MAIN:Deckard's System Scanner v20071014.68
Run by Ilya Shor on 2008-02-29 14:51:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Unable to create WMI object; The operation completed successfully.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).System Drive C: has 9.3 GiB (less than 15%) free.-- HijackThis (run as Ilya Shor.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:56:05 PM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Desktop\dss.exe
C:\DOCUME~1\ILYASH~1.ICO\Desktop\Ilya Shor.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapp...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.comO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll (file missing)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {66DEBAF8-3C4D-4944-B5F5-A629709AB9C9} - (no file)
O2 - BHO: (no name) - {75FFC9F0-CB82-43C0-8BB3-395A8EECDEB6} - (no file)
O2 - BHO: (no name) - {80251448-BB28-45E8-B655-DFB6FB940B08} - C:\WINDOWS\system32\jkhfc.dll
O2 - BHO: (no name) - {E4C33052-78B6-44B2-A8AA-31DC1FE78759} - (no file)
O2 - BHO: (no name) - {EF8EFD1C-0BE3-4D13-957A-738643AFD590} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [BM7b4db051] Rundll32.exe "C:\WINDOWS\system32\wrhshuwc.dll",s
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [787e83cd] rundll32.exe "C:\WINDOWS\system32\wwrnyyng.dll",b
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [] (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - S-1-5-21-1004336348-1078081533-725345543-1004 Startup: PowerReg Scheduler V3.exe (User '?')
O4 - S-1-5-21-1004336348-1078081533-725345543-1004 Startup: TA_Start.lnk = C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Local Settings\Temp\thinksnet.exe (User '?')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Local Settings\Temp\thinksnet.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...81/mcinsctl.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by102fd.bay10...es/MsnPUpld.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,16/mcgdmgr.cabO16 - DPF: {C190FF32-96D0-445F-9F60-5CF288FD3D0F} (ActiveFormX Control) -
https://resnet.verif.../CAT/CNICAT.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://bigflash.mic...ash/FlashAX.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcaf...350/mcfscan.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalci...illama/ampx.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: jkkkhfd - jkkkhfd.dll (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) -
http://i.xanga.com/p...lie/header2.jpg--
End of file - 9797 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 ddxgb - c:\docume~1\ilyash~1.ico\locals~1\temp\ddxgb.sys (file missing)
3 dsNcAdpt (Juniper Network Connect Adapter) - system32\drivers\dsncadpt.sys (file missing)
3 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys <Not Verified; Network Associates, Inc; Virus Scan Enterprise, Entercept>
2 HPFECP13 - c:\windows\system32\drivers\hpfecp13.sys
3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; Network Associates, Inc.; VirusScan>
1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; Network Associates, Inc.; VirusScan>
1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
1 oreans32 - c:\windows\system32\drivers\oreans32.sys
3 PortTalk - system32\drivers\porttalk.sys (file missing)
3 tbhsd (Tunebite High-Speed Dubbing) - c:\windows\system32\drivers\tbhsd.sys <Not Verified; RapidSolution Software AG; Tunebite High-Speed Dubbing>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe
2 McTaskManager (Network Associates Task Manager) - c:\program files\network associates\virusscan\vstskmgr.exe
4 NMIndexingService - c:\program files\common files\ahead\lib\nmindexingservice.exe (file missing)
2 Viewpoint Manager Service - c:\program files\viewpoint\common\viewpointservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Unable to create WMI object.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-29 00:40:02 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2007-01-19 21:31:21 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2005-05-15 01:07:00 420 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
-- Files created between 2008-01-29 and 2008-02-29 -----------------------------
2008-02-29 03:46:43 84544 --a------ C:\WINDOWS\system32\wwrnyyng.dll
2008-02-29 03:43:43 89664 --a------ C:\WINDOWS\system32\umsxovig.dll
2008-02-28 23:01:57 0 d-------- C:\ComboFix(2)
2008-02-28 03:46:01 85056 --a------ C:\WINDOWS\system32\pgeeekxl.dll
2008-02-28 03:43:01 90176 --a------ C:\WINDOWS\system32\wcihwwnw.dll
2008-02-27 22:33:19 0 d-------- C:\VundoFix Backups
2008-02-27 15:16:38 0 d-------- C:\Program Files\VideoLAN
2008-02-27 15:08:20 116224 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
2008-02-27 15:08:18 23552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL <Not Verified; Microsoft Corporation; MSMAPI-Steuerelementbibliothek>
2008-02-27 15:08:17 0 d-------- C:\Program Files\PDFCreator
2008-02-27 14:28:54 0 dr-h----- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Recent
2008-02-27 03:42:25 89152 --a------ C:\WINDOWS\system32\iwqxwvnh.dll
2008-02-27 02:42:06 86080 -----n--- C:\WINDOWS\system32\bhkfqrrq.dll
2008-02-27 01:01:14 32 --a------ C:\WINDOWS\go
2008-02-26 02:44:04 90688 --a------ C:\WINDOWS\system32\xtvkewgb.dll
2008-02-26 02:41:04 85056 -----n--- C:\WINDOWS\system32\cxssiyvx.dll
2008-02-26 01:10:42 0 d-------- C:\Program Files\USBDLM
2008-02-25 14:31:39 290551 --ahs---- C:\WINDOWS\system32\cfhkj.ini2
2008-02-25 14:31:16 321600 -----n--- C:\WINDOWS\system32\jkhfc.dll
2008-02-25 14:26:16 41723 ---hs---- C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
2008-02-25 14:26:11 0 d-------- C:\WINDOWS\system32\iDlo01
2008-02-24 16:02:14 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Juniper Networks
2008-02-24 13:53:05 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-22 02:40:25 0 d-------- C:\Program Files\Western Digital Technologies
2008-02-22 02:39:15 364544 --a------ C:\WINDOWS\system32\WDBtnMgr.exe <Not Verified; Western Digital Technologies, Inc.; WD Button Manager>
2008-02-22 02:20:09 0 d-------- C:\New Folder
2008-02-22 01:51:46 0 d-------- C:\WINDOWS\system32\NtmsData
2008-02-21 08:05:08 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
2008-01-29 12:37:19 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
-- Find3M Report ---------------------------------------------------------------
2008-02-29 01:18:52 0 d-------- C:\Program Files\DC++
2008-02-28 22:53:39 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Skype
2008-02-27 16:58:30 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\vlc
2008-02-27 14:23:22 0 d-------- C:\Program Files\Ares Lite Edition
2008-02-27 01:59:04 120 --a------ C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\AVSDVDPlayer.m3u
2008-02-25 14:26:16 0 d-a------ C:\Program Files\Common Files
2008-02-23 01:39:33 0 d-------- C:\Program Files\Microsoft Silverlight
2008-02-21 08:34:56 0 d-------- C:\Program Files\Common Files\?ecurity
2008-02-21 08:01:16 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\AdobeUM
2008-01-30 17:40:29 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Adobe
2008-01-21 23:27:54 0 d-------- C:\Program Files\Camfrog
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66DEBAF8-3C4D-4944-B5F5-A629709AB9C9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75FFC9F0-CB82-43C0-8BB3-395A8EECDEB6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80251448-BB28-45E8-B655-DFB6FB940B08}]
02/25/2008 02:31 PM 321600 --------- C:\WINDOWS\system32\jkhfc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4C33052-78B6-44B2-A8AA-31DC1FE78759}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF8EFD1C-0BE3-4D13-957A-738643AFD590}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 07:00 PM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [08/06/2004 02:50 AM]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [08/02/2007 11:59 AM]
"BM7b4db051"="C:\WINDOWS\system32\wrhshuwc.dll" []
"QuickTime Task"="C:\PROGRAM FILES\QUICKTIME\QTTASK.exe" [10/25/2006 06:58 PM]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [08/04/2004 02:56 AM]
"787e83cd"="C:\WINDOWS\system32\wwrnyyng.dll" [02/29/2008 03:46 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [08/01/2006 02:35 PM]
"@"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [12/27/2003 5:14:11 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{ED120D76-BF31-412C-A99B-783C6676E128}"= C:\WINDOWS\system32\jkkkhfd.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkkhfd]
jkkkhfd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\jkhfc.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ilya Shor.ICOMPUTETHINGS^Start Menu^Programs^Startup^Check For Dope Wars Updates.lnk]
path=C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Start Menu\Programs\Startup\Check For Dope Wars Updates.lnk
backup=C:\WINDOWS\pss\Check For Dope Wars Updates.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
"C:\Program Files\America Online 9.0\AOL.EXE" -b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares Lite Edition\Ares.exe" -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunDLL]
rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\saap]
c:\program files\search-assistant\saap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOLService"=2 (0x2)
"McAfeeFramework"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-02-29 14:57:16 ------------
EXTRADeckard's System Scanner v20071014.68
Run by Ilya Shor on 2008-02-29 14:51:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Unable to create WMI object; The operation completed successfully.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).System Drive C: has 9.3 GiB (less than 15%) free.-- HijackThis (run as Ilya Shor.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:56:05 PM, on 2/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Desktop\dss.exe
C:\DOCUME~1\ILYASH~1.ICO\Desktop\Ilya Shor.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapp...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.comO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll (file missing)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {66DEBAF8-3C4D-4944-B5F5-A629709AB9C9} - (no file)
O2 - BHO: (no name) - {75FFC9F0-CB82-43C0-8BB3-395A8EECDEB6} - (no file)
O2 - BHO: (no name) - {80251448-BB28-45E8-B655-DFB6FB940B08} - C:\WINDOWS\system32\jkhfc.dll
O2 - BHO: (no name) - {E4C33052-78B6-44B2-A8AA-31DC1FE78759} - (no file)
O2 - BHO: (no name) - {EF8EFD1C-0BE3-4D13-957A-738643AFD590} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [BM7b4db051] Rundll32.exe "C:\WINDOWS\system32\wrhshuwc.dll",s
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [787e83cd] rundll32.exe "C:\WINDOWS\system32\wwrnyyng.dll",b
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [] (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1004336348-1078081533-725345543-1004\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - S-1-5-21-1004336348-1078081533-725345543-1004 Startup: PowerReg Scheduler V3.exe (User '?')
O4 - S-1-5-21-1004336348-1078081533-725345543-1004 Startup: TA_Start.lnk = C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Local Settings\Temp\thinksnet.exe (User '?')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Local Settings\Temp\thinksnet.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...81/mcinsctl.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by102fd.bay10...es/MsnPUpld.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,16/mcgdmgr.cabO16 - DPF: {C190FF32-96D0-445F-9F60-5CF288FD3D0F} (ActiveFormX Control) -
https://resnet.verif.../CAT/CNICAT.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://bigflash.mic...ash/FlashAX.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcaf...350/mcfscan.cabO16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalci...illama/ampx.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: jkkkhfd - jkkkhfd.dll (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) -
http://i.xanga.com/p...lie/header2.jpg--
End of file - 9797 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
3 ddxgb - c:\docume~1\ilyash~1.ico\locals~1\temp\ddxgb.sys (file missing)
3 dsNcAdpt (Juniper Network Connect Adapter) - system32\drivers\dsncadpt.sys (file missing)
3 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys <Not Verified; Network Associates, Inc; Virus Scan Enterprise, Entercept>
2 HPFECP13 - c:\windows\system32\drivers\hpfecp13.sys
3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; Network Associates, Inc.; VirusScan>
1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; Network Associates, Inc.; VirusScan>
1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
1 oreans32 - c:\windows\system32\drivers\oreans32.sys
3 PortTalk - system32\drivers\porttalk.sys (file missing)
3 tbhsd (Tunebite High-Speed Dubbing) - c:\windows\system32\drivers\tbhsd.sys <Not Verified; RapidSolution Software AG; Tunebite High-Speed Dubbing>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe
2 McTaskManager (Network Associates Task Manager) - c:\program files\network associates\virusscan\vstskmgr.exe
4 NMIndexingService - c:\program files\common files\ahead\lib\nmindexingservice.exe (file missing)
2 Viewpoint Manager Service - c:\program files\viewpoint\common\viewpointservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Unable to create WMI object.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-29 00:40:02 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2007-01-19 21:31:21 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2005-05-15 01:07:00 420 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
-- Files created between 2008-01-29 and 2008-02-29 -----------------------------
2008-02-29 03:46:43 84544 --a------ C:\WINDOWS\system32\wwrnyyng.dll
2008-02-29 03:43:43 89664 --a------ C:\WINDOWS\system32\umsxovig.dll
2008-02-28 23:01:57 0 d-------- C:\ComboFix(2)
2008-02-28 03:46:01 85056 --a------ C:\WINDOWS\system32\pgeeekxl.dll
2008-02-28 03:43:01 90176 --a------ C:\WINDOWS\system32\wcihwwnw.dll
2008-02-27 22:33:19 0 d-------- C:\VundoFix Backups
2008-02-27 15:16:38 0 d-------- C:\Program Files\VideoLAN
2008-02-27 15:08:20 116224 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
2008-02-27 15:08:18 23552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL <Not Verified; Microsoft Corporation; MSMAPI-Steuerelementbibliothek>
2008-02-27 15:08:17 0 d-------- C:\Program Files\PDFCreator
2008-02-27 14:28:54 0 dr-h----- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Recent
2008-02-27 03:42:25 89152 --a------ C:\WINDOWS\system32\iwqxwvnh.dll
2008-02-27 02:42:06 86080 -----n--- C:\WINDOWS\system32\bhkfqrrq.dll
2008-02-27 01:01:14 32 --a------ C:\WINDOWS\go
2008-02-26 02:44:04 90688 --a------ C:\WINDOWS\system32\xtvkewgb.dll
2008-02-26 02:41:04 85056 -----n--- C:\WINDOWS\system32\cxssiyvx.dll
2008-02-26 01:10:42 0 d-------- C:\Program Files\USBDLM
2008-02-25 14:31:39 290551 --ahs---- C:\WINDOWS\system32\cfhkj.ini2
2008-02-25 14:31:16 321600 -----n--- C:\WINDOWS\system32\jkhfc.dll
2008-02-25 14:26:16 41723 ---hs---- C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
2008-02-25 14:26:11 0 d-------- C:\WINDOWS\system32\iDlo01
2008-02-24 16:02:14 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Juniper Networks
2008-02-24 13:53:05 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-22 02:40:25 0 d-------- C:\Program Files\Western Digital Technologies
2008-02-22 02:39:15 364544 --a------ C:\WINDOWS\system32\WDBtnMgr.exe <Not Verified; Western Digital Technologies, Inc.; WD Button Manager>
2008-02-22 02:20:09 0 d-------- C:\New Folder
2008-02-22 01:51:46 0 d-------- C:\WINDOWS\system32\NtmsData
2008-02-21 08:05:08 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
2008-01-29 12:37:19 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
-- Find3M Report ---------------------------------------------------------------
2008-02-29 01:18:52 0 d-------- C:\Program Files\DC++
2008-02-28 22:53:39 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Skype
2008-02-27 16:58:30 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\vlc
2008-02-27 14:23:22 0 d-------- C:\Program Files\Ares Lite Edition
2008-02-27 01:59:04 120 --a------ C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\AVSDVDPlayer.m3u
2008-02-25 14:26:16 0 d-a------ C:\Program Files\Common Files
2008-02-23 01:39:33 0 d-------- C:\Program Files\Microsoft Silverlight
2008-02-21 08:34:56 0 d-------- C:\Program Files\Common Files\?ecurity
2008-02-21 08:01:16 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\AdobeUM
2008-01-30 17:40:29 0 d-------- C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Application Data\Adobe
2008-01-21 23:27:54 0 d-------- C:\Program Files\Camfrog
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66DEBAF8-3C4D-4944-B5F5-A629709AB9C9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75FFC9F0-CB82-43C0-8BB3-395A8EECDEB6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80251448-BB28-45E8-B655-DFB6FB940B08}]
02/25/2008 02:31 PM 321600 --------- C:\WINDOWS\system32\jkhfc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4C33052-78B6-44B2-A8AA-31DC1FE78759}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF8EFD1C-0BE3-4D13-957A-738643AFD590}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 07:00 PM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [08/06/2004 02:50 AM]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [08/02/2007 11:59 AM]
"BM7b4db051"="C:\WINDOWS\system32\wrhshuwc.dll" []
"QuickTime Task"="C:\PROGRAM FILES\QUICKTIME\QTTASK.exe" [10/25/2006 06:58 PM]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [08/04/2004 02:56 AM]
"787e83cd"="C:\WINDOWS\system32\wwrnyyng.dll" [02/29/2008 03:46 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [08/01/2006 02:35 PM]
"@"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:56 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [12/27/2003 5:14:11 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{ED120D76-BF31-412C-A99B-783C6676E128}"= C:\WINDOWS\system32\jkkkhfd.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkkhfd]
jkkkhfd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\jkhfc.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ilya Shor.ICOMPUTETHINGS^Start Menu^Programs^Startup^Check For Dope Wars Updates.lnk]
path=C:\Documents and Settings\Ilya Shor.ICOMPUTETHINGS\Start Menu\Programs\Startup\Check For Dope Wars Updates.lnk
backup=C:\WINDOWS\pss\Check For Dope Wars Updates.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
"C:\Program Files\America Online 9.0\AOL.EXE" -b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares Lite Edition\Ares.exe" -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunDLL]
rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\saap]
c:\program files\search-assistant\saap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOLService"=2 (0x2)
"McAfeeFramework"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-02-29 14:57:16 ------------
THANKS FOR YOUR HELP!!