main.txt:
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-06-17 18:22:08
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:23:24, on 6/17/2008
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\Windows Home Server\WHSConnector.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Hide My IP 2008\SecureSrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://google.ca/O2 - BHO: (no name) - {42A70D2D-3F1A-4061-B18A-FC1A5ACD44AA} - C:\WINDOWS\system32\ssqPgDUK.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {E707216F-6AFF-4BD4-962D-EC5CDBA812A1} - C:\WINDOWS\system32\yayyApNe.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Home Server Banner - {D73E76A3-F902-45BD-8FC8-95AE8E014671} - C:\Program Files\Windows Home Server\WHSDeskBands.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunServices: [WGETMO] C:\WINDOWS\SYSTEM32\WGETMO.EXE
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O15 - ESC Trusted Zone:
http://www.2shared.comO15 - ESC Trusted Zone:
http://lastchaos.aeriagames.comO15 - ESC Trusted Zone:
http://view.atdmt.comO15 - ESC Trusted Zone:
http://www.baictron.comO15 - ESC Trusted Zone:
http://*.bux.toO15 - ESC Trusted Zone:
http://www.cabalonline.comO15 - ESC Trusted Zone:
http://adserving.cpxinteractive.comO15 - ESC Trusted Zone:
http://www.daemon-search.comO15 - ESC Trusted Zone:
http://ad.doubleclick.netO15 - ESC Trusted Zone:
http://www.goozeman.game-deception.comO15 - ESC Trusted Zone:
http://xiah.gamescampus.comO15 - ESC Trusted Zone:
http://www.google.caO15 - ESC Trusted Zone:
http://www.gunzonline.comO15 - ESC Trusted Zone:
http://img72.imageshack.usO15 - ESC Trusted Zone:
http://www.java.comO15 - ESC Trusted Zone:
http://bl137w.blu137.mail.live.comO15 - ESC Trusted Zone:
http://search.live.comO15 - ESC Trusted Zone:
http://files1.majorgeeks.comO15 - ESC Trusted Zone:
http://about1.mirc.comO15 - ESC Trusted Zone:
http://about2.mirc.comO15 - ESC Trusted Zone:
http://rad.msn.comO15 - ESC Trusted Zone:
http://*.myshoppingsavings.netO15 - ESC Trusted Zone:
http://www.nokia.caO15 - ESC Trusted Zone:
http://cabal.ogplanet.comO15 - ESC Trusted Zone:
http://forum.organner.plO15 - ESC Trusted Zone:
http://www.plaync.comO15 - ESC Trusted Zone:
http://*.project-7.netO15 - ESC Trusted Zone:
http://rs230tl2.rapidshare.comO15 - ESC Trusted Zone:
http://www.rewardscentre.netO15 - ESC Trusted Zone:
http://*.steamcommunity.comO15 - ESC Trusted Zone:
http://storefront.steampowered.comO15 - ESC Trusted Zone:
http://ftp.twaren.netO15 - ESC Trusted Zone:
http://media.warrock.netO15 - ESC Trusted Zone:
http://client.winamp.comO15 - ESC Trusted Zone:
http://*.windowsupdate.comO15 - ESC Trusted Zone:
http://launcher.worldofwarcraft.comO15 - ESC Trusted Zone:
http://www.worldofwarcraft.comO15 - ESC Trusted Zone:
http://*.xpservers.netO15 - ESC Trusted Zone:
http://*.windowsupdate.com (HKLM)
O15 - ESC Trusted IP range:
http://64.15.152.87O20 - Winlogon Notify: FGWLNotify - C:\Program Files\Fortres Grand\Fortres Security Runtime 6.0\FGWLNotify.dll
O20 - Winlogon Notify: yayyApNe - C:\WINDOWS\SYSTEM32\yayyApNe.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecureSrv - Unknown owner - C:\Program Files\Hide My IP 2008\SecureSrv.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
--
End of file - 8905 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 giveio - c:\windows\system32\giveio.sys
R1 speedfan - c:\windows\system32\speedfan.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R2 SBKUPNT - c:\windows\system32\drivers\sbkupnt.sys
R3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
S3 Ad-Watch Connect Filter (Ad-Watch Connect Kernel Filter) - c:\windows\system32\drivers\nsdriver.sys (file missing)
S3 Ad-Watch Real-Time Scanner (AW Real-Time Scanner) - c:\windows\system32\drivers\awrtpd.sys (file missing)
S3 Ad-Watch Registry Filter (Ad-Watch Registry Kernel Filter) - c:\windows\system32\drivers\awrtrd.sys (file missing)
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 FGCWL - c:\program files\fortres grand\virtual sandbox 1.0\fgcwl.sys (file missing)
S3 gokudr1ver - c:\program files\super saiyan\goku.sys
S3 IpInIp (IP in IP Tunnel Driver) - c:\windows\system32\drivers\ipinip.sys (file missing)
S3 NPF (NetGroup Packet Filter Driver) - c:\windows\system32\drivers\npf.sys <Not Verified; Politecnico di Torino; NPF Driver>
S3 pgfilter - c:\program files\peerguardian2\pgfilter.sys
S3 SCREAMINGBDRIVER (Screaming Bee Audio) - c:\windows\system32\drivers\screamingbaudio.sys (file missing)
S3 uzsnuq - c:\documents and settings\administrator\desktop\lol\uzsnuq.sys (file missing)
S3 VMnetAdapter (VMware Virtual Ethernet Adapter Driver) - c:\windows\system32\drivers\vmnetadapter.sys (file missing)
S3 XDva158 - c:\windows\system32\xdva158.sys (file missing)
S3 zenx1 - c:\documents and settings\administrator\desktop\zenxengine_maplestory\zenxengine_maplestory\zenxengine maplestory\zenx.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 SAVAdminService (Sophos Anti-Virus status reporter) - "c:\program files\sophos\sophos anti-virus\savadminservice.exe" <Not Verified; Sophos Plc; Sophos Anti-Virus>
R2 SAVService (Sophos Anti-Virus) - "c:\program files\sophos\sophos anti-virus\savservice.exe" <Not Verified; Sophos Plc; Sophos Anti-Virus>
R2 Sophos Agent - "c:\program files\sophos\remote management system\managementagentnt.exe" -service -name agent <Not Verified; Sophos Plc; Sophos Messaging System>
R2 Sophos AutoUpdate Service - "c:\program files\sophos\autoupdate\alsvc.exe" <Not Verified; Sophos Plc; Sophos AutoUpdate>
R2 Sophos Message Router - "c:\program files\sophos\remote management system\routernt.exe" -service -name router -orblistenendpoints iiop://:8193/ssl_port=8194 <Not Verified; Sophos Plc; Sophos Messaging System>
S3 rpcapd (Remote Packet Capture Protocol v.0 (experimental)) - "c:\program files\winpcap\rpcapd.exe" -d -f "c:\program files\winpcap\rpcapd.ini"
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S4 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 fsrt (Fortres Security Runtime) - "c:\program files\fortres grand\fortres security runtime 6.0\fsrt.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-05-17 and 2008-06-17 -----------------------------
2008-06-17 17:27:36 168 --a------ C:\Start_.cmd
2008-06-17 01:14:55 0 d-------- C:\Program Files\Lavasoft
2008-06-17 01:14:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-17 00:29:03 0 d-------- C:\Program Files\WinPcap
2008-06-17 00:28:29 77824 --a------ C:\WINDOWS\system32\nmapwin.exe <Not Verified; JVSoftware; NMapWin nmap front-end>
2008-06-17 00:28:29 108536 --a------ C:\WINDOWS\system32\nmap-services
2008-06-17 00:28:29 557444 --a------ C:\WINDOWS\system32\nmap-service-probes
2008-06-17 00:28:29 290816 --a------ C:\WINDOWS\system32\nmapserv.exe
2008-06-17 00:28:29 17955 --a------ C:\WINDOWS\system32\nmap-rpc
2008-06-17 00:28:29 6318 --a------ C:\WINDOWS\system32\nmap-protocols
2008-06-17 00:28:29 809345 --a------ C:\WINDOWS\system32\nmap-os-fingerprints
2008-06-17 00:28:29 225546 --a------ C:\WINDOWS\system32\nmap-mac-prefixes
2008-06-17 00:28:29 192 --a------ C:\WINDOWS\system32\nmap_performance.reg
2008-06-17 00:28:29 452096 --a------ C:\WINDOWS\system32\nmap.exe <Not Verified; ; Nmap>
2008-06-17 00:28:29 25611 --a------ C:\WINDOWS\system32\COPYING
2008-06-17 00:28:29 192007 --a------ C:\WINDOWS\system32\CHANGELOG
2008-06-17 00:28:28 114688 --a------ C:\WINDOWS\system32\CCGNU32.dll <Not Verified; Open Source Telecom; OST Common C++>
2008-06-17 00:28:23 10752 --a------ C:\WINDOWS\system32\aamd532.dll <Not Verified; Almeida & Andrade Ltda; MD5 Maker DLL>
2008-06-17 00:28:22 561179 --a------ C:\WINDOWS\system32\dao360.dll <Not Verified; Microsoft Corporation; Microsoft® Jet>
2008-06-17 00:28:20 137216 --a------ C:\WINDOWS\system32\MSDERUN.DLL <Not Verified; Microsoft Corporation; Microsoft Data Environment Runtime 1.0>
2008-06-17 00:28:17 0 d-------- C:\Program Files\Net Tools
2008-06-16 22:33:13 0 d-------- C:\Program Files\Trend Micro
2008-06-16 20:33:12 0 d-------- C:\Program Files\Sun
2008-06-16 20:32:25 0 d-------- C:\Program Files\Common Files\Java
2008-06-16 18:59:01 2154 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-16 16:40:44 1152 --a------ C:\WINDOWS\system32\windrv.sys
2008-06-16 16:40:02 0 d-------- C:\Program Files\Common Files\Download Manager
2008-06-15 15:18:54 0 d-------- C:\Program Files\Spyware Doctor
2008-06-15 15:18:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-06-15 15:16:08 577232 --ahs---- C:\WINDOWS\system32\wHQqYJlm.ini2
2008-06-15 14:11:27 2087 --ahs---- C:\WINDOWS\system32\kmnnmnnn.ini2
2008-06-15 03:18:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-15 03:06:51 0 --a------ C:\WINDOWS\system32\MSVolume.dll
2008-06-15 03:00:48 3976 --ahs---- C:\WINDOWS\system32\KUDgPqss.ini2
2008-06-15 03:00:37 58368 --a------ C:\WINDOWS\system32\tuvVoOFv.dll
2008-06-15 02:58:37 58368 --a------ C:\WINDOWS\system32\ssqoNgGx.dll
2008-06-15 02:55:42 58368 --a------ C:\WINDOWS\system32\yayyApNe.dll
2008-06-15 02:46:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\HideIP
2008-06-15 02:37:20 0 d-------- C:\Documents and Settings\Administrator\Application Data\Hide IP NG
2008-06-14 22:43:31 0 d-------- C:\binary
2008-06-14 21:29:08 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft Games
2008-06-14 21:26:42 0 d-------- C:\Program Files\GameSpy Arcade
2008-06-14 21:24:47 0 d-------- C:\Program Files\Microsoft Games
2008-06-14 04:05:54 12 --a------ C:\Program Files\ID.dat
2008-06-14 03:54:06 0 d-------- C:\Program Files\sound
2008-06-14 03:53:52 0 d-------- C:\Program Files\Collision
2008-06-14 03:53:40 0 d-------- C:\Program Files\world
2008-06-14 03:49:08 0 d-------- C:\Program Files\bitmaps
2008-06-14 03:45:49 0 d-------- C:\Program Files\model
2008-06-14 03:43:28 162816 --a------ C:\Program Files\fmod.dll <Not Verified; Firelight Technologies Pty, Ltd; FMOD>
2008-06-14 03:43:28 40960 --a------ C:\Program Files\Error.exe
2008-06-14 03:43:28 98304 --a------ C:\Program Files\eax.dll <Not Verified; Creative Technology Ltd; Creative Technology Ltd eax>
2008-06-14 03:43:28 1038848 --a------ C:\Program Files\dbghelp.dll <Not Verified; Microsoft Corporation; Debugging Tools for Windows®>
2008-06-14 03:43:28 63488 --a------ C:\Program Files\bugslayerutil.dll <Not Verified; Debugging Applications for Microsoft .NET and Microsoft Windows; >
2008-06-14 03:43:27 0 d-------- C:\Program Files\shaderbin
2008-06-14 03:37:47 0 d-------- C:\Program Files\res
2008-06-14 03:37:36 0 d-------- C:\Program Files\music
2008-06-14 03:37:35 0 d-------- C:\Program Files\GameGuard
2008-06-14 03:37:32 218112 --a------ C:\Program Files\wmasf.dll <Not Verified; Microsoft Corporation; Microsoft® Windows Media Services>
2008-06-14 03:37:32 4 --a------ C:\Program Files\version.dat
2008-06-14 03:37:32 7536640 --a------ C:\Program Files\rohanclient.exe <Not Verified; YNK Games; Rohan>
2008-06-14 03:37:32 53248 --a------ C:\Program Files\npkpdb.dll <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Program Database DLL>
2008-06-14 03:37:32 37009 --a------ C:\Program Files\npkcusb.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
2008-06-14 03:37:32 34978 --a------ C:\Program Files\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
2008-06-14 03:37:32 467024 --a------ C:\Program Files\npkcrypt.dll <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver Support Dll>
2008-06-14 03:37:32 0 d-------- C:\Program Files\data
2008-06-14 03:37:31 118784 --a------ C:\Program Files\MakeReg.exe
2008-06-14 03:37:31 24576 --a------ C:\Program Files\Loader.exe <Not Verified; ; Loader ?? ????>
2008-06-14 03:37:31 460 --a------ C:\Program Files\Loader.dat
2008-06-14 03:37:31 856064 --a------ C:\Program Files\libeay32.dll
2008-06-14 03:37:31 5537792 --a------ C:\Program Files\Launcher.dll <Not Verified; Geomind; Launcher DLL>
2008-06-14 03:37:31 30208 --a------ C:\Program Files\gouninstusa.exe
2008-06-13 23:55:03 0 d-------- C:\Program Files\Hide My IP 2008
2008-06-11 22:08:07 0 d-------- C:\Shiz
2008-06-11 17:31:04 0 d-------- C:\Program Files\Microsoft Device Emulator
2008-06-11 17:30:55 0 d-------- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2008-06-11 17:15:45 0 d-------- C:\WINDOWS\Symbols
2008-06-11 17:15:45 0 d-------- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
2008-06-11 17:15:44 0 d-------- C:\Program Files\Common Files\Business Objects
2008-06-11 17:15:44 0 d-------- C:\Program Files\CE Remote Tools
2008-06-09 16:18:03 0 d-------- C:\Program Files\MSDN
2008-06-09 16:14:30 96896 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
2008-06-09 16:14:29 0 d-------- C:\Program Files\MagicDisc
2008-06-09 16:10:37 0 d-------- C:\Program Files\MagicISO
2008-06-09 15:14:16 0 d-------- C:\Program Files\LimeWire
2008-06-09 12:39:40 0 d-------- C:\Program Files\Microsoft.NET
2008-06-09 04:27:04 0 d-------- C:\Program Files\HTML Help Workshop
2008-06-09 04:27:03 0 d-------- C:\Program Files\Common Files\Merge Modules
2008-06-09 04:27:03 0 d-------- C:\Program Files\Common Files\Crystal Decisions
2008-06-09 04:25:41 0 d-------- C:\Program Files\Microsoft Visual Studio .NET 2003
2008-06-08 01:04:15 0 d-------- C:\Program Files\Steam
2008-06-07 01:19:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mount&Blade
2008-06-07 01:18:35 0 d-------- C:\Mount&Blade
2008-06-05 00:18:11 252 --a------ C:\uxthemepatch.cmd
2008-06-03 00:59:55 64 --a------ C:\WINDOWS\system32\system.bat
2008-06-03 00:59:55 146 --a------ C:\WINDOWS\system32\syssvr.bat
2008-06-03 00:59:55 114 --a------ C:\WINDOWS\system32\drivers\config.sys
2008-06-01 23:39:51 0 d-------- C:\Program Files\Gamescampus
2008-06-01 02:08:54 0 d-------- C:\Program Files\dbh Studios
2008-05-31 02:19:42 0 d-------- C:\Program Files\Indianboy 2007 Present Discord Times Precracked Full version
2008-05-31 01:49:57 0 d-------- C:\Program Files\ReflexiveArcade
2008-05-29 00:48:26 0 d-------- C:\Documents and Settings\Administrator\.unlimitedftp
2008-05-28 00:45:42 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-27 18:40:19 0 d-------- C:\Documents and Settings\Administrator\Application Data\Dev-Cpp
2008-05-27 18:38:42 0 d-------- C:\Dev-Cpp
2008-05-26 23:15:57 73728 --a------ C:\WINDOWS\system32\GkSui18.EXE
2008-05-26 23:15:56 0 d-------- C:\Program Files\GameWiz32
2008-05-24 22:45:31 0 d-------- C:\Program Files\vbSkinner Free 2
2008-05-24 22:45:27 197120 -----n--- C:\WINDOWS\Setup1.exe <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Windows>
2008-05-24 22:45:26 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-05-24 01:10:23 0 d-------- C:\Program Files\PTDD Group
2008-05-23 23:03:04 11 --a------ C:\WINDOWS\epmbcd
2008-05-23 22:21:13 0 d-------- C:\Program Files\EASEUS
2008-05-23 21:33:16 14976 --a------ C:\WINDOWS\system32\drivers\SBKUPNT.SYS
2008-05-23 21:33:16 13312 --a------ C:\WINDOWS\system32\DEVLOAD.EXE
2008-05-23 21:24:46 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-05-23 18:49:33 0 d-------- C:\Documents and Settings\Administrator\Application Data\InfraRecorder
2008-05-23 18:49:27 0 d-------- C:\Program Files\InfraRecorder
2008-05-22 19:49:04 0 d-------- C:\WINDOWS\.silabclient_store_32
2008-05-22 17:25:40 1 --a------ C:\Documents and Settings\Administrator\SI.bin
2008-05-22 16:48:07 0 d-------- C:\WINDOWS\system32\NtmsData
2008-05-21 22:20:53 0 d-------- C:\Program Files\Microsoft Virtual PC
2008-05-21 19:33:35 0 d-------- C:\Program Files\Hushpage
2008-05-21 19:10:18 0 d-------- C:\WINDOWS\.mpr_file_store_32
2008-05-21 19:10:06 0 d-------- C:\Program Files\MoparScape
2008-05-21 19:01:26 106496 --a------ C:\WINDOWS\system\kernel.exe <Not Verified; Microsoft Corporation; Kernel>
2008-05-21 18:58:26 1034859 --a------ C:\WINDOWS\system32\woblist.dll
2008-05-20 00:38:45 0 d-------- C:\Program Files\SoftwarePassport
2008-05-19 23:57:03 0 d-------- C:\FGCDIR
2008-05-19 23:21:31 0 d-------- C:\Program Files\Fortres Grand
2008-05-19 22:08:04 0 d-------- C:\Documents and Settings\Administrator\Application Data\VMware
2008-05-19 21:50:17 0 d-------- C:\Documents and Settings\Default User\Application Data\VMware
2008-05-19 21:48:48 0 d-------- C:\Documents and Settings\All Users\Application Data\VMware
2008-05-19 21:43:49 163840 --a------ C:\WINDOWS\system32\windowsupdater68367892376.exe <Not Verified; Pre-Instinct® Software; Server>
2008-05-18 23:02:31 0 d-------- C:\Program Files\NCSoft
2008-05-18 15:18:44 61440 --a------ C:\WINDOWS\system\WanPacket.dll <Not Verified; CACE Technologies; WinPcap low level NetMon wrapper library>
2008-05-18 15:18:41 61440 --a------ C:\WINDOWS\system32\WanPacket.dll <Not Verified; CACE Technologies; WinPcap low level NetMon wrapper library>
2008-05-18 15:14:23 225280 --a------ C:\WINDOWS\system32\wpcap.dll <Not Verified; NetGroup - Politecnico di Torino; WinPcap high level library>
2008-05-17 18:46:23 0 d-------- C:\Documents and Settings\Administrator\Application Data\GetRightToGo
-- Find3M Report ---------------------------------------------------------------
2008-06-17 16:48:28 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-17 01:09:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Xfire
2008-06-17 00:57:49 32 --a------ C:\WINDOWS\go
2008-06-17 00:55:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-06-16 23:56:14 0 d-------- C:\Program Files\FlashGet
2008-06-16 20:33:04 0 d-------- C:\Program Files\Java
2008-06-16 20:32:25 0 d-------- C:\Program Files\Common Files
2008-06-16 16:15:29 0 d-------- C:\Program Files\lx_cats
2008-06-15 02:35:13 204 --a------ C:\Program Files\Option.cfg
2008-06-15 02:35:13 796 --a------ C:\Program Files\3116037.set
2008-06-12 23:43:25 0 d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-06-11 17:07:24 0 d-------- C:\Program Files\PeerGuardian2
2008-06-10 16:49:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\mIRC
2008-06-10 16:43:14 0 d-------- C:\Program Files\mIRC
2008-06-09 20:11:38 0 d-------- C:\Program Files\Xfire
2008-06-07 02:29:03 0 d-------- C:\Program Files\Cheat Engine
2008-06-06 00:42:21 0 d-------- C:\Program Files\PDF Reader 2
2008-05-24 01:10:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-23 18:47:12 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-22 17:20:40 0 d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-22 17:15:56 0 d-------- C:\Program Files\Funcom
2008-05-14 19:21:34 0 d-------- C:\Documents and Settings\Administrator\Application Data\Screaming Bee
2008-05-14 19:19:00 0 d-------- C:\Program Files\Common Files\Screaming Bee
2008-05-14 19:18:07 0 d-------- C:\Program Files\Screaming Bee
2008-05-13 15:53:01 0 d-------- C:\Program Files\Common Files\Bcgsoft
2008-05-13 15:50:07 0 d-------- C:\Program Files\The Game Creators
2008-05-09 19:16:54 0 d-------- C:\Program Files\OGPlanet
2008-05-08 23:16:46 0 d-------- C:\Program Files\Microsoft Synchronization Services
2008-05-08 23:16:46 0 d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-08 23:12:20 0 d-------- C:\Program Files\Microsoft SDKs
2008-05-06 00:04:07 0 d-------- C:\Documents and Settings\Administrator\Application Data\Easy Macro Recorder
2008-05-04 19:11:03 0 d-------- C:\Program Files\ArtMoney
2008-05-03 01:14:55 0 d-------- C:\Program Files\Workspace Macro Pro 6.5
2008-05-02 18:57:58 0 d-------- C:\Program Files\ZD Soft
2008-04-29 22:44:01 0 d-------- C:\Program Files\Silkroad
2008-04-26 13:58:25 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-04-25 16:05:49 0 d-------- C:\Program Files\Vstplugins
2008-04-25 16:05:36 0 d-------- C:\Program Files\Sony
2008-04-25 15:58:42 0 d-------- C:\Program Files\MSBuild
2008-04-25 15:54:02 0 d-------- C:\Program Files\Reference Assemblies
2008-04-25 15:50:50 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sony Setup
2008-04-22 15:19:40 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-21 22:30:44 0 d-------- C:\Program Files\Common Files\TechSmith Shared
2008-04-21 22:30:40 0 d-------- C:\Program Files\TechSmith
2008-04-20 20:48:15 0 d-------- C:\Program Files\World of Warcraft
2008-04-20 16:12:13 0 d-------- C:\Program Files\MAIET
2008-04-20 00:02:00 7711 --a------ C:\Program Files\UnInstall_24318.txt
2008-04-20 00:01:56 0 d-------- C:\Program Files\Super Saiyan
2008-04-19 21:00:05 0 d-------- C:\Program Files\LittleFighter2
2008-04-19 01:38:52 0 d-------- C:\Program Files\InnerSpace
2008-04-18 22:29:59 72192 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2008-04-17 18:57:14 0 d-------- C:\Program Files\MSXML 4.0
2008-03-23 04:08:17 17920 --a------ C:\WINDOWS\system32\sophosboottasks.exe <Not Verified; Sophos Plc; Sophos Anti-Virus>
2008-03-22 16:11:42 98304 --a------ C:\WINDOWS\system32CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42A70D2D-3F1A-4061-B18A-FC1A5ACD44AA}]
C:\WINDOWS\system32\ssqPgDUK.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E707216F-6AFF-4BD4-962D-EC5CDBA812A1}]
06/15/2008 02:55 58368 --a------ C:\WINDOWS\system32\yayyApNe.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 15:42]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 01:41]
"LXCYCATS"="C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [02/24/2006 07:54]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 01:41]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [12/10/2007 14:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [02/13/2008 19:09]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"WGETMO"=C:\WINDOWS\SYSTEM32\WGETMO.EXE
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [6/9/2008 4:14:29 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [3/23/2008 4:59:22 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ShowSuperHidden"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E707216F-6AFF-4BD4-962D-EC5CDBA812A1}"= C:\WINDOWS\system32\yayyApNe.dll [06/15/2008 02:55 58368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
dimsntfy.dll 02/17/2007 03:50 19456 C:\WINDOWS\system32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FGWLNotify]
C:\Program Files\Fortres Grand\Fortres Security Runtime 6.0\FGWLNotify.dll 04/11/2006 11:29 69632 C:\Program Files\Fortres Grand\Fortres Security Runtime 6.0\FGWLNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayyApNe]
yayyApNe.dll 06/15/2008 02:55 58368 C:\WINDOWS\system32\yayyApNe.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlJYqQHw
"Notification Packages"= RASSFM KDCSVC WDIGEST scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Home Server.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Home Server.lnk
backup=C:\WINDOWS\pss\Windows Home Server.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cam]
C:\WINDOWS\camdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\camdrvs]
C:\Winnt\camdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
"C:\Program Files\Lexmark 3400 Series\ezprint.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\Documents and Settings\Administrator\Desktop\Test.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcymon.exe]
"C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDM Agent]
C:\Program Files\PDM\PDM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchAndDestroyT]
C:\Program Files\Search And Destroy\SearchAndDestroy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"c:\program files\steam\steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
%systemroot%\system32\dumprep 0 -u
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"fsrt"=2 (0x2)
"lanmanserver"=2 (0x2)
"lxcy_device"=3 (0x3)
"idsvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService Alerter WebClient LmHosts WinHttpAutoProxySvc W32Time
NetworkService 6to4 DHCP DnsCache
WinErr ERsvc
tapisrv Tapisrv
regsvc RemoteRegistry
swprv swprv
DcomLaunch DcomLaunch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Sacsvr
Schedule
Seclogon
Themes
TrkWks
TrkSvr
W32Time
Wmi
WmdmPmSp
winmgmt
wuauserv
BITS
ShellHWDetection
uploadmgr
xmlprov
AeLookupSvc
helpsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f63bd39-f4ba-11d8-8787-00111166bb1d}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \WIP\CMD\go.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{988ae6bf-ecc9-11dc-9fe6-00111166bb1d}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL \WIP\CMD\go.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36BBA8D2-CA5C-4847-81CC-4F807DD86C91}]
%SystemRoot%\system32\regsvr32.exe /s /n /i:IEUpdateUser urlmon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6D69F546-C1AF-4049-AE9E-28627B91D3F5}]
%SystemRoot%\system32\regsvr32.exe /s /n /i:IEUpdateAdmin urlmon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}]
%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenAdmin
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}]
%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenUser
-- End of Deckard's System Scanner: finished at 2008-06-17 18:35:37 ------------