Deckard's System Scanner v20071014.68 Run by jll2 on 2008-03-03 20:05:23 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 80: 2008-03-03 14:35:45 UTC - RP387 - Deckard's System Scanner Restore Point 79: 2008-03-03 14:16:48 UTC - RP386 - Uniblue RegistryBooster 78: 2008-03-02 14:00:47 UTC - RP385 - System Checkpoint 77: 2008-03-01 12:26:23 UTC - RP384 - Installed SUPERAntiSpyware Free Edition 76: 2008-03-01 06:05:42 UTC - RP383 - System Checkpoint -- First Restore Point -- 1: 2008-02-21 16:03:55 UTC - RP308 - Installed Windows XP KB896428. Backed up registry hives. Performed disk cleanup. [color=red]Percentage of Memory in Use: 85% (more than 75%).[/color] [color=red]Total Physical Memory: 503 MiB (512 MiB recommended).[/color] -- HijackThis (run as jll2.exe) ------------------------------------------------ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:09:54 PM, on 3/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe C:\Program Files\Citrix\ICA Client\ssonsvr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\System32\igfxpers.exe C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\UpdaterUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Network Associates\VirusScan\EntVUtil.EXE C:\Program Files\Common Files\Teleca Shared\Generic.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\System32\WISPTIS.EXE C:\WINDOWS\explorer.exe C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe C:\DOCUME~1\jll2\LOCALS~1\Temp\Rar$EX03.109\Uniblue_Registry_Booster_v2.0.1114.3657\Crack\register.exe C:\Documents and Settings\jll2\Desktop\dss.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\jll2.exe C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\McScript_InUse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://delphi.ap.joneslanglasalle.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.128.4.69:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.*.*.*;*.ap.jllnet.com;*.ap.joneslanglasalle.com;ipmpwt.joneslanglasalle.com; R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: {c7d875be-8b0e-f9e9-5464-cf54b00f27b0} - {0b72f00b-45fc-4645-9e9f-e0b8eb578d7c} - C:\WINDOWS\system32\ibhcxxto.dll (file missing) O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: (no name) - {85429961-D537-4B19-8FDA-F284548CC281} - (no file) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\Apple\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [imekrmig7.0] "C:\Program Files\Common Files\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE" O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - Global Startup: BGInfo.lnk = C:\WINDOWS\Bginfo.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office11\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O14 - IERESET.INF: START_PAGE_URL=http://delphi.ap.joneslanglasalle.com O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB O16 - DPF: {2E687AA8-B276-4910-BBFB-4E412F685379} (CWebsiteViewer Object) - http://ausyd077.ap.jllnet.com/WebsiteViewerRoot/WebsiteViewer.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} (DDSC Class) - http://delphi.ap.joneslanglasalle.com/Dashboard/msddsc.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203315985171 O16 - DPF: {EBC1356E-7D5E-44EC-831D-847882F06FE5} (Gateway Client for MetaFrame) - https://webdesk.ap.joneslanglasalle.com/webdesk/cds/CGC/en/CSGProxy.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{373E75A6-C8D0-4B5F-8231-1D100EB42C40}: Domain = ap.jllnet.com O17 - HKLM\System\CCS\Services\Tcpip\..\{B82E01BD-02A1-4161-BE6A-289E4F4D1D94}: NameServer = 125.22.47.125,202.56.250.5 O17 - HKLM\System\CS2\Services\Tcpip\..\{373E75A6-C8D0-4B5F-8231-1D100EB42C40}: Domain = ap.jllnet.com O17 - HKLM\System\CS3\Services\Tcpip\..\{373E75A6-C8D0-4B5F-8231-1D100EB42C40}: Domain = ap.jllnet.com O17 - HKLM\System\CS4\Services\Tcpip\..\{373E75A6-C8D0-4B5F-8231-1D100EB42C40}: Domain = ap.jllnet.com O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: cbxxwxv - C:\WINDOWS\ O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe -- End of file - 10886 bytes -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20080229-194651-190 O2 - BHO: (no name) - {85429961-D537-4B19-8FDA-F284548CC281} - C:\WINDOWS\system32\ddayx.dll (file missing) -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys R3 BDSelfPr - c:\program files\bitdefender\bitdefender 2008\bdselfpr.sys R3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys R3 SASENUM - c:\program files\superantispyware\sasenum.sys R4 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 McAfeeFramework (McAfee Framework Service) - "c:\program files\network associates\common framework\frameworkservice.exe" /servicestart R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-02-27 01:00:30 278 --a------ C:\WINDOWS\Tasks\Defrag (Desktop) .....job -- Files created between 2008-02-03 and 2008-03-03 ----------------------------- 2008-03-03 19:22:22 0 d-------- C:\Documents and Settings\jll2\Application Data\Uniblue 2008-03-03 19:04:39 0 d-------- C:\Program Files\Uniblue 2008-03-03 15:09:40 0 --a------ C:\WINDOWS\nsreg.dat 2008-03-03 15:09:32 0 d-------- C:\Documents and Settings\jll2\Application Data\Mozilla 2008-03-03 14:05:06 3503 --a------ C:\Start_.cmd 2008-03-03 14:01:46 0 d-------- C:\327882R2FWJFW 2008-03-01 17:59:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-03-01 17:56:54 0 d-------- C:\Program Files\SUPERAntiSpyware 2008-03-01 17:56:54 0 d-------- C:\Documents and Settings\jll2\Application Data\SUPERAntiSpyware.com 2008-02-29 19:45:02 0 d-------- C:\Program Files\Trend Micro 2008-02-29 17:15:58 0 d-------- C:\cmdcons 2008-02-29 17:14:38 68096 --a------ C:\WINDOWS\system32\zip.exe 2008-02-29 17:14:38 98816 --a------ C:\WINDOWS\system32\sed.exe 2008-02-29 17:14:38 80412 --a------ C:\WINDOWS\system32\grep.exe 2008-02-29 17:14:38 73728 --a------ C:\WINDOWS\system32\fdsv.exe 2008-02-28 15:39:37 0 d-------- C:\VundoFix Backups 2008-02-25 12:45:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-02-23 15:43:10 0 d-------- C:\Documents and Settings\jll2\Application Data\BitDefender 2008-02-23 15:35:51 0 d-------- C:\Program Files\BitDefender 2008-02-23 15:35:51 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender 2008-02-23 15:30:21 0 d-------- C:\Program Files\Common Files\BitDefender 2008-02-23 12:18:28 0 d-------- C:\WINDOWS\pss 2008-02-21 21:45:36 0 d-------- C:\Temp 2008-02-21 21:44:23 0 d-------- C:\Program Files\Xilisoft 2008-02-21 11:07:17 0 d-------- C:\WINDOWS\system32\%%DATA_DIR%% 2008-02-20 15:42:03 0 d-------- C:\Program Files\Unity 2008-02-19 22:40:37 0 d-------- C:\Program Files\SamsonSoft 2008-02-19 22:38:56 0 d-------- C:\WINDOWS\system32\URTTemp 2008-02-19 22:33:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Zabersoft 2008-02-19 20:33:38 0 d-------- C:\Documents and Settings\jll2\Application Data\Media Player Classic 2008-02-19 20:26:45 164352 --a------ C:\WINDOWS\system32\unrar.dll 2008-02-19 20:26:35 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll 2008-02-19 20:26:34 159839 --a------ C:\WINDOWS\system32\xvidvfw.dll 2008-02-19 20:26:34 755027 --a------ C:\WINDOWS\system32\xvidcore.dll 2008-02-19 20:26:33 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll 2008-02-19 20:26:33 81920 --a------ C:\WINDOWS\system32\dpl100.dll 2008-02-19 20:26:33 682496 --a------ C:\WINDOWS\system32\divx.dll 2008-02-19 20:26:31 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll 2008-02-19 20:26:29 0 d-------- C:\Program Files\K-Lite Codec Pack 2008-02-19 18:54:40 0 d-------- C:\Program Files\Digital Locker Assistant 2008-02-19 18:11:42 0 d-------- C:\Documents and Settings\jll2\Application Data\StumbleUpon 2008-02-19 18:11:38 0 d-------- C:\Program Files\StumbleUpon 2008-02-19 14:52:55 0 d-------- C:\WINDOWS\network diagnostic 2008-02-19 14:07:39 0 d-------- C:\Program Files\MSXML 4.0 2008-02-19 10:51:09 0 d-------- C:\WINDOWS\Prefetch 2008-02-18 12:46:02 0 d-------- C:\WINDOWS\peernet 2008-02-18 12:46:01 0 d-------- C:\WINDOWS\provisioning 2008-02-18 12:42:16 0 d-------- C:\WINDOWS\ServicePackFiles 2008-02-18 12:31:26 0 d-------- C:\WINDOWS\EHome 2008-02-15 10:27:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2008-02-13 10:01:03 0 d-------- C:\WINDOWS\system32\PreInstall 2008-02-13 09:35:38 0 d-------- C:\WINDOWS\system32\SoftwareDistribution 2008-02-09 19:28:40 0 d-------- C:\Program Files\Winamp 2008-02-09 19:28:40 0 d-------- C:\Documents and Settings\jll2\Application Data\Winamp 2008-02-08 19:38:34 0 d-------- C:\Documents and Settings\jll2\Application Data\Teleca 2008-02-08 19:36:49 0 d------c- C:\WINDOWS\system32\DRVSTORE 2008-02-08 19:35:43 0 d-------- C:\Documents and Settings\jll2\Application Data\Sony Ericsson 2008-02-08 19:35:24 0 d-------- C:\Program Files\Common Files\Sony Ericsson Shared 2008-02-08 19:35:21 0 d-------- C:\Program Files\Common Files\Teleca Shared 2008-02-08 19:35:17 0 d-------- C:\Program Files\Sony Ericsson 2008-02-08 19:34:37 0 d-------- C:\WINDOWS\Downloaded Installations 2008-02-08 19:33:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Teleca 2008-02-08 19:33:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson 2008-02-07 18:24:47 0 d-------- C:\WINDOWS\system32\Dell 2008-02-07 13:12:18 0 d-------- C:\Documents and Settings\jll2\Application Data\Sun 2008-02-07 12:35:55 0 d-------- C:\Documents and Settings\jll2\Application Data\WinRAR 2008-02-07 11:29:01 0 d-------- C:\Documents and Settings\jll2\Application Data\AdobeUM 2008-02-07 10:06:25 0 d-------- C:\Documents and Settings\jll2\Application Data\Macromedia -- Find3M Report --------------------------------------------------------------- 2008-03-01 17:48:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-02-23 15:30:21 0 d-------- C:\Program Files\Common Files 2008-02-19 19:16:42 73216 --a------ C:\WINDOWS\ST6UNST.EXE 2008-02-19 14:13:49 0 d-------- C:\Program Files\Microsoft Works 2008-02-18 12:46:04 0 d-------- C:\Program Files\Movie Maker 2008-02-18 12:41:40 0 d-------- C:\Program Files\Windows NT 2008-02-07 18:24:47 0 d-------- C:\Program Files\Dell 2008-02-07 11:28:52 0 d-------- C:\Documents and Settings\jll2\Application Data\Adobe 2008-01-28 10:01:40 0 d-------- C:\Documents and Settings\jll2\Application Data\Yahoo! 2008-01-25 15:49:00 0 d-------- C:\Program Files\FriendFinder 2008-01-03 09:16:49 0 d-------- C:\Program Files\NETWORK ASSOCIATES -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0b72f00b-45fc-4645-9e9f-e0b8eb578d7c}] C:\WINDOWS\system32\ibhcxxto.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85429961-D537-4B19-8FDA-F284548CC281}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [04/05/2005 06:52 PM] "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [04/05/2005 06:49 PM] "ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 05:30 PM] "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 12:12 PM] "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [06/13/2007 08:16 AM] "BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [10/09/2007 03:46 PM] "BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [02/25/2008 12:10 PM] "QuickTime Task"="C:\Program Files\Apple\QuickTime\qttask.exe" [04/30/2004 09:37 AM] "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [01/16/2008 04:24 AM] "PHIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.exe" [03/22/2007 07:17 PM] "McAfeeUpdaterUI"="C:\Program Files\NETWORK ASSOCIATES\COMMON FRAMEWORK\UpdaterUI.exe" [08/31/2005 04:50 PM] "IMSCMig"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.exe" [04/02/2007 09:42 PM] "IMJPMIG9.0"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.exe" [04/19/2007 02:00 PM] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/04/2004 11:01 AM] "imekrmig7.0"="C:\Program Files\Common Files\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE" [04/19/2007 02:00 PM] "CJIMETIPSYNC"="C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.exe" [03/22/2007 07:17 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:26 PM] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [02/13/2004 07:55 AM] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM] "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [10/22/2007 10:12 AM] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ BGInfo.lnk - C:\WINDOWS\Bginfo.exe [11/11/2005 2:40:50 PM] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 nwprovau [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{89aa037a-e6ac-11dc-a38d-de4af262252f}] Auto\command- tomskype.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tomskype.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d640950b-d621-11dc-a36d-00142237fd9f}] Auto\command- E:\tomskype.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tomskype.exe *Newly Created Service* - ENTDRV51 *Newly Created Service* - SASDIFSV *Newly Created Service* - SASENUM *Newly Created Service* - SASKUTIL -- End of Deckard's System Scanner: finished at 2008-03-03 20:41:03 ------------