Deckard's System Scanner v20071014.68 Run by dmengeler on 2008-05-17 19:27:08 Computer is in Normal Mode. -------------------------------------------------------------------------------- [color=red]Total Physical Memory: 511 MiB (512 MiB recommended).[/color] -- HijackThis (run as dmengeler.exe) ------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:27:15 PM, on 5/17/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Stonesoft\StoneGate VPN Client\gatekeeper.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe C:\WINDOWS\system32\win32osf.exe C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Documents and Settings\dmengeler\Desktop\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\dmengeler.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://intranet.ed.local/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by ElliottDavis, LLC R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {92A444D2-F945-4dd9-89A1-896A6C2D8D22} - (no file) O2 - BHO: XBTBPos00 Class - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\PROGRA~1\SOFTOM~1\TOOLBA~1\bin\tbcore3U.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r O4 - HKLM\..\Run: [Windows OS Function] C:\WINDOWS\system32\win32osf.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102092125030 O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182452037406 O16 - DPF: {89172179-D07F-455E-BBEB-C41D42AEC078} - file:///C:/Program%20Files/Softomate/ToolbarStudio/projects/daviscreation_webinstall/daviscreation.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: StoneGate VPN Client (SGClient) - Stonesoft Corp. - C:\Program Files\Stonesoft\StoneGate VPN Client\gatekeeper.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 8365 bytes -- Files created between 2008-04-17 and 2008-05-17 ----------------------------- 2008-05-17 19:02:35 0 d-------- C:\Documents and Settings\dmengeler\Application Data\Malwarebytes 2008-05-17 19:02:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-05-17 19:02:08 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-05-17 18:44:08 0 d-------- C:\Program Files\Trend Micro 2008-05-17 18:40:51 0 d-------- C:\Program Files\Common Files\Java 2008-05-17 18:34:32 0 dr-h----- C:\Documents and Settings\dmengeler\Recent 2008-05-08 22:12:57 3584 --a------ C:\WINDOWS\system32\win32osf.exe 2008-05-08 20:10:17 0 d-------- C:\WINDOWS\system32\Adobe 2008-04-21 18:48:19 0 d-------- C:\Documents and Settings\dmengeler\Application Data\mIRC 2008-04-21 18:48:18 0 d-------- C:\Program Files\mIRC -- Find3M Report --------------------------------------------------------------- 2008-05-17 19:24:11 0 d-------- C:\Program Files\Symantec AntiVirus 2008-05-17 18:41:40 0 d-------- C:\Program Files\Java 2008-05-17 18:40:51 0 d-------- C:\Program Files\Common Files 2008-05-14 21:47:44 0 d-------- C:\Documents and Settings\dmengeler\Application Data\Adobe 2008-05-12 21:16:01 0 d-------- C:\Program Files\Workspace Macro Pro 6.5 2008-05-12 21:14:15 0 d-------- C:\Program Files\Softomate 2008-05-12 21:09:56 0 d-------- C:\Program Files\OgreDemo 2008-05-12 21:08:53 0 d-------- C:\Program Files\Net Tools 2008-05-12 21:07:54 0 d-------- C:\Program Files\Image-Line 2008-05-12 21:07:24 0 d-------- C:\Program Files\Free WMA to MP3 Converter 2008-05-12 21:07:16 0 d-------- C:\Program Files\Free Screen Recorder 2008-05-12 21:07:00 0 d-------- C:\Program Files\Flash Saver 2008-05-12 21:05:40 0 d-------- C:\Program Files\VstPlugins 2008-05-12 21:03:21 0 d-------- C:\Program Files\AviSynth 2.5 2008-05-08 22:02:33 436 --a------ C:\Documents and Settings\dmengeler\Application Data\SamsungLiveUpdateConfig.ini 2008-05-08 21:52:11 0 d-------- C:\Program Files\Google 2008-05-08 20:43:35 0 d-------- C:\Documents and Settings\dmengeler\Application Data\AdobeUM 2008-04-10 19:09:33 0 d-------- C:\Program Files\Microsoft DirectX SDK (March 2008) 2008-04-10 18:04:19 0 d-------- C:\Program Files\Pcsx2 2008-04-09 03:12:04 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-04-07 16:20:33 0 d-------- C:\Documents and Settings\dmengeler\Application Data\SmartFTP 2008-04-07 16:20:01 0 d-------- C:\Program Files\SmartFTP Client 2008-04-07 16:19:21 0 d-------- C:\Program Files\SmartFTP Client 3.0 Setup Files 2008-04-06 16:20:43 0 d-------- C:\Program Files\Outsim 2008-04-05 22:21:57 0 d-------- C:\Documents and Settings\dmengeler\Application Data\Yahoo! 2008-04-05 22:21:56 0 d-------- C:\Program Files\Yahoo! 2008-04-05 19:06:25 1025 --a------ C:\logfile.dat 2008-04-05 19:05:50 0 d-------- C:\Program Files\FXhome VisionLab Studio 2008-04-05 14:41:09 0 d-------- C:\Program Files\Icon Constructor 3 2008-04-05 14:40:50 0 d-------- C:\Program Files\HyCam2 2008-04-02 21:34:35 0 d-------- C:\Program Files\Microsoft Visual Studio 9.0 2008-03-24 01:11:57 0 d-------- C:\Program Files\AC3Filter 2008-03-23 23:49:00 0 d-------- C:\Program Files\Common Files\LightScribe 2008-03-23 23:29:24 769536 --a------ C:\Documents and Settings\dmengeler\Application Data\sfdnwin.dll 2008-03-23 23:27:13 0 d-------- C:\Program Files\SAMSUNG 2008-03-18 20:36:13 0 d-------- C:\Documents and Settings\dmengeler\Application Data\Google 2008-03-18 15:50:33 0 d-------- C:\Program Files\CCleaner 2008-03-17 21:14:51 0 d-------- C:\Documents and Settings\dmengeler\Application Data\W Photo Studio Viewer 2008-03-16 09:35:13 5 --a------ C:\Message.vbs -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92A444D2-F945-4dd9-89A1-896A6C2D8D22}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [07/19/2006 07:26 PM] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [09/27/2006 08:33 PM] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 05:25 AM] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/10/2008 04:27 PM] "Name of App"="C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe" [01/04/2008 05:33 PM] "Windows OS Function"="C:\WINDOWS\system32\win32osf.exe" [05/17/2008 06:12 PM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM] "LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [08/23/2007 05:36 PM] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 4:44:06 AM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlyMonitor] "C:\Program Files\Leapfrog\FlyWorld\bin\FlyMonitor.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StoneGateAgent] "C:\Program Files\Stonesoft\StoneGate VPN Client\sgagent.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ca0c253-0d71-11dc-b759-000874dd479e}] AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe explore\Command- E:\autorun.exe open\Command- E:\autorun.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" -- End of Deckard's System Scanner: finished at 2008-05-17 19:27:41 ------------