My computer is currently running very slowwwww on the Internet and I don't know why. I don't have any pop-up problems, but loading websites such as Gmail or Facebook takes forever and a lot of the images do not show up. Here is my SmitFraudFix and DSS log, thanks!
SmitFraudFix v2.301
Scan done at 20:54:09.01, Sun 08/30/2009
Run from C:\Documents and Settings\Andrew Krueger\Desktop\Virus - what to use\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Andrew Krueger
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Andrew Krueger\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ANDREW~1\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Dell Wireless 1450 Dual-band (802.11a/b/g) USB2.0 Adapter - Packet Scheduler Miniport
DNS Server Search Order: 192.168.10.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B00E97DA-6E46-4451-921F-420462E0295C}: DhcpNameServer=192.168.10.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B00E97DA-6E46-4451-921F-420462E0295C}: DhcpNameServer=192.168.10.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{B00E97DA-6E46-4451-921F-420462E0295C}: DhcpNameServer=192.168.10.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.10.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
Deckard's System Scanner v20071014.68
Run by Andrew Krueger on 2009-08-30 20:55:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 510 MiB (512 MiB recommended).
-- HijackThis (run as Andrew Krueger.exe) --------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:30 PM, on 8/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Pelmiced.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Andrew Krueger\Desktop\Virus - what to use\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ANDREW~1.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Andrew Krueger\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/p...owserPlugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 9165 bytes
-- Files created between 2009-07-30 and 2009-08-30 -----------------------------
2009-08-30 20:51:41 4884 --a------ C:\WINDOWS\system32\tmp.reg
2009-08-30 20:51:22 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2009-08-30 20:51:22 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2009-08-30 20:51:22 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2009-08-30 20:51:22 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2009-08-30 20:51:22 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2009-08-30 20:51:22 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2009-08-30 20:51:22 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2009-08-11 18:58:10 0 d-------- C:\WINDOWS\Prefetch
2009-08-11 14:06:29 0 d-------- C:\WINDOWS\system32\scripting
2009-08-11 14:06:29 0 d-------- C:\WINDOWS\l2schemas
2009-08-11 14:06:28 0 d-------- C:\WINDOWS\system32\en
2009-08-11 14:06:27 0 d-------- C:\WINDOWS\system32\bits
2009-08-11 14:03:15 0 d-------- C:\WINDOWS\ServicePackFiles
2009-08-11 14:00:47 0 d-------- C:\WINDOWS\network diagnostic
2009-08-11 13:51:54 0 d-------- C:\WINDOWS\EHome
2009-08-09 01:54:33 49152 --a------ C:\WINDOWS\system32\pmpopo.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:33 241664 --a------ C:\WINDOWS\system32\pelutil.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:33 114688 --a------ C:\WINDOWS\system32\pelscrll.dll <Not Verified; ELECOM Electronics Ltd.; MouseSuite 98>
2009-08-09 01:54:33 69632 --a------ C:\WINDOWS\system32\pelhooks.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:33 36864 --a------ C:\WINDOWS\system32\pelcomm.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:33 225280 --a------ C:\WINDOWS\system32\hPppm.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:32 28672 --a------ C:\WINDOWS\system32\UnInst.exe <Not Verified; Primax Electronics Ltd.; primax UnInst>
2009-08-09 01:54:32 126976 --a------ C:\WINDOWS\system32\Twister.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:32 45056 --a------ C:\WINDOWS\system32\SetupNT.exe <Not Verified; Primax Electronics Ltd.; Setup Wizard>
2009-08-09 01:54:32 159854 --a------ C:\WINDOWS\system32\PMaria.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:32 94208 --a------ C:\WINDOWS\system32\Pelzoom.dll <Not Verified; Primax Electronics Ltd.; Primax Mouse>
2009-08-09 01:54:32 8704 --a------ C:\WINDOWS\system32\Pelvendr.sys <Not Verified; Primax Electronics Ltd.; Primax USB Vendor Test>
2009-08-09 01:54:32 303104 --a------ C:\WINDOWS\system32\PelSetup.exe <Not Verified; Primax Electronics Ltd.; Primax Input Device Products>
2009-08-09 01:54:32 24576 --a------ C:\WINDOWS\system32\Pelsetup.dll <Not Verified; Primax Electronics Ltd.; Primax Mouse>
2009-08-09 01:54:32 18944 --a------ C:\WINDOWS\system32\Pelmouse.sys <Not Verified; Primax Electronics Ltd.; Primax Mouse>
2009-08-09 01:54:32 45056 --a------ C:\WINDOWS\system32\ergo5b.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 229376 --a------ C:\WINDOWS\system32\PMUninst.exe <Not Verified; Primax Electronics Ltd.; Primax Mouse>
2009-08-09 01:54:31 36864 --a------ C:\WINDOWS\system32\PMUninNT.exe <Not Verified; Primax Electronics Ltd.; Primax Mouse>
2009-08-09 01:54:31 40960 --a------ C:\WINDOWS\system32\PMTilt3.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 40960 --a------ C:\WINDOWS\system32\PMTILT.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 61952 --a------ C:\WINDOWS\system32\PMRESHP.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 45056 --a------ C:\WINDOWS\system32\PMMO32R.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 14848 --a------ C:\WINDOWS\system32\PMMo32.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 65536 --a------ C:\WINDOWS\system32\PMIBM.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:31 15040 --a------ C:\WINDOWS\system32\PINSTNPD.EXE <Not Verified; Primax Electronics Ltd.; Primax Input Devices>
2009-08-09 01:54:31 45056 --a------ C:\WINDOWS\system32\PELRESS.DLL <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:31 151552 --a------ C:\WINDOWS\system32\PELMICED.EXE <Not Verified; Primax Electronics Ltd.; MouseSuite 98>
2009-08-09 01:54:30 241664 --a------ C:\WINDOWS\system32\Notifier.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2009-08-09 01:54:30 40960 --a------ C:\WINDOWS\system32\LaunHelp-backup.exe <Not Verified; Primax Electronics Ltd.; primax LaunHelp>
2009-08-09 01:54:30 61440 --a------ C:\WINDOWS\system32\LaunHelp.exe <Not Verified; Primax Electronics Ltd.; primax LaunHelp>
2009-08-09 01:54:30 290816 --a------ C:\WINDOWS\system32\HPWHEEL.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite 98>
2009-08-09 01:54:30 619467 --a------ C:\WINDOWS\system32\HPbdo.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:30 21504 --a------ C:\WINDOWS\system32\HorizontalScroll.exe <Not Verified; ; SkinDialog_Demo Application>
2009-08-09 01:54:30 77824 --a------ C:\WINDOWS\system32\Dynex5B.dll <Not Verified; Primax Electronics Ltd.; Mouse Suite>
2009-08-09 01:54:27 0 d-------- C:\Program Files\Dynex
2009-08-08 13:27:18 11168 --ah----- C:\WINDOWS\system32\yovanijo
2009-08-08 13:26:41 0 d-------- C:\_OTM
2009-08-08 03:19:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-08-08 03:19:02 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2009-08-06 00:55:50 77824 --a------ C:\WINDOWS\system32\swupdate.dll
2009-08-06 00:55:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Macromedia
-- Find3M Report ---------------------------------------------------------------
2009-08-30 20:24:30 0 d-------- C:\Program Files\Common Files\AOL
2009-08-30 20:13:27 0 d-------- C:\Program Files\BitComet
2009-08-20 21:11:53 0 d-------- C:\Program Files\LimeWire
2009-08-20 11:14:00 0 d-------- C:\Documents and Settings\Andrew Krueger\Application Data\Mozilla
2009-08-11 14:13:11 0 d-------- C:\Program Files\Messenger
2009-08-11 14:06:27 0 d-------- C:\Program Files\Movie Maker
2009-08-11 14:02:59 0 d-------- C:\Program Files\Windows NT
2009-08-10 00:24:39 0 d-------- C:\Program Files\Common Files
2009-08-09 13:46:14 84992 --ahs---- C:\WINDOWS\system32\fupipivo.dll
2009-08-09 01:54:25 0 d--h----- C:\Program Files\InstallShield Installation Information
2009-08-08 12:10:14 216064 --a------ C:\WINDOWS\PEV.exe
2009-08-08 03:17:22 0 d-------- C:\Program Files\AIM
2009-08-07 12:07:48 0 d-------- C:\Program Files\Common Files\Logitech
2009-07-31 23:29:22 0 d-------- C:\Program Files\Avancemos 1
2009-07-03 15:19:30 0 d-------- C:\Program Files\Windows Media Connect 2
2009-07-01 19:30:40 0 d-------- C:\Program Files\EasyPlanner
2009-06-22 16:31:20 65 --a------ C:\WINDOWS\system32\bd7340.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 07:42 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [02/23/2005 04:19 PM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 01:05 AM]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [07/27/2004 04:50 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [02/16/2005 04:15 PM]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [01/27/2005 01:02 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/13/2004 03:49 PM]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [03/15/2005 08:58 AM]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/20/2005 09:35 AM]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 09:32 AM]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/20/2005 09:36 AM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [06/08/2005 03:24 PM]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [06/08/2005 03:14 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [12/19/2006 08:06 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [11/04/2008 11:30 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [11/20/2008 02:20 PM]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [10/25/2006 09:03 AM]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [10/11/2007 07:03 PM]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [10/11/2007 07:01 PM]
"PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [08/31/2007 09:01 AM]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [11/05/2007 09:34 PM]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [10/30/2007 03:05 PM]
"Mouse Suite 98 Daemon"="ICO.EXE" [10/23/2006 01:54 PM C:\WINDOWS\system32\ico.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [06/08/2005 02:44 PM]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 11:09 AM]
"Google Update"="C:\Documents and Settings\Andrew Krueger\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [04/12/2009 12:19 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:12 PM]
C:\Documents and Settings\Andrew Krueger\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [10/20/2005 12:04:08 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 11:05:26 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [7/24/2005 11:11:50 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/4/2004 7:28:24 PM]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [11/4/2004 7:50:52 PM]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [11/11/2004 11:59:36 AM]
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [7/24/2005 11:11:13 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74012a1d-667b-11de-b277-0014a5075f83}]
AutoRun\command- E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f29ce3a-0ef9-11de-b245-0014a5075f83}]
AutoRun\command- E:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2009-08-30 20:56:18 ------------