Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Antispyware.net [RESOLVED]


  • This topic is locked This topic is locked

#1
nyychick2

nyychick2

    Member

  • Member
  • PipPip
  • 25 posts
My desktop has had antispyware.net on it for the past few days and while I was gone my system was updated from XP to Vista. I was wondering how I could get rid of the malware on my computer.

Thank you for your help!
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Please download SmitfraudFix (by S!Ri) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
How do I make sure I have it on my computer? I don't want my desktop bg to be gone. I had antispyware.net on my computer when I had XP and then the other day someone came and updated my system to Vista and the popups stopped. But I ran spydoctor on my desktop and I still have about 9000 infections and 70 or so viruses.
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Trust me you have it on your PC

Your desktop can be fixed easily enough if that happens
  • 0

#5
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
SmitFraudFix v2.303

Scan done at 21:29:23.00, Fri 03/14/2008
Run from C:\Users\Home\Desktop\SmitfraudFix
OS: Microsoft Windows [Version 6.0.6000] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost
::1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\Windows\764.exe Deleted
C:\Windows\absolute key logger.lnk Deleted
C:\Windows\aconti.exe Deleted
C:\Windows\aconti.log Deleted
C:\Windows\acontidialer.txt Deleted
C:\Windows\adbar.dll Deleted
C:\Windows\cbinst$.exe Deleted
C:\Windows\daxtime.dll Deleted
C:\Windows\default.htm Deleted
C:\Windows\dp0.dll Deleted
C:\Windows\eventlowg.dll Deleted
C:\Windows\fhfmm-Uninstaller.exe Deleted
C:\Windows\fhfmm.exe Deleted
C:\Windows\flt.dll Deleted
C:\Windows\hotporn.exe Deleted
C:\Windows\ie_32.exe Deleted
C:\Windows\jd2002.dll Deleted
C:\Windows\kkcomp$.exe Deleted
C:\Windows\kkcomp.dll Deleted
C:\Windows\kkcomp.exe Deleted
C:\Windows\liqad$.exe Deleted
C:\Windows\liqad.dll Deleted
C:\Windows\liqad.exe Deleted
C:\Windows\liqui-Uninstaller.exe Deleted
C:\Windows\liqui.dll Deleted
C:\Windows\liqui.exe Deleted
C:\Windows\ngd.dll Deleted
C:\Windows\pbar.dll Deleted
C:\Windows\spredirect.dll Deleted
C:\Windows\vxddsk.exe Deleted
C:\Windows\wml.exe Deleted
C:\Windows\xadbrk.dll Deleted
C:\Windows\xadbrk.exe Deleted
C:\Windows\xadbrk_.exe Deleted
C:\Windows\xxxvideo.exe Deleted
C:\Windows\system32\ESHOPEE.exe Deleted
C:\Windows\system32\winfrun32.bin Deleted
C:\Windows\system32\acespy\ Deleted
C:\Program Files\akl\ Deleted
C:\Program Files\amsys\ Deleted
C:\Program Files\e-zshopper\ Deleted
C:\Program Files\p2pnetworks\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3580D07F-75A9-4CB3-946D-411EF8C9B6EC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3580D07F-75A9-4CB3-946D-411EF8C9B6EC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{3580D07F-75A9-4CB3-946D-411EF8C9B6EC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



Deckard's System Scanner v20071014.68
Run by Home on 2008-03-14 21:57:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
8: 2008-03-15 01:47:23 UTC - RP16 - Removed AVG 7.5
7: 2008-03-14 10:14:22 UTC - RP15 - Windows Update
6: 2008-03-13 12:56:20 UTC - RP14 - Windows Update
5: 2008-03-12 07:01:27 UTC - RP13 - Windows Update
4: 2008-03-11 09:46:52 UTC - RP12 - Windows Update


-- First Restore Point --
1: 2008-03-09 12:01:17 UTC - RP9 - Windows Update


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 77% (more than 75%).
Total Physical Memory: 510 MiB (1024 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-03-14 22:01:33
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal

Running processes:
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Windows\System32\DSentry.exe
C:\Program Files\Common Files\AOL\1133723631\ee\aolsoftware.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
C:\Windows\System32\taskeng.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Users\Home\Desktop\dss.exe
C:\Windows\System32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsof...search.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,qbkyuvf.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - C:\WINDOWS\system32\ugscvxve.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [vujetmxe] regsvr32 /u "C:\ProgramData\vujetmxe.dll"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AMERIC~1.0A\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [a0928fd1.exe] C:\Documents and Settings\Home\Local Settings\Application Data\a0928fd1.exe
O4 - HKLM\..\Policies\Explorer\Run: [xxhTmzEur0] C:\WINDOWS\pidshuxu.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\network diagnostic\xpnetdiag.exe
O15 - Trusted Zone: *.admissions.nyu.edu (HKCU)
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} () - http://www.addictive...ab/1w2fcksh.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} () - http://download.av.a...83/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/p...owserPlugin.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgall..._2/axofupld.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} () - http://cabs.elitemed...s/mediaview.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} () - http://download.av.a...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft....ayx_vp3_mp3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontec...2ie06101001.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driver...driveragent.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O20 - AppInit_DLLs: c:\windows\system32\awtsrss.dll
O20 - Winlogon Notify: ddcca - C:\Windows\system32\ddcca.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSVCHST.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\Windows\System32\nujwjkwv6.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


--
End of file - 10104 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 AFS2K - c:\windows\system32\drivers\afs2k.sys <Not Verified; Oak Technology Inc.; AFS>
R2 dsunidrv (DellSupport UniDriver) - c:\windows\system32\drivers\dsunidrv.sys <Not Verified; Gteko Ltd.; Gteko Diagnostics>

S3 DSproct - \??\c:\program files\dellsupport\gtaction\triggers\dsproct.sys
S4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys <Not Verified; Mylex Corporation; Mylex Disk Array Controller Driver>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>

S2 sawadtww6 (myivqjirjkoj) - c:\windows\system32\nujwjkwv6.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-03-08 04:16:15 544 --a------ C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Home.job


-- Files created between 2008-02-14 and 2008-03-14 -----------------------------

2008-03-14 21:29:37 3612 --a------ C:\Windows\system32\tmp.reg
2008-03-14 21:29:02 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-03-14 21:29:02 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-14 21:29:02 82432 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-14 21:24:39 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-14 21:24:38 51200 --a------ C:\Windows\system32\dumphive.exe
2008-03-14 21:24:36 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-14 21:24:36 53248 --a------ C:\Windows\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-08 21:23:10 0 d-------- C:\Users\Home\.housecall6.6
2008-03-07 23:35:53 0 d-------- C:\Windows\Panther
2008-03-07 23:10:47 0 d--h----- C:\$WINDOWS.~Q
2008-03-07 22:56:18 0 d--h----- C:\$INPLACE.~TR
2008-03-07 22:35:09 0 d-------- C:\Program Files\Norton Internet Security
2008-03-07 22:11:38 0 dr------- C:\Users\Home\Searches
2008-03-07 22:11:21 0 dr------- C:\Users\Home\Contacts
2008-03-07 21:48:22 22668 --a------ C:\Windows\system32\emptyregdb.dat
2008-03-07 21:33:20 0 d-------- C:\Users\Default\video
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Templates
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Start Menu
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\SendTo
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Recent
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\PrintHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\NetHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\My Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Music
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\Local Settings
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Links
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Favorites
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Downloads
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Desktop
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Cookies
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Application Data
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\AppData
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Videos
2008-03-07 20:52:31 0 d-------- C:\Users\Bhavini\Saved Games
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Pictures
2008-03-07 20:52:31 2105344 --a------ C:\Users\Bhavini\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Templates
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Start Menu
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\SendTo
2008-03-07 20:52:27 0 d-------- C:\Users\Minal\Saved Games
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Recent
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\PrintHood
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Pictures
2008-03-07 20:52:27 2748416 --a------ C:\Users\Minal\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\NetHood
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\My Documents
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\Local Settings
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Links
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Favorites
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Downloads
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Documents
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Desktop
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Cookies
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Application Data
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\AppData
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Templates
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Start Menu
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\SendTo
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Recent
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\PrintHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\NetHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\My Documents
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\Local Settings
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Cookies
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Application Data
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Saved Games
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Pictures
2008-03-07 20:52:22 3670016 --ahs---- C:\Users\Home\NTUSER.DAT
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Music
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Links
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Favorites
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Downloads
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Documents
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Desktop
2008-03-07 20:52:22 0 d--h----- C:\Users\Home\AppData
2008-03-07 20:50:18 0 d-------- C:\Windows\system32\URTTEMP
2008-03-07 20:50:05 0 d--hs---- C:\Windows\Installer
2008-03-07 20:45:56 0 d-------- C:\Windows\system32\catroot2
2008-03-07 20:45:28 0 d-------- C:\Windows\Debug
2008-03-07 20:45:27 0 d-------- C:\Windows\CSC
2008-03-07 20:36:56 0 d-------- C:\Windows\Prefetch
2008-03-07 19:49:51 0 d--hs---- C:\Boot
2008-03-07 19:10:36 0 d------c- C:\Windows\system32\DRVSTORE
2008-03-03 01:09:18 0 d-------- C:\Program Files\Enigma Software Group
2008-03-02 19:14:43 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-02 17:31:30 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-02 00:01:22 0 d-a------ C:\Users\All Users\TEMP
2008-03-01 14:34:54 0 d-------- C:\Program Files\QdrDrive


-- Find3M Report ---------------------------------------------------------------

2008-03-13 09:13:49 0 d-------- C:\Program Files\Windows Mail
2008-03-08 21:04:53 9826 --a------ C:\Windows\mozver.dat
2008-03-08 17:33:27 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-08 16:49:29 0 d-------- C:\Program Files\Symantec
2008-03-08 04:26:29 174 --ahs---- C:\Program Files\desktop.ini
2008-03-08 04:12:23 0 d-------- C:\Program Files\Windows Calendar
2008-03-08 04:12:09 0 d-------- C:\Program Files\Windows Defender
2008-03-08 04:11:56 0 d-------- C:\Program Files\Windows Sidebar
2008-03-07 23:01:39 0 d-------- C:\Program Files\Common Files
2008-03-07 21:23:04 0 d-------- C:\Users\Home\AppData\Roaming\Webshots
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\WeatherBug
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\vlc
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\Viewpoint
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Talkback
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Symantec
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sun
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sonic
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Registry Defender
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Real
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\MSN6
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\Mozilla
2008-03-07 21:22:13 0 d--h----- C:\Users\Home\AppData\Roaming\Move Networks
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Macromedia
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Leadertech
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Jasc Software Inc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Jasc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Identities
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\ICAClient
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\HotSync
2008-03-07 21:21:28 0 d--h----- C:\Users\Home\AppData\Roaming\Gtek
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Google
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\ESPN
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\CyberLink
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel Photo Album
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\Apple Computer
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\AOL
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Aim
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Adobe
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\acccore
2008-03-07 21:09:39 0 d-------- C:\Program Files\Your Company Name
2008-03-07 21:09:37 0 d-------- C:\Program Files\WordPerfect Office 11
2008-03-07 21:09:13 0 d--hs---- C:\Program Files\winupdates
2008-03-07 21:09:13 0 d-------- C:\Program Files\WildTangent
2008-03-07 21:09:08 0 d-------- C:\Program Files\Viewpoint
2008-03-07 21:09:06 0 d-------- C:\Program Files\support.com
2008-03-07 21:08:57 0 d-------- C:\Program Files\Real
2008-03-07 21:08:56 0 d-------- C:\Program Files\QuickTime
2008-03-07 21:08:42 0 d-------- C:\Program Files\PokerRoom.com
2008-03-07 21:08:42 0 d-------- C:\Program Files\Photo Pos Pro
2008-03-07 21:08:41 0 d-------- C:\Program Files\palmOne
2008-03-07 21:08:37 0 d-------- C:\Program Files\Ofoto
2008-03-07 21:06:25 0 d-------- C:\Program Files\NetZero
2008-03-07 21:06:22 0 d-------- C:\Program Files\MUSICMATCH
2008-03-07 21:06:22 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-07 21:06:17 0 d-------- C:\Program Files\Modem Helper
2008-03-07 21:06:00 0 d-------- C:\Program Files\microsoft frontpage
2008-03-07 21:06:00 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-07 21:06:00 0 d-------- C:\Program Files\McAfee.com
2008-03-07 21:06:00 0 d-------- C:\Program Files\MasqueAIM
2008-03-07 21:05:59 0 d-------- C:\Program Files\Learn2.com
2008-03-07 21:05:48 0 d-------- C:\Program Files\Java
2008-03-07 21:05:28 0 d-------- C:\Program Files\Jasc Software Inc
2008-03-07 21:04:33 0 d-------- C:\Program Files\iTunes
2008-03-07 21:04:30 0 d-------- C:\Program Files\iPod
2008-03-07 21:04:27 0 d-------- C:\Program Files\Intel
2008-03-07 21:04:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-07 21:04:25 0 d-------- C:\Program Files\HP
2008-03-07 21:03:00 0 d-------- C:\Program Files\Google
2008-03-07 21:02:59 0 d-------- C:\Program Files\DivX
2008-03-07 21:02:58 0 d-------- C:\Program Files\DellSupport
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell Computer
2008-03-07 21:02:38 0 d-------- C:\Program Files\CyberLink
2008-03-07 21:02:38 0 d-------- C:\Program Files\CorelPaintShopProX_
2008-03-07 21:01:48 0 d-------- C:\Program Files\CorelPaintShopProX
2008-03-07 21:00:39 0 d-------- C:\Program Files\Corel
2008-03-07 21:00:37 0 d-------- C:\Program Files\Connection Wizard
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\WhenU
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\Thraex Software
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Real
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\NSV
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\Java
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-07 21:00:10 0 d-------- C:\Program Files\Common Files\HP
2008-03-07 21:00:09 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-07 21:00:08 0 d-------- C:\Program Files\Common Files\Corel
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\aolshare
2008-03-07 21:00:05 0 d-------- C:\Program Files\Common Files\aolback
2008-03-07 21:00:04 0 d-------- C:\Program Files\Common Files\AOL
2008-03-07 20:59:39 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-07 20:59:39 0 d-------- C:\Program Files\Citrix
2008-03-07 20:59:39 0 d-------- C:\Program Files\BearShare
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOL Companion
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOD
2008-03-07 20:59:36 0 d-------- C:\Program Files\America Online 9.0c
2008-03-07 20:59:31 0 d-------- C:\Program Files\America Online 9.0b
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0a
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM+
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM Toolbar
2008-03-07 20:59:14 0 d-------- C:\Program Files\AIM


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
08/24/2007 11:51 PM 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
03/07/2008 11:01 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A98C34C6-A944-B922-7851-E9DA1F7785B7}]
C:\WINDOWS\system32\ugscvxve.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [08/24/2007 11:51 PM 316784]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/08/2008 03:36 AM]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [08/13/2003 12:27 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe" [11/02/2005 11:01 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 09:38 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 06:28 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/14/2006 04:24 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 09:47 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/02/2006 10:13 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/07/2004 12:39 AM]
"vujetmxe"="regsvr32 /u C:\ProgramData\vujetmxe.dll" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/14/2008 12:01 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [11/02/2006 05:45 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/21/2007 06:55 AM]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" []
"AOL Fast Start"="C:\PROGRA~1\AMERIC~1.0A\AOL.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"a0928fd1.exe"="C:\Documents and Settings\Home\Local Settings\Application Data\a0928fd1.exe" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0c\aoltray.exe [6/28/2005 6:54:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 6:19:24 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 4:05:56 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"xxhTmzEur0"=C:\WINDOWS\pidshuxu.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}"= C:\WINDOWS\system32\ddcca.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\Windows\system32\userinit.exe,qbkyuvf.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcca]
ddcca.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\awtsrss.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc CscService TabletInputService UmRdpService wlansvc WPDBusEnum EMDMgmt
LocalServiceNoNetwork PLA DPS BFE mpssvc
LocalServiceNetworkRestricted DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc PnrpAutoReg


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2deb790-eca7-11dc-9677-806e6f6e6963}]
AutoRun\command- D:\CDSTART.EXE

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-03-14 22:05:14 ------------




Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Business (build 6000)
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 2.66GHz
Percentage of Memory in Use: 72%
Physical Memory (total/avail): 509.44 MiB / 138.59 MiB
Pagefile Memory (total/avail): 1502.29 MiB / 890.74 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1923.25 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 74.47 GiB total, 25.24 GiB free.
D: is CDROM (CDFS)
E: is CDROM (No Media)
F: is Removable (No Media)

\\.\PHYSICALDRIVE0 - ST380011A ATA Device - 74.5 GiB - 2 partitions
\PARTITION0 - Unknown - 31.35 MiB
\PARTITION1 (bootable) - Installable File System - 74.47 GiB - C:

\\.\PHYSICALDRIVE1 - HP USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: Norton Internet Security v15.0.0.60 (Symantec Corporation)
AV: Norton Internet Security v15.0.0.60 (Symantec Corporation)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) Disabled
AS: Norton Internet Security v15.0.0.60 (Symantec Corporation)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\AIM\\AIM95_c0\\aim.exe"="C:\\Program Files\\AIM\\AIM95_c0\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\AIM\\AIM95_c1\\aim.exe"="C:\\Program Files\\AIM\\AIM95_c1\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\AIM\\AIM95_c2\\aim.exe"="C:\\Program Files\\AIM\\AIM95_c2\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLHostManager.exe"="C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLHostManager.exe:*:Disabled:AOLHostManager Service"
"C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1110582691\\EE\\AOLServiceHost.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader"
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"="C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe:*:Enabled:AOL"
"C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe"="C:\\Program Files\\Dell Computer\\Dell Picture Studio v2.0\\launch.exe:*:Enabled:Jasc Paint Shop Photo Album Application"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Save\\Save.exe"="C:\\Program Files\\Save\\Save.exe:*:Disabled:Save!"
"C:\\WINDOWS\\system32"="C:\\WINDOWS\\system32:*:Enabled:lockx"
"C:\\WINDOWS\\SYSTEM32\\rnhtfans.exe"="C:\\WINDOWS\\SYSTEM32\\rnhtfans.exe:*:Enabled:rnhtfans"
"C:\\WINDOWS\\SYSTEM32\\smsc.exe"="C:\\WINDOWS\\SYSTEM32\\smsc.exe:*:Enabled:smsc"
"C:\\XP_FixWinpack.exe"="C:\\XP_FixWinpack.exe:*:Enabled:XP_FixWinpack"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Home\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\j2re1.4.2\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=DJG9J341
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Home
LOCALAPPDATA=C:\Users\Home\AppData\Local
LOGONSERVER=\\DJG9J341
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Sonic Shared;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\j2re1.4.2\lib\ext\QTJava.zip
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Home\AppData\Local\Temp
TMP=C:\Users\Home\AppData\Local\Temp
USERDOMAIN=DJG9J341
USERNAME=Home
USERPROFILE=C:\Users\Home
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

Bhavini (new local)
Minal (new local)
Home


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
--> C:\Program Files\Common Files\Real\Update_OB\rnuninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF00D1-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{25EF03DA-F17B-11D6-88EA-000476CD2443}\Setup.exe" -l0x9 UNINSTALL
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{410438A3-B591-4028-B70A-3CC0B33FBCD1}\Setup.exe" -l0x9 -L0x9anything
Adobe Download Manager 1.2 (Remove Only) --> "C:\Program Files\Common Files\Adobe\ESD\uninst.exe"
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7646-A00000000001}
AIM+ (remove only) --> "C:\Program Files\AIM+\uninst.exe"
AOL Coach Version 1.0(Build:20030807.3) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
AOL Uninstaller --> C:\Program Files\Common Files\AOL\uninstaller.exe
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
BCM V.92 56K Modem --> C:\Windows\BCMSMU.exe quiet
BUM --> MsiExec.exe /I{55937F00-A69B-4049-8D3A-1C7729742B6F}
ccCommon --> MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
Component Framework --> MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
Dell Digital Jukebox Driver --> C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Media Experience --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe" -uninstall
Dell Solution Center --> MsiExec.exe /X{11F1920A-56A2-4642-B6E0-3B31A12C9288}
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DS21Patch --> MsiExec.exe /I{9B79DCB0-AAD7-456B-8D07-433C936FA24B}
DVDSentry --> MsiExec.exe /I{98DF85D9-96C0-4F57-A92E-C3539477EF5E}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
HP Image Zone 3.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP PSC & OfficeJet 3.5 --> "C:\Program Files\HP\Digital Imaging\{0FABD3D7-3036-4e78-B29D-58957ADB0A12}\setup\hpzscr01.exe" -datfile hposcr03.dat
HP Software Update --> MsiExec.exe /X{34957B51-9676-41CE-9E52-44AE91B73F1C}
Icons --> C:\WINDOWS\system32\uninsticn
Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&a
  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,qbkyuvf.exe,
O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - C:\WINDOWS\system32\ugscvxve.dll (file missing)
O4 - HKLM\..\Run: [vujetmxe] regsvr32 /u "C:\ProgramData\vujetmxe.dll"
O4 - HKCU\..\Run: [a0928fd1.exe] C:\Documents and Settings\Home\Local Settings\Application Data\a0928fd1.exe
O4 - HKLM\..\Policies\Explorer\Run: [xxhTmzEur0] C:\WINDOWS\pidshuxu.exe
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} () - http://cabs.elitemed...s/mediaview.cab
O20 - AppInit_DLLs: c:\windows\system32\awtsrss.dll
O20 - Winlogon Notify: ddcca - C:\Windows\system32\ddcca.dll (file missing)
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\Windows\System32\nujwjkwv6.exe


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\QdrDrive
    C:\Windows\System32\nujwjkwv6.exe
    c:\windows\system32\awtsrss.dll
    C:\WINDOWS\pidshuxu.exe
    C:\Documents and Settings\Home\Local Settings\Application Data\a0928fd1.exe
    C:\ProgramData\vujetmxe.dll
    C:\Windows\system32\qbkyuvf.exe
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    purity
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Reboot and post a new DSS log
  • 0

#7
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
I ran everything I just couldn't save the Results to post. Is there anyway to get it back so I can post it here?
  • 0

#8
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Just go ahead and run DSS there, that will let me see if the files are present
  • 0

#9
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
I am sorry, but I don't know what that means.
  • 0

#10
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
DSS = Deckards System Scanner

You ran it in Post #2

I need you to run it again and post the log. It should be on your desktop
  • 0

Advertisements


#11
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Okay, thank you.

Deckard's System Scanner v20071014.68
Run by Home on 2008-03-16 16:04:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 510 MiB (1024 MiB recommended).


-- HijackThis (run as Home.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:04:50 PM, on 3/16/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DSentry.exe
C:\Program Files\Common Files\AOL\1133723631\ee\aolsoftware.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Home.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AMERIC~1.0A\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [xxhTmzEur0] C:\WINDOWS\pidshuxu.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O13 - Gopher Prefix:
O15 - Trusted Zone: admissions.nyu.edu
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.addictive...ab/1w2fcksh.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.a...83/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/p...owserPlugin.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgall..._2/axofupld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.a...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft....ayx_vp3_mp3.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontec...2ie06101001.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driver...driveragent.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\WINDOWS\system32\nujwjkwv6.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 9062 bytes

-- Files created between 2008-02-16 and 2008-03-16 -----------------------------

2008-03-15 11:51:42 0 d-------- C:\Program Files\Trend Micro
2008-03-14 21:29:37 3612 --a------ C:\Windows\system32\tmp.reg
2008-03-14 21:29:02 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-03-14 21:29:02 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-14 21:29:02 82432 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-14 21:24:39 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-14 21:24:38 51200 --a------ C:\Windows\system32\dumphive.exe
2008-03-14 21:24:36 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-14 21:24:36 53248 --a------ C:\Windows\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-08 21:23:10 0 d-------- C:\Users\Home\.housecall6.6
2008-03-07 23:35:53 0 d-------- C:\Windows\Panther
2008-03-07 23:10:47 0 d--h----- C:\$WINDOWS.~Q
2008-03-07 22:56:18 0 d--h----- C:\$INPLACE.~TR
2008-03-07 22:35:09 0 d-------- C:\Program Files\Norton Internet Security
2008-03-07 22:11:38 0 dr------- C:\Users\Home\Searches
2008-03-07 22:11:21 0 dr------- C:\Users\Home\Contacts
2008-03-07 21:48:22 22668 --a------ C:\Windows\system32\emptyregdb.dat
2008-03-07 21:33:20 0 d-------- C:\Users\Default\video
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Templates
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Start Menu
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\SendTo
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Recent
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\PrintHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\NetHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\My Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Music
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\Local Settings
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Links
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Favorites
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Downloads
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Desktop
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Cookies
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Application Data
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\AppData
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Videos
2008-03-07 20:52:31 0 d-------- C:\Users\Bhavini\Saved Games
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Pictures
2008-03-07 20:52:31 2105344 --a------ C:\Users\Bhavini\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Templates
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Start Menu
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\SendTo
2008-03-07 20:52:27 0 d-------- C:\Users\Minal\Saved Games
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Recent
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\PrintHood
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Pictures
2008-03-07 20:52:27 2748416 --a------ C:\Users\Minal\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\NetHood
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\My Documents
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\Local Settings
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Links
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Favorites
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Downloads
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Documents
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Desktop
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Cookies
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Application Data
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\AppData
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Templates
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Start Menu
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\SendTo
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Recent
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\PrintHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\NetHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\My Documents
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\Local Settings
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Cookies
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Application Data
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Saved Games
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Pictures
2008-03-07 20:52:22 3670016 --ahs---- C:\Users\Home\NTUSER.DAT
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Music
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Links
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Favorites
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Downloads
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Documents
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Desktop
2008-03-07 20:52:22 0 d--h----- C:\Users\Home\AppData
2008-03-07 20:50:18 0 d-------- C:\Windows\system32\URTTEMP
2008-03-07 20:50:05 0 d--hs---- C:\Windows\Installer
2008-03-07 20:45:56 0 d-------- C:\Windows\system32\catroot2
2008-03-07 20:45:28 0 d-------- C:\Windows\Debug
2008-03-07 20:45:27 0 d-------- C:\Windows\CSC
2008-03-07 20:36:56 0 d-------- C:\Windows\Prefetch
2008-03-07 19:49:51 0 d--hs---- C:\Boot
2008-03-07 19:10:36 0 d------c- C:\Windows\system32\DRVSTORE
2008-03-03 01:09:18 0 d-------- C:\Program Files\Enigma Software Group
2008-03-02 19:14:43 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-02 17:31:30 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-02 00:01:22 0 d-a------ C:\Users\All Users\TEMP


-- Find3M Report ---------------------------------------------------------------

2008-03-13 09:13:49 0 d-------- C:\Program Files\Windows Mail
2008-03-08 21:04:53 9826 --a------ C:\Windows\mozver.dat
2008-03-08 17:33:27 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-08 16:49:29 0 d-------- C:\Program Files\Symantec
2008-03-08 04:26:29 174 --ahs---- C:\Program Files\desktop.ini
2008-03-08 04:12:23 0 d-------- C:\Program Files\Windows Calendar
2008-03-08 04:12:09 0 d-------- C:\Program Files\Windows Defender
2008-03-08 04:11:56 0 d-------- C:\Program Files\Windows Sidebar
2008-03-07 23:01:39 0 d-------- C:\Program Files\Common Files
2008-03-07 21:23:04 0 d-------- C:\Users\Home\AppData\Roaming\Webshots
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\WeatherBug
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\vlc
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\Viewpoint
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Talkback
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Symantec
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sun
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sonic
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Registry Defender
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Real
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\MSN6
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\Mozilla
2008-03-07 21:22:13 0 d--h----- C:\Users\Home\AppData\Roaming\Move Networks
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Macromedia
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Leadertech
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Jasc Software Inc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Jasc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Identities
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\ICAClient
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\HotSync
2008-03-07 21:21:28 0 d--h----- C:\Users\Home\AppData\Roaming\Gtek
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Google
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\ESPN
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\CyberLink
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel Photo Album
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\Apple Computer
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\AOL
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Aim
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Adobe
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\acccore
2008-03-07 21:09:39 0 d-------- C:\Program Files\Your Company Name
2008-03-07 21:09:37 0 d-------- C:\Program Files\WordPerfect Office 11
2008-03-07 21:09:13 0 d--hs---- C:\Program Files\winupdates
2008-03-07 21:09:13 0 d-------- C:\Program Files\WildTangent
2008-03-07 21:09:08 0 d-------- C:\Program Files\Viewpoint
2008-03-07 21:09:06 0 d-------- C:\Program Files\support.com
2008-03-07 21:08:57 0 d-------- C:\Program Files\Real
2008-03-07 21:08:56 0 d-------- C:\Program Files\QuickTime
2008-03-07 21:08:42 0 d-------- C:\Program Files\PokerRoom.com
2008-03-07 21:08:42 0 d-------- C:\Program Files\Photo Pos Pro
2008-03-07 21:08:41 0 d-------- C:\Program Files\palmOne
2008-03-07 21:08:37 0 d-------- C:\Program Files\Ofoto
2008-03-07 21:06:25 0 d-------- C:\Program Files\NetZero
2008-03-07 21:06:22 0 d-------- C:\Program Files\MUSICMATCH
2008-03-07 21:06:22 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-07 21:06:17 0 d-------- C:\Program Files\Modem Helper
2008-03-07 21:06:00 0 d-------- C:\Program Files\microsoft frontpage
2008-03-07 21:06:00 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-07 21:06:00 0 d-------- C:\Program Files\McAfee.com
2008-03-07 21:06:00 0 d-------- C:\Program Files\MasqueAIM
2008-03-07 21:05:59 0 d-------- C:\Program Files\Learn2.com
2008-03-07 21:05:48 0 d-------- C:\Program Files\Java
2008-03-07 21:05:28 0 d-------- C:\Program Files\Jasc Software Inc
2008-03-07 21:04:33 0 d-------- C:\Program Files\iTunes
2008-03-07 21:04:30 0 d-------- C:\Program Files\iPod
2008-03-07 21:04:27 0 d-------- C:\Program Files\Intel
2008-03-07 21:04:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-07 21:04:25 0 d-------- C:\Program Files\HP
2008-03-07 21:03:00 0 d-------- C:\Program Files\Google
2008-03-07 21:02:59 0 d-------- C:\Program Files\DivX
2008-03-07 21:02:58 0 d-------- C:\Program Files\DellSupport
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell Computer
2008-03-07 21:02:38 0 d-------- C:\Program Files\CyberLink
2008-03-07 21:02:38 0 d-------- C:\Program Files\CorelPaintShopProX_
2008-03-07 21:01:48 0 d-------- C:\Program Files\CorelPaintShopProX
2008-03-07 21:00:39 0 d-------- C:\Program Files\Corel
2008-03-07 21:00:37 0 d-------- C:\Program Files\Connection Wizard
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\WhenU
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\Thraex Software
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Real
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\NSV
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\Java
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-07 21:00:10 0 d-------- C:\Program Files\Common Files\HP
2008-03-07 21:00:09 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-07 21:00:08 0 d-------- C:\Program Files\Common Files\Corel
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\aolshare
2008-03-07 21:00:05 0 d-------- C:\Program Files\Common Files\aolback
2008-03-07 21:00:04 0 d-------- C:\Program Files\Common Files\AOL
2008-03-07 20:59:39 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-07 20:59:39 0 d-------- C:\Program Files\Citrix
2008-03-07 20:59:39 0 d-------- C:\Program Files\BearShare
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOL Companion
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOD
2008-03-07 20:59:36 0 d-------- C:\Program Files\America Online 9.0c
2008-03-07 20:59:31 0 d-------- C:\Program Files\America Online 9.0b
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0a
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM+
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM Toolbar
2008-03-07 20:59:14 0 d-------- C:\Program Files\AIM


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
08/24/2007 11:51 PM 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
03/07/2008 11:01 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A98C34C6-A944-B922-7851-E9DA1F7785B7}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [08/24/2007 11:51 PM 316784]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/08/2008 03:36 AM]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [08/13/2003 12:27 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe" [11/02/2005 11:01 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 09:38 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 06:28 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/14/2006 04:24 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 09:47 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/02/2006 10:13 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/07/2004 12:39 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/14/2008 12:01 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [11/02/2006 05:45 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/21/2007 06:55 AM]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" []
"AOL Fast Start"="C:\PROGRA~1\AMERIC~1.0A\AOL.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0c\aoltray.exe [6/28/2005 6:54:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 6:19:24 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 4:05:56 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"xxhTmzEur0"=C:\WINDOWS\pidshuxu.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}"= C:\WINDOWS\system32\ddcca.dll [ ]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc CscService TabletInputService UmRdpService wlansvc WPDBusEnum EMDMgmt
LocalServiceNoNetwork PLA DPS BFE mpssvc
LocalServiceNetworkRestricted DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc PnrpAutoReg


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2deb790-eca7-11dc-9677-806e6f6e6963}]
AutoRun\command- D:\CDSTART.EXE

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-03-16 16:05:57 ------------
  • 0

#12
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - (no file)
O4 - HKLM\..\Policies\Explorer\Run: [xxhTmzEur0] C:\WINDOWS\pidshuxu.exe


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Program Files\winupdates
    C:\Program Files\WildTangent
    C:\Program Files\Viewpoint
    C:\WINDOWS\pidshuxu.exe
    D:\CDSTART.EXE
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    purity
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b2deb790-eca7-11dc-9677-806e6f6e6963}
    HKEY_CLASSES_ROOT\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Reboot and post a new DSS log
  • 0

#13
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Deckard's System Scanner v20071014.68
Run by Home on 2008-03-17 11:21:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 510 MiB (1024 MiB recommended).


-- HijackThis (run as Home.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:40 AM, on 3/17/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DSentry.exe
C:\Program Files\Common Files\AOL\1133723631\ee\aolsoftware.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Home.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AMERIC~1.0A\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O13 - Gopher Prefix:
O15 - Trusted Zone: admissions.nyu.edu
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.addictive...ab/1w2fcksh.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.a...83/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/p...owserPlugin.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgall..._2/axofupld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.a...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft....ayx_vp3_mp3.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontec...2ie06101001.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driver...driveragent.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\WINDOWS\system32\nujwjkwv6.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

--
End of file - 8937 bytes

-- Files created between 2008-02-17 and 2008-03-17 -----------------------------

2008-03-15 11:51:42 0 d-------- C:\Program Files\Trend Micro
2008-03-14 21:29:37 3612 --a------ C:\Windows\system32\tmp.reg
2008-03-14 21:29:02 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-03-14 21:29:02 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-14 21:29:02 82432 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-14 21:24:39 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-14 21:24:38 51200 --a------ C:\Windows\system32\dumphive.exe
2008-03-14 21:24:36 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-14 21:24:36 53248 --a------ C:\Windows\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-08 21:23:10 0 d-------- C:\Users\Home\.housecall6.6
2008-03-07 23:35:53 0 d-------- C:\Windows\Panther
2008-03-07 23:10:47 0 d--h----- C:\$WINDOWS.~Q
2008-03-07 22:56:18 0 d--h----- C:\$INPLACE.~TR
2008-03-07 22:35:09 0 d-------- C:\Program Files\Norton Internet Security
2008-03-07 22:11:38 0 dr------- C:\Users\Home\Searches
2008-03-07 22:11:21 0 dr------- C:\Users\Home\Contacts
2008-03-07 21:48:22 22668 --a------ C:\Windows\system32\emptyregdb.dat
2008-03-07 21:33:20 0 d-------- C:\Users\Default\video
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Templates
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Start Menu
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\SendTo
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Recent
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\PrintHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\NetHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\My Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Music
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\Local Settings
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Links
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Favorites
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Downloads
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Desktop
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Cookies
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Application Data
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\AppData
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Videos
2008-03-07 20:52:31 0 d-------- C:\Users\Bhavini\Saved Games
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Pictures
2008-03-07 20:52:31 2105344 --a------ C:\Users\Bhavini\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Templates
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Start Menu
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\SendTo
2008-03-07 20:52:27 0 d-------- C:\Users\Minal\Saved Games
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Recent
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\PrintHood
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Pictures
2008-03-07 20:52:27 2748416 --a------ C:\Users\Minal\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\NetHood
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\My Documents
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\Local Settings
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Links
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Favorites
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Downloads
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Documents
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Desktop
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Cookies
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Application Data
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\AppData
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Templates
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Start Menu
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\SendTo
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Recent
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\PrintHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\NetHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\My Documents
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\Local Settings
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Cookies
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Application Data
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Saved Games
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Pictures
2008-03-07 20:52:22 3670016 --ahs---- C:\Users\Home\NTUSER.DAT
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Music
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Links
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Favorites
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Downloads
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Documents
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Desktop
2008-03-07 20:52:22 0 d--h----- C:\Users\Home\AppData
2008-03-07 20:50:18 0 d-------- C:\Windows\system32\URTTEMP
2008-03-07 20:50:05 0 d--hs---- C:\Windows\Installer
2008-03-07 20:45:56 0 d-------- C:\Windows\system32\catroot2
2008-03-07 20:45:28 0 d-------- C:\Windows\Debug
2008-03-07 20:45:27 0 d-------- C:\Windows\CSC
2008-03-07 20:36:56 0 d-------- C:\Windows\Prefetch
2008-03-07 19:49:51 0 d--hs---- C:\Boot
2008-03-07 19:10:36 0 d------c- C:\Windows\system32\DRVSTORE
2008-03-03 01:09:18 0 d-------- C:\Program Files\Enigma Software Group
2008-03-02 19:14:43 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-02 17:31:30 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-02 00:01:22 0 d-a------ C:\Users\All Users\TEMP


-- Find3M Report ---------------------------------------------------------------

2008-03-13 09:13:49 0 d-------- C:\Program Files\Windows Mail
2008-03-08 21:04:53 9826 --a------ C:\Windows\mozver.dat
2008-03-08 17:33:27 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-08 16:49:29 0 d-------- C:\Program Files\Symantec
2008-03-08 04:26:29 174 --ahs---- C:\Program Files\desktop.ini
2008-03-08 04:12:23 0 d-------- C:\Program Files\Windows Calendar
2008-03-08 04:12:09 0 d-------- C:\Program Files\Windows Defender
2008-03-08 04:11:56 0 d-------- C:\Program Files\Windows Sidebar
2008-03-07 23:01:39 0 d-------- C:\Program Files\Common Files
2008-03-07 21:23:04 0 d-------- C:\Users\Home\AppData\Roaming\Webshots
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\WeatherBug
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\vlc
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\Viewpoint
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Talkback
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Symantec
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sun
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sonic
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Registry Defender
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Real
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\MSN6
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\Mozilla
2008-03-07 21:22:13 0 d--h----- C:\Users\Home\AppData\Roaming\Move Networks
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Macromedia
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Leadertech
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Jasc Software Inc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Jasc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Identities
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\ICAClient
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\HotSync
2008-03-07 21:21:28 0 d--h----- C:\Users\Home\AppData\Roaming\Gtek
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Google
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\ESPN
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\CyberLink
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel Photo Album
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\Apple Computer
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\AOL
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Aim
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Adobe
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\acccore
2008-03-07 21:09:39 0 d-------- C:\Program Files\Your Company Name
2008-03-07 21:09:37 0 d-------- C:\Program Files\WordPerfect Office 11
2008-03-07 21:09:13 0 d-------- C:\Program Files\WildTangent
2008-03-07 21:09:06 0 d-------- C:\Program Files\support.com
2008-03-07 21:08:57 0 d-------- C:\Program Files\Real
2008-03-07 21:08:56 0 d-------- C:\Program Files\QuickTime
2008-03-07 21:08:42 0 d-------- C:\Program Files\PokerRoom.com
2008-03-07 21:08:42 0 d-------- C:\Program Files\Photo Pos Pro
2008-03-07 21:08:41 0 d-------- C:\Program Files\palmOne
2008-03-07 21:08:37 0 d-------- C:\Program Files\Ofoto
2008-03-07 21:06:25 0 d-------- C:\Program Files\NetZero
2008-03-07 21:06:22 0 d-------- C:\Program Files\MUSICMATCH
2008-03-07 21:06:22 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-07 21:06:17 0 d-------- C:\Program Files\Modem Helper
2008-03-07 21:06:00 0 d-------- C:\Program Files\microsoft frontpage
2008-03-07 21:06:00 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-07 21:06:00 0 d-------- C:\Program Files\McAfee.com
2008-03-07 21:06:00 0 d-------- C:\Program Files\MasqueAIM
2008-03-07 21:05:59 0 d-------- C:\Program Files\Learn2.com
2008-03-07 21:05:48 0 d-------- C:\Program Files\Java
2008-03-07 21:05:28 0 d-------- C:\Program Files\Jasc Software Inc
2008-03-07 21:04:33 0 d-------- C:\Program Files\iTunes
2008-03-07 21:04:30 0 d-------- C:\Program Files\iPod
2008-03-07 21:04:27 0 d-------- C:\Program Files\Intel
2008-03-07 21:04:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-07 21:04:25 0 d-------- C:\Program Files\HP
2008-03-07 21:03:00 0 d-------- C:\Program Files\Google
2008-03-07 21:02:59 0 d-------- C:\Program Files\DivX
2008-03-07 21:02:58 0 d-------- C:\Program Files\DellSupport
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell Computer
2008-03-07 21:02:38 0 d-------- C:\Program Files\CyberLink
2008-03-07 21:02:38 0 d-------- C:\Program Files\CorelPaintShopProX_
2008-03-07 21:01:48 0 d-------- C:\Program Files\CorelPaintShopProX
2008-03-07 21:00:39 0 d-------- C:\Program Files\Corel
2008-03-07 21:00:37 0 d-------- C:\Program Files\Connection Wizard
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\WhenU
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\Thraex Software
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Real
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\NSV
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\Java
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-07 21:00:10 0 d-------- C:\Program Files\Common Files\HP
2008-03-07 21:00:09 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-07 21:00:08 0 d-------- C:\Program Files\Common Files\Corel
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\aolshare
2008-03-07 21:00:05 0 d-------- C:\Program Files\Common Files\aolback
2008-03-07 21:00:04 0 d-------- C:\Program Files\Common Files\AOL
2008-03-07 20:59:39 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-07 20:59:39 0 d-------- C:\Program Files\Citrix
2008-03-07 20:59:39 0 d-------- C:\Program Files\BearShare
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOL Companion
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOD
2008-03-07 20:59:36 0 d-------- C:\Program Files\America Online 9.0c
2008-03-07 20:59:31 0 d-------- C:\Program Files\America Online 9.0b
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0a
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM+
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM Toolbar
2008-03-07 20:59:14 0 d-------- C:\Program Files\AIM


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
08/24/2007 11:51 PM 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
03/07/2008 11:01 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A98C34C6-A944-B922-7851-E9DA1F7785B7}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [08/24/2007 11:51 PM 316784]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/08/2008 03:36 AM]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [08/13/2003 12:27 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe" [11/02/2005 11:01 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 09:38 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 06:28 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/14/2006 04:24 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 09:47 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/02/2006 10:13 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/07/2004 12:39 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/14/2008 12:01 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [11/02/2006 05:45 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/21/2007 06:55 AM]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" []
"AOL Fast Start"="C:\PROGRA~1\AMERIC~1.0A\AOL.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0c\aoltray.exe [6/28/2005 6:54:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 6:19:24 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 4:05:56 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc CscService TabletInputService UmRdpService wlansvc WPDBusEnum EMDMgmt
LocalServiceNoNetwork PLA DPS BFE mpssvc
LocalServiceNetworkRestricted DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc PnrpAutoReg

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-03-17 11:23:01 ------------
  • 0

#14
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - (no file)
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\WINDOWS\system32\nujwjkwv6.exe


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please run the OTMoveIt2 by OldTimer again.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\nujwjkwv6.exe
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    purity
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sawadtww6
  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Reboot and post a new DSS log
  • 0

#15
nyychick2

nyychick2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Deckard's System Scanner v20071014.68
Run by Home on 2008-03-17 14:18:15
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 510 MiB (1024 MiB recommended).


-- HijackThis (run as Home.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:18:38 PM, on 3/17/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DSentry.exe
C:\Program Files\Common Files\AOL\1133723631\ee\aolsoftware.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Home.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {A98C34C6-A944-B922-7851-E9DA1F7785B7} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [AOL Fast Start] "C:\PROGRA~1\AMERIC~1.0A\AOL.EXE" -b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O13 - Gopher Prefix:
O15 - Trusted Zone: admissions.nyu.edu
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.addictive...ab/1w2fcksh.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.a...83/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/p...owserPlugin.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgall..._2/axofupld.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.a...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft....ayx_vp3_mp3.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} (Quantum Streaming IE Player Class) - http://mvnet.xlontec...2ie06101001.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://plugin.driver...driveragent.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: myivqjirjkoj (sawadtww6) - Unknown owner - C:\WINDOWS\system32\nujwjkwv6.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

--
End of file - 8904 bytes

-- Files created between 2008-02-17 and 2008-03-17 -----------------------------

2008-03-15 11:51:42 0 d-------- C:\Program Files\Trend Micro
2008-03-14 21:29:37 3612 --a------ C:\Windows\system32\tmp.reg
2008-03-14 21:29:02 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-03-14 21:29:02 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-14 21:29:02 82432 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-14 21:24:39 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-14 21:24:38 51200 --a------ C:\Windows\system32\dumphive.exe
2008-03-14 21:24:36 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-14 21:24:36 53248 --a------ C:\Windows\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-08 21:23:10 0 d-------- C:\Users\Home\.housecall6.6
2008-03-07 23:35:53 0 d-------- C:\Windows\Panther
2008-03-07 23:10:47 0 d--h----- C:\$WINDOWS.~Q
2008-03-07 22:56:18 0 d--h----- C:\$INPLACE.~TR
2008-03-07 22:35:09 0 d-------- C:\Program Files\Norton Internet Security
2008-03-07 22:11:38 0 dr------- C:\Users\Home\Searches
2008-03-07 22:11:21 0 dr------- C:\Users\Home\Contacts
2008-03-07 21:48:22 22668 --a------ C:\Windows\system32\emptyregdb.dat
2008-03-07 21:33:20 0 d-------- C:\Users\Default\video
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Templates
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Start Menu
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\SendTo
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Recent
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\PrintHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\NetHood
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\My Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Music
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\Local Settings
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Links
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Favorites
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Downloads
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Documents
2008-03-07 20:52:32 0 dr------- C:\Users\Bhavini\Desktop
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Cookies
2008-03-07 20:52:32 0 d--hs---- C:\Users\Bhavini\Application Data
2008-03-07 20:52:32 0 d--h----- C:\Users\Bhavini\AppData
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Videos
2008-03-07 20:52:31 0 d-------- C:\Users\Bhavini\Saved Games
2008-03-07 20:52:31 0 dr------- C:\Users\Bhavini\Pictures
2008-03-07 20:52:31 2105344 --a------ C:\Users\Bhavini\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Templates
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Start Menu
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\SendTo
2008-03-07 20:52:27 0 d-------- C:\Users\Minal\Saved Games
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Recent
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\PrintHood
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Pictures
2008-03-07 20:52:27 2748416 --a------ C:\Users\Minal\NTUSER.DAT
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\NetHood
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\My Documents
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\Local Settings
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Links
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Favorites
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Downloads
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Documents
2008-03-07 20:52:27 0 dr------- C:\Users\Minal\Desktop
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Cookies
2008-03-07 20:52:27 0 d--hs---- C:\Users\Minal\Application Data
2008-03-07 20:52:27 0 d--h----- C:\Users\Minal\AppData
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Templates
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Start Menu
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\SendTo
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Recent
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\PrintHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\NetHood
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\My Documents
2008-03-07 20:52:23 0 d--h----- C:\Users\Home\Local Settings
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Cookies
2008-03-07 20:52:23 0 d--hs---- C:\Users\Home\Application Data
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Saved Games
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Pictures
2008-03-07 20:52:22 3670016 --ahs---- C:\Users\Home\NTUSER.DAT
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Music
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Links
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Favorites
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Downloads
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Documents
2008-03-07 20:52:22 0 dr------- C:\Users\Home\Desktop
2008-03-07 20:52:22 0 d--h----- C:\Users\Home\AppData
2008-03-07 20:50:18 0 d-------- C:\Windows\system32\URTTEMP
2008-03-07 20:50:05 0 d--hs---- C:\Windows\Installer
2008-03-07 20:45:56 0 d-------- C:\Windows\system32\catroot2
2008-03-07 20:45:28 0 d-------- C:\Windows\Debug
2008-03-07 20:45:27 0 d-------- C:\Windows\CSC
2008-03-07 20:36:56 0 d-------- C:\Windows\Prefetch
2008-03-07 19:49:51 0 d--hs---- C:\Boot
2008-03-07 19:10:36 0 d------c- C:\Windows\system32\DRVSTORE
2008-03-03 01:09:18 0 d-------- C:\Program Files\Enigma Software Group
2008-03-02 19:14:43 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-02 17:31:30 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-02 00:01:22 0 d-a------ C:\Users\All Users\TEMP


-- Find3M Report ---------------------------------------------------------------

2008-03-13 09:13:49 0 d-------- C:\Program Files\Windows Mail
2008-03-08 21:04:53 9826 --a------ C:\Windows\mozver.dat
2008-03-08 17:33:27 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-08 16:49:29 0 d-------- C:\Program Files\Symantec
2008-03-08 04:26:29 174 --ahs---- C:\Program Files\desktop.ini
2008-03-08 04:12:23 0 d-------- C:\Program Files\Windows Calendar
2008-03-08 04:12:09 0 d-------- C:\Program Files\Windows Defender
2008-03-08 04:11:56 0 d-------- C:\Program Files\Windows Sidebar
2008-03-07 23:01:39 0 d-------- C:\Program Files\Common Files
2008-03-07 21:23:04 0 d-------- C:\Users\Home\AppData\Roaming\Webshots
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\WeatherBug
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\vlc
2008-03-07 21:23:01 0 d-------- C:\Users\Home\AppData\Roaming\Viewpoint
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Talkback
2008-03-07 21:23:00 0 d-------- C:\Users\Home\AppData\Roaming\Symantec
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sun
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Sonic
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Registry Defender
2008-03-07 21:22:17 0 d-------- C:\Users\Home\AppData\Roaming\Real
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\MSN6
2008-03-07 21:22:15 0 d-------- C:\Users\Home\AppData\Roaming\Mozilla
2008-03-07 21:22:13 0 d--h----- C:\Users\Home\AppData\Roaming\Move Networks
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Macromedia
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Leadertech
2008-03-07 21:21:29 0 d-------- C:\Users\Home\AppData\Roaming\Jasc Software Inc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Jasc
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Identities
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\ICAClient
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\HotSync
2008-03-07 21:21:28 0 d--h----- C:\Users\Home\AppData\Roaming\Gtek
2008-03-07 21:21:28 0 d-------- C:\Users\Home\AppData\Roaming\Google
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\ESPN
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\CyberLink
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel
2008-03-07 21:21:27 0 d-------- C:\Users\Home\AppData\Roaming\Corel Photo Album
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\Apple Computer
2008-03-07 21:21:25 0 d-------- C:\Users\Home\AppData\Roaming\AOL
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Aim
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\Adobe
2008-03-07 21:20:47 0 d-------- C:\Users\Home\AppData\Roaming\acccore
2008-03-07 21:09:39 0 d-------- C:\Program Files\Your Company Name
2008-03-07 21:09:37 0 d-------- C:\Program Files\WordPerfect Office 11
2008-03-07 21:09:13 0 d-------- C:\Program Files\WildTangent
2008-03-07 21:09:06 0 d-------- C:\Program Files\support.com
2008-03-07 21:08:57 0 d-------- C:\Program Files\Real
2008-03-07 21:08:56 0 d-------- C:\Program Files\QuickTime
2008-03-07 21:08:42 0 d-------- C:\Program Files\PokerRoom.com
2008-03-07 21:08:42 0 d-------- C:\Program Files\Photo Pos Pro
2008-03-07 21:08:41 0 d-------- C:\Program Files\palmOne
2008-03-07 21:08:37 0 d-------- C:\Program Files\Ofoto
2008-03-07 21:06:25 0 d-------- C:\Program Files\NetZero
2008-03-07 21:06:22 0 d-------- C:\Program Files\MUSICMATCH
2008-03-07 21:06:22 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-07 21:06:17 0 d-------- C:\Program Files\Modem Helper
2008-03-07 21:06:00 0 d-------- C:\Program Files\microsoft frontpage
2008-03-07 21:06:00 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-07 21:06:00 0 d-------- C:\Program Files\McAfee.com
2008-03-07 21:06:00 0 d-------- C:\Program Files\MasqueAIM
2008-03-07 21:05:59 0 d-------- C:\Program Files\Learn2.com
2008-03-07 21:05:48 0 d-------- C:\Program Files\Java
2008-03-07 21:05:28 0 d-------- C:\Program Files\Jasc Software Inc
2008-03-07 21:04:33 0 d-------- C:\Program Files\iTunes
2008-03-07 21:04:30 0 d-------- C:\Program Files\iPod
2008-03-07 21:04:27 0 d-------- C:\Program Files\Intel
2008-03-07 21:04:27 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-07 21:04:25 0 d-------- C:\Program Files\HP
2008-03-07 21:03:00 0 d-------- C:\Program Files\Google
2008-03-07 21:02:59 0 d-------- C:\Program Files\DivX
2008-03-07 21:02:58 0 d-------- C:\Program Files\DellSupport
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell
2008-03-07 21:02:50 0 d-------- C:\Program Files\Dell Computer
2008-03-07 21:02:38 0 d-------- C:\Program Files\CyberLink
2008-03-07 21:02:38 0 d-------- C:\Program Files\CorelPaintShopProX_
2008-03-07 21:01:48 0 d-------- C:\Program Files\CorelPaintShopProX
2008-03-07 21:00:39 0 d-------- C:\Program Files\Corel
2008-03-07 21:00:37 0 d-------- C:\Program Files\Connection Wizard
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\WhenU
2008-03-07 21:00:36 0 d-------- C:\Program Files\Common Files\Thraex Software
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\SWF Studio
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-07 21:00:29 0 d-------- C:\Program Files\Common Files\Real
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-07 21:00:27 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\NSV
2008-03-07 21:00:26 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\Java
2008-03-07 21:00:17 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-07 21:00:10 0 d-------- C:\Program Files\Common Files\HP
2008-03-07 21:00:09 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-03-07 21:00:08 0 d-------- C:\Program Files\Common Files\Corel
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\Borland Shared
2008-03-07 21:00:07 0 d-------- C:\Program Files\Common Files\aolshare
2008-03-07 21:00:05 0 d-------- C:\Program Files\Common Files\aolback
2008-03-07 21:00:04 0 d-------- C:\Program Files\Common Files\AOL
2008-03-07 20:59:39 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-07 20:59:39 0 d-------- C:\Program Files\Citrix
2008-03-07 20:59:39 0 d-------- C:\Program Files\BearShare
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOL Companion
2008-03-07 20:59:37 0 d-------- C:\Program Files\AOD
2008-03-07 20:59:36 0 d-------- C:\Program Files\America Online 9.0c
2008-03-07 20:59:31 0 d-------- C:\Program Files\America Online 9.0b
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0a
2008-03-07 20:59:27 0 d-------- C:\Program Files\America Online 9.0
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM+
2008-03-07 20:59:15 0 d-------- C:\Program Files\AIM Toolbar
2008-03-07 20:59:14 0 d-------- C:\Program Files\AIM


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
08/24/2007 11:51 PM 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
03/07/2008 11:01 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A98C34C6-A944-B922-7851-E9DA1F7785B7}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [08/24/2007 11:51 PM 316784]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/08/2008 03:36 AM]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [08/13/2003 12:27 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1133723631\ee\AOLSoftware.exe" [11/02/2005 11:01 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 09:38 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 06:28 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/14/2006 04:24 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 09:47 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/02/2006 10:13 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [01/07/2004 12:39 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/14/2008 12:01 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [11/02/2006 05:45 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/21/2007 06:55 AM]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" []
"AOL Fast Start"="C:\PROGRA~1\AMERIC~1.0A\AOL.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0c\aoltray.exe [6/28/2005 6:54:13 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 6:19:24 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 4:05:56 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc CscService TabletInputService UmRdpService wlansvc WPDBusEnum EMDMgmt
LocalServiceNoNetwork PLA DPS BFE mpssvc
LocalServiceNetworkRestricted DHCP eventlog AudioSrv LmHosts wscsvc p2pimsvc PNRPSvc p2psvc PnrpAutoReg

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-03-17 14:20:01 ------------
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP