This thread's last reply is from April 1, 2009, 7:02 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Greetings, all: I'm using Cox Cable (US)'s McAfee Security Suite. Since Thursday evening I have gotten McAfee pop-up notifications on boot-up, that the suite had detected StealthMBR!mbr in any &/or all of the following locations: G:\, G:\Desktop.ini, I:\ and I:\Desktop.ini - neither of these drives have a Desktop file (that I know of), and the F drive is my boot drive on this computer. The popup ID's it as an unquarantineable trojan & recommends I reboot & run a scan - which I have done, but when complete the suite states no problems detected. I've looked for a solution online, but I'm confused by what I have seen - I'm just a home enduser, not a registry whiz or any other sort of expert user.
If anyone needs any futher info, let me know. Thanks in advance for any and all assistance you can give me with this problem. The HijackThis log is as follows:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:41:44 PM, on 3/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
My name is Carolyn and I'll be glad to help you with your computer problems. HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that it happens.
Please do not run any other tool untill instructed to do so!
Please reply to this thread, do not start another!
Please tell me about any problems that have occurred during the fix.
Please tell me of any other symptoms you may be having as these can help also.
Please try as much as possible not to run anything while executing a fix.
If you follow these instructions, everything should go smoothly.
Step 1
Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt
Save both reports to your desktop.
Step 2
Please download gmer.zip from Gmer and save it to your desktop.
Right click on gmer.zip and select Extract All....
Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
Click on the Browse button. Click on Desktop. Then click OK.
Click Next. It will start extracting.
Once done, check (tick) the Show extracted files box and click Finish.
Double click on gmer.exe to run it. It will start running a scan. If it detects rootkit activity, you will receive a prompt to run a full scan. Click Yes.
When done, you may receive another notice. Click OK.
Click on Save ... to save a log.
Copy and paste in Gmer.txt and click Save.
Close Gmer.
If you receive no notice, click on the Scan button.
It will start scanning again.
When done, click on Save ... to save a log.
Copy and paste in Gmer.txt and click Save.
Close Gmer.
Note: Do not run any programs while Gmer is running.
Thanks very much for your assistance, Carolyn. Here are the logs you requested; I will patiently await your response:
DDS (Ver_09-02-01.01) - NTFSx86
Run by [redacted] at 10:58:48.59 on Sun 03/15/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1093 [GMT -7:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-02-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 10/15/2008 7:37:35 PM
System Uptime: 3/13/2009 7:53:01 PM (39 hours ago)
A: is Removable
C: is FIXED (NTFS) - 233 GiB total, 126.638 GiB free.
E: is FIXED (NTFS) - 6 GiB total, 5.883 GiB free.
F: is FIXED (NTFS) - 75 GiB total, 46.397 GiB free.
G: is FIXED (NTFS) - 70 GiB total, 22.51 GiB free.
H: is FIXED (NTFS) - 70 GiB total, 23.1 GiB free.
I: is FIXED (NTFS) - 37 GiB total, 16.26 GiB free.
X: is CDROM ()
Y: is CDROM ()
Z: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 3/5/2009 7:14:52 PM - System Checkpoint
RP2: 3/5/2009 7:16:12 PM - Post-Trojan Removal Attempts
RP3: 3/6/2009 7:54:01 PM - System Checkpoint
RP4: 3/7/2009 12:04:48 PM - Removed Roxio Update Manager
RP5: 3/7/2009 12:07:53 PM - Removed Roxio Easy Media Creator
RP6: 3/8/2009 8:16:31 AM - Uniblue RegistryBooster 2009
RP7: 3/9/2009 5:49:03 AM - Removed SUPERAntiSpyware Free Edition
RP8: 3/9/2009 10:15:35 AM - Ad-Aware Checkpoint
RP9: 3/9/2009 10:29:27 AM - Uniblue RegistryBooster 2009
RP10: 3/10/2009 9:41:37 AM - Removed Java(TM) 6 Update 11
RP11: 3/10/2009 9:42:03 AM - Installed Java(TM) 6 Update 12
RP12: 3/10/2009 11:28:27 AM - Uniblue RegistryBooster 2009
RP13: 3/10/2009 7:46:27 PM - Installed Roxio Easy Media Creator
RP14: 3/10/2009 9:00:14 PM - Software Distribution Service 3.0
RP15: 3/12/2009 4:00:58 PM - System Checkpoint
RP16: 3/13/2009 4:10:59 PM - System Checkpoint
RP17: 3/14/2009 4:21:51 PM - System Checkpoint
RP18: 3/15/2009 6:41:34 AM - Software Distribution Service 3.0
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Photoshop Elements 2.0
Adobe Reader 9
AI Nap
ASUSUpdate
Canon iP4500 series
CDDRV_Installer
Colin McRae Rally 2
Colin McRae Rally 2005
Cool & Quiet
Critical Update for Windows Media Player 11 (KB959772)
EPSON Copy Utility 3
EPSON Scan
Google Earth
Google Update Helper
Google Updater
Grand Prix Legends
GTR
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Java(TM) 6 Update 12
Java(TM) 6 Update 7
KhalInstallWrapper
LightScribe System Software 1.17.90.1
LightScribe Template Labeler
Logitech SetPoint
McAfee SecurityCenter
MediaFACE 4.2
MediaFACE 4.2 Image Library
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Midtown Madness
Microsoft Monster Truck Madness 2
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Pinball Arcade
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 7 Ultra Edition
neroxml
NVIDIA Drivers
PC Probe II
Player
RAIDXpert
Rally Trophy
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Roxio Drag-to-Disc
Roxio Easy Media Creator
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB958439)
Security Update for Microsoft Office Excel 2007 (KB958437)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Shockwave
SideWinder Force Feedback Wheel (USB)
Sierra Utilities
Spybot - Search & Destroy
SpywareBlaster 4.1
SuperNZB v3.2.1
U.S. Robotics V.92 PCI Faxmodem
Uniblue RegistryBooster 2009
Update for Microsoft Office 2007 Help for Common Features (KB957244)
Update for Microsoft Office Excel 2007 Help (KB957242)
Update for Microsoft Office OneNote 2007 Help (KB957245)
Update for Microsoft Office PowerPoint 2007 Help (KB957247)
Update for Microsoft Office Word 2007 Help (KB957252)
Update for Microsoft Script Editor Help (KB957253)
Update for Office 2007 (KB946691)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
3/9/2009 5:49:06 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
3/9/2009 10:32:14 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
==== End Of File ===========================
GMER 1.0.15.14939 - http://www.gmer.net
Rootkit scan 2009-03-15 13:05:43
Windows 5.1.2600 Service Pack 3
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
I notice the presence of Uniblue RegistryBooster 2009 Registry Cleaner on your pc.
I don't personally recommend the use of ANY registry cleaners.
Here is an excerpt from a discussion on regcleaners
Most reg cleaners aren't "bad" as such, but they aren't perfect and even the best have been known to cause problems.
The point we are trying to make is that the risk of using one far outweighs any benefit.
If it does work perfectly you will not see any difference
If it doesn't work properly you may end up with an expensive doorstop.
I am not seeing any signs of StealthMBR on your computer. It definitely would have shown up in the GMER scan if that were there... But just to be over-cautious, I would like to do one more scan.
Disable Spybot's TeaTimer. This is a two step process.
Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.
First step:
Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
Open Spybot S&D
Click Mode, choose Advanced Mode
Go To the bottom of the Vertical Panel on the Left, Click Tools
then, also in left panel, click Resident shows a red/white shield.
If your firewall raises a question, say OK
In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
OK any prompts.
Use File, Exit to terminate Spybot
Reboot your machine for the changes to take effect.
Don't forget to re-enable it, when your computer is clean.
Disable Ad-Aware
First please disable Ad-Aware as it may interfere with repairs.
Click the Settings button, Auto Scans tab, and under "Scan on Ad-Aware startup",
be sure both selections for "No automated scan" are checked (green).
Then click Save and close Ad-Aware.
========================================
Download Dr. Web CureIt and save it to your desktop.
Double click on cureit.exe to run it.
Click on Start to start the scan.
Dr Web CureIt will prompt you. Click OK.
This will start an express scan. It shouldn't take too long.
When done, click on Options > Change settings.
Select the Scan tab. Uncheck (untick) Heuristics analysis box.
Select the Log file tab. Uncheck (untick) Maximum log file size box.
Click OK to apply the settings.
Select the Complete scan radio button, then click on the green triangle button on the right hand side.
It will start scanning. Please be patient as this scan can be long.
During the scan, if it finds any infected items, it will prompt you. Click Yes to all to cure the files.
Click on File > Save report list. Save this report to a convenient location.
========================================
Please post the report from DrWeb CureIt along with a fresh HijackThis log and a description of how your computer is behaving.
Well ... THAT was interesting. There were items there, but they appear to have been taken care of.
First, after reading the link you provided to me regarding registry cleaners, I have attempted to uninstall Uniblue RegistryBooster through Control Panel - it seemed the prudent thing to do in light of the potential negatives.
I disabled TeaTimer; no problems there. I'm running Ad-Aware Free "Anniversary Edition" - it does not provide for auto scanning, so there was nothing to disable.
On the express scan, Dr. Web CureIt found 3 items: "Infected with BackDoor.MaosBoot". It took me straight to a "repair" prompt, so I was unable to save the log, such as it was. I elected to repair; all 3 instances were stated by the propts to be located at F:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll (I hope I transcribed this correctly). After the reipairs were effected the computer rebooted - and there were no McAfee Trojan notifications upon startup. I ran a complete scan and no items were identified; hence, I was provided with no option allowing me to save a log. Here is the subsequent HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:59:20 PM, on 3/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
There is one more nagging little item in this box that bothers me a bit: I installed an old fax modem and downloaded a driver for it, which I never got to work. Unfortunately, a little gift came with the modem driver, a Modem On Hold Utility which blinks a control panel on startup and which dropped a little yellow telephone icon onto my tray. When I point at it it says "Right click on me!", which seems a bit too enthusiastic for a modem. If I elect to "Exit MOH Application" on its control panel it warns "You pressed EXIT button. Modem On Hold and Initiate Call will be disabled. If you're online currently, the sustem may be corrupted! Are you sure to terminate this program?", which sounds vaguely threatening, stilted English and all. Are you aware of any way I can get rid of this little nuisance? I would be happy to start another thread if that is what would be necessary to solve this issue.
Thanks so much for your assistance, Carolyn. The service you and your cohorts are providing for the rest of us is invaluable. It is such a relief to have confidence regarding my computer's internet connection again.
Whoops - I spoke too soon. One of my hard drives (which was divided into two partitions, G and H) has disappeared - or, rather, has been redefined as a single "unallocated" drive. The G is one of the drives the Trojan seemed to have taken residence on ... have to go to work now ...
One of my hard drives (which was divided into two partitions, G and H) has disappeared - or, rather, has been redefined as a single "unallocated" drive. The G is one of the drives the Trojan seemed to have taken residence on ...
Sounds like that hard drive failed. You will have to post at one of the general computer troubleshooting forums for assistance with that problem. Let's do one more scan first though to make certain that your computer is clean.
===========================
Disable EasySpeak Call Waiting
Run HijackThis
Click on the Scan button
Put a check beside the item listed below (if present):
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe -c
Close all open windows and browsers/email, etc...
Click on the "Fix Checked" button
When completed, close the application.
===========================
Remove Outdated Java
Older versions have vulnerabilities that malware can use to infect your system.
Please Click Start > Control Panel > Add/Remove Programs
Remove this program by clicking Remove
Java(TM) 6 Update 7
===========================
Please go to Kaspersky website and perform an online antivirus scan.
Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply alongwith a fresh HijackThis log and a description of how your computer is behaving.
Thanks to your guidance, EasySpeak Call Waiting, whatever that was, is GONE. And Java(TM) 6 Update 7 has been eradicated as well. However ...
I tried to run the Kaspersky online virus scan, but when I was prompted to install the associated ActiveX app I was told by a dialog box in no uncertain terms that "Windows has blocked this software because it can't verify the publisher." In the hope that I could get something good to happen, I dumped Cox Security Suite by McAfee and installed the trial Kaspersky Internet Security 2009. I still got "Windows has blocked this software..." Meh. I started to run a full scan in Kaspersky Internet Security, but by the time I got up this morning it indicated the scan was only 5% complete ... after 8-1/2 hours. It seems to have gotten bogged down in my uploaded video files. I stopped the full scan and ran a quick scan, which indicated no items. But I'm attempting a full scan again, being more patient(!) this time.
I'll post the requested logs once this scan wraps up - assuming it ever does! ;~)
"HalibutStance" wrote:I tried to run the Kaspersky online virus scan, but when I was prompted to install the associated ActiveX app I was told by a dialog box in no uncertain terms that "Windows has blocked this software because it can't verify the publisher."
That is strange, the Kaspersky online scan does not use ActiveX - it uses Java.
In the hope that I could get something good to happen, I dumped Cox Security Suite by McAfee and installed the trial Kaspersky Internet Security 2009. I still got "Windows has blocked this software..." Meh. I started to run a full scan in Kaspersky Internet Security, but by the time I got up this morning it indicated the scan was only 5% complete ... after 8-1/2 hours.
Did you completely uninstall McAfee before installing Kaspersky Internet Security? Please stop that scan. It is not a replacement for the online scan I requested and it should not take that long to run.
Please do the following:
Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
I double-checked my McAfee uninstall - there was a McAfee folder lurking about under Programs in the Startup file of the Study account. It's been deleted.
Requested logs:
Logfile of random's system information tool 1.05 (written by random/random)
Run by [redacted] at 2009-03-19 18:48:00
Microsoft Windows XP Home Edition Service Pack 3
System drive F: has 46 GB (61%) free of 76 GB
Total RAM: 2047 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:48:09 PM, on 3/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
info.txt logfile of random's system information tool 1.05 2009-03-19 18:48:11
======Uninstall list======
-->F:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->F:\WINDOWS\system32\\MSIEXEC.EXE /x {637099FB-45FD-4BC7-9651-6FB540DBB749}
-->F:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->F:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->F:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->F:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->F:\WINDOWS\UNRecode.exe /UNINSTALL
-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
-->MsiExec.exe /I{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
-->MsiExec.exe /I{1B683082-8791-4D00-8ADE-6C8986FCCC68}
-->MsiExec.exe /I{1E2F8094-9DCD-4B87-ADB3-25CC5A0442FF}
-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
-->MsiExec.exe /I{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}
-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 F:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Ad-Aware-->"F:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->F:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe AIR-->F:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->F:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop Elements 2.0-->F:\WINDOWS\ISUNINST.EXE -f"F:\Program Files\Adobe\Photoshop Elements 2\Uninst.isu" -c"F:\Program Files\Adobe\Photoshop Elements 2\Uninst.dll"
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
AI Nap-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{E2216699-EA02-4B85-BAB1-1DF34C4BDF9D}\setup.exe" -l0x9
ASUSUpdate-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x9
AudioConverter Studio 5.9-->"F:\Program Files\AudioConverter Studio\unins000.exe"
Canon iP4500 series-->"F:\WINDOWS\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4500_series\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP4500_series /L0x0009
CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Colin McRae Rally 2-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{19B72AA9-985A-11D4-9C8A-00D0B75D1498}\setup.exe"
Colin McRae Rally 2005-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{CC67770B-581D-4E96-B72A-A7907CE18725}\setup.exe" -l0x9
Cool & Quiet-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}\setup.exe" -l0x9
Critical Update for Windows Media Player 11 (KB959772)-->"F:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
EPSON Copy Utility 3-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall
EPSON Scan-->F:\Program Files\epson\escndv\setup\setup.exe /r
Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Updater-->"F:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Grand Prix Legends-->F:\WINDOWS\IsUninst.exe -ff:\SIERRA\gpl\Uninst.isu
GTR-->F:\GTR\Support\unins000.exe
High Definition Audio Driver Package - KB888111-->"F:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"F:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->F:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->F:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"F:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"F:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)-->"F:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"F:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"F:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
LightScribe System Software 1.17.90.1-->MsiExec.exe /X{CB16F6D9-EBC9-4BC6-B917-7AF53E99C067}
LightScribe Template Labeler-->MsiExec.exe /X{FCBE0690-CBE1-4C60-87B0-4A70A6F5434E}
Logitech SetPoint-->"F:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe" -runfromtemp -l0x0009 -removeonly
MediaFACE 4.2 Image Library-->F:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2D6DFE76-A197-4337-90BA-8DCB840CA84B} /l1033
MediaFACE 4.2-->F:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{E129EC5D-FC37-4260-B6B7-1113D8613A89} /l1033
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"F:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "F:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->F:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"F:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"F:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"F:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Midtown Madness-->"F:\Program Files\Microsoft Games\Midtown Madness\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Monster Truck Madness 2-->F:\Program Files\Microsoft Games\Monster Truck Madness 2\UNINSTAL.EXE
Microsoft National Language Support Downlevel APIs-->"F:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Home and Student 2007-->"F:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Pinball Arcade-->"F:\Program Files\Microsoft Games\Pinball Arcade\UNINSTAL.EXE" /runtemp
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"F:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Nero 7 Ultra Edition-->MsiExec.exe /X{98EFD8F0-08DE-48DB-B922-A2EBAB711033}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NVIDIA Drivers-->F:\WINDOWS\system32\nvuninst.exe UninstallGUI
PC Probe II-->RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\setup.exe" -l0x9
RAIDXpert-->F:\Program Files\InstallShield Installation Information\{8B76B8E9-F773-4B75-A08C-120079EB765E}\setup.exe -runfromtemp -l0x0409
Rally Trophy-->MsiExec.exe /I{42A4EC40-09BC-427C-B657-67978B784058}
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->F:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\Setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
Roxio Drag-to-Disc-->MsiExec.exe /I{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}
Roxio Easy Media Creator-->MsiExec.exe /I{B7FB0C86-41A4-4402-9A33-912C462042A0}
Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85}
Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
Security Update for 2007 Microsoft Office System (KB958439)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6491B8AA-D11C-4648-A461-6234B31EB7E2}
Security Update for Microsoft Office Excel 2007 (KB958437)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {648FC016-2D6B-4A16-8D87-404533642F4B}
Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
Security Update for Microsoft Office system 2007 (KB956828)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {885E081B-72BD-4E76-8E98-30B4BE468FAC}
Security Update for Microsoft Office Word 2007 (KB956358)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {4551666D-0FD6-4C69-8A81-1C6F2E64517C}
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"F:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"F:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"F:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"F:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"F:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"F:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"F:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"F:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"F:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)-->"F:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->F:\WINDOWS\system32\MacroMed\Flash\genuinst.exe F:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"F:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"F:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"F:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"F:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"F:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"F:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"F:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"F:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"F:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"F:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"F:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"F:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"F:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"F:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"F:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"F:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"F:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"F:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"F:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"F:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"F:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"F:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"F:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"F:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"F:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Shockwave-->F:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE F:\WINDOWS\system32\Macromed\SHOCKW~1\INSTALL.LOG
SideWinder Force Feedback Wheel (USB)-->F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Microsoft Hardware\Game Controllers\Force Feedback Wheel (USB)\Uninst.isu" -c"F:\Program Files\Microsoft Hardware\Game Controllers\Force Feedback Wheel (USB)\Uninstall.dll"
Sierra Utilities-->F:\Program Files\Sierra On-Line\sutil32.exe uninstall
SpywareBlaster 4.1-->"F:\Program Files\SpywareBlaster\unins000.exe"
SuperNZB v3.2.1-->"F:\Program Files\SuperNZB\unins000.exe"
U.S. Robotics V.92 PCI Faxmodem-->F:\Program Files\CONEXANT\USR_MODEM_PCI_VEN_16EC&DEV_2F00&SUBSYS_010A16EC\HXFSETUP.EXE -U -IVEN_16EC&DEV_2F00&SUBSYS_010A16EC&REV_01
Update for Microsoft Office 2007 Help for Common Features (KB957244)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {C8C72583-C907-4D20-8973-C3858D96BD9E}
Update for Microsoft Office Excel 2007 Help (KB957242)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {51864046-74C8-487B-97CD-6167A4B1DB56}
Update for Microsoft Office OneNote 2007 Help (KB957245)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {7332DE60-DC79-4578-A60A-A5EA0D6E032B}
Update for Microsoft Office PowerPoint 2007 Help (KB957247)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {B20E2C59-EEC5-4102-9E50-5DBB2093C37D}
Update for Microsoft Office Word 2007 Help (KB957252)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {54DF3345-0720-4224-9740-C7E00303F565}
Update for Microsoft Script Editor Help (KB957253)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {F21BF703-548C-47B2-B92A-6876E9566C42}
Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Windows XP (KB951072-v2)-->"F:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"F:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"F:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"F:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->F:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Windows Internet Explorer 7-->"F:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"F:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"F:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"F:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"F:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Search 4.0-->"F:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"F:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
AV: Kaspersky Internet Security
FW: Kaspersky Internet Security
System event log
Computer Name: [redacted]
Event Code: 7036
Message: The Application Management service entered the stopped state.
Record Number: 8820
Source Name: Service Control Manager
Time Written: 20090307120459.000000-480
Event Type: information
User:
Computer Name: [redacted]
Event Code: 7035
Message: The Application Management service was successfully sent a start control.
Record Number: 8819
Source Name: Service Control Manager
Time Written: 20090307120459.000000-480
Event Type: information
User: DAVID-BB87081CA\Study
Computer Name: [redacted]
Event Code: 7023
Message: The Application Management service terminated with the following error:
The specified module could not be found.
Record Number: 8818
Source Name: Service Control Manager
Time Written: 20090307120459.000000-480
Event Type: error
User:
Computer Name: [redacted]
Event Code: 7036
Message: The Application Management service entered the stopped state.
Record Number: 8817
Source Name: Service Control Manager
Time Written: 20090307120459.000000-480
Event Type: information
User:
Computer Name: [redacted]
Event Code: 7035
Message: The Application Management service was successfully sent a start control.
Record Number: 8816
Source Name: Service Control Manager
Time Written: 20090307120459.000000-480
Event Type: information
User: DAVID-BB87081CA\Study
Application event log
Computer Name: [redacted]
Event Code: 0
Message:
Record Number: 41
Source Name: McAfee SiteAdvisor Service
Time Written: 20081204050359.000000-480
Event Type: information
User:
Computer Name: [redacted]
Event Code: 0
Message:
Record Number: 40
Source Name: gusvc
Time Written: 20081204050355.000000-480
Event Type: information
User:
Computer Name: [redacted]
Event Code: 11728
Message: Product: Microsoft Visual C++ 2005 Redistributable -- Configuration completed successfully.
Record Number: 39
Source Name: MsiInstaller
Time Written: 20081203211526.000000-480
Event Type: information
User: DAVID-BB87081CA\Study
Remove one obstacle and it seems like another one pops right up. Ran CCCleaner for all user accounts; no problem. Went into Security under Internet Options in Control Panel and disabled anything that might block any sort of ActiveX app. Clicked "pause protection" on Kaspersky Security Suite and set it to restart upon reboot. Tried to run the Kaspersky scan, but this time it wouldn't go because it said I didn't have Java post-1.5 installed. I uninstalled the Java whatever.12 that was installed on this thing, then went to Java and did a fresh reinstall. Went back to Kaspersky, got thru the initialization and got at least a half-hour into the multiple updates when the computer rebooted itself. When it all came back up it told me that it had "recovered from a serious error" that was caused by an "anti-virus program", and everything seemed to be as normal with the computer since that hard drive went missing. I paused the Security Suite again, went thru the motions on the scan again, but this time it only got to the end of the initial 3k kb update before it rebooted. It told me again that it had "recovered from a serious error" and that's where I sit right now. The computer seems to be acting normally at this time. Here's the current HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:58:31 PM, on 3/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Frustrating I know... You have been very patient and sounds like you are doing all of the right things here.
Let's try a different online scan... Don't wrestle with it if it does not want to work. With or without the scan results, my next recommendation will be for you to visit a General Troubleshooting Forum where they can help you determine what happened to that drive and if there are other hardware issues afoot here.
Click here to perform a Panda online scan. Please use Internet Explorer as it requires ActiveX.
Click on Scan your PC now.
A new window will open.
Select your country and type in your email address. You may also optionally choose to receive emails from Panda. If you don't wish to, please select I do not want to receive marketing information from Panda Software and/or its International Representatives where applicable. option.
Click on Free online scan.
You will be prompted to install an ActiveX. Please allow it.
Once installed, it will start downloading the virus definitions. Please be patient. This takes a while.
Once the files are downloaded, it will ask you to select what to scan. Select My Computer.
The scan will start. It takes a while, please be patient.
Once done, click on View Report.
You will be brought to another page. Click on Save Report. Save it to your desktop. Please post this report in your next reply.
Good morning, Carolyn ... or whatever time it is Down East -
Sorry for the delay. I've been researching how best to recover the data from the crashed hard drive, and I think I'm very close to a solution. I imagine that once I migrate files from the dead drive to my spare, which will possibly be tonight, I will want to run another, but more on that later. In the meantime, here is the Panda scan from the other day; it looks like, thanks to your kind assistance, this whole mess is very close to being wrapped up:
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-03-22 19:52:22
PROTECTIONS: 1
MALWARE: 7
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Kaspersky Internet Security 8.0.0.506 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00148914 Cookie/Tucows TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@tucows[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@com[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@com[3].txt
00167795 Cookie/Cd Freaks TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\[redacted][3].txt
00168105 Cookie/Cd Freaks TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@cdfreaks[1].txt
00170549 Cookie/FortuneCity TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@fortunecity[1].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@go[1].txt
00207338 Cookie/Target TrackingCookie No 0 Yes No F:\Documents and Settings\Study\Cookies\study@target[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================
This is my general post for when your logs show no more signs of malware - Please let me know if you still are having problems with your computer and what these problems are
Your log now appears to be clean. Congratulations!
You can get rid of the tools we used:
Please delete RSIT.exe from your computer
Please delete DDS.exe from your computer
Go to Start --> Run and copy/paste C:\WINDOWS\gmer_uninstall.cmd into the run window, click Okay. When that process completes, please reboot your computer.
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints. You need to be registered to post as, unfortunately, we were hit with too many spam posts to allow guest posting to continue. Just find your country room and register your complaint.
Protection Programs
Don't forget to re-enable any protection programs we disabled during your fix.
General Security and Computer Health
Below are some steps to follow in order to dramatically lower the chances of reinfection. You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.
Clear Infected System Restore Points
Turn System Restore off
On the Desktop, right click on the My Computer icon.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK. Restart your computer
Turn System Restore on
On the Desktop, right click on the My Computer icon.
Click Properties.
Click the System Restore tab.
Uncheck *Turn off System Restore*.
Click Apply, and then click OK.
Note: only do this once,and not on a regular basis
Set correct settings for files
Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
Under Hidden files and folders if necessary select Do not show hidden files and folders.
If unchecked please check Hide protected operating system files (Recommended)
If necessary check Display content of system folders
If necessary UncheckHide file extensions for known file types.
Click OK
Make sure that you keep your antivirus updated
New viruses come out every minute, so it is essential that you have the latest signatures for your antivirus program to provide you with the best possible protection from malicious software. Note: You should only have one antivirus installed at a time. Having more than one antivirus program installed at once is likely to cause conflicts and may well decrease your overall protection as well as impairing the performance of your PC.
Continue to use a firewall with outbound protection
The Windows firewall only monitors incoming traffic, NOT outgoing. Using a software firewall in its default configuration to replace the Windows firewall greatly reduces the risk of your computer being hacked. Make sure your firewall is always enabled while your computer is connected to the internet. Note: You should only have one firewall installed at a time. Having more than one firewall installed at once is likely to cause conflicts and may well decrease your overall protection as well as seriously impairing the performance of your PC.
Security Updates for Windows, Internet Explorer & Microsoft Office
Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis. Note: The update process uses ActiveX, so you will need to use internet explorer for it and allow the ActiveX control to install.
Update Non-Microsoft Programs
Microsoft isn't the only company whose products can contain security vulnerabilities. To check whether other programs running on your PC are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month.
Make Internet Explorer More Secure
You are using Internet Explorer v. 7. Therefore please read and follow the recommendations at this SITE
Recommended Programs
I would recommend the download and installation of some or all of the following programs (if not already present), and the updating of them on a regular basis.
WinPatrol
As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. For more information, please visit HERE.
SpywareBlaster
SpywareBlaster sets killbits in the registry to prevent known malicious ActiveX controls from installing on your computer. If you don't know what ActiveX controls are, see HERE. You can download SpywareBlaster from HERE.
Malwarebytes' Anti-Malware or SuperAntiSpyware
These are anti-malware applications that can thoroughly remove even the most advanced malware. They include a number of features, including a built in protection monitor that blocks malicious processes before they even start.
You can download Malwarebytes' Anti-Malware from HERE. You can find a tutorial HERE.
You can download SuperAntiSpyware from HERE.
Hosts File
For added protection you may also like to add a host file. A simple explanation of what a Hosts file does is HERE and for more information regarding host files read HERE.
Be sure to disable the service "DNS Client" FIRST to allow the use of large HOSTS files without slowdowns.
If this isn't done first, the next reboot may take a VERY LONG TIME.
This is how to do it. First be sure you are signed in as a user with administrative privileges:
Stop and Disable the DNS Client Service
Go to Start, Run and type Services.msc and click OK.
Under the Extended Tab, Scroll down and find this service. DNS Client
Right-Click on the DNS Client Service. Choose Properties
Select the General tab. Click on the Stop button.
Click the Arrow-down tab on the right-hand side at the Start-up Type box.
From the drop-down menu, click on Manual
Click the Apply tab, then click OK
Use an alternative Internet Browser
Many of the exploits are directed to users of Internet Explorer. Try using a different browser instead: Firefox
Opera
Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date.
I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.