Deckard's System Scanner v20071014.68
Run by John on 2008-04-15 18:13:02
Computer is in Safe Mode with Networking.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; computer is in safe mode.
-- Last 5 Restore Point(s) --
96: 2008-04-14 20:13:00 UTC - RP737 - Restore Operation
95: 2008-04-12 00:09:40 UTC - RP736 - Installed AVG 7.5
94: 2008-04-11 22:44:09 UTC - RP735 - 4/11/08
93: 2008-04-11 22:13:51 UTC - RP734 - Deckard's System Scanner Restore Point
92: 2008-04-11 21:13:50 UTC - RP733 - Restore Operation
-- First Restore Point --
1: 2008-01-08 20:17:49 UTC - RP642 - System Checkpoint
Performed disk cleanup.
Total Physical Memory: 254 MiB (512 MiB recommended).-- HijackThis (run as John.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:13, on 2008-04-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\John\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\John.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
--
End of file - 6507 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080411-141951-118 O2 - BHO: (no name) - {014A4822-BB58-44C0-A68E-CB9E579EE4BF} - C:\WINDOWS\system32\atl7.dll
backup-20080411-141951-129 O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
backup-20080411-141951-163 O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-141951-171 O17 - HKLM\System\CCS\Services\Tcpip\..\{2810EB22-763D-4D0C-9450-64BBD1758685}: NameServer = 85.255.116.52,85.255.112.108
backup-20080411-141951-179 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.52 85.255.112.108
backup-20080411-141951-199 O4 - HKCU\..\Run: [Sen] "C:\DOCUME~1\John\MYDOCU~1\SMBOLS~1\scanregw.exe" -vt yazb
backup-20080411-141951-212 O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A
backup-20080411-141951-214 O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-141951-246 O4 - HKCU\..\Run: [aromis] C:\WINDOWS\aromis.exe
backup-20080411-141951-257 O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
backup-20080411-141951-264 O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
backup-20080411-141951-276 O21 - SSODL: hoYiTukQUTqEw - {D04D1AA3-7AE7-B009-8FF7-1FB6B1BC9023} - C:\WINDOWS\system32\en.dll
backup-20080411-141951-289 O17 - HKLM\System\CS1\Services\Tcpip\..\{2810EB22-763D-4D0C-9450-64BBD1758685}: NameServer = 85.255.116.52,85.255.112.108
backup-20080411-141951-303 O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
backup-20080411-141951-307 O4 - HKCU\..\Run: [Ershoihb] "C:\Documents and Settings\John\Application Data\?ecurity\w?wexec.exe"
backup-20080411-141951-334 O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
backup-20080411-141951-340 O4 - HKLM\..\Run: [AntiVirusPro] C:\Program Files\AntiVirusPro\AntiVirusPro.exe
backup-20080411-141951-396 O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
backup-20080411-141951-398 O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\system32\alt.exe.exe
backup-20080411-141951-404 O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
backup-20080411-141951-440 O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
backup-20080411-141951-532 O17 - HKLM\System\CCS\Services\Tcpip\..\{CF10C264-C3DF-47C9-B4C5-CEF2A7A7DBC8}: NameServer = 85.255.116.52,85.255.112.108
backup-20080411-141951-577 O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
backup-20080411-141951-592 O4 - HKCU\..\Run: [QdrPack15] "C:\Program Files\QdrPack\QdrPack15.exe"
backup-20080411-141951-595 O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
backup-20080411-141951-671 O4 - HKCU\..\Run: [QdrModule15] "C:\Program Files\QdrModule\QdrModule15.exe"
backup-20080411-141951-723 O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
backup-20080411-141951-737 O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
backup-20080411-141951-748 O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
backup-20080411-141951-778 O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-141951-785 O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-141951-801 O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
backup-20080411-141951-819 O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
backup-20080411-141951-869 O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
backup-20080411-141951-880 O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
backup-20080411-141951-919 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.52 85.255.112.108
backup-20080411-141951-943 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wmsdkns.exe,C:\WINDOWS\system32\ntos.exe,
backup-20080411-141951-953 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-141951-976 O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
backup-20080411-141951-995 O2 - BHO: (no name) - {10319EB0-7626-0AD9-0412-2800BAC980CA} - C:\WINDOWS\system32\uudgnf.dll
backup-20080411-142037-709 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-142515-898 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-143041-124 O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-143041-697 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-143041-917 O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-143554-120 O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
backup-20080411-143554-168 O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
backup-20080411-143554-174 O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
backup-20080411-143554-189 O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-143554-217 O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
backup-20080411-143554-246 O4 - HKCU\..\Run: [MSI Configuration] msiconf.exe
backup-20080411-143554-307 O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
backup-20080411-143554-351 O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-143554-403 O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
backup-20080411-143554-506 O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
backup-20080411-143554-520 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-143554-550 O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
backup-20080411-143554-597 O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
backup-20080411-143554-627 O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
backup-20080411-143554-710 O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
backup-20080411-143554-774 O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
backup-20080411-143554-792 O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
backup-20080411-143554-853 O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
backup-20080411-143554-860 O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
backup-20080411-143554-874 O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
backup-20080411-143554-894 O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-143924-860 O24 - Desktop Component 0: Desktop Uninstall - C:\WINDOWS\warnhp.html
backup-20080411-155004-128 O4 - HKCU\..\RunOnce: [SpybotDeletingB8184] command /c del "C:\WINDOWS\bjam.dll_tobedeleted"
backup-20080411-155004-147 O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
backup-20080411-155004-162 O4 - HKCU\..\RunOnce: [SpybotDeletingD8612] cmd /c del "C:\WINDOWS\system32\WER8274.DLL_tobedeleted"
backup-20080411-155004-178 O4 - HKLM\..\RunOnce: [SpybotDeletingC5140] cmd /c del "C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe_tobedeleted"
backup-20080411-155004-264 O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
backup-20080411-155004-267 O4 - HKLM\..\Run: [advap32] C:\DOCUME~1\John\LOCALS~1\Temp\3D31.tmp/r
backup-20080411-155004-290 O4 - HKCU\..\RunOnce: [SpybotDeletingB1602] command /c del "C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe_tobedeleted"
backup-20080411-155004-295 O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
backup-20080411-155004-331 O4 - HKLM\..\RunOnce: [SpybotDeletingC8480] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll_tobedeleted"
backup-20080411-155004-344 O4 - HKCU\..\RunOnce: [SpybotDeletingB1002] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll_tobedeleted"
backup-20080411-155004-345 O4 - HKLM\..\RunOnce: [SpybotDeletingA8240] command /c del "C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe_tobedeleted"
backup-20080411-155004-354 O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
backup-20080411-155004-393 O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
backup-20080411-155004-399 O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
backup-20080411-155004-407 O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
backup-20080411-155004-413 O4 - HKCU\..\RunOnce: [SpybotDeletingD5659] cmd /c del "C:\WINDOWS\bjam.dll_tobedeleted"
backup-20080411-155004-442 O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
backup-20080411-155004-473 O4 - HKLM\..\RunOnce: [SpybotDeletingC9410] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll_tobedeleted"
backup-20080411-155004-496 O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
backup-20080411-155004-515 O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
backup-20080411-155004-517 O4 - HKCU\..\RunOnce: [SpybotDeletingD3950] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll_tobedeleted"
backup-20080411-155004-528 O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
backup-20080411-155004-530 O4 - HKLM\..\RunOnce: [SpybotDeletingA5620] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll_tobedeleted"
backup-20080411-155004-531 O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
backup-20080411-155004-573 O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-155004-628 O4 - HKCU\..\RunOnce: [SpybotDeletingB9330] command /c del "C:\WINDOWS\system32\ctfmona.exe_tobedeleted"
backup-20080411-155004-660 F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\ntos.exe,C:\WINDOWS\system32\wmsdkns.exe,
backup-20080411-155004-678 O4 - HKCU\..\RunOnce: [SpybotDeletingD826] cmd /c del "C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe_tobedeleted"
backup-20080411-155004-690 O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
backup-20080411-155004-730 O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
backup-20080411-155004-735 O4 - HKCU\..\RunOnce: [SpybotDeletingD3335] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll_tobedeleted"
backup-20080411-155004-763 O4 - HKCU\..\RunOnce: [SpybotDeletingB4741] command /c del "C:\WINDOWS\2020search.dll_tobedeleted"
backup-20080411-155004-791 O4 - HKCU\..\RunOnce: [SpybotDeletingD1396] cmd /c del "C:\WINDOWS\2020search.dll_tobedeleted"
backup-20080411-155004-804 O4 - HKCU\..\Run: [Yahoo! Pager] 1
backup-20080411-155004-837 O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
backup-20080411-155004-843 O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\John\cftmon.exe
backup-20080411-155004-884 O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
backup-20080411-155004-911 O4 - HKLM\..\RunOnce: [SpybotDeletingA4804] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll_tobedeleted"
backup-20080411-155004-917 O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-155004-930 O4 - HKCU\..\RunOnce: [SpybotDeletingD2436] cmd /c del "C:\WINDOWS\system32\ctfmona.exe_tobedeleted"
backup-20080411-155004-938 O4 - HKCU\..\RunOnce: [SpybotDeletingB6956] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll_tobedeleted"
backup-20080411-155004-973 O4 - HKCU\..\RunOnce: [SpybotDeletingB4732] command /c del "C:\WINDOWS\system32\WER8274.DLL_tobedeleted"
backup-20080411-155004-996 O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
backup-20080411-155004-997 O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
backup-20080411-155005-174 O21 - SSODL: hoYiTukQUTqEw - {D04D1AA3-7AE7-B009-8FF7-1FB6B1BC9023} - C:\WINDOWS\system32\en.dll
backup-20080411-155005-384 O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
S3 catchme - c:\docume~1\john\locals~1\temp\catchme.sys (file missing)
S3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>
S3 USB2_04 (USB2_04 driver) - c:\windows\system32\drivers\nkv2.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Process Modules -------------------------------------------------------------
All modules okay.
-- Files created between 2008-03-15 and 2008-04-15 -----------------------------
2008-04-15 17:47:12 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-04-15 17:40:02 0 d-------- C:\cmdcons
2008-04-15 17:38:47 68096 --a------ C:\WINDOWS\zip.exe
2008-04-15 17:38:47 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-15 17:38:47 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-15 17:38:47 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-15 17:38:47 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-15 17:38:47 98816 --a------ C:\WINDOWS\sed.exe
2008-04-15 17:38:47 80412 --a------ C:\WINDOWS\grep.exe
2008-04-15 17:38:47 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-14 16:16:02 60160 --a------ C:\WINDOWS\system32\drivers\nkv2.sys
2008-04-12 11:52:48 444 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-04-11 20:16:30 0 dr-h----- C:\$VAULT$.AVG
2008-04-11 20:12:27 0 d-------- C:\Documents and Settings\John\Application Data\AVG7
2008-04-11 20:11:13 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-11 20:09:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-11 20:09:42 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-11 19:38:24 0 d--hs---- C:\WINDOWS\system32\wsnpoem
2008-04-11 19:35:03 192512 --a------ C:\WINDOWS\system32\cbOCR.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-04-11 18:46:16 0 d-------- C:\Documents and Settings\John\Application Data\Malwarebytes
2008-04-11 18:46:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-11 18:46:05 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-11 17:17:20 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-11 17:17:02 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-04-11 17:17:02 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-04-11 17:17:02 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-04-11 17:17:02 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-04-11 17:17:02 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-04-11 17:17:02 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-04-11 17:17:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-04-11 17:17:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-04-11 17:17:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Google
2008-04-11 16:40:28 0 d-------- C:\WINDOWS\network diagnostic
2008-04-11 16:36:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-11 14:49:37 0 d-------- C:\WINDOWS\ERUNT
2008-04-09 18:23:19 0 d-------- C:\Program Files\Trend Micro
2008-04-09 18:22:31 0 d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-04-09 18:20:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-04-09 18:18:40 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-04-09 18:18:40 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-04-09 18:18:40 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-04-09 18:18:40 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-04-09 18:18:40 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-04-09 18:18:40 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-04-09 18:18:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\Corel
2008-04-09 18:18:39 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-04-09 18:18:39 638976 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
2008-04-09 17:38:26 691545 --a------ C:\WINDOWS\unins000.exe
2008-04-09 17:38:26 2542 --a------ C:\WINDOWS\unins000.dat
2008-04-07 10:48:37 160256 --a------ C:\WINDOWS\system32\blackster.scr <Not Verified; Peter's Productions; Bugs!>
2008-04-01 04:12:22 16 --a------ C:\s3ck
2008-03-28 16:02:15 0 d-------- C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-03-28 16:00:35 0 d-------- C:\Program Files\Dell Support Center
2008-03-28 16:00:23 0 d-------- C:\Program Files\Common Files\supportsoft
2008-03-20 00:51:30 16 --a------ C:\s2p8
2008-03-19 11:34:06 16 --a------ C:\s2i4
-- Find3M Report ---------------------------------------------------------------
2008-04-11 18:59:32 5018 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-04-11 18:59:01 104 -r-hs---- C:\WINDOWS\system32\0628A65766.sys
2008-04-11 17:15:59 0 d-------- C:\Program Files\Common Files
2008-03-20 16:07:41 0 d-------- C:\Documents and Settings\John\Application Data\Corel
2008-03-04 21:04:45 16 --a------ C:\s1uk
2008-02-23 10:22:10 16 --a------ C:\s3hk
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 21:42]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-03-22 08:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-22 08:27]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-15 03:12]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 21:20]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 15:02]
"Motive SmartBridge"="C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2006-11-15 08:07]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 17:16]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-11 20:10]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 21:04]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-11-14 18:33]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-03-22 08:27:10]
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-03-25 15:12:21]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-22 08:24:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Qwc05.sys]
@="Driver"
-- End of Deckard's System Scanner: finished at 2008-04-15 18:14:19 ------------