Deckard's System Scanner v20071014.68
Run by Nic on 2008-03-29 11:28:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
70: 2008-03-29 01:28:17 UTC - RP191 - Deckard's System Scanner Restore Point
69: 2008-03-28 23:15:44 UTC - RP190 - Last known good configuration
68: 2008-03-28 23:15:15 UTC - RP189 - Installed Navman NavDesk 2008
67: 2008-03-28 23:15:14 UTC - RP188 - System Checkpoint
66: 2008-03-28 23:15:14 UTC - RP187 - System Checkpoint
-- First Restore Point --
1: 2008-03-28 23:13:51 UTC - RP122 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis (run as Nic.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:58 AM, on 29/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Documents and Settings\All Users\Application Data\kdoxyfex\inyrcfuj.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Logitech\MediaLife\MediaLifeService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\LozWare\Lozdodge\LDG_Manager.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ofwrurip.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\QUT VPN Client\cvpnd.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\LozWare\Lozdodge\LDG_Service.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Nick\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Nic.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PC-Antispyware Site Blocker Button - {10F0C2A9-8E38-43e3-204D-45524C494E20} - C:\Program Files\PC-Antispyware\IeExtension.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {70A6BA03-F8E7-42D6-A023-2D34CD6643C9} - C:\WINDOWS\system32\awtqnnnn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ContextAdvisor - {87E68009-29A8-D669-F7C2-B31D08635C50} - C:\Program Files\ContextAdvisor\ContextAdvisor-1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {94BC3D1D-22E9-4744-8ED1-3E08A3B74078} - C:\WINDOWS\system32\rqRHaxYO.dll
O2 - BHO: (no name) - {B7EA0C59-1858-423F-B900-EE21B86042A6} - (no file)
O2 - BHO: (no name) - {C748BBB6-D4F5-435E-A5A5-3197BEFB2C7D} - (no file)
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [MediaLifeService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Tpscrex] C:\Program Files\MSTpscre\Tpscrex.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [pdfw] C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe
O4 - HKLM\..\Run: [Lozdodge] C:\Program Files\LozWare\Lozdodge\LDG_Manager.exe HIDE
O4 - HKLM\..\Run: [PC-Antispyware] "C:\Program Files\PC-Antispyware\PC-Antispyware.exe" hide
O4 - HKLM\..\Run: [MbarInstall] C:\DOCUME~1\Nick\LOCALS~1\Temp\tem242.tmp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [wvqojfqn] C:\WINDOWS\system32\ofwrurip.exe
O4 - HKCU\..\Run: [xfzsklvq] C:\WINDOWS\system32\crizqfit.exe
O4 - HKLM\..\Policies\Explorer\Run: [jWK1q1eUkS] C:\Documents and Settings\All Users\Application Data\kdoxyfex\inyrcfuj.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: QUT Secure Access Service Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.c.../acclaim_v4.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: rqRHaxYO - C:\WINDOWS\SYSTEM32\rqRHaxYO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\QUT VPN Client\cvpnd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Parallels DHCP Service for Virtual NIC (PRLDHCP) - Parallels Software International, Inc. - C:\Program Files\Parallels\Parallels Workstation\PRLDHCP.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
--
End of file - 10260 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 BootScreen - c:\windows\\systemroot\system32\drivers\vidstub.sys (file missing)
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R2 hypervisor (Parallels Hypervisor) - c:\windows\system32\drivers\hypervisor.sys
R2 pvs (Parallels Kernel Driver) - c:\windows\system32\drivers\pvs.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
R2 pvsnet (Parallels Network Driver) - c:\windows\system32\drivers\pvsnet.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
R2 pvspth (Parallels Passthrough Driver) - c:\windows\system32\drivers\pvspth.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
R2 pvsum (Parallels USB Manager) - c:\windows\system32\drivers\pvsum.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
R3 PVSVNIC (Parallels Virtual NIC Driver) - c:\windows\system32\drivers\pvsvnic.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 SAVAdminService (Sophos Anti-Virus status reporter) - "c:\program files\sophos\sophos anti-virus\savadminservice.exe" <Not Verified; Sophos Plc; Sophos Anti-Virus>
R2 SAVService (Sophos Anti-Virus) - "c:\program files\sophos\sophos anti-virus\savservice.exe" <Not Verified; Sophos Plc; Sophos Anti-Virus>
R2 Sophos AutoUpdate Service - "c:\program files\sophos\autoupdate\alsvc.exe" <Not Verified; Sophos Plc; Sophos AutoUpdate>
S2 PRLDHCP (Parallels DHCP Service for Virtual NIC) - c:\program files\parallels\parallels workstation\prldhcp.exe <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0001
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0001
Service: CVirtA
-- Scheduled Tasks -------------------------------------------------------------
2008-03-29 11:21:08 446 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-03-29 10:21:00 390 --a------ C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1203553245.job
2008-03-29 03:00:00 360 --a------ C:\WINDOWS\Tasks\XoftSpySE.job
2008-03-26 19:50:13 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-03-23 15:40:28 304 --a------ C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
-- Files created between 2008-02-29 and 2008-03-29 -----------------------------
2008-03-29 11:30:32 0 d-------- C:\Program Files\Trend Micro
2008-03-29 11:24:56 110592 --a------ C:\WINDOWS\system32\crizqfit.exe
2008-03-29 11:14:15 2892 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-29 11:12:32 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-29 11:12:32 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-29 11:12:32 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-29 11:12:32 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-29 11:12:32 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-03-29 11:12:32 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-29 11:12:32 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-29 10:04:44 0 d-------- C:\Documents and Settings\Nick\Application Data\PC-Antispyware
2008-03-29 10:03:32 0 d-------- C:\Program Files\PC-Antispyware
2008-03-29 09:13:39 10034 --ahs---- C:\WINDOWS\system32\nnnnqtwa.ini2
2008-03-29 09:11:48 268288 --a------ C:\WINDOWS\system32\awtqnnnn.dll
2008-03-29 09:03:58 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-03-29 09:03:58 4096 --a------ C:\WINDOWS\system32winlogonpc.exe
2008-03-29 09:03:58 4096 --a------ C:\WINDOWS\system32hoproxy.dll
2008-03-29 09:03:58 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-03-29 09:03:58 81920 --a------ C:\WINDOWS\dwltqnmx.exe
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32taack.exe
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32taack.dat
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32sncntr.exe
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32mwin32.exe
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32hxiwlgpm.exe
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-03-29 09:03:57 4096 --a------ C:\WINDOWS\a.bat
2008-03-29 09:03:57 0 d-------- C:\Documents and Settings\Nick\Desktopvirii
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32ssurf022.dll
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32psoft1.exe
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32psof1.exe
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32ps1.exe
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32msnbho.dll
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32medup020.dll
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32medup012.dll
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe
2008-03-29 09:03:56 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-03-29 09:03:55 4096 --a------ C:\WINDOWS\system32temp#01.exe
2008-03-29 09:03:55 0 d-------- C:\WINDOWS\system32smp
2008-03-29 09:03:55 4096 --a------ C:\WINDOWS\system32netode.exe
2008-03-29 09:03:55 4096 --a------ C:\WINDOWS\system32mtr2.exe
2008-03-29 09:03:55 4096 --a------ C:\WINDOWS\system32msgp.exe
2008-03-29 09:03:55 4096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll
2008-03-29 09:03:54 4096 --a------ C:\WINDOWS\system32dpcproxy.exe
2008-03-29 09:03:51 4096 --a------ C:\WINDOWS\system32ssvchost.exe
2008-03-29 09:03:51 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-03-29 09:03:51 4096 --a------ C:\WINDOWS\system32regm64.dll
2008-03-29 09:03:51 4096 --a------ C:\WINDOWS\system32regc64.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32vcatchpi.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32thun32.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32thun.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32Rundl1.exe
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32newsd32.exe
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32msvchost.exe
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32emesx.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32anticipator.dll
2008-03-29 09:03:50 4096 --a------ C:\WINDOWS\system32akttzn.exe
2008-03-29 09:03:50 4096 --a------ C:\Documents and Settings\Nick\DesktopFWebdEditor.exe
2008-03-29 09:03:50 4096 --a------ C:\Documents and Settings\Nick\Desktopfwebd.exe
2008-03-29 09:03:50 4096 --a------ C:\Documents and Settings\Nick\Desktopfilemanagerclient.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\winsystem.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32WINWGPX.EXE
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32winsystem.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32vbsys2.dll
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32sysreq.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32mssecu.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32bdn.com
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\system32awtoolb.dll
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\mssecu.exe
2008-03-29 09:03:49 4096 --a------ C:\WINDOWS\bdn.com
2008-03-29 09:03:36 40448 --a------ C:\WINDOWS\system32\byXQKeFw.dll
2008-03-29 09:03:20 110592 --a------ C:\WINDOWS\system32\ofwrurip.exe
2008-03-29 09:03:20 0 d-------- C:\Documents and Settings\All Users\Application Data\kdoxyfex
2008-03-29 09:03:12 40448 --a------ C:\WINDOWS\system32\rqRHaxYO.dll
2008-03-29 08:37:55 0 d-------- C:\Program Files\Navman
2008-03-28 15:44:33 0 d-------- C:\Documents and Settings\Guest\Application Data\Macromedia
2008-03-28 15:44:32 0 d-------- C:\Documents and Settings\Guest\Application Data\Adobe
2008-03-28 07:52:59 0 d-------- C:\Documents and Settings\Guest\Application Data\Talkback
2008-03-28 07:49:07 0 d-------- C:\Documents and Settings\Guest\Application Data\Mozilla
2008-03-28 07:48:30 0 d-------- C:\Documents and Settings\Guest\Application Data\Logitech
2008-03-28 07:48:05 0 d-------- C:\Documents and Settings\Guest\Application Data\Share-to-Web Upload Folder
2008-03-28 07:47:32 0 d-------- C:\Documents and Settings\Guest\Application Data\Identities
2008-03-28 07:47:11 0 d--h----- C:\Documents and Settings\Guest\Templates
2008-03-28 07:47:11 0 dr------- C:\Documents and Settings\Guest\Start Menu
2008-03-28 07:47:11 0 dr-h----- C:\Documents and Settings\Guest\SendTo
2008-03-28 07:47:11 0 dr-h----- C:\Documents and Settings\Guest\Recent
2008-03-28 07:47:11 0 d--h----- C:\Documents and Settings\Guest\PrintHood
2008-03-28 07:47:11 0 d--h----- C:\Documents and Settings\Guest\NetHood
2008-03-28 07:47:11 0 dr------- C:\Documents and Settings\Guest\My Documents
2008-03-28 07:47:11 0 d--h----- C:\Documents and Settings\Guest\Local Settings
2008-03-28 07:47:11 0 dr------- C:\Documents and Settings\Guest\Favorites
2008-03-28 07:47:11 0 d-------- C:\Documents and Settings\Guest\Desktop
2008-03-28 07:47:11 0 d--hs---- C:\Documents and Settings\Guest\Cookies
2008-03-28 07:47:11 0 dr-h----- C:\Documents and Settings\Guest\Application Data
2008-03-28 07:47:11 0 d---s---- C:\Documents and Settings\Guest\Application Data\Microsoft
2008-03-28 07:47:10 786432 --ah----- C:\Documents and Settings\Guest\NTUSER.DAT
2008-03-26 19:15:27 0 d-------- C:\Program Files\LozWare
2008-03-23 10:23:08 0 d-------- C:\Program Files\Common Files\Cisco Systems
2008-03-23 10:22:59 15872 --a------ C:\WINDOWS\system32\sophosboottasks.exe <Not Verified; Sophos Plc; Sophos Anti-Virus>
2008-03-23 10:22:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Sophos
2008-03-23 10:21:30 0 d-------- C:\Program Files\Sophos
2008-03-22 13:48:12 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-03-22 13:45:07 0 d-------- C:\Documents and Settings\Nick\Application Data\InstallShield Installation Information
2008-03-22 13:44:58 0 d-------- C:\Program Files\2K Games
2008-03-22 13:43:20 0 d-------- C:\Documents and Settings\Nick\Application Data\InstallShield
2008-03-21 13:42:17 0 d-------- C:\Program Files\Incomplete
2008-03-16 16:18:43 0 d-------- C:\Documents and Settings\Nick\Application Data\Google
2008-03-15 13:07:07 12310 --a------ C:\WINDOWS\system32\drivers\pvsnet.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-15 13:06:47 8320 --a------ C:\WINDOWS\system32\drivers\PvsUM.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-15 13:06:47 13344 --a------ C:\WINDOWS\system32\drivers\pvspth.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-15 13:06:47 28800 --a------ C:\WINDOWS\system32\drivers\pvs.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-15 13:06:47 51712 --a------ C:\WINDOWS\system32\drivers\hypervisor.sys
2008-03-15 13:06:46 22752 --a------ C:\WINDOWS\system32\drivers\pvsusb.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-15 13:04:44 0 d-------- C:\Program Files\Parallels
2008-03-15 13:03:43 4412 --a------ C:\WINDOWS\system32\drivers\pvsvnic.sys <Not Verified; Parallels Software International, Inc.; Parallels Workstation 2.2>
2008-03-10 18:35:04 48 --a------ C:\Documents and Settings\Nick\test.bat
2008-03-06 17:39:52 118784 --a------ C:\WINDOWS\GREUninstall.exe
2008-03-02 12:09:18 9235 --a------ C:\WINDOWS\mozver.dat
-- Find3M Report ---------------------------------------------------------------
2008-03-29 11:23:34 0 d-------- C:\Documents and Settings\Nick\Application Data\Hamachi
2008-03-29 10:02:22 0 d-------- C:\Program Files\ContextAdvisor
2008-03-29 08:37:40 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-25 16:02:23 0 d-------- C:\Program Files\Java
2008-03-23 10:23:08 0 d-------- C:\Program Files\Common Files
2008-03-21 13:53:35 0 d-------- C:\Documents and Settings\Nick\Application Data\LimeWire
2008-03-21 13:42:17 0 d-------- C:\Program Files\LimeWire
2008-03-19 15:45:39 0 d-------- C:\Documents and Settings\Nick\Application Data\Azureus
2008-03-16 16:18:43 0 d-------- C:\Program Files\Google
2008-03-14 17:05:30 0 d-------- C:\Program Files\Azureus
2008-03-10 16:57:45 1683634 --a------ C:\WINDOWS\system32\version69ie7fix.dll
2008-03-09 09:00:50 0 d-------- C:\Program Files\Mozilla Sunbird
2008-03-06 17:41:50 0 d-------- C:\Documents and Settings\Nick\Application Data\Mozilla
2008-03-06 17:40:57 335 --a------ C:\WINDOWS\nsreg.dat
2008-02-29 16:35:37 0 d-------- C:\Documents and Settings\Nick\Application Data\Real
2008-02-27 16:35:51 0 d-------- C:\Program Files\Windows Live
2008-02-27 12:21:21 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-02-27 11:28:14 0 d-------- C:\Program Files\CaraQ
2008-02-27 06:57:13 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-24 12:55:22 2546 --a------ C:\WINDOWS\unins000.dat
2008-02-24 12:40:36 691545 --a------ C:\WINDOWS\unins000.exe
2008-02-24 11:00:52 0 d-------- C:\Documents and Settings\Nick\Application Data\Adobe
2008-02-23 18:40:52 0 d-------- C:\Program Files\FBrowserAdvisor
2008-02-22 18:19:22 0 d-------- C:\Program Files\Docudesk
2008-02-22 17:44:26 0 d-------- C:\Program Files\Amic Utilities
2008-02-22 09:51:50 0 d-------- C:\Documents and Settings\Nick\Application Data\Share-to-Web Upload Folder
2008-02-21 12:02:06 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-21 10:18:24 0 d-------- C:\Program Files\ReadIris
2008-02-21 09:56:31 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-02-21 09:54:58 0 d-------- C:\Program Files\Hewlett-Packard
2008-02-15 18:01:01 0 d-------- C:\Program Files\Rhinoceros 4.0
2008-02-07 17:06:57 0 d-------- C:\Program Files\MSTpscre
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10F0C2A9-8E38-43e3-204D-45524C494E20}]
29/03/2008 10:04 AM 176128 --a------ C:\Program Files\PC-Antispyware\IeExtension.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{70A6BA03-F8E7-42D6-A023-2D34CD6643C9}]
29/03/2008 09:11 AM 268288 --a------ C:\WINDOWS\system32\awtqnnnn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87E68009-29A8-D669-F7C2-B31D08635C50}]
31/12/2007 06:48 AM 1019904 --a------ C:\Program Files\ContextAdvisor\ContextAdvisor-1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94BC3D1D-22E9-4744-8ED1-3E08A3B74078}]
29/03/2008 09:03 AM 40448 --a------ C:\WINDOWS\system32\rqRHaxYO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7EA0C59-1858-423F-B900-EE21B86042A6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C748BBB6-D4F5-435E-A5A5-3197BEFB2C7D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [24/02/2004 09:10 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25 AM]
"MediaLifeService"="C:\Program Files\Logitech\MediaLife\MediaLifeService.exe" [12/05/2005 09:23 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [14/11/2007 11:43 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [15/11/2007 01:11 PM]
"Tpscrex"="C:\Program Files\MSTpscre\Tpscrex.exe" []
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [11/04/2002 04:19 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
"pdfw"="C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe" []
"Lozdodge"="C:\Program Files\LozWare\Lozdodge\LDG_Manager.exe" [26/03/2008 07:15 PM]
"PC-Antispyware"="C:\Program Files\PC-Antispyware\PC-Antispyware.exe" [29/03/2008 10:04 AM]
"MbarInstall"="C:\DOCUME~1\Nick\LOCALS~1\Temp\tem242.tmp.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43 AM]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [19/09/2007 12:16 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [16/11/2006 07:04 PM]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [01/11/2007 07:18 PM]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 10:00 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34 AM]
"wvqojfqn"="C:\WINDOWS\system32\ofwrurip.exe" [29/03/2008 09:03 AM]
"xfzsklvq"="C:\WINDOWS\system32\crizqfit.exe" [29/03/2008 11:24 AM]
C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [15/11/2007 4:43:19 PM]
Microsoft Office OneNote 2003 Quick Launch.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [19/04/2007 1:49:52 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [2/08/2007 11:45:14 PM]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [27/06/2002 1:20:58 AM]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [1/11/2007 7:18:05 PM]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [29/10/2007 5:43:21 PM]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [27/06/2002 1:21:30 AM]
QUT Secure Access Service Client.lnk - C:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [27/11/2007 8:59:11 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"jWK1q1eUkS"=C:\Documents and Settings\All Users\Application Data\kdoxyfex\inyrcfuj.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\PROGRA~1\Qualcomm\Eudora\EuShlExt.dll [17/08/2006 02:57 PM 86016]
"{94BC3D1D-22E9-4744-8ED1-3E08A3B74078}"= C:\WINDOWS\system32\rqRHaxYO.dll [29/03/2008 09:03 AM 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRHaxYO]
rqRHaxYO.dll 29/03/2008 09:03 AM 40448 C:\WINDOWS\system32\rqRHaxYO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtqnnnn
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
"C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TalkAndWrite"=C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\1163D2B46CC742E5A3CC9E4157887751\TalkAndWrite.exe /run
-- Hosts -----------------------------------------------------------------------
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
8027 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-03-29 11:32:03 ------------
Edited by Nic_van_Dessel, 28 March 2008 - 07:53 PM.