Deckard's System Scanner v20071014.68 Run by stu on 2008-07-31 22:17:39 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 48: 2008-07-31 21:18:37 UTC - RP362 - Deckard's System Scanner Restore Point 47: 2008-07-31 18:28:11 UTC - RP361 - System Checkpoint 46: 2008-07-27 18:25:41 UTC - RP360 - Removed Digital Locker Assistant 45: 2008-07-27 13:53:11 UTC - RP359 - Removed Windows Live installer 44: 2008-07-27 13:51:37 UTC - RP358 - Removed Bonjour -- First Restore Point -- 1: 2008-07-25 12:06:59 UTC - RP315 - System Checkpoint Backed up registry hives. Performed disk cleanup. [color=red]Percentage of Memory in Use: 82% (more than 75%).[/color] -- HijackThis (run as stu.exe) ------------------------------------------------- logfile has no content; running clone. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2008-07-31 22:23:30 Platform: Windows XP Service Pack 2 (5.01.2600) MSIE: Internet Explorer (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG8\avgwdsvc.exe C:\Program Files\Kontiki\KService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG8\avgrsx.exe C:\Program Files\Ahead\ODD Toolkit\dvdtray.exe C:\Program Files\AVG\AVG8\avgemc.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\Program Files\Real\RealPlayer\realplay.exe C:\Program Files\VoyagerTest\fts.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\ScanSoft\OmniPageSE\opware32.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I0H2.EXE C:\Program Files\Common Files\AOL\1173903062\ee\aolsoftware.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE C:\Program Files\Kontiki\KHost.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\AV9\av2009.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\SEC\Natural Color Pro\NCProTray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\AVG\AVG8\aAvgApi.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\AVG\AVG8\avgscanx.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\stu\Local Settings\Temporary Internet Files\Content.IE5\DWA0A8NS\dss[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\WINDOWS\system32\winsrc.dll (file missing) O2 - BHO: (no name) - {094133C8-1D3D-4785-8A56-531CC89612EF} - C:\WINDOWS\system32\tuvVOFyV.dll O2 - BHO: (no name) - {22BB2D8D-B263-43F4-B7E4-2F5DCD577625} - C:\WINDOWS\system32\efccCSih.dll O2 - BHO: {e45bcdf6-4e97-718a-e6a4-fd38d50fdd13} - {31ddf05d-83df-4a6e-a817-79e46fdcb54e} - C:\WINDOWS\system32\iwtwba.dll (file missing) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O2 - BHO: targetedbanner browser optimizer - {c393b5ba-fdf5-99f1-e4c8-4692a5ff79a9} - C:\WINDOWS\system32\eniqtzjffpagqbyjn.dll O2 - BHO: (no name) - {C690EBA3-843B-44EA-98C7-8FAB83826171} - C:\WINDOWS\system32\geBtsSlj.dll (file missing) O2 - BHO: (no name) - {FBE8BCFF-0235-42F7-9C21-03E988C86FE6} - C:\WINDOWS\system32\ddcCrRIx.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar2.dll O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe" O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1173903062\ee\AOLSoftware.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200" O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe O4 - HKLM\..\Run: [kdx] "C:\Program Files\Kontiki\KHost.exe" -all O4 - HKLM\..\Run: [{cbf74647-2ff5-dc6c-46cd-94d62d94e88f}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\eniqtzjffpagqbyjn.dll" DllStart O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [8cac459a] rundll32.exe "C:\WINDOWS\system32\sswyebbb.dll",b O4 - HKLM\..\Run: [BM8f9f7606] Rundll32.exe "C:\WINDOWS\system32\aqbcavfd.dll",s O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKCU\..\Run: [Uniblue RegistryBooster2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all O4 - HKCU\..\Run: [AOL Dialer] C:\Program Files\Common Files\AOL\ACS\AOlDial.exe O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe O4 - HKCU\..\Run: [01202983901146170543956190995315] C:\Program Files\AV9\av2009.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: NCProTray.lnk = ? O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm450YYGB O9 - Extra button: (no name) - CmdMapping - (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} () - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/CursorManiaFWBInitialSetup1.0.1.0.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab Class) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192130370546 O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe O16 - DPF: {EAC95A5E-B836-47A1-9508-DC5307C37003} () - http://scanner.vav-scan.com/setup/demo/setup.cab O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{6D8A3959-7FD0-45D7-9636-2F32A65C15D5}: NameServer = 92.31.241.20 92.31.241.21 O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: tuvVOFyV - C:\WINDOWS\system32\tuvVOFyV.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE -- End of file - 14587 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys S1 NaturalColor - c:\windows\system32\drivers\mtictwl.sys (file missing) S1 NCPro - c:\windows\system32\drivers\mtictwl.sys (file missing) S3 MagicTune - c:\windows\system32\drivers\mtictwl.sys (file missing) S3 USBAAPL (Apple Mobile USB Driver) - c:\windows\system32\drivers\usbaapl.sys S3 w200bus (Sony Ericsson W200 driver (WDM)) - c:\windows\system32\drivers\w200bus.sys S3 w200mdfl (Sony Ericsson W200 USB WMC Modem Filter) - c:\windows\system32\drivers\w200mdfl.sys S3 w200mdm (Sony Ericsson W200 USB WMC Modem Driver) - c:\windows\system32\drivers\w200mdm.sys S3 w200mgmt (Sony Ericsson W200 USB WMC Device Management Drivers (WDM)) - c:\windows\system32\drivers\w200mgmt.sys S3 w200obex (Sony Ericsson W200 USB WMC OBEX Interface) - c:\windows\system32\drivers\w200obex.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- S2 MyWebSearchService (My Web Search Service) - c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-05-26 20:10:24 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -- Files created between 2008-06-30 and 2008-07-31 ----------------------------- 2008-07-31 22:22:18 0 d-------- C:\Program Files\Trend Micro 2008-07-31 20:54:24 0 d--h---c- C:\$AVG8.VAULT$ 2008-07-31 20:43:41 0 d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-31 20:43:41 0 d-------- C:\Documents and Settings\stu\Application Data\AVGTOOLBAR 2008-07-31 20:43:25 0 d-------- C:\Program Files\AVG 2008-07-31 20:43:24 0 d------c- C:\Documents and Settings\All Users\Application Data\avg8 2008-07-31 20:05:09 0 d-------- C:\Program Files\VAV 2008-07-31 19:58:28 0 d-------- C:\Program Files\AV9 2008-07-31 19:45:44 83456 --a------ C:\WINDOWS\system32\sswyebbb.dll 2008-07-31 19:39:44 639979 --ahs---- C:\WINDOWS\system32\hiSCccfe.ini2 2008-07-31 19:39:38 283136 --a------ C:\WINDOWS\system32\efccCSih.dll 2008-07-28 23:54:03 103424 --a------ C:\WINDOWS\system32\sewpxdnw.dll 2008-07-28 23:51:02 603442 --ahs---- C:\WINDOWS\system32\xIRrCcdd.ini2 2008-07-28 20:11:33 101888 --a------ C:\WINDOWS\system32\qsjula.dll 2008-07-28 20:11:32 101888 --a------ C:\WINDOWS\system32\jjehfuwc.dll 2008-07-28 20:08:34 93184 --a------ C:\WINDOWS\system32\recsbhpx.dll 2008-07-27 20:08:02 102400 --a------ C:\WINDOWS\system32\kwyihq.dll 2008-07-27 20:08:01 102400 --a------ C:\WINDOWS\system32\xvfyvnet.dll 2008-07-27 19:02:07 101888 --a------ C:\WINDOWS\system32\menqqy.dll 2008-07-27 19:02:06 101888 --a------ C:\WINDOWS\system32\yvtdfxor.dll 2008-07-27 19:01:56 93184 --a------ C:\WINDOWS\system32\uborlwsy.dll 2008-07-26 17:15:01 101888 --a------ C:\WINDOWS\system32\caoxyc.dll 2008-07-26 17:14:59 101888 --a------ C:\WINDOWS\system32\isnlwori.dll 2008-07-26 17:14:50 93184 --a------ C:\WINDOWS\system32\uxbpsuvs.dll 2008-07-25 14:38:59 0 d-------- C:\Program Files\iPod 2008-07-25 13:06:38 604274 --ahs---- C:\WINDOWS\system32\jlSstBeg.ini2 2008-07-25 13:00:55 64841 --a------ C:\WINDOWS\system32\iyacviaucnma.exe 2008-07-25 13:00:50 0 d-------- C:\WINDOWS\system32\debug4 2008-07-25 13:00:50 0 d-------- C:\WINDOWS\system32\cur2 2008-07-25 13:00:47 0 d-------- C:\WINDOWS\system32\kBin15 2008-07-25 13:00:43 32768 --a------ C:\WINDOWS\system32\tuvVOFyV.dll 2008-07-25 13:00:43 32768 --a------ C:\WINDOWS\system32\pmnLcBqo.dll 2008-07-21 19:40:21 0 d-------- C:\Program Files\Selectsoft 2008-07-20 11:11:48 197120 --a------ C:\WINDOWS\patchw32.dll 2008-07-20 11:11:48 0 d-------- C:\Program Files\Common Files\PocketSoft 2008-07-17 20:29:48 0 d-------- C:\Documents and Settings\stu\Application Data\InstallShield 2008-07-16 14:09:34 0 d------c- C:\Documents and Settings\All Users\temp 2008-07-16 14:09:34 0 d------c- C:\Documents and Settings\All Users\Gamespot 2008-07-16 14:09:33 0 d-------- C:\Program Files\GameSpot 2008-07-13 18:25:44 0 d-------- C:\Documents and Settings\stu\Application Data\WinRAR 2008-07-12 16:40:15 0 d------c- C:\Setup 2008-07-12 16:39:48 0 d-------- C:\Program Files\AOL Broadband 2008-07-12 16:38:03 72192 --a------ C:\WINDOWS\system32\taskkill.EXE 2008-07-09 22:51:27 0 d-------- C:\Documents and Settings\stu\Desktopmw21.1 2008-07-09 20:39:44 0 d------c- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters 2008-07-08 16:10:00 158208 --a------ C:\WINDOWS\system32\eniqtzjffpagqbyjn.dll 2008-07-01 14:41:53 3532 --a----c- C:\drmHeader.bin 2008-07-01 14:10:12 0 d-------- C:\Documents and Settings\stu\Application Data\LimeWire 2008-06-30 16:49:55 0 d-------- C:\Program Files\MSECache 2008-06-30 11:23:35 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller 2008-06-30 11:23:08 0 d------c- C:\Documents and Settings\All Users\Application Data\WLInstaller -- Find3M Report --------------------------------------------------------------- 2008-07-31 20:27:31 0 d-------- C:\Program Files\Common Files\Adobe 2008-07-31 18:58:22 0 d-------- C:\Program Files\Common Files\AOL 2008-07-29 20:53:41 0 d-------- C:\Program Files\Common Files 2008-07-29 17:10:54 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll 2008-07-27 19:21:29 0 d-------- C:\Program Files\LimeWire 2008-07-25 14:39:46 0 d-------- C:\Program Files\iTunes 2008-07-25 14:35:25 0 d-------- C:\Program Files\QuickTime 2008-07-25 12:23:15 0 d-------- C:\Documents and Settings\stu\Application Data\Canon 2008-07-24 17:13:29 0 d-------- C:\Program Files\MediaMonkey 2008-07-20 11:08:50 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-07-20 11:08:47 0 d-------- C:\Program Files\Atari 2008-07-18 17:29:00 0 d-------- C:\Documents and Settings\stu\Application Data\SPORE Creature Creator 2008-07-16 17:12:28 0 d-------- C:\Program Files\SEGA 2008-07-09 21:21:15 0 d-------- C:\Program Files\MagicTune Premium 2008-07-01 15:50:50 0 d-------- C:\Program Files\DivX 2008-07-01 08:51:29 0 d-------- C:\Program Files\Samsung 2008-07-01 08:50:05 0 d-------- C:\Program Files\EPSON 2008-06-24 20:25:00 0 d-------- C:\Documents and Settings\stu\Application Data\Adobe 2008-06-21 17:12:31 0 d-------- C:\Program Files\Kontiki 2008-06-21 17:12:25 0 d-------- C:\Program Files\Sky 2008-06-21 17:01:50 0 d-------- C:\Program Files\Common Files\Symantec Shared 2008-06-18 19:27:16 0 d-------- C:\Program Files\Electronic Arts 2008-06-15 11:07:28 0 d-------- C:\Documents and Settings\stu\Application Data\Macromedia 2008-06-12 00:00:35 0 d-------- C:\Documents and Settings\stu\Application Data\DivX 2008-06-11 20:51:04 0 d-------- C:\Program Files\FunWebProducts 2008-06-11 19:15:27 0 d-------- C:\Program Files\MyWebSearch 2008-06-11 19:15:19 28672 --a------ C:\WINDOWS\system32\f3PSSavr.scr 2008-06-11 01:07:20 3596288 --a----c- C:\WINDOWS\system32\qt-dx331.dll 2008-06-11 01:03:26 196608 --a----c- C:\WINDOWS\system32\dtu100.dll 2008-06-11 01:03:26 81920 --a----c- C:\WINDOWS\system32\dpl100.dll 2008-06-11 01:03:20 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll 2008-06-11 01:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll 2008-06-11 01:03:20 815104 --a------ C:\WINDOWS\system32\divx_xx0a.dll 2008-06-11 01:03:20 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll 2008-06-11 01:03:18 683520 --a------ C:\WINDOWS\system32\DivX.dll 2008-05-22 23:18:54 12288 --a----c- C:\WINDOWS\system32\DivXWMPExtType.dll -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}] C:\WINDOWS\system32\winsrc.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{094133C8-1D3D-4785-8A56-531CC89612EF}] 25/07/2008 13:00 32768 --a------ C:\WINDOWS\system32\tuvVOFyV.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22BB2D8D-B263-43F4-B7E4-2F5DCD577625}] 31/07/2008 19:39 283136 --a------ C:\WINDOWS\system32\efccCSih.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31ddf05d-83df-4a6e-a817-79e46fdcb54e}] C:\WINDOWS\system32\iwtwba.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}] 31/07/2008 20:43 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c393b5ba-fdf5-99f1-e4c8-4692a5ff79a9}] 08/07/2008 16:10 158208 --a------ C:\WINDOWS\system32\eniqtzjffpagqbyjn.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C690EBA3-843B-44EA-98C7-8FAB83826171}] C:\WINDOWS\system32\geBtsSlj.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FBE8BCFF-0235-42F7-9C21-03E988C86FE6}] C:\WINDOWS\system32\ddcCrRIx.dll [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [31/07/2008 20:43 2055960] [-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}] [HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 12:50] "DVDTray"="C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe" [03/09/2004 09:58] "AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [07/12/2007 16:30] "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [10/03/2007 01:04] "%FP%Friendly fts.exe"="C:\Program Files\VoyagerTest\fts.exe" [06/05/2003 10:28] "HostManager"="C:\Program Files\Common Files\AOL\1173903062\ee\AOLSoftware.exe" [17/11/2006 14:21] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25] "Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [03/06/2002 11:38] "EPSON Stylus Photo R200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.exe" [11/09/2003 04:00] "AOLAspSunset2"="C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe" [] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [30/11/2004 22:10] "XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [26/09/2007 19:05] "amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [23/07/2007 12:06] "DSLSTATEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe" [28/06/2003 17:10] "DSLAGENTEXE"="C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe" [19/08/2003 14:47] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 22:16] "MyWebSearch Plugin"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL" [11/06/2008 19:15] "My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [11/06/2008 19:15] "MyWebSearch Email Plugin"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe" [11/06/2008 19:15] "kdx"="C:\Program Files\Kontiki\KHost.exe" [27/02/2008 18:56] "{cbf74647-2ff5-dc6c-46cd-94d62d94e88f}"="C:\WINDOWS\system32\eniqtzjffpagqbyjn.dll" [08/07/2008 16:10] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [10/07/2008 09:47] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [27/05/2008 10:50] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/07/2008 10:51] "8cac459a"="C:\WINDOWS\system32\sswyebbb.dll" [31/07/2008 19:45] "BM8f9f7606"="C:\WINDOWS\system32\aqbcavfd.dll" [] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [31/07/2008 20:43] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [28/02/2006 13:00] "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 13:35] "Uniblue RegistryBooster2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [13/10/2004 17:24] "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [14/07/2005 22:35] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/04/2008 23:35] "kdx"="C:\Program Files\Kontiki\KHost.exe" [27/02/2008 18:56] "AOL Dialer"="C:\Program Files\Common Files\AOL\ACS\AOlDial.exe" [07/12/2007 16:30] "MyWebSearch Email Plugin"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe" [11/06/2008 19:15] "01202983901146170543956190995315"="C:\Program Files\AV9\av2009.exe" [31/07/2008 19:58] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [31/07/2008 20:33:14] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [17/01/1999 20:05:56] NCProTray.lnk - C:\Program Files\SEC\Natural Color Pro\NCProTray.exe [27/12/2007 18:26:52] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{094133C8-1D3D-4785-8A56-531CC89612EF}"= C:\WINDOWS\system32\tuvVOFyV.dll [25/07/2008 13:00 32768] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvVOFyV] tuvVOFyV.dll 25/07/2008 13:00 32768 C:\WINDOWS\system32\tuvVOFyV.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=avgrsstx.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\WINDOWS\system32\efccCSih [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3b2449d-abaa-11db-b772-806d6172696f}] AutoRun\command- F:\Bin\assetup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f472d1d0-b3aa-11dc-9454-0011f5ade58f}] AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.mgae.com/keylauncher/?code=3654338236377835 *Newly Created Service* - AVG8EMC *Newly Created Service* - AVG8WD *Newly Created Service* - AVGLDX86 *Newly Created Service* - AVGMFX86 *Newly Created Service* - AVGTDIX [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static] msiexec /fums {3CBBEE47-C8F4-316A-92FF-ED7E3DFAE41E} /qb -- End of Deckard's System Scanner: finished at 2008-07-31 22:26:26 ------------