Thanks so much for looking into this for me. After installing Deckard's System Scan, the following notepads appeared:
Brian
Main.txt is as follows:
Deckard's System Scanner v20071014.68
Run by Sarah Vanek on 2008-03-16 07:26:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-03-16 15:26:25 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).-- HijackThis (run as Sarah Vanek.exe) -----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:27:53 AM, on 3/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\RunDll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Sarah Vanek\Desktop\dss.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Sarah Vanek.exe
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [jkdfj94kgdftdf] C:\WINDOWS\TEMP\winlogan.exe
O4 - HKLM\..\Run: [ctfmona] C:\WINDOWS\System32\ctfmona.exe
O4 - HKLM\..\Run: [icasServ] C:\WINDOWS\System32\icasServ.exe
O4 - HKLM\..\Run: [ShareSearcher] c:\wsusupd.exe
O4 - HKLM\..\Run: [SystemDefender] "C:\Program Files\SystemDefender\SystemDefender.exe" hide
O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\AVSYST~1\ugac.exe" -start
O4 - HKLM\..\Run: [bm(1)] "C:\Program Files\Common Files\AVSystemCare\bm.exe" dm=http://avsystemcare.com ad=http://avsystemcare.com sd=http://ykeeper.avsystemcare.com
O4 - HKLM\..\Run: [ptask] C:\Program Files\AVSystemCare\ptask.exe
O4 - HKLM\..\Run: [WinMed] winmed.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinIFixer] C:\Program Files\WinIFixer\WinIFixer.exe
O4 - HKLM\..\Run: [EasySpywareCleaner] C:\Program Files\EasySpywareCleaner\EasySpywareCleaner.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Sarah Vanek\Local Settings\Application Data\cftmon.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [AVSystemCare] C:\Program Files\AVSystemCare\pgs.exe
O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\ErrClean\strpmon.exe" dm=http://errclean.com ad=http://errclean.com sd=http://inspaid.errclean.com
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\SARAHV~1\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\System32\spoolvs.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jkdfj94kgdftdf] C:\WINDOWS\TEMP\winlogan.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [braviax] C:\WINDOWS\System32\braviax.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - Global Startup: Belkin Wireless G Notebook Card Client Utility.lnk = ?
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1204393670618O20 - AppInit_DLLs: C:\WINDOWS\System32\cru629.dat
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O21 - SSODL: sglsxIpH - {681FCE85-C2B5-642F-98A2-731A7DA5EA14} - C:\WINDOWS\System32\govk.dll (file missing)
O21 - SSODL: WinApp - {C285CF22-115F-3252-41AC-F686D912C63D} - C:\WINDOWS\System32\clipuser32.dll (file missing)
O21 - SSODL: MonRunOnce - {425300ee-456a-4c42-b194-2ba30ca041f3} - C:\WINDOWS\Installer\{425300ee-456a-4c42-b194-2ba30ca041f3}\MonRunOnce.dll (file missing)
O22 - SharedTaskScheduler: sklfc94krteetj - {B5AC49A2-94F2-42BD-F434-2604812C897D} - (no file)
O22 - SharedTaskScheduler: JKhfj3ofgfgdtj - {B5AF0562-94F3-42BD-F434-2604812C797D} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Online Search Service - Unknown owner - C:\WINDOWS\System32\winlagons.exe (file missing)
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\System32\svchost.exe:exe.exe (file missing)
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe (file missing)
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8271 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 IBMTPCHK - c:\windows\system32\drivers\ibmbldid.sys
R1 Smapint - c:\windows\system32\drivers\smapint.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R1 TDSMAPI - c:\windows\system32\drivers\tdsmapi.sys
R1 TPHKDRV - c:\windows\system32\drivers\tphkdrv.sys <Not Verified; IBM Corporation; ThinkPad OnScreenDisplay>
R1 TPPWR - c:\windows\system32\drivers\tppwr.sys <Not Verified; IBM Corp.; IBM ThinkPad Utility>
R1 TSMAPIP - c:\windows\system32\drivers\tsmapip.sys
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.5.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.5.0>
R2 PMEM - c:\windows\system32\drivers\pmemnt.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R3 SjyPkt - c:\windows\system32\drivers\sjypkt.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
S0 dhlp - c:\windows\system32\drivers\dhlp.sys (file missing)
S1 pcximg - c:\windows\system\pcximg.pif (file missing)
S3 PCDRDRV (Pcdr Helper Driver) - c:\progra~1\pc-doc~1\diagno~1\pcdrdrv.sys (file missing)
S3 PcdrNt - c:\windows\system32\drivers\pcdrnt.sys <Not Verified; PC-Doctor Inc.; PC-Doctor NT 3.0>
S3 Secdrv - c:\windows\system32\drivers\secdrv.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; Scheduler>
S2 Google Online Search Service - c:\windows\system32\winlagons.exe -a (file missing)
S2 IBMPMSVC (IBM PM Service) - c:\windows\system32\ibmpmsvc.exe (file missing)
S2 ICF - c:\windows\system32\svchost.exe:exe.exe (file missing)
S2 QCONSVC - system32\qconsvc.exe (file missing)
S2 Schedule (Task Scheduler) - c:\windows\system32\drivers\spools.exe (file missing)
S2 TpKmpSVC (IBM KCU Service) - c:\windows\system32\tpkmpsvc.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-12-13 15:28:42 314 --a------ C:\WINDOWS\Tasks\BMMTask.job
-- Files created between 2008-02-16 and 2008-03-16 -----------------------------
2008-03-15 20:26:16 0 d-------- C:\Program Files\Trend Micro
2008-03-15 19:34:32 262144 --a------ C:\Program Files\Uninstall Spy Blocker.dll <Not Verified; ZoneAlarm; ZoneAlarm Spy Blocker for Internet Explorer and Firefox>
2008-03-14 22:02:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\TrojanHunter
2008-03-01 09:48:02 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-02-28 10:13:05 910336 --a------ C:\vx2cleaner.dll
2008-02-28 10:13:05 164864 --a------ C:\UNWISE.EXE
2008-02-28 10:11:56 0 d-------- C:\Program Files\Lavasoft
2008-02-28 10:01:55 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\TrojanHunter
2008-02-28 10:00:41 0 d-------- C:\Program Files\TrojanHunter 5.0
2008-02-28 09:50:18 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-28 09:50:08 4212 ---h----- C:\WINDOWS\System32\zllictbl.dat
2008-02-28 09:49:59 11264 --a------ C:\WINDOWS\System32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-02-28 09:49:32 0 d-------- C:\WINDOWS\System32\ZoneLabs
2008-02-28 09:48:35 0 d-------- C:\WINDOWS\Internet Logs
2008-02-28 09:42:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-28 09:42:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-28 09:08:52 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\InfeStop.com
2008-02-27 08:23:29 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\spy-rid.com
2008-02-27 07:58:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 18:01:08 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\EasySpywareCleaner.com
2008-02-26 08:08:42 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\WinIFixer.com
2008-02-25 20:03:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-25 20:03:16 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\Mozilla
2008-02-25 17:35:31 0 d-------- C:\Program Files\Avira
2008-02-25 17:35:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-25 11:55:38 16384 --a------ C:\WINDOWS\System32\nod32se.exe
2008-02-25 10:04:39 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\errclean
2008-02-25 09:52:46 0 d--hs---- C:\AVSystemCare
2008-02-25 09:52:42 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\SysCleaner
2008-02-25 09:52:29 0 dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-25 09:47:44 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\SystemDefender
2008-02-25 09:41:50 6656 --a------ C:\WINDOWS\System32\users32.dat
2008-02-25 09:40:36 6144 --a------ C:\WINDOWS\System32\cru629.dat
2008-02-25 09:38:17 2 --a------ C:\1746914948
-- Find3M Report ---------------------------------------------------------------
2008-03-01 09:48:59 0 d--h----- C:\Program Files\WindowsUpdate
2008-02-29 07:26:02 0 d-------- C:\Program Files\Common Files
2008-02-28 10:13:08 766 --a------ C:\Program Files\INSTALL.LOG
2008-02-12 07:58:49 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\MSN6
2008-01-04 20:30:47 0 --ah----- C:\IO.SYS
2008-01-04 20:30:47 0 --ah----- C:\CONFIG.SYS
2008-01-04 20:30:47 0 --ah----- C:\AUTOEXEC.BAT
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [10/11/2001 10:32 PM C:\WINDOWS\system32\S3Tray2.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [07/31/2003 03:25 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [07/31/2003 03:24 PM]
"ATIModeChange"="Ati2mdxx.exe" [09/04/2001 04:24 PM C:\WINDOWS\system32\Ati2mdxx.exe]
"BluetoothAuthenticationAgent"="irprops.cpl" [11/22/2002 02:45 PM C:\WINDOWS\system32\irprops.cpl]
"TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" []
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [01/17/2003 01:32 AM]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [01/17/2003 01:32 AM]
"QCWLICON"="C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" []
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [08/08/2003 03:39 PM]
"TP4EX"="tp4ex.exe" [09/04/2002 01:05 AM C:\WINDOWS\system32\TP4EX.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [12/24/2002 02:01 AM]
"AGRSMMSG"="AGRSMMSG.exe" [10/18/2002 11:07 AM C:\WINDOWS\AGRSMMSG.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [04/29/2003 09:00 PM]
"UC_SMB"="" []
"StorageGuard"="c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [06/18/2002 12:01 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [01/10/2003 03:50 AM]
"QCTray"="C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe" []
"jkdfj94kgdftdf"="C:\WINDOWS\TEMP\winlogan.exe" []
"ctfmona"="C:\WINDOWS\System32\ctfmona.exe" []
"icasServ"="C:\WINDOWS\System32\icasServ.exe" []
"ShareSearcher"="c:\wsusupd.exe" []
"SystemDefender"="C:\Program Files\SystemDefender\SystemDefender.exe" []
"ugac"="C:\PROGRA~1\COMMON~1\AVSYST~1\ugac.exe" []
"bm(1)"="C:\Program Files\Common Files\AVSystemCare\bm.exe" []
"ptask"="C:\Program Files\AVSystemCare\ptask.exe" []
"WinMed"="winmed.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/25/2008 06:33 PM]
"WinIFixer"="C:\Program Files\WinIFixer\WinIFixer.exe" []
"EasySpywareCleaner"="C:\Program Files\EasySpywareCleaner\EasySpywareCleaner.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/2007 04:05 PM]
"THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [02/08/2008 11:22 AM]
"autoload"="C:\Documents and Settings\Sarah Vanek\Local Settings\Application Data\cftmon.exe" []
"ntuser"="C:\WINDOWS\system32\drivers\spools.exe" []
"AVSystemCare"="C:\Program Files\AVSystemCare\pgs.exe" []
"ucookw"="C:\PROGRA~1\ErrClean\ucookw.exe" []
"Salestart"="C:\Program Files\Common Files\ErrClean\strpmon.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/20/2002 03:08 PM]
"Jnskdfmf9eldfd"="C:\DOCUME~1\SARAHV~1\LOCALS~1\Temp\csrssc.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"Spoolsv"="C:\WINDOWS\System32\spoolvs.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ntuser"=C:\WINDOWS\system32\drivers\spools.exe
"jkdfj94kgdftdf"=C:\WINDOWS\TEMP\winlogan.exe
"braviax"=C:\WINDOWS\System32\braviax.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless G Notebook Card Client Utility.lnk - C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe [1/7/2008 3:59:49 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"sglsxIpH"= {681FCE85-C2B5-642F-98A2-731A7DA5EA14} - C:\WINDOWS\System32\govk.dll [ ]
"WinApp"= {C285CF22-115F-3252-41AC-F686D912C63D} - C:\WINDOWS\System32\clipuser32.dll [ ]
"MonRunOnce"= {425300ee-456a-4c42-b194-2ba30ca041f3} - C:\WINDOWS\Installer\{425300ee-456a-4c42-b194-2ba30ca041f3}\MonRunOnce.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"System"="kduke.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt]
crypts.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\System32\cru629.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Reserved]
@="Driver Group"
-- End of Deckard's System Scanner: finished at 2008-03-16 07:29:45 ------------
And the extra.txt is as follows:
Deckard's System Scanner v20071014.68
Run by Sarah Vanek on 2008-03-16 07:26:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-03-16 15:26:25 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).-- HijackThis (run as Sarah Vanek.exe) -----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:27:53 AM, on 3/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\RunDll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Sarah Vanek\Desktop\dss.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Sarah Vanek.exe
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [jkdfj94kgdftdf] C:\WINDOWS\TEMP\winlogan.exe
O4 - HKLM\..\Run: [ctfmona] C:\WINDOWS\System32\ctfmona.exe
O4 - HKLM\..\Run: [icasServ] C:\WINDOWS\System32\icasServ.exe
O4 - HKLM\..\Run: [ShareSearcher] c:\wsusupd.exe
O4 - HKLM\..\Run: [SystemDefender] "C:\Program Files\SystemDefender\SystemDefender.exe" hide
O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\AVSYST~1\ugac.exe" -start
O4 - HKLM\..\Run: [bm(1)] "C:\Program Files\Common Files\AVSystemCare\bm.exe" dm=http://avsystemcare.com ad=http://avsystemcare.com sd=http://ykeeper.avsystemcare.com
O4 - HKLM\..\Run: [ptask] C:\Program Files\AVSystemCare\ptask.exe
O4 - HKLM\..\Run: [WinMed] winmed.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinIFixer] C:\Program Files\WinIFixer\WinIFixer.exe
O4 - HKLM\..\Run: [EasySpywareCleaner] C:\Program Files\EasySpywareCleaner\EasySpywareCleaner.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\Sarah Vanek\Local Settings\Application Data\cftmon.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [AVSystemCare] C:\Program Files\AVSystemCare\pgs.exe
O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\ErrClean\strpmon.exe" dm=http://errclean.com ad=http://errclean.com sd=http://inspaid.errclean.com
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\SARAHV~1\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\System32\spoolvs.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jkdfj94kgdftdf] C:\WINDOWS\TEMP\winlogan.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [braviax] C:\WINDOWS\System32\braviax.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - Global Startup: Belkin Wireless G Notebook Card Client Utility.lnk = ?
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1204393670618O20 - AppInit_DLLs: C:\WINDOWS\System32\cru629.dat
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O21 - SSODL: sglsxIpH - {681FCE85-C2B5-642F-98A2-731A7DA5EA14} - C:\WINDOWS\System32\govk.dll (file missing)
O21 - SSODL: WinApp - {C285CF22-115F-3252-41AC-F686D912C63D} - C:\WINDOWS\System32\clipuser32.dll (file missing)
O21 - SSODL: MonRunOnce - {425300ee-456a-4c42-b194-2ba30ca041f3} - C:\WINDOWS\Installer\{425300ee-456a-4c42-b194-2ba30ca041f3}\MonRunOnce.dll (file missing)
O22 - SharedTaskScheduler: sklfc94krteetj - {B5AC49A2-94F2-42BD-F434-2604812C897D} - (no file)
O22 - SharedTaskScheduler: JKhfj3ofgfgdtj - {B5AF0562-94F3-42BD-F434-2604812C797D} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Online Search Service - Unknown owner - C:\WINDOWS\System32\winlagons.exe (file missing)
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe (file missing)
O23 - Service: ICF - Unknown owner - C:\WINDOWS\System32\svchost.exe:exe.exe (file missing)
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe (file missing)
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8271 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 IBMTPCHK - c:\windows\system32\drivers\ibmbldid.sys
R1 Smapint - c:\windows\system32\drivers\smapint.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R1 TDSMAPI - c:\windows\system32\drivers\tdsmapi.sys
R1 TPHKDRV - c:\windows\system32\drivers\tphkdrv.sys <Not Verified; IBM Corporation; ThinkPad OnScreenDisplay>
R1 TPPWR - c:\windows\system32\drivers\tppwr.sys <Not Verified; IBM Corp.; IBM ThinkPad Utility>
R1 TSMAPIP - c:\windows\system32\drivers\tsmapip.sys
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.5.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.5.0>
R2 PMEM - c:\windows\system32\drivers\pmemnt.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R3 SjyPkt - c:\windows\system32\drivers\sjypkt.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
S0 dhlp - c:\windows\system32\drivers\dhlp.sys (file missing)
S1 pcximg - c:\windows\system\pcximg.pif (file missing)
S3 PCDRDRV (Pcdr Helper Driver) - c:\progra~1\pc-doc~1\diagno~1\pcdrdrv.sys (file missing)
S3 PcdrNt - c:\windows\system32\drivers\pcdrnt.sys <Not Verified; PC-Doctor Inc.; PC-Doctor NT 3.0>
S3 Secdrv - c:\windows\system32\drivers\secdrv.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (AntiVir PersonalEdition Classic Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; Scheduler>
S2 Google Online Search Service - c:\windows\system32\winlagons.exe -a (file missing)
S2 IBMPMSVC (IBM PM Service) - c:\windows\system32\ibmpmsvc.exe (file missing)
S2 ICF - c:\windows\system32\svchost.exe:exe.exe (file missing)
S2 QCONSVC - system32\qconsvc.exe (file missing)
S2 Schedule (Task Scheduler) - c:\windows\system32\drivers\spools.exe (file missing)
S2 TpKmpSVC (IBM KCU Service) - c:\windows\system32\tpkmpsvc.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-12-13 15:28:42 314 --a------ C:\WINDOWS\Tasks\BMMTask.job
-- Files created between 2008-02-16 and 2008-03-16 -----------------------------
2008-03-15 20:26:16 0 d-------- C:\Program Files\Trend Micro
2008-03-15 19:34:32 262144 --a------ C:\Program Files\Uninstall Spy Blocker.dll <Not Verified; ZoneAlarm; ZoneAlarm Spy Blocker for Internet Explorer and Firefox>
2008-03-14 22:02:59 0 d-------- C:\Documents and Settings\Administrator\Application Data\TrojanHunter
2008-03-01 09:48:02 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-02-28 10:13:05 910336 --a------ C:\vx2cleaner.dll
2008-02-28 10:13:05 164864 --a------ C:\UNWISE.EXE
2008-02-28 10:11:56 0 d-------- C:\Program Files\Lavasoft
2008-02-28 10:01:55 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\TrojanHunter
2008-02-28 10:00:41 0 d-------- C:\Program Files\TrojanHunter 5.0
2008-02-28 09:50:18 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-02-28 09:50:08 4212 ---h----- C:\WINDOWS\System32\zllictbl.dat
2008-02-28 09:49:59 11264 --a------ C:\WINDOWS\System32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-02-28 09:49:32 0 d-------- C:\WINDOWS\System32\ZoneLabs
2008-02-28 09:48:35 0 d-------- C:\WINDOWS\Internet Logs
2008-02-28 09:42:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-28 09:42:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-28 09:08:52 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\InfeStop.com
2008-02-27 08:23:29 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\spy-rid.com
2008-02-27 07:58:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-26 18:01:08 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\EasySpywareCleaner.com
2008-02-26 08:08:42 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\WinIFixer.com
2008-02-25 20:03:20 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-25 20:03:16 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\Mozilla
2008-02-25 17:35:31 0 d-------- C:\Program Files\Avira
2008-02-25 17:35:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-25 11:55:38 16384 --a------ C:\WINDOWS\System32\nod32se.exe
2008-02-25 10:04:39 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\errclean
2008-02-25 09:52:46 0 d--hs---- C:\AVSystemCare
2008-02-25 09:52:42 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\SysCleaner
2008-02-25 09:52:29 0 dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-25 09:47:44 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\SystemDefender
2008-02-25 09:41:50 6656 --a------ C:\WINDOWS\System32\users32.dat
2008-02-25 09:40:36 6144 --a------ C:\WINDOWS\System32\cru629.dat
2008-02-25 09:38:17 2 --a------ C:\1746914948
-- Find3M Report ---------------------------------------------------------------
2008-03-01 09:48:59 0 d--h----- C:\Program Files\WindowsUpdate
2008-02-29 07:26:02 0 d-------- C:\Program Files\Common Files
2008-02-28 10:13:08 766 --a------ C:\Program Files\INSTALL.LOG
2008-02-12 07:58:49 0 d-------- C:\Documents and Settings\Sarah Vanek\Application Data\MSN6
2008-01-04 20:30:47 0 --ah----- C:\IO.SYS
2008-01-04 20:30:47 0 --ah----- C:\CONFIG.SYS
2008-01-04 20:30:47 0 --ah----- C:\AUTOEXEC.BAT
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"S3TRAY2"="S3Tray2.exe" [10/11/2001 10:32 PM C:\WINDOWS\system32\S3Tray2.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [07/31/2003 03:25 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [07/31/2003 03:24 PM]
"ATIModeChange"="Ati2mdxx.exe" [09/04/2001 04:24 PM C:\WINDOWS\system32\Ati2mdxx.exe]
"BluetoothAuthenticationAgent"="irprops.cpl" [11/22/2002 02:45 PM C:\WINDOWS\system32\irprops.cpl]
"TPHOTKEY"="C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" []
"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [01/17/2003 01:32 AM]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [01/17/2003 01:32 AM]
"QCWLICON"="C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE" []
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [08/08/2003 03:39 PM]
"TP4EX"="tp4ex.exe" [09/04/2002 01:05 AM C:\WINDOWS\system32\TP4EX.exe]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [12/24/2002 02:01 AM]
"AGRSMMSG"="AGRSMMSG.exe" [10/18/2002 11:07 AM C:\WINDOWS\AGRSMMSG.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [04/29/2003 09:00 PM]
"UC_SMB"="" []
"StorageGuard"="c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [06/18/2002 12:01 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [01/10/2003 03:50 AM]
"QCTray"="C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe" []
"jkdfj94kgdftdf"="C:\WINDOWS\TEMP\winlogan.exe" []
"ctfmona"="C:\WINDOWS\System32\ctfmona.exe" []
"icasServ"="C:\WINDOWS\System32\icasServ.exe" []
"ShareSearcher"="c:\wsusupd.exe" []
"SystemDefender"="C:\Program Files\SystemDefender\SystemDefender.exe" []
"ugac"="C:\PROGRA~1\COMMON~1\AVSYST~1\ugac.exe" []
"bm(1)"="C:\Program Files\Common Files\AVSystemCare\bm.exe" []
"ptask"="C:\Program Files\AVSystemCare\ptask.exe" []
"WinMed"="winmed.exe" []
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/25/2008 06:33 PM]
"WinIFixer"="C:\Program Files\WinIFixer\WinIFixer.exe" []
"EasySpywareCleaner"="C:\Program Files\EasySpywareCleaner\EasySpywareCleaner.exe" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [11/14/2007 04:05 PM]
"THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [02/08/2008 11:22 AM]
"autoload"="C:\Documents and Settings\Sarah Vanek\Local Settings\Application Data\cftmon.exe" []
"ntuser"="C:\WINDOWS\system32\drivers\spools.exe" []
"AVSystemCare"="C:\Program Files\AVSystemCare\pgs.exe" []
"ucookw"="C:\PROGRA~1\ErrClean\ucookw.exe" []
"Salestart"="C:\Program Files\Common Files\ErrClean\strpmon.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/20/2002 03:08 PM]
"Jnskdfmf9eldfd"="C:\DOCUME~1\SARAHV~1\LOCALS~1\Temp\csrssc.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"Spoolsv"="C:\WINDOWS\System32\spoolvs.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ntuser"=C:\WINDOWS\system32\drivers\spools.exe
"jkdfj94kgdftdf"=C:\WINDOWS\TEMP\winlogan.exe
"braviax"=C:\WINDOWS\System32\braviax.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless G Notebook Card Client Utility.lnk - C:\Program Files\Belkin\Cardbus F5D701F\Wireless Utility\Belkinwcui.exe [1/7/2008 3:59:49 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"sglsxIpH"= {681FCE85-C2B5-642F-98A2-731A7DA5EA14} - C:\WINDOWS\System32\govk.dll [ ]
"WinApp"= {C285CF22-115F-3252-41AC-F686D912C63D} - C:\WINDOWS\System32\clipuser32.dll [ ]
"MonRunOnce"= {425300ee-456a-4c42-b194-2ba30ca041f3} - C:\WINDOWS\Installer\{425300ee-456a-4c42-b194-2ba30ca041f3}\MonRunOnce.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"System"="kduke.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt]
crypts.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\System32\cru629.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Reserved]
@="Driver Group"
-- End of Deckard's System Scanner: finished at 2008-03-16 07:29:45 ------------