1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

No Desktop

Discussion in 'Malware and Virus Removal Archive' started by MrSelfDestruct, 2008/11/30.

  1. 2008/11/30
    MrSelfDestruct

    MrSelfDestruct Inactive Thread Starter

    Joined:
    2008/11/30
    Messages:
    8
    Likes Received:
    0
    Hello, I'm not really experienced with computer stuff for the most part, and I don't really understand any of the suggestions I've seen you guys give people, but I'd like you to listen to my problem if you would. If this is the wrong place, please redirect me as to where I should put this.

    A little less than a year ago, my computer got some kind of malicious program and it damaged my explorer file, apparently. I had no desktop and was forced to open programs from Task Manager. It was a seriously hassle. I have no money, and my good spyware and virus protection programs ran out some time ago. So a friend directed me to a program called Spybot. It claimed to have removed some programs and stuff, but nothing fixed my explorer and I was left without a desktop.

    Then one day, randomly, it returned. I woke up in the morning to find overnight my desktop had returned, and my explorer file was fine. In the corner of the screen there was a message saying Windows had performed an update and removed malicious programs. Or something to that effect.
    After that, everything was fine.

    Now, it's happened again. I just got out of the shower to find my desktop gone, and all the things that would happen back then (such as restarting the explorer file causing the desktop to return for a few seconds and then disappear) are all happening now as well.

    Thing is, it took around 2 months for Windows to do whatever it did back then, and it was a serious hassle. I use my computer a lot. I need it, and I can't be dealing with this now. I don't even have a promise Windows will do whatever it did back then again.

    Wherever I ask, nobody really seems to know how to fix it. Most people will tell me to use System Restore, but the only dates it have are after the problem occurred. Then everyone tells me I'll just have to completely re-setup my computer, losing everything on it. I just can't do that. There is no way.

    So, I was wondering, does anyone know what update Windows did to remove the program and fix my explorer, returning my desktop? Is there anyway that I could have this done manually? Can I get their updates like that whenever I want? Or, if I can't, does anyone here have any idea of another way I can try and solve this problem.

    Any help is greatly appreciated.
    I am super depressed right now.
    Thank you for your time.
     
  2. 2008/11/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

    Please read this and post the logs requested in this thread.
     

  3. to hide this advert.

  4. 2008/11/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I guess you are running XP?? Always helpful to post your Operating System.
    Each month on Patch Tuesday MS deliver and run the latest version of the Malicious Software Removal Tool - this is what probably cleared out an infection that your computer picked up.
    Yes - Start > Windows Update or Internet Explorer > Tools > Windows Update

    Check that your computer is set to receive updates automatically .....

    Control Panel > Windows Security Centre > Manage Security Settings for .... Automatic Updates - click on this and ensure auto is set.

    Updating will only occur automatically when you are connected to the Internet.
    There is plenty of good free antivirus and antimalware software available - see my article for a summary .....

    Keep your Computer free from Viruses, Trojans, Spyware and Malware
     
  5. 2008/11/30
    MrSelfDestruct

    MrSelfDestruct Inactive Thread Starter

    Joined:
    2008/11/30
    Messages:
    8
    Likes Received:
    0
    Forgive me for failing to provide info.
    Yes, I am currently running XP.

    I went ahead to the place you told me about and I downloaded and installed all their updates for me, including the November 2008's Malicious Software Removal Tool. Sadly, it did not help the problem. I was fully expecting it to, since it fits that this update is what fixed the problem last time. I wonder why it did not do so this time.

    I guess I have no idea what to do now. Installing those updates was the only thing I could think of, since Windows said it installed an update when my desktop returned last time. I'm completely out of ideas, and I just noticed something.

    My Firefox no longer seems to work. Every single time I try and open it, it tells me it encountered a problem and needs to be closes. It doesn't even get a chance to load up. So I'm stuck using Internet Explorer for now. This seems even worse than last time. I'd hate to have to go for a month or two like this, or worse yet, I'd hate to always be like this if it was never fixed.

    So I went ahead and ran that RSIT thing mentioned in the page I was linked to. It gace me two text files called "Log" and "Info ". Not sure which one people normally post first, but I'll post "Log" first and "Info" second. Since it was suggested to break them up, I'll make a new post for "Log" and then a new post for "Info" to try and keep things organized.

    Thanks for listening to me, and if this stuff tells you anything, please give me suggestions as to what I should so. The future is looking pretty dark for me and my computer right now.

    Thank you for your time.
     
  6. 2008/11/30
    MrSelfDestruct

    MrSelfDestruct Inactive Thread Starter

    Joined:
    2008/11/30
    Messages:
    8
    Likes Received:
    0
    "Log "


    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Compaq_Owner at 2008-11-30 20:10:33
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 36 GB (24%) free of 146 GB
    Total RAM: 446 MB (4% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:11:00, on 2008/11/30
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Nexon\Mabinogi\npkcmsvc.exe
    C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\0Y71YB2B\RSIT[1].exe
    C:\Program Files\trend micro\Compaq_Owner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?T...=Q405&bd=presario&pf=desktop&parm1=seconduser
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?T...=Q405&bd=presario&pf=desktop&parm1=seconduser
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?T...=Q405&bd=presario&pf=desktop&parm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?T...=Q405&bd=presario&pf=desktop&parm1=seconduser
    F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {2277383C-872F-46A1-9822-B848BA8826D8} - C:\WINDOWS\system32\hgGywxxY.dll
    O2 - BHO: (no name) - {641B6B7F-0728-F8E2-9281-8F88DB4B4663} - C:\DOCUME~1\COMPAQ~1\APPLIC~1\THIRDC~1\error cdrom.exe (file missing)
    O2 - BHO: (no name) - {97807FE1-CB4B-4626-BE6C-D2C73E79F3D7} - C:\WINDOWS\system32\vtsqp.dll (file missing)
    O2 - BHO: (no name) - {A63E645F-13BD-45ED-B15F-6E8C1BD57279} - C:\WINDOWS\system32\ddcYoOGY.dll
    O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe "
    O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe "
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes2\iTunesHelper.exe "
    O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS_Download_version\TrayServer.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [QdrModule11] "C:\Program Files\QdrModule\QdrModule11.exe "
    O4 - HKCU\..\Run: [QdrPack11] "C:\Program Files\QdrPack\QdrPack11.exe "
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\Compaq_Owner\Application Data\gadcom\gadcom.exe" 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A
    O4 - HKCU\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs "
    O4 - HKCU\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat "
    O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
    O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
    O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4DD988A3-8A9A-4CC1-A763-F822C09E4315} (MGXCore Class) - http://www.va-sa-ra.co.jp/mgx/win/MGXPlugin.cab
    O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://169.237.137.101/activex/AMC.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3519197F-6678-40A7-B681-0E5AA5BC45D1}: NameServer = 81.92.1.3
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4C751C91-A885-4316-97AA-78149B0A8019}: NameServer = 81.92.1.3
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9F421ABE-1899-4465-8ECB-D4225070A27F}: NameServer = 81.92.1.3
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B79CD0E0-7DB7-4724-A9D0-ED3179536593}: NameServer = 81.92.1.3
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E59AB02A-0E38-4C2B-8B2A-1E658B80357F}: NameServer = 81.92.1.3
    O20 - Winlogon Notify: ddcYoOGY - C:\WINDOWS\SYSTEM32\ddcYoOGY.dll
    O20 - Winlogon Notify: efcywtu - efcywtu.dll (file missing)
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    O23 - Service: Google Update Service (gupdate1c8c039b2d11f5c) (gupdate1c8c039b2d11f5c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
    O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
    O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 9779 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\F28ADAFF9A858EAF.job
    C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2277383C-872F-46A1-9822-B848BA8826D8}]
    C:\WINDOWS\system32\hgGywxxY.dll [2008-11-30 318464]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{641B6B7F-0728-F8E2-9281-8F88DB4B4663}]
    C:\DOCUME~1\COMPAQ~1\APPLIC~1\THIRDC~1\error cdrom.exe []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97807FE1-CB4B-4626-BE6C-D2C73E79F3D7}]
    C:\WINDOWS\system32\vtsqp.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A63E645F-13BD-45ED-B15F-6E8C1BD57279}]
    C:\WINDOWS\system32\ddcYoOGY.dll [2008-11-30 25600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53}]
    Google Gears Helper - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll [2008-11-29 1667072]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-03-24 352256]
    {32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-08-08 691656]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "PCDrProfiler "= []
    "LSBWatcher "=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe []
    "TkBellExe "=C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot []
    "AOLDialer "=C:\Program Files\Common Files\AOL\ACS\AOLDial.exe []
    "UfSeAgnt.exe "=C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe []
    "iTunesHelper "=C:\Program Files\iTunes2\iTunesHelper.exe [2007-12-11 267048]
    "TrayServer "=C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS_Download_version\TrayServer.exe []
    "IMJPMIG8.1 "=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]
    "MSPY2002 "=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
    "PHIME2002ASync "=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
    "PHIME2002A "=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
    "Aim6 "= []
    "MSMSGS "=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
    "QdrModule11 "=C:\Program Files\QdrModule\QdrModule11.exe []
    "QdrPack11 "=C:\Program Files\QdrPack\QdrPack11.exe []
    "Veoh "=C:\Program Files\Veoh Networks\Veoh\VeohClient.exe [2008-03-24 3587120]
    " "= []
    "DAEMON Tools Lite "=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "WMPNSCFG "=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]
    "gadcom "=C:\Documents and Settings\Compaq_Owner\Application Data\gadcom\gadcom.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A []

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "TSClientMSIUninstaller "=cmd.exe /C cscript C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs []
    "TSClientAXDisabler "=cmd.exe /C C:\WINDOWS\Installer\TSClientMsiTrans\tscdsbl.bat []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Belkin Wireless USB Utility.lnk - C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\WINDOWS\system32\Ati2evxx.dll [2005-06-07 46080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcYoOGY]
    C:\WINDOWS\system32\ddcYoOGY.dll [2008-11-30 25600]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcywtu]
    efcywtu.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2006-05-23 402736]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} "=C:\WINDOWS\system32\efcywtu.dll []
    "{A63E645F-13BD-45ED-B15F-6E8C1BD57279} "=C:\WINDOWS\system32\ddcYoOGY.dll [2008-11-30 25600]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "authentication packages "=msv1_0
    C:\WINDOWS\system32\hgGywxxY

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders "=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\svcWRSSSDK]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=91000000

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%ProgramFiles%\iTunes\iTunes.exe "= "%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes "
    "C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe "= "C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe:*:Enabled:Compaq Connections "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
    shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


    ======List of files/folders created in the last 3 months======

    2008-11-30 20:10:33 ----D---- C:\rsit
    2008-11-30 19:59:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-11-30 19:57:11 ----D---- C:\WINDOWS\ie7updates
    2008-11-30 19:53:51 ----D---- C:\WINDOWS\WBEM
    2008-11-30 19:52:35 ----HDC---- C:\WINDOWS\ie7
    2008-11-30 19:52:16 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
    2008-11-30 19:51:41 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
    2008-11-30 19:45:41 ----D---- C:\WINDOWS\LastGood
    2008-11-30 19:40:02 ----ASH---- C:\WINDOWS\system32\YxxwyGgh.ini2
    2008-11-30 19:39:56 ----ASH---- C:\WINDOWS\system32\YxxwyGgh.ini
    2008-11-30 19:37:15 ----D---- C:\WINDOWS\Prefetch
    2008-11-30 19:26:49 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-11-30 19:26:32 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
    2008-11-30 19:26:15 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-11-30 19:25:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-11-30 19:25:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-11-30 19:24:30 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
    2008-11-30 19:24:06 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
    2008-11-30 19:23:39 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-11-30 19:22:44 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
    2008-11-30 19:22:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-11-30 19:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-11-30 19:21:22 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2008-11-30 19:20:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2008-11-30 19:20:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-11-30 19:20:11 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
    2008-11-30 19:19:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-11-30 19:19:32 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-11-30 19:19:17 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2008-11-30 19:18:37 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
    2008-11-30 19:18:22 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-11-30 19:18:00 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-11-30 19:06:11 ----D---- C:\WINDOWS\system32\en-us
    2008-11-30 19:06:10 ----D---- C:\WINDOWS\system32\scripting
    2008-11-30 19:06:08 ----D---- C:\WINDOWS\l2schemas
    2008-11-30 19:06:06 ----D---- C:\WINDOWS\system32\en
    2008-11-30 19:06:06 ----D---- C:\WINDOWS\system32\bits
    2008-11-30 19:01:26 ----D---- C:\WINDOWS\ServicePackFiles
    2008-11-30 18:57:52 ----D---- C:\WINDOWS\network diagnostic
    2008-11-30 18:50:36 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2008-11-30 18:50:10 ----D---- C:\WINDOWS\EHome
    2008-11-30 18:30:19 ----SHD---- C:\Config.Msi
    2008-11-30 16:07:00 ----A---- C:\WINDOWS\system32\64c574c5-.txt
    2008-11-30 16:06:19 ----A---- C:\WINDOWS\system32\hgGywxxY.dll
    2008-11-30 16:00:54 ----A---- C:\WINDOWS\system32\nnnliFyw.dll
    2008-11-30 16:00:51 ----A---- C:\WINDOWS\system32\ddcYoOGY.dll
    2008-11-16 11:17:11 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Nitroplus
    2008-11-16 10:52:04 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\WinRAR
    2008-11-16 04:55:56 ----D---- C:\Program Files\Nitroplus
    2008-11-13 03:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
    2008-11-13 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
    2008-11-11 21:20:20 ----D---- C:\Program Files\Kagetsu Tohya English v0.5
    2008-11-07 21:13:42 ----D---- C:\Program Files\Fate-stay night English
    2008-11-05 23:46:13 ----D---- C:\Program Files\Will
    2008-10-25 02:02:02 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
    2008-10-23 18:28:44 ----D---- C:\Program Files\7-Zip
    2008-10-16 02:03:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
    2008-10-16 02:03:03 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-16 02:02:48 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
    2008-10-16 02:02:33 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
    2008-10-16 02:02:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
    2008-10-16 02:01:21 ----HDC---- C:\WINDOWS\$NtUninstallKB956390_0$
    2008-09-30 16:43:34 ----A---- C:\WINDOWS\system32\msxml4.dll
    2008-09-30 13:03:09 ----D---- C:\Documents and Settings\All Users\Application Data\FreeRIP
    2008-09-30 13:03:05 ----D---- C:\Program Files\FreeRIP3
    2008-09-28 19:06:56 ----N---- C:\WINDOWS\system32\xmllite.dll
    2008-09-28 19:06:48 ----N---- C:\WINDOWS\system32\wlanapi.dll
    2008-09-28 19:06:33 ----N---- C:\WINDOWS\system32\tspkg.dll
    2008-09-28 19:06:32 ----N---- C:\WINDOWS\system32\tsgqec.dll
    2008-09-28 19:06:22 ----N---- C:\WINDOWS\system32\spupdwxp.exe
    2008-09-28 19:06:19 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
    2008-09-28 19:06:17 ----N---- C:\WINDOWS\system32\slserv.exe
    2008-09-28 19:06:17 ----N---- C:\WINDOWS\system32\slrundll.exe
    2008-09-28 19:06:17 ----N---- C:\WINDOWS\system32\slgen.dll
    2008-09-28 19:06:17 ----N---- C:\WINDOWS\system32\slextspk.dll
    2008-09-28 19:06:17 ----N---- C:\WINDOWS\slrundll.exe
    2008-09-28 19:06:16 ----N---- C:\WINDOWS\system32\slcoinst.dll
    2008-09-28 19:06:12 ----N---- C:\WINDOWS\system32\setupn.exe
    2008-09-28 19:06:06 ----N---- C:\WINDOWS\system32\s3gnb.dll
    2008-09-28 19:06:04 ----N---- C:\WINDOWS\system32\rhttpaa.dll
    2008-09-28 19:06:01 ----N---- C:\WINDOWS\system32\rasqec.dll
    2008-09-28 19:06:00 ----N---- C:\WINDOWS\system32\qutil.dll
    2008-09-28 19:05:58 ----N---- C:\WINDOWS\system32\qcliprov.dll
    2008-09-28 19:05:58 ----N---- C:\WINDOWS\system32\qagentrt.dll
    2008-09-28 19:05:58 ----N---- C:\WINDOWS\system32\qagent.dll
    2008-09-28 19:05:51 ----N---- C:\WINDOWS\system32\onex.dll
    2008-09-28 19:05:47 ----N---- C:\WINDOWS\system32\nv4_disp.dll
    2008-09-28 19:05:35 ----N---- C:\WINDOWS\system32\napstat.exe
    2008-09-28 19:05:35 ----N---- C:\WINDOWS\system32\napmontr.dll
    2008-09-28 19:05:35 ----N---- C:\WINDOWS\system32\napipsec.dll
    2008-09-28 19:05:35 ----N---- C:\WINDOWS\system32\mtxparhd.dll
    2008-09-28 19:05:34 ----A---- C:\WINDOWS\system32\msxml6r.dll
    2008-09-28 19:05:28 ----N---- C:\WINDOWS\system32\msshavmsg.dll
    2008-09-28 19:05:28 ----N---- C:\WINDOWS\system32\mssha.dll
    2008-09-28 19:05:07 ----N---- C:\WINDOWS\system32\mmcperf.exe
    2008-09-28 19:05:07 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
    2008-09-28 19:05:06 ----N---- C:\WINDOWS\system32\mmcex.dll
    2008-09-28 19:05:06 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
    2008-09-28 19:05:03 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
    2008-09-28 19:04:46 ----N---- C:\WINDOWS\system32\l2gpstore.dll
    2008-09-28 19:04:45 ----N---- C:\WINDOWS\system32\kmsvc.dll
    2008-09-28 19:04:44 ----N---- C:\WINDOWS\system32\kbdpash.dll
    2008-09-28 19:04:44 ----N---- C:\WINDOWS\system32\kbdnepr.dll
    2008-09-28 19:04:44 ----N---- C:\WINDOWS\system32\kbdiultn.dll
    2008-09-28 19:04:44 ----N---- C:\WINDOWS\system32\kbdbhc.dll
    2008-09-28 19:04:27 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
    2008-09-28 19:04:18 ----N---- C:\WINDOWS\system32\faxpatch.exe
    2008-09-28 19:04:18 ----A---- C:\WINDOWS\003055_.tmp
    2008-09-28 19:04:15 ----N---- C:\WINDOWS\system32\eapsvc.dll
    2008-09-28 19:04:15 ----N---- C:\WINDOWS\system32\eapqec.dll
    2008-09-28 19:04:15 ----N---- C:\WINDOWS\system32\eappprxy.dll
    2008-09-28 19:04:15 ----N---- C:\WINDOWS\system32\eapphost.dll
    2008-09-28 19:04:14 ----N---- C:\WINDOWS\system32\eappgnui.dll
    2008-09-28 19:04:14 ----N---- C:\WINDOWS\system32\eappcfg.dll
    2008-09-28 19:04:14 ----N---- C:\WINDOWS\system32\eapp3hst.dll
    2008-09-28 19:04:14 ----N---- C:\WINDOWS\system32\eapolqec.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3ui.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3svc.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3msm.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3dlg.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3cfg.dll
    2008-09-28 19:04:09 ----N---- C:\WINDOWS\system32\dot3api.dll
    2008-09-28 19:04:08 ----N---- C:\WINDOWS\system32\dimsroam.dll
    2008-09-28 19:04:07 ----N---- C:\WINDOWS\system32\dimsntfy.dll
    2008-09-28 19:04:06 ----N---- C:\WINDOWS\system32\dhcpqec.dll
    2008-09-28 19:04:01 ----N---- C:\WINDOWS\system32\credssp.dll
    2008-09-28 19:03:53 ----N---- C:\WINDOWS\system32\bitsprx4.dll
    2008-09-28 19:03:52 ----N---- C:\WINDOWS\system32\azroles.dll
    2008-09-28 19:03:51 ----N---- C:\WINDOWS\system32\ativtmxx.dll
    2008-09-28 19:03:49 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
    2008-09-28 19:03:48 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
    2008-09-28 19:03:37 ----N---- C:\WINDOWS\system32\aaclient.dll
    2008-09-26 02:01:24 ----HDC---- C:\WINDOWS\$NtUninstallKB901190$
    2008-09-25 14:47:52 ----A---- C:\WINDOWS\system32\korwbrkr.dll
    2008-09-25 14:47:52 ----A---- C:\WINDOWS\system32\chtbrkr.dll
    2008-09-25 14:47:52 ----A---- C:\WINDOWS\system32\chsbrkr.dll
    2008-09-25 14:47:51 ----A---- C:\WINDOWS\system32\msir3jp.dll
    2008-09-25 14:47:32 ----A---- C:\WINDOWS\system32\c_g18030.dll
    2008-09-25 14:47:31 ----A---- C:\WINDOWS\system32\kbd101a.dll
    2008-09-25 14:47:19 ----A---- C:\WINDOWS\system32\kbdnecNT.dll
    2008-09-25 14:47:19 ----A---- C:\WINDOWS\system32\kbdnecAT.dll
    2008-09-25 14:47:19 ----A---- C:\WINDOWS\system32\kbdnec95.dll
    2008-09-25 14:47:19 ----A---- C:\WINDOWS\system32\kbdlk41j.dll
    2008-09-25 14:47:19 ----A---- C:\WINDOWS\system32\kbdlk41a.dll
    2008-09-25 14:47:18 ----A---- C:\WINDOWS\system32\kbdibm02.dll
    2008-09-25 14:47:18 ----A---- C:\WINDOWS\system32\kbdax2.dll
    2008-09-25 14:47:18 ----A---- C:\WINDOWS\system32\kbd106n.dll
    2008-09-25 14:47:18 ----A---- C:\WINDOWS\system32\kbd101.dll
    2008-09-25 14:47:18 ----A---- C:\WINDOWS\system32\f3ahvoas.dll
    2008-09-25 14:46:55 ----A---- C:\WINDOWS\system32\c_is2022.dll
    2008-09-25 14:46:52 ----A---- C:\WINDOWS\system32\uniime.dll
    2008-09-25 14:46:42 ----A---- C:\WINDOWS\system32\imjp81k.dll
    2008-09-25 14:46:37 ----A---- C:\WINDOWS\system32\kbdkor.dll
    2008-09-25 14:46:37 ----A---- C:\WINDOWS\system32\kbdjpn.dll
    2008-09-25 14:46:37 ----A---- C:\WINDOWS\system32\kbd106.dll
    2008-09-25 14:46:37 ----A---- C:\WINDOWS\system32\kbd103.dll
    2008-09-25 14:46:37 ----A---- C:\WINDOWS\system32\kbd101c.dll
    2008-09-25 14:46:33 ----A---- C:\WINDOWS\system32\kbd101b.dll
    2008-09-25 14:37:16 ----D---- C:\Documents and Settings\All Users\Application Data\ezRights
    2008-09-19 18:57:02 ----D---- C:\Program Files\Tsukihime
    2008-09-10 17:03:34 ----A---- C:\COMLOG.txt
    2008-09-10 02:01:45 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
    2008-09-10 02:00:38 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$

    ======List of files/folders modified in the last 3 months======

    2008-11-30 20:11:00 ----D---- C:\Program Files\Trend Micro
    2008-11-30 20:06:27 ----D---- C:\Program Files\Mozilla Firefox
    2008-11-30 20:05:27 ----D---- C:\WINDOWS\Temp
    2008-11-30 20:05:16 ----D---- C:\WINDOWS
    2008-11-30 20:05:09 ----D---- C:\WINDOWS\system32
    2008-11-30 20:05:08 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-11-30 20:03:04 ----D---- C:\WINDOWS\system32\dllcache
    2008-11-30 20:03:04 ----D---- C:\WINDOWS\Help
    2008-11-30 20:03:04 ----D---- C:\Program Files\Internet Explorer
    2008-11-30 20:02:24 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-11-30 19:59:39 ----D---- C:\WINDOWS\inf
    2008-11-30 19:59:03 ----A---- C:\WINDOWS\imsins.BAK
    2008-11-30 19:56:31 ----HD---- C:\WINDOWS\$hf_mig$
    2008-11-30 19:53:43 ----D---- C:\WINDOWS\Media
    2008-11-30 19:42:06 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-11-30 19:41:27 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-11-30 19:37:23 ----A---- C:\WINDOWS\setuplog.txt
    2008-11-30 19:36:25 ----D---- C:\WINDOWS\system32\Setup
    2008-11-30 19:36:25 ----D---- C:\WINDOWS\AppPatch
    2008-11-30 19:36:24 ----D---- C:\WINDOWS\system32\wbem
    2008-11-30 19:36:23 ----D---- C:\WINDOWS\Fonts
    2008-11-30 19:36:16 ----D---- C:\WINDOWS\system32\drivers
    2008-11-30 19:26:55 ----D---- C:\WINDOWS\system32\CatRoot
    2008-11-30 19:23:27 ----D---- C:\WINDOWS\security
    2008-11-30 19:18:24 ----D---- C:\Program Files\Messenger
    2008-11-30 19:07:17 ----D---- C:\WINDOWS\WinSxS
    2008-11-30 19:06:42 ----D---- C:\WINDOWS\ime
    2008-11-30 19:06:11 ----D---- C:\WINDOWS\system32\usmt
    2008-11-30 19:06:07 ----SHD---- C:\WINDOWS\Installer
    2008-11-30 19:06:06 ----D---- C:\WINDOWS\PeerNet
    2008-11-30 19:06:05 ----D---- C:\Program Files\Movie Maker
    2008-11-30 19:01:16 ----D---- C:\WINDOWS\system32\Restore
    2008-11-30 19:01:15 ----D---- C:\WINDOWS\system32\npp
    2008-11-30 19:01:13 ----D---- C:\WINDOWS\msagent
    2008-11-30 19:01:11 ----D---- C:\WINDOWS\srchasst
    2008-11-30 19:01:07 ----D---- C:\Program Files\NetMeeting
    2008-11-30 19:01:04 ----D---- C:\WINDOWS\system32\Com
    2008-11-30 19:01:01 ----D---- C:\Program Files\Windows Media Player
    2008-11-30 19:01:00 ----D---- C:\Program Files\Windows NT
    2008-11-30 19:00:59 ----D---- C:\Program Files\Outlook Express
    2008-11-30 19:00:53 ----D---- C:\Program Files\Common Files\System
    2008-11-30 19:00:25 ----D---- C:\WINDOWS\system32\oobe
    2008-11-30 19:00:20 ----D---- C:\WINDOWS\system
    2008-11-30 18:36:03 ----D---- C:\WINDOWS\SoftwareDistribution
    2008-11-30 18:31:40 ----D---- C:\Program Files\Google
    2008-11-30 16:56:06 ----D---- C:\Program Files\Spybot - Search & Destroy
    2008-11-16 04:55:56 ----D---- C:\Program Files
    2008-11-16 04:55:35 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-11-14 23:59:10 ----D---- C:\WINDOWS\Tasks
    2008-11-13 20:17:54 ----D---- C:\WINDOWS\system32\FxsTmp
    2008-11-03 16:10:26 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-10-27 18:01:09 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Any Video Converter
    2008-10-18 22:33:52 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\dvdcss
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
    2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
    2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
    2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
    2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
    2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
    2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
    2008-10-15 11:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-03 12:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-09-30 13:09:51 ----A---- C:\WINDOWS\cdplayer.ini
    2008-09-28 17:45:48 ----D---- C:\WINDOWS\Debug
    2008-09-25 14:51:10 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
    2008-09-20 19:18:08 ----A---- C:\WINDOWS\avisplitter.INI
    2008-09-17 19:33:58 ----D---- C:\Program Files\xerox
    2008-09-10 17:06:14 ----A---- C:\WINDOWS\webica.ini
    2008-09-04 12:15:04 ----A---- C:\WINDOWS\system32\msxml3.dll
    2008-09-03 06:37:46 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\DNA
    2008-09-01 12:32:58 ----D---- C:\Program Files\DNA

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
    R1 tmtdi;Trend Micro TDI Driver; C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2007-12-16 65936]
    R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
    R2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM; \??\C:\Program Files\VMLaunch\BuddyVM.sys []
    R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
    R2 tmevtmgr;tmevtmgr; \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys []
    R2 tmpreflt;tmpreflt; C:\WINDOWS\system32\DRIVERS\tmpreflt.sys [2007-12-16 35856]
    R2 tmxpflt;tmxpflt; C:\WINDOWS\system32\DRIVERS\tmxpflt.sys [2007-12-16 202768]
    R2 vsapint;vsapint; C:\WINDOWS\system32\DRIVERS\vsapint.sys [2007-12-16 1126072]
    R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-06-30 1094848]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-20 2317696]
    R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-06-07 1235968]
    R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
    R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
    R3 SSKBFD;Webroot Spy Sweeper Keylogger Shield Keyboard Filter; C:\WINDOWS\System32\Drivers\sskbfd.sys [2007-01-25 21056]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S1 lusbaudio;Logitech USB Microphone; C:\WINDOWS\system32\drivers\OVSound2.sys [2001-08-17 25216]
    S2 npkcrypt;npkcrypt; \??\C:\Nexon\Mabinogi\npkcrypt.sys []
    S2 tmactmon;tmactmon; \??\C:\WINDOWS\system32\drivers\tmactmon.sys []
    S3 agb5o35y;agb5o35y; C:\WINDOWS\system32\drivers\agb5o35y.sys []
    S3 BLKWGU(Belkin);Belkin Wireless G USB Network Adapter(Belkin); C:\WINDOWS\system32\DRIVERS\BLKWGU.sys [2005-11-10 402944]
    S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 Jukebox3;Jukebox3; C:\WINDOWS\system32\DRIVERS\ctpdusb.sys [2004-09-30 16880]
    S3 mqdmbus;Motorola DM Composite Driver (WDM); C:\WINDOWS\system32\DRIVERS\mqdmbus.sys []
    S3 mqdmmdfl;Motorola USB Modem (Filter); C:\WINDOWS\system32\DRIVERS\mqdmmdfl.sys []
    S3 mqdmmdm;Motorola USB Modem; C:\WINDOWS\system32\DRIVERS\mqdmmdm.sys []
    S3 mqdmserd;Motorola USB Diag; C:\WINDOWS\system32\DRIVERS\mqdmserd.sys []
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
    S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
    S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
    S3 QCEmerald;Logitech QuickCam Web; C:\WINDOWS\system32\DRIVERS\OVCE.sys [2001-08-17 31872]
    S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
    S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
    S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
    S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2007-10-31 30464]
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
    S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys []
    S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
    S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\WINDOWS\system32\DRIVERS\xusb21.sys [2007-02-17 52352]
    S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys [2004-10-25 17664]
    S4 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2006-10-23 46640]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-10-31 110592]
    R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-06-07 376832]
    R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
    R2 npkcmsvc;npkcmsvc; C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
    R2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2007-12-16 693512]
    R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
    R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
    R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
    R3 tmproxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2007-12-16 648456]
    S2 gupdate1c8c039b2d11f5c;Google Update Service (gupdate1c8c039b2d11f5c); C:\Program Files\Google\Update\GoogleUpdate.exe [2008-09-01 133104]
    S2 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2007-12-16 333064]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
    S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2007-12-11 504104]
    S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]

    -----------------EOF-----------------
     
  7. 2008/11/30
    MrSelfDestruct

    MrSelfDestruct Inactive Thread Starter

    Joined:
    2008/11/30
    Messages:
    8
    Likes Received:
    0
    info.txt logfile of random's system information tool 1.04 2008-11-30 20:11:09

    ======Uninstall list======

    -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    -->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    -->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
    -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
    -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
    -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9 /remove
    -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    7-Zip 4.57--> "C:\Program Files\7-Zip\Uninstall.exe "
    Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
    Agere Systems PCI Soft Modem-->agrsmdel
    AIM 6-->C:\Program Files\AIM6\uninst.exe
    Any Video Converter 2.6.2--> "C:\Program Files\Any Video Converter\unins000.exe "
    AOL Coach Version 2.0(Build:20041026.5 en)-->C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP
    AOL Deskbar--> "C:\Program Files\AOL Deskbar\UNWISE.EXE" /u "C:\Program Files\AOL Deskbar\INSTALL.LOG "
    AOL Uninstaller (Choose which Products to Remove)-->C:\Program Files\Common Files\AOL\uninstaller.exe
    AOL You've Got Pictures Screensaver-->C:\Program Files\Common Files\AOL\Screensaver\uninst_ygpss.exe
    Apple Mobile Device Support-->MsiExec.exe /I{B5C209B1-8DDB-4642-A573-375B951514CB}
    Apple Software Update-->MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
    ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
    ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    Audio Edit-->C:\WINDOWS\st6unst.exe -n "C:\Program Files\Audio Edit\ST6UNST.LOG"
    AviSynth 2.5--> "C:\Program Files\AviSynth 2.5\Uninstall.exe "
    AXIS Media Control Embedded-->rundll32 "C:\Program Files\Axis Communications\AXIS Media Control Embedded\AxisMediaControlEmb.dll ",UninstallMe
    Belkin Wireless USB Utility-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A6359CCF-215D-43D9-8366-479D231F2A72}
    BitLord 1.1-->C:\Program Files\BitLord\uninst.exe
    Blaze Media Pro--> "C:\Documents and Settings\All Users\Application Data\{137E54F6-3421-4EAC-89EB-A08622409B6F}\setup_blazemp.exe" REMOVE=TRUE MODIFY=FALSE
    CHAOS;HEAD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C0AEC1BB-5731-439A-96B1-66ABD2B24F62}\setup.exe" -l0x11 -removeonly
    Citrix ICA Web Client-->C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
    Compaq Connections (remove only)-->C:\WINDOWS\HPCPCUninstall-5577497\HPBWSetup.exe -appid 5577497 -uninstall
    Compaq Organize-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}\Setup.exe" UNINSTALL
    Cosmo Player 2.1.1 (41451)-->C:\WINDOWS\IsUninst.exe -f "C:\Program Files\CosmoSoftware\CosmoPlayer\CosmoPlayer211.isu "
    Creative Jukebox Driver-->C:\Program Files\Creative\Jukebox 3 Drivers\DrvUnins.exe /s
    Creative Removable Disk Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 /remove
    Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
    Creative Zen Micro-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D944236D-7992-41D6-8257-930B5832F1CC}\SETUP.EXE" -l0x9 /remove
    DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
    Delete Virtual-Mate Launcher--> "C:\Program Files\VMLaunch\unins000.exe "
    DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
    DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
    DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
    DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    Easy Internet Sign-up-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033
    Elecard MPEG-2 Decoder&Streaming Plug-in for WMP--> "C:\Program Files\Elecard\Elecard MPEG-2 Decoder&Streaming Plug-in for WMP\Uninstall.exe" "C:\Program Files\Elecard\Elecard MPEG-2 Decoder&Streaming Plug-in for WMP\install.log" -u
    Fate/stay night English v3.1-->C:\Program Files\Fate-stay night English\uninstall.exe
    Firebird SQL Server - MAGIX Edition-->C:\Program Files\MAGIX\Common\Database\unwise.exe
    FreeRIP v3.091--> "C:\Program Files\FreeRIP3\unins000.exe "
    GoldWave v5.22--> "C:\Program Files\GoldWaves\unstall.exe" "GoldWave v5.22" "C:\Program Files\GoldWaves\unstall.log "
    Google Gears-->MsiExec.exe /I{2A9C3F41-DACA-37AB-84FB-2E6193C42151}
    Google Update-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    Hexecute RC7-->C:\WINDOWS\system32\msinfhlp.exe ;uninstall; ;C:\Program Files\Hexecute\Hexecute RC7.dat;
    High Definition Audio Driver Package - KB888111--> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe "
    HijackThis 2.0.2--> "C:\Program Files\trend micro\HijackThis.exe" /uninstall
    Hotfix for Windows Media Format 11 SDK (KB929399)--> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe "
    Hotfix for Windows Media Player 11 (KB939683)--> "C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe "
    Hotfix for Windows XP (KB952287)--> "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe "
    HP Boot Optimizer-->MsiExec.exe /I{3BA95526-6AE0-4B87-A62D-17187EF565FC}
    HP Image Zone Express-->MsiExec.exe /X{FE64AE29-0883-4C70-8388-DC026019C900}
    HP Software Update-->MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
    InterVideo WinDVD Player--> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
    iTunes-->MsiExec.exe /I{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}
    J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
    Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Kagetsu Tohya English v0.5--> "C:\Program Files\Kagetsu Tohya English v0.5\uninstall.exe "
    K-Lite Codec Pack 3.8.5 Full--> "C:\Program Files\K-Lite Codec Pack\unins000.exe "
    LimeWire PRO 4.14.8--> "C:\Program Files\LimeWirePro2\uninstall.exe "
    Magic DVD Ripper V5.3 build 5--> "C:\Program Files\MagicDVDRipper\unins000.exe "
    Microsoft .NET Framework 1.1 Hotfix (KB928366)--> "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp "
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
    Microsoft AppLocale-->MsiExec.exe /I{394BE3D9-7F57-4638-A8D1-1D88671913B7}
    Microsoft Compression Client Pack 1.0 for Windows XP--> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe "
    Microsoft Internationalized Domain Names Mitigation APIs--> "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe "
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.1--> "C:\WINDOWS\$NtUninstallWdf01001$\spuninst\spuninst.exe "
    Microsoft National Language Support Downlevel APIs--> "C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe "
    Microsoft Plus! Dancer LE-->MsiExec.exe /X{1A103D70-5C9B-4E1A-B306-5106C68F9914}
    Microsoft Plus! Photo Story 2 LE-->MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
    Microsoft Text-to-Speech Engine 4.0 (English)-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msTTSf22.inf, Uninstall
    Microsoft User-Mode Driver Framework Feature Pack 1.0--> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe "
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Windows Application Compatibility Database-->C:\WINDOWS\system32\sdbinst.exe -u "C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb "
    Microsoft Word 2002-->MsiExec.exe /I{901B0409-6000-11D3-8CFE-0050048383C9}
    Microsoft Works Suite 2006 Setup Launcher-->C:\Program Files\Microsoft Works Suite 2006\Setup\Launcher.exe /ARP E:\
    Microsoft Works Suite Add-in for Microsoft Word-->MsiExec.exe /I{17E3A651-12B9-4149-BAE8-E6FB9A5ADC4F}
    Motorola Driver Installation-->MsiExec.exe /I{8F4507EF-C5F3-46CE-9718-9D3698821333}
    Mozilla Firefox (2.0.0.18)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    MSXML 6 Service Pack 2 (KB954459)-->MsiExec.exe /I{1A528690-6A2D-4BC5-B143-8C4AE8D19D96}
    Office 2003 Tour-->MsiExec.exe /I{BE9FEFBA-F2F8-468B-A108-4356F73A3E9C}
    PC-Doctor 5 for Windows-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{AB61A692-5543-4C48-979B-8CEA1C52FE9C} /l1033
    PMP DV-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF68A865-76E3-4F34-ADD3-B38EFA5E6E62}\Setup.exe"
    Python 2.2 pywin32 extensions (build 203)--> "C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log "
    Quicken 2005-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2DBE41DD-2129-4C65-A3D3-5647236A60F3} anything
    QuickTime-->MsiExec.exe /I{E0D51394-1D45-460A-B62D-383BC4F8B335}
    RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    Remove WeatherBug Installer-->c:\hp\bin\cloaker.exe c:\hp\bin\commands.exe /c c:\hp\bin\wbug\clean.bat
    Rhapsody Player Engine-->MsiExec.exe /I{84F1DE76-C48C-4281-87A0-CC9548D1E7F9}
    Security Update for Step By Step Interactive Training (KB923723)--> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe "
    Security Update for Windows Internet Explorer 7 (KB956390)--> "C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe "
    Security Update for Windows Media Player 10 (KB911565)--> "C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 10 (KB917734)--> "C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 11 (KB936782)--> "C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 11 (KB954154)--> "C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB938464)--> "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB941569)--> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB946648)--> "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950759)--> "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950760)--> "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950762)--> "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950974)--> "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951066)--> "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951376)--> "C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951376-v2)--> "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951698)--> "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951748)--> "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB952954)--> "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB953838)--> "C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB953839)--> "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB954211)--> "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB955069)--> "C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956390)--> "C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956391)--> "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956803)--> "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956841)--> "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB957095)--> "C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB957097)--> "C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB958644)--> "C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe "
    SMPlayer 0.5.62--> "C:\Program Files\SMPlayer\unins000.exe "
    Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
    Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
    Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
    Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
    Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
    Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
    Spybot - Search & Destroy--> "C:\Program Files\Spybot - Search & Destroy\unins000.exe "
    Trend Micro AntiVirus-->C:\Program Files\Trend Micro\Internet Security\remove.exe
    Trend Micro AntiVirus-->MsiExec.exe /X{A621B45A-D138-4A95-BE10-7CABA05EF94E}
    True Love-->C:\Hentai\Truelove\SXUNINST.EXE
    Update for Windows XP (KB951072-v2)--> "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe "
    Update for Windows XP (KB951978)--> "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe "
    Update for Windows XP (KB953356)--> "C:\WINDOWS\$NtUninstallKB953356$\spuninst\spuninst.exe "
    VeohTV BETA-->C:\Program Files\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409
    VideoLAN VLC media player 0.8.5-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
    VobSub v2.23 (Remove Only)--> "C:\Program Files\Gabest\VobSub\uninstall.exe "
    Windows Imaging Component--> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe "
    Windows Internet Explorer 7--> "C:\WINDOWS\ie7\spuninst\spuninst.exe "
    Windows Media Connect--> "C:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe "
    Windows Media Format 11 runtime--> "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Format 11 runtime--> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe "
    Windows Media Player 11--> "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows Media Player 11--> "C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe "
    Windows XP Service Pack 3--> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe "
    WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
    Xvid 1.1.3 final uninstall--> "C:\Program Files\Xvid\unins000.exe "
    XviD MPEG4 Video Codec (remove only)--> "C:\WINDOWS\system32\xvid-uninstall.exe "

    ======Hosts File======

    127.0.0.1 localhost
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com

    ======Security center information======

    AV: Norton Internet Security (outdated)
    AV: Trend Micro AntiVirus (outdated)
    FW: Norton Internet Security

    ======Environment variables======

    "ComSpec "=%SystemRoot%\system32\cmd.exe
    "Path "=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\QuickTime\QTSystem\
    "windir "=%SystemRoot%
    "FP_NO_HOST_CHECK "=NO
    "OS "=Windows_NT
    "PROCESSOR_ARCHITECTURE "=x86
    "PROCESSOR_LEVEL "=15
    "PROCESSOR_IDENTIFIER "=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
    "PROCESSOR_REVISION "=2f02
    "NUMBER_OF_PROCESSORS "=1
    "PATHEXT "=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP "=%SystemRoot%\TEMP
    "TMP "=%SystemRoot%\TEMP
    "SonicCentral "=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
    "CLASSPATH "=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
    "QTJAVA "=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip

    -----------------EOF-----------------
     
  8. 2008/11/30
    MrSelfDestruct

    MrSelfDestruct Inactive Thread Starter

    Joined:
    2008/11/30
    Messages:
    8
    Likes Received:
    0
    [Edit]

    My posts show up now, please look over them and tell me if you find the cause of the problems. Thank you.
     
    Last edited: 2008/11/30
  9. 2008/12/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    FYI
    This is not the area of my expertise and one of our malware experts will look at your logs as soon as possible - they are dealt with in the order in which they are received.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.