Hi kok-crunch
My antivirus updates every day this is because it is the full registered version 2 year 2 user standrd license AGV internet Security.
here are the two logs from my computer
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-06-22 17:22:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 5 Restore Point(s) --
73: 2008-06-22 08:04:04 UTC - RP73 - Deckard's System Scanner Restore Point
72: 2008-06-20 23:41:18 UTC - RP72 - Software Distribution Service 3.0
71: 2008-06-13 13:54:33 UTC - RP71 - System Checkpoint
70: 2008-06-12 13:02:26 UTC - RP70 - Installed RamBooster
69: 2008-06-11 12:15:41 UTC - RP69 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-05-20 17:28:26 UTC - RP1 - System Checkpoint
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:22:20, on 22/06/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberScrub Privacy Suite\CSRiskmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Administrator\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Privacy Suite RiskMonitor] C:\Program Files\CyberScrub Privacy Suite\CSRiskmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1211443084484O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun....ows-i586-jc.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 7760 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080612-133355-101 O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" /s
backup-20080612-133355-108 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
backup-20080612-133355-116 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
backup-20080612-133355-213 O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
backup-20080612-133355-223 O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
backup-20080612-133355-240 O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
backup-20080612-133355-369 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
backup-20080612-133355-398 O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
backup-20080612-133355-439 O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
backup-20080612-133355-592 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
backup-20080612-133355-855 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
backup-20080612-133355-973 O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&AD17F01&0&00E3
Manufacturer: Marvell
Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller #2
PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&AD17F01&0&00E3
Service: yukonwxp
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&8D68EE5&0&00E4
Manufacturer: Marvell
Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&8D68EE5&0&00E4
Service: yukonwxp
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RTL8187_Wireless
Device ID: USB\VID_0BDA&PID_8187\0015AF0D1A15
Manufacturer:
Name: RTL8187_Wireless
PNP Device ID: USB\VID_0BDA&PID_8187\0015AF0D1A15
Service:
-- Process Modules -------------------------------------------------------------
C:\WINDOWS\system32\winlogon.exe (pid 704)
2007-04-19 13:41:36 294912 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>
C:\WINDOWS\system32\svchost.exe (pid 1040)
2007-07-24 15:17:08 147456 --a------ C:\Program Files\Bonjour\mdnsNSP.dll <Not Verified; Apple Inc.; Bonjour>
C:\WINDOWS\explorer.exe (pid 2092)
2008-05-26 11:52:02 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>
-- Scheduled Tasks -------------------------------------------------------------
2008-06-22 17:14:49 502 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
2008-06-12 11:15:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-22 and 2008-06-22 -----------------------------
2008-06-20 23:53:19 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-20 23:53:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-20 23:53:15 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-14 09:27:05 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-14 09:27:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-06-14 09:24:38 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-06-14 09:24:26 0 d-------- C:\Program Files\Skype
2008-06-14 09:24:26 0 d-------- C:\Program Files\Common Files\Skype
2008-06-14 09:24:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-12 14:02:27 0 d-------- C:\Program Files\RamBooster 2.0
2008-06-10 17:39:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\NeroDCTemplates
2008-06-10 15:38:41 0 d-------- C:\Program Files\QuickTime
2008-06-10 13:57:09 0 d-------- C:\Program Files\Trend Micro
2008-06-10 13:47:40 0 d-------- C:\Program Files\BAVACARS
2008-06-10 13:47:33 796672 --a------ C:\WINDOWS\GPInstall.exe <Not Verified; Qsc; GP-Install>
2008-06-10 13:46:48 0 d-------- C:\Program Files\BAVOSP
2008-06-07 15:34:39 2977792 -----n--- C:\WINDOWS\UNNMP.exe <Not Verified; Nero AG; Nero Web Engine>
2008-06-07 15:33:23 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2008-06-07 15:32:16 2973696 -----n--- C:\WINDOWS\UNNeroVision.exe <Not Verified; Nero AG; Nero Web Engine>
2008-06-07 15:31:46 364544 -----n--- C:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
2008-06-07 15:31:46 471040 -----n--- C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:46 262144 -----n--- C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:45 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2008-06-07 15:31:45 38912 -----n--- C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2008-06-07 15:31:45 1568768 -----n--- C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:40 0 d-------- C:\Program Files\Ahead
2008-06-07 13:08:49 0 d-------- C:\Program Files\SquawkBox3
2008-06-06 16:18:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\TomTom
2008-06-06 16:18:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-06-06 16:17:34 0 d-------- C:\Program Files\TomTom HOME 2
2008-06-06 16:07:43 0 d-------- C:\Program Files\TomTom HOME
2008-06-05 16:19:41 0 d-------- C:\Documents and Settings\Administrator\Contacts
2008-06-05 16:16:06 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-05 16:15:45 0 d-------- C:\Program Files\Windows Live
2008-06-05 16:15:36 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-05 10:45:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-06-05 10:42:53 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-05 10:42:23 0 d-------- C:\Program Files\CyberLink
2008-06-05 00:01:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2008-06-04 23:46:01 0 d-------- C:\WINDOWS\pss
2008-06-04 23:27:01 0 d-------- C:\WINDOWS\system32\appmgmt
2008-06-04 23:20:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\dvdcss
2008-06-04 09:11:15 0 d-------- C:\Program Files\NeroInstall.bak
2008-06-04 09:08:05 0 d-------- C:\Program Files\Nero
2008-06-04 09:08:05 0 d-------- C:\Program Files\Common Files\Nero
2008-06-04 09:08:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-03 16:11:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ulead Systems
2008-06-03 16:01:48 53248 -----n--- C:\WINDOWS\system32\uvsc.dll <Not Verified; Ulead; Ulead uvsc>
2008-06-03 16:01:48 86016 -----n--- C:\WINDOWS\system32\uvAC3Enc.dll <Not Verified; Ulead Systems, Inc.; Ulead AC3 Encoder>
2008-06-03 16:01:48 61440 -----n--- C:\WINDOWS\system32\pcmaout.dll <Not Verified; MainConcept AG; MainConcept ® MPEG PCM Audio>
2008-06-03 16:01:48 90112 -----n--- C:\WINDOWS\system32\mpgvparse.dll <Not Verified; Ulead System, Inc.; Ulead Mpeg Video Parser>
2008-06-03 16:01:48 10752 -----n--- C:\WINDOWS\system32\MPGVOUT.dll <Not Verified; Ulead Systems, Inc; Ulead MPEG Video Wrapper>
2008-06-03 16:01:48 147456 -----n--- C:\WINDOWS\system32\mpgmux.dll <Not Verified; Ulead Systems, Inc; Ulead MPEG Multiplexer>
2008-06-03 16:01:48 65536 -----n--- C:\WINDOWS\system32\mpgcheck.dll <Not Verified; Ulead Systems, Inc.; Ulead MPEG Settings Checker>
2008-06-03 16:01:48 102400 -----n--- C:\WINDOWS\system32\mpgcap32.dll <Not Verified; Ulead Systems, Inc.; Ulead Systems, Inc. mpgcap32>
2008-06-03 16:01:48 90112 -----n--- C:\WINDOWS\system32\mpgaparse.dll <Not Verified; Ulead Systems, Inc.; Ulead MPEG Audio Parser>
2008-06-03 16:01:48 124928 -----n--- C:\WINDOWS\system32\MPGAOUT.DLL <Not Verified; Ulead Systems, Inc; Ulead MPEG Audio Encoder>
2008-06-03 16:01:48 315392 -----n--- C:\WINDOWS\system32\mpg_dlg.dll <Not Verified; ULead Systems; ULead® MPEG Encoder setting dialogs>
2008-06-03 16:01:48 180224 -----n--- C:\WINDOWS\system32\MPEGIN.DLL <Not Verified; Ulead Systems, Inc; Ulead MPEG SR File Decoder>
2008-06-03 16:01:48 532480 -----n--- C:\WINDOWS\system32\MCMpgDec.dll <Not Verified; Ulead Systems, Inc.; Ulead MPEG Stream Decoder>
2008-06-03 16:01:48 73728 -----n--- C:\WINDOWS\system32\ac3aout.dll <Not Verified; Ulead Systems, Inc.; Ulead AC3 Audio Encoder>
2008-06-03 15:58:23 24576 -----n--- C:\WINDOWS\system32\UleadPhotoExplorer8_Res.dll <Not Verified; Ulead Systems, Inc.; Ulead Photo Explorer>
2008-06-03 15:58:23 24576 -----n--- C:\WINDOWS\system32\Ulead Photo Explorer 8.scr <Not Verified; Ulead Systems, Inc.; Ulead Photo Explorer>
2008-06-03 15:58:15 0 d-------- C:\Program Files\Ulead Systems
2008-06-03 15:58:13 0 d-------- C:\Program Files\Common Files\Ulead Systems
2008-06-03 15:57:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-06-03 12:32:30 0 d-------- C:\Documents and Settings\Administrator\Application Data\FaxCtr
2008-06-03 10:45:53 0 d-------- C:\Documents and Settings\All Users\Application Data\ashampoo
2008-06-03 10:45:45 0 d-------- C:\Program Files\Ashampoo
2008-06-03 09:36:35 0 d-------- C:\Documents and Settings\All Users\Lx_cats
2008-06-03 09:30:55 0 d-------- C:\logs
2008-06-03 09:29:55 12288 --a------ C:\WINDOWS\system32\LXF3PMRC.DLL
2008-06-03 09:29:55 45056 --a------ C:\WINDOWS\system32\LXF3PMON.DLL
2008-06-03 09:29:55 36864 --a------ C:\WINDOWS\system32\lxf3oem.dll <Not Verified; ; Lexmark Fax Solutions Software>
2008-06-03 09:29:55 32768 --a------ C:\WINDOWS\system32\LXF3FXPU.DLL
2008-06-03 09:29:55 98345 --a------ C:\WINDOWS\system32\IMHOST32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-06-03 09:29:55 339968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-06-03 09:29:50 0 d-------- C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-06-03 09:29:39 0 d-------- C:\Program Files\Lexmark Fax Solutions
2008-06-03 09:29:23 0 d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-06-03 09:28:22 294912 --a------ C:\WINDOWS\system32\lxdiinst.dll
2008-06-03 09:28:12 0 d-------- C:\Program Files\Lexmark 3500-4500 Series
2008-06-02 16:06:31 0 d-------- C:\Netgear
2008-05-31 22:26:14 0 d-------- C:\Program Files\Apple Software Update
2008-05-31 15:41:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\vlc
2008-05-31 15:40:09 0 d-------- C:\Program Files\VideoLAN
2008-05-31 15:37:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-05-31 15:36:53 0 d-------- C:\Program Files\iPod
2008-05-31 15:36:50 0 d-------- C:\Program Files\iTunes
2008-05-31 15:36:35 0 d-------- C:\Program Files\Bonjour
2008-05-31 15:36:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-31 15:35:48 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-31 15:35:27 0 d-------- C:\Program Files\Common Files\Apple
2008-05-31 15:35:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-31 14:48:07 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-05-31 11:29:45 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberScrub
2008-05-31 11:28:30 0 d-------- C:\Program Files\CyberScrub Privacy Suite
2008-05-31 11:15:47 90 ---hs---- C:\WINDOWS\cnerolf.dat
2008-05-27 14:07:27 0 d-------- C:\Program Files\iStar
2008-05-26 16:26:05 0 d-------- C:\WINDOWS\Sun
2008-05-26 16:26:05 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-05-26 16:24:24 0 d-------- C:\Program Files\Java
2008-05-26 16:22:42 0 d-------- C:\Program Files\Common Files\Java
2008-05-26 16:10:21 0 d-------- C:\Program Files\uTorrent
2008-05-26 16:10:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-26 15:51:11 0 d-------- C:\Train Store
2008-05-26 15:24:55 304128 --a------ C:\WINDOWS\unin0407.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield Deinstaller>
2008-05-26 15:24:50 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-26 15:02:20 0 d-------- C:\Program Files\J A Formoso
2008-05-26 12:55:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-05-26 12:40:33 0 d-------- C:\Program Files\Google
2008-05-26 12:40:33 0 d-------- C:\Documents and Settings\Administrator\Application Data\Google
2008-05-26 12:39:42 0 d-------- C:\Program Files\Kontiki
2008-05-26 12:39:42 0 d-------- C:\logs3
2008-05-26 12:39:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-05-26 11:48:07 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-26 11:47:40 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-26 11:47:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-05-26 11:44:15 0 d-------- C:\Program Files\Kyodai
2008-05-26 11:43:15 5248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-05-26 11:43:15 155136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-05-26 11:43:14 0 d-------- C:\Program Files\D-Tools
2008-05-26 11:43:00 0 d-------- C:\WINDOWS\Downloaded Installations
2008-05-26 11:42:37 0 d-------- C:\Program Files\UltraISO
2008-05-26 11:42:37 0 d-------- C:\Program Files\Common Files\EZB Systems
2008-05-26 11:42:01 0 d-------- C:\Program Files\WinISO
2008-05-26 10:45:03 0 dr-h----- C:\$VAULT$.AVG
2008-05-26 10:43:51 0 d-------- C:\Documents and Settings\Administrator\Application Data\TuneUp Software
2008-05-26 10:43:43 0 d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-26 10:43:39 0 d-------- C:\Program Files\TuneUp Utilities 2008
2008-05-26 10:42:58 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-24 01:20:03 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-24 01:19:58 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-24 00:32:47 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-24 00:32:47 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-22 12:25:55 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-22 12:02:40 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-22 12:01:24 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-22 12:01:24 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-22 11:59:39 0 d-------- C:\WINDOWS\system32\URTTEMP
2008-05-22 10:39:43 0 d-------- C:\WINDOWS\system32\Lang
2008-05-22 10:37:46 0 d-------- C:\WINDOWS\system32\RTCOM
2008-05-22 10:34:51 0 d-------- C:\WINDOWS\Prefetch
2008-05-22 10:24:32 0 d-------- C:\WINDOWS\system32\scripting
2008-05-22 10:24:32 0 d-------- C:\WINDOWS\system32\en
2008-05-22 10:24:32 0 d-------- C:\WINDOWS\l2schemas
2008-05-22 10:24:31 0 d-------- C:\WINDOWS\system32\bits
2008-05-22 10:22:28 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-22 10:20:21 0 d-------- C:\WINDOWS\network diagnostic
2008-05-22 09:29:46 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-22 09:00:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-22 09:00:25 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-22 09:00:24 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-22 08:58:36 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-22 08:57:47 0 d--hs---- C:\Documents and Settings\Administrator\UserData
-- Find3M Report ---------------------------------------------------------------
2008-06-22 08:56:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-06-14 09:24:26 0 d-------- C:\Program Files\Common Files
2008-06-11 16:16:29 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-07 15:31:41 0 d-------- C:\Program Files\Common Files\Ahead
2008-05-26 13:03:34 0 d-------- C:\Program Files\Microsoft Games
2008-05-22 10:24:57 0 d-------- C:\Program Files\Old Messenger
2008-05-22 10:24:31 0 d-------- C:\Program Files\Movie Maker
2008-05-22 10:22:09 0 d-------- C:\Program Files\Windows NT
2008-05-21 09:39:37 0 d-------- C:\Program Files\Microsoft Works
2008-05-21 09:39:31 0 d-------- C:\Program Files\MSBuild
2008-05-21 09:38:49 0 d-------- C:\Program Files\Microsoft.NET
2008-05-21 09:37:40 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-21 09:28:34 0 d-------- C:\Program Files\Microsoft AutoRoute
2008-05-21 08:59:04 0 d-------- C:\Program Files\Common Files\LightScribe
2008-05-21 08:47:36 0 d-------- C:\Program Files\Creative
2008-05-21 08:45:54 233472 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-05-21 08:44:26 0 d-------- C:\Documents and Settings\Administrator\Application Data\Creative
2008-05-21 08:41:43 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-21 08:37:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\ATI
2008-05-21 08:34:06 0 d-------- C:\Program Files\Common Files\ATI Technologies
2008-05-21 08:33:03 0 d-------- C:\Program Files\ATI Technologies
2008-05-20 19:09:54 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-20 19:09:51 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-20 19:09:29 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2008-05-20 18:28:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-05-20 18:21:27 0 d-------- C:\Program Files\microsoft frontpage
2008-05-20 18:21:12 0 -rahs---- C:\MSDOS.SYS
2008-05-20 18:21:12 0 -rahs---- C:\IO.SYS
2008-05-20 18:21:12 0 --a------ C:\CONFIG.SYS
2008-05-20 18:21:12 0 --a------ C:\AUTOEXEC.BAT
2008-05-20 18:20:08 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-20 18:19:20 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-20 18:18:29 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-20 18:18:10 0 d-------- C:\Program Files\Online Services
2008-05-20 18:18:01 0 d-------- C:\Program Files\MSN Gaming Zone
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PD0620 STISvc"="P0620Pin.dll" [10/05/2005 18:03 C:\WINDOWS\system32\P0620Pin.dll]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [21/05/2008 09:19]
"CTHelper"="CTHELPER.EXE" [09/04/2007 12:32 C:\WINDOWS\system32\CtHelper.exe]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [11/05/2000 01:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [14/04/2008 01:12]
"Privacy Suite RiskMonitor"="C:\Program Files\CyberScrub Privacy Suite\CSRiskmon.exe" [22/11/2007 10:53]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [26/05/2008 11:52 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 21/05/2008 08:19 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f24eb0a-33da-11dd-9045-00184ddee7e8}]
AutoRun\command- L:\InstallTomTomHOME.exe
-- End of Deckard's System Scanner: finished at 2008-06-22 17:24:38 ------------
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-06-22 17:22:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 5 Restore Point(s) --
73: 2008-06-22 08:04:04 UTC - RP73 - Deckard's System Scanner Restore Point
72: 2008-06-20 23:41:18 UTC - RP72 - Software Distribution Service 3.0
71: 2008-06-13 13:54:33 UTC - RP71 - System Checkpoint
70: 2008-06-12 13:02:26 UTC - RP70 - Installed RamBooster
69: 2008-06-11 12:15:41 UTC - RP69 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-05-20 17:28:26 UTC - RP1 - System Checkpoint
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:22:20, on 22/06/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberScrub Privacy Suite\CSRiskmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Administrator\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Privacy Suite RiskMonitor] C:\Program Files\CyberScrub Privacy Suite\CSRiskmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1211443084484O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun....ows-i586-jc.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 7760 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080612-133355-101 O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" /s
backup-20080612-133355-108 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
backup-20080612-133355-116 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
backup-20080612-133355-213 O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
backup-20080612-133355-223 O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
backup-20080612-133355-240 O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
backup-20080612-133355-369 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
backup-20080612-133355-398 O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
backup-20080612-133355-439 O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
backup-20080612-133355-592 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
backup-20080612-133355-855 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
backup-20080612-133355-973 O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&AD17F01&0&00E3
Manufacturer: Marvell
Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller #2
PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&AD17F01&0&00E3
Service: yukonwxp
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&8D68EE5&0&00E4
Manufacturer: Marvell
Name: Marvell Yukon 88E8053 PCI-E Gigabit Ethernet Controller
PNP Device ID: PCI\VEN_11AB&DEV_4362&SUBSYS_81421043&REV_20\4&8D68EE5&0&00E4
Service: yukonwxp
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RTL8187_Wireless
Device ID: USB\VID_0BDA&PID_8187\0015AF0D1A15
Manufacturer:
Name: RTL8187_Wireless
PNP Device ID: USB\VID_0BDA&PID_8187\0015AF0D1A15
Service:
-- Process Modules -------------------------------------------------------------
C:\WINDOWS\system32\winlogon.exe (pid 704)
2007-04-19 13:41:36 294912 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>
C:\WINDOWS\system32\svchost.exe (pid 1040)
2007-07-24 15:17:08 147456 --a------ C:\Program Files\Bonjour\mdnsNSP.dll <Not Verified; Apple Inc.; Bonjour>
C:\WINDOWS\explorer.exe (pid 2092)
2008-05-26 11:52:02 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>
-- Scheduled Tasks -------------------------------------------------------------
2008-06-22 17:14:49 502 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
2008-06-12 11:15:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-22 and 2008-06-22 -----------------------------
2008-06-20 23:53:19 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-20 23:53:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-20 23:53:15 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-14 09:27:05 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-14 09:27:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\skypePM
2008-06-14 09:24:38 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-06-14 09:24:26 0 d-------- C:\Program Files\Skype
2008-06-14 09:24:26 0 d-------- C:\Program Files\Common Files\Skype
2008-06-14 09:24:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-12 14:02:27 0 d-------- C:\Program Files\RamBooster 2.0
2008-06-10 17:39:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\NeroDCTemplates
2008-06-10 15:38:41 0 d-------- C:\Program Files\QuickTime
2008-06-10 13:57:09 0 d-------- C:\Program Files\Trend Micro
2008-06-10 13:47:40 0 d-------- C:\Program Files\BAVACARS
2008-06-10 13:47:33 796672 --a------ C:\WINDOWS\GPInstall.exe <Not Verified; Qsc; GP-Install>
2008-06-10 13:46:48 0 d-------- C:\Program Files\BAVOSP
2008-06-07 15:34:39 2977792 -----n--- C:\WINDOWS\UNNMP.exe <Not Verified; Nero AG; Nero Web Engine>
2008-06-07 15:33:23 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2008-06-07 15:32:16 2973696 -----n--- C:\WINDOWS\UNNeroVision.exe <Not Verified; Nero AG; Nero Web Engine>
2008-06-07 15:31:46 364544 -----n--- C:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
2008-06-07 15:31:46 471040 -----n--- C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:46 262144 -----n--- C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:45 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2008-06-07 15:31:45 38912 -----n--- C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2008-06-07 15:31:45 1568768 -----n--- C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-06-07 15:31:40 0 d-------- C:\Program Files\Ahead
2008-06-07 13:08:49 0 d-------- C:\Program Files\SquawkBox3
2008-06-06 16:18:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\TomTom
2008-06-06 16:18:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-06-06 16:17:34 0 d-------- C:\Program Files\TomTom HOME 2
2008-06-06 16:07:43 0 d-------- C:\Program Files\TomTom HOME
2008-06-05 16:19:41 0 d-------- C:\Documents and Settings\Administrator\Contacts
2008-06-05 16:16:06 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-05 16:15:45 0 d-------- C:\Program Files\Windows Live
2008-06-05 16:15:36 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-05 10:45:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-06-05 10:42:53 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-05 10:42:23 0 d-------- C:\Program Files\CyberLink
2008-06-05 00:01:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Nero
2008-06-04 23:46:01 0 d-------- C:\WINDOWS\pss
2008-06-04 23:27:01 0 d-------- C:\WINDOWS\system32\appmgmt
2008-06-04 23:20:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\dvdcss
2008-06-04 09:11:15 0 d-------- C:\Program Files\NeroInstall.bak
2008-06-04 09:08:05 0 d-------- C:\Program Files\Nero
2008-06-04 09:08:05 0 d-------- C:\Program Files\Common Files\Nero
2008-06-04 09:08:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-03 16:11:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ulead Systems
2008-06-03 16:01:48 53248 -----n--- C:\WINDOWS\system32\uvsc.dll <Not Verified; Ulead; Ulead uvsc>
2008-06-03 16:01:48 86016 -----n--- C:\WINDOWS\system32\uvAC3Enc.dll <Not Verified; Ulead Systems, Inc.; Ulead AC3 Encoder>
2008-06-03 16:01:48 61440 -----n--- C:\WINDOWS\system32\pcmaout.dll <Not Verified; MainConcept AG; MainConcept ® MPEG PCM Audio>
2008-06-03 16:01:48 90112 -----n--- C:\WINDOWS\system32\mpgvparse.dll <Not Verified; Ulead System, Inc.; Ulead Mpeg Video Parser>
2008-06-03 16:01:48 10752 -----n--- C:\WINDOWS\system32\MPGVOUT.dll <Not Verified; Ulead Systems, Inc; Ulead MPEG Video Wrapper>
2008-06-03 16:01:48 147456 -----n--- C:\WINDOWS\system32\mpgmux.dll <Not Verified; Ulead Systems, Inc; Ulead MPEG Multiplexer>
2008-06-03 16:01:48 65536 -----n--- C:\WINDOWS\system32\mpgcheck.dll <Not Verified;