the main.txt
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-03-21 16:14:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
8: 2008-03-22 00:16:12 UTC - RP31 - Deckard's System Scanner Restore Point
7: 2008-03-21 05:50:25 UTC - RP30 - System Checkpoint
6: 2008-03-19 23:40:44 UTC - RP29 - Software Distribution Service 3.0
5: 2008-03-19 02:14:15 UTC - RP28 - Installed AVG 7.5
4: 2008-03-19 00:37:44 UTC - RP27 - Software Distribution Service 3.0
-- First Restore Point --
1: 2008-03-16 22:12:27 UTC - RP24 - Software Distribution Service 3.0
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 88% (more than 75%).Total Physical Memory: 128 MiB (512 MiB recommended).System Drive C: has 0.44 GiB (less than 15%) free.-- HijackThis (run as Administrator.exe) ---------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-03-21 16:24:08
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\mrofinu1000106.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\NETGEAR\WG311v3\WG311v3.exe
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator\Desktop\Administrator.exe
C:\WINDOWS\SoftwareDistribution\Download\2abaeb659824de5967ddf7181c6befdb\update\update.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://home.microsof...search.asp?p=%sR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://antispywareup...?aid=496.cbcbcbR1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft...amp;ar=iesearchO2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {433AC9B7-0878-76DF-0A1B-5E00CEC58EEE} - C:\WINDOWS\system32\cje.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll
O2 - BHO: (no name) - {74460762-BDEB-4466-9653-69B4369D146D} - C:\Program Files\Outlook Express\mepov555077.dll
O2 - BHO: (no name) - {75A469FF-0681-4EC3-8CEC-95DB40C9A285} - C:\WINDOWS\system32\pmnmnop.dll
O2 - BHO: (no name) - {84BB2147-33FD-4F0E-B964-A31E461416FD} - C:\WINDOWS\system32\ljjji.dll
O2 - BHO: (no name) - {8A52504F-B31D-4974-BB9D-8B0A9E5C8C13} - C:\Program Files\Common Files\zecojyv777444.dll
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: {e563cf2a-065f-f1f9-35e4-63059017a9fa} - {af9a7109-5036-4e53-9f1f-f560a2fc365e} - C:\WINDOWS\system32\wcuqhkaw.dll (file missing)
O2 - BHO: 0 - {DED879B8-C95C-4649-28B7-B9C6F97E5AE1} - C:\Program Files\Movie Maker\qubapik.dll (file missing)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [448b8978] rundll32.exe "C:\WINDOWS\system32\mhwdwiny.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\WG311v3.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1205010008345O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.ma...ash/swflash.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://plugin.driver...driveragent.cabO18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O20 - Winlogon Notify: pmnmnop - C:\WINDOWS\system32\pmnmnop.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
--
End of file - 5498 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 W8335XP (NETGEAR WG311v3 802.11g Wireless PCI Adapter for Windows XP (8335)) - c:\windows\system32\drivers\wg311v3xp.sys <Not Verified; Marvell Semiconductor, Inc; Device driver for Marvell 802.11 NIC>
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-02-21 and 2008-03-21 -----------------------------
2008-03-21 16:19:07 0 d-------- C:\WINDOWS\LastGood
2008-03-20 19:10:39 1600 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-20 18:47:03 0 d-------- C:\Program Files\180searchassistant
2008-03-20 18:47:03 0 d-------- C:\Program Files\180search assistant
2008-03-20 18:47:01 0 d-------- C:\Program Files\180solutions
2008-03-18 19:05:31 0 dr-h----- C:\$VAULT$.AVG
2008-03-18 18:28:07 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-03-18 18:22:41 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-18 18:15:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-18 18:15:54 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-18 16:36:39 0 d-------- C:\VundoFix Backups
2008-03-18 16:04:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-18 10:48:25 0 d-------- C:\Documents and Settings\Administrator\Application Data\U3
2008-03-18 10:27:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-03-18 10:23:40 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-03-18 10:23:40 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-03-18 10:23:40 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-03-18 10:23:40 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-03-18 10:23:40 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-03-18 10:23:40 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-03-18 10:23:40 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-03-18 10:23:40 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-03-18 10:23:40 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-03-18 10:23:40 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-03-18 10:23:40 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-03-18 10:23:40 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-03-18 10:23:39 2097152 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-03-16 17:08:04 99904 --a------ C:\WINDOWS\system32\ofvutfod.dll
2008-03-16 15:30:33 92224 --a------ C:\WINDOWS\system32\vwydxkei.dll
2008-03-16 15:26:19 99904 --a------ C:\WINDOWS\system32\tqwjvdgp.dll
2008-03-16 14:45:22 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-03-16 14:45:15 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-03-16 14:37:00 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-03-16 14:28:37 135168 --a------ C:\WINDOWS\tk58.exe
2008-03-16 14:27:05 136627 --a------ C:\WINDOWS\POTA777444.exe
2008-03-16 14:26:21 23296 --a------ C:\WINDOWS\stcloader.exe
2008-03-16 14:26:21 0 d-------- C:\Program Files\stc
2008-03-16 14:26:20 14848 --a------ C:\WINDOWS\voiceip.dll
2008-03-16 14:26:19 24064 --a------ C:\WINDOWS\swin32.dll
2008-03-16 14:26:18 31744 --a------ C:\WINDOWS\bokja.exe
2008-03-16 14:26:00 12800 --a------ C:\WINDOWS\mssvr.exe
2008-03-16 14:25:59 8448 --a------ C:\WINDOWS\mspphe.dll
2008-03-16 14:25:51 0 d-------- C:\Program Files\seekmo
2008-03-16 14:25:50 0 d-------- C:\Program Files\zango
2008-03-16 14:25:48 20480 --a------ C:\WINDOWS\system32\WER8274.DLL
2008-03-16 14:25:39 0 d-------- C:\WINDOWS\FLEOK
2008-03-16 14:25:38 18176 --a------ C:\WINDOWS\saiemod.dll
2008-03-16 14:25:32 27392 --a------ C:\WINDOWS\system32\MSNSA32.dll
2008-03-16 14:25:28 20736 --a------ C:\WINDOWS\msapasrc.dll
2008-03-16 14:25:27 16896 --a------ C:\WINDOWS\msa64chk.dll
2008-03-16 14:25:23 28416 --a------ C:\WINDOWS\system32\SIPSPI32.dll
2008-03-16 14:25:21 15616 --a------ C:\WINDOWS\system32\shdocpe.dll
2008-03-16 14:25:21 17664 --a------ C:\WINDOWS\system32\ntnut32.exe
2008-03-16 14:25:20 25856 --a------ C:\WINDOWS\shdocpl.dll
2008-03-16 14:25:19 17920 --a------ C:\WINDOWS\ntnut.exe
2008-03-16 14:25:18 13824 --a------ C:\WINDOWS\shdocpe.dll
2008-03-16 14:25:17 11008 --a------ C:\WINDOWS\winsb.dll
2008-03-16 14:25:17 0 d-------- C:\Program Files\Sysmnt
2008-03-16 14:25:15 11008 --a------ C:\WINDOWS\browserad.dll
2008-03-16 14:25:15 10496 --a------ C:\WINDOWS\aviwrap32.dll
2008-03-16 14:25:15 13312 --a------ C:\WINDOWS\avisynthex32.dll
2008-03-16 14:25:14 15872 --a------ C:\WINDOWS\avifile32.dll
2008-03-16 14:25:14 12544 --a------ C:\WINDOWS\autodisc32.dll
2008-03-16 14:25:14 10752 --a------ C:\WINDOWS\audiosrv32.dll
2008-03-16 14:25:13 16128 --a------ C:\WINDOWS\ati2dvag32.dll
2008-03-16 14:25:13 13312 --a------ C:\WINDOWS\ati2dvaa32.dll
2008-03-16 14:25:13 10752 --a------ C:\WINDOWS\athprxy32.dll
2008-03-16 14:25:13 26112 --a------ C:\WINDOWS\asycfilt32.dll
2008-03-16 14:25:11 9216 --a------ C:\WINDOWS\asferror32.dll
2008-03-16 14:25:11 17408 --a------ C:\WINDOWS\apphelp32.dll
2008-03-16 14:25:10 12800 --a------ C:\WINDOWS\changeurl_30.dll
2008-03-16 14:24:43 99904 --a------ C:\WINDOWS\system32\pcyntmwo.dll
2008-03-16 14:11:38 234723 --ahs---- C:\WINDOWS\system32\ijjjl.ini2
2008-03-16 14:11:37 63 --a------ C:\WINDOWS\system32\448b9bf6
2008-03-16 14:11:24 290816 --a------ C:\WINDOWS\system32\ljjji.dll
2008-03-16 14:10:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-16 14:08:30 0 d-------- C:\Program Files\Outerinfo
2008-03-16 14:08:24 0 d-------- C:\WINDOWS\system32\?icrosoft.NET
2008-03-16 14:08:04 0 d-------- C:\Program Files\Bat
2008-03-16 14:07:41 60928 --a------ C:\WINDOWS\system32\cje.dll
2008-03-16 14:07:26 0 d--hs---- C:\WINDOWS\QW1iZXI
2008-03-16 14:07:18 37376 --a------ C:\WINDOWS\mrofinu1000106.exe
2008-03-16 14:06:36 0 d-------- C:\WINDOWS\system32\IDME
2008-03-16 14:06:36 0 d-------- C:\WINDOWS\system32\FxTmp
2008-03-16 14:06:07 44544 --a------ C:\WINDOWS\system32\pmnmnop.dll
2008-03-16 14:06:04 0 d-------- C:\WINDOWS\system32\aqVreo19
2008-03-16 14:06:03 0 d-------- C:\Temp
2008-03-16 14:06:03 41724 ---hs---- C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
2008-03-16 14:06:01 0 d-------- C:\Documents and Settings\Amber\Application Data\?dobe
2008-03-14 18:23:06 0 d-------- C:\WINDOWS\system32\PreInstall
2008-03-14 18:22:59 0 d--h----- C:\WINDOWS\$hf_mig$
2008-03-13 20:02:18 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-03-13 19:58:04 0 d-------- C:\WINDOWS\Prefetch
2008-03-13 19:30:40 0 d-------- C:\WINDOWS\peernet
2008-03-13 19:30:33 0 d-------- C:\WINDOWS\provisioning
2008-03-13 19:16:16 0 d-------- C:\WINDOWS\ServicePackFiles
2008-03-13 19:00:20 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-03-13 07:32:28 0 d-------- C:\WINDOWS\EHome
2008-03-11 07:23:53 0 d-------- C:\WINDOWS\system32\appmgmt
2008-03-09 15:56:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-03-09 15:54:01 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-09 15:54:01 0 d--h---c- C:\WINDOWS\$xpsp1hfm$
2008-03-08 19:35:19 0 d-------- C:\WINDOWS\ShellNew
2008-03-08 19:21:20 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Identities
2008-03-08 19:06:38 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-03-08 19:06:06 282624 -ra------ C:\WINDOWS\system32\drivers\WG311v3XP.sys <Not Verified; Marvell Semiconductor, Inc; Device driver for Marvell 802.11 NIC>
2008-03-08 18:20:01 0 d-------- C:\WINDOWS\system32\bits
2008-03-08 18:11:50 0 d-------- C:\OEMSettings
2008-03-08 18:08:53 0 d-------- C:\WINDOWS\Downloaded Installations
2008-03-08 18:05:17 0 d-------- C:\Documents and Settings\Amber\Application Data\Macromedia
2008-03-08 18:05:16 0 d-------- C:\Documents and Settings\Amber\Application Data\Adobe
2008-03-08 18:04:44 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
2008-03-08 13:07:36 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-03-08 12:59:35 0 d---s---- C:\Documents and Settings\Amber\UserData
2008-03-08 09:37:13 0 d--hs---- C:\WINDOWS\Installer
2008-03-08 09:37:06 0 d-------- C:\Documents and Settings\Amber\Application Data\Identities
2008-03-08 09:36:22 0 dr------- C:\Documents and Settings\Amber\Favorites
2008-03-08 09:36:22 0 d-------- C:\Documents and Settings\Amber\Desktop
2008-03-08 09:36:22 0 d---s---- C:\Documents and Settings\Amber\Cookies
2008-03-08 09:36:22 0 dr-h----- C:\Documents and Settings\Amber\Application Data
2008-03-08 09:36:22 0 d---s---- C:\Documents and Settings\Amber\Application Data\Microsoft
2008-03-08 09:36:21 0 d--h----- C:\Documents and Settings\Amber\Templates
2008-03-08 09:36:21 0 dr------- C:\Documents and Settings\Amber\Start Menu
2008-03-08 09:36:21 0 dr-h----- C:\Documents and Settings\Amber\SendTo
2008-03-08 09:36:21 0 dr-h----- C:\Documents and Settings\Amber\Recent
2008-03-08 09:36:21 0 d--h----- C:\Documents and Settings\Amber\PrintHood
2008-03-08 09:36:21 1437696 --a------ C:\Documents and Settings\Amber\NTUSER.DAT
2008-03-08 09:36:21 0 d--h----- C:\Documents and Settings\Amber\NetHood
2008-03-08 09:36:21 0 dr------- C:\Documents and Settings\Amber\My Documents
2008-03-08 09:36:21 0 d--h----- C:\Documents and Settings\Amber\Local Settings
2008-03-08 01:03:14 0 d--hs---- C:\System Volume Information
2008-03-08 01:03:09 237568 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-03-08 01:03:09 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-03-08 01:03:09 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-03-08 01:03:09 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-03-08 01:03:09 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-03-08 01:03:07 1572864 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-03-08 01:03:07 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-03-08 01:03:07 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-03-08 01:03:07 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-03-08 01:03:07 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-03-08 00:52:19 0 d-------- C:\WINDOWS\system32\xircom
2008-03-08 00:52:18 0 d-------- C:\Program Files\microsoft frontpage
2008-03-08 00:50:26 237568 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-03-08 00:44:50 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-03-08 00:44:05 0 dr------- C:\WINDOWS\Offline Web Pages
2008-03-08 00:44:05 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-03-08 00:42:27 0 d-------- C:\WINDOWS\srchasst
2008-03-08 00:42:03 0 d-------- C:\WINDOWS\system32\DirectX
2008-03-08 00:42:02 0 d-------- C:\WINDOWS\system32\Macromed
2008-03-08 00:40:41 0 d-------- C:\WINDOWS\system32\Restore
2008-03-08 00:40:29 0 d-------- C:\WINDOWS\PCHEALTH
2008-03-08 00:40:23 0 d---s---- C:\WINDOWS\Tasks
2008-03-08 00:40:16 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-08 00:38:00 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-08 00:37:14 0 d-------- C:\WINDOWS\Registration
2008-03-08 00:35:30 0 d-------- C:\Program Files\Windows NT
2008-03-08 00:35:01 0 d-------- C:\WINDOWS\system32\MsDtc
2008-03-08 00:34:57 0 d-------- C:\WINDOWS\system32\Com
2008-03-07 16:19:30 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-03-07 16:18:35 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-03-07 16:18:35 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-03-07 16:18:35 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-03-07 16:18:35 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-03-07 16:18:35 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-03-07 16:18:35 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-03-07 16:18:35 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-03-07 16:18:35 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-03-07 16:18:35 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-03-07 16:18:35 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-03-07 16:18:35 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-03-07 16:18:35 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-03-07 16:18:35 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-03-07 16:18:35 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-03-07 16:18:35 0 dr------- C:\Documents and Settings\All Users\Documents
2008-03-07 16:18:35 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-03-07 16:18:02 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-03-07 16:18:02 0 d-------- C:\WINDOWS\system32\CatRoot
2008-03-07 16:17:56 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-03-07 16:17:56 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-03-07 16:17:55 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-03-07 16:17:55 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-03-07 16:17:26 0 d-------- C:\Documents and Settings
2008-03-07 16:06:24 0 d-------- C:\WINDOWS
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\WinSxS
2008-03-07 16:06:24 0 dr------- C:\WINDOWS\Web
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\twain_32
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\wins
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\wbem
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\usmt
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\spool
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\ShellExt
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\Setup
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\ras
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\oobe
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\npp
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\mui
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\inetsrv
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\IME
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\icsxml
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\ias
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\export
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\drivers
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-03-07 16:06:24 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\dhcp
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\config
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\3076
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\2052
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1054
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1042
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1041
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1037
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1033
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1031
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1028
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system32\1025
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\system
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\security
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Resources
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\repair
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\mui
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\msapps
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\msagent
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Media
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\java
2008-03-07 16:06:24 0 d--h----- C:\WINDOWS\inf
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\ime
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Help
2008-03-07 16:06:24 0 dr--s---- C:\WINDOWS\Fonts
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Driver Cache
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Debug
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Cursors
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Connection Wizard
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\Config
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\AppPatch
2008-03-07 16:06:24 0 d-------- C:\WINDOWS\addins
2008-03-05 10:43:16 187904 ---hs---- C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
2008-02-27 17:54:15 217088 --a------ C:\Program Files\Common Files\zecojyv777444.dll
-- Find3M Report ---------------------------------------------------------------
2008-03-18 19:05:35 0 dr------- C:\Program Files\Movie Maker
2008-03-16 14:27:34 0 dr------- C:\Program Files\Common Files
2008-03-13 19:57:02 0 dr------- C:\Program Files\Messenger
2008-03-08 18:10:35 0 d-------- C:\Program Files\NETGEAR
2008-03-08 13:14:27 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-08 00:43:08 0 d-------- C:\Program Files\Online Services
2008-03-07 16:18:35 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{433AC9B7-0878-76DF-0A1B-5E00CEC58EEE}]
01/28/2008 08:29 AM 60928 --a------ C:\WINDOWS\system32\cje.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{622cc208-b014-4fe0-801b-874a5e5e403a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63F7460B-C831-4142-A4AA-5EC303EC4343}]
03/07/2008 09:15 PM 413696 --a------ C:\Program Files\Bat\Bat.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74460762-BDEB-4466-9653-69B4369D146D}]
08/02/2007 05:43 AM 282624 --a------ C:\Program Files\Outlook Express\mepov555077.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75A469FF-0681-4EC3-8CEC-95DB40C9A285}]
03/16/2008 02:06 PM 44544 --a------ C:\WINDOWS\system32\pmnmnop.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84BB2147-33FD-4F0E-B964-A31E461416FD}]
03/16/2008 02:11 PM 290816 --a------ C:\WINDOWS\system32\ljjji.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A52504F-B31D-4974-BB9D-8B0A9E5C8C13}]
02/27/2008 05:54 PM 217088 --a------ C:\Program Files\Common Files\zecojyv777444.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c5b2f29-1f46-4639-a6b4-828942301d3e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{af9a7109-5036-4e53-9f1f-f560a2fc365e}]
C:\WINDOWS\system32\wcuqhkaw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DED879B8-C95C-4649-28B7-B9C6F97E5AE1}]
C:\Program Files\Movie Maker\qubapik.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"runner1"="C:\WINDOWS\mrofinu1000106.exe" [03/16/2008 02:07 PM]
"448b8978"="C:\WINDOWS\system32\mhwdwiny.dll" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [03/18/2008 06:17 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/12/2001 5:01:04 PM]
NETGEAR WG311v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311v3\WG311v3.exe [11/21/2007 5:51:20 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{75A469FF-0681-4EC3-8CEC-95DB40C9A285}"= C:\WINDOWS\system32\pmnmnop.dll [03/16/2008 02:06 PM 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmnop]
pmnmnop.dll 03/16/2008 02:06 PM 44544 C:\WINDOWS\system32\pmnmnop.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ljjji.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\LaunchU3.exe -a
-- Hosts -----------------------------------------------------------------------
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
8027 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-03-21 17:00:01 ------------
and the extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel Celeron processor
Percentage of Memory in Use: 74%
Physical Memory (total/avail): 127.42 MiB / 32.96 MiB
Pagefile Memory (total/avail): 307.09 MiB / 64.48 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1949.39 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 5.59 GiB total, 0.38 GiB free.
D: is CDROM (No Media)
E: is CDROM (CDFS)
F: is Removable (FAT)
\\.\PHYSICALDRIVE0 - TOSHIBA MK6015MAP - 5.59 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 5.59 GiB - C:
\\.\PHYSICALDRIVE1 - SanDisk U3 Cruzer Micro USB Device - 1953.22 MiB - 1 partition
\PARTITION0 - MS-DOS V4 Huge - 1952.88 MiB - F:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: AVG 7.5.503 v7.5.503 (Grisoft)
Outdated[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AMBER-BW9KC1SN8
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
LOGONSERVER=\\AMBER-BW9KC1SN8
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS;C:\WINDOWS\COMMAND
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0803
ProgramFiles=C:\Program Files
PROMPT=$p$g
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
USERDOMAIN=AMBER-BW9KC1SN8
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
winbootdir=C:\WINDOWS
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Amber
(admin)Administrator
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
Bat --> "C:\Program Files\Bat\un_BatSetup_15041.exe"
HijackThis 2.0.2 --> "C:\Documents and Settings\Administrator\Desktop\HijackThis.exe" /uninstall
Microsoft Office XP Standard --> MsiExec.exe /I{90120409-6000-11D3-8CFE-0050048383C9}
NETGEAR WG311v3 PCI Adapter --> C:\Program Files\InstallShield Installation Information\{70014586-7BBA-4A92-A610-CDC896C48F8F}\setup.exe -runfromtemp -l0x0409
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
-- Application Event Log -------------------------------------------------------
Event Record #/Type143 / Error
Event Submitted/Written: 03/19/2008 04:46:17 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application rundll32.exe, version 5.1.2600.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type137 / Error
Event Submitted/Written: 03/19/2008 03:42:56 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application mgmrwmrv.exe, version 1.0.0.384, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type132 / Error
Event Submitted/Written: 03/18/2008 07:20:18 PM
Event ID/Source: 100 / AVG7
Event Description:
2008-03-19 03:20:18,656 AMBER-BW9KC1SN8 [001436:001448] ERROR 000 AVG7.WTS.CAvgAmWts ProcessIdToSessionId(468) call failed with WIN32 error 87, returning session id is 0
Event Record #/Type131 / Error
Event Submitted/Written: 03/18/2008 07:20:11 PM / 03/18/2008 07:20:12 PM
Event ID/Source: 100 / AVG7
Event Description:
2008-03-19 03:20:11,936 AMBER-BW9KC1SN8 [001436:001448] ERROR 000 AVG7.WTS.CAvgAmWts ProcessIdToSessionId(468) call failed with WIN32 error 87, returning session id is 0
Event Record #/Type127 / Error
Event Submitted/Written: 03/18/2008 06:48:51 PM
Event ID/Source: 100 / AVG7
Event Description:
2008-03-19 02:48:51,873 AMBER-BW9KC1SN8 [001392:001400] ERROR 000 AVG7.WTS.CAvgAmWts ProcessIdToSessionId(1604) call failed with WIN32 error 87, returning session id is 0
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1105 / Error
Event Submitted/Written: 03/21/2008 03:59:19 PM / 03/21/2008 04:01:40 PM
Event ID/Source: 5 / ACPI
Event Description:
AMLI: ACPI BIOS is attempting to write to an illegal IO port address (0x4d0), which lies in the 0x4d0 - 0x4d1 protected
address range. This could lead to system instability. Please contact your system vendor for technical assistance.
Event Record #/Type1104 / Error
Event Submitted/Written: 03/21/2008 03:59:19 PM / 03/21/2008 04:01:39 PM
Event ID/Source: 4 / ACPI
Event Description:
AMLI: ACPI BIOS is attempting to read from an illegal IO port address (0x4d0), which lies in the 0x4d0 - 0x4d1 protected
address range. This could lead to system instability. Please contact your system vendor for technical assistance.
Event Record #/Type1095 / Error
Event Submitted/Written: 03/20/2008 09:36:58 PM
Event ID/Source: 16 / Windows Update Agent
Event Description:
Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
Event Record #/Type1083 / Error
Event Submitted/Written: 03/20/2008 08:45:56 PM / 03/20/2008 08:47:51 PM
Event ID/Source: 5 / ACPI
Event Description:
AMLI: ACPI BIOS is attempting to write to an illegal IO port address (0x4d0), which lies in the 0x4d0 - 0x4d1 protected
address range. This could lead to system instability. Please contact your system vendor for technical assistance.
Event Record #/Type1082 / Error
Event Submitted/Written: 03/20/2008 08:45:56 PM / 03/20/2008 08:47:51 PM
Event ID/Source: 4 / ACPI
Event Description:
AMLI: ACPI BIOS is attempting to read from an illegal IO port address (0x4d0), which lies in the 0x4d0 - 0x4d1 protected
address range. This could lead to system instability. Please contact your system vendor for technical assistance.
-- End of Deckard's System Scanner: finished at 2008-03-21 17:00:01 ------------