SDFix: Version 1.212 Run by User on Sun 08/03/2008 at 22:16
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Restoring Default Desktop Wallpaper
Restoring Default ScreenSaver value
Restoring Windows ProductId To Remove Fake Virus Alert
Restoring Time Format To Remove Fake Virus Alert
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\SYSTEM32\PHCJ5J~1.BMP - Deleted
C:\WINDOWS\SYSTEM32\BLPHCJ~1.SCR - Deleted
C:\WINDOWS\EWTL.EXE - Deleted
C:\Documents and Settings\User\Application Data\Macromedia\Flash
Player\macromedia.com\support\flashplayer\sys\#www.redtube.com\settings.sol - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk -
Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP
2008.lnk - Deleted
C:\Documents and Settings\User\Favorites\Error Cleaner.url - Deleted
C:\Documents and Settings\User\Desktop\Error Cleaner.url - Deleted
C:\Documents and Settings\User\Favorites\Privacy Protector.url - Deleted
C:\Documents and Settings\User\Desktop\Privacy Protector.url - Deleted
C:\Documents and Settings\User\Favorites\Spyware&Malware Protection.url - Deleted
C:\Documents and Settings\User\Desktop\Spyware&Malware Protection.url - Deleted
C:\WINDOWS\privacy_danger\images\capt.gif - Deleted
C:\WINDOWS\privacy_danger\images\danger.jpg - Deleted
C:\WINDOWS\privacy_danger\images\down.gif - Deleted
C:\WINDOWS\privacy_danger\images\spacer.gif - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2AE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2CA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2F4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2AD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2D2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt2FB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\.tt6.tmp.vbs - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\vistasp1.exe.bat - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP33.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP40.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP42.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP43.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP44.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP62.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP63.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP54.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP55.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP12.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP64.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP65.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP66.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP60.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP61.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP67.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP68.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP69.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP13.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP14.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP15.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP51.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP10.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP49.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP17.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP18.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP53.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP34.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP19.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP35.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP1F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP24.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP25.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP26.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP27.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP28.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP29.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP30.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP31.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP20.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP37.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP38.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP39.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP3D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP41.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP45.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP57.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP47.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP48.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP4C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP50.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP52.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP56.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP58.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP59.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP73.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP21.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP22.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP23.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP74.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP32.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP86.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP87.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP46.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP71.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP6F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP70.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP72.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP80.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP75.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP76.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP78.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP77.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP83.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP84.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP90.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP91.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP79.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP7F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP81.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP82.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP85.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP88.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP89.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP92.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP93.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP8F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP94.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP97.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP95.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP98.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9C.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP96.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9F.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9D.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPB7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP99.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9A.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9B.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMP9E.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPA7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPAE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPBF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPC5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPCE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPD8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE1.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPDB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPEA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPEC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPEB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPED.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPE8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPEE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF0.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF2.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF3.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPEF.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF4.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF5.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF6.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF7.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF8.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPF9.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFA.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFB.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFC.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFD.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFE.tmp - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\TMPFF.tmp - Deleted
C:\WINDOWS\nfavxwdbolx.dll - Deleted
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk - Deleted
C:\DOCUME~1\User\LOCALS~1\Temp\s1265.php.bat - Deleted
C:\WINDOWS\eqvwamkl.dll - Deleted
C:\WINDOWS\fdkowvbp.dll - Deleted
C:\WINDOWS\grswptdl.exe - Deleted
C:\WINDOWS\wnslvxtf.dll - Deleted
C:\WINDOWS\system32\nvrsul32.dll - Deleted
Folder C:\Documents and Settings\User\Application Data\Macromedia\Flash
Player\macromedia.com\support\flashplayer\sys\#www.redtube.com - Removed
Folder C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 - Removed
Folder C:\WINDOWS\privacy_danger - Removed
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-03 22:23:20
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardp
rofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG
Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG
Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG
Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG
Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program
Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program
Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Java\\jre1.5.0_10\\BIN\\javaw.exe"="C:\\Program
Files\\Java\\jre1.5.0_10\\BIN\\javaw.exe:*:Enabled:Java 2 Platform Standard Edition binary"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\\Program Files\\Messenger\\MSMSGS.EXE"="C:\\Program
Files\\Messenger\\MSMSGS.EXE:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet
Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"="C:\\Program Files\\Ocean
Technology\\GG E-Sports Platform\\GGclient.exe:*:Enabled:GG E-Sports Platform Client"
"C:\\Program Files\\Warcraft III\\War3.exe"="C:\\Program Files\\Warcraft III\\War3.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\SupaSupa, AERO-REVO!\\SupaSupa.exe"="C:\\Program Files\\SupaSupa,
AERO-REVO!\\SupaSupa.exe:*:Enabled:SupaSupa"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh
Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\sysreset\\mirc.exe"="C:\\sysreset\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program
Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\Dragonfly\\Special Force\\specialforce.exe"="C:\\Program Files\\Dragonfly\\Special
Force\\specialforce.exe:*:Enabled:specialforce"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program
Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"="C:\\Program
Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE:*:Enabled:Microsoft ® Visual
Studio VSA RPC Event Creator"
"C:\\Program Files\\Garena\\Garena.exe"="C:\\Program Files\\Garena\\Garena.exe:*:Enabled:Garena"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainpr
ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN
Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN
Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Fri 23 Apr 1999 93,890 ..SH. --- "C:\COMMAND.COM"
Tue 6 Mar 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 16 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0759.tmp"
Sun 16 Mar 2008 274,944 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3106.tmp"
Sun 16 Mar 2008 273,920 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1493.tmp"
Sun 16 Mar 2008 376,832 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3048.tmp"
Sun 16 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0164.tmp"
Sun 16 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2607.tmp"
Sun 16 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2922.tmp"
Sun 16 Mar 2008 24,576 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0054.tmp"
Sun 16 Mar 2008 25,088 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3188.tmp"
Sun 16 Mar 2008 25,088 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1276.tmp"
Sun 16 Mar 2008 25,088 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2359.tmp"
Sun 16 Mar 2008 25,600 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1555.tmp"
Sun 16 Mar 2008 26,624 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1491.tmp"
Sun 16 Mar 2008 28,160 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2107.tmp"
Sun 16 Mar 2008 30,720 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1487.tmp"
Sun 16 Mar 2008 32,256 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0853.tmp"
Sun 16 Mar 2008 291,840 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2568.tmp"
Sun 16 Mar 2008 294,400 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0433.tmp"
Sun 16 Mar 2008 307,200 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0658.tmp"
Mon 17 Mar 2008 72,192 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0536.tmp"
Mon 17 Mar 2008 83,456 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3413.tmp"
Mon 17 Mar 2008 312,832 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3507.tmp"
Mon 17 Mar 2008 325,120 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3523.tmp"
Mon 17 Mar 2008 82,944 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3319.tmp"
Mon 24 Mar 2008 439,296 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3968.tmp"
Mon 24 Mar 2008 440,832 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1419.tmp"
Mon 25 Feb 2008 31,744 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3052.tmp"
Sun 16 Mar 2008 51,712 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1909.tmp"
Sun 16 Mar 2008 52,736 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0781.tmp"
Sun 16 Mar 2008 52,736 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL3956.tmp"
Sun 16 Mar 2008 54,272 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0220.tmp"
Sun 16 Mar 2008 54,272 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0971.tmp"
Sun 16 Mar 2008 54,784 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2428.tmp"
Sun 16 Mar 2008 55,808 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0199.tmp"
Sat 15 Mar 2008 125,952 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL4031.tmp"
Sun 16 Mar 2008 125,952 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL0901.tmp"
Sun 16 Mar 2008 189,440 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2073.tmp"
Sun 16 Mar 2008 190,976 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL1992.tmp"
Sun 16 Mar 2008 258,560 ...H. --- "C:\Documents and Settings\User\My Documents\school\IS
134.6\~WRL2263.tmp"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\User\Application Data\U3\temp\Launchpad
Removal.exe"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\tumbong\Application
Data\U3\temp\Launchpad Removal.exe"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Guest 2\Application
Data\U3\temp\Launchpad Removal.exe"
Finished!Deckard's System Scanner v20071014.68
Run by User on 2008-08-03 22:28:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2008-08-03 14:28:10 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-08-03 08:19:31 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 79% (more than 75%).Total Physical Memory: 447 MiB (512 MiB recommended).-- HijackThis (run as User.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:29:24, on 8/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\User\Desktop\dss.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\User.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Fab%20Fashion/Images/stg_drm.ocx
O16 - DPF: {21BB8360-F943-447E-98F3-3C22345375A7} (CPlayFirstChocolatierControl Object) -
http://aolsvc.aol.co...eb.1.0.0.13.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {4C68DACE-E6BC-4650-9C7E-D036720CA729} (Nps Control) -
http://kr.gameguard..../tyscan/nps.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by105w.bay105...es/MsnPUpld.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} -
http://download.sopc...oad/SOPCORE.CABO16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Wedding%20Dash/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} -
https://my.levelupga...crypt/npkcx.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
--
End of file - 9660 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080803-205332-432 O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
backup-20080803-205711-555 O21 - SSODL: wnslvxtf - {723A27A8-1BE4-4C02-B2C0-ABDDE1DAEE34} - C:\WINDOWS\wnslvxtf.dll
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 DgiVecp (Team MFP Comm Driver) - c:\windows\system32\drivers\dgivecp.sys <Not Verified; DeviceGuys, Inc.; DeviceGuys, Inc. Team MFP for Windows NT, 9x, and 3.1>
R2 MASPINT - c:\windows\system32\drivers\maspint.sys <Not Verified; MicroStaff Co.,Ltd.; Aspi32 Driver for WinNT>
R3 catchme - c:\docume~1\user\locals~1\temp\catchme.sys (file missing)
S3 EP518P (EZPhone Cam) - c:\windows\system32\drivers\ep518vid.sys <Not Verified; OmniVision Technologies, Inc.; OmniVision Technologies, Inc. USB Dual-Mode Camera>
S3 npkcrypt - c:\program files\gravity\ragnarokonline\npkcrypt.sys (file missing)
S3 npkycryp - c:\program files\gravity\ro\npkycryp.sys (file missing)
S3 PCAlertDriver - c:\biostools\ntglm7x.sys <Not Verified; Your Corporation; Your Product Name>
S3 UTS2pl (Motorola Serial port driver) - c:\windows\system32\drivers\uts2pl.sys <Not Verified; Prolific Technology Inc.; USB-Serial data down load Cable>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-08-02 22:11:06 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-07-03 and 2008-08-03 -----------------------------
2008-08-03 22:11:05 0 d-------- C:\WINDOWS\ERUNT
2008-08-03 20:21:01 0 d-------- C:\Program Files\Trend Micro
2008-08-03 18:30:11 0 d-------- C:\WINDOWS\system32\NtmsData
2008-08-03 17:19:20 0 d--hs---- C:\FOUND.002
2008-08-03 16:18:28 0 d-------- C:\Documents and Settings\User\Application Data\TmpRecentIcons
2008-07-29 18:32:02 0 d-------- C:\Documents and Settings\Guest 2\Application Data\U3
2008-07-26 13:33:08 0 d-------- C:\Documents and Settings\User\Application Data\Jane s Hotel Family Hero
2008-07-25 23:52:49 0 d-------- C:\Program Files\Garena
2008-07-25 23:52:12 0 d-------- C:\Documents and Settings\User\Application Data\InstallShield
2008-07-25 23:29:26 64313 --a------ C:\WINDOWS\War3Unin.dat
2008-07-25 23:29:25 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-07-25 23:29:25 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-07-25 23:25:20 0 d-------- C:\Program Files\Warcraft III
2008-07-23 23:11:46 0 d-------- C:\Program Files\Democracy
2008-07-12 22:20:59 0 d-------- C:\Documents and Settings\User\Application Data\GamesCafe
2008-07-12 22:16:55 0 d-------- C:\Program Files\CLUE Classic
2008-07-12 11:41:16 0 d-------- C:\Program Files\Web Publish
2008-07-11 23:41:12 0 d-------- C:\My Installations
2008-07-11 23:41:11 143360 --a------ C:\WINDOWS\system32\isdbgi51.dll <Not Verified; InstallShield Software Corporation; InstallShield®>
2008-07-11 22:51:36 140048 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:36 135168 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:36 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
2008-07-11 22:51:36 42496 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:36 6550 --a------ C:\WINDOWS\jautoexp.dat
2008-07-11 22:51:30 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-07-11 22:51:29 147456 --a------ C:\WINDOWS\wjview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:29 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-07-11 22:51:29 207872 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:29 73728 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft JDBC Bridge>
2008-07-11 22:51:29 843024 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:28 155920 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:28 14848 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:28 361744 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:28 32528 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:28 154112 --a------ C:\WINDOWS\jview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:27 209168 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:26 44544 --a------ C:\WINDOWS\clspack.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-11 22:51:25 103424 --a------ C:\WINDOWS\extrac32.exe <Not Verified; Microsoft Corporation; Microsoft ® CAB File Extract Utility>
2008-07-08 22:20:31 0 d-------- C:\Documents and Settings\Guest 2\Saved Games
2008-07-08 22:20:31 0 d-------- C:\Documents and Settings\Guest 2\Application Data\Flood Light Games
2008-07-07 19:19:09 0 d-------- C:\Documents and Settings\User\Application Data\Flood Light Games
2008-07-07 19:19:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Flood Light Games
-- Find3M Report ---------------------------------------------------------------
2008-07-17 23:59:54 212 --a------ C:\WINDOWS\recover.reg
2008-06-22 23:26:40 0 d-------- C:\Documents and Settings\User\Application Data\Sandlot Games
2008-06-22 22:22:34 0 d-------- C:\Program Files\GameHouse
2008-06-22 17:38:00 0 d-------- C:\Documents and Settings\User\Application Data\dvdcss
2008-06-21 14:57:20 0 d-------- C:\Program Files\QuickFix
2008-06-20 22:02:48 0 d-------- C:\Program Files\BFG
2008-06-20 21:58:56 0 d-------- C:\Program Files\Chocolatier
2008-06-20 21:19:46 0 d-------- C:\Program Files\ReflexiveArcade
2008-06-11 21:55:56 0 --a------ C:\Program Files\temp01
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50]
"AVG7_CC"="C:\PROGRA~1