Deckard's System Scanner v20071014.68
Run by Administrator on 2008-05-25 09:28:00
Computer is in Safe Mode with Networking.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; computer is in safe mode.
-- Last 5 Restore Point(s) --
42: 2008-04-05 02:35:49 UTC - RP566 - Windows Defender Checkpoint
41: 2008-04-05 02:35:49 UTC - RP565 - Windows Defender Checkpoint
40: 2008-04-05 02:35:49 UTC - RP564 - Windows Defender Checkpoint
39: 2008-04-05 02:35:48 UTC - RP563 - Windows Defender Checkpoint
38: 2008-04-05 02:35:48 UTC - RP562 - Restore Operation
-- First Restore Point --
1: 2008-04-05 02:35:37 UTC - RP525 - Removed My Sam's Club Digital Photo Center
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 77% (more than 75%).
Total Physical Memory: 495 MiB (512 MiB recommended).
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-25 09:33:35
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.5730.13)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wmsdkns.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wmsdkns.exe,
O1 - Hosts: 124.217.251.147 google.dk
O1 - Hosts: 124.217.251.147 google.se
O1 - Hosts: 124.217.251.147 google.co.nz
O1 - Hosts: 124.217.251.147 google.cn
O1 - Hosts: 124.217.251.147 google.com.pr
O1 - Hosts: 124.217.251.147 google.com.ca
O1 - Hosts: 124.217.251.147 google.com.ch
O1 - Hosts: 124.217.251.147 google.fi
O1 - Hosts: 124.217.251.147 google.co.in
O1 - Hosts: 124.217.251.147 google.co.uk
O1 - Hosts: 124.217.251.147 google.lv
O1 - Hosts: 124.217.251.147 google.co.hu
O1 - Hosts: 124.217.251.147 google.lk
O1 - Hosts: 124.217.251.147 google.com.au
O1 - Hosts: 124.217.251.147 google.ru
O1 - Hosts: 124.217.251.147 google.nl
O1 - Hosts: 124.217.251.147 google.be
O1 - Hosts: 124.217.251.147 google.de
O1 - Hosts: 124.217.251.147 gogle.de
O1 - Hosts: 124.217.251.147 googel.de
O1 - Hosts: 124.217.251.147 google.ro
O1 - Hosts: 124.217.251.147 google.kz
O1 - Hosts: 124.217.251.147 google.by
O1 - Hosts: 124.217.251.147 google.no
O1 - Hosts: 124.217.251.147 google.pl
O1 - Hosts: 124.217.251.147 google.com.pl
O1 - Hosts: 124.217.251.147 google.es
O1 - Hosts: 124.217.251.147 google.pt
O1 - Hosts: 124.217.251.147 google.com.br
O1 - Hosts: 124.217.251.147 google.vc
O1 - Hosts: 124.217.251.147 google.co.za
O1 - Hosts: 124.217.251.147 google.tm
O1 - Hosts: 124.217.251.147 google.com.my
O1 - Hosts: 124.217.251.147 google.bg
O1 - Hosts: 124.217.251.147 google.co.jp
O1 - Hosts: 124.217.251.147 google.ie
O1 - Hosts: 124.217.251.147 google.co.ck
O1 - Hosts: 124.217.251.147 google.com.mx
O1 - Hosts: 124.217.251.147 google.com.om
O1 - Hosts: 124.217.251.147 google.fr
O1 - Hosts: 124.217.251.147 google.mu
O1 - Hosts: 124.217.251.147 google.com.ph
O1 - Hosts: 124.217.251.147 google.com.jm
O1 - Hosts: 124.217.251.147 google.com
O1 - Hosts: 124.217.251.147 google.us
O1 - Hosts: 124.217.251.147 google.ro
O1 - Hosts: 124.217.251.147 www.google.dk
O1 - Hosts: 124.217.251.147 www.google.se
O1 - Hosts: 124.217.251.147 www.google.co.nz
O1 - Hosts: 124.217.251.147 www.google.cn
O1 - Hosts: 124.217.251.147 www.google.com.pr
O1 - Hosts: 124.217.251.147 www.google.com.ca
O1 - Hosts: 124.217.251.147 www.google.com.ch
O1 - Hosts: 124.217.251.147 www.google.fi
O1 - Hosts: 124.217.251.147 www.google.co.in
O1 - Hosts: 124.217.251.147 www.google.co.uk
O1 - Hosts: 124.217.251.147 www.google.lv
O1 - Hosts: 124.217.251.147 www.google.co.hu
O1 - Hosts: 124.217.251.147 www.google.lk
O1 - Hosts: 124.217.251.147 www.google.com.au
O1 - Hosts: 124.217.251.147 www.google.ru
O1 - Hosts: 124.217.251.147 www.google.nl
O1 - Hosts: 124.217.251.147 www.google.be
O1 - Hosts: 124.217.251.147 www.google.de
O1 - Hosts: 124.217.251.147 www.gogle.de
O1 - Hosts: 124.217.251.147 www.googel.de
O1 - Hosts: 124.217.251.147 www.google.ro
O1 - Hosts: 124.217.251.147 www.google.kz
O1 - Hosts: 124.217.251.147 www.google.by
O1 - Hosts: 124.217.251.147 www.google.no
O1 - Hosts: 124.217.251.147 www.google.pl
O1 - Hosts: 124.217.251.147 www.google.com.pl
O1 - Hosts: 124.217.251.147 www.google.es
O1 - Hosts: 124.217.251.147 www.google.pt
O1 - Hosts: 124.217.251.147 www.google.com.br
O1 - Hosts: 124.217.251.147 www.google.vc
O1 - Hosts: 124.217.251.147 www.google.co.za
O1 - Hosts: 124.217.251.147 www.google.tm
O1 - Hosts: 124.217.251.147 www.google.com.my
O1 - Hosts: 124.217.251.147 www.google.bg
O1 - Hosts: 124.217.251.147 www.google.co.jp
O1 - Hosts: 124.217.251.147 www.google.ie
O1 - Hosts: 124.217.251.147 www.google.co.ck
O1 - Hosts: 124.217.251.147 www.google.com.mx
O1 - Hosts: 124.217.251.147 www.google.com.om
O1 - Hosts: 124.217.251.147 www.google.fr
O1 - Hosts: 124.217.251.147 www.google.mu
O1 - Hosts: 124.217.251.147 www.google.com.ph
O1 - Hosts: 124.217.251.147 www.google.com.jm
O1 - Hosts: 124.217.251.147 www.google.com
O1 - Hosts: 124.217.251.147 www.google.us
O1 - Hosts: 124.217.251.147 www.google.ro
O1 - Hosts: 124.217.251.147 www.video.google.com
O1 - Hosts: 124.217.251.147 www.maps.google.com
O1 - Hosts: 124.217.251.147 www.groups.google.com
O1 - Hosts: 124.217.251.147 www.news.google.com
O1 - Hosts: 124.217.251.147 www.images.google.com
O1 - Hosts: 124.217.251.147 www.earth.google.com
O1 - Hosts: 124.217.251.147 www.code.google.com
O1 - Hosts: 124.217.251.147 www.directory.google.com
O1 - Hosts: 124.217.251.147 www.labs.google.com
O1 - Hosts: 124.217.251.147 www.desktop.google.com
O1 - Hosts: 124.217.251.147 www.blogsearch.google.com
O1 - Hosts: 124.217.251.147 www.books.google.com
O1 - Hosts: 124.217.251.147 www.docs.google.com
O1 - Hosts: 124.217.251.147 www.scholar.google.com
O1 - Hosts: 124.217.251.147 www.pages.google.com
O1 - Hosts: 124.217.251.147 www.finance.google.com
O1 - Hosts: 124.217.251.147 www.pack.google.com
O1 - Hosts: 124.217.251.147 www.sketchup.google.com
O1 - Hosts: 124.217.251.147 www.base.google.com
O1 - Hosts: 124.217.251.147 www.gears.google.com
O1 - Hosts: 124.217.251.147 www.checkout.google.com
O1 - Hosts: 124.217.251.147 www.catalogs.google.com
O1 - Hosts: 124.217.251.147 video.google.com
O1 - Hosts: 124.217.251.147 maps.google.com
O1 - Hosts: 124.217.251.147 groups.google.com
O1 - Hosts: 124.217.251.147 news.google.com
O1 - Hosts: 124.217.251.147 images.google.com
O1 - Hosts: 124.217.251.147 earth.google.com
O1 - Hosts: 124.217.251.147 code.google.com
O1 - Hosts: 124.217.251.147 directory.google.com
O1 - Hosts: 124.217.251.147 labs.google.com
O1 - Hosts: 124.217.251.147 desktop.google.com
O1 - Hosts: 124.217.251.147 blogsearch.google.com
O1 - Hosts: 124.217.251.147 books.google.com
O1 - Hosts: 124.217.251.147 docs.google.com
O1 - Hosts: 124.217.251.147 scholar.google.com
O1 - Hosts: 124.217.251.147 pages.google.com
O1 - Hosts: 124.217.251.147 finance.google.com
O1 - Hosts: 124.217.251.147 pack.google.com
O1 - Hosts: 124.217.251.147 sketchup.google.com
O1 - Hosts: 124.217.251.147 base.google.com
O1 - Hosts: 124.217.251.147 gears.google.com
O1 - Hosts: 124.217.251.147 checkout.google.com
O1 - Hosts: 124.217.251.147 catalogs.google.com
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\yayyvWQj.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {BCD5B47E-73DB-4FBD-A3C3-D77E83D5A515} - C:\WINDOWS\system32\khFwTKca.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [iSecurity applet] rundll32.exe iSecurity.cpl,SecurityMonitor
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [windows defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [wdmon] C:\WINDOWS\wdmon.exe
O4 - HKLM\..\Run: [vlc] C:\WINDOWS\vlc.exe
O4 - HKLM\..\Run: [tomcatstartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [sunjavaupdatesched] "C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe"
O4 - HKLM\..\Run: [statusclient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [soundman] SOUNDMAN.EXE
O4 - HKLM\..\Run: [seekmo] C:\WINDOWS\system32\head2.exe
O4 - HKLM\..\Run: [pinga64] C:\WINDOWS\pinga.exe
O4 - HKLM\..\Run: [phime2002async] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [phime2002a] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [netx] C:\WINDOWS\svx.exe
O4 - HKLM\..\Run: [netw] C:\WINDOWS\svw.exe
O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [msvtt] C:\WINDOWS\system32\gavurjjf.exe
O4 - HKLM\..\Run: [mspy2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [imjpmig8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hphupd06] C:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [hphmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [hpdj taskbar utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [hp component manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccapp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - HKLM\..\Run: [a4f165dc] rundll32.exe "C:\WINDOWS\system32\vawpvkfq.dll",b
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [KB926239] rundll32.exe apphelp.dll,ShimFlushCache
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4538] command /c del "C:\WINDOWS\system32\inugljji.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4583] cmd /c del "C:\WINDOWS\system32\inugljji.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA824] command /c del "C:\WINDOWS\system32\jgaavxfe.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2619] cmd /c del "C:\WINDOWS\system32\jgaavxfe.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB8780] command /c del "C:\WINDOWS\system32\wind32.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3959] cmd /c del "C:\WINDOWS\system32\wind32.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4557] command /c del "C:\WINDOWS\system32\cimothqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6875] cmd /c del "C:\WINDOWS\system32\cimothqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1740] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4526] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8737] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5055] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1227] command /c del "C:\WINDOWS\system32\cimothqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9728] cmd /c del "C:\WINDOWS\system32\cimothqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9045] command /c del "C:\WINDOWS\system32\frrycmjm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4047] cmd /c del "C:\WINDOWS\system32\frrycmjm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6912] command /c del "C:\WINDOWS\system32\qkgeygvo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2679] cmd /c del "C:\WINDOWS\system32\qkgeygvo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4946] command /c del "C:\WINDOWS\system32\ssqRLDVO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3684] cmd /c del "C:\WINDOWS\system32\ssqRLDVO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8858] command /c del "C:\Program Files\Helper\1207886533.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6439] cmd /c del "C:\Program Files\Helper\1207886533.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9086] command /c del "C:\WINDOWS\system32\efcBtutr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1138] cmd /c del "C:\WINDOWS\system32\efcBtutr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3593] command /c del "C:\WINDOWS\system32\bumpeohj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6012] cmd /c del "C:\WINDOWS\system32\bumpeohj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2114] command /c del "C:\WINDOWS\system32\efcBtutr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3927] cmd /c del "C:\WINDOWS\system32\efcBtutr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3664] command /c del "C:\WINDOWS\system32\yaYPJyAr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6423] cmd /c del "C:\WINDOWS\system32\yaYPJyAr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5274] command /c del "C:\WINDOWS\system32\geBRLDvS.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD604] cmd /c del "C:\WINDOWS\system32\geBRLDvS.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9050] command /c del "C:\WINDOWS\system32\hexcrjcq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4073] cmd /c del "C:\WINDOWS\system32\hexcrjcq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2223] command /c del "C:\WINDOWS\system32\ixuliuim.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6384] cmd /c del "C:\WINDOWS\system32\ixuliuim.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1570] command /c del "C:\WINDOWS\system32\geBRLDvS.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7231] cmd /c del "C:\WINDOWS\system32\geBRLDvS.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1021] command /c del "C:\WINDOWS\system32\hexcrjcq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9529] cmd /c del "C:\WINDOWS\system32\hexcrjcq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6004] command /c del "C:\WINDOWS\system32\ixuliuim.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2422] cmd /c del "C:\WINDOWS\system32\ixuliuim.dll_old"
O4 - HKLM\..\Policies\Explorer\Run: [jWeeDUr0Kf] C:\Documents and Settings\All Users\Application Data\mdqbivaz\sdkjwnqj.exe
O4 - HKUS\S-1-5-18\..\Run: [xicwzfyr] C:\WINDOWS\system32\gjivmxqd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [xicwzfyr] C:\WINDOWS\system32\gjivmxqd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_12) - http://java.sun.com/...indows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.ma...ash/swflash.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{B1CDF7E2-2888-4685-A4E0-0DC513BCEDD4}: NameServer = 85.255.115.27,85.255.112.202
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.202
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.202
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.27 85.255.112.202
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O20 - AppInit_DLLs: iSecurity.cpl
O21 - SSODL: iSecurity - {A8311E8F-E459-4D22-89B4-CB9DCF10A425} - (no file)
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
O22 - SharedTaskScheduler: COM+ Service - {3C49DDAC-3DA4-4743-AF6C-5974FEAF875C} - C:\WINDOWS\system32\winload.dll
O22 - SharedTaskScheduler: Hjkfj93dffd - {B5AF0562-94F3-42BD-F434-2604812C797D} - (no file)
O22 - SharedTaskScheduler: exegeses - {db763ed8-100a-481b-8913-50a2f41dcdc3} - (no file)
O23 - Service: apple mobile device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: bonjour service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: caevtsvc - Unknown owner - C:\WINDOWS\system32\CaEvtSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: cxevtsvc - Unknown owner - C:\WINDOWS\system32\CxEvtSvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DHCP Client Dhcpmnmsrvc (dhcpmnmsrvc) - Unknown owner - C:\WINDOWS\system32\3076qc.exe
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityRasAuto (fastuserswitchingcompatibilityrasauto) - Unknown owner - C:\WINDOWS\system32\3com_dmil.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\HPBOID.EXE
O23 - Service: iPod Service (ipodservice) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LPTRDC server (lptrdcsrv) - Unknown owner - C:\WINDOWS\ctfmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Routing and Remote Access RemoteAccessNetman (remoteaccessnetman) - Unknown owner - C:\WINDOWS\system32\2052r.exe
O23 - Service: Remote Procedure Call (RPC) Locator RpcLocatorWebClient (rpclocatorwebclient) - Unknown owner - C:\WINDOWS\system32\acleditc.exe
O23 - Service: SavRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Performance Logs and Alerts SysmonLog AntiVirus (sysmonlog antivirus) - Unknown owner - C:\WINDOWS\system32\adsnwu.exe
O23 - Service: Viewpoint Manager Service ViewpointHidServ (viewpointhidserv) - Unknown owner - C:\WINDOWS\system32\Adobev.exe
O23 - Service: WebClient WebClientLmHosts (webclientlmhosts) - Unknown owner - C:\WINDOWS\system32\fasd522.exe srv
O23 - Service: Security Center wscsvcNetman (wscsvcnetman) - Unknown owner - C:\WINDOWS\system32\3076q.exe
O23 - Service: Security Center wscsvcNetman wscsvcnetmanSavRoam (wscsvcnetmansavroam) - Unknown owner - C:\WINDOWS\system32\acelpdeck.exe
--
End of file - 21986 bytes
-- File Associations -----------------------------------------------------------
.bat - batfile - shell\edit\command - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - inifile - shell\open\command - %SystemRoot%\System32\NOTEPAD.EXE %1"
.pif - piffile - shell\open\command - "%1" %*"
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 afu01 - c:\windows\system32\drivers\afu01.sys (file missing)
S0 bix33 - c:\windows\system32\drivers\bix33.sys (file missing)
S0 Bkc28 - c:\windows\system32\drivers\bkc28.sys (file missing)
S0 Bld42 - c:\windows\system32\drivers\bld42.sys (file missing)
S0 Cac57 - c:\windows\system32\drivers\cac57.sys (file missing)
S0 cha82 - c:\windows\system32\drivers\cha82.sys (file missing)
S0 chh66 - c:\windows\system32\drivers\chh66.sys (file missing)
S0 crr15 - c:\windows\system32\drivers\crr15.sys (file missing)
S0 cuk43 - c:\windows\system32\drivers\cuk43.sys (file missing)
S0 dgq44 - c:\windows\system32\drivers\dgq44.sys (file missing)
S0 din53 - c:\windows\system32\drivers\din53.sys (file missing)
S0 dlb44 - c:\windows\system32\drivers\dlb44.sys (file missing)
S0 Dxi88 - c:\windows\system32\drivers\dxi88.sys (file missing)
S0 ebt55 - c:\windows\system32\drivers\ebt55.sys (file missing)
S0 ecj34 - c:\windows\system32\drivers\ecj34.sys (file missing)
S0 ecy56 - c:\windows\system32\drivers\ecy56.sys (file missing)
S0 Eej34 - c:\windows\system32\drivers\eej34.sys (file missing)
S0 Eer81 - c:\windows\system32\drivers\eer81.sys (file missing)
S0 ert64 - c:\windows\system32\drivers\ert64.sys (file missing)
S0 Ery52 - c:\windows\system32\drivers\ery52.sys (file missing)
S0 eyl10 - c:\windows\system32\drivers\eyl10.sys (file missing)
S0 fad71 - c:\windows\system32\drivers\fad71.sys (file missing)
S0 fif11 - c:\windows\system32\drivers\fif11.sys (file missing)
S0 Fsf74 - c:\windows\system32\drivers\fsf74.sys (file missing)
S0 gak23 - c:\windows\system32\drivers\gak23.sys (file missing)
S0 gqq84 - c:\windows\system32\drivers\gqq84.sys (file missing)
S0 hco45 - c:\windows\system32\drivers\hco45.sys (file missing)
S0 hrp56 - c:\windows\system32\drivers\hrp56.sys (file missing)
S0 Hrr45 - c:\windows\system32\drivers\hrr45.sys (file missing)
S0 Ikn83 - c:\windows\system32\drivers\ikn83.sys (file missing)
S0 iku51 - c:\windows\system32\drivers\iku51.sys (file missing)
S0 ini60 - c:\windows\system32\drivers\ini60.sys (file missing)
S0 ivv36 - c:\windows\system32\drivers\ivv36.sys (file missing)
S0 Ixl33 - c:\windows\system32\drivers\ixl33.sys (file missing)
S0 jnl16 - c:\windows\system32\drivers\jnl16.sys (file missing)
S0 jqg33 - c:\windows\system32\drivers\jqg33.sys (file missing)
S0 Kap44 - c:\windows\system32\drivers\kap44.sys (file missing)
S0 kfi45 - c:\windows\system32\drivers\kfi45.sys (file missing)
S0 koy11 - c:\windows\system32\drivers\koy11.sys (file missing)
S0 lgg14 - c:\windows\system32\drivers\lgg14.sys (file missing)
S0 lls71 - c:\windows\system32\drivers\lls71.sys (file missing)
S0 lov36 - c:\windows\system32\drivers\lov36.sys (file missing)
S0 Lsl82 - c:\windows\system32\drivers\lsl82.sys (file missing)
S0 lve82 - c:\windows\system32\drivers\lve82.sys (file missing)
S0 map13 - c:\windows\system32\drivers\map13.sys (file missing)
S0 mcm75 - c:\windows\system32\drivers\mcm75.sys (file missing)
S0 mka67 - c:\windows\system32\drivers\mka67.sys (file missing)
S0 mmh67 - c:\windows\system32\drivers\mmh67.sys (file missing)
S0 moe76 - c:\windows\system32\drivers\moe76.sys (file missing)
S0 mrc66 - c:\windows\system32\drivers\mrc66.sys (file missing)
S0 Nix36 - c:\windows\system32\drivers\nix36.sys (file missing)
S0 nnd65 - c:\windows\system32\drivers\nnd65.sys (file missing)
S0 nsl36 - c:\windows\system32\drivers\nsl36.sys (file missing)
S0 nxp03 - c:\windows\system32\drivers\nxp03.sys (file missing)
S0 Oer20 - c:\windows\system32\drivers\oer20.sys (file missing)
S0 Oot10 - c:\windows\system32\drivers\oot10.sys (file missing)
S0 paa58 - c:\windows\system32\drivers\paa58.sys (file missing)
S0 pfa22 - c:\windows\system32\drivers\pfa22.sys (file missing)
S0 phk38 - c:\windows\system32\drivers\phk38.sys (file missing)
S0 pkw66 - c:\windows\system32\drivers\pkw66.sys (file missing)
S0 prk85 - c:\windows\system32\drivers\prk85.sys (file missing)
S0 qis34 - c:\windows\system32\drivers\qis34.sys (file missing)
S0 rrp34 - c:\windows\system32\drivers\rrp34.sys (file missing)
S0 Rry82 - c:\windows\system32\drivers\rry82.sys (file missing)
S0 sap13 - c:\windows\system32\drivers\sap13.sys (file missing)
S0 sgi68 - c:\windows\system32\drivers\sgi68.sys (file missing)
S0 sik21 - c:\windows\system32\drivers\sik21.sys (file missing)
S0 snb04 - c:\windows\system32\drivers\snb04.sys (file missing)
S0 tmc36 - c:\windows\system32\drivers\tmc36.sys (file missing)
S0 toe18 - c:\windows\system32\drivers\toe18.sys (file missing)
S0 Ttq24 - c:\windows\system32\drivers\ttq24.sys (file missing)
S0 Ttw67 - c:\windows\system32\drivers\ttw67.sys (file missing)
S0 twh44 - c:\windows\system32\drivers\twh44.sys (file missing)
S0 urr25 - c:\windows\system32\drivers\urr25.sys (file missing)
S0 uxx88 - c:\windows\system32\drivers\uxx88.sys (file missing)
S0 vds85 - c:\windows\system32\drivers\vds85.sys (file missing)
S0 veg17 - c:\windows\system32\drivers\veg17.sys (file missing)
S0 vel85 - c:\windows\system32\drivers\vel85.sys (file missing)
S0 vin55 - c:\windows\system32\drivers\vin55.sys (file missing)
S0 vly25 - c:\windows\system32\drivers\vly25.sys (file missing)
S0 vnn58 - c:\windows\system32\drivers\vnn58.sys (file missing)
S0 Vot33 - c:\windows\system32\drivers\vot33.sys (file missing)
S0 vyv27 - c:\windows\system32\drivers\vyv27.sys (file missing)
S0 wac47 - c:\windows\system32\drivers\wac47.sys (file missing)
S0 waw84 - c:\windows\system32\drivers\waw84.sys (file missing)
S0 wcf18 - c:\windows\system32\drivers\wcf18.sys (file missing)
S0 Wfr75 - c:\windows\system32\drivers\wfr75.sys (file missing)
S0 wkv74 - c:\windows\system32\drivers\wkv74.sys (file missing)
S0 Wmr74 - c:\windows\system32\drivers\wmr74.sys (file missing)
S0 wwh06 - c:\windows\system32\drivers\wwh06.sys (file missing)
S0 wwo72 - c:\windows\system32\drivers\wwo72.sys (file missing)
S0 wyr22 - c:\windows\system32\drivers\wyr22.sys (file missing)
S0 Xds11 - c:\windows\system32\drivers\xds11.sys (file missing)
S0 Xis31 - c:\windows\system32\drivers\xis31.sys (file missing)
S0 xnq33 - c:\windows\system32\drivers\xnq33.sys (file missing)
S0 xxq30 - c:\windows\system32\drivers\xxq30.sys (file missing)
S0 Yel55 - c:\windows\system32\drivers\yel55.sys (file missing)
S0 yev58 - c:\windows\system32\drivers\yev58.sys (file missing)
S0 You41 - c:\windows\system32\drivers\you41.sys (file missing)
S0 yyj86 - c:\windows\system32\drivers\yyj86.sys (file missing)
S1 itcoe (itcoe adapter) - c:\windows\system32\itcoe.sys
S1 nqaplwj - c:\windows\nqaplwj.sys
S1 ydhqzop - c:\windows\ydhqzop.sys
S1 zeqbqwp - c:\windows\zeqbqwp.sys
S2 grande48 - c:\windows\system32\drivers\grande48.sys (file missing)
S2 npkcrypt - c:\nexon\maplestory\npkcrypt.sys (file missing)
S3 apf47 - c:\windows\system32\drivers\apf47.sys (file missing)
S3 Arf25 - c:\windows\system32\drivers\arf25.sys (file missing)
S3 Asushwio - c:\windows\system32\drivers\asushwio.sys
S3 Blv44 - c:\windows\system32\drivers\blv44.sys (file missing)
S3 Bxn61 - c:\windows\system32\drivers\bxn61.sys
S3 byj66 - c:\windows\system32\drivers\byj66.sys (file missing)
S3 Chu74 - c:\windows\system32\drivers\chu74.sys (file missing)
S3 eraserutildrv10741 - c:\program files\common files\symantec shared\eengine\eraserutildrv10741.sys (file missing)
S3 eraserutilrebootdrv - c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys (file missing)
S3 Eyh44 - c:\windows\system32\drivers\eyh44.sys (file missing)
S3 Ffw41 - c:\windows\system32\drivers\ffw41.sys (file missing)
S3 Hcp13 - c:\windows\system32\drivers\hcp13.sys (file missing)
S3 Jog17 - c:\windows\system32\drivers\jog17.sys (file missing)
S3 liq00 - c:\windows\system32\drivers\liq00.sys (file missing)
S3 lsv86 - c:\windows\system32\drivers\lsv86.sys (file missing)
S3 npa41 - c:\windows\system32\drivers\npa41.sys (file missing)
S3 Uac22 - c:\windows\system32\drivers\uac22.sys (file missing)
S3 Vsb40 - c:\windows\system32\drivers\vsb40.sys (file missing)
S3 Xau46 - c:\windows\system32\drivers\xau46.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 apple mobile device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
S2 bonjour service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S2 caevtsvc - c:\windows\system32\caevtsvc.exe -k netsvcs
S2 cxevtsvc - c:\windows\system32\cxevtsvc.exe -k netsvcs
S2 dhcpmnmsrvc (DHCP Client Dhcpmnmsrvc) - c:\windows\system32\3076qc.exe srv
S2 fastuserswitchingcompatibilityrasauto (Fast User Switching Compatibility FastUserSwitchingCompatibilityRasAuto) - c:\windows\system32\3com_dmil.exe srv
S2 lptrdcsrv (LPTRDC server) - c:\windows\ctfmon.exe
S2 remoteaccessnetman (Routing and Remote Access RemoteAccessNetman) - c:\windows\system32\2052r.exe srv
S2 rpclocatorwebclient (Remote Procedure Call (RPC) Locator RpcLocatorWebClient) - c:\windows\system32\acleditc.exe srv
S2 sysmonlog antivirus (Performance Logs and Alerts SysmonLog AntiVirus) - c:\windows\system32\adsnwu.exe srv
S2 viewpointhidserv (Viewpoint Manager Service ViewpointHidServ) - c:\windows\system32\adobev.exe srv
S2 webclientlmhosts (WebClient WebClientLmHosts) - c:\windows\system32\fasd522.exe srv (file missing)
S2 wscsvcnetman (Security Center wscsvcNetman) - c:\windows\system32\3076q.exe srv
S2 wscsvcnetmansavroam (Security Center wscsvcNetman wscsvcnetmanSavRoam) - c:\windows\system32\acelpdeck.exe srv
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-25 09:11:50 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-04-06 01:30:00 508 --a------ C:\WINDOWS\Tasks\WebReg 20080406003000.job
2008-04-06 01:28:27 368 --a------ C:\WINDOWS\Tasks\HP Usg Daily FY04.job
2008-03-28 00:36:59 508 --a------ C:\WINDOWS\Tasks\WebReg 20080327233659.job
2008-03-26 18:44:24 508 --a------ C:\WINDOWS\Tasks\WebReg 20080326174422.job
-- Files created between 2008-04-25 and 2008-05-25 -----------------------------
2008-05-24 21:36:24 5824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-05-24 09:41:51 8704 --a------ C:\WINDOWS\2020search.dll
2008-05-24 09:41:50 15104 --a------ C:\WINDOWS\updatetc.exe
2008-05-24 08:07:44 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-24 08:06:08 0 d-------- C:\Program Files\Spyware Doctor
2008-05-24 08:06:08 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-05-24 07:54:49 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-17 18:50:06 0 d-------- C:\Program Files\iTunes
2008-05-17 18:28:23 0 d-------- C:\Program Files\Bonjour
2008-05-17 18:00:27 0 d-------- C:\Program Files\Apple Software Update
2008-05-17 17:58:49 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-17 17:51:41 0 d-------- C:\Program Files\Common Files\Apple
2008-05-17 17:51:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-12 15:09:14 41984 -r-hs---- C:\WINDOWS\system32\acelpdeck.exe
2008-05-10 17:37:54 28672 --a------ C:\WINDOWS\2020search2.dll
2008-05-10 17:37:53 32512 --a------ C:\WINDOWS\system32\MSIXU.DLL
2008-05-10 12:20:19 0 d-------- C:\Program Files\Advanced Spyware Remover
2008-05-10 06:31:29 3499695 --ahs---- C:\WINDOWS\system32\a3det.sys
2008-05-06 18:06:20 41984 -r-hs---- C:\WINDOWS\system32\3076qc.exe
2008-05-05 16:40:32 0 d-------- C:\Program Files\Error Expert
2008-05-03 12:25:06 37888 -r-hs---- C:\WINDOWS\system32\2052r.exe
2008-04-29 15:08:05 37888 -r-hs---- C:\WINDOWS\system32\Adobev.exe
2008-04-27 20:04:51 0 d-------- C:\Program Files\180search assistant
2008-04-27 20:04:50 0 d-------- C:\Program Files\180solutions
2008-04-27 20:04:50 0 d-------- C:\Program Files\180searchassistant
2008-04-27 19:23:36 7 --a------ C:\WINDOWS\system32\ngxt.bin
2008-04-27 19:15:39 0 d-------- C:\6fc469863b6d6b9e6bfdcbc7b1d854f1
2008-04-27 19:01:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-27 19:01:33 0 d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2008-04-27 19:01:15 0 d-------- C:\Program Files\Yahoo!
2008-04-27 19:01:14 0 d--h----- C:\WINDOWS\msdownld.tmp
2008-04-27 18:52:22 0 d-------- C:\WINDOWS\LastGood
2008-04-27 18:51:39 94784 --a------ C:\WINDOWS\system32\vawpvkfq.dll
2008-04-27 18:50:47 514822 --ahs---- C:\WINDOWS\system32\acKTwFhk.ini2
2008-04-27 18:50:36 281600 -----n--- C:\WINDOWS\system32\khFwTKca.dll
2008-04-27 15:35:10 335 --a------ C:\WINDOWS\mozregistry.dat
2008-04-27 15:28:58 94784 --a------ C:\WINDOWS\system32\mwqidrpt.dll
2008-04-27 15:12:31 105024 --a------ C:\WINDOWS\system32\rthlmbon.dll
2008-04-27 14:47:02 5120 --a------ C:\WINDOWS\system32\fasd575.exe
2008-04-27 14:46:56 7680 --a------ C:\WINDOWS\system32\fasd574.exe
2008-04-27 14:46:54 29136 --a------ C:\WINDOWS\system32\fasd576.exe
2008-04-27 14:46:53 233984 --a------ C:\WINDOWS\system32\fasd573.exe
2008-04-26 11:43:43 107072 --a------ C:\WINDOWS\system32\oykoedtj.dll
2008-04-26 11:40:40 525518 --ahs---- C:\WINDOWS\system32\bcbKQXyb.ini2
2008-04-26 10:19:10 9216 --a------ C:\WINDOWS\stcloader.exe
2008-04-26 10:19:10 0 d-------- C:\Program Files\seekmo
2008-04-26 10:19:08 0 d-------- C:\Program Files\zango
2008-04-26 10:19:05 0 d-------- C:\WINDOWS\FLEOK
2008-04-26 07:19:40 0 --a------ C:\WINDOWS\system32\k86.bin
2008-04-26 07:17:45 8816 --a------ C:\WINDOWS\system32\drivers\Ahf81.sys
2008-04-25 16:11:47 10240 --a------ C:\WINDOWS\system32\fasd570.exe
2008-04-25 16:11:34 79872 --a------ C:\WINDOWS\system32\fasd449.exe
2008-04-25 16:11:31 28672 --a------ C:\WINDOWS\system32\fasd564.exe
-- Find3M Report ---------------------------------------------------------------
2008-05-25 09:09:43 12246 --a------ C:\WINDOWS\system32\mt_32.dll
2008-05-24 21:40:21 229376 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-05-24 08:25:47 2560 --a------ C:\WINDOWS\system32\itcoe.sys
2008-05-18 14:47:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-05-17 18:48:07 0 d-------- C:\Program Files\iPod
2008-05-17 18:17:21 0 d-------- C:\Program Files\QuickTime
2008-05-17 17:51:41 0 d-------- C:\Program Files\Common Files
2008-05-16 11:04:18 2024 --a------ C:\WINDOWS\mozver.dat
2008-05-16 10:53:48 0 d-------- C:\Program Files\WINForms Desktop
2008-05-12 15:09:19 32 --a-s---- C:\WINDOWS\system32\494392728.dat
2008-05-11 09:20:49 0 d-------- C:\Program Files\Alwil Software
2008-05-11 00:13:51 5120 --a------ C:\WINDOWS\system32\ftp33.dll
2008-05-11 00:09:40 834 --a------ C:\WINDOWS\system32\a15k.sys
2008-05-10 12:37:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-10 06:31:00 563 --a-s---- C:\WINDOWS\system32\3127182004.dat
2008-04-27 19:16:54 45568 --a------ C:\WINDOWS\system32\fasd563.exe
2008-04-27 16:29:52 4380 --a------ C:\WINDOWS\system32\fasd532.exe
2008-04-26 11:29:08 516094 --ahs---- C:\WINDOWS\system32\SvDLRBeg.ini2
2008-04-24 15:00:36 37888 -rahs---- C:\WINDOWS\system32\acleditc.exe
2008-04-24 14:48:21 34816 --a------ C:\WINDOWS\system32\head2.exe
2008-04-23 18:29:03 0 d-------- C:\Program Files\Helper
2008-04-23 17:57:17 21504 --ahs---- C:\WINDOWS\system32\3076qy.dll
2008-04-23 17:57:15 16384 --ahs---- C:\WINDOWS\system32\6to4svcr.dll
2008-04-23 17:57:09 23552 --ahs---- C:\WINDOWS\system32\activedsio.dll
2008-04-23 17:45:55 444416 --a------ C:\autoex.dll
2008-04-23 17:45:54 233984 --a------ C:\WINDOWS\system32\fasd556.exe
2008-04-23 17:45:46 83471 --a------ C:\WINDOWS\system32\fasd541.exe
2008-04-23 17:45:39 37376 --a------ C:\WINDOWS\system32\qoMdeBrp.dll
2008-04-23 17:45:36 8704 --a------ C:\WINDOWS\system32\fasd559.exe
2008-04-23 17:45:32 32 --a------ C:\smp.bat
2008-04-23 17:45:29 11776 --a------ C:\d.exe
2008-04-23 17:45:25 2 --a------ C:\-1527683725
2008-04-23 17:45:15 61874 --a------ C:\WINDOWS\ydhqzop.sys
2008-04-23 17:45:07 577024 --a------ C:\WINDOWS\system32\user32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-23 17:45:06 201216 --a------ C:\WINDOWS\system32\nvrsma.dll
2008-04-23 17:45:03 87040 --a------ C:\WINDOWS\system32\ntpl.bin
2008-04-23 17:45:03 87040 --a------ C:\ktgmhs.exe
2008-04-23 17:45:01 65536 --a------ C:\wxebxbo.exe
2008-04-23 17:44:59 13824 --a------ C:\rwhucv.exe
2008-04-23 17:44:58 29136 --a------ C:\WINDOWS\system32\fasd558.exe
2008-04-22 21:49:58 423729 --ahs---- C:\WINDOWS\system32\hQpqrXyb.ini2
2008-04-22 19:22:25 143080 --a------ C:\WINDOWS\system32\fasd469.exe
2008-04-22 19:09:54 37376 --a------ C:\WINDOWS\system32\qoMeEWmL.dll
2008-04-22 19:08:53 67506 --a------ C:\WINDOWS\fkjdfje.sys
2008-04-22 19:08:44 61952 --a------ C:\WINDOWS\system32\gavurjjf.exe
2008-04-22 19:08:44 61952 --a------ C:\gavurjjf.exe
2008-04-22 19:08:41 71168 --a------ C:\lilsesn.exe
2008-04-22 19:08:34 13824 --a------ C:\gjtxc.exe
2008-04-22 19:08:11 24576 --a------ C:\WINDOWS\system32\userinit.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-22 19:08:03 160256 --a------ C:\WINDOWS\system32\blackster.scr <Not Verified; Peter's Productions; Bugs!>
2008-04-22 19:07:55 268660 --a------ C:\WINDOWS\system32\fasd550.exe
2008-04-22 14:54:53 37888 --a------ C:\WINDOWS\system32\fasd555.exe
2008-04-22 03:06:48 90112 --a------ C:\WINDOWS\wxvgsdbq.exe
2008-04-22 03:06:48 184320 --a------ C:\WINDOWS\dpevflbg.dll
2008-04-22 03:06:44 282624 --a------ C:\WINDOWS\qnmargolqgp.dll
2008-04-22 03:06:42 98304 --a------ C:\WINDOWS\olgdqarf.exe
2008-04-21 15:06:21 48585 --a------ C:\WINDOWS\system32\activedsi.sys
2008-04-21 15:06:18 23040 --ahs---- C:\WINDOWS\system32\adsmsexti.dll
2008-04-21 14:53:42 11776 --a------ C:\WINDOWS\system32\fasd251.exe
2008-04-21 14:53:34 257180 --a------ C:\WINDOWS\system32\fasd549.exe
2008-04-20 22:50:16 32768 --a------ C:\pagefile.dll <Not Verified; ; SunJavaBHO Module>
2008-04-20 22:50:12 1024 --a------ C:\WINDOWS\system32\fasd545.exe
2008-04-20 16:08:55 0 d-------- C:\Program Files\FBrowserAdvisor
2008-04-20 11:36:01 37888 -rahs---- C:\WINDOWS\system32\3com_dmil.exe
2008-04-20 11:33:05 132096 --a------ C:\WINDOWS\system32\CxEvtSvc.exe
2008-04-20 11:23:53 11776 --a------ C:\WINDOWS\system32\fasd544.exe
2008-04-18 18:53:25 22016 --ahs---- C:\WINDOWS\system32\adsldpw.dll
2008-04-18 18:51:53 41984 -rahs---- C:\WINDOWS\system32\adsnwu.exe
2008-04-18 18:49:30 109568 --a------ C:\WINDOWS\system32\CaEvtSvc.exe
2008-04-18 18:39:05 5120 --a------ C:\WINDOWS\system32\fasd540.exe
2008-04-18 07:12:13 319439 --ahs---- C:\WINDOWS\system32\dMlVyyay.ini2
2008-04-16 15:17:46 132096 --a------ C:\WINDOWS\kavir.exe
2008-04-16 15:16:56 10752 --a------ C:\WINDOWS\system32\fasd534.exe
2008-04-16 15:16:47 12800 --a------ C:\WINDOWS\system32\fasd529.exe
2008-04-16 12:08:27 4096 --a------ C:\WINDOWS\system32winlogonpc.exe
2008-04-16 12:08:26 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-04-16 12:08:26 4096 --a------ C:\WINDOWS\system32mwin32.exe
2008-04-16 12:08:26 4096 --a------ C:\WINDOWS\system32hoproxy.dll
2008-04-16 12:08:26 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-04-16 12:08:26 4096 --a------ C:\WINDOWS\a.bat
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32taack.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32taack.dat
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32sncntr.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32psoft1.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32psof1.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32ps1.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32hxiwlgpm.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe
2008-04-16 12:08:25 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32temp#01.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32ssvchost.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32ssurf022.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32regm64.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32regc64.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32netode.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32mtr2.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32msnbho.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32msgp.exe
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32medup020.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32medup012.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll
2008-04-16 12:08:24 4096 --a------ C:\WINDOWS\system32dpcproxy.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\winsystem.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32vcatchpi.dll
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32thun32.dll
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32thun.dll
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32Rundl1.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32newsd32.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32msvchost.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32emesx.dll
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32anticipator.dll
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\system32akttzn.exe
2008-04-16 12:08:23 4096 --a------ C:\WINDOWS\mssecu.exe
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32WINWGPX.EXE
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32winsystem.exe
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32vbsys2.dll
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32sysreq.exe
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32mssecu.exe
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32bdn.com
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\system32awtoolb.dll
2008-04-16 12:08:22 4096 --a------ C:\WINDOWS\bdn.com
2008-04-16 12:08:08 94208 --a------ C:\WINDOWS\system32\gjivmxqd.exe
2008-04-16 12:07:57 36352 --a------ C:\WINDOWS\system32\oPijhHaY.dll
2008-04-16 12:07:34 346112 --a------ C:\WINDOWS\system32\efcywuu.dll
2008-04-16 12:06:42 37376 --a------ C:\WINDOWS\system32\yayyvWQj.dll
2008-04-16 12:05:55 55218 --a------ C:\WINDOWS\qaszpurn.sys
2008-04-16 12:05:27 233984 --a------ C:\WINDOWS\system32\fasd527.exe
2008-04-16 12:05:20 25040 --a------ C:\WINDOWS\system32\fasd531.exe
2008-04-15 23:45:25 4380 --a------ C:\WINDOWS\system32\fasd491.exe
2008-04-13 14:07:54 12288 --a------ C:\WINDOWS\system32\fasd525.exe
2008-04-13 14:07:51 10000 --a------ C:\WINDOWS\system32\djki397g.dll
2008-04-13 14:07:48 10000 --a------ C:\WINDOWS\system32\hdxjd4g.dll
2008-04-13 13:28:56 22016 --ahs---- C:\WINDOWS\system32\a3de.dll
2008-04-13 13:27:28 41984 -rahs---- C:\WINDOWS\system32\3076q.exe
2008-04-13 13:14:02 11264 --a------ C:\WINDOWS\system32\fasd436.exe
2008-04-12 14:01:43 14849 --a------ C:\WINDOWS\system32\sysmgr.exe
2008-04-12 13:12:14 102456 --a------ C:\WINDOWS\system32\msvcrt2.dll
2008-04-11 23:32:40 322202 --ahs---- C:\WINDOWS\system32\rAyJPYay.ini2
2008-04-11 11:40:15 22016 --ahs---- C:\WINDOWS\system32\aaaamons.dll
2008-04-11 11:39:14 233984 --a------ C:\WINDOWS\system32\fasd517.exe
2008-04-11 11:39:04 7680 --a------ C:\WINDOWS\system32\fasd521.exe
2008-04-11 11:38:46 20944 --a------ C:\WINDOWS\system32\fasd518.exe
2008-04-11 11:38:45 37376 --a------ C:\WINDOWS\system32\pmnMccCv.dll
2008-04-11 11:38:36 14848 --a------ C:\WINDOWS\system32\fasd523.exe <Not Verified; Microsoft Corporation; Microsoft>
2008-04-11 11:32:02 3648 --a------ C:\WINDOWS\system32\rwnyslqt.dll
2008-04-11 08:37:58 212992 --a------ C:\WINDOWS\temlxopqgdk.dll
2008-04-11 08:37:54 172032 --a------ C:\WINDOWS\qdnkewfa.dll
2008-04-11 08:37:54 217088 --a------ C:\WINDOWS\mgsvflkw.dll
2008-04-11 01:29:24 407004 --ahs---- C:\WINDOWS\system32\rtutBcfe.ini2
2008-04-10 21:40:00 3648 --a------ C:\WINDOWS\system32\husnvmvp.dll
2008-04-10 21:30:04 23040 --a------ C:\WINDOWS\swin32.dll
2008-04-10 20:59:56 37376 --a------ C:\WINDOWS\system32\iifcBuuU.dll
2008-04-10 20:59:51 55218 --a------ C:\WINDOWS\zeqbqwp.sys
2008-04-10 20:59:46 25088 --a------ C:\WINDOWS\gavurjjf.exe
2008-04-10 20:59:08 235397 --a------ C:\WINDOWS\system32\fasd487.exe
2008-04-10 20:57:55 360619 --ahs---- C:\WINDOWS\system32\OVDLRqss.ini2
2008-04-10 20:40:06 3648 --a------ C:\WINDOWS\system32\mgjctndo.dll
2008-04-09 20:21:53 25600 --a------ C:\WINDOWS\system32\fasd512.exe
2008-04-09 15:46:35 32512 --a------ C:\WINDOWS\cdsm32.dll
2008-04-09 15:46:33 14336 --a------ C:\WINDOWS\mssvr.exe
2008-04-09 15:46:33 9216 --a------ C:\WINDOWS\bjam.dll
2008-04-09 13:47:19 32000 --a------ C:\WINDOWS\voiceip.dll
2008-04-09 13:47:15 28416 --a------ C:\WINDOWS\180ax.exe
2008-04-09 13:47:14 10496 --a------ C:\WINDOWS\salm.exe
2008-04-09 12:55:34 3648 --a------ C:\WINDOWS\system32\mcndfomr.dll
2008-04-09 12:05:12 44544 --a------ C:\WINDOWS\system32\fasd513.exe
2008-04-07 20:43:27 0 d-------- C:\Program Files\stc
2008-04-07 20:43:25 31488 --a------ C:\WINDOWS\bokja.exe
2008-04-07 20:43:23 19968 --a------ C:\WINDOWS\mspphe.dll
2008-04-07 20:43:11 31744 --a------ C:\WINDOWS\system32\WER8274.DLL
2008-04-07 20:42:55 9216 --a------ C:\WINDOWS\saiemod.dll
2008-04-07 20:42:54 23296 --a------ C:\WINDOWS\system32\MSNSA32.dll
2008-04-07 20:42:51 22016 --a------ C:\WINDOWS\msapasrc.dll
2008-04-07 20:42:50 20480 --a------ C:\WINDOWS\msa64chk.dll
2008-04-07 20:42:48 24320 --a------ C:\WINDOWS\system32\SIPSPI32.dll
2008-04-07 20:42:46 24576 --a------ C:\WINDOWS\system32\shdocpe.dll
2008-04-07 20:42:45 23040 --a------ C:\WINDOWS\system32\ntnut32.exe
2008-04-07 20:42:43 15616 --a------ C:\WINDOWS\shdocpl.dll
2008-04-07 20:42:43 17920 --a------ C:\WINDOWS\ntnut.exe
2008-04-07 20:42:42 13056 --a------ C:\WINDOWS\shdocpe.dll
2008-04-07 20:42:40 30208 --a------ C:\WINDOWS\winsb.dll
2008-04-07 20:42:40 0 d-------- C:\Program Files\Sysmnt
2008-04-07 20:42:38 13568 --a------ C:\WINDOWS\browserad.dll
2008-04-07 20:42:37 14848 --a------ C:\