info.txt logfile of random's system information tool 1.05 2009-03-12 21:44:08 ======Uninstall list====== -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\Windows\UNNeroBackItUp.exe /UNINSTALL -->C:\Windows\UNNeroMediaHome.exe /UNINSTALL -->C:\Windows\UNNeroShowTime.exe /UNINSTALL -->C:\Windows\UNNeroVision.exe /UNINSTALL -->C:\Windows\UNRecode.exe /UNINSTALL Ad-Aware-->"C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE Ad-Aware-->C:\ProgramData\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003} Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE Call of Duty(R) - World at War(TM) 1.1 Patch-->C:\Program Files\InstallShield Installation Information\{AFAE2B15-89A0-4215-A030-F7B5B478886B}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) - World at War(TM) 1.2 Patch-->C:\Program Files\InstallShield Installation Information\{2BF0AE92-C3BC-4112-9066-1546342B1FAE}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) - World at War(TM) 1.3 Patch-->C:\Program Files\InstallShield Installation Information\{149464D9-B06F-4505-9968-FD1206F67AD3}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) - World at War(TM)-->C:\Program Files\InstallShield Installation Information\{D80A6A73-E58A-4673-AFF5-F12D7110661F}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch-->C:\Program Files\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch-->C:\Program Files\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch-->C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch-->C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM)-->C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0409 Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DAC1AE4-33D1-4A78-8A42-00E09EDECC3E}\SETUP.EXE" -l0x9 UNINST CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A} Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E} DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN Driver Genius Professional Edition 2006 6.2.1525-->"C:\Program Files\Driver-Soft\DriverGenius\unins000.exe" EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B66E665A-DF96-4C38-9422-C7F74BC1B4E5}\SETUP.EXE" -l0x9 UNINST EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2EB81825-E9EE-44F4-8F51-1240C3898DC6}\Setup.exe" -l0x9 UNINST EPSON Print CD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}\SETUP.EXE" -l0x9 -SYSTEM EPSON Printer Software-->C:\Windows\system32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u ESET Online Scanner-->C:\Windows\system32\OnlineScannerUninstaller.exe ESP1400_1410 User's Guide-->C:\Program Files\EPSON\TPMANUAL\ESP1400_1410\ENG\USE_G\DOCUNINS.EXE GrabIt 1.7.2 Beta 3 (build 996)-->"C:\Program Files\GrabIt\unins000.exe" HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355} Logitech SetPoint-->"C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe" -runfromtemp -l0x0009 -removeonly Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe Mozilla Thunderbird (2.0.0.19)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94} Nero 8-->MsiExec.exe /X{1CA7ACD6-B21B-4240-AA05-4FC55F6E1033} neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI Realtek AC'97 Audio-->Alcrmv.exe -r -m Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe" TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe" Trojan Remover 6.7.6-->"C:\Program Files\Trojan Remover\unins000.exe" TweakVista-->"C:\ProgramData\{983E5E27-ED7A-4551-8D0E-8536786F9C14}\TweakVista_Setup.exe" REMOVE=TRUE MODIFY=FALSE TweakVista-->C:\ProgramData\{983E5E27-ED7A-4551-8D0E-8536786F9C14}\TweakVista_Setup.exe VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B} Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27} Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\Windows\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT="" Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE} Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52} Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe Windows Live Essentials-->MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536} Windows Live Messenger-->MsiExec.exe /X{0AAA9C97-74D4-47CE-B089-0B147EF3553C} Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5} Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238} WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe =====HijackThis Backups===== O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.203,85.255.112.77 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.203,85.255.112.77 O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.203,85.255.112.77 ======Security center information====== AV: Avira AntiVir PersonalEdition AS: Lavasoft Ad-Watch Live! AS: Windows Defender System event log Computer Name: Angus-PC Event Code: 104 Message: The service is publishing to the network. Record Number: 28772 Source Name: Microsoft-Windows-ResourcePublication Time Written: 20090312214212.000000-000 Event Type: Information User: NT AUTHORITY\LOCAL SERVICE Computer Name: Angus-PC Event Code: 7036 Message: The Windows Image Acquisition (WIA) service entered the running state. Record Number: 28773 Source Name: Service Control Manager Time Written: 20090312214216.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 1 Message: The system has resumed from sleep. Sleep Time: 2009-03-12T18:57:55.180Z Wake Time: 2009-03-12T21:42:12.890Z Wake Source: Unknown Record Number: 28774 Source Name: Microsoft-Windows-Power-Troubleshooter Time Written: 20090312214216.265625-000 Event Type: Information User: NT AUTHORITY\LOCAL SERVICE Computer Name: Angus-PC Event Code: 7036 Message: The WinHTTP Web Proxy Auto-Discovery Service service entered the running state. Record Number: 28775 Source Name: Service Control Manager Time Written: 20090312214245.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 18 Message: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?13 ?March ?2009 at 03:00: - Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB954430) - Windows Malicious Software Removal Tool - March 2009 (KB890830) Record Number: 28776 Source Name: Microsoft-Windows-WindowsUpdateClient Time Written: 20090312214326.876584-000 Event Type: Information User: NT AUTHORITY\SYSTEM Application event log Computer Name: Angus-PC Event Code: 9013 Message: The Desktop Window Manager was unable to start because composition was disabled by a running application Record Number: 1569 Source Name: Desktop Window Manager Time Written: 20090312160617.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 9013 Message: The Desktop Window Manager was unable to start because composition was disabled by a running application Record Number: 1570 Source Name: Desktop Window Manager Time Written: 20090312160651.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 1 Message: The Windows Security Center Service has started. Record Number: 1571 Source Name: SecurityCenter Time Written: 20090312160802.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 9013 Message: The Desktop Window Manager was unable to start because composition was disabled by a running application Record Number: 1572 Source Name: Desktop Window Manager Time Written: 20090312170452.000000-000 Event Type: Information User: Computer Name: Angus-PC Event Code: 8224 Message: The VSS service is shutting down due to idle timeout. Record Number: 1573 Source Name: VSS Time Written: 20090312173334.000000-000 Event Type: Information User: Security event log Computer Name: Angus-PC Event Code: 5038 Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error. File Name: \Device\HarddiskVolume1\Windows\System32\drivers\PnkBstrK.sys Record Number: 2169 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090312165903.248792-000 Event Type: Audit Failure User: Computer Name: Angus-PC Event Code: 5032 Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. Error Code: 2 Record Number: 2170 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090312214206.750000-000 Event Type: Audit Failure User: Computer Name: Angus-PC Event Code: 5032 Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. Error Code: 2 Record Number: 2171 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090312214206.750000-000 Event Type: Audit Failure User: Computer Name: Angus-PC Event Code: 5032 Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. Error Code: 2 Record Number: 2172 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090312214206.750000-000 Event Type: Audit Failure User: Computer Name: Angus-PC Event Code: 5032 Message: Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network. Error Code: 2 Record Number: 2173 Source Name: Microsoft-Windows-Security-Auditing Time Written: 20090312214207.562500-000 Event Type: Audit Failure User: ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=x86 "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 35 Stepping 2, AuthenticAMD "PROCESSOR_REVISION"=2302 "NUMBER_OF_PROCESSORS"=2 -----------------EOF-----------------