I ran it in Normal mode,
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-13 22:26:02
Microsoft Windows XP Professional Service Pack 2
System drive D: has 171 GB (96%) free of 179 GB
Total RAM: 3007 MB (87% free)
HijackThis download failed
======Scheduled tasks folder======
D:\WINDOWS\tasks\bdmiqanb.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=D:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-27 1261336]
"LXBXCATS"=rundll32 D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll []
"lxbxmon.exe"=D:\Program Files\Lexmark 7100 Series\lxbxmon.exe [2005-01-18 196608]
"FaxCenterServer4_in_1"=D:\Program Files\Lexmark 7100 Series\fm3032.exe [2004-12-06 286720]
"EzPrint"=D:\Program Files\Lexmark 7100 Series\ezprint.exe [2004-09-17 61440]
"Adobe Reader Speed Launcher"=D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
D:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
D:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
D:\WINDOWS\system32\NvCpl.dll [2007-08-23 8478720]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
D:\WINDOWS\system32\NvMcTray.dll [2007-08-23 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
D:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-09-14 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
D:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2006-11-13 561213]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3
"NVSvc"=2
"btwdins"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
D:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
D:\WINDOWS\system32\ssqPIBSK
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati1tpxx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xpxx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati1tpxx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ati8xpxx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
"NoFolderOptions"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\AVG\AVG8\avgemc.exe"="D:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"D:\Program Files\AVG\AVG8\avgupd.exe"="D:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"D:\WINDOWS\system32\mmc.exe"="D:\WINDOWS\system32\mmc.exe:*:Disabled:Microsoft Management Console"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{27fb5c44-7a74-11dd-9e9a-001e68c6e09b}]
shell\Auto\command - F:\Start.exe
shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
======List of files/folders created in the last 2 months======
2009-01-13 22:26:02 —-D—- D:\rsit
2009-01-13 22:26:02 —-D—- D:\Program Files\trend micro
2009-01-13 22:00:57 —-D—- D:\Program Files\Malwarebytes' Anti-Malware
2009-01-08 00:30:13 —-A—- D:\WINDOWS\system32\fnnwuke.dll
2009-01-07 23:24:02 —-D—- D:\Program Files\gjhgfhfjh
2009-01-07 23:16:52 —-SHD—- D:\Config.Msi
2009-01-07 21:57:57 —-D—- D:\VundoFix Backups
2009-01-07 21:57:57 —-A—- D:\VundoFix.txt
2009-01-07 14:20:08 —-AH—- D:\matt.txt
2009-01-07 10:18:33 —-A—- D:\WINDOWS\system32\geBqQjgE.dll
2009-01-07 10:17:20 —-A—- D:\WINDOWS\vmreg.dll
2009-01-07 10:17:20 —-A—- D:\WINDOWS\sysexplorer.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\syscert.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\spoolsystem.exe
2009-01-07 10:17:20 —-A—- D:\WINDOWS\reged.exe
2009-01-06 21:30:53 —-A—- D:\WINDOWS\system32\byXPFutR.dll
2009-01-06 21:30:27 —-D—- D:\Program Files\Microsoft Common
2009-01-06 21:15:11 —-D—- D:\matt
2009-01-06 21:15:03 —-D—- D:\HJT
2009-01-06 21:12:50 —-A—- D:\WINDOWS\system32\knhwrj.dll
2009-01-06 21:12:48 —-A—- D:\WINDOWS\system32\vwqbklae.dll
2009-01-06 21:10:29 —-A—- D:\WINDOWS\system32\pmnlmLBs.dll
2009-01-06 21:10:20 —-SH—- D:\WINDOWS\system32\fkphlmfb.ini
2009-01-06 21:10:15 —-A—- D:\WINDOWS\system32\bfmlhpkf.dll
2009-01-06 15:16:24 —-ASH—- D:\WINDOWS\system32\KSBIPqss.ini2
2009-01-06 15:16:24 —-ASH—- D:\WINDOWS\system32\KSBIPqss.ini
2009-01-06 15:11:54 —-A—- D:\WINDOWS\system32\winscenter.exe
2009-01-06 15:11:53 —-A—- D:\WINDOWS\sys.com
2009-01-06 15:11:25 —-D—- D:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
2009-01-06 15:11:24 —-A—- D:\Documents and Settings\All Users\Application Data\svhost.exe
2009-01-06 15:11:01 —-A—- D:\WINDOWS\system32\cbXQiFya.dll
2009-01-06 15:11:00 —-A—- D:\WINDOWS\Inoyoxeb.dll
2009-01-06 15:10:53 —-A—- D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
2009-01-06 15:10:51 —-A—- D:\WINDOWS\system32\rs32net.exe
2008-12-21 10:59:33 —-SHD—- D:\RECYCLER
2008-12-21 10:50:20 —-D—- D:\ComboFix
2008-12-21 10:36:39 —-A—- D:\ComboFix.txt
2008-12-19 17:35:44 —-HDC—- D:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-19 17:35:40 —-HDC—- D:\WINDOWS\$NtUninstallKB955839$
2008-12-19 17:33:59 —-HDC—- D:\WINDOWS\$NtUninstallKB954600$
2008-12-19 17:33:50 —-HDC—- D:\WINDOWS\$NtUninstallKB956802$
2008-12-19 14:05:45 —-D—- D:\WINDOWS\ERDNT
2008-12-19 09:26:04 —-A—- D:\avenger.txt
2008-12-19 09:12:14 —-D—- D:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-12-19 09:01:27 —-HD—- D:\WINDOWS\PIF
2008-12-19 08:53:12 —-D—- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-15 09:29:30 —-SHD—- D:\WINDOWS\CSC
2008-12-13 19:29:28 —-A—- D:\WINDOWS\system32\wmpns.dll
2008-12-13 18:34:56 —-A—- D:\WINDOWS\ntbtlog.txt
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\DL5
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\cap2
2008-12-13 18:33:20 —-D—- D:\WINDOWS\system32\ain
2008-12-13 18:15:50 —-D—- D:\WINDOWS\system32\whSLD02
2008-12-01 11:42:42 —-D—- D:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-19 15:34:39 —-D—- D:\Program Files\Citrix
2008-11-19 15:34:09 —-D—- D:\WINDOWS\Sun
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\javaws.exe
2008-11-19 15:29:39 —-A—- D:\WINDOWS\system32\deploytk.dll
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\javaw.exe
2008-11-19 15:29:38 —-A—- D:\WINDOWS\system32\java.exe
2008-11-19 15:29:25 —-D—- D:\Program Files\Java
2008-11-19 15:28:00 —-D—- D:\Documents and Settings\Owner\Application Data\Sun
2008-11-15 15:23:53 —-HDC—- D:\WINDOWS\$NtUninstallKB957097$
2008-11-15 15:23:43 —-HDC—- D:\WINDOWS\$NtUninstallKB955069$
======List of files/folders modified in the last 2 months======
2009-01-13 22:26:02 —-RD—- D:\Program Files
2009-01-13 22:25:53 —-D—- D:\WINDOWS\system32
2009-01-13 22:25:53 —-A—- D:\WINDOWS\system32\PerfStringBackup.INI
2009-01-13 22:25:27 —-D—- D:\WINDOWS\Temp
2009-01-13 22:01:00 —-D—- D:\WINDOWS\system32\drivers
2009-01-13 21:42:53 —-A—- D:\WINDOWS\SchedLgU.Txt
2009-01-08 01:13:13 —-D—- D:\Program Files\Mozilla Firefox
2009-01-08 00:40:54 —-D—- D:\WINDOWS\Prefetch
2009-01-08 00:39:11 —-RSHDC—- D:\WINDOWS\system32\dllcache
2009-01-08 00:39:03 —-D—- D:\WINDOWS\system32\CatRoot2
2009-01-08 00:39:02 —-A—- D:\WINDOWS\system32\svchost.exe
2009-01-07 23:16:52 —-SHD—- D:\WINDOWS\Installer
2009-01-07 11:50:23 —-D—- D:\Program Files\Adobe
2009-01-07 10:20:13 —-D—- D:\Documents and Settings\All Users\Application Data\avg8
2009-01-07 10:17:20 —-D—- D:\WINDOWS
2009-01-06 15:17:07 —-A—- D:\WINDOWS\system32\8357c3cd-.txt
2009-01-06 15:11:52 —-SD—- D:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-06 15:11:05 —-SD—- D:\WINDOWS\Tasks
2009-01-05 11:40:20 —-D—- D:\Program Files\Lx_cats
2008-12-22 16:15:42 —-HD—- D:\WINDOWS\inf
2008-12-21 13:22:44 —-SHD—- D:\System Volume Information
2008-12-21 13:22:44 —-D—- D:\WINDOWS\system32\Restore
2008-12-21 10:36:07 —-A—- D:\WINDOWS\system.ini
2008-12-21 10:35:43 —-D—- D:\WINDOWS\AppPatch
2008-12-21 10:35:43 —-D—- D:\Program Files\Common Files
2008-12-19 17:35:43 —-A—- D:\WINDOWS\imsins.BAK
2008-12-19 17:35:29 —-D—- D:\Program Files\Internet Explorer
2008-12-19 17:35:14 —-HD—- D:\WINDOWS\$hf_mig$
2008-12-19 17:24:56 —-SD—- D:\Documents and Settings\Owner\Application Data\Microsoft
2008-12-19 15:48:33 —-D—- D:\WINDOWS\system32\config
2008-12-13 19:29:36 —-A—- D:\WINDOWS\OEWABLog.txt
2008-12-13 19:28:19 —-D—- D:\Documents and Settings
2008-12-13 19:12:22 —-D—- D:\WINDOWS\Minidump
2008-12-13 18:39:21 —-D—- D:\temp
2008-12-13 01:40:02 —-A—- D:\WINDOWS\system32\mshtml.dll
2008-12-09 18:24:37 —-A—- D:\WINDOWS\system32\MRT.exe
2008-12-05 18:56:55 —-HD—- D:\$AVG8.VAULT$
2008-11-24 23:06:53 —-D—- D:\Program Files\MSN
2008-11-22 06:18:10 —-D—- D:\WINDOWS\Help
2008-11-16 18:57:23 —-D—- D:\WINDOWS\system32\QI02
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; D:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-04 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; D:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-04 26824]
R1 kbdhid;Keyboard HID Driver; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; D:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-03 8832]
R2 AvgTdiX;AVG Free8 Network Redirector; D:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-04 76040]
R2 mdmxsdk;mdmxsdk; D:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 rimmptsk;rimmptsk; D:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; D:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; D:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R3 BTKRNL;Bluetooth Bus Enumerator; D:\WINDOWS\system32\DRIVERS\btkrnl.sys [2006-11-15 862922]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; D:\WINDOWS\System32\Drivers\btwusb.sys [2006-11-15 67672]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; D:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; D:\WINDOWS\system32\drivers\CHDAud.sys [2007-12-18 732160]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; D:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HpqRemHid;HP Remote Control HID Device; D:\WINDOWS\system32\DRIVERS\HpqRemHid.sys [2007-07-11 7168]
R3 HSF_DPV;HSF_DPV; D:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-11-01 989696]
R3 HSFHWAZL;HSFHWAZL; D:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-11-01 211456]
R3 nv;nv; D:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-08-23 6844864]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; D:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-03-06 58752]
R3 nvnetbus;NVIDIA Network Bus Enumerator; D:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-03-06 19968]
R3 nvsmu;nvsmu; D:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 pfc;Padus ASPI Shell; D:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 sdbus;sdbus; D:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-08-04 67584]
R3 SynTP;Synaptics TouchPad Driver; D:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-09-14 213696]
R3 usbccgp;Microsoft USB Generic Parent Driver; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; D:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; D:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;USB Mass Storage Driver; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbvideo;USB Video Device (WDM); D:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-03 78464]
R3 winachsf;winachsf; D:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-11-01 731520]
S1 streamm;streamm; D:\WINDOWS\System32\drivers\streamm.sys []
S3 AR5416;Atheros AR5008 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-18 1312576]
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 HidUsb;Microsoft HID Class Driver; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 HpqKbFiltr;HpqKbFilter Driver; D:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TVICHW32;TVICHW32; \??\D:\WINDOWS\system32\DRIVERS\TVICHW32.SYS []
S3 usbprint;Microsoft USB PRINTER Class; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 Wdf01000;Wdf01000; D:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service; D:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-09-14 468768]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8emc;AVG Free8 E-mail Scanner; D:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-04 875288]
R2 avg8wd;AVG Free8 WatchDog; D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2008-11-19 152984]
R3 lxbx_device;lxbx_device; D:\WINDOWS\system32\lxbxcoms.exe [2005-01-06 462848]
S2 icf;ICF; D:\WINDOWS\system32\svchost.exe [2009-01-08 14336]
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 btwdins;Bluetooth Service; D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2006-11-11 266295]
S4 FCI;FCI; D:\WINDOWS\system32\svchost.exe [2009-01-08 14336]
S4 NVSvc;NVIDIA Display Driver Service; D:\WINDOWS\system32\nvsvc32.exe [2007-08-23 155716]
S4 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
—————–EOF—————–
info.txt logfile of random's system information tool 1.05 2009-01-13 22:26:05
======Uninstall list======
–>D:\Program Files\Conexant\SmartAudio\SETUP.EXE -U -ISmartAudio -SM=SMAUDIO.EXE,1801
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint Plus–>MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Acrobat.com–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>D:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player Plugin–>D:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
ArcSoft Software Suite–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{EE7C3A14-1D20-49F6-B903-491561076F0F}\SETUP.EXE" -l0x9
AVG Free 8.0–>D:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Broadcom 802.11 Wireless LAN Adapter–>"D:\Program Files\Broadcom\Broadcom 802.11\Driver\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="D:\Program Files\Broadcom\Broadcom 802.11\Driver"
Conexant HD Audio–>D:\Program Files\CONEXANT\CNXT_AUDIO_HDA\UIU32a.exe -U -I*.INF
Driver Genius Professional Edition 2007–>"D:\Program Files\Driver-Soft\DriverGenius\unins000.exe"
DriverAgent by TouchStone Software–>RunDll32.exe advpack.dll,LaunchINFSection driveragent_exe.inf,TVICHW32Remove
HDAUDIO Soft Data Fax Modem with SmartCP–>D:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_HERMOSA_HSF\UIU32m.exe -U -IHPQHER5m.inf
HijackThis 2.0.2–>"D:\HJT\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB915865)–>"D:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"D:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Integrated Module with Bluetooth wireless technology–>MsiExec.exe /X{84814E6B-2581-46EC-926A-823BD1C670F6}
HP Integrated Wireless LAN W400-W500 Driver–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{5C3DA2A1-03B2-44BD-B5AA-A44BD6E0C0C1}\setup.exe" -l0x9
Java™ 6 Update 10–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Lexmark 7100 Series Fax Solutions–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{316A75E3-039D-4BF4-AC29-3FF91E8555CD} /l1033 /z/U
Lexmark 7100 Series–>D:\WINDOWS\system32\spool\drivers\w32x86\3\lxbxUNST.EXE -NOLICENSE
Malwarebytes' Anti-Malware–>"D:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0–>D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Internationalized Domain Names Mitigation APIs–>"D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5–>"D:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.5)–>D:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN–>D:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
NVIDIA Drivers–>D:\WINDOWS\system32\nvudisp.exe UninstallGUI
PC Wizard 2008.1.84–>"D:\Program Files\PC Wizard 2008\unins000.exe"
Realtek AC'97 Audio–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
RICOH R5C853 Driver WXP Ver.1.01.05–>RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{59F6A514-9813-47A3-948C-8A155460CC2A}\setup.exe" -l0x9 anything
Security Update for Windows Internet Explorer 7 (KB938127)–>"D:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"D:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)–>"D:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"D:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"D:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)–>"D:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB911564)–>"D:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"D:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 6.4 (KB925398)–>"D:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Security Update for Windows Media Player 9 (KB936782)–>"D:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB890046)–>"D:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
Security Update for Windows XP (KB893756)–>"D:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896358)–>"D:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896423)–>"D:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
Security Update for Windows XP (KB896428)–>"D:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899587)–>"D:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
Security Update for Windows XP (KB899591)–>"D:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
Security Update for Windows XP (KB900725)–>"D:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901017)–>"D:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
Security Update for Windows XP (KB901214)–>"D:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
Security Update for Windows XP (KB902400)–>"D:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905414)–>"D:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB905749)–>"D:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB908519)–>"D:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911562)–>"D:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
Security Update for Windows XP (KB911927)–>"D:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
Security Update for Windows XP (KB913580)–>"D:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914388)–>"D:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
Security Update for Windows XP (KB914389)–>"D:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918118)–>"D:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
Security Update for Windows XP (KB918439)–>"D:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920213)–>"D:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920670)–>"D:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920683)–>"D:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
Security Update for Windows XP (KB920685)–>"D:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923191)–>"D:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923414)–>"D:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>D:\WINDOWS\system32\MacroMed\Flash\genuinst.exe D:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB923980)–>"D:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924270)–>"D:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
Security Update for Windows XP (KB924667)–>"D:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
Security Update for Windows XP (KB925902)–>"D:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926255)–>"D:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB926436)–>"D:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927779)–>"D:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
Security Update for Windows XP (KB927802)–>"D:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928255)–>"D:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
Security Update for Windows XP (KB928843)–>"D:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
Security Update for Windows XP (KB929123)–>"D:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
Security Update for Windows XP (KB930178)–>"D:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931261)–>"D:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
Security Update for Windows XP (KB931784)–>"D:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
Security Update for Windows XP (KB932168)–>"D:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
Security Update for Windows XP (KB933729)–>"D:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935839)–>"D:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB935840)–>"D:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
Security Update for Windows XP (KB936021)–>"D:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
Security Update for Windows XP (KB937894)–>"D:\WINDOWS\$NtUninstallKB937894$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)–>"D:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"D:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941693)–>"D:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943055)–>"D:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943460)–>"D:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
Security Update for Windows XP (KB943485)–>"D:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944338-v2)–>"D:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB944653)–>"D:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
Security Update for Windows XP (KB945553)–>"D:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946026)–>"D:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"D:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB948590)–>"D:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950749)–>"D:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"D:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"D:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"D:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"D:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"D:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"D:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"D:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)–>"D:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)–>"D:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"D:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"D:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"D:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"D:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"D:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"D:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"D:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"D:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"D:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"D:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Spyware Guard 2008–>D:\Program Files\Spyware Guard 2008\uninstall.exe
Synaptics Pointing Device Driver–>rundll32.exe "D:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Texas Instruments PCIxx21/x515/xx12 drivers.–>D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A} /l1033
Update for Windows XP (KB894391)–>"D:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
Update for Windows XP (KB898461)–>"D:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB900485)–>"D:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
Update for Windows XP (KB908531)–>"D:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
Update for Windows XP (KB910437)–>"D:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
Update for Windows XP (KB911280)–>"D:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
Update for Windows XP (KB916595)–>"D:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
Update for Windows XP (KB920872)–>"D:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
Update for Windows XP (KB922582)–>"D:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
Update for Windows XP (KB927891)–>"D:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
Update for Windows XP (KB930916)–>"D:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
Update for Windows XP (KB932823-v3)–>"D:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
Update for Windows XP (KB938828)–>"D:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
Update for Windows XP (KB951072-v2)–>"D:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"D:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Windows Installer 3.1 (KB893803)–>"D:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Internet Explorer 7–>"D:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows XP Hotfix - KB873339–>D:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
Windows XP Hotfix - KB885835–>D:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
Windows XP Hotfix - KB885836–>D:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
Windows XP Hotfix - KB886185–>D:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
Windows XP Hotfix - KB887472–>D:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
Windows XP Hotfix - KB888302–>D:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
Windows XP Hotfix - KB890859–>"D:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
Windows XP Hotfix - KB891781–>D:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
=====HijackThis Backups=====
O4 - HKLM\..\Run: [Qgoqoxi] rundll32.exe "D:\WINDOWS\Inoyoxeb.dll",e
O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] D:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogin.exe
O4 - HKLM\..\Run: [jsg8jfgfdfhfhf] D:\DOCUME~1\Owner\LOCALS~1\Temp\winlogun.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O4 - HKLM\..\Run: [spywareguard] D:\Program Files\Spyware Guard 2008\spywareguard.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] D:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - AppInit_DLLs: knhwrj.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - D:\WINDOWS\system32\rwhbfb873unjdfdg.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {c5bf49a2-94f3-42bd-f434-3604812c8955} - (no file)
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {c5af42a3-94f3-42bd-f634-3604832c897d} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [887407b3] rundll32.exe "D:\WINDOWS\system32\bfmlhpkf.dll",b
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {a17474b7-0200-496a-9a5e-31532900f0fd} - D:\WINDOWS\system32\ssqPIBSK.dll
O21 - SSODL: InternetConnection - {9BB113B3-2F6C-48D2-9AB7-75BEA0014FBD} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: ieModule - {B36D696C-C331-4E30-AA93-4BE550E7C75A} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O4 - HKLM\..\Run: [LSA Shellu] D:\Documents and Settings\Owner\lsass.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {31697D4A-AEC7-4BCE-8BF0-3FEAEC5C8FE2} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: D:\WINDOWS\system32\gseb37dkjgfgf.dll - {c5af42a3-94f3-42bd-f634-3604832c897d} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - D:\WINDOWS\system32\gseb37dkjgfgf.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O4 - HKCU\..\Run: [rs32net] D:\WINDOWS\System32\rs32net.exe
O20 - Winlogon Notify: opnnnkax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O21 - SSODL: InternetConnection - {EEED702B-2A45-4F66-8076-6FAE05CF126B} - D:\Documents and Settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\acgiqunxap.dll
O2 - BHO: (no name) - {C6403D33-965C-452D-A8F3-2FA92C6446B9} - D:\WINDOWS\system32\ssqPIBSK.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O22 - SharedTaskScheduler: hjse7fw3jnefi7wejfndd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - (no file)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\opnnnKax.dll
O2 - BHO: (no name) - {E66D37F9-1D81-4C9C-ABDE-EE4407A17CC0} - D:\WINDOWS\system32\ssqPIBSK.dll
O20 - Winlogon Notify: opnnnKax - D:\WINDOWS\SYSTEM32\opnnnKax.dll
O2 - BHO: (no name) - {cfdf0f20-4944-48a6-9370-d8075facae40} - D:\WINDOWS\system32\ssqPIBSK.dll (file missing)
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke32.dll
O4 - HKLM\..\Run: [CTEMON.EXE] "" /h
O20 - Winlogon Notify: fnnwuke - fnnwuke32.dll (file missing)
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrssc.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://bontrafic.org/s/in.cgi?3&key;=door
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: FCI - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O20 - Winlogon Notify: fnnwuke - D:\WINDOWS\SYSTEM32\fnnwuke.dll
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
O23 - Service: ICF (icf) - Unknown owner - D:\WINDOWS\system32\svchost.exe:ext.exe
======Security center information======
AV: AVG Anti-Virus Free (outdated)
System event log
Computer Name: OWNER-FC0C2179D
Event Code: 7035
Message: The Fast User Switching Compatibility service was successfully sent a start control.
Record Number: 12115
Source Name: Service Control Manager
Time Written: 20081224103840.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: OWNER-FC0C2179D
Event Code: 7036
Message: The Terminal Services service entered the running state.
Record Number: 12114
Source Name: Service Control Manager
Time Written: 20081224103840.000000-300
Event Type: information
User:
Computer Name: OWNER-FC0C2179D
Event Code: 7026
Message: The following boot-start or system-start driver(s) failed to load:
ohci1394
Record Number: 12113
Source Name: Service Control Manager
Time Written: 20081224103836.000000-300
Event Type: error
User:
Computer Name: OWNER-FC0C2179D
Event Code: 4201
Message: The system detected that network adapter HP WLAN 802.11a/b/g W500 - Packet Scheduler Miniport was connected to the network,
and has initiated normal operation over the network adapter.
Record Number: 12112
Source Name: Tcpip
Time Written: 20081224103812.000000-300
Event Type: information
User:
Computer Name: OWNER-FC0C2179D
Event Code: 26
Message: Application popup: : Machine Check: Regs
Record Number: 12111
Source Name: Application Popup
Time Written: 20081224103812.000000-300
Event Type: information
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 104 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=6802
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
—————–EOF—————–