hello again,
here is the DSS log:
Deckard's System Scanner v20071014.68
Run by rhona gilmore ltd on 2008-06-30 17:05:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Drive C: has 4.74 GiB (less than 15%) free.-- HijackThis (run as rhona gilmore ltd.exe) -----------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:05:12, on 30/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\rhona gilmore ltd\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\RHONAG~1.EXE
C:\WINDOWS\system32\taskmgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0E64E841-2463-47C9-8797-DAF2810BBF61} - C:\WINDOWS\system32\awtqqqnm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: (no name) - {BCBABB03-A1B9-40A0-BA0D-1E09DBE1103B} - C:\WINDOWS\system32\rqRJBQKB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebo...toUploader5.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zon...kr.cab56986.cabO16 - DPF: {38D63471-E630-4492-A986-B8C48B79F2F8} (CVideoEgg_ActiveXCtl Object) -
http://update.videoe...ggPublisher.exeO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail....es/MSNPUpld.cabO16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zon...1/GAME_UNO1.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1139563373171O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab31267.cabO16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) -
http://dlm.tools.aka...vex-2.2.1.6.cabO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: awtqqqnm - C:\WINDOWS\SYSTEM32\awtqqqnm.dll
O20 - Winlogon Notify: winxtx32 - C:\WINDOWS\SYSTEM32\winxtx32.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
--
End of file - 11502 bytes
-- Files created between 2008-05-30 and 2008-06-30 -----------------------------
2008-06-30 12:55:33 0 d-------- C:\Program Files\Sun
2008-06-30 12:43:13 0 d-------- C:\Documents and Settings\rhona gilmore ltd\.SunDownloadManager
2008-06-28 10:27:35 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\ATI
2008-06-26 21:47:44 0 d-------- C:\fsc.tmp
2008-06-26 16:32:04 0 d-------- C:\Program Files\Trend Micro
2008-06-26 15:41:56 0 d-------- C:\ATI
2008-06-26 15:06:23 0 dr-h----- C:\Documents and Settings\Administrator.FS-PC\SendTo
2008-06-26 15:06:23 0 dr-h----- C:\Documents and Settings\Administrator.FS-PC\Recent
2008-06-26 15:06:23 0 d--h----- C:\Documents and Settings\Administrator.FS-PC\PrintHood
2008-06-26 15:06:23 0 d--h----- C:\Documents and Settings\Administrator.FS-PC\NetHood
2008-06-26 15:06:23 0 dr------- C:\Documents and Settings\Administrator.FS-PC\My Documents
2008-06-26 15:06:23 0 d--h----- C:\Documents and Settings\Administrator.FS-PC\Local Settings
2008-06-26 15:06:23 0 dr------- C:\Documents and Settings\Administrator.FS-PC\Favorites
2008-06-26 15:06:23 0 d-------- C:\Documents and Settings\Administrator.FS-PC\Desktop
2008-06-26 15:06:23 0 d--hs---- C:\Documents and Settings\Administrator.FS-PC\Cookies
2008-06-26 15:06:23 0 dr-h----- C:\Documents and Settings\Administrator.FS-PC\Application Data
2008-06-26 15:06:23 0 d---s---- C:\Documents and Settings\Administrator.FS-PC\Application Data\Microsoft
2008-06-26 15:06:23 0 d-------- C:\Documents and Settings\Administrator.FS-PC\Application Data\Identities
2008-06-26 15:06:22 0 d--h----- C:\Documents and Settings\Administrator.FS-PC\Templates
2008-06-26 15:06:22 0 dr------- C:\Documents and Settings\Administrator.FS-PC\Start Menu
2008-06-26 15:06:22 786432 --ah----- C:\Documents and Settings\Administrator.FS-PC\NTUSER.DAT
2008-06-26 14:09:39 96966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-26 14:09:39 88774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-26 14:08:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-06-26 14:03:45 3967520 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-26 14:03:45 0 d-------- C:\Program Files\Kaspersky Lab
2008-06-26 14:03:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-26 14:02:58 45856 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-26 13:55:18 0 d-------- C:\KAV
2008-06-26 13:28:08 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\Antivirus2008y
2008-06-26 12:31:58 0 d-------- C:\Documents and Settings\Administrator\Local Settings
2008-06-26 12:31:58 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-06-26 12:31:58 0 d-------- C:\Documents and Settings\Administrator\Cookies
2008-06-26 12:31:58 0 d-------- C:\Documents and Settings\Administrator\Application Data
2008-06-26 12:31:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-06-26 12:31:57 0 d-------- C:\Documents and Settings\Administrator\Templates
2008-06-26 12:31:57 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-06-26 02:13:42 8368128 --a------ C:\Documents and Settings\rhona gilmore ltd\ntuser.dat
2008-06-26 02:13:41 233472 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-06-26 02:12:17 581157 --ahs---- C:\WINDOWS\system32\BKQBJRqr.ini2
2008-06-26 02:12:11 285696 --a------ C:\WINDOWS\system32\rqRJBQKB.dll
2008-06-26 02:07:20 32256 --a------ C:\WINDOWS\system32\winxtx32.dll
2008-06-26 02:07:05 34304 --a------ C:\WINDOWS\system32\awtqqqnm.dll
2008-06-11 19:34:15 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\Leadertech
-- Find3M Report ---------------------------------------------------------------
2008-06-30 12:54:53 0 d-------- C:\Program Files\Java
2008-06-27 10:18:17 0 d-------- C:\Program Files\AviSynth 2.5
2008-06-26 22:02:10 0 d-------- C:\Program Files\ATI Technologies
2008-06-26 21:52:59 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-23 15:48:28 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\UseNeXT
2008-05-19 17:11:10 0 d-------- C:\Program Files\Yahoo!
2008-05-10 17:33:27 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\Uniblue
2008-05-10 11:10:23 0 d-------- C:\Documents and Settings\rhona gilmore ltd\Application Data\AdobeUM
2008-05-08 23:37:11 0 d-------- C:\Program Files\Kontiki
2008-05-08 23:37:06 0 d-------- C:\Program Files\Channel4
2008-05-03 19:18:20 0 d-------- C:\Program Files\Red Kawa
2008-05-03 18:49:25 0 d-------- C:\Program Files\Movavi Video Converter 6
2008-05-03 18:45:31 0 d-------- C:\Program Files\Allok MPEG4 Converter
2008-05-03 18:39:06 2368 --a------ C:\WINDOWS\system32\SVKP.sys <Not Verified; AntiCracking; SVKP driver for NT>
2008-05-03 17:30:56 0 d-------- C:\Program Files\LG PC Suite 2
2008-05-03 17:12:49 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-03 17:07:04 0 d-------- C:\Program Files\Common Files
2008-04-18 14:52:38 4 --a------ C:\WINDOWS\vx86036.dat
2008-04-11 23:21:28 42932 --ah----- C:\WINDOWS\system32\mlfcache.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E64E841-2463-47C9-8797-DAF2810BBF61}]
26/06/2008 02:07 34304 --a------ C:\WINDOWS\system32\awtqqqnm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCBABB03-A1B9-40A0-BA0D-1E09DBE1103B}]
26/06/2008 02:12 285696 --a------ C:\WINDOWS\system32\rqRJBQKB.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [13/10/2005 21:05]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [18/03/2005 14:35]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [18/03/2005 14:34]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [23/08/2005 14:47]
"SMSERIAL"="sm56hlpr.exe" [16/09/2005 14:01 C:\WINDOWS\sm56hlpr.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [09/07/2001 10:50]
"PCMService"="C:\Program Files\CyberLink\PowerCinema\PCMService.exe" [28/07/2005 20:02]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25/03/2008 04:28]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [06/06/2005 23:46]
"BigDog303"="C:\WINDOWS\VM303_STI.exe" []
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [26/06/2006 10:46]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [26/06/2006 11:34]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [26/06/2006 11:33]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [28/03/2008 23:37]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/03/2008 10:36]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [23/04/2007 11:23]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [08/02/2008 18:36]
"ATICCC"="c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [12/08/2005 14:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 12:34]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [02/05/2006 15:51]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 13:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [25/07/2007 21:48]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" []
"kdx"="C:\Program Files\Kontiki\KHost.exe" [23/04/2007 11:23]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
C:\Documents and Settings\rhona gilmore ltd\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [18/03/2008 10:47:17]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/04/2008 03:38:16]
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [12/08/2005 14:43:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0E64E841-2463-47C9-8797-DAF2810BBF61}"= C:\WINDOWS\system32\awtqqqnm.dll [26/06/2008 02:07 34304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqqqnm]
awtqqqnm.dll 26/06/2008 02:07 34304 C:\WINDOWS\system32\awtqqqnm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winxtx32]
winxtx32.dll 26/06/2008 02:07 32256 C:\WINDOWS\system32\winxtx32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\rqRJBQKB
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30439a4c-ec36-11db-ace2-0014a540eecc}]
Auto\command- sxs.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{676adeb1-96a9-11dc-adbc-0014a540eecc}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c211c42-97a1-11dc-adbf-0014a540eecc}]
AutoRun\command- E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bae1771c-d8d1-11dc-ae1e-0014a540eecc}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
-- End of Deckard's System Scanner: finished at 2008-06-30 17:18:08 ------------
and i cant seem to run kaspersky online scanner as my java runtime programme keeps on responding with critical failure and says that it cannot be run, and it says that there are several java virtual machines running in the same process caused an error!! So im not sure what to do there..
Thank you