1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Connecting to Net overwhelms PC

Discussion in 'Malware and Virus Removal Archive' started by Tober27, 2008/11/17.

  1. 2008/11/17
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    [Resolved] Connecting to Net overwhelms PC

    I don't mean to double post, but was told to post logs of RSIT in this forum.
    My problem as first stated is this:

    When I plug in my network connection, my computer is fine for about a minute, but then seems to become so busy it is unusable. It hasn't frozen, I can still move the mouse, and wait extremely long for it to respond, but can't figure out why.

    It does this whether I open any programs or not. I get low % CPU usage in Task Manager so can't see what is bogging it down.
    I'm on XP and have service pack 3.

    RSIT log:
    Logfile of random's system information tool 1.04 (written by random/random)
    Run by ToberII at 2008-11-17 11:25:01
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 2 GB (4%) free of 38 GB
    Total RAM: 255 MB (35% free)

    HijackThis download failed

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\RegistrySmart Scheduled Scan.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
    Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2008-10-14 130248]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll [2007-12-18 817936]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-12 222448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
    Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E8DF67A1-B618-4F3F-9E7C-CBE175ADEF5B}]
    WinAVI FLVSense - C:\Program Files\WinAVI FLV Converter\FLVTune.dll [2008-01-28 114688]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll [2007-12-18 817936]
    {D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-02-22 352256]
    {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2008-10-14 437368]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched "=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
    "GrooveMonitor "=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
    "NeroFilterCheck "=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
    "ISUSPM "=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-03-20 213936]
    "avast! "=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
    "QuickTime Task "=C:\Program Files\QuickTime\QTTask.exe [2008-03-28 413696]
    "Adobe Photo Downloader "=C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe [2007-09-10 67488]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} "=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-03-12 153136]
    " "= []
    "Uniblue RegistryBooster 2 "=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe [2007-12-06 1910040]
    "Messenger (Yahoo!) "=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]
    "Yahoo! Pager "=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]

    C:\Documents and Settings\ToberII\Start Menu\Programs\Startup
    OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD} "=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
    "{93994DE8-8239-4655-B1D1-5F4E91300429} "=C:\PROGRA~1\DVDIDL~1\DVDShell.dll [2004-10-09 49152]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=145

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe "= "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger "
    "C:\Program Files\Azureus\Azureus.exe "= "C:\Program Files\Azureus\Azureus.exe:*:Enabled:Azureus "
    "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe "= "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Disabled:Veoh Client "
    "C:\Program Files\eMule\emule.exe "= "C:\Program Files\eMule\emule.exe:*:Enabled:eMule "
    "C:\Program Files\Soulseek\slsk.exe "= "C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek "
    "C:\Program Files\SoulseekNS\slsk.exe "= "C:\Program Files\SoulseekNS\slsk.exe:*:Enabled:SoulSeek "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "
    "C:\Program Files\Orbitdownloader\orbitdm.exe "= "C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit "
    "C:\Program Files\Orbitdownloader\orbitnet.exe "= "C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit "
    "C:\Program Files\Internet Explorer\iexplore.exe "= "C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "

    ======List of files/folders created in the last 3 months======

    2008-11-17 11:17:02 ----D---- C:\rsit
    2008-11-17 11:17:02 ----D---- C:\Program Files\trend micro
    2008-11-16 10:54:46 ----D---- C:\Config.Msi
    2008-11-16 00:06:37 ----D---- C:\Program Files\SUPERAntiSpyware
    2008-11-16 00:06:37 ----D---- C:\Documents and Settings\ToberII\Application Data\SUPERAntiSpyware.com
    2008-11-16 00:01:18 ----D---- C:\Program Files\RogueRemover FREE
    2008-11-15 23:56:54 ----D---- C:\Documents and Settings\ToberII\Application Data\RegistrySmart
    2008-11-15 23:55:22 ----D---- C:\Program Files\RegistrySmart
    2008-11-01 14:43:53 ----D---- C:\Program Files\Xvid
    2008-11-01 14:41:44 ----D---- C:\Program Files\GSpot
    2008-11-01 14:14:02 ----A---- C:\WINDOWS\system32\rmoc3260.dll
    2008-11-01 14:14:02 ----A---- C:\WINDOWS\system32\pndx5032.dll
    2008-11-01 14:14:02 ----A---- C:\WINDOWS\system32\pndx5016.dll
    2008-11-01 14:14:02 ----A---- C:\WINDOWS\system32\pncrt.dll
    2008-11-01 14:13:57 ----A---- C:\WINDOWS\system32\unrar.dll
    2008-11-01 14:13:54 ----A---- C:\WINDOWS\avisplitter.ini
    2008-11-01 14:13:46 ----A---- C:\WINDOWS\system32\yv12vfw.dll
    2008-11-01 14:13:45 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2008-11-01 14:13:44 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2008-11-01 14:13:38 ----A---- C:\WINDOWS\system32\divx.dll
    2008-11-01 14:13:34 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
    2008-11-01 14:13:34 ----A---- C:\WINDOWS\system32\ff_vfw.dll
    2008-11-01 14:13:23 ----D---- C:\Program Files\K-Lite Codec Pack
    2008-11-01 14:13:23 ----D---- C:\Documents and Settings\All Users\Application Data\Real
    2008-10-30 14:52:23 ----D---- C:\Documents and Settings\ToberII\Application Data\WinAVI
    2008-10-30 14:51:48 ----D---- C:\Program Files\WinAVI FLV Converter
    2008-10-30 14:40:31 ----D---- C:\Program Files\WinAVI Video Converter
    2008-10-30 00:17:29 ----D---- C:\ConverterOutput
    2008-10-30 00:17:19 ----A---- C:\Cucu_Video_log.txt
    2008-10-29 22:16:37 ----D---- C:\Program Files\Cucusoft
    2008-10-28 19:47:25 ----D---- C:\Documents and Settings\ToberII\Application Data\GrabPro
    2008-10-28 19:46:05 ----D---- C:\Program Files\Orbitdownloader
    2008-10-24 02:21:50 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-10-15 03:07:31 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-10-15 03:06:24 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-15 03:05:10 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-10-15 02:56:27 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-10-15 02:54:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-10-07 15:25:51 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
    2008-10-01 11:29:25 ----D---- C:\Documents and Settings\ToberII\Application Data\U3
    2008-09-18 14:27:33 ----D---- C:\Program Files\Magic M4A to MP3 Converter
    2008-09-18 13:31:57 ----D---- C:\Documents and Settings\All Users\Application Data\AVS4YOU
    2008-09-18 13:31:50 ----D---- C:\Documents and Settings\ToberII\Application Data\AVS4YOU
    2008-09-18 13:28:20 ----D---- C:\Program Files\Common Files\AVSMedia
    2008-09-18 13:28:19 ----A---- C:\WINDOWS\system32\cc3270mt.dll
    2008-09-18 13:25:52 ----A---- C:\WINDOWS\system32\msxml3a.dll
    2008-09-18 13:25:52 ----A---- C:\WINDOWS\system32\msvcp70.dll
    2008-09-18 13:25:50 ----A---- C:\WINDOWS\system32\msvcr70.dll
    2008-09-18 13:25:48 ----D---- C:\Program Files\AVS4YOU
    2008-09-15 18:14:24 ----A---- C:\WINDOWS\system32\qt-dx331.dll
    2008-09-15 18:12:54 ----A---- C:\WINDOWS\system32\ssldivx.dll
    2008-09-15 18:12:54 ----A---- C:\WINDOWS\system32\libdivx.dll
    2008-09-15 18:12:02 ----A---- C:\WINDOWS\system32\dtu100.dll.manifest
    2008-09-15 18:12:02 ----A---- C:\WINDOWS\system32\dtu100.dll
    2008-09-15 18:12:02 ----A---- C:\WINDOWS\system32\dpl100.dll.manifest
    2008-09-15 18:12:02 ----A---- C:\WINDOWS\system32\dpl100.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpv11.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpus11.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpuGUI11.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpuGUI10.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpu11.dll
    2008-09-15 18:12:00 ----A---- C:\WINDOWS\system32\dpu10.dll
    2008-09-15 18:11:28 ----A---- C:\WINDOWS\system32\DivXCodecVersionChecker.exe
    2008-09-10 09:36:57 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
    2008-09-10 09:33:07 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-09-10 09:29:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
    2008-09-01 20:50:25 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
    2008-09-01 20:50:25 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
    2008-09-01 20:50:23 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
    2008-09-01 20:50:21 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
    2008-09-01 20:50:21 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
    2008-09-01 20:50:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
    2008-09-01 20:50:15 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
    2008-09-01 20:50:15 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
    2008-09-01 20:50:13 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
    2008-09-01 20:50:12 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
    2008-09-01 20:50:09 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
    2008-09-01 20:50:09 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
    2008-09-01 20:50:06 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
    2008-09-01 20:50:03 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
    2008-09-01 20:50:01 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
    2008-09-01 20:50:00 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
    2008-09-01 20:49:58 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
    2008-09-01 20:49:57 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
    2008-09-01 20:49:55 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
    2008-09-01 20:49:52 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
    2008-09-01 20:49:42 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
    2008-09-01 20:49:42 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
    2008-09-01 20:49:33 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
    2008-09-01 20:49:24 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
    2008-09-01 20:49:15 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
    2008-09-01 20:49:15 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
    2008-09-01 20:49:06 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
    2008-09-01 20:48:58 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
    2008-09-01 20:48:58 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
    2008-09-01 20:48:50 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
    2008-09-01 20:48:50 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
    2008-09-01 20:48:37 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
    2008-09-01 20:42:20 ----D---- C:\WINDOWS\Logs
    2008-09-01 19:55:10 ----D---- C:\Program Files\Utherverse Digital Inc
    2008-08-28 10:14:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-08-27 19:38:19 ----D---- C:\WINDOWS\Prefetch
    2008-08-27 19:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-08-27 19:32:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-08-27 19:32:10 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2008-08-27 19:31:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2008-08-27 19:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-08-27 19:31:17 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
    2008-08-27 19:30:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-08-27 19:30:39 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-08-27 19:30:23 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2008-08-27 19:29:59 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-08-27 19:20:33 ----A---- C:\WINDOWS\setuplog.txt
    2008-08-27 19:16:43 ----D---- C:\WINDOWS\system32\scripting
    2008-08-27 19:16:25 ----D---- C:\WINDOWS\l2schemas
    2008-08-27 19:16:23 ----D---- C:\WINDOWS\system32\en
    2008-08-27 10:52:29 ----N---- C:\WINDOWS\system32\wlanapi.dll
    2008-08-27 10:51:50 ----N---- C:\WINDOWS\system32\tspkg.dll
    2008-08-27 10:50:57 ----N---- C:\WINDOWS\system32\setupn.exe
    2008-08-27 10:50:40 ----N---- C:\WINDOWS\system32\rasqec.dll
    2008-08-27 10:50:38 ----N---- C:\WINDOWS\system32\qutil.dll
    2008-08-27 10:50:32 ----N---- C:\WINDOWS\system32\qcliprov.dll
    2008-08-27 10:50:31 ----N---- C:\WINDOWS\system32\qagentrt.dll
    2008-08-27 10:50:31 ----N---- C:\WINDOWS\system32\qagent.dll
    2008-08-27 10:50:16 ----N---- C:\WINDOWS\system32\onex.dll
    2008-08-27 10:49:25 ----N---- C:\WINDOWS\system32\napstat.exe
    2008-08-27 10:49:25 ----N---- C:\WINDOWS\system32\napmontr.dll
    2008-08-27 10:49:25 ----N---- C:\WINDOWS\system32\napipsec.dll
    2008-08-27 10:49:07 ----N---- C:\WINDOWS\system32\msshavmsg.dll
    2008-08-27 10:49:07 ----N---- C:\WINDOWS\system32\mssha.dll
    2008-08-27 10:47:59 ----N---- C:\WINDOWS\system32\mmcperf.exe
    2008-08-27 10:47:57 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
    2008-08-27 10:47:57 ----N---- C:\WINDOWS\system32\mmcex.dll
    2008-08-27 10:47:56 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
    2008-08-27 10:47:02 ----N---- C:\WINDOWS\system32\l2gpstore.dll
    2008-08-27 10:47:01 ----N---- C:\WINDOWS\system32\kmsvc.dll
    2008-08-27 10:46:58 ----N---- C:\WINDOWS\system32\kbdpash.dll
    2008-08-27 10:46:58 ----N---- C:\WINDOWS\system32\kbdnepr.dll
    2008-08-27 10:46:58 ----N---- C:\WINDOWS\system32\kbdiultn.dll
    2008-08-27 10:46:57 ----N---- C:\WINDOWS\system32\kbdbhc.dll
    2008-08-27 10:46:08 ----A---- C:\WINDOWS\005658_.tmp
    2008-08-27 10:46:02 ----N---- C:\WINDOWS\system32\eapsvc.dll
    2008-08-27 10:46:02 ----N---- C:\WINDOWS\system32\eapqec.dll
    2008-08-27 10:46:02 ----N---- C:\WINDOWS\system32\eappprxy.dll
    2008-08-27 10:46:02 ----N---- C:\WINDOWS\system32\eapphost.dll
    2008-08-27 10:46:02 ----N---- C:\WINDOWS\system32\eappgnui.dll
    2008-08-27 10:46:01 ----N---- C:\WINDOWS\system32\eappcfg.dll
    2008-08-27 10:46:01 ----N---- C:\WINDOWS\system32\eapp3hst.dll
    2008-08-27 10:46:01 ----N---- C:\WINDOWS\system32\eapolqec.dll
    2008-08-27 10:45:49 ----N---- C:\WINDOWS\system32\dot3ui.dll
    2008-08-27 10:45:49 ----N---- C:\WINDOWS\system32\dot3svc.dll
    2008-08-27 10:45:48 ----N---- C:\WINDOWS\system32\dot3msm.dll
    2008-08-27 10:45:48 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
    2008-08-27 10:45:48 ----N---- C:\WINDOWS\system32\dot3dlg.dll
    2008-08-27 10:45:48 ----N---- C:\WINDOWS\system32\dot3cfg.dll
    2008-08-27 10:45:48 ----N---- C:\WINDOWS\system32\dot3api.dll
    2008-08-27 10:45:43 ----N---- C:\WINDOWS\system32\dimsroam.dll
    2008-08-27 10:45:42 ----N---- C:\WINDOWS\system32\dimsntfy.dll
    2008-08-27 10:45:39 ----N---- C:\WINDOWS\system32\dhcpqec.dll
    2008-08-27 10:45:24 ----N---- C:\WINDOWS\system32\credssp.dll
    2008-08-27 10:45:00 ----N---- C:\WINDOWS\system32\bitsprx4.dll
    2008-08-27 10:44:59 ----N---- C:\WINDOWS\system32\azroles.dll

    ======List of files/folders modified in the last 3 months======

    2008-11-17 11:17:02 ----RD---- C:\Program Files
    2008-11-16 23:40:19 ----D---- C:\Program Files\Mozilla Firefox
    2008-11-16 21:27:12 ----D---- C:\WINDOWS\Temp
    2008-11-16 21:23:48 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-16 11:08:06 ----D---- C:\WINDOWS\system32
    2008-11-16 11:08:05 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-11-16 11:01:13 ----D---- C:\WINDOWS\system32\config
    2008-11-16 10:58:53 ----D---- C:\WINDOWS\system32\wbem
    2008-11-16 10:58:33 ----D---- C:\WINDOWS\Registration
    2008-11-16 10:56:58 ----D---- C:\Documents and Settings\ToberII\Application Data\Azureus
    2008-11-16 10:56:12 ----D---- C:\WINDOWS
    2008-11-16 10:56:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-11-16 10:55:52 ----SHD---- C:\WINDOWS\Installer
    2008-11-16 10:55:41 ----D---- C:\WINDOWS\system32\drivers
    2008-11-16 10:52:56 ----D---- C:\Documents and Settings
    2008-11-16 10:51:06 ----D---- C:\WINDOWS\system32\Restore
    2008-11-16 10:12:29 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-16 00:02:16 ----D---- C:\Program Files\Common Files
    2008-11-15 23:56:57 ----SD---- C:\WINDOWS\Tasks
    2008-11-15 03:23:53 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-11-13 11:29:52 ----D---- C:\Program Files\IsoBuster
    2008-11-08 15:28:24 ----A---- C:\WINDOWS\win.ini
    2008-11-08 15:25:58 ----HD---- C:\WINDOWS\inf
    2008-11-06 14:39:42 ----D---- C:\WINDOWS\system32\CatRoot
    2008-11-06 14:39:29 ----D---- C:\WINDOWS\Help
    2008-11-05 22:03:50 ----D---- C:\Documents and Settings\All Users\Application Data\Soulseek
    2008-11-04 15:30:36 ----D---- C:\Documents and Settings\ToberII\Application Data\Orbit
    2008-11-01 13:52:55 ----D---- C:\Program Files\Common Files\Real
    2008-11-01 13:51:21 ----D---- C:\Documents and Settings\ToberII\Application Data\Real
    2008-11-01 13:49:29 ----D---- C:\Program Files\DivX
    2008-11-01 13:04:50 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-10-30 13:48:15 ----A---- C:\YServer.txt
    2008-10-29 19:07:47 ----D---- C:\Program Files\Azureus
    2008-10-28 20:08:38 ----D---- C:\Downloads
    2008-10-24 02:24:53 ----A---- C:\WINDOWS\imsins.BAK
    2008-10-24 02:14:35 ----HD---- C:\WINDOWS\$hf_mig$
    2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
    2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
    2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
    2008-10-16 14:06:48 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2008-10-15 10:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-15 03:15:13 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-10-15 03:02:09 ----D---- C:\Program Files\Internet Explorer
    2008-10-15 03:00:32 ----D---- C:\WINDOWS\ie7updates
    2008-10-09 17:15:57 ----D---- C:\Documents and Settings\All Users\Application Data\yahoo!
    2008-10-07 13:19:40 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-10-03 11:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-10-02 03:20:07 ----D---- C:\Documents and Settings\ToberII\Application Data\Move Networks
    2008-10-01 10:21:39 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-09-24 23:59:45 ----D---- C:\Documents and Settings\ToberII\Application Data\dvdcss
    2008-09-18 13:28:13 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-09-18 13:28:12 ----D---- C:\WINDOWS\WinSxS
    2008-09-01 20:50:43 ----D---- C:\WINDOWS\system32\DirectX
    2008-09-01 20:43:35 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-08-27 19:36:34 ----D---- C:\WINDOWS\system32\Setup
    2008-08-27 19:36:34 ----D---- C:\WINDOWS\AppPatch
    2008-08-27 19:36:34 ----D---- C:\Program Files\Outlook Express
    2008-08-27 19:36:33 ----D---- C:\Program Files\Common Files\System
    2008-08-27 19:36:31 ----RSD---- C:\WINDOWS\Fonts
    2008-08-27 19:35:05 ----D---- C:\WINDOWS\security
    2008-08-27 19:30:06 ----D---- C:\Program Files\Messenger
    2008-08-27 19:18:08 ----D---- C:\WINDOWS\ServicePackFiles
    2008-08-27 19:17:59 ----D---- C:\WINDOWS\network diagnostic
    2008-08-27 19:17:58 ----D---- C:\WINDOWS\ime
    2008-08-27 19:16:47 ----D---- C:\WINDOWS\system32\usmt
    2008-08-27 19:16:47 ----D---- C:\WINDOWS\system32\en-US
    2008-08-27 19:16:22 ----D---- C:\WINDOWS\system32\bits
    2008-08-27 19:16:21 ----D---- C:\WINDOWS\peernet
    2008-08-27 19:16:20 ----D---- C:\Program Files\Movie Maker
    2008-08-27 19:05:48 ----D---- C:\WINDOWS\system32\npp
    2008-08-27 19:05:46 ----D---- C:\WINDOWS\msagent
    2008-08-27 19:05:42 ----D---- C:\WINDOWS\srchasst
    2008-08-27 19:05:38 ----D---- C:\Program Files\NetMeeting
    2008-08-27 19:05:34 ----D---- C:\WINDOWS\system32\Com
    2008-08-27 19:05:26 ----D---- C:\Program Files\Windows Media Player
    2008-08-27 19:05:24 ----D---- C:\Program Files\Windows NT
    2008-08-27 19:04:13 ----D---- C:\WINDOWS\system32\oobe
    2008-08-27 19:04:09 ----D---- C:\WINDOWS\system
    2008-08-27 18:56:06 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-08-27 18:55:18 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2008-08-27 18:43:27 ----D---- C:\WINDOWS\EHome
    2008-08-27 02:24:32 ----A---- C:\WINDOWS\system32\mshtml.dll
    2008-08-26 01:24:31 ----A---- C:\WINDOWS\system32\wininet.dll
    2008-08-26 01:24:31 ----A---- C:\WINDOWS\system32\webcheck.dll
    2008-08-26 01:24:31 ----A---- C:\WINDOWS\system32\urlmon.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\url.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\pngfilt.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\occache.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\mstime.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\msrating.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\mshtmled.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\msfeeds.dll
    2008-08-26 01:24:30 ----A---- C:\WINDOWS\system32\jsproxy.dll
    2008-08-26 01:24:29 ----A---- C:\WINDOWS\system32\iertutil.dll
    2008-08-26 01:24:29 ----A---- C:\WINDOWS\system32\iernonce.dll
    2008-08-26 01:24:29 ----A---- C:\WINDOWS\system32\iedkcs32.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\ieapfltr.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\ieaksie.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\ieakeng.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\icardie.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\extmgr.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\dxtrans.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\dxtmsft.dll
    2008-08-26 01:24:28 ----A---- C:\WINDOWS\system32\advpack.dll
    2008-08-25 18:28:00 ----D---- C:\WINDOWS\Debug
    2008-08-25 02:38:00 ----A---- C:\WINDOWS\system32\ieudinit.exe
    2008-08-25 02:37:59 ----A---- C:\WINDOWS\system32\ie4uinit.exe
    2008-08-22 23:54:51 ----A---- C:\WINDOWS\system32\ieakui.dll

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944]
    R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
    R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-06-12 56108]
    R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-10-01 21035]
    R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2005-11-20 16512]
    R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416]
    R2 irda;IrDA Protocol; C:\WINDOWS\System32\DRIVERS\irda.sys [2008-04-13 88192]
    R3 ac97intc;Intel(r) 82801 Audio Driver Install Service (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
    R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152]
    R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-13 13952]
    R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\System32\DRIVERS\e100b325.sys [2001-08-17 117760]
    R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584]
    R3 sdbus;sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [2008-04-13 79232]
    R3 SMCIRDA;SMC IrCC Miniport Device Driver; C:\WINDOWS\System32\DRIVERS\smcirda.sys [2001-08-17 35913]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S2 EAPPkt;Realtek EAPPkt Protocol; C:\WINDOWS\system32\DRIVERS\EAPPkt.sys []
    S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-13 11904]
    S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-13 11008]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6; C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640]
    R2 Irmon;Infrared Monitor; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
    R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
    R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
    R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040]
    R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
    S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-06-23 654848]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
    S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe []
    S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
    S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-14 779824]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

    -----------------EOF-----------------

    RSIT info:
    info.txt logfile of random's system information tool 1.04 2008-11-17 11:17:11

    ======Uninstall list======

    --> "C:\Program Files\InstallShield Installation Information\{F37167DD-4436-4641-90B6-329D60632DDA}\Setup.exe" REMOVEALL --u:{F37167DD-4436-4641-90B6-329D60632DDA}
    -->C:\PROGRA~1\Yahoo!\Common\unyt.exe
    -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
    -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    -->C:\WINDOWS\UNRecode.exe /UNINSTALL
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
    Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Photoshop Elements 6.0-->msiexec /I {F54AC413-D2C6-4A24-B324-370C223C6250}
    Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
    AIM 6-->C:\Program Files\AIM6\uninst.exe
    Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
    avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll ",RunSetup
    AviSynth 2.5--> "C:\Program Files\AviSynth 2.5\Uninstall.exe "
    Azureus-->C:\Program Files\Azureus\Uninstall.exe
    CDisplay 1.8--> "C:\Program Files\CDisplay\unins000.exe "
    DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    DVD Ripper Platinum 4-->C:\Program Files\ImTOO\DVD Ripper Platinum 4\Uninstall.exe
    DVD2SVCD 1.2.3 Build 1--> "C:\Program Files\DVD2SVCD\unins000.exe "
    DVDIdle Pro 5.9.8.5--> "C:\Program Files\DVDIdle Pro\unins000.exe "
    eMule--> "C:\Program Files\eMule\Uninstall.exe "
    GoldWave v5.18--> "C:\Program Files\GoldWave\unstall.exe" "GoldWave v5.18" "C:\Program Files\GoldWave\unstall.log "
    GrabPro - Toolbar-->regsvr32 /u /s "C:\Program Files\Orbitdownloader\GrabPro.dll"
    GSpot Codec Information Appliance-->C:\Program Files\GSpot\Uninstall.exe
    Hotfix for Windows Internet Explorer 7 (KB947864)--> "C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe "
    Hotfix for Windows Media Format 11 SDK (KB929399)--> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe "
    Hotfix for Windows Media Player 11 (KB939683)--> "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe "
    Hotfix for Windows XP (KB952287)--> "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe "
    Huffyuv AVI lossless video codec (Remove Only)-->rundll.exe setupx.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\HUFFYUV.INF
    InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
    InterVideo WinDVD 8-->C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
    Invoke Solutions Participant 6.0.0.1445--> "C:\Program Files\Invoke Solutions\Participant\6.0\unins000.exe "
    IsoBuster 2.1--> "C:\Program Files\IsoBuster\Uninst\unins000.exe "
    J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
    Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
    Keynote Connector-->C:\WINDOWS\DOWNLO~1\CONNEC~1.EXE /Uninstall
    K-Lite Mega Codec Pack 4.2.5--> "C:\Program Files\K-Lite Codec Pack\unins000.exe "
    Magic ISO Maker v5.4 (build 0239)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
    Magic M4A to MP3 Converter 3.1--> "C:\Program Files\Magic M4A to MP3 Converter\unins000.exe "
    Microsoft .NET Framework 1.1 Hotfix (KB928366)--> "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp "
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft .NET Framework 3.0-->c:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
    Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
    Microsoft Base Smart Card Cryptographic Service Provider Package--> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe "
    Microsoft Compression Client Pack 1.0 for Windows XP--> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe "
    Microsoft Internationalized Domain Names Mitigation APIs--> "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe "
    Microsoft National Language Support Downlevel APIs--> "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe "
    Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
    Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
    Microsoft Office Enterprise 2007--> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
    Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
    Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
    Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
    Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
    Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
    Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
    Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
    Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
    Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
    Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
    Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
    Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
    Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
    Microsoft Reader-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B6F7DBE7-2FE2-458F-A738-B10832746036}\Setup.exe" -L0x9
    Microsoft User-Mode Driver Framework Feature Pack 1.0--> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe "
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
    Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
    Nero 7 Ultra Edition-->MsiExec.exe /I{43FFE159-3199-4188-A1CD-629166AD1033}
    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    Orbit Downloader--> "C:\Program Files\Orbitdownloader\unins000.exe "
    PowerISO--> "C:\Program Files\PowerISO\uninstall.exe "
    QuickTime Alternative 1.80--> "C:\Program Files\QuickTime Alternative\unins000.exe "
    QuickTime-->MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
    Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
    Security Update for 2007 Microsoft Office System (KB955936)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028}
    Security Update for Microsoft Office Excel 2007 (KB955470)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E}
    Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
    Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
    Security Update for Microsoft Office Publisher 2007 (KB950114)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
    Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
    Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
    Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
    Security Update for Visio 2007 (KB947590)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
    Security Update for Windows Internet Explorer 7 (KB928090)--> "C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB931768)--> "C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB933566)--> "C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB937143)--> "C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB938127)--> "C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB942615)--> "C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB944533)--> "C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB953838)--> "C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB956390)--> "C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe "
    Security Update for Windows Media Encoder (KB954156)--> "C:\WINDOWS\$NtUninstallKB954156_WM9L$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 11 (KB936782)--> "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 11 (KB954154)--> "C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 8 (KB917734)--> "C:\WINDOWS\$NtUninstallKB917734_WMP8$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 9 (KB917734)--> "C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
    Security Update for Windows XP (KB938464)--> "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB941569)--> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB946648)--> "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950760)--> "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950762)--> "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950974)--> "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951066)--> "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951376)--> "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951376-v2)--> "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951698)--> "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951748)--> "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB952954)--> "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB953839)--> "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB954211)--> "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956391)--> "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956803)--> "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956841)--> "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB957095)--> "C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB958644)--> "C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe "
    SoulSeek 157 NS 12d--> "C:\Program Files\SoulseekNS\uninstall.exe "
    Subtitle Workshop 2.51--> "C:\Program Files\URUSoft\Subtitle Workshop\uninstall.exe "
    Uniblue RegistryBooster 2--> "C:\Program Files\Uniblue\RegistryBooster 2\unins000.exe "
    Update for Microsoft Office Outlook 2007 (KB952142)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {4AD3A076-427C-491F-A5B7-7D1DE788A756}
    Update for Office 2007 (KB946691)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
    Update for Outlook 2007 Junk Email Filter (kb957258)-->msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {E070CDA4-A8DD-47FA-89A0-F5DA5D5DDFF9}
    Update for Windows XP (KB951072-v2)--> "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe "
    Update for Windows XP (KB951978)--> "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe "
    VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{D1B11537-EA51-4DD8-BF1E-098BEE48868D}\setup.exe -runfromtemp -l0x0409
    VideoLAN VLC media player 0.8.6a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
    Win AVI HelixSDK--> "C:\Program Files\WinAVI Video Converter\HelixSDK\unins000.exe "
    Winamp--> "C:\Program Files\Winamp\UninstWA.exe "
    WinAVI FLV Converter--> "C:\Program Files\WinAVI FLV Converter\unins000.exe "
    WinAVI Video Converter--> "C:\Program Files\WinAVI Video Converter\unins000.exe "
    Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
    Windows Imaging Component--> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe "
    Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
    Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
    Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
    Windows Media Encoder 9 Series-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Windows Media Encoder 9 Series-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
    Windows Media Format 11 runtime--> "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime--> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe "
    Windows Media Player 11--> "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows Media Player 11--> "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe "
    Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
    Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
    Windows XP Service Pack 3--> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe "
    WinHugs--> "C:\Program Files\WinHugs\uninstaller.exe "
    WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
    Xvid 1.1.3 final uninstall--> "C:\Program Files\Xvid\unins000.exe "
    Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
    Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

    ======Security center information======

    AV: avast! antivirus 4.8.1229 [VPS 081105-0] (outdated)

    ======Environment variables======

    "ComSpec "=%SystemRoot%\system32\cmd.exe
    "Path "=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
    "windir "=%SystemRoot%
    "OS "=Windows_NT
    "PROCESSOR_ARCHITECTURE "=x86
    "PROCESSOR_LEVEL "=15
    "PROCESSOR_IDENTIFIER "=x86 Family 15 Model 2 Stepping 4, GenuineIntel
    "PROCESSOR_REVISION "=0204
    "NUMBER_OF_PROCESSORS "=1
    "PATHEXT "=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP "=%SystemRoot%\TEMP
    "TMP "=%SystemRoot%\TEMP
    "FP_NO_HOST_CHECK "=NO
    "CLASSPATH "=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
    "QTJAVA "=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip

    -----------------EOF-----------------
     
  2. 2008/11/18
    mattman

    mattman Inactive Alumni

    Joined:
    2002/06/10
    Messages:
    8,198
    Likes Received:
    63
    This scares me
    Check that information. You have a 38GB C: drive and it only has 2GB free? That is too small. From my experience, when you get to less than 10% free on Win XP, the system can start acting strangely.

    Are you running 256MB of RAM? That is too small unless you are only running a "basic" system (you have lots of startup programs).

    I suggest you have at least 20% of free space on your Windows drive. 256MB of RAM will run Win XP if you don't load many programs (excluding startup).

    Matt
     

  3. to hide this advert.

  4. 2008/11/18
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Then of course there's 1/2 a dozen P2P apps running :eek:
     
    Arie,
    #3
  5. 2008/11/18
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    I know I have a weak machine, but that can't be the problem. I usually fluctuate the amount of space on my hard drive, and now have 4GB, and have run with a lot less than 2.
    The P2P programs also can't be the problem, as after booting I close everything I can before trying to connect to the internet.
    Whats happening isn't my PC trying to run too many things at once and being too slow to respond. It happens when it appears be running nothing, and I can leave it connected for hours without it settling, or catching up to whatever it should be doing, as it would if I was running too many programs.
     
  6. 2008/11/19
    mattman

    mattman Inactive Alumni

    Joined:
    2002/06/10
    Messages:
    8,198
    Likes Received:
    63
    You are working "on the edge ". If you know anyone that is upgrading to a new computer, they may give you their old one. There are probably many similar to yours that are sitting in storage. You should be able to end up with an extra HDD, the RAM on your machine is probably "PC ", PC1600 to PC3200 type.

    For Win XP, Defragmentation won't run at less than 15% free space. That sounds alarm bells for me.

    You will probably get better performance if you find out what is loading at startup and set them not to run at startup.

    From Arie's suggestion, if P2P programs are running in the background from startup, when you connect to the internet they will all try connecting to look for unfinished downloads. Your internet will be swamped with requests for connections.

    In short, I suggest you look at what you are asking the system to do.

    Matt
     
  7. 2008/11/19
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    Again, I'm positive that P2P programs are not the problem, as they're not running or have any unfinished downloads when connecting. Days earlier when I did, there wasn't a problem.
    When I connect nothing is running, not even a browser.

    I intend to reformat my computer, as I can't figure out what the problem is, but thought I would look here before doing so.
    If I could afford to upgrade I would, and will when I can.

    Should I not have installed Service Pack 3, and stuck with 2?
     
  8. 2008/11/19
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Ok, so what's happened since "Days earlier "?

    Something will be running, look past CPU usage, what is memory usage? How much work is your hard drive doing (ie swap space)?

    RANT ON

    It's been my experience even after several times of telling people why their system is slow, and assisting in removing certain programs (because an uprade wasn't possible) within a week those very same programs have reappeared either because "They weren't the problem ", "My Kids did it ", "You couldn't have taken it off properly ", "I Don't know how that came back ".

    RANT OFF

    Tober, listen to these guys, they know what they're talking about.
     
  9. 2008/11/19
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Tober27, and welcome to WindowsBBS :)

    How about we start off with seeing what's establishing connections. Download TCPView by Mark Russinovich and extract it to it's own folder.
    Disconnect from the internet and allow your computer to become inactive.
    Double click TCPView.exe then connect to the internet and wait for the activity you described to begin.
    At that point, click File>Save as and save it as TCP.txt on your desktop. Post that log here for review.
     
  10. 2008/11/19
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    I'm not actually able to do anything on the internet for more than a minute before the computer becomes basically unresponsive. Even when I unplug the internet connection it doesn't improve until I force restart it.

    I ran TCP (downloaded with a seperate PC) and this is the saved file after the problem is happening. It took, I think, over an hour to save the file, as it responds that slowly. The only processes I observed making connections, or trying to were avast and 2 'svchost.exe's


    alg.exe:2484 TCP serenity-ii:1026 serenity-ii:0 LISTENING
    ashMaiSv.exe:1384 TCP serenity-ii:12143 serenity-ii:0 LISTENING
    ashMaiSv.exe:1384 TCP serenity-ii:12110 serenity-ii:0 LISTENING
    ashMaiSv.exe:1384 TCP serenity-ii:12025 serenity-ii:0 LISTENING
    ashMaiSv.exe:1384 TCP serenity-ii:12119 serenity-ii:0 LISTENING
    lsass.exe:712 UDP serenity-ii:isakmp *:*
    lsass.exe:712 UDP serenity-ii:4500 *:*
    svchost.exe:1180 UDP serenity-ii:1900 *:*
    svchost.exe:944 TCP serenity-ii:epmap serenity-ii:0 LISTENING
    svchost.exe:984 UDP serenity-ii:ntp *:*
    System:4 TCP serenity-ii:microsoft-ds serenity-ii:0 LISTENING
    System:4 UDP serenity-ii:microsoft-ds *:*

    thanks for looking
     
  11. 2008/11/20
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hmmm, is your computer named serenity-ii ?
    With TCPView open, do you see any connections where the State is established?
    What kind of connection do you have?

    Download mbr.exe and save it to your desktop.
    Double click mbr.exe to run it.
    It will open and close very quickly and produce the file mbr.log on the desktop.
    Double click mbr.log to open it and post it's contents.
     
  12. 2008/11/20
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    avast tells me that mbr is a trojan, malware.
    umm... is that normal?

    Yes, my computer is named serenity-ii
    Two 'svchost.exe's were briefly Established, but I think that is all. Avast may have been briefly, but I'm not sure it made it that far.
     
  13. 2008/11/20
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes, that sounds normal for Avast. They seem to love tagging our tools as infections. :mad: I assure you, the file is safe.

    Continue to monitor TCPView and note any established connections. Note as much information about them as you can and post it here (Avast excluded).
     
  14. 2008/11/20
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    I didn't see any reach ESTABLISHED this time. About the only activity I saw was svchost.exes

    It took me, again, over an hour to run MBR and get a log. Also had to turn off avast to do it. Am not sure it worked right as all the log had in it was:

    Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK
     
  15. 2008/11/20
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That log is fine. For the record, I agree with Mattman ........ you would do well to try and get the free space closer to 15%. The drive needs room for the pagefile and temps to expand.

    Please open the Device Manager and check for any errors.

    I also need to ask again .... what type of internet connection do you have?
     
  16. 2008/11/22
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    RESOLVED.

    When running MBR I had to turn off avast so that it wouldn't interfere with it and realised that I didn't have a problem until a program tried to access the internet. Previously I thought it happened when I connected, but that was due to avast automatically attempting to update.

    I was worried that there might be a hardware problem with my ethernet card, as then my last resort of reformatting and starting from scratch probably wouldn't help.
    I then realised that running Registry Booster takes far longer than it should have, seeming to snag on certain files or sectors for far longer than it should have taken.

    I continued to free some space so I could defrag and run an error-check disc scan, hoping that maybe the ethernet driver is on a bad sector or something(?)
    It turns out to have been the case, and repaired with the simple scan.
    I was too focused on looking for some hidden virus, or spyware to even think of that being the cause.

    I knew I was having a hard time explaining the problem, or how the computer was acting when it was occurring, but I also knew it wasn't due to any of the programs that I have installed. If I could have explained better, I'm sure that would have been clear.


    So was it due to a bad, corrupted, damaged sector, or cluster... or what would it have been?
     
  17. 2008/11/22
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to hear you got it resolved. I could only guess at what the root of the cause was.
     
  18. 2008/11/22
    Tober27

    Tober27 Inactive Thread Starter

    Joined:
    2008/11/16
    Messages:
    12
    Likes Received:
    0
    Thanks for all the help!
     
  19. 2008/11/22
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You bet! :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.