cleanUpLaptop
Topic Starter
Hello,
I was running MS AntiSpyware last week. It had caught several things, and was attempting to fix them when I got the BSOD. Upon restarting then, and each time since then, after clicking my user account I get another BSOD and the computer restarts. I can only get into Windows by running in safe mode. Here's the BSOD error code:
*** STOP : 0x0000008E (0xC0000005,0x7FFA1090,0xAA7ECC58,0x00000000)
There had been several different spyware problems that MSAS kept finding and trying to remove, but that kept reappearing. I ran Adaware too, with the same repetitive result. Then finally the total freeze as MSAS was trying to clean off what it found.
In safe mode I ran Housecall from trendmicro.com. It found just over 16,000 viruses. The guy at Medion USA (my laptop brand) was impressed, since he hadn't seen over 3700 before. I think Limewire is involved. Most of the 'viruses' Housecall found were in C:\complete (not my normal Limewire downloads folder) and … well I can't remmber right now what the other folder was. But it was thousands of folders named somehow using the names of movies from imdb.com. This is my guess anyway, as the folders were always named with a movie title and the year in parentheses, titles in English, German, Japanese, etc. Inside each folder was a small zip file with the same name as the folder, if I recall correctly. All those were found by Housecall. It deleted 600 or so, and I manually deleted the rest. Prior to the BSOD, Limewire had been starting itself repeatedly, until I just uninstalled it, and left it uninstalled. The other folder was similar, though with far fewer files and they were named after software titles, I think.
I downloaded AVG 7.0 on the suggestion of Medion customer service, but it won't install in safe mode. So I have no antivirus software installed that might deal with whatever the problem is. I had mistakenly thought Microsoft was also going after viruses with the AntiSpyware beta, since I just couldn't imagine them still ignoring the need to be able to fix these problems in their operating system. I used to have Symantec Corporate, but had removed it when I installed MSAS. Now if I can get back in, I'll go back to something more reliable and covering more problems.
I ran HijackThis, and got an obviously virus infested log. Since the names of the folders and files in Windows\System32 are random, searching online for matches hasn't helped. So I don't know what virus(es) I have. And I'd like to make sure what exactly I can delete.
I also ran MemTest and my ram seems healthy. None of the other 0x8E errors I found discussed online seem to fit the problem, and especially with the HJT log, I'm convinced the computer's got viruses.
Here's the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 8:57:15 PM, on 10/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\lncdvy.exe
C:\Documents and Settings\patrick\Desktop\newPrograms\web\hijackThis\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [agvs] C:\WINDOWS\system32\vafrwg\agvs.exe
O4 - HKLM\..\Run: [kicd] C:\WINDOWS\system32\ybllqu\kicd.exe
O4 - HKLM\..\Run: [knugtwd] C:\WINDOWS\system32\niuor\knugtwd.exe
O4 - HKLM\..\Run: [etfur] C:\WINDOWS\system32\bactalvh\etfur.exe
O4 - HKLM\..\Run: [ispiovlj] C:\WINDOWS\system32\nooa\ispiovlj.exe
O4 - HKLM\..\Run: [uxpwgb] C:\WINDOWS\system32\jrcdgp\uxpwgb.exe
O4 - HKLM\..\Run: [gxevwr] C:\WINDOWS\system32\ibmb\gxevwr.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [xftnchxr] C:\WINDOWS\system32\ynkkaw\xftnchxr.exe
O4 - HKLM\..\Run: [ieuamx] C:\WINDOWS\system32\powxnp\ieuamx.exe
O4 - HKLM\..\Run: [sanmhip] C:\WINDOWS\system32\ioafsvi\sanmhip.exe
O4 - HKLM\..\Run: [qditibh] C:\WINDOWS\system32\kpgrbo\qditibh.exe
O4 - HKLM\..\Run: [juoy] C:\WINDOWS\system32\rpwnyy\juoy.exe
O4 - HKLM\..\Run: [vqrrmmjt] C:\WINDOWS\system32\nvhe\vqrrmmjt.exe
O4 - HKLM\..\Run: [hguevjc] C:\WINDOWS\system32\wnyd\hguevjc.exe
O4 - HKLM\..\Run: [obdapacn] C:\WINDOWS\system32\obdapacn.exe
O4 - HKLM\..\Run: [xngk] C:\WINDOWS\system32\raqqxfy\xngk.exe
O4 - HKLM\..\Run: [lhmpop] C:\WINDOWS\system32\jccucwsg\lhmpop.exe
O4 - HKLM\..\Run: [onochbln] C:\WINDOWS\system32\eflxumq\onochbln.exe
O4 - HKLM\..\Run: [oobg] C:\WINDOWS\system32\nbeqxt\oobg.exe
O4 - HKLM\..\Run: [uimpdum] C:\WINDOWS\system32\xogmbbxg\uimpdum.exe
O4 - HKLM\..\Run: [lpsmaaw] C:\WINDOWS\system32\spulu\lpsmaaw.exe
O4 - HKLM\..\Run: [pwfwsiif] C:\WINDOWS\system32\swwx\pwfwsiif.exe
O4 - HKLM\..\Run: [ldnsjei] C:\WINDOWS\system32\ajtjnqo\ldnsjei.exe
O4 - HKLM\..\Run: [acbhleb] C:\WINDOWS\system32\rfycpa\acbhleb.exe
O4 - HKLM\..\Run: [tjwvnoqu] C:\WINDOWS\system32\dokcon\tjwvnoqu.exe
O4 - HKLM\..\Run: [qchueph] C:\WINDOWS\system32\svqf\qchueph.exe
O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
O4 - HKLM\..\Run: [dngojs] C:\WINDOWS\system32\rxrpr\dngojs.exe
O4 - HKLM\..\Run: [tcrdtr] C:\WINDOWS\system32\edlkm\tcrdtr.exe
O4 - HKLM\..\Run: [stluku] C:\WINDOWS\system32\feyvy\stluku.exe
O4 - HKLM\..\Run: [mjtm] C:\WINDOWS\system32\dcnvrvpr\mjtm.exe
O4 - HKLM\..\Run: [vwkjfva] C:\WINDOWS\system32\jame\vwkjfva.exe
O4 - HKLM\..\Run: [csjy] C:\WINDOWS\system32\rquse\csjy.exe
O4 - HKLM\..\Run: [akbjyaly] C:\WINDOWS\system32\uhwh\akbjyaly.exe
O4 - HKLM\..\Run: [jlefx] C:\WINDOWS\system32\jkrakj\jlefx.exe
O4 - HKLM\..\Run: [nymd] C:\WINDOWS\system32\oqab\nymd.exe
O4 - HKLM\..\Run: [pjquhcaf] C:\WINDOWS\system32\wcsdwr\pjquhcaf.exe
O4 - HKLM\..\Run: [jirqirj] C:\WINDOWS\system32\myau\jirqirj.exe
O4 - HKLM\..\Run: [dipb] C:\WINDOWS\system32\lvthheru\dipb.exe
O4 - HKLM\..\Run: [omcgqa] C:\WINDOWS\system32\kpjcsg\omcgqa.exe
O4 - HKLM\..\Run: [tlpswp] C:\WINDOWS\system32\aghycxrn\tlpswp.exe
O4 - HKLM\..\Run: [gjsjwedi] C:\WINDOWS\system32\swkjpg\gjsjwedi.exe
O4 - HKLM\..\Run: [efrmaog] C:\WINDOWS\system32\tweipxv\efrmaog.exe
O4 - HKLM\..\Run: [mubfcjdi] C:\WINDOWS\system32\lnol\mubfcjdi.exe
O4 - HKLM\..\Run: [gyicighb] C:\WINDOWS\system32\esqwws\gyicighb.exe
O4 - HKLM\..\Run: [jbdginrv] C:\WINDOWS\system32\eawj\jbdginrv.exe
O4 - HKLM\..\Run: [xopfdfkc] C:\WINDOWS\system32\rods\xopfdfkc.exe
O4 - HKLM\..\Run: [apeybq] C:\WINDOWS\system32\rngf\apeybq.exe
O4 - HKLM\..\Run: [plpllkeh] C:\WINDOWS\system32\sesg\plpllkeh.exe
O4 - HKLM\..\Run: [evjdhvs] C:\WINDOWS\system32\eydqkb\evjdhvs.exe
O4 - HKLM\..\Run: [rsdmx] C:\WINDOWS\system32\gqpm\rsdmx.exe
O4 - HKLM\..\Run: [synje] C:\WINDOWS\system32\picy\synje.exe
O4 - HKLM\..\Run: [cglvwqku] C:\WINDOWS\system32\moosc\cglvwqku.exe
O4 - HKLM\..\Run: [ifnm] C:\WINDOWS\system32\lyhbxnu\ifnm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [gozlnyr] C:\WINDOWS\system32\lncdvy.exe r
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [GIANTAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121035336328
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: hguevjcwnyd - Unknown owner - C:\WINDOWS\system32\wnyd\hguevjc.exe
O23 - Service: ispiovljnooa - Unknown owner - C:\WINDOWS\system32\nooa\ispiovlj.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: mubfcjdilnol - Unknown owner - C:\WINDOWS\system32\lnol\mubfcjdi.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: xngkraqqxfy - Unknown owner - C:\WINDOWS\system32\raqqxfy\xngk.exe
Thanks for whatever help I can get. I can still get some work done in safe mode, but it's getting obnoxious!
I was running MS AntiSpyware last week. It had caught several things, and was attempting to fix them when I got the BSOD. Upon restarting then, and each time since then, after clicking my user account I get another BSOD and the computer restarts. I can only get into Windows by running in safe mode. Here's the BSOD error code:
*** STOP : 0x0000008E (0xC0000005,0x7FFA1090,0xAA7ECC58,0x00000000)
There had been several different spyware problems that MSAS kept finding and trying to remove, but that kept reappearing. I ran Adaware too, with the same repetitive result. Then finally the total freeze as MSAS was trying to clean off what it found.
In safe mode I ran Housecall from trendmicro.com. It found just over 16,000 viruses. The guy at Medion USA (my laptop brand) was impressed, since he hadn't seen over 3700 before. I think Limewire is involved. Most of the 'viruses' Housecall found were in C:\complete (not my normal Limewire downloads folder) and … well I can't remmber right now what the other folder was. But it was thousands of folders named somehow using the names of movies from imdb.com. This is my guess anyway, as the folders were always named with a movie title and the year in parentheses, titles in English, German, Japanese, etc. Inside each folder was a small zip file with the same name as the folder, if I recall correctly. All those were found by Housecall. It deleted 600 or so, and I manually deleted the rest. Prior to the BSOD, Limewire had been starting itself repeatedly, until I just uninstalled it, and left it uninstalled. The other folder was similar, though with far fewer files and they were named after software titles, I think.
I downloaded AVG 7.0 on the suggestion of Medion customer service, but it won't install in safe mode. So I have no antivirus software installed that might deal with whatever the problem is. I had mistakenly thought Microsoft was also going after viruses with the AntiSpyware beta, since I just couldn't imagine them still ignoring the need to be able to fix these problems in their operating system. I used to have Symantec Corporate, but had removed it when I installed MSAS. Now if I can get back in, I'll go back to something more reliable and covering more problems.
I ran HijackThis, and got an obviously virus infested log. Since the names of the folders and files in Windows\System32 are random, searching online for matches hasn't helped. So I don't know what virus(es) I have. And I'd like to make sure what exactly I can delete.
I also ran MemTest and my ram seems healthy. None of the other 0x8E errors I found discussed online seem to fit the problem, and especially with the HJT log, I'm convinced the computer's got viruses.
Here's the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 8:57:15 PM, on 10/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\lncdvy.exe
C:\Documents and Settings\patrick\Desktop\newPrograms\web\hijackThis\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O3 - Toolbar: Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] C:\Program Files\ABBYY FineReader 7.0 Professional Edition\AbbyyNewsReader.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [agvs] C:\WINDOWS\system32\vafrwg\agvs.exe
O4 - HKLM\..\Run: [kicd] C:\WINDOWS\system32\ybllqu\kicd.exe
O4 - HKLM\..\Run: [knugtwd] C:\WINDOWS\system32\niuor\knugtwd.exe
O4 - HKLM\..\Run: [etfur] C:\WINDOWS\system32\bactalvh\etfur.exe
O4 - HKLM\..\Run: [ispiovlj] C:\WINDOWS\system32\nooa\ispiovlj.exe
O4 - HKLM\..\Run: [uxpwgb] C:\WINDOWS\system32\jrcdgp\uxpwgb.exe
O4 - HKLM\..\Run: [gxevwr] C:\WINDOWS\system32\ibmb\gxevwr.exe
O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
O4 - HKLM\..\Run: [xftnchxr] C:\WINDOWS\system32\ynkkaw\xftnchxr.exe
O4 - HKLM\..\Run: [ieuamx] C:\WINDOWS\system32\powxnp\ieuamx.exe
O4 - HKLM\..\Run: [sanmhip] C:\WINDOWS\system32\ioafsvi\sanmhip.exe
O4 - HKLM\..\Run: [qditibh] C:\WINDOWS\system32\kpgrbo\qditibh.exe
O4 - HKLM\..\Run: [juoy] C:\WINDOWS\system32\rpwnyy\juoy.exe
O4 - HKLM\..\Run: [vqrrmmjt] C:\WINDOWS\system32\nvhe\vqrrmmjt.exe
O4 - HKLM\..\Run: [hguevjc] C:\WINDOWS\system32\wnyd\hguevjc.exe
O4 - HKLM\..\Run: [obdapacn] C:\WINDOWS\system32\obdapacn.exe
O4 - HKLM\..\Run: [xngk] C:\WINDOWS\system32\raqqxfy\xngk.exe
O4 - HKLM\..\Run: [lhmpop] C:\WINDOWS\system32\jccucwsg\lhmpop.exe
O4 - HKLM\..\Run: [onochbln] C:\WINDOWS\system32\eflxumq\onochbln.exe
O4 - HKLM\..\Run: [oobg] C:\WINDOWS\system32\nbeqxt\oobg.exe
O4 - HKLM\..\Run: [uimpdum] C:\WINDOWS\system32\xogmbbxg\uimpdum.exe
O4 - HKLM\..\Run: [lpsmaaw] C:\WINDOWS\system32\spulu\lpsmaaw.exe
O4 - HKLM\..\Run: [pwfwsiif] C:\WINDOWS\system32\swwx\pwfwsiif.exe
O4 - HKLM\..\Run: [ldnsjei] C:\WINDOWS\system32\ajtjnqo\ldnsjei.exe
O4 - HKLM\..\Run: [acbhleb] C:\WINDOWS\system32\rfycpa\acbhleb.exe
O4 - HKLM\..\Run: [tjwvnoqu] C:\WINDOWS\system32\dokcon\tjwvnoqu.exe
O4 - HKLM\..\Run: [qchueph] C:\WINDOWS\system32\svqf\qchueph.exe
O4 - HKLM\..\Run: [MsUpdate] C:\Program Files\MsUpdate\MsUpdate.exe /auto
O4 - HKLM\..\Run: [dngojs] C:\WINDOWS\system32\rxrpr\dngojs.exe
O4 - HKLM\..\Run: [tcrdtr] C:\WINDOWS\system32\edlkm\tcrdtr.exe
O4 - HKLM\..\Run: [stluku] C:\WINDOWS\system32\feyvy\stluku.exe
O4 - HKLM\..\Run: [mjtm] C:\WINDOWS\system32\dcnvrvpr\mjtm.exe
O4 - HKLM\..\Run: [vwkjfva] C:\WINDOWS\system32\jame\vwkjfva.exe
O4 - HKLM\..\Run: [csjy] C:\WINDOWS\system32\rquse\csjy.exe
O4 - HKLM\..\Run: [akbjyaly] C:\WINDOWS\system32\uhwh\akbjyaly.exe
O4 - HKLM\..\Run: [jlefx] C:\WINDOWS\system32\jkrakj\jlefx.exe
O4 - HKLM\..\Run: [nymd] C:\WINDOWS\system32\oqab\nymd.exe
O4 - HKLM\..\Run: [pjquhcaf] C:\WINDOWS\system32\wcsdwr\pjquhcaf.exe
O4 - HKLM\..\Run: [jirqirj] C:\WINDOWS\system32\myau\jirqirj.exe
O4 - HKLM\..\Run: [dipb] C:\WINDOWS\system32\lvthheru\dipb.exe
O4 - HKLM\..\Run: [omcgqa] C:\WINDOWS\system32\kpjcsg\omcgqa.exe
O4 - HKLM\..\Run: [tlpswp] C:\WINDOWS\system32\aghycxrn\tlpswp.exe
O4 - HKLM\..\Run: [gjsjwedi] C:\WINDOWS\system32\swkjpg\gjsjwedi.exe
O4 - HKLM\..\Run: [efrmaog] C:\WINDOWS\system32\tweipxv\efrmaog.exe
O4 - HKLM\..\Run: [mubfcjdi] C:\WINDOWS\system32\lnol\mubfcjdi.exe
O4 - HKLM\..\Run: [gyicighb] C:\WINDOWS\system32\esqwws\gyicighb.exe
O4 - HKLM\..\Run: [jbdginrv] C:\WINDOWS\system32\eawj\jbdginrv.exe
O4 - HKLM\..\Run: [xopfdfkc] C:\WINDOWS\system32\rods\xopfdfkc.exe
O4 - HKLM\..\Run: [apeybq] C:\WINDOWS\system32\rngf\apeybq.exe
O4 - HKLM\..\Run: [plpllkeh] C:\WINDOWS\system32\sesg\plpllkeh.exe
O4 - HKLM\..\Run: [evjdhvs] C:\WINDOWS\system32\eydqkb\evjdhvs.exe
O4 - HKLM\..\Run: [rsdmx] C:\WINDOWS\system32\gqpm\rsdmx.exe
O4 - HKLM\..\Run: [synje] C:\WINDOWS\system32\picy\synje.exe
O4 - HKLM\..\Run: [cglvwqku] C:\WINDOWS\system32\moosc\cglvwqku.exe
O4 - HKLM\..\Run: [ifnm] C:\WINDOWS\system32\lyhbxnu\ifnm.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [gozlnyr] C:\WINDOWS\system32\lncdvy.exe r
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [GIANTAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000140.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000140.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121035336328
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: hguevjcwnyd - Unknown owner - C:\WINDOWS\system32\wnyd\hguevjc.exe
O23 - Service: ispiovljnooa - Unknown owner - C:\WINDOWS\system32\nooa\ispiovlj.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: mubfcjdilnol - Unknown owner - C:\WINDOWS\system32\lnol\mubfcjdi.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: xngkraqqxfy - Unknown owner - C:\WINDOWS\system32\raqqxfy\xngk.exe
Thanks for whatever help I can get. I can still get some work done in safe mode, but it's getting obnoxious!