ----A---- C:\WINDOWS\muveeapp.INI
2009-10-07 10:45:39 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\muvee Technologies
2009-10-06 20:49:37 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-06 20:48:38 ----D---- C:\Program Files\SUPERAntiSpyware
2009-10-06 20:48:38 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\SUPERAntiSpyware.com
2009-10-06 20:47:27 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-10-06 20:44:28 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-10-06 20:44:28 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-06 20:41:55 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\Malwarebytes
2009-10-06 20:41:41 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-06 16:52:04 ----D---- C:\Program Files\AVG
2009-10-06 00:44:20 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-10-06 00:44:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-10-06 00:43:59 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-10-06 00:43:45 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-10-06 00:43:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-10-06 00:43:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-10-06 00:43:25 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-10-06 00:43:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-10-06 00:43:11 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-10-06 00:43:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-10-06 00:42:52 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-10-06 00:42:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-10-06 00:42:21 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-10-06 00:42:11 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-10-06 00:42:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-10-06 00:41:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-10-06 00:41:47 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-10-06 00:41:39 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-10-06 00:41:32 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-10-06 00:41:26 ----D---- C:\Program Files\MSXML 4.0
2009-10-06 00:41:02 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-10-06 00:40:54 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-10-06 00:40:44 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-10-06 00:40:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-10-06 00:40:01 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-10-06 00:39:48 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-10-06 00:39:40 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-10-06 00:39:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-10-06 00:39:28 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-10-06 00:39:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-10-06 00:39:13 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-10-06 00:39:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-10-06 00:38:57 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-10-06 00:38:49 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-10-06 00:38:41 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-10-06 00:38:16 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-10-06 00:38:09 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-10-06 00:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-10-06 00:37:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-10-06 00:37:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-10-06 00:37:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-10-06 00:37:34 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-10-06 00:37:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-10-06 00:37:16 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-10-06 00:36:47 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-10-06 00:35:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-10-06 00:34:31 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-10-06 00:34:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-10-06 00:33:00 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-10-06 00:26:31 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-10-05 22:43:49 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-10-05 21:45:00 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\AdobeUM
2009-10-05 21:44:28 ----D---- C:\Program Files\Common Files\Adobe
2009-10-05 19:32:20 ----D---- C:\Davar
2009-10-05 19:24:12 ----A---- C:\WINDOWS\Kaluach3.INI
2009-10-05 19:23:58 ----D---- C:\Program Files\Kaluach3
2009-10-05 19:16:06 ----A---- C:\WINDOWS\system32\msonpmon.dll
2009-10-05 19:12:18 ----D---- C:\Program Files\Microsoft Works
2009-10-05 19:11:17 ----D---- C:\Program Files\MSBuild
2009-10-05 19:09:17 ----D---- C:\Program Files\Microsoft Visual Studio
2009-10-05 19:09:17 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-05 19:06:23 ----D---- C:\Program Files\Microsoft.NET
2009-10-05 19:00:46 ----D---- C:\WINDOWS\SHELLNEW
2009-10-05 18:59:23 ----D---- C:\Program Files\Microsoft Office
2009-10-05 18:59:18 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-10-05 18:58:07 ----RD---- C:\MSOCache
2009-10-05 16:42:55 ----D---- C:\Program Files\Google
2009-10-05 15:33:45 ----A---- C:\WINDOWS\system32\SynTPCo4.dll
2009-10-05 15:33:45 ----A---- C:\WINDOWS\system32\SynTPAPI.dll
2009-10-05 15:33:45 ----A---- C:\WINDOWS\system32\SynCtrl.dll
2009-10-05 15:33:45 ----A---- C:\WINDOWS\system32\SynCOM.dll
2009-10-05 15:33:44 ----D---- C:\Program Files\Synaptics
2009-10-05 15:15:33 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-05 15:15:27 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-10-05 15:14:49 ----D---- C:\Program Files\Windows Media Connect 2
2009-10-05 15:14:22 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-10-05 15:11:47 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-10-05 15:10:49 ----D---- C:\WINDOWS\system32\LogFiles
2009-10-05 15:10:36 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-10-05 14:53:08 ----D---- C:\Program Files\ATI Technologies
2009-10-05 14:51:55 ----D---- C:\swsetup
2009-10-05 14:37:40 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\MSNInstaller
2009-10-05 13:53:16 ----D---- C:\WINDOWS\ie8updates
2009-10-05 13:52:02 ----D---- C:\WINDOWS\WBEM
2009-10-05 13:50:12 ----HDC---- C:\WINDOWS\ie8
2009-10-05 13:28:00 ----D---- C:\Documents and Settings\Moshe Spira\Application Data\Adobe
2009-10-05 12:06:09 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-10-05 11:57:41 ----D---- C:\Documents and Settings\All Users\Application Data\Seagate
2009-10-05 11:57:04 ----SHD---- C:\WINDOWS\ftpcache
======List of files/folders modified in the last 1 months======
2009-11-04 12:30:22 ----D---- C:\WINDOWS\Prefetch
2009-11-03 12:27:47 ----SD---- C:\Documents and Settings\Moshe Spira\Application Data\Microsoft
2009-11-02 17:57:24 ----D---- C:\WINDOWS\system32
2009-11-02 17:57:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-11-02 17:54:08 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-01 19:44:01 ----D---- C:\WINDOWS
2009-11-01 16:45:20 ----D---- C:\Program Files\Internet Explorer
2009-11-01 16:44:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-01 16:35:19 ----HD---- C:\WINDOWS\inf
2009-11-01 16:35:17 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-11-01 16:35:09 ----A---- C:\WINDOWS\imsins.BAK
2009-11-01 16:35:07 ----D---- C:\WINDOWS\WinSxS
2009-11-01 16:34:46 ----HD---- C:\WINDOWS\$hf_mig$
2009-11-01 16:32:19 ----SHD---- C:\WINDOWS\Installer
2009-10-31 21:11:49 ----D---- C:\Documents and Settings\All Users\Application Data\QuickTime
2009-10-28 23:42:54 ----RD---- C:\Program Files
2009-10-27 19:10:01 ----A---- C:\WINDOWS\system.ini
2009-10-27 19:01:20 ----D---- C:\WINDOWS\system32\drivers
2009-10-27 19:01:19 ----D---- C:\WINDOWS\AppPatch
2009-10-27 19:01:02 ----D---- C:\Program Files\Common Files
2009-10-24 21:30:56 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-18 16:56:40 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-18 15:37:02 ----D---- C:\Program Files\Adobe
2009-10-17 23:27:00 ----D---- C:\WINDOWS\network diagnostic
2009-10-17 19:38:25 ----D---- C:\WINDOWS\system32\wbem
2009-10-14 16:55:14 ----SHD---- C:\System Volume Information
2009-10-14 16:55:14 ----D---- C:\WINDOWS\system32\Restore
2009-10-12 22:25:40 ----D---- C:\WINDOWS\system32\config
2009-10-12 01:49:21 ----RASH---- C:\boot.ini
2009-10-08 19:43:06 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-08 19:43:05 ----D---- C:\Program Files\HPQ
2009-10-07 10:57:59 ----D---- C:\Program Files\Online Services
2009-10-06 16:52:57 ----D---- C:\WINDOWS\Registration
2009-10-06 16:25:57 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-06 00:43:13 ----D---- C:\Program Files\Outlook Express
2009-10-06 00:37:36 ----D---- C:\Program Files\Messenger
2009-10-05 21:48:31 ----RSD---- C:\WINDOWS\Fonts
2009-10-05 19:06:23 ----D---- C:\WINDOWS\pchealth
2009-10-05 19:01:55 ----A---- C:\WINDOWS\win.ini
2009-10-05 19:01:35 ----D---- C:\Program Files\Common Files\System
2009-10-05 15:14:49 ----D---- C:\Program Files\Windows Media Player
2009-10-05 15:14:39 ----D---- C:\WINDOWS\Help
2009-10-05 14:53:23 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-10-05 13:52:02 ----D---- C:\WINDOWS\system32\en-us
2009-10-05 13:51:39 ----D---- C:\WINDOWS\Media
2009-10-05 13:46:49 ----D---- C:\WINDOWS\Debug
2009-10-05 11:57:10 ----D---- C:\WINDOWS\Downloaded Installations
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-08-11 39424]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-10-24 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-10-24 28424]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-10-26 360584]
R1 bckd;bckd; C:\WINDOWS\system32\drivers\bckd.sys [2009-01-13 72992]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2009-10-19 132296]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2009-10-19 25160]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-07-14 1269760]
R3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2005-03-10 371712]
R3 CAMCAUD;Conexant AMC Audio; C:\WINDOWS\system32\drivers\camc6aud.sys [2005-02-18 38016]
R3 CAMCHALA;CAMCHALA; C:\WINDOWS\system32\drivers\camc6hal.sys [2005-02-18 349696]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2004-12-15 1038208]
R3 HSFHWATI;HSFHWATI; C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-03 74496]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-11-14 199040]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2005-03-16 159488]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2004-12-15 703232]
S1 eabfiltr;EABFiltr; \??\C:\WINDOWS\system32\drivers\EABFiltr.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\MOSHES~1\LOCALS~1\Temp\catchme.sys []
S3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2004-09-14 13872]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-07-14 380928]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-10-24 285392]
R2 bckwfs;Blue Coat K9 Web Protection; C:\Program Files\Blue Coat K9 Web Protection\k9filter.exe [2009-01-13 1078560]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2009-10-19 723632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-28 153376]
R3 iPodService;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2004-10-13 327680]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 GoogleDesktopManager-090809-085438;Google Desktop Manager 5.9.909.8267; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-05 30192]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
-----------------EOF-----------------
info.txt:
info.txt logfile of random's system information tool 1.06 2009-11-04 12:32:13
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->msiexec /qb /x {6D8D64BE-F500-55B6-705D-DFD08AFE0624}
Acrobat.com-->MsiExec.exe /I{6D8D64BE-F500-55B6-705D-DFD08AFE0624}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 9.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A92000000001}
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x9
ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
Blue CoatŪ K9 Web Protection 4.0.288-->C:\Program Files\Blue Coat K9 Web Protection\uninst.exe
Broadcom 802.11 Wireless LAN Adapter-->C:\WINDOWS\system32\BCMWLU00.exe verbose /rootkey=Software\Broadcom\802.11\UninstallInfo
COMODO Internet Security-->C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe -u
Conexant AC-Link Audio-->C:\Program Files\CONEXANT\CNXT_AUDIO\HXFSETUP.EXE -U -Iqta3091.inf
Data Fax SoftModem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_1002&DEV_4378&SUBSYS_3091103C\HXFSETUP.EXE -U -IVEN_1002&DEV_4378&SUBSYS_3091103C
Davar 2.4-->C:\Davar\unins000.exe
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
iTunes-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BE20E2F5-1903-4AAE-B1AF-2046E586C925}
Java 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Ultimate 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ULTIMATER /dll OSETUP.DLL
Microsoft Office Ultimate 2007-->MsiExec.exe /X{91120000-002E-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Works-->MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
Mozilla Firefox (2.0.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
REALTEK Gigabit and Fast Ethernet NIC Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe" -l0x9 REMOVE
Security Update for Windows Internet Explorer 8 (KB971961)-->"C:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB972260)-->"C:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 8 (KB974455)-->"C:\WINDOWS\ie8updates\KB974455-IE8\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Stickies 6.7a-->"C:\WINDOWS\lsb_un20.exe" /C=UC /N=Stickies 6.7a
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Texas Instruments PCIxx21/x515 drivers.-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{612DC38A-B36A-4699-88EB-12C7394DE2FC} /l1033
Update for Windows Internet Explorer 8 (KB973874)-->"C:\WINDOWS\ie8updates\KB973874-IE8\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
======Hosts File======
127.0.0.1 go.mail.ru
127.0.0.1 nova.rambler.ru
127.0.0.1 google.ad
127.0.0.1 www.google.ad
127.0.0.1 google.ae
127.0.0.1 www.google.ae
127.0.0.1 google.am
127.0.0.1 www.google.am
127.0.0.1 google.com.ar
127.0.0.1 www.google.com.ar
======Security center information======
AV: AVG Anti-Virus Free
FW: COMODO Firewall
======System event log======
Computer Name: MOSHE-COMPAQ
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
Record Number: 1751
Source Name: DCOM
Time Written: 20091007173534.000000-240
Event Type: error
User: MOSHE-COMPAQ\Moshe Spira
Computer Name: MOSHE-COMPAQ
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
eabfiltr
Record Number: 1732
Source Name: Service Control Manager
Time Written: 20091007171721.000000-240
Event Type: error
User:
Computer Name: MOSHE-COMPAQ
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
eabfiltr
Record Number: 1710
Source Name: Service Control Manager
Time Written: 20091007160519.000000-240
Event Type: error
User:
Computer Name: MOSHE-COMPAQ
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
eabfiltr
Record Number: 1688
Source Name: Service Control Manager
Time Written: 20091007154110.000000-240
Event Type: error
User:
Computer Name: MOSHE-COMPAQ
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
Record Number: 1678
Source Name: DCOM
Time Written: 20091007115306.000000-240
Event Type: error
User: MOSHE-COMPAQ\Moshe Spira
=====Application event log=====
Computer Name: MOSHE-COMPAQ
Event Code: 1002
Message: Hanging application iexplore.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Record Number: 107
Source Name: Application Hang
Time Written: 20091005145427.000000-240
Event Type: error
User:
Computer Name: MOSHE-COMPAQ
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 88
Source Name: WinMgmt
Time Written: 20091002181830.000000-240
Event Type: warning
User: MOSHE-COMPAQ\Moshe Spira
Computer Name: MOSHE-COMPAQ
Event Code: 1517
Message: Windows saved user MOSHE-COMPAQ\Moshe Spira registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
Record Number: 71
Source Name: Userenv
Time Written: 20091002151248.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: MOSHE-COMPAQ
Event Code: 1020
Message: Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i.
Record Number: 60
Source Name: ASP.NET 1.1.4322.0
Time Written: 20091002145200.000000-240
Event Type: warning
User:
Computer Name: MOSHE-COMPAQ
Event Code: 1020
Message: Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine. To configure ASP.NET to run in IIS, please install or enable IIS and re-register ASP.NET using aspnet_regiis.exe /i.
Record Number: 45
Source Name: ASP.NET 1.1.4322.0
Time Written: 20091002145034.000000-240
Event Type: warning
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\ATI Technologies\ATI Control Panel
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 36 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2402
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------