This is main.txt
Deckard's System Scanner v20071014.68
Run by Adalsteinn on 2008-05-08 15:59:57
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
52: 2008-05-08 23:00:00 UTC - RP185 - Deckard's System Scanner Restore Point
51: 2008-05-07 23:53:06 UTC - RP184 - Installed Windows XP KB909394.
50: 2008-05-07 23:52:59 UTC - RP183 - Installed Windows Media Player 10 KB894476.
49: 2008-05-07 23:49:09 UTC - RP182 - Unsigned driver install
48: 2008-05-07 22:51:50 UTC - RP181 - ComboFix created restore point
-- First Restore Point --
1: 2008-04-01 17:41:26 UTC - RP134 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 13.25 GiB (less than 15%) free.-- HijackThis (run as Adalsteinn.exe) ------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:00:30 PM, on 5/8/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Adalsteinn\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Adalsteinn.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.daemon-search.com/startpageR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SurfingEnhancer - {57636FBF-8C24-0D22-E203-3D4DFA59E2A4} - C:\Program Files\SurfingEnhancer\SurfingEnhancer-1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 4830 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 atksgt - c:\windows\system32\drivers\atksgt.sys
R2 lirsgt - c:\windows\system32\drivers\lirsgt.sys
S3 catchme - c:\combofix\catchme.sys (file missing)
S3 lac97inf - c:\docume~1\adalst~1\locals~1\temp\lac97inf.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
S4 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe <Not Verified; Rocket Division Software; StarWind Alcohol Edition>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Network Controller
Device ID: PCI\VEN_1814&DEV_0201&SUBSYS_0B541432&REV_01\4&3B1D9AB8&0&3040
Manufacturer:
Name: Network Controller
PNP Device ID: PCI\VEN_1814&DEV_0201&SUBSYS_0B541432&REV_01\4&3B1D9AB8&0&3040
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200014F1&REV_00\4&3B1D9AB8&0&4040
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200014F1&REV_00\4&3B1D9AB8&0&4040
Service:
-- Files created between 2008-04-08 and 2008-05-08 -----------------------------
2008-05-08 15:43:54 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\Malwarebytes
2008-05-08 15:43:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-08 15:43:49 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-07 16:29:53 0 d-------- C:\Program Files\Trend Micro
2008-05-07 15:50:59 68096 --a------ C:\WINDOWS\zip.exe
2008-05-07 15:50:59 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-07 15:50:59 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-07 15:50:59 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-07 15:50:59 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-07 15:50:59 98816 --a------ C:\WINDOWS\sed.exe
2008-05-07 15:50:59 80412 --a------ C:\WINDOWS\grep.exe
2008-05-07 15:50:59 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-06 21:11:36 0 d-------- C:\Documents and Settings\Adalsteinn\.housecall6.6
2008-05-05 14:13:37 372736 --a------ C:\WINDOWS\System32\MtRepair2.exe <Not Verified; M i r a r; M i r a r ATD RPT RPSVC>
2008-05-05 14:13:37 372736 --a------ C:\WINDOWS\System32\MtRepair1.exe <Not Verified; M i r a r; M i r a r ATD RPT RPSVC>
2008-05-05 14:13:27 385024 --a------ C:\WINDOWS\System32\WinNB54.dll <Not Verified; ; MBar AFF ATD IESC>
2008-05-05 14:13:19 0 d-------- C:\Program Files\SurfingEnhancer
2008-04-20 20:05:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-19 18:19:29 0 d-------- C:\Program Files\Bethesda Softworks
2008-04-19 16:23:52 679936 --a------ C:\WINDOWS\System32\ijjiSetup.exe <Not Verified; NHN USA; ijjiSetup Application>
2008-04-19 16:23:52 0 d-------- C:\Program Files\NHN USA
2008-04-15 13:55:19 0 d-------- C:\WINDOWS\System32\Adobe
2008-04-10 01:25:37 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\iPodder
2008-04-10 01:25:26 0 d-------- C:\Program Files\Juice
2008-04-08 16:10:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Ableton
2008-04-08 16:10:19 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\Ableton
2008-04-08 16:09:50 368640 --a------ C:\WINDOWS\System32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-04-08 16:09:17 0 d-------- C:\Program Files\Ableton
-- Find3M Report ---------------------------------------------------------------
2008-05-08 15:56:18 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\AVG7
2008-05-08 15:42:04 0 d-------- C:\Program Files\Common Files\Download Manager
2008-05-08 15:01:00 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\uTorrent
2008-05-07 20:57:58 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\LimeWire
2008-05-07 16:53:00 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-04-26 22:06:01 0 d-------- C:\Program Files\Steam
2008-04-19 18:19:17 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-15 14:10:46 2777 --a------ C:\WINDOWS\mozver.dat
2008-04-15 13:55:48 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\Adobe
2008-04-15 13:55:47 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\Macromedia
2008-04-13 20:05:19 0 d-------- C:\Program Files\iDump
2008-04-13 20:04:34 0 d-------- C:\Program Files\Media Widget
2008-04-11 20:06:37 0 d-------- C:\Program Files\Common Files
2008-04-11 19:57:31 0 d-------- C:\Program Files\Creative
2008-04-03 18:15:09 0 d-------- C:\Program Files\Audible
2008-04-03 18:12:25 0 d-------- C:\Program Files\Opera
2008-04-03 18:04:13 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-01 20:38:35 0 d-------- C:\Program Files\ScummVM
2008-03-29 16:31:59 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\ScummVM
2008-03-29 14:41:05 0 d-------- C:\Program Files\Project64 1.6
2008-03-29 14:08:22 0 d-------- C:\Program Files\Project64 v1.5
2008-03-22 02:17:43 0 d-------- C:\Documents and Settings\Adalsteinn\Application Data\dvdcss
2008-03-22 02:16:52 0 d-------- C:\Program Files\InterActual
2008-03-15 18:09:05 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-03-05 22:05:07 43520 --a------ C:\WINDOWS\System32\CmdLineExt03.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57636FBF-8C24-0D22-E203-3D4DFA59E2A4}]
12/30/2007 01:48 PM 1019904 --a------ C:\Program Files\SurfingEnhancer\SurfingEnhancer-1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [06/03/2004 08:51 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/18/2008 09:02 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 05:00 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [06/20/2006 10:36 PM]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [06/22/2007 05:45 AM]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [12/22/2007 12:23 AM]
"Aim6"="" []
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [06/12/2006 02:32 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Adalsteinn^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Adalsteinn^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
"C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
"C:\Program Files\DAEMON Tools\daemon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack10]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMC_AutoUpdate]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StarWindServiceAE"=2 (0x2)
"Adobe LM Service"=3 (0x3)
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
-- End of Deckard's System Scanner: finished at 2008-05-08 16:00:57 ------------