Deckard's System Scanner v20071014.68
Run by Administrator on 2008-02-20 22:47:12
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-02-20 14:47:13 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:47:57 PM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\DOCUME~1\ADMINI~1\Desktop\PROGRAMS\HIJACK~1\Administrator.exe
C:\WINDOWS\system32\NOTEPAD2.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\Wtablet\TabUserW.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.arcadetow...aploader_v6.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{34E2A552-FCC7-4DCB-B63E-0255E6D34129}: NameServer = 58.69.254.44 58.69.254.46
O17 - HKLM\System\CS1\Services\Tcpip\..\{34E2A552-FCC7-4DCB-B63E-0255E6D34129}: NameServer = 58.69.254.44 58.69.254.46
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\Common Files\A&W\MidRadio.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
-- HijackThis Fixed Entries (C:\DOCUME~1\ADMINI~1\Desktop\PROGRAMS\HIJACK~1\backups\) --------------------------------------------------------------------------------
backup-20070817-175459-131 O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\WebAssist.dll
backup-20070817-181516-834 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
backup-20070817-181516-917 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
backup-20080220-224433-298 O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
backup-20080220-224433-476 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
backup-20080220-224433-549 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
backup-20080220-224433-632 O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
backup-20080220-224433-662 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
backup-20080220-224433-798 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
-- File Associations -----------------------------------------------------------
.bat - batfile - shell\edit\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.cmd - cmdfile - shell\edit\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.inf - inffile - shell\open\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.ini - inifile - shell\open\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.reg - regfile - shell\edit\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.txt - txtfile - shell\open\command - C:\WINDOWS\system32\NOTEPAD2.EXE %1.vbs - VBSFile - shell\edit\command - C:\WINDOWS\system32\Notepad2.exe %1-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys <Not Verified; IVT Corporation; BlueSoleil©>
R0 PenClass (Pen Class) - c:\windows\system32\drivers\penclass.sys <Not Verified; Wacom Technology Corporation; Wacom Pen Class Driver>
R2 Haspnt - c:\windows\system32\drivers\haspnt.sys <Not Verified; Aladdin Knowledge Systems; Windows NT HASP Kernel Device Driver>
R2 Sentinel - c:\windows\system32\drivers\sentinel.sys <Not Verified; Rainbow Technologies, Inc.; Sentinel System Driver>
R3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys <Not Verified; IVT Corporation; Windows ® 2000 DDK driver>
R3 BlueletSCOAudio (Bluetooth SCO Audio Service) - c:\windows\system32\drivers\blueletscoaudio.sys <Not Verified; IVT Corporation; Windows ® 2000 DDK driver>
R3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys <Not Verified; IVT Corporation; BlueSoleil>
R3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys
R3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys <Not Verified; IVT Corporation; BlueSoleil>
R3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys <Not Verified; IVT Corporation; BlueSoleil>
S2 DS1410D - c:\windows\system32\drivers\ds1410d.sys (file missing)
S3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys <Not Verified; IVT Corporation; Bluetooth USB Device Driver>
S3 catchme - c:\docume~1\admini~1\locals~1\temp\catchme.sys (file missing)
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 NAL (Nal Service ) - c:\windows\system32\drivers\iqvw32.sys <Not Verified; Intel Corporation; Intel® iQVW32.SYS>
S3 npkcrypt - c:\program files\lineageii\system\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
S3 npkcusb - c:\program files\lineageii\system\npkcusb.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
S3 Sntnlusb (Rainbow USB SuperPro) - c:\windows\system32\drivers\sntnlusb.sys <Not Verified; Rainbow Technologies Inc.; Rainbow Technologies USB Security Device Driver>
S3 XDva011 - c:\windows\system32\xdva011.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Autodesk Licensing Service - "c:\program files\common files\autodesk shared\service\adskscsrv.exe" <Not Verified; Autodesk; Autodesk Licensing Service>
R2 BlueSoleil Hid Service - c:\program files\ivt corporation\bluesoleil\btntservice.exe
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 mi-raysat_3dsmax9_32 (mental ray 3.5 Satellite (32-bit)) - "c:\program files\autodesk\3ds max 9\mentalray\satellite\raysat_3dsmax9_32server.exe"
R2 TabletService - c:\windows\system32\tablet.exe <Not Verified; Wacom Technology, Corp.; Wacom Win32 Tablet Service>
S3 CiSvc (Indexing Service) - c:\windows\system32\cisvc.exe (file missing)
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At95.job
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At71.job
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At47.job
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At23.job
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At143.job
2008-02-20 22:00:00 350 --a------ C:\WINDOWS\Tasks\At119.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At85.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At61.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At37.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At133.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At13.job
2008-02-20 12:00:00 350 --a------ C:\WINDOWS\Tasks\At109.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At96.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At72.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At48.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At24.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At144.job
2008-02-19 23:00:00 350 --a------ C:\WINDOWS\Tasks\At120.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At87.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At63.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At39.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At15.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At135.job
2008-02-19 14:00:00 350 --a------ C:\WINDOWS\Tasks\At111.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At86.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At62.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At38.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At14.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At134.job
2008-02-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At110.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At94.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At70.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At46.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At22.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At142.job
2008-02-18 21:00:00 350 --a------ C:\WINDOWS\Tasks\At118.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At9.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At81.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At57.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At33.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At129.job
2008-02-18 08:00:00 350 --a------ C:\WINDOWS\Tasks\At105.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At80.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At8.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At56.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At32.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At128.job
2008-02-18 07:00:00 350 --a------ C:\WINDOWS\Tasks\At104.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At79.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At7.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At55.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At31.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At127.job
2008-02-18 06:00:00 350 --a------ C:\WINDOWS\Tasks\At103.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At78.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At6.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At54.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At30.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At126.job
2008-02-18 05:00:00 350 --a------ C:\WINDOWS\Tasks\At102.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At77.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At53.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At5.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At29.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At125.job
2008-02-18 04:00:00 350 --a------ C:\WINDOWS\Tasks\At101.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At76.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At52.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At4.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At28.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At124.job
2008-02-18 03:00:00 350 --a------ C:\WINDOWS\Tasks\At100.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At93.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At69.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At45.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At21.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At141.job
2008-02-17 20:00:00 350 --a------ C:\WINDOWS\Tasks\At117.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At92.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At68.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At44.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At20.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At140.job
2008-02-17 19:00:00 350 --a------ C:\WINDOWS\Tasks\At116.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At91.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At67.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At43.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At19.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At139.job
2008-02-17 18:00:00 350 --a------ C:\WINDOWS\Tasks\At115.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At89.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At65.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At41.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At17.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At137.job
2008-02-17 16:00:00 350 --a------ C:\WINDOWS\Tasks\At113.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At88.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At64.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At40.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At16.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At136.job
2008-02-17 15:00:00 350 --a------ C:\WINDOWS\Tasks\At112.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At84.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At60.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At36.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At132.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At12.job
2008-02-17 11:00:00 350 --a------ C:\WINDOWS\Tasks\At108.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At83.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At59.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At35.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At131.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At11.job
2008-02-17 10:00:00 350 --a------ C:\WINDOWS\Tasks\At107.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At82.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At58.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At34.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At130.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At106.job
2008-02-17 09:00:00 350 --a------ C:\WINDOWS\Tasks\At10.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At99.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At75.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At51.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At3.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At27.job
2008-02-17 02:00:00 350 --a------ C:\WINDOWS\Tasks\At123.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At98.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At74.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At50.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At26.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At2.job
2008-02-17 01:00:00 350 --a------ C:\WINDOWS\Tasks\At122.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At97.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At73.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At49.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At25.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At121.job
2008-02-17 00:00:00 350 --a------ C:\WINDOWS\Tasks\At1.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At90.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At66.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At42.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At18.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At138.job
2008-02-16 17:00:00 350 --a------ C:\WINDOWS\Tasks\At114.job
2007-11-30 16:16:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-01-20 and 2008-02-20 -----------------------------
2008-02-20 21:30:24 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-02-16 20:42:08 0 d-------- C:\Documents and Settings\Administrator\Application Data\Help
2008-01-20 04:36:22 0 d-------- C:\Program Files\Common Files\INCA Shared
-- Find3M Report ---------------------------------------------------------------
2008-02-20 22:47:48 0 d-------- C:\Documents and Settings\Administrator\Application Data\Free Download Manager
2008-02-20 22:47:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-02-20 21:36:06 12615 --a------ C:\WINDOWS\system32\tablet.dat
2008-02-20 21:36:04 0 --a------ C:\WINDOWS\TempFile
2008-02-20 11:37:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-02-06 21:45:32 0 d-------- C:\Program Files\World of Warcraft
2008-01-27 09:49:15 24224 --a------ C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-01-20 04:36:22 0 d-------- C:\Program Files\Common Files
2008-01-13 19:39:40 1343 --a------ C:\WINDOWS\checkip.dat
2008-01-13 19:38:47 1716 --a------ C:\WINDOWS\ipconfig.dat
2007-12-30 22:19:56 0 d-------- C:\Program Files\LimeWire
2007-12-30 22:18:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2007-12-24 00:02:35 0 d-------- C:\Program Files\Autodesk
2007-12-23 22:28:18 0 d-------- C:\Program Files\Common Files\Alias Shared
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [12/22/2007 08:49 AM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [07/21/2007 02:05 AM]
"RTHDCPL"="RTHDCPL.EXE" [11/15/2006 09:21 AM C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [10/22/2006 12:22 PM C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [10/22/2006 12:22 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 09:26 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"TaskSwitchXP"=C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
"Free Download Manager"=C:\Program Files\Free Download Manager\fdm.exe -autorun
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
TabUserW.exe.lnk - C:\WINDOWS\system32\Wtablet\TabUserW.exe [12/5/2003 12:48:40 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"=1 (0x1)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)
"NoRemoteRecursiveEvents"=1 (0x1)
"MemCheckBoxInRunDlg"=1 (0x1)
"DisableCAD"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoSMHelp"=1 (0x1)
"NoSaveSettings"=0 (0x0)
"DisableCAD"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=1 (0x1)
"ClearRecentDocsOnExit"=1 (0x1)
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"NoSMHelp"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]
C:\Program Files\Free Download Manager\fdm.exe -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskSwitchXP]
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c296e62-5436-11dc-b6a1-0019d16179ca}]
AutoRun\command- F:\password_viewer.exe %1
Explore\command- F:\password_viewer.exe %1
Open\command- F:\password_viewer.exe %1
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4366319a-17e0-11dc-a1d8-0019d16179ca}]
AutoRun\command- EXPLORER.EXE
explore\Command- EXPLORER.EXE
open\Command- EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68d1db2c-514d-11dc-b693-0019d16179ca}]
AutoRun\command- E:\
explore\Command- WScript.exe .\azkaban.vbs
open\Command- WScript.exe .\azkaban.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b55d053a-6574-11dc-b6fb-0019d16179ca}]
AutoRun\command- E:\
explore\Command- WScript.exe .\azkaban.vbs
open\Command- WScript.exe .\azkaban.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9bc6d22-2f6f-11dc-b604-0019d16179ca}]
AutoRun\command- E:\password_viewer.exe %1
Explore\command- E:\password_viewer.exe %1
Open\command- E:\password_viewer.exe %1
-- End of Deckard's System Scanner: finished at 2008-02-20 22:48:21 ------------