1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive [InActive] TotalSecure 2009...It's KILLING me...

Discussion in 'Malware and Virus Removal Archive' started by zachcharge, 2008/10/25.

  1. 2008/10/25
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    Bonjour all,


    I feel a little bit like a scab for making my first post on BBS a crying plead for help but...well I am being murdered here and I've heard this is one of the best websites for specific malware removal help. Anyway for my problem...and story. Gather around children.


    On the 23/10/08 at night my PC, a 2 year old Compaq Pressario (spelling?) with a 2.2ghz CPU, 1.5gb ram, 60 or so GB hardrive, Windows XP SP3 (from memory, can't tell specific specs at the moment), was infected with the annoying Antispyware 2009 (or something with a similar name). This was my first infection since I restored my PC to factory settings 3 months ago (and even so, was only the second spyware infection my PC ever had). It was too late so I left it for morning. On the Friday I was able to easily remove the bugger using Vundofix, malwarebyte and a program that was made to specifically remove it, all before school (I'm 16). I was all happy that my pc no longer had an annoying red X in the toolbar...


    However, exactly 48 minutes ago to writing the numbers 48 in this post, my PC was hijacked (I think that's the proper term) by Total Secure 2009...


    I was on wikipedia (looking up movie I missed first 5 minutes of so I can catch up) until suddenly Total Secure popped up, my time in the task bar was replaced with the text VIRUS ALERT, at least 6 new icons appeared in the icon task bar, around 10 pop ups appeared and a loud screeching "warning beep" noise plagued my PC. I quickly closed everything and DC my pc from the internet (some icons advertising...disturbing...err, dirty sites, started popping up on my desktop). I tried scanning with malwarebyte and AVG anti-virus but AVG crashed "unexpectedly" (yeah right...) and malwarebyte was going to slow due to all CPU being used up. All this in about 10 minutes. I disabled my internet connection in about 2 minutes after first realizing the infection.


    I rebooted into safe mode with the intentions of going into my system32 folder and deleting anything created at the exact time of the attack and after. After a long lag struggle (in safe mode the VIRUS ALERT next to the time was still there), I was able to get rid of some of the files (and from reading off a couple of slightly unhelpful "guide to remove total secure 2009" was able to make sure I deleted the right files).


    However this was only the start of m troubles. Windows explorer stopped responding, so I had to reboot (I couldn't use task manager's run as that was disabled by "my administrator" (again yeah right, I AM the administrator). I went back into safe mode. Now...I am literally stuck. I tried opening Vundofix,
    explorer stops responding. I try opening start menu. My computer button and programs is gone. I downloaded SpyNoMore (one of the removal guides told me so), put on usb, put in infected PC and explorer stops working. I put in CD, open My Computer, crashes straight away.

    In short...I can't do nothing. I can't put any programs to try fix the problem. I can't use anything already on my PC to fix the problem...I can't open task manager...I can't get the program to fix task manager...I CAN'T DO ANYTHING!!! ...I can't even put RSIT to get a log for you...


    Please...help me. My PC pretty much got destroyed in under 10 minutes. I can't get a log for my PC, run anything, do anything...


    Oh, here are a few things I have noticed;
    -The total secure 2009 seems to look different than the picture shown on the guides telling us how to get rid of them...maybe a beefed up version of the hell program?
    -I must've gotten infected from the first spyware I had 2 days ago. I did barely anything, got AVG, Malwarebyte, firewall etc and still got infected.
    -It took about 1 and a half minutes for ts09 to download processes that are numbered in task manager (when it was working) 1-9, and there were icons in system32 numbered 1-9 (if I remembered correctly, can't double check now).
    -The fake popups included the usual fake virus alert messages that most spyware make and windows that look like the windows security monitor thingy...except it bombarded my computer quickly.

    Anyway...please help. I had a lot of homework on my PC. I have no idea what to do, the thing has blocked off everything. Please help...thanks. Sorry for the long non-log post.

    -ZachCharge
     
  2. 2008/10/25
    hrlow2

    hrlow2 Banned

    Joined:
    2008/10/09
    Messages:
    48
    Likes Received:
    0
    hello ZachCharge. I am assuming you are using a different machine to do this post. If you can boot your Compaq into Safe Mode, run your antivirus and antispyware programs from there. Also check your Add/Remove section. Good Luck.
     

  3. to hide this advert.

  4. 2008/10/25
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    Everything stopped...starting when I was in safemode.
     
  5. 2008/10/25
    hrlow2

    hrlow2 Banned

    Joined:
    2008/10/09
    Messages:
    48
    Likes Received:
    0
    hello again. Have you tried to run Ultimate Boot CD on your machine? Couldn't hurt to try.
     
  6. 2008/10/25
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    Don't think I need to now.

    Update...my autistic brother turned on the pc and...it worked mostly. The start menu was disabled and yadda yadda yadda but programs could open. I ran Smitfruadfix (then regained all computer function) and then Malwarebyte, which removed a hell of a lot of rouge programs that downloaded itself with TotalSecure 2009.

    Only problem now is, after 3 mintues of celebrating the all programs disappeared again (and was fixed with smitfraud again). So...should I post logso we can get rid of any unwanted bits?
     
  7. 2008/10/25
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Read this and post the logs requested.

    hrlow2 - posting suggestions/solutions in this forum is strongly discouraged - this is the domain of our trained analysts who will deal with this thread when it comes to the top of the list
     
  8. 2008/10/25
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    Done and done heres the log;

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Compaq_Owner at 2008-10-26 08:59:59
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 138 GB (75%) free of 185 GB
    Total RAM: 1534 MB (61% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 09:00:20, on 26/10/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\NCLAUNCH.EXe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\Program Files\AVG\AVG8\avgscanx.exe
    C:\Program Files\AVG\AVG8\avgui.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Compaq_Owner\Desktop\RSIT.exe
    C:\Program Files\trend micro\Compaq_Owner.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
    O3 - Toolbar: (no name) - {5CCA7D45-B04C-4014-8AD2-EF6788741F44} - (no file)
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [RECGUARD] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{94242226-C7CC-4BE2-BCF6-2E60E24FC82A}: NameServer = 10.1.1.1,10.1.1.2
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O21 - SSODL: qnflkotm - {E9892065-F2A2-4BC6-ACB9-350C873A990C} - \qnflkotm.dll (file missing)
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 5485 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\Symantec NetDetect.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {5CCA7D45-B04C-4014-8AD2-EF6788741F44}

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSPY2002 "=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-04 59392]
    "NvCplDaemon "=C:\WINDOWS\system32\NvCpl.dll [2005-08-03 7110656]
    "RECGUARD "=C:\WINDOWS\SMINST\RECGUARD.EXE [2005-07-22 237568]
    "AVG8_TRAY "=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-09-30 1234712]
    "PHIME2002A "=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
    "PHIME2002ASync "=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-04 455168]
    "hpsysdrv "=c:\windows\system\hpsysdrv.exe [1998-05-08 52736]
    "TkBellExe "=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-08-17 185896]
    "AdobeCS4ServiceManager "=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite "=C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
    "ctfmon.exe "=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
    "NCLaunch "=C:\WINDOWS\NCLAUNCH.EXe [2008-10-06 40960]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
    C:\WINDOWS\ALCXMNTR.EXE [2004-09-08 57344]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe [2005-02-17 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
    C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-04 208952]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
    C:\HP\KBD\KBD.EXE [2005-02-02 61440]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
    nwiz.exe /installquiet /keeploaded /nodetect []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
    C:\Program Files\PowerISO\PWRISOVM.EXE [2007-08-07 200704]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
    C:\Windows\Creator\Remind_XP.exe [2004-12-14 663552]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-08-17 185896]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
    C:\PROGRA~1\PALTAL~1\paltalk.exe [2008-08-30 11704832]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
    C:\PROGRA~1\OPENOF~1.4\program\QUICKS~1.EXE [2008-01-21 393216]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    qnflkotm - {E9892065-F2A2-4BC6-ACB9-350C873A990C} - \qnflkotm.dll []

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmhct.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSmhct.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSserv.sys]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun "=145
    "NoRun "=0
    "NoFind "=0
    "NoLogOff "=0
    "DisallowRun "=0

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "C:\Program Files\AVG\AVG8\avgemc.exe "= "C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe "
    "C:\Program Files\AVG\AVG8\avgupd.exe "= "C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe "
    "C:\Program Files\Age of Empires 2\age2_x1.exe "= "C:\Program Files\Age of Empires 2\age2_x1.exe:*:Enabled:Age of Empires II Expansion "
    "C:\Program Files\uTorrent\uTorrent.exe "= "C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent "
    "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE "= "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Paltalk Messenger\paltalk.exe "= "C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:paltalkScene "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "
    "Game.exe "= "Game.exe:*:Enabled:GostSoul "
    "C:\Program Files\Netgame\Ghost\Game.exe "= "C:\Program Files\Netgame\Ghost\Game.exe:*:Enabled:Game "
    "C:\Program Files\GameFlier\GhostOnline\game.exe "= "C:\Program Files\GameFlier\GhostOnline\game.exe:*:Enabled:game "
    "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_A3N4\tiupgrade.exe "= "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_A3N4\tiupgrade.exe:*:Enabled:tiupgrade "
    "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_WXHV\tiupgrade.exe "= "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_WXHV\tiupgrade.exe:*:Enabled:tiupgrade "
    "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_YFXB\tiupgrade.exe "= "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ckz_YFXB\tiupgrade.exe:*:Enabled:tiupgrade "
    "C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe "= "C:\Program Files\Microsoft Games\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion "
    "C:\WINDOWS\system32\drivers\svchost.exe "= "C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost "
    "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe "= "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe "= "%windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 "
    "%windir%\Network Diagnostic\xpnetdiag.exe "= "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 "
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe "= "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger "
    "C:\Program Files\Windows Live\Messenger\livecall.exe "= "C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) "

    ======List of files/folders created in the last 3 months======

    2008-10-26 09:00:00 ----D---- C:\Program Files\trend micro
    2008-10-26 08:59:59 ----D---- C:\rsit
    2008-10-26 08:22:44 ----A---- C:\WINDOWS\ntbtlog.txt
    2008-10-26 08:18:54 ----A---- C:\WINDOWS\system32\tmp.txt
    2008-10-26 08:18:42 ----A---- C:\WINDOWS\system32\o4Patch.exe
    2008-10-26 08:18:42 ----A---- C:\WINDOWS\system32\IEDFix.C.exe
    2008-10-25 22:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-10-25 22:03:13 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\0000005738
    2008-10-25 22:01:06 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\TmpRecentIcons
    2008-10-25 22:00:56 ----A---- C:\vwnskbot.dll
    2008-10-25 22:00:30 ----D---- C:\Program Files\Common Files\Adobe AIR
    2008-10-25 21:56:31 ----D---- C:\Program Files\Common Files\Macrovision Shared
    2008-10-23 23:13:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-10-23 23:12:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-23 23:12:54 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-10-23 23:12:50 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-10-23 23:12:45 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-10-23 23:11:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
    2008-10-23 16:26:39 ----A---- C:\rapport.txt
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\WS2Fix.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\VCCLSID.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\VACFix.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\swxcacls.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\swsc.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\swreg.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\SrchSTS.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\Process.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\IEDFix.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\dumphive.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\AntiXPVSTFix.exe
    2008-10-23 16:25:34 ----A---- C:\WINDOWS\system32\404Fix.exe
    2008-10-22 22:42:39 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
    2008-10-22 22:42:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-22 22:42:34 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-22 17:45:57 ----D---- C:\Program Files\Peggle Nights
    2008-10-21 21:24:57 ----D---- C:\Program Files\Babya
    2008-10-20 20:06:09 ----D---- C:\.jagex_cache_32
    2008-10-13 21:25:24 ----D---- C:\Program Files\Scracc
    2008-10-13 19:57:21 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
    2008-10-13 19:57:21 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
    2008-10-13 19:57:21 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
    2008-10-13 19:57:20 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
    2008-10-13 19:57:20 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
    2008-10-13 19:57:19 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
    2008-10-13 19:57:18 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
    2008-10-13 19:57:18 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
    2008-10-13 19:57:18 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
    2008-10-13 19:57:17 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
    2008-10-13 19:57:17 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
    2008-10-13 19:57:17 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
    2008-10-13 19:57:16 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
    2008-10-13 19:57:15 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
    2008-10-13 19:57:14 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
    2008-10-13 19:57:14 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
    2008-10-13 19:57:13 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
    2008-10-13 19:57:13 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
    2008-10-13 19:57:13 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
    2008-10-13 19:57:12 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
    2008-10-13 19:57:11 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
    2008-10-13 19:57:10 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
    2008-10-13 19:57:10 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
    2008-10-13 19:57:09 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
    2008-10-13 19:57:08 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
    2008-10-13 19:57:08 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
    2008-10-13 19:57:07 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
    2008-10-13 19:57:07 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
    2008-10-13 19:57:07 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
    2008-10-13 19:57:06 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
    2008-10-13 19:57:06 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
    2008-10-13 19:57:05 ----A---- C:\WINDOWS\system32\xinput1_3.dll
    2008-10-13 19:57:05 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
    2008-10-13 19:57:03 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
    2008-10-13 19:57:02 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
    2008-10-13 19:57:02 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
    2008-10-13 19:56:59 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
    2008-10-13 19:56:58 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
    2008-10-13 19:56:58 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
    2008-10-13 19:56:57 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
    2008-10-13 19:56:56 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
    2008-10-13 19:56:56 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
    2008-10-13 19:56:56 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
    2008-10-13 19:56:55 ----A---- C:\WINDOWS\system32\xinput1_2.dll
    2008-10-13 19:56:55 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
    2008-10-13 19:56:54 ----A---- C:\WINDOWS\system32\xinput1_1.dll
    2008-10-13 19:56:54 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
    2008-10-13 19:56:54 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
    2008-10-13 19:56:49 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
    2008-10-13 19:56:48 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
    2008-10-13 19:56:48 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
    2008-10-13 19:56:47 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
    2008-10-13 19:56:47 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
    2008-10-13 19:56:46 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
    2008-10-13 19:56:46 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
    2008-10-13 19:56:45 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
    2008-10-13 19:56:45 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
    2008-10-13 19:56:43 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
    2008-10-13 19:32:44 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-10-13 19:32:38 ----D---- C:\WINDOWS\Logs
    2008-10-13 19:30:40 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2008-10-13 13:40:53 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Home Sweet Home 2
    2008-10-13 13:36:00 ----D---- C:\Program Files\Home Sweet Home 2 Kitchens And Baths
    2008-10-06 19:34:43 ----D---- C:\Program Files\Common Files\SWF Studio
    2008-10-06 19:34:40 ----A---- C:\WINDOWS\NCUNINST.EXe
    2008-10-06 19:34:40 ----A---- C:\WINDOWS\NCLAUNCH.EXe
    2008-10-04 14:58:39 ----A---- C:\WINDOWS\system32\d3dx9.dll
    2008-10-04 14:58:39 ----A---- C:\WINDOWS\system32\D3DX81ab.dll
    2008-10-04 14:58:38 ----D---- C:\Program Files\Cheat Engine
    2008-10-03 22:16:56 ----D---- C:\Program Files\Fashionista
    2008-10-03 21:32:04 ----D---- C:\Program Files\Cake Mania 3
    2008-10-03 11:18:38 ----D---- C:\Program Files\AC Tool
    2008-10-02 01:11:48 ----D---- C:\Program Files\Timed Shutdown
    2008-10-01 14:31:30 ----D---- C:\Program Files\Cooking Dash
    2008-09-28 19:26:38 ----D---- C:\Program Files\GameFlier
    2008-09-26 14:40:06 ----D---- C:\Netgame
    2008-09-26 14:36:19 ----D---- C:\Program Files\Netgame
    2008-09-26 12:41:06 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\InstallShield
    2008-09-25 08:18:05 ----D---- C:\Program Files\Maxis
    2008-09-24 21:01:34 ----D---- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
    2008-09-24 21:01:14 ----D---- C:\Program Files\GameHouse
    2008-09-23 11:15:34 ----D---- C:\Program Files\MSXML 4.0
    2008-09-21 20:57:10 ----D---- C:\Program Files\Microsoft Games
    2008-09-21 12:24:30 ----D---- C:\Program Files\Paint.NET
    2008-09-20 16:57:49 ----D---- C:\Program Files\Enterbrain
    2008-09-20 16:57:26 ----D---- C:\Program Files\Common Files\Enterbrain
    2008-09-20 13:13:47 ----D---- C:\Program Files\Cinema Tycoon 2 Movie Mania
    2008-09-18 19:26:38 ----D---- C:\Program Files\Atari
    2008-09-16 19:53:04 ----D---- C:\Program Files\Magic Seeds
    2008-09-16 19:53:02 ----D---- C:\Program Files\PowerISO
    2008-09-16 19:41:04 ----SHD---- C:\Config.Msi
    2008-09-15 11:38:57 ----D---- C:\Program Files\AskBarDis
    2008-09-14 17:00:16 ----D---- C:\Program Files\Cat Daddy Games
    2008-09-14 01:06:59 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
    2008-09-14 01:06:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
    2008-09-14 01:04:54 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
    2008-09-13 12:25:17 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Magic Seeds
    2008-09-12 22:12:20 ----D---- C:\WINDOWS\Prefetch
    2008-09-12 22:06:36 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
    2008-09-12 22:06:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
    2008-09-12 22:06:28 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
    2008-09-12 22:06:23 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
    2008-09-12 22:06:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
    2008-09-12 22:06:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
    2008-09-12 22:06:10 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
    2008-09-12 22:06:06 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
    2008-09-12 22:06:01 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
    2008-09-12 22:03:17 ----D---- C:\Program Files\Messenger
    2008-09-12 22:03:03 ----D---- C:\WINDOWS\system32\scripting
    2008-09-12 22:03:03 ----D---- C:\WINDOWS\system32\en-us
    2008-09-12 22:03:02 ----D---- C:\WINDOWS\l2schemas
    2008-09-12 22:03:02 ----D---- C:\Program Files\msn
    2008-09-12 22:03:01 ----D---- C:\WINDOWS\system32\en
    2008-09-12 22:03:01 ----D---- C:\WINDOWS\system32\bits
    2008-09-12 22:00:41 ----D---- C:\WINDOWS\ServicePackFiles
    2008-09-12 21:58:25 ----D---- C:\WINDOWS\network diagnostic
    2008-09-12 21:56:02 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
    2008-09-12 21:56:01 ----D---- C:\WINDOWS\EHome
    2008-09-12 17:25:36 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Oberon Games
    2008-09-12 17:25:36 ----D---- C:\Documents and Settings\All Users\Application Data\Oberon Games
    2008-09-12 17:24:42 ----D---- C:\Program Files\Turbo Fiesta
    2008-09-09 18:31:13 ----D---- C:\Program Files\The Great Chocolate Chase
    2008-09-09 16:41:54 ----D---- C:\Program Files\Diner Dash Seasonal Snack Pack
    2008-09-08 21:53:06 ----D---- C:\Program Files\Panda Craze
    2008-09-08 21:30:55 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\SulusGames
    2008-09-08 21:20:40 ----D---- C:\Program Files\Cinema Tycoon Gold
    2008-09-07 10:09:38 ----D---- C:\Documents and Settings\All Users\Application Data\Sandlot Games
    2008-09-07 10:08:54 ----D---- C:\Program Files\Westward II Heroes Of The Frontier
    2008-09-06 14:42:01 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Paltalk
    2008-09-06 14:41:57 ----D---- C:\WINDOWS\PaltalkScene
    2008-09-06 14:41:57 ----D---- C:\Program Files\Paltalk Messenger
    2008-09-03 20:58:37 ----D---- C:\Program Files\PopCap Games
    2008-08-30 05:39:37 ----A---- C:\WINDOWS\system32\msxml3a.dll
    2008-08-27 20:28:43 ----D---- C:\Program Files\Sim File Maid 2
    2008-08-27 19:55:34 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
    2008-08-27 18:55:39 ----D---- C:\Program Files\EA GAMES
    2008-08-26 19:01:40 ----N---- C:\WINDOWS\system32\xmllite.dll
    2008-08-26 19:01:38 ----N---- C:\WINDOWS\system32\wmphoto.dll
    2008-08-26 19:01:37 ----N---- C:\WINDOWS\system32\wlanapi.dll
    2008-08-26 19:01:37 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
    2008-08-26 19:01:37 ----N---- C:\WINDOWS\system32\windowscodecs.dll
    2008-08-26 19:01:35 ----N---- C:\WINDOWS\system32\verclsid.exe
    2008-08-26 19:01:33 ----N---- C:\WINDOWS\system32\tspkg.dll
    2008-08-26 19:01:33 ----N---- C:\WINDOWS\system32\tsgqec.dll
    2008-08-26 19:01:30 ----N---- C:\WINDOWS\system32\spupdwxp.exe
    2008-08-26 19:01:30 ----A---- C:\WINDOWS\system32\spdwnwxp.exe
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\system32\slserv.exe
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\system32\slrundll.exe
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\system32\slgen.dll
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\system32\slextspk.dll
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\system32\slcoinst.dll
    2008-08-26 19:01:29 ----N---- C:\WINDOWS\slrundll.exe
    2008-08-26 19:01:28 ----N---- C:\WINDOWS\system32\setupn.exe
    2008-08-26 19:01:27 ----N---- C:\WINDOWS\system32\s3gnb.dll
    2008-08-26 19:01:27 ----N---- C:\WINDOWS\system32\rhttpaa.dll
    2008-08-26 19:01:26 ----N---- C:\WINDOWS\system32\rasqec.dll
    2008-08-26 19:01:26 ----N---- C:\WINDOWS\system32\qutil.dll
    2008-08-26 19:01:26 ----N---- C:\WINDOWS\system32\qcliprov.dll
    2008-08-26 19:01:25 ----N---- C:\WINDOWS\system32\qagentrt.dll
    2008-08-26 19:01:25 ----N---- C:\WINDOWS\system32\qagent.dll
    2008-08-26 19:01:25 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
    2008-08-26 19:01:24 ----N---- C:\WINDOWS\system32\onex.dll
    2008-08-26 19:01:21 ----N---- C:\WINDOWS\system32\napstat.exe
    2008-08-26 19:01:21 ----N---- C:\WINDOWS\system32\napmontr.dll
    2008-08-26 19:01:21 ----N---- C:\WINDOWS\system32\napipsec.dll
    2008-08-26 19:01:20 ----N---- C:\WINDOWS\system32\mtxparhd.dll
    2008-08-26 19:01:20 ----N---- C:\WINDOWS\system32\msxml6r.dll
    2008-08-26 19:01:20 ----N---- C:\WINDOWS\system32\msxml6.dll
    2008-08-26 19:01:20 ----N---- C:\WINDOWS\system32\msshavmsg.dll
    2008-08-26 19:01:20 ----N---- C:\WINDOWS\system32\mssha.dll
    2008-08-26 19:01:16 ----N---- C:\WINDOWS\system32\mmcperf.exe
    2008-08-26 19:01:16 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
    2008-08-26 19:01:16 ----N---- C:\WINDOWS\system32\mmcex.dll
    2008-08-26 19:01:16 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
    2008-08-26 19:01:15 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
    2008-08-26 19:01:12 ----N---- C:\WINDOWS\system32\l2gpstore.dll
    2008-08-26 19:01:04 ----N---- C:\WINDOWS\system32\kmsvc.dll
    2008-08-26 19:01:04 ----N---- C:\WINDOWS\system32\kbdpash.dll
    2008-08-26 19:01:04 ----N---- C:\WINDOWS\system32\kbdnepr.dll
    2008-08-26 19:01:04 ----N---- C:\WINDOWS\system32\kbdiultn.dll
    2008-08-26 19:01:04 ----N---- C:\WINDOWS\system32\kbdbhc.dll
    2008-08-26 19:00:37 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
    2008-08-26 19:00:30 ----N---- C:\WINDOWS\system32\faxpatch.exe
    2008-08-26 19:00:30 ----A---- C:\WINDOWS\002613_.tmp
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eapsvc.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eapqec.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eappprxy.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eapphost.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eappgnui.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eappcfg.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eapp3hst.dll
    2008-08-26 19:00:28 ----N---- C:\WINDOWS\system32\eapolqec.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3ui.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3svc.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3msm.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3dlg.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3cfg.dll
    2008-08-26 19:00:24 ----N---- C:\WINDOWS\system32\dot3api.dll
    2008-08-26 19:00:22 ----N---- C:\WINDOWS\system32\dimsroam.dll
    2008-08-26 19:00:22 ----N---- C:\WINDOWS\system32\dimsntfy.dll
    2008-08-26 19:00:21 ----N---- C:\WINDOWS\system32\dhcpqec.dll
    2008-08-26 19:00:18 ----N---- C:\WINDOWS\system32\credssp.dll
    2008-08-26 19:00:12 ----N---- C:\WINDOWS\system32\bitsprx4.dll
    2008-08-26 19:00:11 ----N---- C:\WINDOWS\system32\azroles.dll
    2008-08-26 19:00:09 ----N---- C:\WINDOWS\system32\ativvaxx.dll
    2008-08-26 19:00:09 ----N---- C:\WINDOWS\system32\ativtmxx.dll
    2008-08-26 19:00:08 ----N---- C:\WINDOWS\system32\ati3duag.dll
    2008-08-26 19:00:08 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
    2008-08-26 19:00:08 ----N---- C:\WINDOWS\system32\ati2dvag.dll
    2008-08-26 19:00:08 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
    2008-08-26 19:00:08 ----N---- C:\WINDOWS\system32\ati2cqag.dll
    2008-08-26 18:59:59 ----N---- C:\WINDOWS\system32\aaclient.dll
    2008-08-26 17:08:14 ----A---- C:\WINDOWS\system32\msonpmon.dll
    2008-08-26 17:07:41 ----D---- C:\Program Files\Microsoft Works
    2008-08-26 17:07:22 ----D---- C:\Program Files\Common Files\DESIGNER
    2008-08-26 17:06:53 ----D---- C:\Program Files\Microsoft.NET
    2008-08-26 17:03:05 ----D---- C:\WINDOWS\SHELLNEW
    2008-08-26 17:01:01 ----D---- C:\Program Files\Microsoft Office
    2008-08-26 17:01:00 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-08-26 16:59:59 ----RHD---- C:\MSOCache
    2008-08-23 09:55:56 ----D---- C:\Documents and Settings\All Users\Application Data\nView_Profiles
    2008-08-22 20:04:06 ----D---- C:\WINDOWS\.jagex_cache_32
    2008-08-21 11:19:44 ----D---- C:\Documents and Settings\All Users\Application Data\Aliasworlds
    2008-08-21 11:15:06 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\PlayFirst
    2008-08-21 11:15:06 ----D---- C:\Documents and Settings\All Users\Application Data\PlayFirst
    2008-08-21 11:12:54 ----D---- C:\Program Files\ReflexiveArcade
    2008-08-20 17:50:30 ----A---- C:\WINDOWS\system32\TwnLib4.dll
    2008-08-20 17:50:30 ----A---- C:\WINDOWS\system32\imagXRA7.dll
    2008-08-20 17:50:30 ----A---- C:\WINDOWS\system32\imagXR7.dll
    2008-08-20 17:50:30 ----A---- C:\WINDOWS\system32\imagXpr7.dll
    2008-08-20 17:50:30 ----A---- C:\WINDOWS\system32\imagX7.dll
    2008-08-19 22:25:14 ----D---- C:\WINDOWS\pss
    2008-08-19 20:52:26 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-08-19 18:38:45 ----D---- C:\zCEP_Uninstaller
    2008-08-19 18:38:45 ----D---- C:\TSData
    2008-08-19 18:21:32 ----D---- C:\WINDOWS\Sun
    2008-08-19 09:23:02 ----D---- C:\etax2008
    2008-08-18 22:08:18 ----D---- C:\Program Files\Lavalys
    2008-08-18 22:01:32 ----HD---- C:\WINDOWS\PIF
    2008-08-18 21:01:49 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\OpenOffice.org2
    2008-08-18 19:31:15 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\AdobeUM
    2008-08-18 17:15:01 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\WinBatch
    2008-08-18 17:12:23 ----D---- C:\temp
    2008-08-18 17:09:54 ----A---- C:\WINDOWS\system32\muweb.dll
    2008-08-18 17:09:54 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
    2008-08-18 17:09:54 ----A---- C:\WINDOWS\system32\mucltui.dll
    2008-08-18 05:19:32 ----D---- C:\WINDOWS\I386
    2008-08-18 05:13:39 ----RD---- C:\Program Files
    2008-08-18 05:13:20 ----RSD---- C:\WINDOWS\assembly
    2008-08-18 05:13:16 ----RD---- C:\WINDOWS\Offline Web Pages
    2008-08-18 05:12:47 ----RSHD---- C:\WINDOWS\system32\dllcache
    2008-08-17 22:26:18 ----HD---- C:\$AVG8.VAULT$
    2008-08-17 16:18:47 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-08-17 16:08:38 ----D---- C:\WINDOWS\system32\LogFiles
    2008-08-17 16:02:32 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\HPQ
    2008-08-17 16:01:21 ----HD---- C:\BJPrinter
    2008-08-17 16:01:19 ----A---- C:\WINDOWS\system32\CNMVS6f.DLL
    2008-08-17 16:01:19 ----A---- C:\WINDOWS\system32\CNMLM6f.DLL
    2008-08-17 15:50:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
    2008-08-17 15:50:53 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
    2008-08-17 15:50:48 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
    2008-08-17 15:50:45 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
    2008-08-17 15:50:41 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
    2008-08-17 15:50:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$
    2008-08-17 15:49:26 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-08-17 15:48:47 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
    2008-08-17 15:48:39 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
    2008-08-17 15:48:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
    2008-08-17 15:48:30 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$
    2008-08-17 15:48:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
    2008-08-17 15:48:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
    2008-08-17 15:47:59 ----HDC---- C:\WINDOWS\$NtUninstallKB953838_0$
    2008-08-17 15:47:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
    2008-08-17 15:47:48 ----HDC---- C:\WINDOWS\$NtUninstallKB885884$
    2008-08-17 15:47:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950749$
    2008-08-17 15:47:31 ----HDC---- C:\WINDOWS\$NtUninstallKB901190$
    2008-08-17 15:47:27 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
    2008-08-17 15:47:19 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP10$
    2008-08-17 15:42:50 ----D---- C:\Program Files\Canon
    2008-08-17 15:42:44 ----HD---- C:\CanonMP
    2008-08-17 15:42:44 ----A---- C:\WINDOWS\system32\UCS32P.DLL
    2008-08-17 15:42:44 ----A---- C:\WINDOWS\system32\CNCL110.DLL
    2008-08-17 15:42:44 ----A---- C:\WINDOWS\system32\cncisco.dll
    2008-08-17 15:42:44 ----A---- C:\WINDOWS\system32\CNCI110.DLL
    2008-08-17 15:42:44 ----A---- C:\WINDOWS\system32\CNCC110.DLL
    2008-08-17 15:21:15 ----D---- C:\Program Files\StuffPlug3
    2008-08-17 15:10:54 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
    2008-08-17 15:09:58 ----DC---- C:\WINDOWS\system32\DRVSTORE
    2008-08-17 14:52:15 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-08-17 14:52:04 ----D---- C:\Program Files\Windows Live
    2008-08-17 14:51:51 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-08-17 14:47:45 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    2008-08-17 14:43:52 ----D---- C:\WINDOWS\system32\PreInstall
    2008-08-17 14:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
    2008-08-17 14:28:41 ----D---- C:\WINDOWS\system32\SoftwareDistribution
    2008-08-17 14:27:32 ----D---- C:\Program Files\uTorrent
    2008-08-17 14:27:27 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\uTorrent
    2008-08-17 14:23:59 ----D---- C:\Program Files\Age of Empires 2
    2008-08-17 14:19:18 ----D---- C:\Program Files\Bethesda Softworks
    2008-08-17 14:17:02 ----D---- C:\Program Files\DAEMON Tools Lite
    2008-08-17 14:13:21 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\DAEMON Tools
    2008-08-17 13:51:47 ----A---- C:\WINDOWS\system32\unrar.dll
    2008-08-17 13:51:46 ----A---- C:\WINDOWS\avisplitter.ini
    2008-08-17 13:51:44 ----A---- C:\WINDOWS\system32\yv12vfw.dll
    2008-08-17 13:51:44 ----A---- C:\WINDOWS\system32\x264vfw.dll
    2008-08-17 13:51:44 ----A---- C:\WINDOWS\system32\huffyuv.dll
    2008-08-17 13:51:43 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
    2008-08-17 13:51:43 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2008-08-17 13:51:43 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2008-08-17 13:51:43 ----A---- C:\WINDOWS\system32\vp7vfw.dll
    2008-08-17 13:51:41 ----A---- C:\WINDOWS\system32\qt-dx331.dll
    2008-08-17 13:51:41 ----A---- C:\WINDOWS\system32\dpl100.dll
    2008-08-17 13:51:40 ----A---- C:\WINDOWS\system32\divx.dll
    2008-08-17 13:51:39 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
    2008-08-17 13:51:39 ----A---- C:\WINDOWS\system32\ff_vfw.dll
    2008-08-17 13:51:37 ----D---- C:\Program Files\K-Lite Codec Pack
    2008-08-17 13:43:17 ----D---- C:\Program Files\OpenOffice.org 2.4
    2008-08-17 13:43:09 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-08-17 13:43:09 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-08-17 13:43:09 ----A---- C:\WINDOWS\system32\java.exe
    2008-08-17 13:42:33 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Sun
    2008-08-17 13:39:38 ----A---- C:\WINDOWS\cdplayer.ini
    2008-08-17 13:37:35 ----D---- C:\Program Files\Common Files\xing shared
    2008-08-17 13:29:27 ----D---- C:\Program Files\7-Zip
    2008-08-17 13:21:21 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Ahead
    2008-08-17 13:11:15 ----A---- C:\WINDOWS\system32\avgrsstx.dll
    2008-08-17 13:11:02 ----D---- C:\Program Files\AVG
    2008-08-17 13:11:02 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
    2008-08-17 13:03:46 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
    2008-08-17 13:03:16 ----D---- C:\Program Files\CCleaner
    2008-08-17 13:02:42 ----D---- C:\Program Files\Mozilla Firefox
    2008-08-17 13:02:06 ----D---- C:\Program Files\Spybot - Search & Destroy
    2008-08-17 13:02:06 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-17 13:00:04 ----RASH---- C:\BOOT.BAK
    2008-08-17 12:59:58 ----RSHD---- C:\cmdcons
    2008-08-17 12:59:58 ----A---- C:\WINDOWS\UPGRADE.TXT
    2008-08-17 12:59:56 ----D---- C:\WINDOWS\setup.pss
    2008-08-17 12:59:31 ----D---- C:\WINDOWS\setupupd
    2008-08-17 12:47:26 ----SHD---- C:\RECYCLER
    2008-08-17 12:43:42 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
    2008-08-17 12:34:08 ----D---- C:\WINDOWS\Options
    2008-08-17 12:31:04 ----A---- C:\WINDOWS\system32\wmpns.dll
    2008-08-17 12:29:00 ----ASH---- C:\Documents and Settings\Compaq_Owner\Application Data\desktop.ini
    2008-08-17 12:28:58 ----SD---- C:\Documents and Settings\Compaq_Owner\Application Data\Microsoft
    2008-08-17 12:28:58 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
    2008-08-17 12:28:58 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Real
    2008-08-17 12:28:58 ----D---- C:\Documents and Settings\Compaq_Owner\Application Data\Identities
    2008-08-17 11:23:51 ----SHD---- C:\System Volume Information
    2008-07-31 10:16:54 ----A---- C:\WINDOWS\system32\msjava.dll

    ======List of files/folders modified in the last 3 months======

    2008-10-26 09:00:20 ----D---- C:\WINDOWS\Temp
    2008-10-26 08:45:30 ----D---- C:\WINDOWS
    2008-10-26 08:45:28 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-10-26 08:34:47 ----D---- C:\WINDOWS\system32
    2008-10-26 08:22:11 ----D---- C:\WINDOWS\system32\drivers
    2008-10-26 08:21:05 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-10-26 08:15:21 ----D---- C:\WINDOWS\Debug
    2008-10-25 22:13:53 ----HD---- C:\WINDOWS\inf
    2008-10-25 22:13:47 ----HD---- C:\WINDOWS\$hf_mig$
    2008-10-25 22:06:20 ----A---- C:\WINDOWS\ModemLog_Agere Systems PCI-SV92PP Soft Modem.txt
    2008-10-25 22:03:20 ----SHD---- C:\WINDOWS\Installer
    2008-10-25 22:02:16 ----D---- C:\Program Files\Common Files\Adobe
    2008-10-25 22:02:16 ----D---- C:\Program Files\Adobe
    2008-10-25 22:00:32 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-10-25 22:00:30 ----D---- C:\Program Files\Common Files
    2008-10-16 03:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-13 19:57:23 ----D---- C:\WINDOWS\system32\DirectX
    2008-10-13 19:56:38 ----D---- C:\WINDOWS\Microsoft.NET
    2008-10-05 16:28:47 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-10-05 14:42:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-09-26 12:41:04 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-09-26 12:41:03 ----D---- C:\Program Files\Common Files\InstallShield
    2008-09-23 11:16:35 ----D---- C:\WINDOWS\WinSxS
    2008-09-21 20:57:33 ----RSD---- C:\WINDOWS\Fonts
    2008-09-21 12:21:24 ----D---- C:\Program Files\Internet Explorer
    2008-09-16 19:53:39 ----D---- C:\WINDOWS\system32\config
    2008-09-16 19:53:27 ----D---- C:\WINDOWS\system32\wbem
    2008-09-16 19:53:27 ----D---- C:\WINDOWS\Registration
    2008-09-16 19:52:25 ----D---- C:\WINDOWS\system32\Restore
    2008-09-12 22:11:47 ----D---- C:\WINDOWS\system32\Setup
    2008-09-12 22:11:47 ----D---- C:\WINDOWS\AppPatch
    2008-09-12 22:06:39 ----D---- C:\WINDOWS\system32\CatRoot
    2008-09-12 22:05:53 ----D---- C:\WINDOWS\security
    2008-09-12 22:03:13 ----D---- C:\WINDOWS\ime
    2008-09-12 22:03:13 ----D---- C:\WINDOWS\Help
    2008-09-12 22:03:03 ----D---- C:\WINDOWS\system32\usmt
    2008-09-12 22:03:01 ----D---- C:\WINDOWS\PeerNet
    2008-09-12 22:03:01 ----D---- C:\Program Files\Movie Maker
    2008-09-12 22:00:36 ----D---- C:\WINDOWS\system32\npp
    2008-09-12 22:00:34 ----D---- C:\WINDOWS\msagent
    2008-09-12 22:00:32 ----D---- C:\WINDOWS\srchasst
    2008-09-12 22:00:30 ----D---- C:\Program Files\NetMeeting
    2008-09-12 22:00:28 ----D---- C:\WINDOWS\system32\Com
    2008-09-12 22:00:26 ----D---- C:\Program Files\Windows Media Player
    2008-09-12 22:00:25 ----D---- C:\Program Files\Windows NT
    2008-09-12 22:00:25 ----D---- C:\Program Files\Outlook Express
    2008-09-12 22:00:22 ----D---- C:\Program Files\Common Files\System
    2008-09-12 22:00:03 ----D---- C:\WINDOWS\system32\oobe
    2008-09-12 22:00:01 ----D---- C:\WINDOWS\system
    2008-08-27 22:44:39 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-08-27 19:55:03 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-08-26 19:59:30 ----D---- C:\Program Files\microsoft frontpage
    2008-08-22 14:43:56 ----RASH---- C:\boot.ini
    2008-08-22 14:43:56 ----A---- C:\WINDOWS\win.ini
    2008-08-22 14:43:56 ----A---- C:\WINDOWS\system.ini
    2008-08-20 16:30:53 ----A---- C:\WINDOWS\system32\mshtml.dll
    2008-08-20 16:30:52 ----A---- C:\WINDOWS\system32\urlmon.dll
    2008-08-20 16:30:51 ----A---- C:\WINDOWS\system32\wininet.dll
    2008-08-20 16:30:51 ----A---- C:\WINDOWS\system32\shdocvw.dll
    2008-08-18 17:12:31 ----HD---- C:\hp
    2008-08-18 05:20:44 ----D---- C:\WINDOWS\SMINST
    2008-08-18 05:19:21 ----D---- C:\Program Files\Common Files\Services
    2008-08-18 05:19:12 ----D---- C:\WINDOWS\system32\ras
    2008-08-18 05:19:01 ----D---- C:\WINDOWS\system32\icsxml
    2008-08-18 05:19:00 ----D---- C:\WINDOWS\system32\ias
    2008-08-18 05:18:08 ----RD---- C:\WINDOWS\Web
    2008-08-18 05:18:08 ----D---- C:\WINDOWS\addins
    2008-08-18 05:17:56 ----D---- C:\WINDOWS\Cursors
    2008-08-18 05:17:53 ----AHDC---- C:\WINDOWS\$NtUninstallKB902400$
    2008-08-18 05:17:52 ----AHDC---- C:\WINDOWS\$NtUninstallKB901214$
    2008-08-18 05:17:52 ----AHDC---- C:\WINDOWS\$NtUninstallKB896688$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB896422$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB896358$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB893066$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB892050$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB891781$
    2008-08-18 05:17:51 ----AHDC---- C:\WINDOWS\$NtUninstallKB890175$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB888239$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB888113$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB887742$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB885836$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB885835$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB885250$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB883667$
    2008-08-18 05:17:50 ----AHDC---- C:\WINDOWS\$NtUninstallKB873339$
    2008-08-17 16:01:23 ----D---- C:\WINDOWS\system32\FxsTmp
    2008-08-17 16:01:13 ----D---- C:\WINDOWS\Media
    2008-08-17 16:01:11 ----D---- C:\WINDOWS\twain_32
    2008-08-17 14:32:17 ----D---- C:\WINDOWS\SoftwareDistribution
    2008-08-17 13:43:08 ----D---- C:\Program Files\Java
    2008-08-17 13:37:27 ----D---- C:\Program Files\Common Files\Real
    2008-08-17 13:37:24 ----A---- C:\WINDOWS\system32\rmoc3260.dll
    2008-08-17 13:37:15 ----A---- C:\WINDOWS\system32\pndx5032.dll
    2008-08-17 13:37:15 ----A---- C:\WINDOWS\system32\pndx5016.dll
    2008-08-17 13:37:12 ----A---- C:\WINDOWS\system32\pncrt.dll
    2008-08-17 12:59:07 ----D---- C:\Program Files\Common Files\Symantec Shared
    2008-08-17 12:59:07 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2008-08-17 12:54:58 ----D---- C:\Program Files\Sonic
    2008-08-17 12:42:35 ----SD---- C:\WINDOWS\Tasks
    2008-08-17 12:36:58 ----D---- C:\WINDOWS\HPCPCUninstall-5577497
    2008-08-17 12:30:40 ----AD---- C:\WINDOWS\system32\pcintro
    2008-08-17 12:28:58 ----D---- C:\Documents and Settings
    2008-08-17 11:22:59 ----D---- C:\WINDOWS\repair
    2008-08-14 21:11:02 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
    2008-08-14 20:33:16 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-10 36352]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-29 97928]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-08-17 26824]
    R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-08-07 33052]
    R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-08-17 76040]
    R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-09-24 1094751]
    R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-08-30 3644928]
    R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
    R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
    R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
    R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
    R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-08-03 3199328]
    R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
    R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-05 74496]
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
    R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
    R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
    R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
    S3 ae98vfcv;ae98vfcv; C:\WINDOWS\system32\drivers\ae98vfcv.sys []
    S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
    S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
    S4 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
    R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-10-23 69632]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-08-03 127043]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
    S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 267776]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-25 655624]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

    -----------------EOF-----------------
     
  9. 2008/10/25
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    And here is the info file;

    info.txt logfile of random's system information tool 1.04 2008-10-26 09:00:23

    ======Uninstall list======

    -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    -->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
    2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
    7-Zip 4.57--> "C:\Program Files\7-Zip\Uninstall.exe "
    AC Tool-->C:\PROGRA~1\ACTOOL~1\UNWISE.EXE C:\PROGRA~1\ACTOOL~1\INSTALL.LOG
    Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
    Adobe AIR-->MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}
    Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
    Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
    Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
    Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
    Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
    Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
    Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
    Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
    Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
    Adobe Device Central CS4-->MsiExec.exe /I{67F0E67A-8E93-4C2C-B29D-47C48262738A}
    Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
    Adobe Extension Manager CS4-->MsiExec.exe /I{054EFA56-2AC1-48F4-A883-0AB89874B972}
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
    Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
    Adobe Photoshop CS4-->C:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
    Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
    Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
    Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
    Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
    Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
    Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
    Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
    Age of Mythology - The Titans Expansion--> "C:\Program Files\Microsoft Games\Age of Mythology\UNINSTXP.EXE" /runtemp /addremove
    Age of Mythology--> "C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
    Agere Systems PCI-SV92PP Soft Modem-->agrsmdel
    AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
    Cake Mania 3--> "C:\Program Files\Cake Mania 3\ReflexiveArcade\unins000.exe "
    Canon MP Drivers 7.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D335AC77-6F59-46D6-9082-F74A9F7E0FC3}\Setup.exe" -l0x9 -Uninstall
    Canon ScanGear Starter-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18A5DFF2-8A95-49F3-873F-743CB5549F3D}\setup.exe" -l0x9 anything
    CCleaner (remove only)--> "C:\Program Files\CCleaner\uninst.exe "
    CEP - Color Enable Package--> "C:\zCEP_Uninstaller\unins000.exe "
    Cheat Engine 5.4--> "C:\Program Files\Cheat Engine\unins000.exe "
    Cinema Tycoon 2 Movie Mania--> "C:\Program Files\Cinema Tycoon 2 Movie Mania\ReflexiveArcade\unins000.exe "
    Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
    Cooking Dash--> "C:\Program Files\Cooking Dash\ReflexiveArcade\unins000.exe "
    Diner Dash Seasonal Snack Pack--> "C:\Program Files\Diner Dash Seasonal Snack Pack\ReflexiveArcade\unins000.exe "
    Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
    e-tax 2008-->C:\etax2008\e-tax 2008_uninstall.exe
    EVEREST Home Edition v2.20--> "C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe "
    Fashionista--> "C:\Program Files\Fashionista\ReflexiveArcade\unins000.exe "
    Ghost-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{649B34DB-839B-45E1-AC83-AA79B8458B98}\setup.exe" -l0x12 -removeonly
    GhostOnline-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97130A1A-4AC4-4E5F-9F13-B658D2F25AB4}\setup.exe" -l0x9
    High Definition Audio Driver Package - KB888111--> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe "
    HijackThis 2.0.2--> "C:\Program Files\trend micro\HijackThis.exe" /uninstall
    Home Sweet Home 2 Kitchens And Baths--> "C:\Program Files\Home Sweet Home 2 Kitchens And Baths\ReflexiveArcade\unins000.exe "
    Hotfix for Windows XP (KB952287)--> "C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe "
    HP Software Update-->MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
    J2SE Runtime Environment 5.0 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150050}
    Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    K-Lite Codec Pack 4.1.4 (Full)--> "C:\Program Files\K-Lite Codec Pack\unins000.exe "
    kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
    Logic Basics 3.0--> "C:\Program Files\Babya\Logic Basics\unins000.exe "
    Magic Seeds--> "C:\Program Files\Magic Seeds\ReflexiveArcade\unins000.exe "
    Malwarebytes' Anti-Malware--> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe "
    Microsoft .NET Framework 1.1 Hotfix (KB928366)--> "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp "
    Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
    Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
    Microsoft Office Home and Student 2007--> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL
    Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE}
    Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
    Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
    Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
    Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
    Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
    Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
    Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
    Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
    Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Morrowind-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\Bethesda Softworks\Morrowind\MWUninstall\Setup.exe" -l0x9
    Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MPlugin--> "C:\Program Files\InstallShield Installation Information\{6102D63A-9387-4FC8-98E4-181121F8C0BA}\setup.exe" -runfromtemp -l0x0009 -removeonly
    MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
    MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
    Network Addon Mod Version April 2008-->C:\Documents and Settings\Compaq_Owner\My Documents\SimCity 4\Plugins\Network Addon Mod\uninst.exe
    NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
    OpenOffice.org 2.4-->MsiExec.exe /I{2CD2C0DB-81C3-416B-9FA6-589B9235359B}
    Paint.NET v3.36-->MsiExec.exe /X{43602F34-1AA3-44FB-AEB2-D08C2C73743F}
    PaltalkScene--> "C:\WINDOWS\PaltalkScene\uninstall.exe" "/U:C:\Program Files\Paltalk Messenger\irunin.xml "
    Peggle Nights--> "C:\Program Files\Peggle Nights\ReflexiveArcade\unins000.exe "
    Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
    PowerISO--> "C:\Program Files\PowerISO\uninstall.exe "
    PS2-->C:\WINDOWS\system32\ps2.exe uninstall
    RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    RGSS-RTP Standard-->MsiExec.exe /I{5A9FE525-8B8F-4701-A937-7F6745A4E9C7}
    RPGXP-->MsiExec.exe /I{9B34CAC6-738F-4A20-B428-A115C3E3474C}
    Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7}
    Security Update for 2007 Microsoft Office System (KB955936)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028}
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
    Security Update for Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    Security Update for Microsoft Office Excel 2007 (KB955470)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E}
    Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4}
    Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77}
    Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
    Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F}
    Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
    Security Update for Step By Step Interactive Training (KB923723)--> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe "
    Security Update for Windows Media Player 10 (KB936782)--> "C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB938464)--> "C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB941569)--> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB946648)--> "C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950762)--> "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB950974)--> "C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951066)--> "C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951376-v2)--> "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951698)--> "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB951748)--> "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB952954)--> "C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB953838)--> "C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB953839)--> "C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB954211)--> "C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956390)--> "C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956391)--> "C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956803)--> "C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB956841)--> "C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB957095)--> "C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe "
    Security Update for Windows XP (KB958644)--> "C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe "
    Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    Sim File Maid 2 1.0.2-->C:\Program Files\Sim File Maid 2\uninst.exe
    SimCity 4 Deluxe-->C:\Program Files\Maxis\SimCity 4 Deluxe\EAUninstall.exe
    Simcity 4 Region and Config Creator (Scracc)-->MsiExec.exe /I{9FF23187-713D-4785-9B62-33B609A10F0D}
    Spybot - Search & Destroy--> "C:\Program Files\Spybot - Search & Destroy\unins000.exe "
    StuartLittle2 Screen Saver-->C:\WINDOWS\NCUNINST.EXe RMSCR StuartLittle2
    StuffPlug 3-->C:\Program Files\StuffPlug3\Uninstall.exe
    Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
    Super Jigsaw Beach Holiday-->C:\PROGRA~1\GAMEHO~1\Jigsaw\UN-BEA~1.EXE /U C:\PROGRA~1\GAMEHO~1\Jigsaw\BeachHoliday-INSTALL.LOG
    Super Jigsaw Caboodle-->C:\PROGRA~1\GAMEHO~1\Jigsaw\UN-CAB~1.EXE /U C:\PROGRA~1\GAMEHO~1\Jigsaw\Caboodle-INSTALL.LOG
    Super Jigsaw Safari-->C:\PROGRA~1\GAMEHO~1\Jigsaw\UN-SAF~1.EXE /U C:\PROGRA~1\GAMEHO~1\Jigsaw\Safari-INSTALL.LOG
    The Sims 2 Nightlife-->C:\Program Files\EA GAMES\The Sims 2 Nightlife\EAUninstall.exe
    The Sims 2-->C:\Program Files\EA GAMES\The Sims 2\EAUninstall.exe
    The Sims™ 2 FreeTime-->C:\Program Files\EA GAMES\The Sims 2 FreeTime\EAUninstall.exe
    The Sims™ 2 Seasons-->C:\Program Files\EA GAMES\The Sims 2 Seasons\EAUninstall.exe
    Timed Shutdown 0.5b--> "C:\Program Files\Timed Shutdown\unins000.exe "
    Turbo Fiesta--> "C:\Program Files\Turbo Fiesta\ReflexiveArcade\unins000.exe "
    Tycoon City - New York Demo-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96701279-A3ED-4F1E-B3C1-38CDA572ED65}\Setup.exe" -l0x9
    Typer Shark Deluxe 1.01-->C:\Program Files\PopCap Games\Typer Shark Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Typer Shark Deluxe\Install.log "
    Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
    Update for Windows XP (KB951072-v2)--> "C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe "
    Update for Windows XP (KB951978)--> "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe "
    Westward II Heroes Of The Frontier--> "C:\Program Files\Westward II Heroes Of The Frontier\ReflexiveArcade\unins000.exe "
    Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
    Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
    Windows Media Format Runtime--> "C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    Windows Media Player 10--> "C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
    Windows XP Service Pack 3--> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe "

    ======Security center information======

    AV: AVG Anti-Virus Free

    ======Environment variables======

    "ComSpec "=%SystemRoot%\system32\cmd.exe
    "Path "=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;c:\Python22;C:\Program Files\Smart Projects\IsoBuster
    "windir "=%SystemRoot%
    "FP_NO_HOST_CHECK "=NO
    "OS "=Windows_NT
    "PROCESSOR_ARCHITECTURE "=x86
    "PROCESSOR_LEVEL "=15
    "PROCESSOR_IDENTIFIER "=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
    "PROCESSOR_REVISION "=2f02
    "NUMBER_OF_PROCESSORS "=1
    "PATHEXT "=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP "=%SystemRoot%\TEMP
    "TMP "=%SystemRoot%\TEMP

    -----------------EOF-----------------



    EDIT:
    I definitely still have some...after affects of the, well I will call this an attack :p. As stated before, sart menu disappeared and was fixed by smitfraud and now my clock changed settings (to show as 08:21 instead of 8:21AM, simply changed through windows settings but still is annoying if random small effects of Total Secure 2009 are still popping up every...20 minutes or so. Maybe my task bar will lock again soon).
     
    Last edited: 2008/10/25
  10. 2008/10/26
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi zachcharge :)

    Download ComboFix by sUBs from here, saving the file to your desktop.


    Please disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click ComboFix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log and a new HijackThis log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     
  11. 2008/10/28
    zachcharge

    zachcharge Inactive Thread Starter

    Joined:
    2008/10/25
    Messages:
    6
    Likes Received:
    0
    Ok, I ran Combofix and it deleted a few things. I haven't had any strange...leftover problems so far :)

    I think I am cured! Thanks for your help noahdfear, if any minor signs have...anything happen, I will promptly inform you.
     
  12. 2008/10/29
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    It's best to post the logs as requested so we can ensure there are no remnants left to be removed.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.