ComboFix 08-02.05.3 - Evan Kopilow 2008-02-08 7:49:35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT -5:00]
Running from: C:\Documents and Settings\Evan Kopilow\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Evan Kopilow\Desktop\CFScript.txt
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
FILE
C:\DOCUME~1\EVANKO~1\LOCALS~1\Temp\jbridgep.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Internet Spam Support Audio
C:\Documents and Settings\Evan Kopilow\Application Data\Kind Option Bait
C:\Documents and Settings\Evan Kopilow\Application Data\Kind Option Bait\
0C:\Documents and Settings\Evan Kopilow\Application Data\Kind Option Bait\FourMemoDefault.exe
C:\Program Files\kind option bait
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_JBRIDGEP
-------\jbridgep
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-07 01:24 . 2008-02-07 01:25 <DIR> d-------- C:\NoLopBackups
2008-02-07 00:55 . 2006-02-28 07:00 388,608 --a------ C:\kmd.exe
2008-02-07 00:51 . 2008-02-07 00:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-05 23:40 . 2008-02-07 08:39 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-02-05 08:26 . 2008-02-05 08:26 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-05 08:26 . 2008-02-07 08:29 <DIR> d-------- C:\Documents and Settings\Evan Kopilow\Application Data\AVG7
2008-02-05 08:25 . 2008-02-05 08:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-05 08:25 . 2008-02-05 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-04 08:34 . 2008-02-04 08:34 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-04 08:34 . 2008-02-04 08:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-04 08:33 . 2008-02-04 08:33 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 20:11 . 2008-02-03 20:11 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-02-02 23:17 . 2008-02-02 23:17 <DIR> d-------- C:\Program Files\DivoCodec
2008-02-02 20:45 . 2008-02-02 20:45 <DIR> d-------- C:\Documents and Settings\Evan Kopilow\Application Data\Talkback
2008-01-19 01:21 . 2008-01-19 01:21 <DIR> d-------- C:\Program Files\iPod
2008-01-11 21:43 . 2008-01-11 21:43 <DIR> d-------- C:\Program Files\AC3Filter
2008-01-11 21:43 . 2007-08-18 02:54 380,928 --a------ C:\WINDOWS\system32\ac3filter.acm
2008-01-11 21:39 . 2008-01-11 21:39 <DIR> d-------- C:\Program Files\AC3File
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-08 19:57 . 2008-01-08 19:57 <DIR> d-------- C:\Program Files\WinAVI Video Converter
2008-01-08 18:53 . 2008-01-08 19:17 <DIR> d-------- C:\Program Files\ahead
2008-01-08 18:53 . 2003-11-12 14:52 1,183,744 --------- C:\WINDOWS\UNNERO.exe
2008-01-08 18:53 . 2000-09-27 16:15 532,480 --a------ C:\WINDOWS\system32\imagx5.dll
2008-01-08 18:53 . 2000-09-21 17:02 507,904 --a------ C:\WINDOWS\system32\imagr5.dll
2008-01-08 18:53 . 2000-09-21 12:53 275,312 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-01-08 18:53 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-01-08 18:53 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-01-08 18:53 . 2004-02-10 10:55 69,416 --------- C:\WINDOWS\UNNERO.cfg
2008-01-08 18:53 . 2002-04-21 15:26 49,152 --------- C:\WINDOWS\system32\MultiSZ.dll
2008-01-08 18:53 . 2000-09-21 07:47 35,328 --a------ C:\WINDOWS\system32\picn20.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 07:18 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\uTorrent
2008-02-07 06:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-07 06:13 --------- d-----w C:\Program Files\Norton SystemWorks
2008-02-07 06:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-07 05:56 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\.purple
2008-02-06 06:06 --------- d-----w C:\Program Files\RegScrubXP
2008-02-05 20:15 --------- d-----w C:\Program Files\uTorrent
2008-02-04 13:33 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\Lavasoft
2008-02-04 00:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-04 00:31 --------- d-----w C:\Program Files\LucasArts
2008-02-01 11:21 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\U3
2008-01-19 06:21 --------- d-----w C:\Program Files\iTunes
2008-01-19 06:20 --------- d-----w C:\Program Files\QuickTime
2008-01-17 05:46 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\gtk-2.0
2008-01-14 12:46 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-01-05 21:56 --------- d-----w C:\Program Files\UDisk utility 1.00.08
2008-01-05 15:06 --------- d-----w C:\Program Files\Trillian
2008-01-02 02:33 --------- d-----w C:\Program Files\Starcraft
2008-01-01 17:33 --------- d-----w C:\Program Files\Pidgin
2008-01-01 17:33 --------- d-----w C:\Program Files\Common Files\GTK
2007-12-29 00:31 --------- d-----w C:\Program Files\Logitech
2007-12-29 00:31 --------- d-----w C:\Program Files\Common Files\Logitech
2007-12-25 18:55 --------- d-----w C:\Program Files\Any Video Converter
2007-12-25 18:55 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\Any Video Converter
2007-12-21 06:01 --------- d-----w C:\Program Files\FLVPlayer
2007-12-21 04:09 --------- d-----w C:\Program Files\Opera
2007-12-20 06:13 --------- d-----w C:\Program Files\Damian Pasternak
2007-12-20 03:25 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\Apple Computer
2007-12-16 22:17 --------- d-----w C:\Program Files\Winamp
2007-12-12 13:31 --------- d-----w C:\Documents and Settings\Evan Kopilow\Application Data\GTek
2007-12-12 13:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Gtek
2007-12-11 02:11 --------- d-----w C:\Program Files\WinTV
2007-12-10 03:31 --------- d-----w C:\Program Files\The Weather Channel FW
2007-12-01 00:01 70,656 ----a-w C:\WINDOWS\ScUnin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 07:00 15360]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2007-03-16 07:51 715888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-01 15:16 5562368]
"nwiz"="nwiz.exe" [2005-04-01 15:16 1495040 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-04-01 15:16 86016]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48 479232]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 09:33 892928]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-05 08:25 579072]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"TraySantaCruz"="C:\WINDOWS\system32\tbctray.exe" [2003-06-23 12:08 290816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-05 08:25 219136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
"NoDesktopCleanupWizard"= 1 (0x1)
R3 HCW848NT;Hauppauge Win/TV;C:\WINDOWS\system32\DRIVERS\hcw848nt.sys [2000-06-12 14:54]
R3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\Drivers\LCcFltr.Sys [2003-12-17 09:50]
R3 SAUSBHW;%SAUSBHW.SvcDesc%;C:\WINDOWS\system32\Drivers\sausb.sys [2001-11-07 12:27]
R3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys [2003-06-23 12:15]
R3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys [2003-06-23 12:15]
R3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2004-05-04 20:25]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 04:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-08 07:55:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PowerPanel\upssrv.exe
C:\PowerPanel\upsio.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-08 7:57:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 12:57:15
ComboFix2.txt 2008-02-07 06:02:28
.
2008-01-09 23:49:23 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:19 AM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PowerPanel\upssrv.exe
C:\PowerPanel\upsio.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: UPS Service (CyberPowerUPS) - Cyber Power System Inc. - C:\PowerPanel\upssrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 5582 bytes
AC3File (remove only)
AC3Filter (remove only)
Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.1
Ahead Nero Express
Apple Mobile Device Support
Apple Software Update
AVG 7.5
AVIcodec (remove only)
Combo Digital Film Reader USB
DivoCodec version 1.0.0.2
DivX 4.12 Codec
Ez OFF
FLV Player 1.3.3
Google Gmail Notifier
GTK+ Runtime 2.12.1 rev b (remove only)
Hauppauge WinTV NT4/Win2000 Drivers
Hauppauge WinTV2000
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HyperLoad - Bowling
iTunes
Java(tm) 6 Update 3
Logitech iTouch Software
Logitech MouseWare 9.79.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (2.0.0.11)
Mozilla Firefox (3.0b2)
NVIDIA Drivers
Opera 9.25
Pidgin
PowerPanel
QuickTime
RegScrubXP 3.25
SDS (Shutdown Scheduler)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Star Wars® Knights of the Old Republic® II: The Sith Lords(tm)
Star Wars®: Knights of the Old Republic (tm)
Starcraft
The Weather Channel Desktop
Trillian
Turtle Beach Santa Cruz
UDISK Accessory
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VIA Rhine-Family Fast Ethernet Adapter
Weather Services
Winamp (remove only)
WinAVI Video Converter
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
WinZip
XviD MPEG-4 Video Codec