Yes, my external HD is connected.
Hijackthis logLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:21:17 AM, on 05/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1208476276921O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1208652957703O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) -
http://www.llf.or.kr...TABSFileupU.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.mac...ash/swflash.cabO16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) -
http://asp.congnamul...Map4Asp_V30.cabO16 - DPF: {E0BF7A2B-2F7C-497A-B50F-292D3F317965} (CongnamulMap Control) -
http://www.congnamul...amulMap_V17.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7371 bytes
DSS - MainDeckard's System Scanner v20071014.68
Run by Melissa on 2008-05-05 04:14:54
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 3 Restore Point(s) --
3: 2008-05-05 11:15:01 UTC - RP35 - Deckard's System Scanner Restore Point
2: 2008-05-05 10:13:51 UTC - RP34 - Removed Windows Live Messenger
1: 2008-05-02 07:09:47 UTC - RP33 - Removed Ad-Aware 2007
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 447 MiB (512 MiB recommended).-- HijackThis (run as Melissa.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:17:10 AM, on 05/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Melissa\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Melissa.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1208476276921O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1208652957703O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) -
http://www.llf.or.kr...TABSFileupU.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.mac...ash/swflash.cabO16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) -
http://asp.congnamul...Map4Asp_V30.cabO16 - DPF: {E0BF7A2B-2F7C-497A-B50F-292D3F317965} (CongnamulMap Control) -
http://www.congnamul...amulMap_V17.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7450 bytes
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SrvcEKIOMngr - c:\windows\system32\drivers\ekiomngr.sys <Not Verified; COMPAL ELECTRONIC INC.; Compal IoManager Application>
R1 SrvcEPECioctl - c:\windows\system32\drivers\ecioctl.sys
R1 SrvcEPIOMngr - c:\windows\system32\drivers\epiomngr.sys <Not Verified; COMPAL ELECTRONIC INC.; Compal IoManager Application>
R1 SrvcSSIOMngr - c:\windows\system32\drivers\ssiomngr.sys <Not Verified; COMPAL ELECTRONIC INC.; Compal IoManager Application>
R3 EPOWER (Compal E-POWER Driver) - c:\windows\system32\drivers\hkdrv.sys <Not Verified; Compal Electronic Inc.; EPOWER>
S1 SASKUTIL - c:\program files\superantispyware\saskutil.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 CeEPwrSvc - c:\program files\toshiba\power management\ceepwrsvc.exe <Not Verified; COMPAL ELECTRONIC INC.; CeEPwrSvc Module>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\56401B9623F4A
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\56401B9623F4A
Service: NIC1394
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Atheros AR5004G Wireless Network Adapter
Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_7064144F&REV_01\4&253A0906&0&10A4
Manufacturer: Atheros
Name: Atheros AR5004G Wireless Network Adapter
PNP Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_7064144F&REV_01\4&253A0906&0&10A4
Service: AR5416
-- Scheduled Tasks -------------------------------------------------------------
2008-05-03 19:54:23 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-04-05 and 2008-05-05 -----------------------------
2008-05-03 19:54:14 0 d-------- C:\Program Files\Apple Software Update
2008-04-28 04:11:22 1914912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-28 04:07:05 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-28 04:06:52 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-04-28 04:06:38 11264 --a------ C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-04-28 04:05:54 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-04-28 04:04:00 0 d-------- C:\WINDOWS\Internet Logs
2008-04-28 01:52:53 0 d-------- C:\Documents and Settings\Melissa\Application Data\BitTorrent
2008-04-28 01:52:38 0 d-------- C:\Program Files\DNA
2008-04-28 01:52:37 0 d-------- C:\Program Files\BitTorrent
2008-04-28 01:52:37 0 d-------- C:\Documents and Settings\Melissa\Application Data\DNA
2008-04-28 00:48:16 0 d-------- C:\Program Files\Trend Micro
2008-04-27 23:48:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-27 21:42:34 0 d-------- C:\Documents and Settings\Melissa\Application Data\Malwarebytes
2008-04-27 21:42:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-27 21:42:15 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-27 21:41:57 0 d-------- C:\Program Files\Common Files\Download Manager
2008-04-27 20:16:40 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-27 20:16:15 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-27 20:16:15 0 d-------- C:\Documents and Settings\Melissa\Application Data\SUPERAntiSpyware.com
2008-04-27 19:38:37 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-27 01:15:27 0 d-------- C:\Program Files\Lavasoft
2008-04-27 01:15:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-26 20:24:57 156951 -r-hs---- C:\3bqqnkd.bat
2008-04-25 00:12:07 159782 -r-hs---- C:\9jjh.com
2008-04-21 23:14:21 0 d-------- C:\Documents and Settings\Melissa\Application Data\Apple Computer
2008-04-21 23:13:45 0 d-------- C:\Program Files\iPod
2008-04-21 23:13:30 0 d-------- C:\Program Files\iTunes
2008-04-21 23:13:04 0 d-------- C:\Program Files\Bonjour
2008-04-21 23:11:20 0 d-------- C:\Program Files\QuickTime
2008-04-21 23:11:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-21 23:09:11 0 d-------- C:\Program Files\Common Files\Apple
2008-04-21 23:09:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-21 20:00:05 158813 -r-hs---- C:\oalvm.com
2008-04-21 03:13:09 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-21 00:41:14 0 d-------- C:\Documents and Settings\Melissa\Application Data\Skype
2008-04-21 00:40:41 0 d-------- C:\Program Files\Common Files\Skype
2008-04-21 00:31:45 0 d-------- C:\Documents and Settings\Melissa\Contacts
2008-04-21 00:17:36 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-21 00:17:07 0 d-------- C:\Program Files\Windows Live
2008-04-21 00:16:46 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-21 00:09:34 0 d-------- C:\Program Files\Google
2008-04-20 23:34:46 208896 -----n--- C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Update Application for Realtek AC'97>
2008-04-20 23:34:45 1048 -----n--- C:\WINDOWS\system32\drivers\alcxinit.dat
2008-04-20 23:34:45 176 -----n--- C:\WINDOWS\system32\drivers\alcxhweq.dat
2008-04-20 23:34:45 139264 -----n--- C:\WINDOWS\alcrmv.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Removing Tool>
2008-04-20 23:33:49 0 d-------- C:\Audio.temp
2008-04-20 23:27:24 0 d-------- C:\epower.temp
2008-04-20 23:19:41 0 d-------- C:\Console.temp
2008-04-20 22:10:50 0 d-------- C:\Program Files\Winamp
2008-04-20 22:10:50 0 d-------- C:\Documents and Settings\Melissa\Application Data\Winamp
2008-04-20 15:53:35 158168 -r-hs---- C:\ig.bat
2008-04-20 02:58:11 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-04-20 02:57:27 3472 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-20 02:56:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-04-20 02:56:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-04-20 02:56:26 0 d-------- C:\Program Files\Logitech
2008-04-19 22:59:53 0 d-------- C:\Program Files\Skype
2008-04-19 22:17:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-04-19 22:17:16 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-19 21:57:29 0 d-------- C:\WINDOWS\Sun
2008-04-19 21:57:29 0 d-------- C:\Documents and Settings\Melissa\Application Data\Sun
2008-04-19 21:55:30 0 d-------- C:\Program Files\Java
2008-04-19 21:55:12 0 d-------- C:\Program Files\Common Files\Java
2008-04-19 10:48:37 158168 -r-hs---- C:\xaul0q8u.bat
2008-04-19 00:22:51 0 d-------- C:\Documents and Settings\Melissa\Application Data\Help
2008-04-19 00:22:04 0 d-------- C:\Program Files\WallpaperToy
2008-04-19 00:17:14 0 d-------- C:\Program Files\Change Mon Ecran
2008-04-19 00:14:07 1056768 --a------ C:\WINDOWS\system32\FreeImage.dll <Not Verified; FreeImage; FreeImage>
2008-04-19 00:14:07 40960 --a------ C:\WINDOWS\system32\DLLDesktop.dll <Not Verified; The Lillypad; DLLDesktop>
2008-04-19 00:14:07 36864 --a------ C:\WINDOWS\system32\AlphaImageCreator.dll <Not Verified; vbAccelerator; vbAccelerator Alpha Image Creator Helper DLL>
2008-04-19 00:14:06 98304 --a------ C:\WINDOWS\system32\ccrpUCW6.dll <Not Verified; Jeremy Adams, CCRP; ccrpUCW>
2008-04-19 00:14:06 90112 --a------ C:\WINDOWS\system32\ccrpTmr6.dll <Not Verified;
http://www.mvps.org/vb; ccrpTimers (for VB6)>
2008-04-18 23:53:17 0 d--hs---- C:\WINDOWS\ftpcache
2008-04-18 23:41:44 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-04-18 23:41:12 0 d-------- C:\WINDOWS\SHELLNEW
2008-04-18 23:30:16 0 d-------- C:\Documents and Settings\Melissa\Application Data\WinRAR
2008-04-18 23:25:03 164352 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-18 23:25:00 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-04-18 23:25:00 755027 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-04-18 23:24:59 159839 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-04-18 23:24:59 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-04-18 23:24:59 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-04-18 23:24:58 682496 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-18 23:24:57 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-04-18 23:24:56 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-04-18 23:13:55 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-18 23:11:23 0 d-------- C:\WINDOWS\system32\LogFiles
2008-04-18 23:11:23 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-18 23:07:24 0 d-------- C:\Documents and Settings\Melissa\Application Data\Media Player Classic
2008-04-18 22:20:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-18 22:19:59 0 d-------- C:\Documents and Settings\Melissa\Application Data\Mozilla
2008-04-18 22:04:10 95744 -r-hs---- C:\WINDOWS\system32\fool1.dll
2008-04-18 22:04:00 157006 -r-hs---- C:\w2ngo.com
2008-04-18 21:54:38 0 d-------- C:\Documents and Settings\Melissa\Application Data\skypePM
2008-04-18 21:54:38 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-18 21:54:08 0 d-------- C:\Program Files\uTorrent
2008-04-18 21:53:55 0 d-------- C:\Documents and Settings\Melissa\Application Data\uTorrent
2008-04-18 21:52:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-04-18 21:10:59 0 d-------- C:\Program Files\Alwil Software
2008-04-18 20:53:01 0 d-------- C:\Program Files\Common Files\logishrd
2008-04-17 18:44:42 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-17 18:44:08 0 d-------- C:\Program Files\TOSHIBA
2008-04-17 18:42:59 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-17 18:41:49 0 d-------- C:\Program Files\EzButton
2008-04-17 18:40:29 356352 --a------ C:\WINDOWS\system32\EMCRI.dll <Not Verified; ; EMCRI Dynamic Link Library>
2008-04-17 18:29:53 0 d-------- C:\Documents and Settings\Melissa\Application Data\EstSoft
2008-04-17 18:29:38 0 d-------- C:\Program Files\ESTsoft
2008-04-17 18:28:10 0 d-------- C:\Documents and Settings\Melissa\Application Data\Macromedia
2008-04-17 18:28:10 0 d-------- C:\Documents and Settings\Melissa\Application Data\Adobe
2008-04-17 17:48:03 0 d-------- C:\WINDOWS\system32\PreInstall
2008-04-17 17:48:01 0 d--h----- C:\WINDOWS\$hf_mig$
2008-04-17 17:41:56 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-04-17 17:40:57 0 d-------- C:\WINDOWS\Prefetch
2008-04-17 17:25:48 0 d-------- C:\WINDOWS\peernet
2008-04-17 17:25:47 0 d-------- C:\WINDOWS\provisioning
2008-04-17 17:24:07 0 d-------- C:\WINDOWS\ServicePackFiles
2008-04-17 17:21:09 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-04-17 17:18:42 0 d-------- C:\WINDOWS\EHome
2008-04-17 17:11:21 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-04-17 17:11:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-17 17:07:49 0 d-------- C:\WINDOWS\system32\bits
2008-04-17 16:51:23 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-04-17 16:51:10 0 d---s---- C:\Documents and Settings\Melissa\UserData
2008-04-17 16:37:47 0 d--hs---- C:\WINDOWS\Installer
2008-04-17 16:37:45 0 d-------- C:\Documents and Settings\Melissa\Application Data\Identities
2008-04-17 16:37:40 0 dr------- C:\Documents and Settings\Melissa\My Documents
2008-04-17 16:37:40 0 d--h----- C:\Documents and Settings\Melissa\Local Settings
2008-04-17 16:37:40 0 dr------- C:\Documents and Settings\Melissa\Favorites
2008-04-17 16:37:40 0 d-------- C:\Documents and Settings\Melissa\Desktop
2008-04-17 16:37:40 0 d---s---- C:\Documents and Settings\Melissa\Cookies
2008-04-17 16:37:40 0 dr-h----- C:\Documents and Settings\Melissa\Application Data
2008-04-17 16:37:39 0 d--h----- C:\Documents and Settings\Melissa\Templates
2008-04-17 16:37:39 0 dr------- C:\Documents and Settings\Melissa\Start Menu
2008-04-17 16:37:39 0 dr-h----- C:\Documents and Settings\Melissa\SendTo
2008-04-17 16:37:39 0 dr-h----- C:\Documents and Settings\Melissa\Recent
2008-04-17 16:37:39 0 d--h----- C:\Documents and Settings\Melissa\PrintHood
2008-04-17 16:37:39 3407872 --ah----- C:\Documents and Settings\Melissa\NTUSER.DAT
2008-04-17 16:37:39 0 d--h----- C:\Documents and Settings\Melissa\NetHood
2008-04-17 16:35:35 0 d--hs---- C:\System Volume Information
2008-04-17 16:35:33 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-04-17 16:35:33 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-04-17 16:35:33 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-04-17 16:35:33 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-04-17 16:35:33 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-04-17 16:35:33 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-04-17 16:35:33 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-04-17 16:35:33 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-04-17 16:35:33 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-04-17 16:35:32 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-04-17 16:30:03 0 d-------- C:\WINDOWS\system32\xircom
2008-04-17 16:30:03 0 d-------- C:\Program Files\microsoft frontpage
2008-04-17 16:30:00 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-04-17 16:29:57 0 -rahs---- C:\MSDOS.SYS
2008-04-17 16:29:57 0 -rahs---- C:\IO.SYS
2008-04-17 16:29:57 0 --a------ C:\CONFIG.SYS
2008-04-17 16:29:57 0 --a------ C:\AUTOEXEC.BAT
2008-04-17 16:29:12 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-04-17 16:29:04 0 dr------- C:\WINDOWS\Offline Web Pages
2008-04-17 16:29:04 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-04-17 16:28:46 0 d-------- C:\WINDOWS\srchasst
2008-04-17 16:28:40 0 d-------- C:\WINDOWS\system32\Macromed
2008-04-17 16:28:40 0 d-------- C:\WINDOWS\system32\DirectX
2008-04-17 16:28:29 0 d-------- C:\Program Files\Movie Maker
2008-04-17 16:28:07 0 d-------- C:\WINDOWS\system32\Restore
2008-04-17 16:28:03 0 d-------- C:\WINDOWS\PCHEALTH
2008-04-17 16:27:58 0 d---s---- C:\WINDOWS\Tasks
2008-04-17 16:27:55 0 d-------- C:\Program Files\Common Files\MSSoap
2008-04-17 16:27:45 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-17 16:27:32 0 d-------- C:\WINDOWS\Registration
2008-04-17 16:27:08 0 d--h----- C:\Program Files\WindowsUpdate
2008-04-17 16:27:08 0 d-------- C:\Program Files\Online Services
2008-04-17 16:27:04 0 d-------- C:\Program Files\Messenger
2008-04-17 16:26:56 0 d-------- C:\Program Files\MSN Gaming Zone
2008-04-17 16:26:48 0 d-------- C:\Program Files\Windows NT
2008-04-17 16:26:38 0 d-------- C:\WINDOWS\system32\MsDtc
2008-04-17 16:26:36 0 d-------- C:\WINDOWS\system32\Com
2008-04-17 06:45:06 0 d-------- C:\Program Files\Common Files\ODBC
2008-04-17 06:45:03 0 dr------- C:\Program Files
2008-04-17 06:45:03 0 d-------- C:\Program Files\Common Files
2008-04-17 06:45:03 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-04-17 06:44:43 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-04-17 06:44:43 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-04-17 06:44:43 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-04-17 06:44:43 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-04-17 06:44:43 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-04-17 06:44:43 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-04-17 06:44:43 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-04-17 06:44:43 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-04-17 06:44:43 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-04-17 06:44:43 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-04-17 06:44:43 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-04-17 06:44:43 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-04-17 06:44:43 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-04-17 06:44:43 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-04-17 06:44:43 0 dr------- C:\Documents and Settings\All Users\Documents
2008-04-17 06:44:43 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-04-17 06:44:31 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-04-17 06:44:31 0 d-------- C:\WINDOWS\system32\CatRoot
2008-04-17 06:44:26 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-04-17 06:44:26 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-04-17 06:44:25 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-04-17 06:44:25 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-04-17 06:44:12 0 d-------- C:\Documents and Settings
2008-04-17 06:40:25 0 d-------- C:\WINDOWS
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\WinSxS
2008-04-17 06:40:25 0 dr------- C:\WINDOWS\Web
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\twain_32
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\wins
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\wbem
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\usmt
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\spool
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\ShellExt
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\Setup
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\ras
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\oobe
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\npp
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\mui
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\inetsrv
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\IME
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\icsxml
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\ias
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\export
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\drivers
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-04-17 06:40:25 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\dhcp
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\config
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\3076
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\2052
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1054
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1042
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1041
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1037
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1033
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1031
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1028
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system32\1025
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\system
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\security
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Resources
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\repair
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\mui
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\msapps
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\msagent
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Media
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\java
2008-04-17 06:40:25 0 d--h----- C:\WINDOWS\inf
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\ime
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Help
2008-04-17 06:40:25 0 dr--s---- C:\WINDOWS\Fonts
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Driver Cache
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Debug
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Cursors
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Connection Wizard
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\Config
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\AppPatch
2008-04-17 06:40:25 0 d-------- C:\WINDOWS\addins
2008-04-15 22:44:09 131072 --a------ C:\WINDOWS\UNINST32.EXE <Not Verified; Dritek System Inc.; Dritek System Inc. UnInst32 12.21.1999 ( VC60 )>
-- Find3M Report ---------------------------------------------------------------
2008-04-17 06:44:43 62 --ahs---- C:\Documents and Settings\Melissa\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [03/08/2004 10:31 PM]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [03/08/2004 10:31 PM]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 10:32 PM]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 10:32 PM]
"EzButton"="C:\Program Files\EzButton\EzButton.EXE" [13/05/2004 07:29 PM]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [06/05/2004 01:12 PM]
"@"="" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [29/03/2008 11:37 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 10:16 PM]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [25/10/2007 04:33 PM]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [25/10/2007 04:37 PM]
"CeEPOWER"="C:\Program Files\TOSHIBA\Power Management\CePMTray.exe" [19/08/2004 06:14 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [28/03/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/03/2008 10:36 AM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [02/04/2008 08:07 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 12:56 AM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" []
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [22/02/2007 11:31 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43 AM]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [28/04/2008 01:52 AM]
C:\Documents and Settings\Melissa\Start Menu\Programs\Startup\
Wallpaper Changer.lnk - C:\Program Files\WallpaperToy\Wallpapertoy.Exe [19/04/2008 12:22:04 AM]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f125d53-0dc4-11dd-9365-000fb0382808}]
AutoRun\command- F:\3bqqnkd.bat
explore\Command- F:\3bqqnkd.bat
open\Command- F:\3bqqnkd.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35b06472-102a-11dd-936d-000fb0382808}]
AutoRun\command- G:\oalvm.com
explore\Command- G:\oalvm.com
open\Command- G:\oalvm.com
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8300 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-05-05 04:19:03 ------------
DSS - ExtraDeckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Mobile Intel® Pentium® 4 CPU 2.80GHz
Percentage of Memory in Use: 67%
Physical Memory (total/avail): 446.98 MiB / 146 MiB
Pagefile Memory (total/avail): 1057.6 MiB / 783.52 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1922.11 MiB
C: is Fixed (NTFS) - 37.26 GiB total, 17.34 GiB free.
D: is Fixed (NTFS) - 37.26 GiB total, 9.64 GiB free.
E: is CDROM (CDFS)
F: is Fixed (NTFS) - 232.88 GiB total, 8.53 GiB free.
\\.\PHYSICALDRIVE0 - ST980815A - 74.53 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 37.26 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 37.26 GiB - D:
\\.\PHYSICALDRIVE1 - ST325082 4A USB Device - 232.88 GiB - 1 partition
\PARTITION0 - Installable File System - 232.88 GiB - F:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.
FW: ZoneAlarm Firewall v7.0.473.000 (Check Point, LTD.)
AV: avast! antivirus 4.8.1169 [VPS 080504-0] v4.8.1169 (ALWIL Software)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Melissa\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MELISSA-BE8IDD4
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Melissa
LOGONSERVER=\\MELISSA-BE8IDD4
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Melissa\LOCALS~1\Temp
TMP=C:\DOCUME~1\Melissa\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=MELISSA-BE8IDD4
USERNAME=Melissa
USERPROFILE=C:\Documents and Settings\Melissa
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Melissa
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
avast! Antivirus --> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
BitTorrent 6.0.2 --> C:\Program Files\BitTorrent\uninst.exe
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
Easy Button --> C:\WINDOWS\UnInst32.exe EzButton.UNI
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
Java 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
K-Lite Codec Pack 3.9.0 Full --> "C:\Program Files\K-Lite Codec Pack\unins000.exe"
Logitech QuickCam --> MsiExec.exe /X{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}
Logitech QuickCam Driver Package --> "C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\11.50.1145\LgDrvInst.exe" -remove -instdir"C:\Program Files\Common Files\LogiShrd\LogiDriverStore\lvdrivers\" -enumdelay=2000 -enabledifx -forcedelete -usbhubsfirst -forceremove -cumulativeremove -promptuninstall -arpregkey"lvdrivers_11.50" /clone_wait /hide_progress
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchS