Thank you for your help. Here are the things you requested:
Diagnostic Report (1.9.0011.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A
Windows Product Key: *****-*****-GDTF9-B9QW7-BBVH6
Windows Product Key Hash: 5kEO8pH8rfJkr7/tAGdnxv6zALo=
Windows Product ID: 76487-OEM-2211906-00806
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010100.3.0.med
ID: {CA8B3254-ED1C-4331-B077-6E7517183AEF}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.69.2
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional Edition 2003 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{CA8B3254-ED1C-4331-B077-6E7517183AEF}</UGUID><Version>1.9.0011.0</Version><OS>5.1.2600.2.00010100.3.0.med</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-BBVH6</PKey><PID>76487-OEM-2211906-00806</PID><PIDType>2</PIDType><SID>S-1-5-21-3668628768-4077671946-321310473</SID><SYSTEM><Manufacturer>Gateway</Manufacturer><Model>GT4024</Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies, LTD</Manufacturer><Version>W7248AG2 1.0K</Version><SMBIOSVersion major="2" minor="4"/><Date>20060516000000.000000+000</Date><SLPBIOS>Gateway,Gateway,Gateway,Gateway</SLPBIOS></BIOS><HWID>EB9F375F0184C06C</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Gateway</name><model>GT4024</model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91110409-6000-11D3-8CFE-0150048383C9}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional Edition 2003</Name><Ver>11</Ver><Val>5BD7BCCE41315DE</Val><Hash>jCWGKYHnRpjo3ohGxhYeQTLV2SM=</Hash><Pid>70145-751-4127124-57328</Pid><PidType>1</PidType></Product></Products><Applications><App Id="15" Version="11" Result="100"/><App Id="16" Version="11" Result="100"/><App Id="18" Version="11" Result="100"/><App Id="19" Version="11" Result="100"/><App Id="1A" Version="11" Result="100"/><App Id="1B" Version="11" Result="100"/><App Id="44" Version="11" Result="100"/></Applications></Office></Software></GenuineResults>
Licensing Data-->
N/A
HWID Data-->
N/A
OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 1CBE0:emachines inc|1CBE0:Gateway, Inc|1E840:Gateway, Inc
Marker string from OEMBIOS.DAT: Gateway,Gateway,Gateway,Gateway
OEM Activation 2.0 Data-->
N/A
Logfile of random's system information tool 1.06 (written by random/random)
Run by Yancy at 2009-11-07 17:40:50
Microsoft Windows XP Professional Service Pack 3
System drive C: has 222 GB (95%) free of 234 GB
Total RAM: 894 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:40:59 PM, on 11/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Yancy\My Documents\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Yancy.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.gateway.com/g/startpage.html ... P&M=GT4024R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/g/startpage.html ... P&M=GT4024R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
F2 - REG:system.ini: Shell=Explorer.exe logon.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [gabadivaj] Rundll32.exe "c:\windows\system32\higudolo.dll",a
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: padamori.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL c:\windows\system32\forobevo.dll c:\windows\system32\zivebire.dll c:\windows\system32\higudolo.dll
O21 - SSODL: newanorek - {e5f11f17-d410-47e9-a701-a4bc8fa7f37f} - c:\windows\system32\zivebire.dll (file missing)
O21 - SSODL: dezurerur - {8cfb50a6-9237-4535-be81-062010b66e68} - c:\windows\system32\higudolo.dll
O22 - SharedTaskScheduler: mujuzedij - {e5f11f17-d410-47e9-a701-a4bc8fa7f37f} - c:\windows\system32\zivebire.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {8cfb50a6-9237-4535-be81-062010b66e68} - c:\windows\system32\higudolo.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 6286 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\anoidpnj.job
C:\WINDOWS\tasks\blhqwbuv.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2009-10-24 1471768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-10-15 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll [2009-10-15 762864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-10-15 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - c:\windows\system32\BAE.dll [2006-02-01 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-10-15 256112]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-10-16 1119488]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-15 169984]
"readericon"=C:\Program Files\Digital Media Reader\readericon45G.exe [2005-12-09 139264]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-01-11 15961088]
"CHotkey"=C:\WINDOWS\zHotkey.exe [2004-12-08 550912]
"Reminder"=C:\WINDOWS\Creator\Remind_XP.exe [2005-02-25 966656]
"Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE [2002-09-14 212992]
"MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe [2005-08-12 1121792]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2009-10-25 2010904]
"gabadivaj"=c:\windows\system32\higudolo.dll [2009-08-07 90112]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-10-15 68856]
"AOL Fast Start"=C:\Program Files\America Online 9.0\AOL.EXE -b []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="padamori.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL c:\windows\system32\forobevo.dll c:\windows\system32\zivebire.dll c:\windows\system32\higudolo.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-01-25 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
newanorek - {e5f11f17-d410-47e9-a701-a4bc8fa7f37f} - c:\windows\system32\zivebire.dll []
dezurerur - {8cfb50a6-9237-4535-be81-062010b66e68} - c:\windows\system32\higudolo.dll [2009-08-07 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
mujuzedij - {e5f11f17-d410-47e9-a701-a4bc8fa7f37f} - c:\windows\system32\zivebire.dll []
mujuzedij - {8cfb50a6-9237-4535-be81-062010b66e68} - c:\windows\system32\higudolo.dll [2009-08-07 90112]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
zazovuba.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1255594202\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1255594202\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Explorer"
"C:\WINDOWS\system32\logonui.exe"="C:\WINDOWS\system32\logonui.exe:*:Enabled:logonui"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe:*:Enabled:GoogleDesktop"
"C:\Program Files\Digital Media Reader\readericon45G.exe"="C:\Program Files\Digital Media Reader\readericon45G.exe:*:Enabled:readericon45G"
"C:\WINDOWS\RTHDCPL.exe"="C:\WINDOWS\RTHDCPL.exe:*:Enabled:RTHDCPL"
"C:\Program Files\BigFix\bigfix.exe"="C:\Program Files\BigFix\bigfix.exe:*:Enabled:bigfix"
"C:\WINDOWS\system32\lsass.exe"="C:\WINDOWS\system32\lsass.exe:*:Enabled:lsass"
"C:\WINDOWS\system32\dllhost.exe"="C:\WINDOWS\system32\dllhost.exe:*:Enabled:dllhost"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-11-07 17:40:50 ----D---- C:\rsit
2009-11-07 17:38:01 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2009-11-02 19:01:02 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-02 19:01:02 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-10-31 11:58:05 ----D---- C:\Program Files\Trend Micro
2009-10-31 10:02:10 ----D---- C:\Documents and Settings\Yancy\Application Data\Malwarebytes
2009-10-29 04:13:00 ----SH---- C:\WINDOWS\system32\yakikeru.dll
2009-10-29 03:49:56 ----SH---- C:\WINDOWS\system32\vuhofafa.dll
2009-10-29 03:26:52 ----SH---- C:\WINDOWS\system32\fineloto.dll
2009-10-29 03:03:49 ----SH---- C:\WINDOWS\system32\fetezeme.dll
2009-10-26 22:08:53 ----D---- C:\WINDOWS\Minidump
2009-10-24 22:43:08 ----HD---- C:\$AVG
2009-10-24 22:42:40 ----D---- C:\Documents and Settings\All Users\Application Data\avg9
2009-10-24 22:41:56 ----D---- C:\WINDOWS\SxsCaPendDel
2009-10-24 20:25:59 ----D---- C:\Program Files\NOS
2009-10-22 05:27:18 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-10-20 21:36:11 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-10-20 21:35:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-10-20 21:15:55 ----A---- C:\WINDOWS\system32\CNMVS75.DLL
2009-10-20 21:15:54 ----A---- C:\WINDOWS\system32\CNMLM75.DLL
2009-10-20 21:15:53 ----A---- C:\WINDOWS\system32\CNMCP75.exe
2009-10-20 21:15:51 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonBJ
2009-10-19 21:35:51 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-19 21:35:50 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-10-19 21:35:24 ----D---- C:\Program Files\Windows Media Connect 2
2009-10-19 21:35:08 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-10-19 21:34:19 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-10-19 21:33:56 ----D---- C:\WINDOWS\system32\LogFiles
2009-10-19 21:33:51 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-10-19 21:33:19 ----HDC---- C:\WINDOWS\$NtUninstallKB925766$
2009-10-19 10:01:03 ----A---- C:\WINDOWS\system32\wmv9vcm.dll
2009-10-19 10:01:02 ----D---- C:\Program Files\im
2009-10-18 22:30:33 ----D---- C:\Documents and Settings\Yancy\Application Data\Adobe
2009-10-18 22:27:49 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-10-15 18:17:49 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-10-15 18:17:36 ----D---- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
2009-10-15 18:17:26 ----D---- C:\Program Files\AVG
2009-10-15 08:06:35 ----D---- C:\Program Files\SetupInfo
2009-10-15 08:06:31 ----D---- C:\Program Files\BigAntSoft-OLD
2009-10-15 07:56:59 ----D---- C:\Program Files\ChartNet
2009-10-15 07:48:49 ----D---- C:\WINDOWS\system32\appmgmt
2009-10-15 06:17:08 ----D---- C:\WINDOWS\Sun
2009-10-15 05:50:14 ----A---- C:\WINDOWS\msoffice.ini
2009-10-15 05:41:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2009-10-15 05:24:13 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-10-15 05:23:58 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-10-15 05:23:55 ----D---- C:\Program Files\MSXML 4.0
2009-10-15 05:22:11 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-10-15 05:22:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-10-15 05:21:44 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-10-15 05:21:30 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-10-15 05:21:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-10-15 05:21:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-10-15 05:20:50 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-10-15 05:20:39 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-10-15 05:20:18 ----HDC---- C:\WINDOWS\$NtUninstallKB974455$
2009-10-15 05:18:58 ----HDC---- C:\WINDOWS\$NtUninstallKB953295$
2009-10-15 05:18:22 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-10-15 05:18:07 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2009-10-15 05:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-10-15 05:17:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973768$
2009-10-15 05:16:06 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-10-15 05:15:53 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2009-10-15 05:15:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-10-15 05:15:29 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-10-15 05:15:16 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-10-15 05:15:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-10-15 05:14:47 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-10-15 05:14:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-10-15 05:14:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-10-15 05:14:05 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-10-15 05:13:53 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-10-15 05:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-10-15 05:09:04 ----D---- C:\WINDOWS\system32\XPSViewer
2009-10-15 05:09:00 ----D---- C:\Program Files\MSBuild
2009-10-15 05:08:53 ----D---- C:\Program Files\Reference Assemblies
2009-10-15 05:08:26 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-10-15 05:08:26 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-10-15 05:08:26 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-10-15 05:08:25 ----D---- C:\94a905a7a493a35b1b2d4d7d28
2009-10-15 05:03:59 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-10-15 05:03:47 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-10-15 05:03:35 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-10-15 05:03:23 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-10-15 05:03:11 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-10-15 05:02:58 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-10-15 05:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-10-15 05:02:23 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-10-15 05:02:08 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-10-15 05:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-10-15 05:01:45 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-10-15 05:01:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-10-15 05:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-10-15 05:01:09 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-10-15 05:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-10-15 05:00:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-10-15 05:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-10-15 05:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-10-15 05:00:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-10-15 05:00:01 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-10-15 04:59:50 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-10-15 04:59:38 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-10-15 04:59:27 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-10-15 04:59:15 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-10-15 04:59:01 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-10-15 04:58:49 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-10-15 04:58:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-10-15 04:58:15 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-10-15 04:45:19 ----D---- C:\Documents and Settings\Yancy\Application Data\AOL
2009-10-15 04:39:48 ----D---- C:\Documents and Settings\Yancy\Application Data\Mozilla
2009-10-15 04:39:40 ----D---- C:\Program Files\Mozilla Firefox
2009-10-15 04:36:18 ----D---- C:\Documents and Settings\Yancy\Application Data\Macromedia
2009-10-15 04:33:49 ----D---- C:\Documents and Settings\Yancy\Application Data\Google
2009-10-15 04:33:19 ----D---- C:\Documents and Settings\Yancy\Application Data\McAfee.com Personal Firewall
2009-10-15 04:33:05 ----ASH---- C:\Documents and Settings\Yancy\Application Data\desktop.ini
2009-10-15 04:33:02 ----SD---- C:\Documents and Settings\Yancy\Application Data\Microsoft
2009-10-15 04:33:02 ----D---- C:\Documents and Settings\Yancy\Application Data\You've Got Pictures Screensaver
2009-10-15 04:33:02 ----D---- C:\Documents and Settings\Yancy\Application Data\SampleView
2009-10-15 04:33:02 ----D---- C:\Documents and Settings\Yancy\Application Data\Identities
2009-10-15 04:32:01 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-10-15 04:26:51 ----D---- C:\WINDOWS\Prefetch
2009-10-15 04:20:54 ----D---- C:\WINDOWS\system32\en-us
2009-10-15 04:20:53 ----D---- C:\WINDOWS\system32\scripting
2009-10-15 04:20:52 ----D---- C:\WINDOWS\system32\en
2009-10-15 04:20:52 ----D---- C:\WINDOWS\l2schemas
2009-10-15 04:20:51 ----D---- C:\WINDOWS\system32\bits
2009-10-15 04:17:47 ----D---- C:\WINDOWS\ServicePackFiles
2009-10-15 04:15:08 ----D---- C:\WINDOWS\network diagnostic
2009-10-15 04:10:47 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-10-15 03:51:16 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-10-15 03:47:46 ----D---- C:\WINDOWS\system32\PreInstall
2009-10-15 03:47:44 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-10-15 03:47:03 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2009-10-15 03:44:48 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-10-15 03:41:14 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-10-15 03:36:28 ----SHD---- C:\RECYCLER
2009-10-15 03:35:42 ----D---- C:\WINDOWS\system32\Lang
2009-10-15 03:35:26 ----A---- C:\WINDOWS\ModemLog_Agere Systems PCI-SV92PP Soft Modem.txt
2009-10-15 03:30:22 ----HDC---- C:\WINDOWS\$NtUninstallKB912919$
2009-10-15 03:30:05 ----HDC---- C:\WINDOWS\$NtUninstallKB908519$
2009-10-15 03:29:45 ----HDC---- C:\WINDOWS\$NtUninstallKB912067$
2009-10-15 03:29:24 ----HDC---- C:\WINDOWS\$NtUninstallKB912024$
2009-10-15 03:28:44 ----HDC---- C:\WINDOWS\$NtUninstallKB910437$
2009-10-15 03:28:22 ----HDC---- C:\WINDOWS\$NtUninstallKB905915$
2009-10-15 03:28:03 ----HDC---- C:\WINDOWS\$NtUninstallKB904706$
2009-10-15 03:27:47 ----HDC---- C:\WINDOWS\$NtUninstallKB896424$
2009-10-15 03:27:26 ----HDC---- C:\WINDOWS\$NtUninstallKB896256$
2009-10-15 03:23:10 ----HDC---- C:\WINDOWS\$NtUninstallKB910728$
2009-10-15 03:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB911564$
2009-10-15 03:21:25 ----HDC---- C:\WINDOWS\$NtUninstallKB911565$
2009-10-15 03:21:02 ----HDC---- C:\WINDOWS\$NtUninstallKB910393$
2009-10-15 03:16:40 ----D---- C:\Program Files\McAfee
2009-10-15 03:16:40 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2009-10-15 03:15:45 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee.com
2009-10-15 03:15:19 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2009-10-15 03:13:31 ----D---- C:\Program Files\gtw_logo
2009-10-15 03:13:31 ----A---- C:\WINDOWS\system32\jesterss.dll
2009-10-15 03:13:15 ----A---- C:\WINDOWS\POWERCFG.EXE
2009-10-15 03:12:34 ----D---- C:\Program Files\Microsoft Money 2006
2009-10-15 03:11:46 ----D---- C:\Program Files\Microsoft Works
2009-10-15 03:11:25 ----D---- C:\Program Files\MSN Encarta Plus
2009-10-15 03:11:12 ----D---- C:\Program Files\Common Files\Nullsoft
2009-10-15 03:11:00 ----A---- C:\WINDOWS\unvise32qt.exe
2009-10-15 03:10:55 ----D---- C:\WINDOWS\system32\QuickTime
2009-10-15 03:10:55 ----D---- C:\Program Files\QuickTime
2009-10-15 03:10:55 ----D---- C:\Documents and Settings\All Users\Application Data\QuickTime
2009-10-15 03:10:50 ----D---- C:\My Music
2009-10-15 03:10:47 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-10-15 03:10:45 ----D---- C:\Program Files\Real
2009-10-15 03:10:45 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-10-15 03:10:45 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-10-15 03:10:44 ----D---- C:\Program Files\Common Files\Real
2009-10-15 03:10:44 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-10-15 03:10:37 ----A---- C:\WINDOWS\system32\aamd532.dll
2009-10-15 03:10:36 ----A---- C:\WINDOWS\system32\SimpleRegistry.dll
2009-10-15 03:10:33 ----D---- C:\Program Files\Viewpoint
2009-10-15 03:10:33 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-10-15 03:10:32 ----D---- C:\Documents and Settings\All Users\Application Data\Pure Networks
2009-10-15 03:10:29 ----D---- C:\Program Files\Pure Networks
2009-10-15 03:10:22 ----D---- C:\Program Files\Common Files\AolCoach
2009-10-15 03:10:01 ----D---- C:\Documents and Settings\All Users\Application Data\AOL
2009-10-15 03:09:53 ----D---- C:\Program Files\Common Files\AOL
2009-10-15 03:09:44 ----D---- C:\Program Files\Common Files\Roxio Shared
2009-10-15 03:09:34 ----D---- C:\Documents and Settings\All Users\Application Data\Napster
2009-10-15 03:09:30 ----D---- C:\Program Files\Napster
2009-10-15 03:09:10 ----A---- C:\WINDOWS\zHotkey.exe
2009-10-15 03:09:10 ----A---- C:\WINDOWS\ShowWnd.exe
2009-10-15 03:09:10 ----A---- C:\WINDOWS\PIC.dll
2009-10-15 03:09:10 ----A---- C:\WINDOWS\PatchWnd.exe
2009-10-15 03:09:10 ----A---- C:\WINDOWS\HKNTDLL.dll
2009-10-15 03:09:10 ----A---- C:\WINDOWS\HIDMNT.dll
2009-10-15 03:08:25 ----D---- C:\Program Files\Microsoft Digital Image 2006
2009-10-15 03:08:10 ----D---- C:\Program Files\Common Files\Adobe
2009-10-15 03:08:10 ----A---- C:\WINDOWS\system32\atl71.dll
2009-10-15 03:07:58 ----D---- C:\Program Files\Adobe
2009-10-15 03:07:57 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-15 03:07:47 ----A---- C:\WINDOWS\system32\Marker32.exe
2009-10-15 03:07:35 ----A---- C:\WINDOWS\system32\javaws.exe
2009-10-15 03:07:35 ----A---- C:\WINDOWS\system32\javaw.exe
2009-10-15 03:07:35 ----A---- C:\WINDOWS\system32\java.exe
2009-10-15 03:07:12 ----D---- C:\Program Files\Java
2009-10-15 03:07:11 ----D---- C:\Program Files\Common Files\Java
2009-10-15 03:05:49 ----A---- C:\WINDOWS\system32\bae.dll
2009-10-15 03:05:43 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2009-10-15 03:05:43 ----A---- C:\WINDOWS\system32\ChCfg.exe
2009-10-15 03:05:24 ----D---- C:\WINDOWS\system32\RTCOM
2009-10-15 03:05:21 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-10-15 03:04:48 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
2009-10-15 03:04:44 ----A---- C:\WINDOWS\SoundMan.exe
2009-10-15 03:04:44 ----A---- C:\WINDOWS\RtlUpd.exe
2009-10-15 03:04:41 ----A---- C:\WINDOWS\RTLCPL.exe
2009-10-15 03:04:38 ----A---- C:\WINDOWS\RTHDCPL.exe
2009-10-15 03:04:37 ----A---- C:\WINDOWS\MicCal.exe
2009-10-15 03:04:35 ----D---- C:\Program Files\Realtek
2009-10-15 03:04:35 ----A---- C:\WINDOWS\alcwzrd.exe
2009-10-15 03:04:35 ----A---- C:\WINDOWS\Alcmtr.exe
2009-10-15 03:04:30 ----A---- C:\WINDOWS\RtlExUpd.dll
2009-10-15 03:04:19 ----A---- C:\WINDOWS\BigFixClientOverride.dll
2009-10-15 03:04:18 ----D---- C:\Program Files\BigFix
2009-10-15 03:03:58 ----D---- C:\Program Files\Digital Media Reader
2009-10-15 03:03:50 ----D---- C:\WINDOWS\Downloaded Installations
2009-10-15 03:03:09 ----D---- C:\Program Files\Common Files\ATI Technologies
2009-10-15 02:59:22 ----D---- C:\Program Files\ATI Technologies
2009-10-15 02:57:16 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-10-15 02:57:11 ----A---- C:\WINDOWS\ODBC.INI
2009-10-15 02:57:07 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-10-15 02:56:43 ----D---- C:\Program Files\Microsoft ActiveSync
2009-10-15 02:56:41 ----D---- C:\Program Files\Common Files\DESIGNER
2009-10-15 02:56:30 ----D---- C:\WINDOWS\SHELLNEW
2009-10-15 02:56:16 ----D---- C:\Program Files\Microsoft.NET
2009-10-15 02:56:16 ----D---- C:\Program Files\Microsoft Office
2009-10-15 02:55:53 ----RHD---- C:\MSOCache
2009-10-15 02:55:43 ----D---- C:\Program Files\Google
2009-10-15 02:51:04 ----HD---- C:\Program Files\InstallShield Installation Information
2009-10-15 02:51:04 ----D---- C:\Program Files\CyberLink
2009-10-15 02:51:01 ----D---- C:\Program Files\Common Files\New Boundary
2009-10-15 02:51:01 ----D---- C:\Program Files\Common Files\InstallShield
2009-10-15 02:51:01 ----D---- C:\Documents and Settings\All Users\Application Data\Prism Deploy
2009-10-15 02:45:49 ----A---- C:\WINDOWS\system32\hccoin.dll
2009-10-15 02:43:21 ----SHD---- C:\System Volume Information
2009-10-15 01:42:02 ----D---- C:\WINDOWS\creator
2009-10-15 01:40:41 ----D---- C:\WINDOWS\SMINST
2009-10-15 01:40:41 ----A---- C:\WINDOWS\agrsmdel.exe
2009-10-15 01:40:38 ----D---- C:\WINDOWS\I386
2009-10-15 01:40:20 ----A---- C:\WINDOWS\system32\wowfaxui.dll
2009-10-15 01:40:17 ----A---- C:\WINDOWS\system32\wowfax.dll
2009-10-15 01:40:06 ----A---- C:\WINDOWS\system32\usrvpa.dll
2009-10-15 01:40:02 ----A---- C:\WINDOWS\system32\usrvoica.dll
2009-10-15 01:39:59 ----A---- C:\WINDOWS\system32\usrv80a.dll
2009-10-15 01:39:55 ----A---- C:\WINDOWS\system32\usrv42a.dll
2009-10-15 01:39:52 ----A---- C:\WINDOWS\system32\usrsvpia.dll
2009-10-15 01:39:48 ----A---- C:\WINDOWS\system32\usrshuta.exe
2009-10-15 01:39:45 ----A---- C:\WINDOWS\system32\usrsdpia.dll
2009-10-15 01:39:41 ----A---- C:\WINDOWS\system32\usrrtosa.dll
2009-10-15 01:39:38 ----A---- C:\WINDOWS\system32\usrprbda.exe
2009-10-15 01:39:34 ----A---- C:\WINDOWS\system32\usrmlnka.exe
2009-10-15 01:39:31 ----A---- C:\WINDOWS\system32\usrlbva.dll
2009-10-15 01:39:27 ----A---- C:\WINDOWS\system32\usrfaxa.dll
2009-10-15 01:39:24 ----A---- C:\WINDOWS\system32\usrdtea.dll
2009-10-15 01:39:21 ----A---- C:\WINDOWS\system32\usrdpa.dll
2009-10-15 01:39:17 ----A---- C:\WINDOWS\system32\usrcoina.dll
2009-10-15 01:39:14 ----A---- C:\WINDOWS\system32\usrcntra.dll
2009-10-15 01:39:13 ----A---- C:\WINDOWS\system32\usbui.dll
2009-10-15 01:39:09 ----A---- C:\WINDOWS\system32\tsbyuv.dll
2009-10-15 01:39:05 ----A---- C:\WINDOWS\system32\streamci.dll
2009-10-15 01:39:05 ----A---- C:\WINDOWS\system32\storprop.dll
2009-10-15 01:39:02 ----A---- C:\WINDOWS\system32\sprio800.dll
2009-10-15 01:38:59 ----A---- C:\WINDOWS\system32\sprio600.dll
2009-10-15 01:38:53 ----A---- C:\WINDOWS\system32\spnike.dll
2009-10-15 01:38:46 ----A---- C:\WINDOWS\system32\pjlmon.dll
2009-10-15 01:38:46 ----A---- C:\WINDOWS\system32\pid.dll
2009-10-15 01:38:43 ----A---- C:\WINDOWS\system32\paqsp.dll
2009-10-15 01:38:37 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-10-15 01:38:35 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-10-15 01:38:29 ----A---- C:\WINDOWS\system32\msyuv.dll
2009-10-15 01:38:20 ----A---- C:\WINDOWS\system32\mdwmdmsp.dll
2009-10-15 01:38:17 ----A---- C:\WINDOWS\system32\iyuv_32.dll
2009-10-15 01:38:14 ----A---- C:\WINDOWS\system32\hid.dll
2009-10-15 01:38:11 ----A---- C:\WINDOWS\system32\dvdplay.exe
2009-10-15 01:37:15 ----A---- C:\WINDOWS\system32\dmutil.dll
2009-10-15 01:37:12 ----A---- C:\WINDOWS\system32\cnbjmon.dll
======List of files/folders modified in the last 1 months======
2009-11-07 17:38:04 ----D---- C:\WINDOWS\system32\CatRoot2
2009-11-07 17:35:46 ----D---- C:\WINDOWS
2009-11-07 17:35:43 ----A---- C:\WINDOWS\win.ini
2009-11-07 17:35:41 ----D---- C:\WINDOWS\Temp
2009-11-07 09:32:35 ----D---- C:\WINDOWS\system32
2009-11-06 18:20:25 ----D---- C:\WINDOWS\Registration
2009-11-06 18:19:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-11-05 18:27:34 ----SD---- C:\WINDOWS\Tasks
2009-11-02 19:19:02 ----D---- C:\Program Files\Common Files\Services
2009-11-02 19:01:04 ----D---- C:\WINDOWS\system32\drivers
2009-11-02 19:01:02 ----RD---- C:\Program Files
2009-11-01 14:35:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-30 06:45:00 ----A---- C:\WINDOWS\setuplog.txt
2009-10-27 15:21:27 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-26 22:10:27 ----D---- C:\WINDOWS\system32\Restore
2009-10-24 22:42:13 ----SHD---- C:\WINDOWS\Installer
2009-10-24 22:42:12 ----D---- C:\WINDOWS\WinSxS
2009-10-24 22:41:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-22 05:27:27 ----HD---- C:\WINDOWS\inf
2009-10-22 05:27:27 ----A---- C:\WINDOWS\imsins.BAK
2009-10-20 21:40:35 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-10-20 05:27:24 ----D---- C:\WINDOWS\Help
2009-10-19 22:42:46 ----D---- C:\WINDOWS\system32\CatRoot
2009-10-19 21:37:19 ----D---- C:\WINDOWS\ehome
2009-10-19 21:35:24 ----D---- C:\Program Files\Windows Media Player
2009-10-19 10:09:14 ----RASH---- C:\boot.ini
2009-10-15 10:25:47 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-15 08:03:07 ----D---- C:\WINDOWS\system
2009-10-15 07:45:01 ----RSD---- C:\WINDOWS\Fonts
2009-10-15 06:01:41 ----RSD---- C:\WINDOWS\assembly
2009-10-15 05:51:56 ----D---- C:\Program Files\Common Files
2009-10-15 05:34:59 ----D---- C:\WINDOWS\system32\wbem
2009-10-15 05:34:59 ----D---- C:\WINDOWS\AppPatch
2009-10-15 05:21:42 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-15 05:14:49 ----D---- C:\Program Files\Outlook Express
2009-10-15 05:08:36 ----D---- C:\WINDOWS\system32\spool
2009-10-15 05:07:10 ----D---- C:\Program Files\Internet Explorer
2009-10-15 04:59:40 ----D---- C:\Program Files\Messenger
2009-10-15 04:33:14 ----A---- C:\WINDOWS\OEWABLog.txt
2009-10-15 04:33:01 ----D---- C:\Documents and Settings
2009-10-15 04:26:22 ----D---- C:\WINDOWS\system32\Setup
2009-10-15 04:26:22 ----D---- C:\Program Files\Common Files\System
2009-10-15 04:25:38 ----D---- C:\WINDOWS\security
2009-10-15 04:21:07 ----D---- C:\WINDOWS\system32\inetsrv
2009-10-15 04:21:07 ----D---- C:\WINDOWS\ime
2009-10-15 04:20:54 ----D---- C:\WINDOWS\system32\usmt
2009-10-15 04:20:51 ----D---- C:\WINDOWS\PeerNet
2009-10-15 04:20:51 ----D---- C:\Program Files\Movie Maker
2009-10-15 04:17:34 ----D---- C:\WINDOWS\system32\npp
2009-10-15 04:17:34 ----D---- C:\WINDOWS\mui
2009-10-15 04:17:32 ----D---- C:\WINDOWS\msagent
2009-10-15 04:17:31 ----D---- C:\WINDOWS\srchasst
2009-10-15 04:17:30 ----D---- C:\Program Files\NetMeeting
2009-10-15 04:17:29 ----D---- C:\WINDOWS\system32\Com
2009-10-15 04:17:25 ----D---- C:\Program Files\Windows NT
2009-10-15 04:17:04 ----D---- C:\WINDOWS\system32\oobe
2009-10-15 03:51:54 ----D---- C:\WINDOWS\Debug
2009-10-15 03:45:14 ----D---- C:\WINDOWS\SoftwareDistribution
2009-10-15 03:42:45 ----D---- C:\WINDOWS\system32\config
2009-10-15 03:36:35 ----D---- C:\WINDOWS\OPTIONS
2009-10-15 03:17:09 ----A---- C:\WINDOWS\system32\emver.ini
2009-10-15 03:13:31 ----A---- C:\WINDOWS\system.ini
2009-10-15 03:13:29 ----D---- C:\WINDOWS\RegisteredPackages
2009-10-15 01:40:25 ----D---- C:\WINDOWS\twain_32
2009-10-15 01:38:47 ----D---- C:\WINDOWS\system32\ras
2009-10-15 01:38:16 ----D---- C:\WINDOWS\system32\icsxml
2009-10-15 01:38:16 ----D---- C:\WINDOWS\system32\ias
2009-10-15 01:37:03 ----D---- C:\WINDOWS\system32\1033
2009-10-15 01:36:52 ----RD---- C:\WINDOWS\Web
2009-10-15 01:36:45 ----D---- C:\WINDOWS\Media
2009-10-15 01:36:19 ----D---- C:\WINDOWS\Cursors
2009-10-15 01:36:16 ----HDC---- C:\WINDOWS\$NtUninstallKB903157$
2009-10-15 01:36:16 ----HDC---- C:\WINDOWS\$NtUninstallKB900325$
2009-10-15 01:36:15 ----SHD---- C:\System Recovery
2009-10-15 01:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB899337$
2009-10-15 01:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB895961$
2009-10-15 01:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB891593$
2009-10-15 01:36:15 ----HDC---- C:\WINDOWS\$NtUninstallKB888795$
2009-10-15 01:36:15 ----D---- C:\Program Files\xerox
2009-10-15 01:36:10 ----D---- C:\Program Files\Windows Plus
2009-10-15 01:36:10 ----D---- C:\Program Files\Online Services
2009-10-15 01:36:10 ----D---- C:\Program Files\MSN Gaming Zone
2009-10-15 01:36:10 ----D---- C:\Program Files\MSN
2009-10-15 01:36:09 ----D---- C:\Program Files\microsoft frontpage
2009-10-15 01:36:09 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-10-15 01:36:09 ----D---- C:\Program Files\Common Files\ODBC
2009-10-15 01:36:09 ----D---- C:\Program Files\Common Files\MSSoap
2009-10-15 01:36:09 ----D---- C:\Drivers
2009-10-15 01:35:37 ----D---- C:\CMPNENTS
2009-10-15 01:35:02 ----D---- C:\WINDOWS\pchealth
2009-10-15 01:35:02 ----D---- C:\WINDOWS\msapps
2009-10-15 01:34:10 ----D---- C:\WINDOWS\Resources
2009-10-15 01:34:08 ----D---- C:\WINDOWS\Provisioning
2009-10-15 01:34:06 ----RD---- C:\WINDOWS\Offline Web Pages
2009-10-15 01:33:42 ----SHD---- C:\WINDOWS\CSC
2009-10-15 01:33:42 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-15 01:33:42 ----D---- C:\WINDOWS\Driver Cache
2009-10-15 01:33:36 ----HDC---- C:\WINDOWS\$NtUninstallKB902841$
2009-10-15 01:33:36 ----HDC---- C:\WINDOWS\$NtUninstallKB899510$
2009-10-15 01:33:33 ----D---- C:\WINDOWS\system32\mui
2009-10-15 01:33:31 ----D---- C:\WINDOWS\system32\URTTemp
2009-10-15 01:33:30 ----SD---- C:\WINDOWS\system32\Microsoft
2009-10-15 01:33:30 ----D---- C:\WINDOWS\system32\MsDtc
2009-10-15 01:33:30 ----D---- C:\WINDOWS\system32\Macromed
2009-10-15 01:33:30 ----D---- C:\WINDOWS\system32\IME
2009-10-15 01:33:30 ----D---- C:\WINDOWS\system32\DirectX
2009-10-15 01:33:22 ----D---- C:\WINDOWS\java
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-10-24 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-10-24 28424]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-10-25 360584]
R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2004-11-10 44288]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2004-11-10 24832]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-09-23 1094751]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-01-25 1478656]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-01-13 4137984]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\system32\DRIVERS\p3.sys [2008-04-13 42752]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\system32\DRIVERS\mxnic.sys [2001-08-17 19968]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-01-25 405504]
R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2009-10-24 285392]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2009-10-15 172032]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-10-15 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2009-11-07 17:41:01
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Agere Systems PCI-SV92PP Soft Modem-->agrsmdel
AOL Coach Version 2.0(Build:20041026.5 en)-->C:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP
AOL You've Got Pictures Screensaver-->C:\Program Files\Common Files\AOL\Screensaver\uninst_ygpss.exe
ATI - Software Uninstall Utility-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI Parental Control & Encoder-->MsiExec.exe /I{9862B19F-4CAD-4EED-920F-2F378D84393F}
AVG Free 9.0-->C:\Program Files\AVG\AVG9\setup.exe /UNINSTALL
BigAnt-->C:\Program Files\SetupInfo\{B05ABDE0-7B54-4970-AA05-032452A13AF9}\UnInstall.exe
BigFix-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\BigFix\Uninst.isu" -c"C:\Program Files\BigFix\Lib\UninstallHelper.dll"
Browser Address Error Redirector-->regsvr32 /u /s "c:\windows\system32\BAE.dll"
Canon iP1600-->C:\WINDOWS\system32\CNMCP75.exe "-PRINTERNAMECanon iP1600" "-HELPERDLLC:\Documents and Settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600 Installer\Inst2\cnmis.dll" "-RCDLLcnmi0409.dll"
ChartNet Login 4.0-->MsiExec.exe /I{7E3D0220-E10A-438C-A397-FCDE09F74801}
Digital Media Reader-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4AC55A61-BA20-4DF5-ABFF-8F4819E0C875} /l1033
DVD Solution-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
gtw_logo-->C:\WINDOWS\system32\gtw_logo.scr /UNINSTALL "C:\WINDOWS\system32\gtw_logo.log"
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 10 (KB910393)-->"C:\WINDOWS\$NtUninstallKB910393$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 1.0 Hotfix (KB953295)-->"C:\WINDOWS\$NtUninstallKB953295$\spuninst\spuninst.exe"
Microsoft .NET Framework 1.1 Security Update (KB953297)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Digital Image Starter Edition 2006-->"C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=11
Microsoft Money 2006-->"C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Mozilla Firefox (3.5.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Multimedia Keyboard Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6E66ECBD-FCA7-4AE1-A8C5-1CA78BEEB057}\Setup.exe" -l0x9
Napster Burn Engine-->MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Power2Go 4.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" -uninstall
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
RealPlayer Basic-->C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"C:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"C:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"C:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"C:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"C:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371-v2)-->"C:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"C:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"C:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971961)-->"C:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"C:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"C:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974455)-->"C:\WINDOWS\$NtUninstallKB974455$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"C:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"C:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"C:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
Sonic Encoders-->MsiExec.exe /I{9941F0AA-B903-4AF4-A055-83A9815CC011}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Update Rollup 2 for Windows XP Media Center Edition 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Windows Backup Utility-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB925766-->"C:\WINDOWS\$NtUninstallKB925766$\spuninst\spuninst.exe"
Windows XP Media Center Edition 2005 KB973768-->"C:\WINDOWS\$NtUninstallKB973768$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
=====HijackThis Backups=====
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE [2009-10-31]
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) [2009-10-31]
O22 - SharedTaskScheduler: kupuhivus - {282d60ae-1569-4c7d-a351-f5b7769e817b} - c:\windows\system32\fogehile.dll (file missing) [2009-10-31]
O21 - SSODL: yuvivukeb - {282d60ae-1569-4c7d-a351-f5b7769e817b} - c:\windows\system32\fogehile.dll (file missing) [2009-10-31]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll [2009-10-31]
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 [2009-10-31]
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL padamori.dll c:\windows\system32\fogehile.dll [2009-10-31]
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll [2009-10-31]
O20 - AppInit_DLLs: padamori.dll [2009-10-31]
O20 - AppInit_DLLs: padamori.dll [2009-10-31]
======Security center information======
AV: AVG Anti-Virus Free
======System event log======
Computer Name: HOMEPC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x80070643: Windows Internet Explorer 7 for Windows XP.
Record Number: 361
Source Name: Windows Update Agent
Time Written: 20091015064128.000000-240
Event Type: error
User:
Computer Name: HOMEPC
Event Code: 20
Message: Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 8 for Windows XP.
Record Number: 285
Source Name: Windows Update Agent
Time Written: 20091015061716.000000-240
Event Type: error
User:
Computer Name: HOMEPC
Event Code: 20
Message: Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.
Record Number: 227
Source Name: Print
Time Written: 20091015060838.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: HOMEPC
Event Code: 20
Message: Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.
Record Number: 226
Source Name: Print
Time Written: 20091015060835.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: HOMEPC
Event Code: 2504
Message: The server could not bind to the transport \Device\NetBT_Tcpip_{01247469-C47B-4D74-8056-EAFFCFD0CE2C}.
Record Number: 76
Source Name: Server
Time Written: 20091015052938.000000-240
Event Type: warning
User:
=====Application event log=====
Computer Name: HOMEPC
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 23
Source Name: WinMgmt
Time Written: 20091015053109.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: HOMEPC
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 22
Source Name: WinMgmt
Time Written: 20091015053109.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: HOMEPC
Event Code: 1
Message: Service registration successful.
Record Number: 17
Source Name: Media Center Receiver
Time Written: 20091015053019.000000-240
Event Type:
User:
Computer Name: HOMEPC
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 12
Source Name: WinMgmt
Time Written: 20091015052151.000000-240
Event Type: warning
User: HOMEPC\Owner
Computer Name: HomePC
Event Code: 1517
Message: Windows saved user HomePC\Owner registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.
This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
Record Number: 6
Source Name: Userenv
Time Written: 20091015044813.000000-240
Event Type: warning
User: NT AUTHORITY\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0407
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
GMER 1.0.15.15163 -
http://www.gmer.netRootkit scan 2009-11-07 18:32:53
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Yancy\LOCALS~1\Temp\uwtdipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
The chartnet program is used by my wife for work (medical transcription).
Again, Thank you