OK i'm back....been busy... logs will follow!
OK ran the move it Here's the log:
Explorer killed successfully
File/Folder F:\fuwobajep.exe not found.
File/Folder G:\jupawibyp.exe not found.
< EmptyTemp >
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF17F9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JETAB43.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6ec.dat scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07312008_131436
Files moved on Reboot...
C:\DOCUME~1\Owner\LOCALS~1\Temp\hpodvd09.log moved successfully.
C:\DOCUME~1\Owner\LOCALS~1\Temp\WCESLog.log moved successfully.
C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF17F9.tmp moved successfully.
File C:\WINDOWS\temp\JETAB43.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_6ec.dat not found!
Ran DSS heres the log:
Deckard's System Scanner v20071014.68
Run by Owner on 2008-07-31 13:31:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:31, on 2008-07-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\FCyberAlert\syslogin.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Owner\My Documents\Software\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCyberAlert\syslogin.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Exif Launcher S.lnk = C:\Program Files\FinePixViewerS\QuickDCF2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1211585209718O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn...ro.cab56649.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
--
End of file - 10675 bytes
-- Files created between 2008-06-30 and 2008-07-31 -----------------------------
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-31 01:03:29 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-31 01:03:29 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-31 01:03:29 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-31 01:03:29 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-30 22:06:33 68096 --a------ C:\WINDOWS\zip.exe
2008-07-30 22:06:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-30 22:06:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-30 22:06:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-30 22:06:33 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-30 22:06:33 98816 --a------ C:\WINDOWS\sed.exe
2008-07-30 22:06:33 80412 --a------ C:\WINDOWS\grep.exe
2008-07-30 22:06:33 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-30 22:04:39 0 dr-hs---- C:\cmdcons
2008-07-30 22:04:38 0 d-------- C:\WINDOWS\setup.pss
2008-07-30 22:03:06 0 d-------- C:\WINDOWS\setupupd
2008-07-30 21:49:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Search
2008-07-29 22:12:47 0 d-------- C:\Program Files\Norton 360
2008-07-29 22:11:55 0 d-------- C:\Program Files\Symantec
2008-07-29 22:09:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-07-29 18:48:02 0 d-------- C:\Documents and Settings\Torey\Application Data\Windows Desktop Search
2008-07-29 18:46:47 0 d-------- C:\Documents and Settings\Tammy\Application Data\Windows Desktop Search
2008-07-29 15:30:32 0 d-------- C:\Program Files\Trend Micro
2008-07-28 21:46:23 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Windows Desktop Search
2008-07-28 21:42:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\SUPERAntiSpyware.com
2008-07-28 21:27:53 0 d-------- C:\Documents and Settings\Alyc\Application Data\Windows Desktop Search
2008-07-28 21:20:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
2008-07-28 21:20:27 0 d-------- C:\Program Files\Windows Desktop Search
2008-07-28 21:20:26 0 d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-28 18:25:53 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-28 17:44:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:42 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-28 17:44:41 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 17:40:35 0 d-------- C:\Program Files\SpywareBlaster
2008-07-28 15:24:42 0 d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-07-28 11:31:58 0 d-------- C:\Documents and Settings\Torey\Application Data\Malwarebytes
2008-07-28 11:31:00 0 d-------- C:\Documents and Settings\Torey\Application Data\Mozilla
2008-07-28 11:06:42 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Malwarebytes
2008-07-28 11:05:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Mozilla
2008-07-27 21:40:28 0 d-------- C:\Documents and Settings\Tammy\Application Data\Mozilla
2008-07-27 21:40:09 0 d-------- C:\Documents and Settings\Tammy\Application Data\Malwarebytes
2008-07-27 21:32:45 0 d-------- C:\Documents and Settings\Alyc\Application Data\Mozilla
2008-07-27 21:31:18 0 dr-h----- C:\Documents and Settings\Alyc\Recent
2008-07-27 21:15:30 0 d-------- C:\WINDOWS\pss
2008-07-27 20:53:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\Malwarebytes
2008-07-27 19:58:35 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-07-27 18:11:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-07-27 18:11:33 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 18:11:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 18:11:01 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-27 15:31:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-27 15:31:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-07-26 12:36:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\FUJIFILM
2008-07-21 15:50:55 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-07-21 14:24:07 0 d-------- C:\Documents and Settings\Owner\Application Data\HouseCall 6.6
2008-07-19 14:26:52 0 d-------- C:\Documents and Settings\Torey\Contacts
2008-07-18 15:23:40 0 d-------- C:\Documents and Settings\Alyc\Contacts
2008-07-18 11:02:58 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-07-18 07:11:23 0 d-------- C:\Documents and Settings\Jordyn\Contacts
2008-07-17 10:13:45 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-17 10:13:41 0 d-------- C:\Program Files\Windows Live
2008-07-17 10:13:27 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-05 05:04:19 0 d-------- C:\Documents and Settings\Tammy\Application Data\Macromedia
-- Find3M Report ---------------------------------------------------------------
2008-07-31 13:30:07 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-07-31 13:26:13 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-30 22:08:01 0 d-------- C:\Program Files\Common Files
2008-07-19 18:08:32 0 d-------- C:\Program Files\Java
2008-06-24 20:33:35 0 --a------ C:\WINDOWS\PowerReg.dat
2008-06-24 20:31:47 0 d-------- C:\Program Files\Infogrames Interactive
2008-06-24 20:31:46 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-05 04:50:36 0 d-------- C:\Program Files\Logitech
2008-06-05 04:49:27 0 d-------- C:\Program Files\Common Files\Logitech
2008-06-02 09:15:29 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2008-05-30 12:49:10 2528 --a------ C:\Documents and Settings\Owner\Application Data\$_hpcst$.hpc
2008-05-24 10:47:37 2078 --a------ C:\Documents and Settings\Owner\Application Data\HPSU_48BitScanUpdate.log
2008-05-24 10:42:08 37631 --a------ C:\Documents and Settings\Owner\Application Data\Update_HP_RedboxHprblog_HPSU.log
2008-05-24 10:41:49 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll <Not Verified; Hewlett Packard; Hewlett Packard Rediscovery Library>
2008-05-24 10:38:12 89277 --a------ C:\WINDOWS\hpoins06.dat
2008-05-24 02:52:04 934607 --a------ C:\WINDOWS\system32\JGScreensaver_3.scr <Not Verified; Axialis Software; Axialis Screen Saver Producer>
2008-05-23 19:48:00 1076 --a------ C:\WINDOWS\checkip.dat
2008-05-23 14:26:04 22 --a------ C:\WINDOWS\FileName
2008-05-23 14:18:26 0 -rahs---- C:\MSDOS.SYS
2008-05-23 14:18:26 0 -rahs---- C:\IO.SYS
2008-05-23 14:18:26 0 --a------ C:\CONFIG.SYS
2008-05-23 14:18:26 0 --a------ C:\AUTOEXEC.BAT
2008-05-23 14:16:27 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 08:43:36 62 --ahs---- C:\Documents and Settings\Owner\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-06-30 13:44 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-07-29 22:13 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [2008-06-30 13:44 349552]
[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 04:21 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 05:04 C:\WINDOWS\SkyTel.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 07:44]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [2006-10-30 07:44]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2006-11-14 01:25]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-15 21:02]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-07 11:32]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-09 21:45]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 14:53]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36]
"FamilyCyberAlert"="C:\WINDOWS\system32\FCyberAlert\syslogin.exe" [2008-04-22 12:20]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 14:37]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 09:50]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-07 11:40]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe [2008-05-24 11:07:32]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 22:19:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2008-05-26 22:19 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
*Newly Created Service* - APPMGMT
*Newly Created Service* - COMHOST
-- End of Deckard's System Scanner: finished at 2008-07-31 13:31:28 ------------
Tried the flash disinfector on Jordyn's profile..... didn't seem to change anything!
Removed Microsoft active sync as it kept opening on login (used to not do this) and I don't use it anyway!
Made all limited accts admin.
Then just for grins I ran DSS in Jordyn's Profile!Deckard's System Scanner v20071014.68
Run by Jordyn on 2008-07-31 13:32:39
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Jordyn.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:32:41 PM, on 7/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\FCyberAlert\syslogin.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\noucouzipyz.exe
C:\Documents and Settings\Owner\My Documents\Software\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Jordyn.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCyberAlert\syslogin.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [fufokoo] C:\Documents and Settings\Jordyn\Application Data\Microsoft\noucouzipyz.exe
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User 'Owner')
O4 - Global Startup: Exif Launcher S.lnk = C:\Program Files\FinePixViewerS\QuickDCF2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1211585209718O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn...ro.cab56649.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
--
End of file - 11745 bytes
-- Files created between 2008-06-30 and 2008-07-31 -----------------------------
2008-07-31 13:32:43 142336 -ra------ C:\WINDOWS\system32\wennouwibas.exe
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-31 01:03:29 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-31 01:03:29 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-31 01:03:29 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-31 01:03:29 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-30 22:06:33 68096 --a------ C:\WINDOWS\zip.exe
2008-07-30 22:06:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-30 22:06:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-30 22:06:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-30 22:06:33 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-30 22:06:33 98816 --a------ C:\WINDOWS\sed.exe
2008-07-30 22:06:33 80412 --a------ C:\WINDOWS\grep.exe
2008-07-30 22:06:33 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-30 22:04:39 0 dr-hs---- C:\cmdcons
2008-07-30 22:04:38 0 d-------- C:\WINDOWS\setup.pss
2008-07-30 22:03:06 0 d-------- C:\WINDOWS\setupupd
2008-07-30 21:49:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Search
2008-07-29 22:12:47 0 d-------- C:\Program Files\Norton 360
2008-07-29 22:11:55 0 d-------- C:\Program Files\Symantec
2008-07-29 22:09:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-07-29 18:48:02 0 d-------- C:\Documents and Settings\Torey\Application Data\Windows Desktop Search
2008-07-29 18:46:47 0 d-------- C:\Documents and Settings\Tammy\Application Data\Windows Desktop Search
2008-07-29 15:30:32 0 d-------- C:\Program Files\Trend Micro
2008-07-28 21:46:23 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Windows Desktop Search
2008-07-28 21:42:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\SUPERAntiSpyware.com
2008-07-28 21:27:53 0 d-------- C:\Documents and Settings\Alyc\Application Data\Windows Desktop Search
2008-07-28 21:20:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
2008-07-28 21:20:27 0 d-------- C:\Program Files\Windows Desktop Search
2008-07-28 21:20:26 0 d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-28 18:25:53 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-28 17:44:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:42 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-28 17:44:41 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 17:40:35 0 d-------- C:\Program Files\SpywareBlaster
2008-07-28 15:24:42 0 d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-07-28 11:31:58 0 d-------- C:\Documents and Settings\Torey\Application Data\Malwarebytes
2008-07-28 11:31:00 0 d-------- C:\Documents and Settings\Torey\Application Data\Mozilla
2008-07-28 11:06:42 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Malwarebytes
2008-07-28 11:05:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Mozilla
2008-07-27 22:05:39 142336 -ra------ C:\WINDOWS\system32\noucouzipyz.exe
2008-07-27 21:40:28 0 d-------- C:\Documents and Settings\Tammy\Application Data\Mozilla
2008-07-27 21:40:09 0 d-------- C:\Documents and Settings\Tammy\Application Data\Malwarebytes
2008-07-27 21:32:45 0 d-------- C:\Documents and Settings\Alyc\Application Data\Mozilla
2008-07-27 21:31:18 0 dr-h----- C:\Documents and Settings\Alyc\Recent
2008-07-27 21:15:30 0 d-------- C:\WINDOWS\pss
2008-07-27 20:53:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\Malwarebytes
2008-07-27 19:58:35 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-07-27 18:11:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-07-27 18:11:33 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 18:11:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 18:11:01 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-27 15:31:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-27 15:31:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-07-26 12:36:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\FUJIFILM
2008-07-21 15:50:55 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-07-21 14:24:07 0 d-------- C:\Documents and Settings\Owner\Application Data\HouseCall 6.6
2008-07-19 14:26:52 0 d-------- C:\Documents and Settings\Torey\Contacts
2008-07-18 15:23:40 0 d-------- C:\Documents and Settings\Alyc\Contacts
2008-07-18 11:02:58 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-07-18 07:11:23 0 d-------- C:\Documents and Settings\Jordyn\Contacts
2008-07-17 10:13:45 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-17 10:13:41 0 d-------- C:\Program Files\Windows Live
2008-07-17 10:13:27 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-05 05:04:19 0 d-------- C:\Documents and Settings\Tammy\Application Data\Macromedia
-- Find3M Report ---------------------------------------------------------------
2008-07-31 13:30:07 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-07-31 13:26:13 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-30 22:08:01 0 d-------- C:\Program Files\Common Files
2008-07-19 18:08:32 0 d-------- C:\Program Files\Java
2008-06-24 20:33:35 0 --a------ C:\WINDOWS\PowerReg.dat
2008-06-24 20:31:47 0 d-------- C:\Program Files\Infogrames Interactive
2008-06-24 20:31:46 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-21 11:29:49 2528 --a------ C:\Documents and Settings\Jordyn\Application Data\$_hpcst$.hpc
2008-06-05 16:34:50 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Sun
2008-06-05 04:50:36 0 d-------- C:\Program Files\Logitech
2008-06-05 04:49:27 0 d-------- C:\Program Files\Common Files\Logitech
2008-05-24 10:41:49 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll <Not Verified; Hewlett Packard; Hewlett Packard Rediscovery Library>
2008-05-24 10:38:12 89277 --a------ C:\WINDOWS\hpoins06.dat
2008-05-24 02:52:04 934607 --a------ C:\WINDOWS\system32\JGScreensaver_3.scr <Not Verified; Axialis Software; Axialis Screen Saver Producer>
2008-05-23 19:48:00 1076 --a------ C:\WINDOWS\checkip.dat
2008-05-23 14:26:04 22 --a------ C:\WINDOWS\FileName
2008-05-23 14:18:26 0 -rahs---- C:\MSDOS.SYS
2008-05-23 14:18:26 0 -rahs---- C:\IO.SYS
2008-05-23 14:18:26 0 --a------ C:\CONFIG.SYS
2008-05-23 14:18:26 0 --a------ C:\AUTOEXEC.BAT
2008-05-23 14:16:27 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 08:43:36 62 --ahs---- C:\Documents and Settings\Jordyn\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
06/30/2008 01:44 PM 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
07/29/2008 10:13 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [06/30/2008 01:44 PM 349552]
[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 04:21 AM C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 05:04 AM C:\WINDOWS\SkyTel.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [10/30/2006 07:44 AM]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [10/30/2006 07:44 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [09/17/2007 01:07 AM]
"nwiz"="nwiz.exe" [09/17/2007 01:07 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [09/17/2007 01:07 AM]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [11/14/2006 01:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/15/2007 09:02 PM]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [05/07/2007 11:32 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [07/09/2002 09:45 PM]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [09/06/2007 02:53 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"FamilyCyberAlert"="C:\WINDOWS\system32\FCyberAlert\syslogin.exe" [04/22/2008 12:20 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/18/20