EXTRA.TXT
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlon XP
Percentage of Memory in Use: 42%
Physical Memory (total/avail): 1023.48 MiB / 591.43 MiB
Pagefile Memory (total/avail): 2462 MiB / 1887.46 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1938.35 MiB
C: is Fixed (NTFS) - 48.82 GiB total, 2.71 GiB free.
D: is Fixed (NTFS) - 62.96 GiB total, 0.52 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - ST312002 6AS SCSI Disk Device - 111.79 GiB - 2 partitions
\PARTITION0 - Extended w/Extended Int 13 - 48.82 GiB - C:
\PARTITION1 (bootable) - Installable File System - 62.96 GiB - D:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
FirstRunDisabled is set.
AV: AVG 7.5.526 v7.5.526 (Grisoft)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Disabled:DNA"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="C:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Disabled:QuickTime Player"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Disabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Disabled:avgcc.exe"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Tony\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=TONY-BCDE431F26
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Tony
LOGONSERVER=\\TONY-BCDE431F26
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0a00
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Tony\LOCALS~1\Temp
TMP=C:\DOCUME~1\Tony\LOCALS~1\Temp
USERDOMAIN=TONY-BCDE431F26
USERNAME=Tony
USERPROFILE=C:\Documents and Settings\Tony
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Tony
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
BA Installer --> MsiExec.exe /I{EDA0FFC5-7964-4E2F-9014-693F04695933}
BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
e-tax 2008 --> C:\etax2008\e-tax 2008_uninstall.exe
Haali Media Splitter --> "C:\Program Files\Matroska Pack\haali\uninstall.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
Java 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
LimeWire 4.16.6 --> "C:\Program Files\LimeWire\uninstall.exe"
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Matroska Pack --> C:\Program Files\Matroska Pack\uninstall.exe
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{20110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.1) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
ninemsn Internet Software --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
NVIDIA nForce Utilities --> C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_SSUtilsNT 132 C:\WINDOWS\INF\nvautlml.inf
NVIDIA Windows 2000/XP nForce Drivers --> rundll32.exe C:\WINDOWS\system32\NVNFINST.DLL,NvUninstallCrush
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
VideoLAN VLC media player 0.8.6e --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type5163 / Success
Event Submitted/Written: 07/24/2008 08:25:30 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type5157 / Error
Event Submitted/Written: 07/24/2008 08:20:06 PM
Event ID/Source: 0 / pctsSvc.exe
Event Description:
The service process could not connect to the service controller
Event Record #/Type5154 / Success
Event Submitted/Written: 07/24/2008 05:23:14 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type5132 / Success
Event Submitted/Written: 07/23/2008 01:49:54 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.
Event Record #/Type5106 / Error
Event Submitted/Written: 07/22/2008 02:56:17 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 6.0.2900.2180, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.
Processing media-specific event for [iexplore.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type9753 / Warning
Event Submitted/Written: 07/23/2008 09:30:16 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type9723 / Error
Event Submitted/Written: 07/22/2008 08:00:00 PM
Event ID/Source: 7901 / Schedule
Event Description:
The At21.job command failed to start due to the following error:
%%2147942402
Event Record #/Type9722 / Warning
Event Submitted/Written: 07/22/2008 07:44:56 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type9721 / Error
Event Submitted/Written: 07/22/2008 07:00:00 PM
Event ID/Source: 7901 / Schedule
Event Description:
The At20.job command failed to start due to the following error:
%%2147942402
Event Record #/Type9720 / Error
Event Submitted/Written: 07/22/2008 06:00:00 PM
Event ID/Source: 7901 / Schedule
Event Description:
The At19.job command failed to start due to the following error:
%%2147942402
-- End of Deckard's System Scanner: finished at 2008-07-24 23:29:15 ------------
MAIN.TXT
Deckard's System Scanner v20071014.68
Run by Tony on 2008-07-24 23:27:34
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
72: 2008-07-24 13:27:40 UTC - RP126 - Deckard's System Scanner Restore Point
71: 2008-07-23 05:41:51 UTC - RP125 - System Checkpoint
70: 2008-07-22 04:39:03 UTC - RP124 - System Checkpoint
69: 2008-07-21 04:09:25 UTC - RP123 - System Checkpoint
68: 2008-07-20 03:59:20 UTC - RP122 - System Checkpoint
-- First Restore Point --
1: 2008-04-25 08:47:53 UTC - RP55 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 2.71 GiB (less than 15%) free.-- HijackThis (run as Tony.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:43 PM, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\1rpM33tt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Tony\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Tony.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6AB3A53B-FB1D-413E-9CFF-5B9DCF64EED4} - C:\WINDOWS\system32\iifgEWMc.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Min stor proj. - {FFFFFFFF-D71D-41e4-A699-F506DBD097F0} - msindc.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} (OCXDownloadChecker Control) -
http://211.28.67.144...hecker_8000.cabO16 - DPF: {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} (DownloadFile Control) -
http://211.28.67.144...adFile_8110.cabO20 - Winlogon Notify: iqdoiswq - iqdoiswq.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 5097 bytes
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RAID Controller
Device ID: PCI\VEN_1095&DEV_3112&SUBSYS_61121095&REV_01\4&3B1D9AB8&0&5840
Manufacturer:
Name: RAID Controller
PNP Device ID: PCI\VEN_1095&DEV_3112&SUBSYS_61121095&REV_01\4&3B1D9AB8&0&5840
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_10B7&DEV_9201&SUBSYS_80AB1043&REV_40\4&35344E25&0&0860
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_10B7&DEV_9201&SUBSYS_80AB1043&REV_40\4&35344E25&0&0860
Service:
Class GUID: {4D36E980-E325-11CE-BFC1-08002BE10318}
Description: Floppy disk drive
Device ID: FDC\GENERIC_FLOPPY_DRIVE\4&33BC18FA&0&0
Manufacturer: (Standard floppy disk drives)
Name: Floppy disk drive
PNP Device ID: FDC\GENERIC_FLOPPY_DRIVE\4&33BC18FA&0&0
Service: flpydisk
-- Scheduled Tasks -------------------------------------------------------------
2008-07-24 23:00:10 350 --a------ C:\WINDOWS\Tasks\At24.job
2008-07-24 23:00:01 350 --a------ C:\WINDOWS\Tasks\At48.job
2008-07-24 22:00:10 350 --a------ C:\WINDOWS\Tasks\At23.job
2008-07-24 22:00:02 350 --a------ C:\WINDOWS\Tasks\At47.job
2008-07-24 21:00:01 350 --a------ C:\WINDOWS\Tasks\At46.job
2008-07-24 21:00:00 350 --a------ C:\WINDOWS\Tasks\At22.job
2008-07-24 20:23:34 350 --a------ C:\WINDOWS\Tasks\At21.job
2008-07-24 20:00:01 350 --a------ C:\WINDOWS\Tasks\At45.job
2008-07-24 19:50:53 350 --a------ C:\WINDOWS\Tasks\At19.job
2008-07-24 19:00:10 350 --a------ C:\WINDOWS\Tasks\At20.job
2008-07-24 19:00:01 350 --a------ C:\WINDOWS\Tasks\At44.job
2008-07-24 18:00:01 350 --a------ C:\WINDOWS\Tasks\At43.job
2008-07-24 17:22:30 350 --a------ C:\WINDOWS\Tasks\At15.job
2008-07-24 02:00:10 350 --a------ C:\WINDOWS\Tasks\At3.job
2008-07-24 02:00:02 350 --a------ C:\WINDOWS\Tasks\At27.job
2008-07-24 01:00:10 350 --a------ C:\WINDOWS\Tasks\At2.job
2008-07-24 01:00:01 350 --a------ C:\WINDOWS\Tasks\At26.job
2008-07-24 00:26:01 350 --a------ C:\WINDOWS\Tasks\At25.job
2008-07-23 17:00:10 350 --a------ C:\WINDOWS\Tasks\At18.job
2008-07-23 17:00:01 350 --a------ C:\WINDOWS\Tasks\At42.job
2008-07-23 16:00:10 350 --a------ C:\WINDOWS\Tasks\At17.job
2008-07-23 16:00:01 350 --a------ C:\WINDOWS\Tasks\At41.job
2008-07-23 15:00:10 350 --a------ C:\WINDOWS\Tasks\At16.job
2008-07-23 15:00:01 350 --a------ C:\WINDOWS\Tasks\At40.job
2008-07-23 14:00:01 350 --a------ C:\WINDOWS\Tasks\At39.job
2008-07-19 13:00:01 350 --a------ C:\WINDOWS\Tasks\At38.job
2008-07-19 13:00:00 350 --a------ C:\WINDOWS\Tasks\At14.job
2008-07-19 12:00:01 350 --a------ C:\WINDOWS\Tasks\At37.job
2008-07-19 12:00:00 350 --a------ C:\WINDOWS\Tasks\At13.job
2008-07-19 10:00:01 350 --a------ C:\WINDOWS\Tasks\At35.job
2008-07-19 10:00:00 350 --a------ C:\WINDOWS\Tasks\At11.job
2008-07-13 03:00:01 350 --a------ C:\WINDOWS\Tasks\At28.job
2008-07-13 03:00:00 350 --a------ C:\WINDOWS\Tasks\At4.job
2008-07-08 04:00:01 350 --a------ C:\WINDOWS\Tasks\At29.job
2008-07-08 04:00:00 350 --a------ C:\WINDOWS\Tasks\At5.job
2008-07-04 05:00:01 350 --a------ C:\WINDOWS\Tasks\At30.job
2008-07-04 05:00:00 350 --a------ C:\WINDOWS\Tasks\At6.job
2008-07-03 11:00:01 350 --a------ C:\WINDOWS\Tasks\At36.job
2008-07-03 11:00:00 350 --a------ C:\WINDOWS\Tasks\At12.job
2008-07-03 09:00:02 350 --a------ C:\WINDOWS\Tasks\At34.job
2008-07-03 09:00:00 350 --a------ C:\WINDOWS\Tasks\At10.job
2008-07-03 08:00:01 350 --a------ C:\WINDOWS\Tasks\At33.job
2008-07-03 08:00:00 350 --a------ C:\WINDOWS\Tasks\At9.job
2008-07-03 07:00:01 350 --a------ C:\WINDOWS\Tasks\At32.job
2008-07-03 07:00:00 350 --a------ C:\WINDOWS\Tasks\At8.job
2008-07-03 06:00:01 350 --a------ C:\WINDOWS\Tasks\At31.job
2008-07-03 06:00:00 350 --a------ C:\WINDOWS\Tasks\At7.job
-- Files created between 2008-06-24 and 2008-07-24 -----------------------------
2008-07-24 20:27:07 0 d-------- C:\Program Files\Trend Micro
2008-07-24 20:05:02 0 d-------- C:\Documents and Settings\Tony\Application Data\Malwarebytes
2008-07-24 20:04:58 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-24 20:04:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-24 20:04:40 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-22 20:11:41 35842 --a------ C:\WINDOWS\system32\1rpM33tt.exe
2008-07-17 21:32:25 0 d-------- C:\etax2008
2008-07-14 18:23:17 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-14 18:23:08 0 d-------- C:\Documents and Settings\Tony\Application Data\Mozilla
2008-07-13 18:13:15 0 d-------- C:\Program Files\QuickTime
2008-07-12 15:10:40 32256 --a------ C:\WINDOWS\system32\qf6rxF6J.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-07-06 03:00:42 0 d-------- C:\Program Files\MSXML 4.0
2008-07-06 02:21:51 0 d-------- C:\Documents and Settings\Tony\Application Data\Help
2008-07-05 21:07:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-07-05 20:28:48 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-05 20:28:46 0 d--h----- C:\WINDOWS\$hf_mig$
2008-07-05 20:24:07 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-03 14:00:21 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Macromedia
2008-07-03 14:00:21 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Adobe
2008-07-03 14:00:11 0 dr------- C:\Documents and Settings\NetworkService\Favorites <FAVORI~1>
2008-07-02 19:47:56 29760 --a------ C:\WINDOWS\system32\X73w7ADE.exe
-- Find3M Report ---------------------------------------------------------------
2008-07-24 20:04:40 0 d-------- C:\Program Files\Common Files
2008-07-24 17:22:59 0 d-------- C:\Documents and Settings\Tony\Application Data\AVG7
2008-07-21 21:36:46 0 d-------- C:\Documents and Settings\Tony\Application Data\LimeWire
2008-07-20 22:54:14 0 d-------- C:\Documents and Settings\Tony\Application Data\BitTorrent
2008-07-18 17:15:57 0 d-------- C:\Program Files\Bonjour
2008-07-06 03:06:42 0 d-------- C:\Program Files\Messenger
2008-06-03 01:32:44 0 d-------- C:\Program Files\BitTorrent
2008-06-03 01:05:31 0 d-------- C:\Program Files\Matroska Pack
2008-06-03 00:54:31 0 d-------- C:\Documents and Settings\Tony\Application Data\Media Player Classic
2008-06-03 00:36:58 0 d-------- C:\Program Files\Movkit
2008-06-01 21:01:31 0 d-------- C:\Program Files\Java
2008-05-30 14:59:02 0 d-------- C:\Documents and Settings\Tony\Application Data\Identities
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6AB3A53B-FB1D-413E-9CFF-5B9DCF64EED4}]
C:\WINDOWS\system32\iifgEWMc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFFFFFFF-D71D-41e4-A699-F506DBD097F0}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [03/08/2004 08:32 PM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 08:32 PM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [03/08/2004 08:32 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 09:16 PM]
"nForce Tray Options"="sstray.exe" [13/11/2002 02:34 PM C:\WINDOWS\system32\sstray.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [26/03/2008 11:39 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [19/02/2008 01:10 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [28/06/2008 02:51 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [31/01/2008 11:13 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [03/08/2004 10:56 PM]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [19/01/2007 11:54 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iqdoiswq]
iqdoiswq.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\iifgEWMc
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fc1053fa-f585-11dc-a210-000c6ec35b1b}]
Auto\command- G:\qeyxuht.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL qeyxuht.exe
-- End of Deckard's System Scanner: finished at 2008-07-24 23:29:15 ------------