Deckard's System Scanner v20071014.68 Run by Megan MacDonald on 2008-07-29 00:18:44 Computer is in Normal Mode. -------------------------------------------------------------------------------- [color=red]Total Physical Memory: 504 MiB (512 MiB recommended).[/color] -- HijackThis (run as Megan MacDonald.exe) ------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:19, on 7/29/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla\Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Megan MacDonald\Desktop\dss.exe C:\DOCUME~1\MEGANM~1\Desktop\Megan MacDonald.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Security\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1001186.exe 61A847B5BBF72813329B39577AFF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310 O4 - HKLM\..\Run: [is-RENDI] "C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-RENDI\is-RENDI.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [StrgSync.exe] C:\Program Files\Storage\StorageSync\StrgSync.exe -w O4 - HKUS\S-1-5-18\..\Run: [mjc] C:\Program Files\mjc\mjc.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [SpeedRunner] C:\Documents and Settings\Megan MacDonald\Application Data\SpeedRunner\SpeedRunner.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [kruo] C:\PROGRA~1\COMMON~1\kruo\kruom.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [mjc] C:\Program Files\mjc\mjc.exe (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Security\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Security\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.cyberlink.com/winxp/CheckDVD.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1198207144984 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198207138687 O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: is-RENDI - Unknown owner - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-RENDI\is-RENDI.exe (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing) O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe -- End of file - 6608 bytes -- Files created between 2008-06-29 and 2008-07-29 ----------------------------- 2008-07-28 23:43:18 0 d-------- C:\WINDOWS\LastGood 2008-07-27 20:05:18 0 d-------- C:\Documents and Settings\Megan MacDonald\DoctorWeb 2008-07-27 18:02:53 342048 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-27 15:12:57 0 d-------- C:\fsaua.data 2008-07-25 16:41:29 0 d-------- C:\Program Files\Webtools 2008-07-25 07:50:38 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\Malwarebytes 2008-07-25 07:50:33 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-25 07:50:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-23 22:11:52 0 dr-hs---- C:\cmdcons 2008-07-23 22:11:37 0 d-------- C:\WINDOWS\setupupd 2008-07-23 19:46:14 68096 --a------ C:\WINDOWS\zip.exe 2008-07-23 19:46:14 53248 --a------ C:\WINDOWS\VFind.exe 2008-07-23 19:46:14 212480 --a------ C:\WINDOWS\swxcacls.exe 2008-07-23 19:46:14 137728 --a------ C:\WINDOWS\swsc.exe 2008-07-23 19:46:14 162304 --a------ C:\WINDOWS\swreg.exe 2008-07-23 19:46:14 98816 --a------ C:\WINDOWS\sed.exe 2008-07-23 19:46:14 80384 --a------ C:\WINDOWS\grep.exe 2008-07-23 19:46:14 86016 --a------ C:\WINDOWS\fdsv.exe 2008-07-23 13:20:46 0 d-------- C:\WINDOWS\system32\CatRoot_bak 2008-07-07 22:10:37 0 d-------- C:\WINDOWS\ERUNT 2008-07-06 20:38:12 0 dr------- C:\Documents and Settings\LocalService\Favorites 2008-07-06 20:38:07 0 d-------- C:\Documents and Settings\LocalService\Application Data\Talkback 2008-07-06 18:38:59 0 d-------- C:\Documents and Settings\LocalService\Application Data\Mozilla 2008-07-06 17:51:09 0 d-------- C:\WINDOWS\SxsCaPendDel 2008-07-06 17:40:29 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\Google 2008-07-06 17:40:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Google -- Find3M Report --------------------------------------------------------------- 2008-07-27 14:52:44 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\LimeWire 2008-07-27 14:41:10 0 d-------- C:\Program Files\Common Files 2008-07-25 16:47:42 0 d-------- C:\Program Files\Security 2008-07-20 02:28:13 664 --a------ C:\WINDOWS\system32\d3d9caps.dat 2008-07-06 17:55:28 0 d-------- C:\Program Files\Google 2008-06-26 16:44:37 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\Macromedia 2008-06-22 20:16:53 0 d-------- C:\Program Files\Picasa2 2008-06-20 14:39:35 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\Leadertech 2008-06-20 14:37:43 0 d-------- C:\Documents and Settings\Megan MacDonald\Application Data\Adobe 2008-06-19 20:18:04 0 d-------- C:\Program Files\LimeWire 2008-06-19 17:22:43 2042 --a------ C:\WINDOWS\mozver.dat 2008-06-17 09:03:29 0 d-------- C:\Program Files\Trillian 2008-06-17 08:44:12 0 d-------- C:\Program Files\iPod 2008-06-17 08:43:40 0 d-------- C:\Program Files\music 2008-06-17 08:42:13 0 d-------- C:\Program Files\QuickTime 2008-06-02 06:21:16 0 d-------- C:\Program Files\Modem Helper 2008-06-02 06:18:13 0 d-------- C:\Program Files\FileZilla -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [12/21/2007 02:48] "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [08/02/2006 01:38] "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [08/02/2006 01:32] "runner1"="C:\WINDOWS\mrofinu1001186.exe" [] "is-RENDI"="C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-RENDI\is-RENDI.exe" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 08:00] "StrgSync.exe"="C:\Program Files\Storage\StorageSync\StrgSync.exe" [12/21/2007 00:46] [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "mjc"=C:\Program Files\mjc\mjc.exe "SpeedRunner"=C:\Documents and Settings\Megan MacDonald\Application Data\SpeedRunner\SpeedRunner.exe "kruo"=C:\PROGRA~1\COMMON~1\kruo\kruom.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - C:\Program Files\Office\Office10\OSA.EXE [2/13/2001 2:01:04 AM] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) "DisableRegistryTools"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "HideLegacyLogonScripts"=0 (0x0) "HideLogoffScripts"=0 (0x0) "RunLogonScriptSync"=1 (0x1) "RunStartupScriptSync"=0 (0x0) "HideStartupScripts"=0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher] "C:\Program Files\DVD Drive\CyberLink\PowerDVD\DVDLauncher.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\music\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] "C:\Program Files\DVD Drive\Dell\Media Experience\PCMService.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] C:\Program Files\Security\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StrgSync.exe] C:\Program Files\Storage\StorageSync\StrgSync.exe -w [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "wuauserv"=2 (0x2) "iPod Service"=3 (0x3) "MpfService"=2 (0x2) "McSysmon"=3 (0x3) "McShield"=2 (0x2) "McProxy"=2 (0x2) "McODS"=3 (0x3) "McNASvc"=2 (0x2) "mcmscsvc"=2 (0x2) "Macromedia Licensing Service"=3 (0x3) "AVGEMS"=2 (0x2) "Avg7UpdSvc"=2 (0x2) "Avg7Alrt"=2 (0x2) "wscsvc"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] AutoRun\command- E:\Launch.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F] AutoRun\command- F:\LaunchU3.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59044394-427c-11dd-b184-0013ce2abbb4}] AutoRun\command- F:\LaunchU3.exe -- End of Deckard's System Scanner: finished at 2008-07-29 00:19:36 ------------