Deckard's System Scanner v20071014.68
Run by Jay on 2008-07-02 16:33:35
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-07-02 20:33:42 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Jay.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:36:07 PM, on 7/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Jay\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Jay.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {78E42A3F-B9A2-47A4-89DB-D63FD4CDD14D} - (no file)
O2 - BHO: (no name) - {EAECE85D-1DC7-4ED9-ACB7-D30DE973EAA7} - C:\WINDOWS\system32\geBuSKDT.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\tknepbmf.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Shortcut to KEYHOLD.lnk = C:\Program Files\HOLDMYREALKEY\KEYHOLD.exe
O4 - Startup: Shortcut to StealthBot v2.6R3.lnk = C:\Program Files\StealthBot\StealthBot v2.6R3.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1211919850811O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zon...er.cab56986.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8784 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080627-203628-782 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080627-203629-299 O20 - Winlogon Notify: xxywVoLe - C:\WINDOWS\SYSTEM32\xxywVoLe.dll
backup-20080627-203629-529 O2 - BHO: {c149ec7e-d997-2868-6334-d38d6b1cf93c} - {c39fc1b6-d83d-4336-8682-799de7ce941c} - C:\WINDOWS\system32\baqcyw.dll
backup-20080627-203629-545 O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\tbukrcbu.dll",s
backup-20080627-203629-551 O4 - HKLM\..\Run: [cc4ef04b] rundll32.exe "C:\WINDOWS\system32\gqdtcyfx.dll",b
backup-20080627-203629-574 O2 - BHO: (no name) - {ACED1C9F-2718-4512-9F69-F4E28C1F484F} - C:\WINDOWS\system32\xxywVoLe.dll
backup-20080627-203629-750 O2 - BHO: (no name) - {53F27B08-B1B7-42CE-A6BC-3988D91E9B11} - C:\WINDOWS\system32\wvUmMEur.dll
backup-20080627-203629-751 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080627-203629-882 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080627-203741-411 O20 - Winlogon Notify: xxywVoLe - C:\WINDOWS\SYSTEM32\xxywVoLe.dll
backup-20080627-205012-352 O2 - BHO: (no name) - {53F27B08-B1B7-42CE-A6BC-3988D91E9B11} - (no file)
backup-20080628-011950-522 O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\rweusnat.dll",s
backup-20080628-011950-947 O4 - HKLM\..\Run: [cc4ef04b] rundll32.exe "C:\WINDOWS\system32\ofqrysyi.dll",b
backup-20080628-012105-899 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
backup-20080629-004757-132 O2 - BHO: (no name) - {F03081EF-9785-4A20-91CA-88B6C741FF17} - C:\WINDOWS\system32\geBuSKDT.dll
backup-20080629-004757-206 O2 - BHO: (no name) - {ACED1C9F-2718-4512-9F69-F4E28C1F484F} - C:\WINDOWS\system32\xxywVoLe.dll
backup-20080629-004757-380 O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\eslxafln.dll",s
backup-20080629-004757-462 O2 - BHO: (no name) - {435F1A75-04A7-497D-988B-E4F5B70C88C3} - (no file)
backup-20080629-004757-640 O20 - Winlogon Notify: xxywVoLe - C:\WINDOWS\SYSTEM32\xxywVoLe.dll
backup-20080629-004757-647 O4 - HKLM\..\Run: [cc4ef04b] rundll32.exe "C:\WINDOWS\system32\ompneoee.dll",b
backup-20080629-004757-662 O2 - BHO: (no name) - {AC473988-1940-40D6-B350-A6EF26981ED6} - C:\WINDOWS\system32\ivvfdjea.dll
backup-20080629-004757-852 O2 - BHO: (no name) - {DE6EF1A9-9BBF-4BB7-B678-80D98FDF5CC1} - C:\WINDOWS\system32\tuvwUMDU.dll (file missing)
backup-20080630-191753-101 O20 - Winlogon Notify: xxywVoLe - xxywVoLe.dll (file missing)
backup-20080630-191753-287 O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\tknepbmf.dll",s
backup-20080630-191753-643 O2 - BHO: (no name) - {ACED1C9F-2718-4512-9F69-F4E28C1F484F} - C:\WINDOWS\system32\xxywVoLe.dll (file missing)
backup-20080630-191753-891 O2 - BHO: (no name) - {F03081EF-9785-4A20-91CA-88B6C741FF17} - (no file)
backup-20080630-191838-784 O2 - BHO: (no name) - {1AD42469-31B7-42F7-AD55-5250A95A92D5} - C:\WINDOWS\system32\geBuSKDT.dll
backup-20080630-191900-835 O2 - BHO: (no name) - {1AD42469-31B7-42F7-AD55-5250A95A92D5} - C:\WINDOWS\system32\geBuSKDT.dll
backup-20080630-210123-124 O2 - BHO: (no name) - {52081714-93E0-48FF-B15F-38303664F2B2} - (no file)
backup-20080630-210123-613 O2 - BHO: (no name) - {1AD42469-31B7-42F7-AD55-5250A95A92D5} - (no file)
backup-20080630-210123-904 O4 - HKLM\..\Run: [BMcf7dc3d7] Rundll32.exe "C:\WINDOWS\system32\tknepbmf.dll",s
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 ATITool (ATITool Overclocking Utility) - c:\windows\system32\drivers\atitool.sys <Not Verified; ; Low-Level Driver>
R3 MTsensor (ATK0110 ACPI UTILITY) - c:\windows\system32\drivers\asacpi.sys <Not Verified; ; ATK0110 ACPI Utility>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not Verified; Prolific Technology Inc.; IoctlSvc Application>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID:
Description:
Device ID: DISPLAY\NTATIVRV01\5&1AA089F0&0&80000008&01&00
Manufacturer:
Name:
PNP Device ID: DISPLAY\NTATIVRV01\5&1AA089F0&0&80000008&01&00
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-06-02 15:29:59 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-06-02 and 2008-07-02 -----------------------------
2008-07-02 02:35:22 81408 --a------ C:\WINDOWS\system32\ablyhrwm.dll
2008-07-02 02:33:23 103424 --a------ C:\WINDOWS\system32\drjtxl.dll
2008-07-02 02:33:21 103424 --a------ C:\WINDOWS\system32\hiabjous.dll
2008-07-02 02:33:13 90624 --a------ C:\WINDOWS\system32\gtpcpxrs.dll
2008-06-30 21:05:45 0 d-------- C:\VundoFix Backups
2008-06-30 19:16:07 81920 --a------ C:\WINDOWS\system32\icwgoxna.dll
2008-06-30 19:14:06 103424 --a------ C:\WINDOWS\system32\aopejj.dll
2008-06-30 19:14:05 103424 --a------ C:\WINDOWS\system32\ucdhhhme.dll
2008-06-30 19:13:57 91136 --a------ C:\WINDOWS\system32\tknepbmf.dll
2008-06-29 00:50:16 0 d-------- C:\!KillBox
2008-06-28 02:35:46 529113 --ahs---- C:\WINDOWS\system32\TDKSuBeg.ini2
2008-06-28 02:35:40 319488 -----n--- C:\WINDOWS\system32\geBuSKDT.dll
2008-06-28 00:49:45 529445 --ahs---- C:\WINDOWS\system32\UDMUwvut.ini2
2008-06-27 23:19:43 529981 --ahs---- C:\WINDOWS\system32\SvFLlUtv.ini2
2008-06-27 20:32:56 0 d-------- C:\Program Files\Trend Micro
2008-06-27 20:29:13 0 d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-06-27 20:29:05 0 d-------- C:\Program Files\Security Task Manager
2008-06-27 19:59:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-27 19:54:30 0 d-------- C:\Program Files\MSXML 4.0
2008-06-26 15:40:03 531519 --ahs---- C:\WINDOWS\system32\ruEMmUvw.ini2
2008-06-26 15:22:44 0 d-------- C:\Documents and Settings\Jay\Application Data\Nero
2008-06-26 15:17:50 0 d-------- C:\Program Files\Nero
2008-06-26 15:17:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-26 15:17:49 0 d-------- C:\Program Files\Common Files\Nero
2008-06-26 15:08:13 0 d-------- C:\WINDOWS\CAVTemp
2008-06-26 14:40:34 0 d-------- C:\Program Files\Total Video Converter
2008-06-25 13:49:11 0 dr-h----- C:\Documents and Settings\Jay\Recent
2008-06-25 11:50:39 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-24 21:11:10 0 d-------- C:\Program Files\CCleaner
2008-06-24 21:09:46 0 d-------- C:\Program Files\Yahoo!
2008-06-22 20:37:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-06-22 20:37:07 0 d-------- C:\Program Files\Common Files\Adobe
2008-06-21 00:18:15 0 d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-06-21 00:18:13 0 d-------- C:\Program Files\CA
2008-06-20 13:21:20 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-06-20 13:21:20 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-06-20 13:21:20 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-06-20 13:21:20 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-06-20 13:21:20 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-06-20 13:21:20 1835008 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-06-20 13:21:20 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-06-20 13:21:20 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-06-20 13:21:20 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-06-20 13:21:20 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-06-20 13:21:20 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-06-20 13:21:20 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-06-20 13:21:20 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-06-20 13:21:20 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-06-20 13:18:59 0 d--hs---- C:\WINDOWS\CSC
2008-06-16 21:07:03 0 d-------- C:\Documents and Settings\Jay\Application Data\Audacity
2008-06-16 21:06:52 0 d-------- C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-06-16 21:03:37 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-06-16 20:58:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Macrium
2008-06-16 20:57:40 0 d-------- C:\Program Files\Macrium
2008-06-16 20:56:36 0 d-------- C:\WINDOWS\system32\appmgmt
2008-06-14 19:20:11 0 d-------- C:\Program Files\ATITool
2008-06-10 23:28:08 0 d-------- C:\WINDOWS\Sun
2008-06-10 20:25:52 0 d-------- C:\Documents and Settings\All Users\Application Data\JCreator
2008-06-10 20:25:51 0 d-------- C:\Documents and Settings\Jay\Application Data\JCreator
2008-06-10 20:21:36 0 d-------- C:\Program Files\Xinox Software
2008-06-10 20:21:09 0 d-------- C:\Documents and Settings\Jay\.SunDownloadManager
2008-06-10 18:44:14 1970176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-06-10 18:44:14 679936 --a------ C:\WINDOWS\system32\D3DX81ab.dll <Not Verified; Generated by JEDI; D3DX81>
2008-06-10 18:44:13 0 d-------- C:\Program Files\Cheat Engine
2008-06-08 19:23:39 0 d-------- C:\Program Files\HOLDMYREALKEY
2008-06-07 13:01:04 0 d-------- C:\Program Files\RocketDock
2008-06-02 17:02:05 0 d-------- C:\Documents and Settings\Jay\Application Data\vlc
2008-06-02 17:00:53 0 d-------- C:\Program Files\VideoLAN
2008-06-02 15:29:55 0 d-------- C:\Program Files\Apple Software Update
-- Find3M Report ---------------------------------------------------------------
2008-07-02 02:32:04 0 d-------- C:\Program Files\Warcraft III
2008-06-30 20:32:16 0 d-------- C:\Program Files\Messenger
2008-06-30 20:32:15 0 d-------- C:\Program Files\FrostWire
2008-06-30 20:24:45 77514 --a------ C:\WINDOWS\War3Unin.dat
2008-06-27 16:05:06 0 d-------- C:\Documents and Settings\Jay\Application Data\Azureus
2008-06-26 15:17:49 0 d-------- C:\Program Files\Common Files
2008-06-22 20:58:00 0 d-------- C:\Documents and Settings\Jay\Application Data\Adobe
2008-06-22 18:50:45 0 d-------- C:\Program Files\Steam
2008-06-19 18:40:04 0 d-------- C:\Program Files\Azureus
2008-06-09 18:25:26 0 d-------- C:\Documents and Settings\Jay\Application Data\Ventrilo
2008-06-08 19:31:41 0 d-------- C:\Program Files\StealthBot
2008-06-02 16:56:29 0 d-------- C:\Documents and Settings\Jay\Application Data\Apple Computer
2008-06-01 22:23:53 0 d-------- C:\Documents and Settings\Jay\Application Data\FrostWire
2008-05-31 12:42:50 0 d-------- C:\Program Files\VentSrv
2008-05-31 12:39:03 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-29 23:33:35 0 d-------- C:\Documents and Settings\Jay\Application Data\Logitech
2008-05-29 23:29:32 0 d-------- C:\Program Files\Common Files\Logitech
2008-05-29 23:29:20 0 d-------- C:\Program Files\Logitech
2008-05-29 23:29:19 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-28 02:24:57 0 d-------- C:\Program Files\Microsoft Works
2008-05-28 02:24:42 0 d-------- C:\Program Files\MSBuild
2008-05-28 02:23:14 0 d-------- C:\Program Files\Microsoft.NET
2008-05-28 02:20:53 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-27 22:52:09 0 d-------- C:\Documents and Settings\Jay\Application Data\Macromedia
2008-05-27 21:16:29 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-27 20:47:51 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-05-27 20:47:51 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-05-27 20:30:20 0 d-------- C:\Program Files\Java
2008-05-27 20:15:49 0 d-------- C:\Program Files\Creative
2008-05-27 20:15:07 0 d-------- C:\Program Files\Analog Devices
2008-05-27 20:07:26 0 d-------- C:\Program Files\WinPcap
2008-05-27 20:00:29 0 d-------- C:\Program Files\Common Files\Java
2008-05-27 19:59:23 0 d-------- C:\Documents and Settings\Jay\Application Data\Sun
2008-05-27 19:51:29 0 d-------- C:\Program Files\iTunes
2008-05-27 19:41:24 0 d-------- C:\Program Files\Ventrilo
2008-05-27 18:37:45 4212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2008-05-27 18:31:05 0 d-------- C:\Documents and Settings\Jay\Application Data\ViStart
2008-05-27 18:25:05 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-27 18:24:13 0 d-------- C:\Documents and Settings\Jay\Application Data\WinRAR
2008-05-27 18:15:00 0 d-------- C:\Program Files\Windows Live
2008-05-27 18:14:45 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-27 18:03:55 0 d-------- C:\Program Files\iPod
2008-05-27 18:03:38 0 d-------- C:\Program Files\Bonjour
2008-05-27 18:03:33 0 d-------- C:\Program Files\QuickTime
2008-05-27 18:02:40 0 d-------- C:\Program Files\Common Files\Apple
2008-05-27 18:00:52 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-27 18:00:51 0 d-------- C:\Documents and Settings\Jay\Application Data\Mozilla
2008-05-27 17:50:34 0 d-------- C:\Program Files\Movie Maker
2008-05-27 17:48:13 0 d-------- C:\Program Files\Windows NT
2008-05-27 17:15:56 0 d-------- C:\Program Files\Marvell
2008-05-27 17:14:43 0 d-------- C:\Documents and Settings\Jay\Application Data\Identities
2008-05-27 17:10:11 0 d-------- C:\Program Files\microsoft frontpage
2008-05-27 17:09:50 0 -rahs---- C:\MSDOS.SYS
2008-05-27 17:09:50 0 -rahs---- C:\IO.SYS
2008-05-27 17:09:50 0 --a------ C:\CONFIG.SYS
2008-05-27 17:09:50 0 --a------ C:\AUTOEXEC.BAT
2008-05-27 17:08:48 0 d-------- C:\Program Files\Online Services
2008-05-27 17:07:43 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-27 17:07:17 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-27 17:06:42 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-27 16:26:01 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-27 16:22:39 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-27 16:18:43 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-27 16:17:08 0 d-------- C:\Documents and Settings\Jay\Application Data\MSN6
2008-05-27 16:16:53 0 d-------- C:\Program Files\Intel
2008-05-27 12:02:10 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-27 12:02:07 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-27 12:01:41 62 --ahs---- C:\Documents and Settings\Jay\Application Data\desktop.ini
2008-05-12 11:49:00 593920 --a------ C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{78E42A3F-B9A2-47A4-89DB-D63FD4CDD14D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EAECE85D-1DC7-4ED9-ACB7-D30DE973EAA7}]
06/28/2008 02:35 AM 319488 --------- C:\WINDOWS\system32\geBuSKDT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [05/03/2005 07:38 AM C:\WINDOWS\system32\P17.dll]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [05/11/2000 02:00 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/29/2008 12:37 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [04/02/2008 10:07 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [08/16/2007 10:25 PM]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [08/20/2007 01:42 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"BMcf7dc3d7"="C:\WINDOWS\system32\tknepbmf.dll" [06/30/2008 07:13 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 12:34 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 08:12 PM]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [09/02/2007 01:58 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
C:\Documents and Settings\Jay\Start Menu\Programs\Startup\
Shortcut to KEYHOLD.lnk - C:\Program Files\HOLDMYREALKEY\KEYHOLD.exe [6/8/2008 7:24:08 PM]
Shortcut to StealthBot v2.6R3.lnk - C:\Program Files\StealthBot\StealthBot v2.6R3.exe [4/19/2005 12:53:30 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [5/29/2008 11:29:24 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geBuSKDT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jay^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Jay\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMcf7dc3d7]
Rundll32.exe "C:\WINDOWS\system32\tbukrcbu.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViStart]
C:\Program Files\ViStart\ViStart
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8756 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-07-02 16:45:59 ------------