With Hijackthis, some things just won't be fixed--the error is just "Registry Edits have been disabled by the Administrator"
And, the DSS was scanning still--I just wasn't sure how important the errors were.
Anyhow Main:
Deckard's System Scanner v20071014.68
Run by CurtFess on 2008-05-24 12:28:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-05-24 16:28:25 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 384 MiB (512 MiB recommended).-- HijackThis (run as CurtFess.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:52 PM, on 5/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\CurtFess\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\CurtFess.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0E59EBEF-0666-4122-B6B5-105068F15D0E} - C:\WINDOWS\system32\cbXOFvVm.dll (file missing)
O2 - BHO: (no name) - {0F5AE548-F131-45DA-8C6F-32EBEB174AE1} - C:\WINDOWS\system32\mlJyAQKB.dll (file missing)
O2 - BHO: (no name) - {1F6CC0D3-565F-482D-A044-AD45FC9C0814} - C:\WINDOWS\system32\urqOExuT.dll (file missing)
O2 - BHO: (no name) - {251AA008-BD0A-4C66-B81F-52DBE4108918} - C:\WINDOWS\system32\qoMfdaYq.dll (file missing)
O2 - BHO: {8550b3b7-eaaf-7259-6ac4-f5de42d32373} - {37323d24-ed5f-4ca6-9527-faae7b3b0558} - C:\WINDOWS\system32\nqmafasx.dll
O2 - BHO: (no name) - {377B2634-D458-48B6-98D5-D9E1199F462F} - C:\WINDOWS\system32\jkkjJBUm.dll (file missing)
O2 - BHO: (no name) - {5B9A2BC5-2243-4EC7-A605-584ACB9356CA} - C:\WINDOWS\system32\opnolLcB.dll (file missing)
O2 - BHO: (no name) - {63371012-F68E-40A5-8D82-99257305308B} - C:\WINDOWS\system32\xxyvusQH.dll (file missing)
O2 - BHO: (no name) - {6AAC6353-ED33-53CC-D575-66557B87733D} - C:\WINDOWS\system32\vfsa.dll (file missing)
O2 - BHO: (no name) - {72FF9E18-AA28-47A4-954F-89857328EC80} - C:\WINDOWS\system32\cbXNGXPH.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7EE573EC-502B-4527-86B9-5F5E649BEA00} - C:\WINDOWS\system32\opnnooop.dll (file missing)
O2 - BHO: StFlex IE Helper - {8334A30C-49E5-489a-B63D-5B927C1EF46E} - C:\Program Files\QdrDrive\QdrDrive15.dll
O2 - BHO: (no name) - {8365396B-25C1-440B-AEB3-3E8122D71938} - C:\WINDOWS\system32\ljJBroLc.dll (file missing)
O2 - BHO: (no name) - {A75B1E37-87F9-DF22-8248-891DF24644C3} - C:\WINDOWS\system32\pybiluq.dll (file missing)
O2 - BHO: (no name) - {A8E8C748-56DD-7D23-8C49-0FC5490D10E7} - C:\WINDOWS\system32\sjfxqbn.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: (no name) - {AE603669-3A5F-4C25-A85D-FF91E7EE01A9} - C:\WINDOWS\system32\byXPFYQg.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {B7CDDC68-4BAE-4F95-A3B3-7B6C168F0B30} - C:\WINDOWS\system32\qoMccYSK.dll (file missing)
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINDOWS\system32\opnoNeFV.dll
O2 - BHO: (no name) - {D744DA6E-16D6-4D62-8F9D-E756C9A88430} - C:\WINDOWS\system32\rqRKCVPh.dll (file missing)
O2 - BHO: (no name) - {D869F825-3467-4976-852A-5BA4D2E31AD7} - C:\WINDOWS\system32\pmnnLeFU.dll (file missing)
O2 - BHO: (no name) - {D928D6B9-4949-4669-BEA0-021F735308EE} - C:\WINDOWS\system32\tuvVOFxw.dll (file missing)
O2 - BHO: (no name) - {FC00DD52-AF6E-4422-9110-586D5DAE7141} - C:\WINDOWS\system32\ljJYSlkj.dll (file missing)
O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [f023c42c] rundll32.exe "C:\WINDOWS\system32\ukorhpti.dll",b
O4 - HKLM\..\Run: [BMf310f7b0] Rundll32.exe "C:\WINDOWS\system32\svoblpdb.dll",s
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Policies\Explorer\Run: [odeesv] C:\WINDOWS\system32\odeesv.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0645D7F3-C20E-4E0B-A545-557527497C0B} (NMInstall Control) -
http://a14.g.akamai....GAPANEL_USA.cabO16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://pcpitstop.com...p/PCPitStop.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.exe.imgfar...tup1.0.0.15.cabO16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip....pGameLoader.dllO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) -
http://www.cyberlink...xp/CheckDVD.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://download.divx...owserPlugin.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.c.../acclaim_v5.cabO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
https://www.gamespyid.com/alaunch.cabO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} -
http://www.nick.com/.../GrooveAX25.cabO16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} -
http://ak.imgfarm.co...etup1.0.0.7.cabO16 - DPF: {7A32634B-029C-4836-A023-528983982A49} -
http://fdl.msn.com/p...t/msnchat42.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.c...utocomplete.cabO16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real...ArcadeRdxIE.cabO16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
http://www.windowsec...scan/axscan.cabO16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) -
http://a532.g.akamai...0/Installer.exeO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: opnoNeFV - C:\WINDOWS\SYSTEM32\opnoNeFV.dll
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\b2new.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O24 - Desktop Component 0: (no name) -
http://www.worldofwa...qiraj-1024x.jpgO24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com -
http://active.intell...ctive/?17974917--
End of file - 12143 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080519-154846-682 O24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com -
http://active.intell...ctive/?17974917backup-20080519-154913-735 O4 - HKLM\..\Run: [AntispySpider] C:\Program Files\AntispySpider\antispyspider.exe
backup-20080519-155120-620 O24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com -
http://active.intell...ctive/?17974917backup-20080519-192138-812 O24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com -
http://active.intell...ctive/?17974917backup-20080519-193801-954 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
backup-20080519-193803-905 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://utu.popcap.co...aploader_v5.cabbackup-20080524-113404-425 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
backup-20080524-113404-476 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
backup-20080524-113404-521 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
backup-20080524-113404-582 F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
backup-20080524-113404-697 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
backup-20080524-113404-820 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
backup-20080524-113404-849 O24 - Desktop Component 2: Intelligent Desktop - intelligentdesktop.com -
http://active.intell...ctive/?17974917-- File Associations -----------------------------------------------------------
.js - JSFile - DefaultIcon - unable to read value.js - JSFile - shell\open\command - unable to read value-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
S3 XTrapD12 - c:\program files\legend of ares\\xtrap\xtrapd12.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 MsSecurity1.209.4 (MsSecurity Updated) - c:\windows\b2new.exe service (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-24 11:06:00 418 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-05-23 16:00:03 414 --ah----- C:\WINDOWS\Tasks\{4BA28505-D509-483C-8D83-A40EFBC328F6}_STARCRAFT_Amercaindancer.job
-- Files created between 2008-04-24 and 2008-05-24 -----------------------------
2008-05-24 12:08:30 315120 --a------ C:\WINDOWS\system32\awttrSJD.dll
2008-05-24 11:21:29 4250 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-24 11:08:29 315120 --a------ C:\WINDOWS\system32\ljJBuvuv.dll
2008-05-23 20:31:42 100608 --a------ C:\WINDOWS\system32\nqmafasx.dll
2008-05-23 20:28:42 2560 --a------ C:\WINDOWS\system32\jkamimev.exe
2008-05-23 20:22:42 83200 --a------ C:\WINDOWS\system32\ukorhpti.dll
2008-05-23 20:19:42 91008 --a------ C:\WINDOWS\system32\svoblpdb.dll
2008-05-22 20:16:41 901681 --ahs---- C:\WINDOWS\system32\TuxEOqru.ini2
2008-05-22 11:02:23 0 dr-h----- C:\$VAULT$.AVG
2008-05-22 09:31:03 23670 --ahs---- C:\WINDOWS\system32\BcLlonpo.ini2
2008-05-21 15:01:21 99952 --a------ C:\WINDOWS\system32\bbvvtuew.dll
2008-05-21 14:55:19 2560 --a------ C:\WINDOWS\system32\btltplun.exe
2008-05-21 14:52:18 83296 --a------ C:\WINDOWS\system32\pvepkxgr.dll
2008-05-21 14:50:23 90896 --a------ C:\WINDOWS\system32\ebxorsgi.dll
2008-05-21 14:49:17 885749 --ahs---- C:\WINDOWS\system32\mUBJjkkj.ini2
2008-05-20 15:18:05 2560 --a------ C:\WINDOWS\system32\blxjaiil.exe
2008-05-20 15:12:04 82976 --a------ C:\WINDOWS\system32\vgxyopeg.dll
2008-05-20 15:09:04 99984 --a------ C:\WINDOWS\system32\hgakgjfk.dll
2008-05-20 15:07:54 90208 --a------ C:\WINDOWS\system32\kmmuvnmf.dll
2008-05-20 15:06:02 1023416 --ahs---- C:\WINDOWS\system32\mVvFOXbc.ini2
2008-05-19 19:09:13 99856 --a------ C:\WINDOWS\system32\vtdwyvpn.dll
2008-05-19 19:09:08 83024 --a------ C:\WINDOWS\system32\iiqnkiss.dll
2008-05-19 19:03:06 2560 --a------ C:\WINDOWS\system32\axaxmtup.exe
2008-05-19 18:58:04 90160 --a------ C:\WINDOWS\system32\jxmghapo.dll
2008-05-19 18:57:04 1011424 --ahs---- C:\WINDOWS\system32\jklSYJjl.ini2
2008-05-19 16:11:31 2560 --a------ C:\WINDOWS\system32\oquyaowm.exe
2008-05-19 16:11:25 99856 --a------ C:\WINDOWS\system32\ypuelghc.dll
2008-05-19 16:06:15 83024 --a------ C:\WINDOWS\system32\vwgkmqgl.dll
2008-05-19 16:06:06 90160 --a------ C:\WINDOWS\system32\suenwvan.dll
2008-05-19 16:05:20 1009135 --ahs---- C:\WINDOWS\system32\BKQAyJlm.ini2
2008-05-19 15:34:46 0 d-------- C:\Program Files\Trend Micro
2008-05-19 15:06:42 2560 --a------ C:\WINDOWS\system32\jkxymbhh.exe
2008-05-19 15:06:34 99856 --a------ C:\WINDOWS\system32\yvvnqukp.dll
2008-05-19 15:03:33 83024 --a------ C:\WINDOWS\system32\fpvyaysu.dll
2008-05-19 15:01:35 90160 --a------ C:\WINDOWS\system32\hymmwckm.dll
2008-05-19 02:57:25 83072 --a------ C:\WINDOWS\system32\gmstlcrd.dll
2008-05-19 02:57:06 98880 --a------ C:\WINDOWS\system32\qnipmugf.dll
2008-05-19 02:56:42 90272 --a------ C:\WINDOWS\system32\rgwxgyft.dll
2008-05-18 03:05:42 98960 --a------ C:\WINDOWS\system32\xsbvxgfb.dll
2008-05-18 02:54:49 90224 --a------ C:\WINDOWS\system32\dtylhlxd.dll
2008-05-18 02:53:40 1343954 --ahs---- C:\WINDOWS\system32\pooonnpo.ini2
2008-05-17 21:59:55 82960 --a------ C:\WINDOWS\system32\jaibvkum.dll
2008-05-17 21:57:05 98960 --a------ C:\WINDOWS\system32\eqgypoti.dll
2008-05-17 21:46:12 90224 --a------ C:\WINDOWS\system32\ooarslfr.dll
2008-05-17 21:44:50 1346063 --ahs---- C:\WINDOWS\system32\UFeLnnmp.ini2
2008-05-17 16:09:51 98960 --a------ C:\WINDOWS\system32\avdqpnnc.dll
2008-05-17 16:06:28 90224 --a------ C:\WINDOWS\system32\yenxqsxm.dll
2008-05-17 08:20:17 82960 --a------ C:\WINDOWS\system32\sqbetgsv.dll
2008-05-17 08:18:06 98960 --a------ C:\WINDOWS\system32\njxkbsjy.dll
2008-05-17 08:11:55 90224 --a------ C:\WINDOWS\system32\ptwmsjxv.dll
2008-05-17 08:08:08 1006431 --ahs---- C:\WINDOWS\system32\HQsuvyxx.ini2
2008-05-16 21:00:31 98896 --a------ C:\WINDOWS\system32\ovbsrwdh.dll
2008-05-16 20:54:24 90240 --a------ C:\WINDOWS\system32\ffhnoswi.dll
2008-05-16 20:51:18 371 --ahs---- C:\WINDOWS\system32\cLorBJjl.ini2
2008-05-16 20:42:36 0 d-------- C:\Documents and Settings\PHAT_MOMMA\Application Data\AVG7
2008-05-16 17:42:16 98896 --a------ C:\WINDOWS\system32\mspufrlj.dll
2008-05-16 17:41:15 82992 --a------ C:\WINDOWS\system32\jllcmdsk.dll
2008-05-16 17:40:09 90240 --a------ C:\WINDOWS\system32\rxsoaqwa.dll
2008-05-16 17:38:08 1348235 --ahs---- C:\WINDOWS\system32\HPXGNXbc.ini2
2008-05-16 16:26:41 347 --ahs---- C:\WINDOWS\system32\stuvGfhk.ini2
2008-05-15 18:40:22 82960 --a------ C:\WINDOWS\system32\covluvny.dll
2008-05-15 18:37:22 98960 --a------ C:\WINDOWS\system32\qmgarqes.dll
2008-05-15 18:35:41 90304 --a------ C:\WINDOWS\system32\spbkehuq.dll
2008-05-15 17:01:32 98960 --a------ C:\WINDOWS\system32\mxumpxht.dll
2008-05-15 16:59:39 90304 --a------ C:\WINDOWS\system32\bccxnrmx.dll
2008-05-15 13:54:12 90304 --a------ C:\WINDOWS\system32\jylrhyvq.dll
2008-05-15 13:51:17 1328017 --ahs---- C:\WINDOWS\system32\qYadfMoq.ini2
2008-05-15 13:46:59 0 d-------- C:\Program Files\RcvSystem
2008-05-11 14:39:26 98912 --a------ C:\WINDOWS\system32\vxkvojbm.dll
2008-05-11 14:35:16 90208 --a------ C:\WINDOWS\system32\jlofcyij.dll
2008-05-11 14:33:24 1050089 --ahs---- C:\WINDOWS\system32\wxFOVvut.ini2
2008-05-11 08:52:51 98912 --a------ C:\WINDOWS\system32\ueqicerl.dll
2008-05-11 08:35:32 90208 --a------ C:\WINDOWS\system32\njhyqnjo.dll
2008-05-11 08:34:16 1041395 --ahs---- C:\WINDOWS\system32\KSYccMoq.ini2
2008-05-10 21:45:45 7109 --ahs---- C:\WINDOWS\system32\hPVCKRqr.ini2
2008-05-10 20:20:58 0 d-------- C:\WINDOWS\network diagnostic
2008-05-10 14:25:42 7785 --ahs---- C:\WINDOWS\system32\gQYFPXyb.ini2
2008-05-10 14:22:36 32768 --a------ C:\WINDOWS\system32\sockins32.dll <Not Verified; ThinkPad; ThinkPad repl>
2008-05-10 14:22:07 0 d-------- C:\Program Files\QdrPack
2008-05-10 14:21:23 0 d-------- C:\Program Files\QdrModule
2008-05-10 14:20:47 0 d-------- C:\Program Files\QdrDrive
2008-05-10 14:20:21 25728 --a------ C:\WINDOWS\system32\opnoNeFV.dll
2008-05-10 14:20:15 0 d-------- C:\Program Files\ISM
-- Find3M Report ---------------------------------------------------------------
2008-05-24 11:03:57 0 d-------- C:\Documents and Settings\CurtFess\Application Data\AVG7
2008-05-19 15:03:13 0 d-------- C:\Program Files\Common Files
2008-05-19 15:02:11 0 d-------- C:\Program Files\AIM+
2008-03-28 09:28:47 0 d-------- C:\Program Files\Armagetron Advanced
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E59EBEF-0666-4122-B6B5-105068F15D0E}]
C:\WINDOWS\system32\cbXOFvVm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F5AE548-F131-45DA-8C6F-32EBEB174AE1}]
C:\WINDOWS\system32\mlJyAQKB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F6CC0D3-565F-482D-A044-AD45FC9C0814}]
C:\WINDOWS\system32\urqOExuT.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{251AA008-BD0A-4C66-B81F-52DBE4108918}]
C:\WINDOWS\system32\qoMfdaYq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37323d24-ed5f-4ca6-9527-faae7b3b0558}]
05/23/2008 08:31 PM 100608 --a------ C:\WINDOWS\system32\nqmafasx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377B2634-D458-48B6-98D5-D9E1199F462F}]
C:\WINDOWS\system32\jkkjJBUm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B9A2BC5-2243-4EC7-A605-584ACB9356CA}]
C:\WINDOWS\system32\opnolLcB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63371012-F68E-40A5-8D82-99257305308B}]
C:\WINDOWS\system32\xxyvusQH.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6AAC6353-ED33-53CC-D575-66557B87733D}]
C:\WINDOWS\system32\vfsa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72FF9E18-AA28-47A4-954F-89857328EC80}]
C:\WINDOWS\system32\cbXNGXPH.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7EE573EC-502B-4527-86B9-5F5E649BEA00}]
C:\WINDOWS\system32\opnnooop.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8334A30C-49E5-489a-B63D-5B927C1EF46E}]
04/03/2008 04:05 PM 147456 --a------ C:\Program Files\QdrDrive\QdrDrive15.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8365396B-25C1-440B-AEB3-3E8122D71938}]
C:\WINDOWS\system32\ljJBroLc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A75B1E37-87F9-DF22-8248-891DF24644C3}]
C:\WINDOWS\system32\pybiluq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8E8C748-56DD-7D23-8C49-0FC5490D10E7}]
C:\WINDOWS\system32\sjfxqbn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE603669-3A5F-4C25-A85D-FF91E7EE01A9}]
C:\WINDOWS\system32\byXPFYQg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B7CDDC68-4BAE-4F95-A3B3-7B6C168F0B30}]
C:\WINDOWS\system32\qoMccYSK.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}]
05/10/2008 02:20 PM 25728 --a------ C:\WINDOWS\system32\opnoNeFV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D744DA6E-16D6-4D62-8F9D-E756C9A88430}]
C:\WINDOWS\system32\rqRKCVPh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D869F825-3467-4976-852A-5BA4D2E31AD7}]
C:\WINDOWS\system32\pmnnLeFU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D928D6B9-4949-4669-BEA0-021F735308EE}]
C:\WINDOWS\system32\tuvVOFxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC00DD52-AF6E-4422-9110-586D5DAE7141}]
C:\WINDOWS\system32\ljJYSlkj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [08/11/2006 10:43 PM]
"nwiz"="nwiz.exe" [08/11/2006 10:43 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [08/11/2006 10:43 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08/28/2004 05:48 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/18/2008 03:55 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/21/2005 07:29 PM]
"@"="" []
"f023c42c"="C:\WINDOWS\system32\ukorhpti.dll" [05/23/2008 08:22 PM]
"BMf310f7b0"="C:\WINDOWS\system32\svoblpdb.dll" [05/23/2008 08:19 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [08/21/2006 01:48 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/15/2007 12:20 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
"DisableRegistryTools"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
@=
"NoActiveDesktop"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"odeesv"=C:\WINDOWS\system32\odeesv.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}"= C:\WINDOWS\system32\opnoNeFV.dll [05/10/2008 02:20 PM 25728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebProxy"= {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoNeFV]
opnoNeFV.dll 05/10/2008 02:20 PM 25728 C:\WINDOWS\system32\opnoNeFV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\urqOExuT
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^CurtFess^Start Menu^Programs^Startup^WinMySQLadmin.lnk]
path=C:\Documents and Settings\CurtFess\Start Menu\Programs\Startup\WinMySQLadmin.lnk
backup=C:\WINDOWS\pss\WinMySQLadmin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\180ax]
c:\windows\180ax.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2LRX2W83X2T3MQ]
C:\WINDOWS\System32\MtyJ62F.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8]
C:\documents and settings\curtfess\local settings\temp\8.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\8D]
C:\documents and settings\amercaindancer\local settings\temp\8D.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AHQInit]
C:\Program Files\Creative\SBLive\Program\AHQInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aida]
"C:\DOCUME~1\AMERCA~1\APPLIC~1\SEMBLY~1\regsvr32.exe" -vt ndrv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM95\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bargains]
C:\Program Files\Bargain Buddy\bin2\bargains.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
C:\Program Files\BroadJump\Client Foundation\CFD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DealHelperBrwsr]
C:\WINDOWS\dhbrwsr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DealHelperUpdate]
C:\WINDOWS\DHUpdt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIAGENT]
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
"C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hehsks]
C:\WINDOWS\vrygq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotNow]
C:\Program Files\PVM\Dialers\HotNow\HotNow.exe /dontdial
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer]
"C:\Program Files\Internet Optimizer\optimize.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ippromon]
C:\WINDOWS\System32\ippromon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\loads.exe]
C:\WINDOWS\suploads.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mediamotor.exe]
C:\WINDOWS\mmups.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mfyj]
C:\WINDOWS\mfyj.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mh4]
C:\documents and settings\amercaindancer\local settings\temp\Mh4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyStartUp]
C:\Program Files\Microsoft Money\System\Money Startup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS Updates]
C:\WINDOWS\mscache.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbb]
c:\temp\msbb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV Agent]
C:\PROGRA~1\NORTON~1\navapw32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\odeesv]
C:\WINDOWS\system32\odeesv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ojexmtyb]
C:\WINDOWS\ojexmtyb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSS]
c:\windows\system32\rk.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prutict]
C:\WINDOWS\system32\prutict.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prvtect]
C:\WINDOWS\system32\prvtect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
C:\WINDOWS\Temp\RecoverFromReboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperPowerIcons]
C:\Program Files\Super Power Icons\SuperPowerIcons.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 2]
C:\Program Files\SurfSideKick 2\Ssk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPS]
C:\PROGRA~1\Toolbar\TBPS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Media]
C:\Program Files\TV Media\Tvm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\Updreg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAPI]
C:\WINDOWS\System32\wtssvcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\Program Files\AWS\WeatherBug\Weather.EXE 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0]
"C:\Program Files\Web_Rebates\WebRebates0.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows SA]
C:\Program Files\WindowsSA\omniscient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTools]
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
C:\Program Files\Microsoft Works\wkfud.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zango]
"c:\program files\zango\zango.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66186F05-BBBB-4a39-864F-72D84615C679}]
rundll32 sockins32.dll,InitModule
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.f1organizer.com #REMOVED ADWARE URL
127.0.0.1 www.netpalnow.com #REMOVED ADWARE URL
127.0.0.1 www.addictivetechnologies.com #REMOVED ADWARE URL
127.0.0.1 easywarez.com www.easywarez.com ftp.easywarez.com update.easywarez.com support.easywarez.com warezspot.com www.warezspot.com #fwav
127.0.0.1 www.warezspot.com ftp.warezspot.com update.warezspot.com support.warezspot.com freegirlfun.com www.freegirlfun.com ftp.freegirlfun.com #fwav
127.0.0.1 ftp.freegirlfun.com update.freegirlfun.com support.freegirlfun.com 204.177.92.193 www.204.177.92.193 ftp.204.177.92.193 update.204.177.92.193 #fwav
127.0.0.1 update.204.177.92.193 support.204.177.92.193 204.177.92.198 www.204.177.92.198 ftp.204.177.92.198 update.204.177.92.198 support.204.177.92.198 #fwav
127.0.0.1 support.204.177.92.198 free-memberships.net www.free-memberships.net ftp.free-memberships.net update.free-memberships.net support.free-memberships.net #fwav
-- End of Deckard's System Scanner: finished at 2008-05-24 13:02:28 ------------