log.txt
Logfile of random's system information tool 1.04 (written by random/random)
Run by Muneeb at 2008-10-14 11:04:10
Microsoft Windows XP Professional Service Pack 2
System drive C: has 5 GB (52%) free of 10 GB
Total RAM: 255 MB (15% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:12 AM, on 10/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Atievxx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\All Users\Application Data\qxedyrwr\mbcfedyv.exe
C:\WINDOWS\tsnpstd3.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\ofobkdkf.exe
C:\Program Files\Customer\Wireless PCI_CardBus utility V1.01\Wireless PCI_CardBus utility V1.01.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Muneeb\Desktop\RSIT.exe
C:\Program Files\trend micro\Muneeb.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.orkut.com
F2 - REG:system.ini: Shell=Explorer.exe "C:\Documents and Settings\Muneeb\Desktop\Setup.exe"
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,"C:\Documents and Settings\Muneeb\Desktop\Setup.exe",
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Oxford Dictionary] "oxford.exe" /tray
O4 - HKCU\..\Run: [PoivY] "C:\Program Files\PoivY.com\PoivY\PoivY.exe" -nosplash -minimized
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKCU\..\Run: [ComApi] C:\WINDOWS\system32\ofobkdkf.exe
O4 - HKCU\..\Run: [InfoDscApl] C:\WINDOWS\system32\inqvcvqh.exe
O4 - HKCU\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe
O4 - HKLM\..\Policies\Explorer\Run: [MMCfsJxbkc] C:\Documents and Settings\All Users\Application Data\qxedyrwr\mbcfedyv.exe
O4 - Global Startup: Wireless PCI_CardBus utility V1.01.exe.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://go.divx.com/p...owserPlugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: karna.dat
O21 - SSODL: chksh - {1F21957C-4D5A-3B5A-80A3-090AF0D9C993} - C:\Program Files\qsgjurf\chksh.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
--
End of file - 3823 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At9.job
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At18.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At25.job
C:\WINDOWS\tasks\At26.job
C:\WINDOWS\tasks\At27.job
C:\WINDOWS\tasks\At28.job
C:\WINDOWS\tasks\At29.job
C:\WINDOWS\tasks\At30.job
C:\WINDOWS\tasks\At31.job
C:\WINDOWS\tasks\At32.job
C:\WINDOWS\tasks\At33.job
C:\WINDOWS\tasks\At34.job
C:\WINDOWS\tasks\At35.job
C:\WINDOWS\tasks\At36.job
C:\WINDOWS\tasks\At37.job
C:\WINDOWS\tasks\At38.job
C:\WINDOWS\tasks\At39.job
C:\WINDOWS\tasks\At40.job
C:\WINDOWS\tasks\At41.job
C:\WINDOWS\tasks\At42.job
C:\WINDOWS\tasks\At43.job
C:\WINDOWS\tasks\At44.job
C:\WINDOWS\tasks\At45.job
C:\WINDOWS\tasks\At46.job
C:\WINDOWS\tasks\At47.job
C:\WINDOWS\tasks\At48.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2006-11-29 262144]
""= []
"Oxford Dictionary"= []
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-29 1234712]
"googletalk"=C:\Program Files\Google\Google Talk\googletalk.exe [2007-01-01 3739648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2006-09-18 843776]
"PE2CKFNT SE"=C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe [1998-07-03 25088]
"brastk"=C:\WINDOWS\system32\brastk.exe []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"MMCfsJxbkc"=C:\Documents and Settings\All Users\Application Data\qxedyrwr\mbcfedyv.exe [2008-10-13 61440]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2008-08-09 5674352]
"Yahoo! Pager"=C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE [2007-01-19 4670968]
"Oxford Dictionary"=oxford.exe /tray []
""= []
"PoivY"=C:\Program Files\PoivY.com\PoivY\PoivY.exe [2008-09-26 9102112]
"SVCHOST.EXE"=C:\WINDOWS\system32\drivers\svchost.exe [2008-10-13 30720]
"ComApi"=C:\WINDOWS\system32\ofobkdkf.exe [2008-10-13 77824]
"InfoDscApl"=C:\WINDOWS\system32\inqvcvqh.exe [2008-10-14 77824]
"brastk"=C:\WINDOWS\system32\brastk.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Calendar Checker]
C:\Program Files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Wireless PCI_CardBus utility V1.01.exe.lnk - C:\Program Files\Customer\Wireless PCI_CardBus utility V1.01\Wireless PCI_CardBus utility V1.01.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="karna.dat"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
chksh - {1F21957C-4D5A-3B5A-80A3-090AF0D9C993} - C:\Program Files\qsgjurf\chksh.dll [2008-10-13 106496]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe"="C:\Program Files\Voipwise.com\Voipwise\Voipwise.exe:*:Enabled:Voipwise"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"D:\Games\Commandos 3\commandos3.exe"="D:\Games\Commandos 3\commandos3.exe:*:Enabled:commandos3"
"C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe"="C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:*:Enabled:VideoAccelerator"
"C:\Program Files\PoivY.com\PoivY\PoivY.exe"="C:\Program Files\PoivY.com\PoivY\PoivY.exe:*:Enabled:PoivY"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4338e5cb-6632-11dd-af06-0810741381b7}]
shell\AutoRun\command - rxukgcm.exe
shell\explore\command - rxukgcm.exe
shell\open\command - rxukgcm.exe
======List of files/folders created in the last 1 months======
2008-10-14 11:04:18 ----D---- C:\Program Files\trend micro
2008-10-14 11:04:09 ----D---- C:\rsit
2008-10-14 02:36:16 ----SHD---- C:\FOUND.002
2008-10-14 02:33:49 ----A---- C:\WINDOWS\system32\inqvcvqh.exe
2008-10-14 02:08:10 ----D---- C:\WINDOWS\system32\appmgmt
2008-10-14 02:08:03 ----SHD---- C:\Config.Msi
2008-10-14 01:31:56 ----A---- C:\WINDOWS\system32\CMMGR32.EXE
2008-10-14 01:16:27 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-14 01:15:14 ----D---- C:\Program Files\SUPERAntiSpyware
2008-10-14 01:15:13 ----D---- C:\Documents and Settings\Muneeb\Application Data\SUPERAntiSpyware.com
2008-10-14 00:21:37 ----HD---- C:\WINDOWS\system32\GroupPolicy
2008-10-13 22:35:59 ----A---- C:\WINDOWS\brastk.exe
2008-10-13 22:34:47 ----A---- C:\WINDOWS\zipped.tmp
2008-10-13 22:34:47 ----A---- C:\WINDOWS\zip3.tmp
2008-10-13 22:34:47 ----A---- C:\WINDOWS\zip2.tmp
2008-10-13 22:34:47 ----A---- C:\WINDOWS\zip1.tmp
2008-10-13 22:34:47 ----A---- C:\WINDOWS\userconfig9x.dll
2008-10-13 22:34:47 ----A---- C:\WINDOWS\system32\winlogonpc.exe
2008-10-13 22:34:47 ----A---- C:\WINDOWS\FVProtect.exe
2008-10-13 22:34:47 ----A---- C:\WINDOWS\base64.tmp
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\taack.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\ps1.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\mwin32.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\hxiwlgpm.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\hoproxy.dll
2008-10-13 22:34:46 ----A---- C:\WINDOWS\system32\bsva-egihsg52.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\iTunesMusic.exe
2008-10-13 22:34:46 ----A---- C:\WINDOWS\a.bat
2008-10-13 22:34:45 ----A---- C:\WINDOWS\system32\msnbho.dll
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\temp#01.exe
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\ssurf022.dll
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\netode.exe
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\mtr2.exe
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\msgp.exe
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\medup020.dll
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\medup012.dll
2008-10-13 22:34:44 ----A---- C:\WINDOWS\system32\h@tkeysh@@k.dll
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\thun32.dll
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\thun.dll
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\ssvchost.exe
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\ssvchost.com
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\Rundl1.exe
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\regm64.dll
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\regc64.dll
2008-10-13 22:34:43 ----A---- C:\WINDOWS\system32\msvchost.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\winsystem.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\WINWGPX.EXE
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\winsystem.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\vcatchpi.dll
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\sysreq.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\newsd32.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\mssecu.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\emesx.dll
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\bdn.com
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\anticipator.dll
2008-10-13 22:34:42 ----A---- C:\WINDOWS\system32\akttzn.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\mssecu.exe
2008-10-13 22:34:42 ----A---- C:\WINDOWS\bdn.com
2008-10-13 22:34:41 ----A---- C:\WINDOWS\system32\vbsys2.dll
2008-10-13 22:34:41 ----A---- C:\WINDOWS\system32\awtoolb.dll
2008-10-13 22:34:07 ----D---- C:\Program Files\qsgjurf
2008-10-13 22:34:06 ----D---- C:\Documents and Settings\All Users\Application Data\qxedyrwr
2008-10-13 22:34:01 ----A---- C:\WINDOWS\system32\ofobkdkf.exe
2008-10-12 01:26:57 ----A---- C:\WINDOWS\system32\74Br7Kr3.exe.a_a
2008-10-07 22:29:24 ----SHD---- C:\FOUND.001
2008-10-07 18:47:58 ----A---- C:\WINDOWS\ULEAD32.INI
2008-10-07 18:47:44 ----A---- C:\WINDOWS\system32\MFCO40.DLL
2008-10-07 18:47:05 ----D---- C:\Program Files\Ulead Systems
2008-10-01 22:35:20 ----D---- C:\Documents and Settings\Muneeb\Application Data\PoivY
2008-10-01 22:30:59 ----D---- C:\Program Files\PoivY.com
2008-09-22 19:59:57 ----D---- C:\Documents and Settings\Muneeb\Application Data\IrfanView
2008-09-21 22:45:03 ----SHD---- C:\Documents and Settings\Muneeb\Application Data\.#
2008-09-21 22:44:44 ----A---- C:\WINDOWS\system32\suppdll.dll
2008-09-21 22:44:42 ----D---- C:\Program Files\Folder Lock
2008-09-21 15:39:57 ----D---- C:\Documents and Settings\Muneeb\Application Data\Media Player Classic
2008-09-21 15:36:32 ----A---- C:\WINDOWS\system32\msvcr71.dll
======List of files/folders modified in the last 1 months======
2008-10-14 07:45:06 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-10-05 00:28:30 ----A---- C:\WINDOWS\win.ini
2008-09-27 12:33:28 ----SH---- C:\boot.ini
2008-09-27 12:33:28 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-29 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-08-09 26824]
R1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2004-08-04 42496]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-08-09 76040]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-03 87424]
R2 windrvNT;windrvNT; \??\C:\WINDOWS\system32\windrvNT.sys []
R3 atimtai;atimtai; C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-17 281600]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 maestro;ESS Maestro 3 Audio Driver (WDM); C:\WINDOWS\system32\drivers\es198x.sys [2001-08-17 174464]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\system32\DRIVERS\smcirda.sys [2001-08-17 35913]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 USRWDXJS;USRWDXJSMiniPCI Winmodem; C:\WINDOWS\system32\DRIVERS\USRWDXJS.sys [2001-08-17 687999]
R3 W8335XP;802.11g/b Driver for Windows XP ; C:\WINDOWS\system32\DRIVERS\Mrvw125.sys [2005-12-29 282624]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys [2004-08-03 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2007-03-21 10198144]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Atievxx.exe [2001-08-17 37376]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
-----------------EOF-----------------
info.txt
info.txt logfile of random's system information tool 1.04 2008-10-14 11:05:20
======Uninstall list======
-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Age Of Empire-II The Conquerors-->C:\WINDOWS\unvise32.exe D:\Games\Age Of Empire-II The Conquerors\uninstal.log
AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Chariots of War-->D:\Games\STRATE~1\CHARIO~1\UNWISE.EXE D:\Games\STRATE~1\CHARIO~1\INSTALL.LOG
Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
Google Talk (remove only)-->"C:\Program Files\Google\Google Talk\uninstall.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
IrfanView (remove only)-->C:\Program Files\IrfanView\iv_uninstall.exe
jetAudio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487-A0EE-196F7E3F4B8A}\Setup.exe" -l0x9
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (2.0b1)-->"C:\Program Files\Mozilla Firefox 2 Beta 1\uninstall\uninstaller.exe" "/ua 2.0b1 (en-US)"
Oxford English Explanatory Dictionary-->MsiExec.exe /X{05E73DD3-7D9E-4913-AF70-219EB395E4B7}
PoivY-->"C:\Program Files\PoivY.com\PoivY\unins000.exe"
RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
The Hadith Software Version 1.1-->"C:\Program Files\The Hadith Software\unins000.exe"
Ulead Photo Express 2.0 SE-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\Uninst.isu" -c"C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\IS32Inst.dll"
USB PC Camera Plus-->C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\setup.exe -runfromtemp -l0x0009 -removeonly
Voipwise-->"C:\Program Files\Voipwise.com\Voipwise\unins000.exe"
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Wireless PCI_CardBus utility V1.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0150ECF7-60CB-43C5-AB0A-877BB76ABA55}\setup.exe" -l0x9 -removeonly
Yahoo! Messenger-->C:\PROGRA~1\YAHOO!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\YAHOO!\MESSEN~1\INSTALL.LOG
======Security center information======
AV: AVG Anti-Virus Free
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Ulead Systems\MPEG
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 6, GenuineIntel
"PROCESSOR_REVISION"=0806
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------