--- Search result list ---
CoolWWWSearch: Program directory (Directory, nothing done)
C:\Documents and Settings\Airwolf11\Local Settings\Temporary Internet Files\MSFT\
CoolWWWSearch: Data (File, nothing done)
C:\Documents and Settings\Airwolf11\Local Settings\Temp\4.tmp
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Ab scissor.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Broadband comparison.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Credit counseling.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Credit report.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Crm software.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Debt credit card.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Escorts.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Fha.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Health insurance.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Help desk software.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Insurance home.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Loan for debt consolidation.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Loan for people with bad credit.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Marketing email.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Mortgage insurance.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Mortgage life insurance.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Nevada corporations.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Online Betting Site.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Online gambling casino.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Online instant loan.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Order phentermine.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Payroll advance.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Personal loans online.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Personal loans with bad credit.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Prescription Drugs Rx Online.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Refinancing my mortgage.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Tahoe vacation rental.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Unsecured bad credit loans.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\Videos.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\What is hydrocodone.url
CoolWWWSearch.Aff.Winshow: Program directory (Directory, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Sites about\
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Only sex website.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Search the web.url
CoolWWWSearch.Aff.Winshow: Link (File, nothing done)
C:\Documents and Settings\Airwolf11\Favorites\Seven days of free [bleep].url
CoolWWWSearch.Feat2Installer: Data (File, nothing done)
C:\WINDOWS\system32\ckslh.log
CoolWWWSearch.Feat2Installer.ADS: Data (File, nothing done)
C:\WINDOWS\regopt.log:ipoish:$DATA
CoolWWWSearch.HomeSearch: Executable (File, nothing done)
C:\WINDOWS\Q819696.log:xnlpwn:$DATA
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_USERSS-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_USERSS-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Internet Explorer\Main\Search Bar=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_USERSS-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Main\Search Page=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Main\Search Bar=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Main\Default_Search_URL=about:blank
CoolWWWSearch.IELinks: IE Search page (Registry change, nothing done)
HKEY_LOCAL_MACHINESoftware\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank
CoolWWWSearch.SearchKlick: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA\DisplayName
CoolWWWSearch.SearchKlick: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA\UninstallString
Smitfraud-C.: User settings (Registry value, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\Wallpaper=...C:\WINDOWS\desktop.html...
Smitfraud-C.: Autorun settings (Windows installer) (Registry value, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows installer
Smitfraud-C.: Program file (File, nothing done)
C:\winstall.exe
Smitfraud-C.: Web page (File, nothing done)
C:\WINDOWS\desktop.html
CoolWWWSearch: Data (File, nothing done)
C:\WINDOWS\system32\wgldm.dat
CoolWWWSearch: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ 11Fßä#·ºÄÖ`I
CoolWWWSearch: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ 11Fßä#·ºÄÖ`I
CoolWWWSearch: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA
CoolWWWSearch: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE
CoolWWWSearch: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW
Spy Sheriff: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\SNO2
Spy Sheriff: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn!=dword:0
Tango: Data (File, nothing done)
c:\data
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Logger.LogSession
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Logger.LogSession.1
WildTangent: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A62FA99E-922E-4ECA-A1D9-B54EF294A3CC}
WildTangent: Global settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\WildTangent
WildTangent: Library (File, nothing done)
C:\WINDOWS\wt\webdriver.dll
WildTangent: Program directory (Directory, nothing done)
C:\WINDOWS\wt\wtupdates\
WildTangent: Program directory (Directory, nothing done)
C:\WINDOWS\wt\updater\
WildTangent: Program directory (Directory, nothing done)
C:\WINDOWS\wt\webdriver\
WildTangent: Program directory (Directory, nothing done)
C:\Program Files\WildTangent\
Windows.ActiveDesktop: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper!=W=1
Windows.Explorer: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceActiveDesktopOn!=W=0
Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
Windows Security Center.UpdateDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify!=dword:0
WildTangent: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\ClassPath=...;C:\Program Files\WildTangent\Apps\DRM0302Java.jar...
WildTangent: Program directory (Directory, nothing done)
C:\WINDOWS\wt\
WildTangent: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{65E7DB1D-0101-4100-BD66-C5C78C917F93}
WildTangent: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1FAD572E-1A3D-44D9-9C23-A87F922DA8C0}
WildTangent: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{D8E9CCF6-8E64-4E39-95CE-C5333FCFBD1F}
WildTangent: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{11066F62-0388-458C-B7E7-47E824894F20}
WildTangent: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Wtdmmpv.WTDMMPVersion
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Wtdmmpv.WTDMMPVersion.1
WildTangent: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{65E7DB1D-0101-4100-BD66-C5C78C917F93}
WildTangent: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1123561945-789336058-1060284298-1003\Software\WildTangent
WildTangent: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{3A7FE611-1994-4ef1-A09F-99456752289D}
WildTangent: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1DE680D4-84B7-4239-A887-9482A29DBE14}
WildTangent: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{25F53F41-0C37-40FA-AE9F-A260DB2D64CF}
WildTangent: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{4A165BD0-165F-474F-AF66-40CD5AC4613E}
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\WildTangent.ActiveLauncher
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\WildTangent.ActiveLauncher.2
WildTangent: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3A7FE611-1994-4ef1-A09F-99456752289D}
WildTangent: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\WildTangent.ActiveLauncher.1
WildTangent: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent CDA
Startpage-EH: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
CoolWWWSearch: Bookmark (Internet Explorer: Airwolf11) (Bookmark, nothing done)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-12-29 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2005-12-23 Includes\Cookies.sbi (*)
2005-12-23 Includes\Dialer.sbi (*)
2005-12-23 Includes\Hijackers.sbi (*)
2005-12-23 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2005-12-23 Includes\Malware.sbi (*)
2005-12-23 Includes\PUPS.sbi (*)
2005-12-23 Includes\Revision.sbi (*)
2005-12-23 Includes\Security.sbi (*)
2005-12-23 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2005-12-23 Includes\Trojans.sbi (*)
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ Windows Media Player: Windows Media Player Hotfix [See KB837272 for more information]
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 819639
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB867282
/ Windows XP / SP3: Windows XP Hotfix - KB873333
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB885884
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB887797
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890047
/ Windows XP / SP3: Windows XP Hotfix - KB890175
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB890923
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Windows XP Hotfix - KB893086
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Hotfix for Windows XP (KB896344)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Security Update for Windows XP (KB896688)
/ Windows XP / SP3: Update for Windows XP (KB896727)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899588)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Update for Windows XP (KB900930)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
--- Startup entries list ---
Located: HK_LM:Run, 5.tmp
command: C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\5.tmp.exe
file: C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\5.tmp.exe
size: 20087
MD5: f5c30f83d916cd2c1c5bc88b4aa9696e
Located: HK_LM:Run, 6.tmp
command: C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\6.tmp.exe
file: C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\6.tmp.exe
size: 11895
MD5: 02715b55cfe7ded3d0160cb9a8205eae
Located: HK_LM:Run, EM_EXEC
command: C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
file: C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
size: 35328
MD5: dcc94f82f41ce23bec02734e3f0baaa2
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
file: C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
size: 196608
MD5: 7c6b5065e7326e3c91a62800df3a31fa
Located: HK_LM:Run, ipzc32.exe
command: C:\WINDOWS\ipzc32.exe
file: C:\WINDOWS\ipzc32.exe
size: 35447
MD5: 6caac12d15c1347944c97d6cbe777c2c
Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, ViewMgr
command: C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
file: C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
size: 106557
MD5: 1cd4dda616a8c2e2ee028895271492e9
Located: HK_LM:Run, windll
command: "C:\Program Files\STARR\wsys.exe"
file: C:\Program Files\STARR\wsys.exe
size: 458752
MD5: eeafafc828aa773fbf1836b033d57ecf
Located: HK_CU:Run, Windows installer
command: C:\winstall.exe
file: C:\winstall.exe
size: 29184
MD5: 2b1283f267e6a1832252bc09157aafb7
Located: Startup (common), IDETool.lnk
command: C:\Program Files\IDETOOL\IDETOOL.EXE
file: C:\Program Files\IDETOOL\IDETOOL.EXE
size: 344064
MD5: b543e6502fd05e4875d204bb4c62f921
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
--- Browser helper object list ---
{543E5DEC-9A89-6C8C-67AC-D0B02ABB10D6} (Class)
BHO name:
CLSID name: Class
Path: C:\WINDOWS\system32\
Long name: mfckq32.dll
Short name:
Date (created): 12/29/2005 10:02:00 AM
Date (last access): 12/29/2005 10:02:02 AM
Date (last write): 12/29/2005 10:02:02 AM
Filesize: 133791
Attributes: archive
MD5: AE060DE096CD1F920517E53F812F9EFC
CRC32: C57FC329
--- ActiveX list ---
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.ma...director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Unknown
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Director\
Long name: SwDir.dll
Short name:
Date (created): 01/18/2004 7:17:36 PM
Date (last access): 12/17/2005 10:02:10 PM
Date (last write): 09/09/2004 2:49:12 PM
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 10.1.0.11
{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
Codebase: http://update.micros...b?1128035147191
Path: C:\WINDOWS\System32\
Long name: wuweb.dll
Short name:
Date (created): 08/03/2004 12:59:06 PM
Date (last access): 12/20/2005 1:04:50 PM
Date (last write): 05/26/2005 3:19:32 AM
Filesize: 173536
Attributes: archive
MD5: C459F2D5E64C942F3F66E1CD7F1C4C00
CRC32: EEF66B50
Version: 5.8.0.2469
{9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control)
DPF name:
CLSID name: cpbrkpie Control
Installer: C:\WINDOWS\Downloaded Program Files\cpbrkpie.inf
Codebase: http://a19.g.akamai....02/cpbrkpie.cab
Path: C:\WINDOWS\
Long name: cpbrkpie.ocx
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class)
DPF name:
CLSID name: ActiveScan Installer Class
Installer: C:\WINDOWS\Downloaded Program Files\asinst.inf
Codebase: http://acs.pandasoft...free/asinst.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: asinst.dll
Short name:
Date (created): 11/11/2005 8:28:22 AM
Date (last access): 12/29/2005 10:16:08 AM
Date (last write): 11/11/2005 8:28:22 AM
Filesize: 135168
Attributes: archive
MD5: 5793AB11CE5B5029ED2B9EB4CF67641C
CRC32: 1E2240F6
Version: 58.3.0.0
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2
Installer:
Codebase: http://java.sun.com/...indows-i586.cab
Path: C:\Program Files\Java\j2re1.4.2\bin\
Long name: NPJPI142.dll
Short name:
Date (created): 02/07/2004 9:23:54 PM
Date (last access): 12/19/2005 4:42:24 PM
Date (last write): 02/07/2004 9:23:54 PM
Filesize: 65636
Attributes: archive
MD5: 4ACFBF6AB1BBE79DBD665C186B3B5AFD
CRC32: BE89D675
Version: 1.4.2.0
--- Process list ---
PID: 0 ( 0) [System]
PID: 488 ( 4) \SystemRoot\System32\smss.exe
PID: 536 ( 488) \??\C:\WINDOWS\system32\csrss.exe
PID: 560 ( 488) \??\C:\WINDOWS\system32\winlogon.exe
PID: 604 ( 560) C:\WINDOWS\system32\services.exe
size: 108032
MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID: 616 ( 560) C:\WINDOWS\system32\lsass.exe
size: 13312
MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID: 772 ( 604) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 848 ( 604) C:\WINDOWS\system32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 920 ( 604) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1000 ( 604) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1064 ( 604) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1252 ( 604) C:\WINDOWS\system32\spoolsv.exe
size: 57856
MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID: 1396 (1380) C:\WINDOWS\Explorer.EXE
size: 1032192
MD5: A0732187050030AE399B241436565E64
PID: 1540 (1396) C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
size: 35328
MD5: DCC94F82F41CE23BEC02734E3F0BAAA2
PID: 1556 (1396) C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
size: 196608
MD5: 7C6B5065E7326E3C91A62800DF3A31FA
PID: 1568 (1396) C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
size: 106557
MD5: 1CD4DDA616A8C2E2EE028895271492E9
PID: 1760 ( 604) C:\Program Files\ewido\security suite\ewidoctrl.exe
size: 16448
MD5: 867D9D1FA818F8629BB7A4A26E94B06A
PID: 1788 (1396) C:\Program Files\IDETOOL\IDETOOL.EXE
size: 344064
MD5: B543E6502FD05E4875D204BB4C62F921
PID: 1800 ( 604) C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
size: 270336
MD5: 3A86FB5FDF6575568B5F1A694186E45E
PID: 1848 (1396) C:\WINDOWS\system32\devldr32.exe
size: 25088
MD5: 1388BB809E435B04D20067BCF6DDBE26
PID: 1896 ( 604) C:\WINDOWS\System32\nvsvc32.exe
size: 81920
MD5: 5ED834603C36414B579979B3A9C90F54
PID: 1960 ( 604) C:\WINDOWS\System32\svchost.exe
size: 14336
MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1996 ( 604) C:\WINDOWS\system32\wdfmgr.exe
size: 38912
MD5: AB0A7CA90D9E3D6A193905DC1715DED0
PID: 220 ( 604) C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
size: 41025
MD5: E8C30EF9BBC6DDB71F0F77FA3A96515F
PID: 252 ( 220) C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
size: 4314112
MD5: 52562F17F1326EC8E37FA8ABFAB3E543
PID: 1820 ( 604) C:\WINDOWS\System32\alg.exe
size: 44544
MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 1272 (1804) C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\1.tmp
size: 29184
MD5: 2B1283F267E6A1832252BC09157AAFB7
PID: 2064 ( 604) C:\WINDOWS\system32\appgf.exe
size: 11895
MD5: 5E96BC3F95FB0773193F5BB09754A075
PID: 2080 (1804) C:\WINDOWS\ipzc32.exe
size: 35447
MD5: 6CAAC12D15C1347944C97D6CBE777C2C
PID: 2116 (1804) C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\5.tmp
size: 20087
MD5: F5C30F83D916CD2C1C5BC88B4AA9696E
PID: 2124 (1804) C:\DOCUME~1\AIRWOL~1\LOCALS~1\Temp\6.tmp
size: 11895
MD5: 02715B55CFE7DED3D0160CB9A8205EAE
PID: 3788 (3224) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 4 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 12/29/2005 10:28:50 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
about:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
res://C:\WINDOWS\system32\lczcq.dll/sp.html#10001%resultposition.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn...st/srchcust.htm
--- Winsock Layered Service Provider list ---
--- Uninstall list ---
Ad-Aware SE Personal (Ad-Aware SE Personal)
uninstall cmd: C:\PROGRA~1\Lavasoft\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~2\INSTALL.LOG
publisher: Lavasoft
help link: http://www.lavasoft.de
(AddressBook)
Adobe Atmosphere Player for Acrobat and Adobe Reader (Adobe Atmosphere Player)
uninstall cmd: C:\WINDOWS\atmoUn.exe
Adobe Download Manager 1.2 (Remove Only) (AdobeESD)
uninstall cmd: "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Aerospatiale HH65A Dolphin V1.1 (Aerospatiale HH65A Dolphin V1.1)
uninstall cmd: C:\Games\Microsoft Games\Flight Simulator 9\Uninstal.exe
Anime Bowling Babes 1.0 (Anime Bowling Babes_is1)
install location: C:\games\Anime Bowling Babes\
uninstall cmd: "C:\games\Anime Bowling Babes\unins000.exe"
publisher: Glimmer Games
help link: http://www.glimmergames.com
Antonov An-24RV (Antonov An-24RV)
uninstall cmd: C:\Games\Microsoft Games\Flight Simulator 9\Uninstal An-24RV.exe
AOL Instant Messenger (AOL Instant Messenger)
uninstall cmd: C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
(Branding)
CleanUp! (CleanUp!)
uninstall cmd: C:\Program Files\CleanUp!\uninstall.exe
Microsoft Combat Flight Simulator (Combat Flight Simulator 1.00)
uninstall cmd: "C:\games\Microsoft Games\Combat Flight Simulator\UNINSTAL.EXE" /runtemp
(Connection Manager)
(DirectAnimation)
(DirectDrawEx)
(DXM_Runtime)
ewido security suite (ewidosecuritysuite)
install location: C:\Program Files\ewido\security suite
uninstall cmd: C:\Program Files\ewido\security suite\Uninstall.exe
publisher: ewido networks
help link: http://www.ewido.net
Microsoft Flight Simulator 2004 A Century of Flight 9.0 (Flight Simulator 9.0)
version (major): 9
install location: C:\games\Microsoft Games\Flight Simulator 9
uninstall cmd: "C:\games\Microsoft Games\Flight Simulator 9\UNINSTAL.EXE" /runtemp /addremove
publisher: Microsoft
help link: http://www.microsoft.com/support
readme: C:\games\Microsoft Games\Flight Simulator 9\Readme.rtf
(Fontcore)
HijackThis 1.99.1 1.99.1 (HijackThis)
uninstall cmd: C:\Program Files\HighJackThis\HijackThis.exe /uninstall
publisher: Soeperman Enterprises Ltd.
hp deskjet 990c series (Remove only) (hp deskjet 990c series)
uninstall cmd: C:\Program Files\hp deskjet 990c series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=LPT1: -vproduct=990c -huninstall
hp deskjet 990c series (hp deskjet 990c series_Driver)
uninstall cmd: rundll32 hpzcon04.dll,VendorJettison hp deskjet 990c series
Home Search Assistent (HSA)
uninstall cmd: rundll32 url.dll,FileProtocolHandler "http://looking-for.c...Assistant.html"
(ICW)
(IE40)
(IE4Data)
(IE5BAKEX)
(IEData)
(InstallShield Uninstall Information)
iTunes 4.7.1.30 (InstallShield_{3CB41017-F5CA-4C56-934C-ED02156251E6})
version: 67567617
version (major): 4
version (minor): 7
estimated size: 13447
install date: 20050127
install location: C:\Program Files\QuickTime\itunes\
install source: C:\WINDOWS\Downloaded Installations\{628E8630-7947-49EA-BE90-7F8BFF77A79C}\
uninstall cmd: C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3CB41017-F5CA-4C56-934C-ED02156251E6}
publisher: Apple Computer, Inc.
contact: AppleCare Support
help link: http://www.info.apple.com/
help telephone: 1-800-275-2273
Search and Rescue 4 1.00.0000 (InstallShield_{BF8921C7-59DD-486C-8D8A-B433DC4A5323})
version: 16777216
version (major): 1
estimated size: 740357
install date: 20050207
install source: E:\
uninstall cmd: C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BF8921C7-59DD-486C-8D8A-B433DC4A5323}
publisher: InterActive Vision
comments:
contact: Customer Support Department
help link: http://www.iavgames.com
help telephone:
readme:
IrfanView (remove only) (IrfanView)
uninstall cmd: C:\Program Files\IrfanView\iv_uninstall.exe
Windows XP Hotfix - KB834707 20040929.110854 (KB834707)
uninstall cmd: C:\WINDOWS\$NtUninstallKB834707$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=834707
Windows XP Hotfix - KB867282 20050127.090417 (KB867282)
uninstall cmd: C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=867282
Windows XP Hotfix - KB873333 20050114.005213 (KB873333)
uninstall cmd: C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=873333
Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=873339
(KB884016)
Windows XP Hotfix - KB885250 20050118.202711 (KB885250)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885250
Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885835
Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885836
Windows XP Hotfix - KB885884 20040924.025457 (KB885884)
uninstall cmd: C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=885884
Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=886185
Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887472
Windows XP Hotfix - KB887742 20041103.095002 (KB887742)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887742
Windows XP Hotfix - KB887797 20041018.133824 (KB887797)
uninstall cmd: C:\WINDOWS\$NtUninstallKB887797$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=887797
Windows XP Hotfix - KB888113 20041116.131036 (KB888113)
uninstall cmd: C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=888113
Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=888302
Security Update for Windows XP (KB890046) 1 (KB890046)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=890046
Windows XP Hotfix - KB890047 20041221.124506 (KB890047)
uninstall cmd: C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=890047
Windows XP Hotfix - KB890175 20041201.233338 (KB890175)
uninstall cmd: C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=890175
Windows XP Hotfix - KB890859 1 (KB890859)
install date: 20050420
uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=890859
Windows XP Hotfix - KB890923 1 (KB890923)
install date: 20050420
uninstall cmd: "C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=890923
Windows Media Format SDK Hotfix - KB891122 (KB891122)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=891122
Windows XP Hotfix - KB891781 20050110.165439 (KB891781)
uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=891781
Windows XP Hotfix - KB893066 1 (KB893066)
install date: 20050420
uninstall cmd: "C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=893066
Windows XP Hotfix - KB893086 1 (KB893086)
install date: 20050420
uninstall cmd: "C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=893086
Security Update for Windows XP (KB893756) 1 (KB893756)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=893756
Windows Installer 3.1 (KB893803) 3.1 (KB893803)
uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft....k/?LinkId=42467
Windows Installer 3.1 (KB893803) 3.1 (KB893803v2)
uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://go.microsoft....k/?LinkId=42467
Update for Windows XP (KB894391) 1 (KB894391)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=894391
Hotfix for Windows XP (KB896344) 2 (KB896344)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896344$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896344
Security Update for Windows XP (KB896358) 1 (KB896358)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896358
Security Update for Windows XP (KB896422) 1 (KB896422)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896422
Security Update for Windows XP (KB896423) 1 (KB896423)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896423
Security Update for Windows XP (KB896424) 1 (KB896424)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896424
Security Update for Windows XP (KB896428) 1 (KB896428)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896428
Security Update for Windows XP (KB896688) 1 (KB896688)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896688
Update for Windows XP (KB896727) 1 (KB896727)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=896727
Update for Windows XP (KB898461) 1 (KB898461)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=898461
Security Update for Windows XP (KB899587) 1 (KB899587)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=899587
Security Update for Windows XP (KB899588) 1 (KB899588)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899588$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=899588
Security Update for Windows XP (KB899589) 1 (KB899589)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899589$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=899589
Security Update for Windows XP (KB899591) 1 (KB899591)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=899591
Security Update for Windows XP (KB900725) 1 (KB900725)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=900725
Update for Windows XP (KB900930) 1 (KB900930)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB900930$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=900930
Security Update for Windows XP (KB901017) 1 (KB901017)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=901017
Security Update for Windows XP (KB901214) 1 (KB901214)
install date: 20050929
uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=901214
Security Update for Windows XP (KB902400) 1 (KB902400)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=902400
Security Update for Windows XP (KB904706) 1 (KB904706)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=904706
Security Update for Windows XP (KB905414) 1 (KB905414)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=905414
Security Update for Windows XP (KB905749) 1 (KB905749)
install date: 20051126
uninstall cmd: "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
publisher: Microsoft Corporation
help link: http://support.micro...com?kbid=905749
Macromedia Shockwave Player (Macromedia Shockwave Player)
uninstall cmd: C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log
MD902 EXPLORER BY LINDEN HOYLE (MD902 EXPLORER BY LINDEN HOYLE)
MH-6 Littlebird Package (MH-6 Littlebird Package1.1)
uninstall cmd: C:\WINDOWS\iun6002ev.exe "C:\Documents and Settings\Airwolf11\Desktop\blah\irunin.ini"
Microsoft