HERE IS THE DSS.EXE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:03:19 PM, on 3/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Airlink101\AWLH5025\WLService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Airlink101\AWLH5025\AWLH5025.exe
C:\WINDOWS\system32\wpabaln.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas1.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy1\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Common Files\HijammmmkThis.exe
O2 - BHO: (no name) - {022A7437-E6AA-45A6-877F-32E42DA93FA8} - (no file)
O2 - BHO: (no name) - {55806BD6-7C07-4086-861C-6001899B1255} - (no file)
O2 - BHO: (no name) - {6D56C2A2-C973-448B-8123-7D2718446D0C} - C:\WINDOWS\system32\awvtu.dll
O2 - BHO: (no name) - {ED120D76-BF31-412C-A99B-783C6676E128} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas1.exe" /minimized
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy1\TeaTimer.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewi...oOnlineScan.cabO20 - AppInit_DLLs: cru629.dat
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5025\WLService.exe
--
End of file - 6246 bytes
Deckard's System Scanner v20071014.68
Run by Bobby Fischer on 2008-03-09 01:16:47
Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Drive C: has 0.38 GiB (less than 15%) free.-- HijackThis (run as Bobby Fischer.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:16:58 AM, on 3/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas1.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Airlink101\AWLH5025\WLService.exe
C:\Program Files\Airlink101\AWLH5025\AWLH5025.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wpabaln.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bobby Fischer\Desktop\dss333.exe
C:\PROGRA~1\COMMON~1\Bobby Fischer.exe
O2 - BHO: (no name) - {221B2B91-8B68-49B4-BE31-0FCC8412DC37} - C:\WINDOWS\system32\awvtu.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas1.exe" /minimized
O4 - HKLM\..\Run: [braviax] braviax.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewi...oOnlineScan.cabO20 - AppInit_DLLs: cru629.dat
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5025\WLService.exe
--
End of file - 5003 bytes
-- Files created between 2008-02-09 and 2008-03-09 -----------------------------
2008-03-09 01:16:48 396288 --a------ C:\Program Files\Common Files\Bobby Fischer.exe <Not Verified; Trend Micro Inc.; HijackThis>
2008-03-09 00:41:57 6656 --a------ C:\WINDOWS\system32\users32.dat
2008-03-08 21:01:31 396288 --a------ C:\Program Files\Common Files\HijammmmkThis.exe <Not Verified; Trend Micro Inc.; HijackThis>
2008-03-08 21:00:52 0 d-------- C:\Program Files\Common Files\New Folder
2008-03-08 16:46:32 24576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2008-03-08 13:44:05 92224 --a------ C:\WINDOWS\system32\eevnobxc.dll
2008-03-08 13:41:47 87104 --a------ C:\WINDOWS\system32\qpqttlmx.dll
2008-03-08 13:41:03 149056 --a------ C:\WINDOWS\system32\kxhinmjr.dll
2008-03-08 02:52:33 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Grisoft
2008-03-08 02:28:40 0 d-------- C:\Program Files\Lavasoft
2008-03-08 02:28:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-08 02:26:20 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-08 02:13:55 0 d-------- C:\Program Files\Spybot - Search & Destroy1
2008-03-08 02:08:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-07 13:40:59 87104 --a------ C:\WINDOWS\system32\wfpknlhb.dll
2008-03-07 13:40:31 90688 --a------ C:\WINDOWS\system32\chciqvjq.dll
2008-03-07 13:40:16 149056 --a------ C:\WINDOWS\system32\wqaggrsq.dll
2008-03-07 13:39:55 149056 --a------ C:\WINDOWS\system32\phmedked.dll
2008-03-07 12:30:42 0 d-------- C:\WINDOWS\system32\LogFiles
2008-03-06 22:43:36 308712 --a------ C:\WINDOWS\system32\winivstr.exe
2008-03-06 22:39:10 6144 --a------ C:\WINDOWS\system32\cru629.dat
2008-03-06 22:39:10 6144 --a------ C:\WINDOWS\cru629.dat
2008-03-06 22:39:10 16384 --a------ C:\WINDOWS\braviax.exe
2008-03-06 22:37:45 16384 --a------ C:\WINDOWS\system32\braviax.exe
2008-03-06 20:14:30 0 d-------- C:\Program Files\Trend Micro
2008-03-06 20:08:35 1696 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-06 20:08:03 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-06 20:08:03 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-06 20:08:03 86016 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-06 20:08:03 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-06 20:08:03 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-03-06 20:08:03 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-06 20:08:03 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-06 13:39:25 96320 --a------ C:\WINDOWS\system32\vdpivdqe.dll
2008-03-06 13:38:49 149056 --a------ C:\WINDOWS\system32\bvkmbrqp.dll
2008-03-06 13:37:56 172282 --ahs---- C:\WINDOWS\system32\utvwa.ini2
2008-03-06 13:37:50 324160 --a------ C:\WINDOWS\system32\awvtu.dll
2008-03-06 12:38:29 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\W?nSxS
2008-03-06 12:27:14 19915 --a------ C:\WINDOWS\system32\drivers\AegisP.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.0.1>
2008-03-06 12:27:13 40960 --a------ C:\WINDOWS\system32\AWLH5025.dll
2008-03-06 12:27:12 94208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-03-06 12:27:12 15872 --a------ C:\WINDOWS\system32\GTNDIS5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2008-03-06 12:27:12 0 d-------- C:\Program Files\Airlink101
2008-03-05 22:48:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-05 10:10:09 0 d-------- C:\kav
2008-03-05 09:58:51 0 d-------- C:\WINDOWS\system32\appmgmt
2008-03-05 09:21:10 17236 --a------ C:\WINDOWS\system32\ddcyy.dll
2008-03-05 09:16:37 0 d--hs---- C:\WINDOWS\Um9nZXI
2008-03-05 09:16:13 86016 --a------ C:\WINDOWS\system32\drivers\ipfltdrvv.sys
2008-03-05 09:16:10 0 d-------- C:\WINDOWS\system32\x3
2008-03-05 09:16:10 0 d-------- C:\WINDOWS\system32\s7
2008-03-05 09:16:10 0 d-------- C:\WINDOWS\system32\k8
2008-03-05 09:16:10 0 d-------- C:\WINDOWS\system32\c4
2008-03-05 09:16:10 0 d-------- C:\Program Files\??curity
2008-03-05 09:16:04 0 d-------- C:\WINDOWS\system32\iDlo01
2008-03-05 05:37:57 36864 --a------ C:\WINDOWS\system32\eetransx.exe <Not Verified; evidence-eliminator.com; Evidence Eliminator >
2008-03-05 05:37:57 61440 --a------ C:\WINDOWS\system32\Eeshellx.dll <Not Verified; evidence-eliminator.com; Evidence Eliminator >
2008-03-05 05:37:57 118784 --a------ C:\WINDOWS\system32\EEGenFn1.dll <Not Verified; Robin Hood Software Ltd; EEGenfn1>
2008-03-05 05:37:55 368912 --a------ C:\WINDOWS\system32\vbar332.dll <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-03-05 05:37:55 0 d-------- C:\Program Files\Evidence Eliminator
2008-03-05 02:35:02 0 d-------- C:\WINDOWS\pss
2008-03-04 19:58:15 0 d-------- C:\WINDOWS\system32\NtmsData
2008-03-04 19:45:42 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\TrueSwitch
2008-03-04 19:12:13 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-03-04 19:01:19 0 d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers Headquarters
2008-03-04 14:42:16 0 d-------- C:\Program Files\VeryPDF PDF Editor v2.2
2008-03-03 21:29:57 0 d-------- C:\Program Files\Download Direct
2008-03-03 21:07:44 634880 --a------ C:\WINDOWS\system32\GSPROP32.DLL <Not Verified; Bits Per Second Ltd; GSPROP>
2008-03-03 21:07:44 59392 --a------ C:\WINDOWS\system32\fce32.DLL
2008-03-03 21:07:26 0 d-------- C:\Program Files\FLSPlan
2008-03-03 06:08:55 0 d-------- C:\Program Files\VeryPDF Form Filler v3.0
2008-03-02 17:00:36 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\ATI
2008-03-02 17:00:36 0 d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-03-02 16:52:31 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Leadertech
2008-03-02 01:57:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-02 00:25:21 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-02 00:25:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-03-02 00:25:11 0 d-------- C:\WINDOWS\Downloaded Installations
2008-03-01 22:58:07 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Google
2008-03-01 22:55:45 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Macromedia
2008-03-01 22:55:42 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Adobe
2008-03-01 22:55:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-03-01 22:55:32 0 d-------- C:\Program Files\Google
2008-03-01 19:32:08 0 d---s---- C:\Documents and Settings\Bobby Fischer\UserData
2008-03-01 19:24:39 0 d-------- C:\Documents and Settings\All Users\Application Data\RoboForm
2008-03-01 19:24:17 0 d-------- C:\Program Files\Siber Systems
2008-03-01 17:35:32 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-03-01 17:35:17 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-03-01 17:34:42 0 d-------- C:\Program Files\ATI Technologies
2008-03-01 17:33:28 0 d-------- C:\ATI
2008-03-01 17:32:24 49152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-03-01 17:31:59 4127488 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys <Not Verified; Realtek Semiconductor Corp.; Windows ® WDM driver for Realtek AC'97 Audio(HRTF data Copyright 1994 by MIT Media Lab)>
2008-03-01 17:31:18 0 d-------- C:\Program Files\Realtek AC97
2008-03-01 17:31:13 10528768 --a------ C:\WINDOWS\system32\RTLCPL.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Audio Sound Effect Manager>
2008-03-01 17:31:06 577536 --a------ C:\WINDOWS\soundman.exe <Not Verified; Realtek Semiconductor Corp.; Realtek Sound Manager>
2008-03-01 17:31:05 147456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll <Not Verified; ; RtlCPAPI Module>
2008-03-01 17:31:05 315392 --a------ C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update driver Tool>
2008-03-01 17:31:05 217088 --a------ C:\WINDOWS\Alcrmv.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Removing driver Tool>
2008-03-01 17:18:04 0 d-------- C:\Program Files\PC Drivers HeadQuarters
2008-03-01 12:43:44 0 d-------- C:\Program Files\Microsoft Works
2008-03-01 12:43:03 0 d-------- C:\Program Files\MSBuild
2008-03-01 12:36:19 0 d-------- C:\WINDOWS\SHELLNEW
2008-03-01 12:33:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-01 12:08:17 319104 --a------ C:\WINDOWS\system32\drivers\RT61.sys <Not Verified; Ralink Technology Inc.; Ralink 802.11 Wireless Adapters>
2008-03-01 12:08:17 8192 --a------ C:\WINDOWS\system32\drivers\RT2661.bin
2008-03-01 12:08:17 8192 --a------ C:\WINDOWS\system32\drivers\rt2561s.bin
2008-03-01 12:08:17 8192 --a------ C:\WINDOWS\system32\drivers\RT2561.bin
2008-03-01 12:08:15 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-01 12:08:00 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-01 12:05:32 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\Identities
2008-03-01 12:05:06 0 dr------- C:\Documents and Settings\Bobby Fischer\Favorites
2008-03-01 12:05:06 0 d-------- C:\Documents and Settings\Bobby Fischer\Desktop
2008-03-01 12:05:06 0 d---s---- C:\Documents and Settings\Bobby Fischer\Cookies
2008-03-01 12:05:06 0 dr-h----- C:\Documents and Settings\Bobby Fischer\Application Data
2008-03-01 12:05:05 0 d--h----- C:\Documents and Settings\Bobby Fischer\Templates
2008-03-01 12:05:05 0 dr------- C:\Documents and Settings\Bobby Fischer\Start Menu
2008-03-01 12:05:05 0 dr-h----- C:\Documents and Settings\Bobby Fischer\SendTo
2008-03-01 12:05:05 0 dr-h----- C:\Documents and Settings\Bobby Fischer\Recent
2008-03-01 12:05:05 0 d--h----- C:\Documents and Settings\Bobby Fischer\PrintHood
2008-03-01 12:05:05 2621440 --ah----- C:\Documents and Settings\Bobby Fischer\NTUSER.DAT
2008-03-01 12:05:05 0 d--h----- C:\Documents and Settings\Bobby Fischer\NetHood
2008-03-01 12:05:05 0 dr------- C:\Documents and Settings\Bobby Fischer\My Documents
2008-03-01 12:05:05 0 d--h----- C:\Documents and Settings\Bobby Fischer\Local Settings
2008-03-01 12:01:28 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-03-01 12:01:10 0 d-------- C:\WINDOWS\Prefetch
2008-03-01 12:01:09 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-03-01 12:01:08 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-03-01 12:01:08 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-03-01 12:01:08 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-03-01 12:01:08 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-03-01 12:01:07 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-03-01 11:59:32 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-03-01 11:59:32 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-03-01 11:59:32 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-03-01 11:59:32 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-03-01 11:59:32 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-03-01 11:53:18 0 d-------- C:\WINDOWS\system32\xircom
2008-03-01 11:53:18 0 d-------- C:\Program Files\microsoft frontpage
2008-03-01 11:51:34 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-03-01 11:51:20 0 -rahs---- C:\MSDOS.SYS
2008-03-01 11:51:20 0 -rahs---- C:\IO.SYS
2008-03-01 11:51:20 0 --a------ C:\CONFIG.SYS
2008-03-01 11:51:20 0 --a------ C:\AUTOEXEC.BAT
2008-03-01 11:48:45 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-03-01 11:48:24 0 dr------- C:\WINDOWS\Offline Web Pages
2008-03-01 11:48:24 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-03-01 11:48:00 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-01 11:47:25 0 d-------- C:\WINDOWS\system32\DirectX
2008-03-01 11:46:39 0 d---s---- C:\WINDOWS\Tasks
2008-03-01 11:46:37 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-01 11:46:31 0 d-------- C:\WINDOWS\srchasst
2008-03-01 11:46:30 0 d-------- C:\WINDOWS\system32\Macromed
2008-03-01 11:46:06 0 d-------- C:\WINDOWS\system32\Restore
2008-03-01 04:24:00 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-01 04:23:29 0 d-------- C:\WINDOWS\Registration
2008-03-01 04:23:13 0 d-------- C:\Program Files\Online Services
2008-03-01 04:21:40 0 d-------- C:\Program Files\Windows Plus
2008-03-01 04:21:02 0 d-------- C:\Program Files\Movie Maker
2008-03-01 04:18:21 0 d-------- C:\Program Files\Messenger
2008-03-01 04:18:15 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-01 04:17:10 0 d-------- C:\Program Files\Windows NT
2008-03-01 04:17:06 0 d-------- C:\WINDOWS\system32\MsDtc
2008-03-01 04:17:04 0 d-------- C:\WINDOWS\system32\Com
2008-02-29 20:07:34 0 d--hs---- C:\WINDOWS\Installer
2008-02-29 20:07:32 0 d-------- C:\Program Files\Common Files\ODBC
2008-02-29 20:07:26 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-02-29 20:07:25 0 dr------- C:\Program Files
2008-02-29 20:07:25 0 d-------- C:\Program Files\Common Files
2008-02-29 20:06:55 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-02-29 20:06:55 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-02-29 20:06:55 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-02-29 20:06:55 0 dr------- C:\Documents and Settings\All Users\Documents
2008-02-29 20:06:55 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-02-29 20:06:54 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-02-29 20:06:54 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-02-29 20:06:54 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-02-29 20:06:54 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-02-29 20:06:54 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-02-29 20:06:54 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-02-29 20:06:54 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-02-29 20:06:54 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-02-29 20:06:54 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-02-29 20:06:54 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-02-29 20:06:54 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-02-29 20:06:26 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-02-29 20:06:26 0 d-------- C:\WINDOWS\system32\CatRoot
2008-02-29 20:06:20 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-02-29 20:06:20 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-02-29 20:06:19 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-02-29 20:06:19 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-02-29 20:05:47 0 d-------- C:\Documents and Settings
2008-02-29 20:05:46 0 d--hs---- C:\System Volume Information
2008-02-29 19:56:49 0 d-------- C:\WINDOWS
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\WinSxS
2008-02-29 19:56:49 0 dr------- C:\WINDOWS\Web
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\twain_32
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\wins
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\wbem
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\usmt
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\spool
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\ShellExt
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\Setup
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\ras
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\oobe
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\npp
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\mui
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\inetsrv
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\IME
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\icsxml
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\ias
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\export
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\drivers
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-02-29 19:56:49 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\dhcp
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\config
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\3076
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\2052
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1054
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1042
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1041
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1037
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1033
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1031
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1028
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system32\1025
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\system
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\security
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Resources
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\repair
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Provisioning
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\PeerNet
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\pchealth
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\mui
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\msapps
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\msagent
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Media
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\java
2008-02-29 19:56:49 0 d--h----- C:\WINDOWS\inf
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\ime
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Help
2008-02-29 19:56:49 0 dr--s---- C:\WINDOWS\Fonts
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\ehome
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Driver Cache
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Debug
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Cursors
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Connection Wizard
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\Config
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\AppPatch
2008-02-29 19:56:49 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-03-09 01:16:58 5004 --a------ C:\Program Files\Common Files\hijackthis.log
2008-03-08 08:09:04 0 d-------- C:\Documents and Settings\Bobby Fischer\Application Data\W?nSxS
2008-03-08 06:40:46 0 d-------- C:\Program Files\??curity
2008-02-29 20:06:54 62 --ahs---- C:\Documents and Settings\Bobby Fischer\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{221B2B91-8B68-49B4-BE31-0FCC8412DC37}]
03/06/2008 01:37 PM 324160 --a------ C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/10/2004 04:04 AM]
"SoundMan"="SOUNDMAN.EXE" [04/16/2007 03:28 PM C:\WINDOWS\soundman.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas1.exe" [06/11/2007 01:25 AM]
"braviax"="braviax.exe" [03/09/2008 12:34 AM C:\WINDOWS\system32\braviax.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [03/08/2008 02:44 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 04:00 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=cru629.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Bobby Fischer^Start Menu^Programs^Startup^TrueAssistant.lnk]
path=C:\Documents and Settings\Bobby Fischer\Start Menu\Programs\Startup\TrueAssistant.lnk
backup=C:\WINDOWS\pss\TrueAssistant.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b843e7d8]
rundll32.exe "C:\WINDOWS\system32\hjutrqnd.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bhte]
"C:\PROGRA~1\CURITY~1\taskmgr.exe" -vt yazb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\braviax]
C:\WINDOWS\system32\braviax.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLD.EXE]
C:\Program Files\Download Direct\DLD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dlkpdj]
C:\WINDOWS\system32\??mantec\m?hta.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Evidence Eliminator]
C:\Program Files\Evidence Eliminator\ee.exe /m
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Imst]
"C:\Documents and Settings\Bobby Fischer\Application Data\W?nSxS\r?ndll.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
"C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
-- End of Deckard's System Scanner: finished at 2008-03-09 01:18:06 ------------
AND HERE IS THE HJT LOG