Hi koko_crunch!
Sorry for the late reply, been unable to check back this thread for past couple of days. Here are the new logs!
Thanks!
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 06/04/2008 at 06:51 PM
Application Version : 4.15.1000
Core Rules Database Version : 3471
Trace Rules Database Version: 1462
Scan type : Complete Scan
Total Scan Time : 02:05:48
Memory items scanned : 381
Memory threats detected : 0
Registry items scanned : 4660
Registry threats detected : 0
File items scanned : 52402
File threats detected : 3
Adware.Tracking Cookie
C:\Documents and Settings\ABO\Cookies\abo@specificclick[2].txt
C:\Documents and Settings\ABO\Cookies\abo@doubleclick[1].txt
C:\Documents and Settings\ABO\Cookies\
[email protected][1].txt
.2o7.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.multiply.112.2o7.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.zedo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ad.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.yieldmanager.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.bs.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adbrite.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adbrite.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adbrite.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adbrite.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
web4.realtracker.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.kontera.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.kontera.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.richmedia.yahoo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adinterax.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adinterax.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.mediafire.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.mediafire.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.mediafire.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
linkto.mediafire.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ads.pointroll.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.eb.adbureau.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.eb.adbureau.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.eb.adbureau.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-streamload.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
data.coremetrics.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-warnerbrothers.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-warnerbrothers.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.warnerbros.112.2o7.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.dynamic.media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.dynamic.media.adrevolver.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.casalemedia.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
server.iad.liveperson.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
ads.revsci.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
www3.addfreestats.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-dig.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-dig.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-zoom.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.media.zoominfo.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.ehg-revlon.hitbox.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
.statcounter.com [ C:\Documents and Settings\ABO\Application Data\Mozilla\Firefox\Profiles\k1h0hcvp.default\cookies.txt ]
Deckard's System Scanner v20071014.68
Run by ABO on 2008-06-04 19:37:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
50: 2008-06-04 11:38:21 UTC - RP268 - Deckard's System Scanner Restore Point
49: 2008-06-03 12:21:20 UTC - RP267 - System Checkpoint
48: 2008-06-02 08:44:42 UTC - RP266 - ComboFix created restore point
47: 2008-06-01 15:37:40 UTC - RP265 - ComboFix created restore point
46: 2008-06-01 04:39:56 UTC - RP264 - Removed Sony USB Driver
-- First Restore Point --
1: 2008-03-18 08:37:50 UTC - RP219 - Software Distribution Service 3.0
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 82% (more than 75%).Total Physical Memory: 239 MiB (512 MiB recommended).-- HijackThis (run as ABO.exe) -------------------------------------------------
logfile has no content; running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-06-04 19:41:09
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
C:\Program Files\Grisoft\AVG Free\avgemc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\Program Files\McAfee.com\Agent\McTskshd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Sierra Wireless Inc\AirCard 700 Series\SwiWiFiComm.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Toshiba\TouchED\TouchED.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\WINDOWS\ltsmmsg.exe
C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\McAfee\SpamKiller\MSKAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\ApntEx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Documents and Settings\ABO\Desktop\dss.exe
C:\Program Files\Trend Micro\HijackThis\ABO.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.google.com/search?q=%sR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.192.192.1:3128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieO2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [AirCardEnabler] "C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: RAMASST.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoft...s/as2stubie.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) -
http://kikaykix.mult...os/uploader.cabO17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{87304114-F465-4FCB-A18C-28C2E32E8869}: NameServer = 58.69.254.133,58.69.254.71
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{EC542B60-CD42-4126-8EA2-EE4DCD5CB18D}: NameServer = 58.69.254.133,58.69.254.71
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG Free\avgemc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\Mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\McTskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Unknown owner - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SwiWiFiComm - Unknown owner - C:\Program Files\Sierra Wireless Inc\AirCard 700 Series\SwiWiFiComm.exe
--
End of file - 10876 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080530-173032-861 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\DisMgnt.exe,
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 TVALD (Toshiba ACPI-Based Value Added Logical Device Driver) - c:\windows\system32\drivers\tvald.sys <Not Verified; Toshiba Corporation; Toshiba ACPI-Compliant Value Added Logical Device>
R0 TVALG (Toshiba Value Added Logical and General Purpose Device Driver) - c:\windows\system32\drivers\tvalg.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Value Added Logical and General Purpose Device Driver>
R1 meiudf - c:\windows\system32\drivers\meiudf.sys <Not Verified; Matsushita Electric Industrial Co.,Ltd.; >
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 catchme - c:\combofix\catchme.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 DVD-RAM_Service - c:\windows\system32\dvdramsv.exe <Not Verified; Matsushita Electric Industrial Co., Ltd.; >
R2 SwiWiFiComm - c:\program files\sierra wireless inc\aircard 700 series\swiwificomm.exe
S2 MskService (McAfee SpamKiller Server) - c:\progra~1\mcafee\spamki~1\msksrvr.exe (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-05-04 and 2008-06-04 -----------------------------
2008-06-03 17:35:41 0 d-------- C:\Documents and Settings\ABO\Application Data\WinRAR
2008-06-02 16:32:47 0 drahs---- C:\autorun.inf
2008-06-01 23:36:46 68096 --a------ C:\WINDOWS\zip.exe
2008-06-01 23:36:46 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-01 23:36:46 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-01 23:36:46 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-01 23:36:46 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-01 23:36:46 98816 --a------ C:\WINDOWS\sed.exe
2008-06-01 23:36:46 80412 --a------ C:\WINDOWS\grep.exe
2008-06-01 23:36:46 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-01 12:05:46 0 d-------- C:\Documents and Settings\ABO\Application Data\Sony Corporation
2008-06-01 11:56:05 0 d-------- C:\Program Files\Sony
2008-05-29 12:39:00 0 d-------- C:\WINDOWS\ERUNT
2008-05-26 09:50:12 0 d-------- C:\kav
2008-05-26 03:19:53 1160 --a------ C:\WINDOWS\mozver.dat
2008-05-25 22:14:06 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-25 22:11:44 0 d-------- C:\Documents and Settings\ABO\Application Data\Mozilla
2008-05-22 17:49:25 0 d-------- C:\Program Files\Panda Security
2008-05-22 13:13:12 0 d-------- C:\Program Files\Trend Micro
2008-05-22 13:13:02 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-22 13:12:27 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-22 13:12:27 0 d-------- C:\Documents and Settings\ABO\Application Data\SUPERAntiSpyware.com
2008-05-22 13:11:56 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-22 13:08:46 0 d-------- C:\Documents and Settings\ABO\Application Data\Malwarebytes
2008-05-22 13:08:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-22 13:08:28 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-22 13:07:25 0 d-------- C:\Program Files\Common Files\Download Manager
2008-05-17 08:13:35 0 d-------- C:\WINDOWS\pss
-- Find3M Report ---------------------------------------------------------------
2008-06-04 11:40:59 0 d-------- C:\Documents and Settings\ABO\Application Data\AVG7
2008-06-01 11:58:51 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-31 11:20:26 0 d-------- C:\Documents and Settings\ABO\Application Data\MSN6
2008-05-26 11:31:07 0 d-------- C:\Program Files\McAfee.com
2008-05-24 14:55:06 0 d-------- C:\Documents and Settings\ABO\Application Data\Adobe
2008-05-22 13:11:56 0 d-------- C:\Program Files\Common Files
2008-05-17 13:59:12 0 d-------- C:\Program Files\Yahoo!
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [04/06/2003 11:19 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [04/06/2003 11:07 PM]
"PmProxy"="C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe" [02/28/2003 06:54 PM]
"00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [04/16/2003 11:01 AM]
"000StTHK"="000StTHK.exe" [06/24/2001 11:28 AM C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [12/25/2002 01:38 PM]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [01/22/2003 09:00 AM]
"TFNF5"="TFNF5.exe" [08/03/2001 04:08 PM C:\WINDOWS\system32\TFNF5.exe]
"Tpwrtray"="TPWRTRAY.EXE" [12/11/2002 01:49 AM C:\WINDOWS\system32\TPWRTRAY.EXE]
"LTSMMSG"="LTSMMSG.exe" [04/18/2003 09:06 AM C:\WINDOWS\ltsmmsg.exe]
"AirCardEnabler"="C:\Program Files\Sierra Wireless Inc\Network Adapter Manager\Network Adapter Manager.exe" [03/29/2005 10:47 AM]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [01/12/2006 08:52 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [04/29/2008 11:57 PM]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [01/11/2006 12:05 PM]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [09/22/2005 06:29 PM]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [07/12/2005 06:06 PM]
"McRegWiz"="C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe" [06/01/2005 02:05 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/04/2008 04:44 PM]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [08/30/2007 05:43 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [10/25/2006 5:19:55 PM]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2/18/2007 4:38:19 PM]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [5/22/2003 7:37:50 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/22/2008 02:13 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 05/22/2008 02:13 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11d891f0-8a79-11db-9c1f-00a0d5ffff89}]
AutoRun\command- bar311.exe %1
Explore\command- bar311.exe %1
Open\command- bar311.exe %1
-- End of Deckard's System Scanner: finished at 2008-06-04 19:43:51 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Mobile Intel® Pentium® 4 - M CPU 2.20GHz
Percentage of Memory in Use: 87%
Physical Memory (total/avail): 238.8 MiB / 29.33 MiB
Pagefile Memory (total/avail): 585.76 MiB / 187.76 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1933.32 MiB
C: is Fixed (NTFS) - 27.95 GiB total, 17.39 GiB free.
D: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - IC25N030ATMR04-0 - 27.95 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 27.95 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: AVG 7.5.524 v7.5.524 (Grisoft)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\ABO\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=ABO
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\ABO
LOGONSERVER=\\ABO
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ABO\LOCALS~1\Temp
TMP=C:\DOCUME~1\ABO\LOCALS~1\Temp
USERDOMAIN=ABO
USERNAME=ABO
USERPROFILE=C:\Documents and Settings\ABO
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
ABO
(admin)Administrator
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> c:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /appid=MSK /uninstall=1 /interact=1 /script_proactive=0 /start="c:\PROGRA~1\mcafee.com\agent\uninst\mskremui.dll::uninstall.htm"
--> c:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /appid=msc /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\screm.ui::uninstall.htm
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat 7.0.9 Professional --> msiexec /I {AC76BA86-1033-0000-7760-000000000002}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop 7.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Alps Pointing-device Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.exe" UNINSTALL
AVG Free Edition --> C:\Program Files\Grisoft\AVG Free\setup.exe /UNINSTALL
DVD-RAM Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}\Setup.exe" DVD-RAM Driver
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_3582
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
InterVideo WinDVD 4 --> "C:\Program Files\InstallShield Installation Information\{98E8A2EF-4EAE-43B8-A172-74842B764777}\setup.exe" REMOVEALL
LifeGoal 1.1 --> "C:\Program Files\MYM\unins000.exe"
Macromedia Flash MX 2004 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F353D44-73BB-4971-B31D-F7642E9E9531}\Setup.exe" -l0x9 UNINSTALL
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee Uninstall Wizard --> C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\comrem.dll::uninstall.htm
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Security Update for Excel 2007 (KB946974) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Office 2007 (KB934062) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}
Security Update for Office 2007 (KB947801) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}
Sierra Wireless AirCard® 700 Series Wireless Network Card --> MsiExec.exe /X{40CD5E65-BCEC-46B0-AAC8-9E8C3AB887E9}
Sierra Wireless Network Adapter Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8DEC2C44-BB50-11D4-9E04-0050DA701DC9}\setup.exe" -l0x9 UNINSTALL
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
TOSHIBA ConfigFree --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}\Setup.exe"
TOSHIBA Console --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}\Setup.exe" -l0x9
Toshiba Hotkey Utility for Display Devices --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\TFNF5Wxp.inf,DefaultUninstall,5
TOSHIBA Power Saver --> TPWRDEL.EXE
TOSHIBA Software Modem --> Tosmreg -U
TOSHIBA TouchPad On/Off Utility V2.05.00 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\TOSHIBA\TouchED\Uninst.isu" -c"C:\Program Files\TOSHIBA\TouchED\tpedinst.dll"
TOSHIBA Utilities --> tutildel.exe
Update for Office 2007 (KB932080) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}
Update for Office 2007 (KB934391) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}
Update for Office 2007 (KB946691) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {90120000-0030-0000-0000-00