dss report as well if it helps
Deckard's System Scanner v20071014.68
Run by Owner on 2008-08-06 20:07:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
31: 2008-08-07 00:07:52 UTC - RP47 - Deckard's System Scanner Restore Point
30: 2008-08-06 21:36:17 UTC - RP46 - Advanced WindowsCare RestorePoint
29: 2008-08-06 20:34:24 UTC - RP45 - Restore Operation
28: 2008-08-06 17:31:51 UTC - RP44 - Installed Trend Micro RUBotted
27: 2008-08-06 17:31:14 UTC - RP43 - Installed Trend Micro RUBotted
-- First Restore Point --
1: 2008-07-30 12:54:07 UTC - RP17 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 84% (more than 75%).Total Physical Memory: 254 MiB (512 MiB recommended).-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:39 PM, on 8/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe
C:\Program Files\AntiVir PersonalEdition Premium\sched.exe
C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\explorer.exe
C:\Program Files\IObit\Advanced WindowsCare V2 Pro\MemCleaner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\IObit\Advanced WindowsCare V2 Pro\Awc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\3HH5YTO9\dss[1].exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
O2 - BHO: (no name) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
O2 - BHO: BhoApp Class - {32324134-3465-4325-6543-325435274523} - C:\Program Files\altcmd\almd32.dll
O2 - BHO: BhoApp Class - {45531D08-A710-B0E6-14C1-D4E2BEA6B724} - C:\Program Files\altcmd\almd32.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5DFB9A9E-6B44-42BC-9142-667AD9C6C8D1} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {80F1B0D1-9425-4197-8B12-3FA84C28F7F7} - C:\WINDOWS\system32\qoMfCsRH.dll
O2 - BHO: {2ec15923-37d9-1b79-b4e4-50b525e614dc} - {cd416e52-5b05-4e4b-97b1-9d7332951ce2} - C:\WINDOWS\system32\khegtl.dll
O2 - BHO: (no name) - {DFE1905B-2E72-4FE3-A4E5-98046608E57E} - C:\WINDOWS\system32\awtqroNh.dll
O2 - BHO: (no name) - {E39B56FF-BDFB-4C7B-A07A-001962168FE9} - (no file)
O2 - BHO: (no name) - {EBFBDC98-F19F-4B00-B97F-19FDA259C069} - C:\WINDOWS\system32\aenhbmtx.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Modem Booster] C:\Program Files\inKline Global\Modem Booster\ModemBtr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" /min
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [SmartRAM] C:\Program Files\IObit\Advanced WindowsCare V2 Pro\MemCleaner.exe /m
O4 - HKLM\..\Run: [e016fcf0] rundll32.exe "C:\WINDOWS\system32\ccvwtpvc.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1216093607632O17 - HKLM\System\CCS\Services\Tcpip\..\{E290DBC2-AB89-4EDF-A85A-F47282F23AAD}: NameServer = 209.244.0.3 209.244.0.4
O20 - Winlogon Notify: qoMfCsRH - C:\WINDOWS\SYSTEM32\qoMfCsRH.dll
O23 - Service: AntiVir PersonalEdition Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe
O23 - Service: AntiVir PersonalEdition Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: AntiVir PersonalEdition Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe
O23 - Service: AntiVir PersonalEdition Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 6931 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080730-135836-154 O4 - HKLM\..\RunOnce: [SpybotDeletingA7690] command /c del "C:\Program Files\webHancer\Programs\whagent.ini"
backup-20080730-135836-729 O17 - HKLM\System\CCS\Services\Tcpip\..\{E290DBC2-AB89-4EDF-A85A-F47282F23AAD}: NameServer = 209.244.0.3 209.244.0.4
backup-20080730-135836-759 O4 - HKLM\..\RunOnce: [SpybotDeletingC9969] cmd /c del "C:\Program Files\webHancer\Programs\readme.txt"
backup-20080730-135836-875 O4 - HKLM\..\RunOnce: [SpybotDeletingC8618] cmd /c del "C:\Program Files\webHancer\Programs\sporder.dll"
backup-20080730-135836-906 O4 - HKLM\..\RunOnce: [SpybotDeletingC5787] cmd /c del "C:\Program Files\webHancer\Programs\whagent.ini"
backup-20080730-135836-979 O4 - HKLM\..\RunOnce: [SpybotDeletingA2179] command /c del "C:\Program Files\webHancer\Programs\readme.txt"
backup-20080730-140406-547 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157backup-20080730-140406-826 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157backup-20080730-140406-897 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896backup-20080730-140406-993 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896backup-20080731-205929-479 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\ymilkjxh.dll",s
backup-20080731-205929-521 O4 - HKLM\..\Run: [e016fcf0] rundll32.exe "C:\WINDOWS\system32\vmaevthw.dll",b
backup-20080802-001820-999 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\vdfwyrto.dll",s
backup-20080802-001821-280 O4 - HKLM\..\Run: [e016fcf0] rundll32.exe "C:\WINDOWS\system32\dimkcwkx.dll",b
backup-20080802-001821-455 O20 - AppInit_DLLs: sdmcfr.dll
backup-20080802-001915-117 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\vdfwyrto.dll",s
backup-20080802-002006-426 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\vdfwyrto.dll",s
backup-20080803-063011-165 O20 - AppInit_DLLs: xucspt.dll
backup-20080803-063011-759 O4 - HKLM\..\Run: [e016fcf0] rundll32.exe "C:\WINDOWS\system32\fcsfxbag.dll",b
backup-20080803-063011-967 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\fqyujhvp.dll",s
backup-20080803-063058-877 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\fqyujhvp.dll",s
backup-20080803-063250-333 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\fqyujhvp.dll",s
backup-20080805-095045-772 O4 - HKLM\..\Run: [e016fcf0] rundll32.exe "C:\WINDOWS\system32\ilittygr.dll",b
backup-20080805-095045-938 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\fksjkonx.dll",s
backup-20080805-095115-876 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\fksjkonx.dll",s
backup-20080806-005039-789 O4 - HKLM\..\Run: [BMe325cf6c] Rundll32.exe "C:\WINDOWS\system32\lqhpgfhn.dll",s
backup-20080806-121535-451 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080806-121537-786 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirMailService (AntiVir PersonalEdition Premium MailGuard) - "c:\program files\antivir personaledition premium\avmailc.exe" <Not Verified; Avira GmbH; AntiVir Mail Guard>
R2 AntiVirScheduler (AntiVir PersonalEdition Premium Scheduler) - "c:\program files\antivir personaledition premium\sched.exe" <Not Verified; Avira GmbH; Scheduler>
R2 AVEService (AntiVir PersonalEdition Premium MailGuard helper service) - "c:\program files\antivir personaledition premium\avesvc.exe" <Not Verified; Avira GmbH; AVE Service>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel® PRO/100 VE Network Connection
Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_01D51028&REV_02\4&1C660DD6&0&40F0
Manufacturer: Intel
Name: Intel® PRO/100 VE Network Connection
PNP Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_01D51028&REV_02\4&1C660DD6&0&40F0
Service: E100B
-- Files created between 2008-07-06 and 2008-08-06 -----------------------------
2008-08-14 19:12:01 0 d--hs---- C:\WINDOWS\Installer
2008-08-14 19:12:00 0 d-------- C:\Program Files\Common Files\ODBC
2008-08-14 19:11:57 0 dr------- C:\Program Files
2008-08-14 19:11:57 0 d-------- C:\Program Files\Common Files
2008-08-14 19:11:57 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-08-14 19:11:35 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-08-14 19:11:35 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-08-14 19:11:35 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-08-14 19:11:35 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-08-14 19:11:35 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-08-14 19:11:35 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-08-14 19:11:35 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-08-14 19:11:35 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-08-14 19:11:35 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-08-14 19:11:35 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-08-14 19:11:35 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-08-14 19:11:35 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-08-14 19:11:35 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-08-14 19:11:35 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-08-14 19:11:35 0 dr------- C:\Documents and Settings\All Users\Documents
2008-08-14 19:11:35 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-08-14 19:11:21 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-08-14 19:11:21 0 d-------- C:\WINDOWS\system32\CatRoot
2008-08-14 19:11:16 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-08-14 19:11:16 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-08-14 19:11:16 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-08-14 19:11:16 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-08-14 19:10:56 0 d--hs---- C:\System Volume Information
2008-08-14 19:10:56 0 d-------- C:\Documents and Settings
2008-08-14 19:04:27 0 d-------- C:\WINDOWS
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\WinSxS
2008-08-14 19:04:27 0 dr------- C:\WINDOWS\Web
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\twain_32
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\wins
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\wbem
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\usmt
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\spool
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\ShellExt
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\Setup
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\ras
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\oobe
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\npp
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\mui
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\inetsrv
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\IME
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\icsxml
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\ias
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\export
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\drivers
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-08-14 19:04:27 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\dhcp
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\config
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\3076
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\2052
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1054
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1042
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1041
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1037
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1033
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1031
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1028
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system32\1025
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\system
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\security
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Resources
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\repair
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Provisioning
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\PeerNet
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\pchealth
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\mui
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\msapps
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\msagent
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Media
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\java
2008-08-14 19:04:27 0 d--h----- C:\WINDOWS\inf
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\ime
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Help
2008-08-14 19:04:27 0 dr--s---- C:\WINDOWS\Fonts
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Driver Cache
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\dell
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Debug
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Cursors
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Connection Wizard
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\Config
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\AppPatch
2008-08-14 19:04:27 0 d-------- C:\WINDOWS\addins
2008-08-06 19:04:01 95744 --a------ C:\WINDOWS\system32\khegtl.dll
2008-08-06 19:03:39 95744 --a------ C:\WINDOWS\system32\qirrbtid.dll
2008-08-06 19:03:21 2048 --a------ C:\WINDOWS\system32\sxhxjiee.exe
2008-08-06 19:01:39 80896 --a------ C:\WINDOWS\system32\ccvwtpvc.dll
2008-08-06 18:11:48 0 d-------- C:\Documents and Settings\Owner\Application Data\IObit
2008-08-06 17:34:41 10052 --a------ C:\WINDOWS\msvrc20.dll
2008-08-06 17:34:40 0 d-------- C:\Program Files\IObit
2008-08-05 19:05:31 81408 --a------ C:\WINDOWS\system32\oypdmxpq.dll
2008-08-05 19:02:25 2048 --a------ C:\WINDOWS\system32\gsahocyy.exe
2008-08-05 19:01:42 96768 --a------ C:\WINDOWS\system32\ytqkwj.dll
2008-08-05 19:00:52 96768 --a------ C:\WINDOWS\system32\gykthlja.dll
2008-08-05 18:59:33 90112 --a------ C:\WINDOWS\system32\lqhpgfhn.dll
2008-08-04 23:51:13 4456448 --a------ C:\Documents and Settings\Owner\ntuser.dat
2008-08-04 23:51:12 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-08-04 19:04:38 2048 --a------ C:\WINDOWS\system32\hdxryoyr.exe
2008-08-04 19:02:07 95744 --a------ C:\WINDOWS\system32\nrtvod.dll
2008-08-04 19:01:36 95744 --a------ C:\WINDOWS\system32\ilonvijg.dll
2008-08-04 18:59:36 80384 --a------ C:\WINDOWS\system32\ilittygr.dll
2008-08-04 18:58:44 91648 --a------ C:\WINDOWS\system32\fksjkonx.dll
2008-08-03 18:59:25 37676 --a------ C:\WINDOWS\system32\fjyrnhcl.dll
2008-08-03 18:56:41 90624 --a------ C:\WINDOWS\system32\spqghovc.dll
2008-08-03 18:55:26 90624 --a------ C:\WINDOWS\system32\exlbyblw.dll
2008-08-03 07:30:08 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-08-03 06:50:16 0 d-------- C:\Program Files\PrivacyEraser Computing
2008-08-02 18:52:52 118784 --a------ C:\WINDOWS\system32\aenhbmtx.dll
2008-08-02 18:50:34 80896 --a------ C:\WINDOWS\system32\fcsfxbag.dll
2008-08-02 18:49:52 100864 --a------ C:\WINDOWS\system32\xucspt.dll
2008-08-02 18:49:18 100864 --a------ C:\WINDOWS\system32\mocysleh.dll
2008-08-02 18:46:08 90624 --a------ C:\WINDOWS\system32\fqyujhvp.dll
2008-08-01 18:48:58 80896 --a------ C:\WINDOWS\system32\dimkcwkx.dll
2008-08-01 18:47:00 102400 --a------ C:\WINDOWS\system32\sdmcfr.dll
2008-08-01 18:46:39 102400 --a------ C:\WINDOWS\system32\nqnseyci.dll
2008-08-01 18:45:50 90624 --a------ C:\WINDOWS\system32\vdfwyrto.dll
2008-07-31 16:27:02 95232 --a------ C:\WINDOWS\system32\xdmnef.dll
2008-07-31 16:27:02 95232 --a------ C:\WINDOWS\system32\hafectmh.dll
2008-07-31 16:26:12 80384 --a------ C:\WINDOWS\system32\vmaevthw.dll
2008-07-31 16:21:52 95232 --a------ C:\WINDOWS\system32\zgjzpd.dll
2008-07-31 16:21:27 95232 --a------ C:\WINDOWS\system32\uqgtypkq.dll
2008-07-31 16:19:55 90112 --a------ C:\WINDOWS\system32\cjfbdvqv.dll
2008-07-30 16:20:19 95744 --a------ C:\WINDOWS\system32\nhhuyg.dll
2008-07-30 16:19:56 95744 --a------ C:\WINDOWS\system32\fafawabi.dll
2008-07-30 16:16:57 81408 --a------ C:\WINDOWS\system32\rlrxopaj.dll
2008-07-30 16:15:10 89600 --a------ C:\WINDOWS\system32\mqpdqwqp.dll
2008-07-30 13:56:42 0 d-------- C:\Program Files\Trend Micro
2008-07-30 13:29:34 0 d-------- C:\WINDOWS\pss
2008-07-30 08:58:03 94720 --a------ C:\WINDOWS\system32\mqtrzk.dll
2008-07-30 08:57:38 94720 --a------ C:\WINDOWS\system32\tdctdeks.dll
2008-07-30 08:53:57 36864 --a------ C:\WINDOWS\system32\cbXOEwUK.dll
2008-07-30 08:53:56 36864 --a------ C:\WINDOWS\system32\awtQgGYo.dll
2008-07-30 08:53:44 898875 --ahs---- C:\WINDOWS\system32\hNorqtwa.ini2
2008-07-30 08:50:29 246272 --a------ C:\WINDOWS\system32\awtqroNh.dll
2008-07-30 08:47:44 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-07-30 08:46:42 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-07-30 08:46:12 0 d-------- C:\Program Files\altcmd
2008-07-30 08:45:08 36864 --a------ C:\WINDOWS\system32\vtUnmLfE.dll
2008-07-30 08:45:08 0 d-------- C:\Program Files\LimeWire
2008-07-30 08:45:07 36864 --a------ C:\WINDOWS\system32\qoMfCsRH.dll
2008-07-30 00:08:34 0 d-------- C:\WINDOWS\system32\URTTemp
2008-07-28 19:01:30 0 d-------- C:\Program Files\CalculatemPro
2008-07-28 17:41:59 0 d-------- C:\Program Files\Magic Holdem
2008-07-28 15:50:20 0 d-------- C:\Program Files\Tournament Indicator
2008-07-28 06:57:35 0 d-------- C:\WINDOWS\RegisteredPackages
2008-07-27 04:19:12 0 d-------- C:\Program Files\Xtreme Forum Manager
2008-07-24 15:46:00 0 d-------- C:\WINDOWS\ie8updates
2008-07-24 15:43:30 0 d--h---c- C:\WINDOWS\ie8
2008-07-24 05:53:19 0 d-------- C:\WINDOWS\Sun
2008-07-21 11:27:06 0 d-------- C:\Documents and Settings\All Users\Application Data\RoboForm
2008-07-21 11:26:51 0 d-------- C:\Program Files\Siber Systems
2008-07-18 11:38:01 0 d-------- C:\Program Files\uTorrent
2008-07-18 11:37:59 0 d-------- C:\Documents and Settings\Owner\Application Data\uTorrent
2008-07-18 09:42:11 0 d-------- C:\Program Files\Holdem Indicator
2008-07-18 09:41:34 0 d-------- C:\Program Files\Full Tilt Poker
2008-07-18 03:28:39 0 d-------- C:\Program Files\Winamp
2008-07-18 03:28:39 0 d-------- C:\Documents and Settings\Owner\Application Data\Winamp
2008-07-18 02:13:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-07-17 19:58:43 0 d-------- C:\Program Files\Yahoo!
2008-07-16 20:30:04 0 d-------- C:\Documents and Settings\Owner\Application Data\Thinstall
2008-07-16 13:48:30 0 d-------- C:\Documents and Settings\Owner\Application Data\AntiVir PersonalEdition Premium
2008-07-16 12:11:39 0 d-------- C:\Documents and Settings\Owner\Application Data\Smart PC Solutions
2008-07-16 12:11:05 0 d-------- C:\Program Files\Smart PC Solutions
2008-07-16 08:12:01 0 d-------- C:\FBPUpdate
2008-07-16 08:09:11 101888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-07-16 08:09:10 0 d-------- C:\Program Files\FriendBlasterPro
2008-07-16 04:33:20 0 d-------- C:\Downloads
2008-07-16 03:41:51 0 d-------- C:\Program Files\AntiVir PersonalEdition Premium
2008-07-16 03:41:51 0 d-------- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Premium
2008-07-15 13:25:03 0 d-------- C:\Program Files\Java
2008-07-15 13:25:01 0 d-------- C:\Program Files\Common Files\Java
2008-07-15 13:23:07 0 d-------- C:\Documents and Settings\Owner\Application Data\Sun
2008-07-15 10:15:00 0 d-------- C:\WINDOWS\system32\Adobe
2008-07-15 10:11:08 0 d-------- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-07-15 10:11:08 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2008-07-15 10:06:12 0 d-------- C:\Program Files\FlashGet
2008-07-15 08:27:07 0 d-------- C:\Program Files\inKline Global
2008-07-15 07:39:45 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-07-15 07:39:34 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-07-15 07:39:12 0 d-------- C:\WINDOWS\Internet Logs
2008-07-15 07:37:07 0 d-------- C:\Documents and Settings\Owner\Application Data\WinRAR
2008-07-15 04:25:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-15 00:22:36 0 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-15 00:10:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-07-15 00:09:51 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-14 23:52:48 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-14 23:45:32 0 d--hs---- C:\Documents and Settings\Owner\UserData
2008-07-14 23:36:35 0 d-------- C:\drvrtmp
2008-07-14 23:36:04 0 d-------- C:\Program Files\CONEXANT
2008-07-14 23:34:48 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-07-14 23:34:47 0 d-------- C:\Program Files\Intel
2008-07-14 23:33:44 0 d-------- C:\WINDOWS\VirtualEar
2008-07-14 23:33:44 49152 --a------ C:\WINDOWS\system32\DSndUp.exe <Not Verified; Analog Devices Inc.; adi DSndUp>
2008-07-14 23:33:44 45056 --a------ C:\WINDOWS\system32\CleanUp.exe <Not Verified; adi; adi CleanUp>
2008-07-14 23:33:44 65536 --a------ C:\WINDOWS\system32\Audio3d.dll <Not Verified; Sensaura Ltd; Sensaura>
2008-07-14 23:33:44 0 d-------- C:\Program Files\Analog Devices
2008-07-14 23:33:43 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-14 23:33:03 0 d-------- C:\WINDOWS\system32\vmm32
2008-07-14 23:33:03 0 d-------- C:\Program Files\Dell
2008-07-14 23:32:48 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-14 23:30:34 0 d-------- C:\Documents and Settings\Owner\Application Data\Identities
2008-07-14 23:30:25 0 d--h----- C:\Documents and Settings\Owner\Local Settings
2008-07-14 23:30:25 0 dr------- C:\Documents and Settings\Owner\Favorites
2008-07-14 23:30:25 0 d-------- C:\Documents and Settings\Owner\Desktop
2008-07-14 23:30:25 0 d--hs---- C:\Documents and Settings\Owner\Cookies
2008-07-14 23:30:25 0 d--h----- C:\Documents and Settings\Owner\Application Data
2008-07-14 23:30:24 0 d--h----- C:\Documents and Settings\Owner\Templates
2008-07-14 23:30:24 0 dr------- C:\Documents and Settings\Owner\Start Menu
2008-07-14 23:30:24 0 dr-h----- C:\Documents and Settings\Owner\SendTo
2008-07-14 23:30:24 0 d--h----- C:\Documents and Settings\Owner\PrintHood
2008-07-14 23:30:24 0 d--h----- C:\Documents and Settings\Owner\NetHood
2008-07-14 23:30:24 0 dr------- C:\Documents and Settings\Owner\My Documents
2008-07-14 23:30:18 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-07-14 23:30:16 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-07-14 23:30:16 0 d-------- C:\WINDOWS\Prefetch
2008-07-14 23:30:15 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-07-14 23:30:15 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-07-14 23:30:15 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-07-14 23:30:15 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-07-14 23:26:23 229376 --a------ C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-07-14 23:26:23 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-07-14 23:26:23 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-07-14 23:26:23 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-07-14 23:26:23 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-07-14 23:23:22 0 d-------- C:\WINDOWS\system32\xircom
2008-07-14 23:23:22 0 d-------- C:\Program Files\microsoft frontpage
2008-07-14 23:23:19 225280 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-07-14 23:23:19 0 d-------- C:\DELL
2008-07-14 23:23:08 0 d--h----- C:\WINDOWS\$hf_mig$
2008-07-14 23:22:56 0 -rahs---- C:\MSDOS.SYS
2008-07-14 23:22:56 0 -rahs---- C:\IO.SYS
2008-07-14 23:22:56 0 --a------ C:\CONFIG.SYS
2008-07-14 23:22:56 0 --a------ C:\AUTOEXEC.BAT
2008-07-14 23:21:48 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-07-14 23:21:37 0 dr------- C:\WINDOWS\Offline Web Pages
2008-07-14 23:21:36 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-07-14 23:21:25 0 d--h----- C:\Program Files\WindowsUpdate
2008-07-14 23:21:06 0 d-------- C:\WINDOWS\system32\DirectX
2008-07-14 23:20:39 0 d---s---- C:\WINDOWS\Tasks
2008-07-14 23:20:38 0 d-------- C:\Program Files\Common Files\MSSoap
2008-07-14 23:20:35 0 d-------- C:\WINDOWS\system32\Macromed
2008-07-14 23:20:35 0 d-------- C:\WINDOWS\srchasst
2008-07-14 23:20:28 0 d-------- C:\Program Files\Movie Maker
2008-07-14 23:20:22 0 d-------- C:\WINDOWS\system32\Restore
2008-07-14 23:20:06 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-07-14 23:19:51 0 d-------- C:\WINDOWS\Registration
2008-07-14 23:19:20 0 d-------- C:\Program Files\Online Services
2008-07-14 23:19:15 0 d-------- C:\Program Files\Messenger
2008-07-14 23:19:12 0 d-------- C:\Program Files\MSN Gaming Zone
2008-07-14 23:18:41 0 d-------- C:\Program Files\Windows NT
2008-07-14 23:18:38 0 d-------- C:\WINDOWS\system32\MsDtc
2008-07-14 23:18:37 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2008-08-14 19:11:35 62 --ahs---- C:\Documents and Settings\Owner\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32324134-3465-4325-6543-325435274523}]
07/31/2008 07:06 PM 167936 --a------ C:\Program Files\altcmd\almd32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45531D08-A710-B0E6-14C1-D4E2BEA6B724}]
07/31/2008 07:06 PM 167936 --a------ C:\Program Files\altcmd\almd32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DFB9A9E-6B44-42BC-9142-667AD9C6C8D1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80F1B0D1-9425-4197-8B12-3FA84C28F7F7}]
07/30/2008 08:45 AM 36864 --a------ C:\WINDOWS\system32\qoMfCsRH.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd416e52-5b05-4e4b-97b1-9d7332951ce2}]
08/06/2008 07:04 PM 95744 --a------ C:\WINDOWS\system32\khegtl.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DFE1905B-2E72-4FE3-A4E5-98046608E57E}]
07/30/2008 08:53 AM 246272 --a------ C:\WINDOWS\system32\awtqroNh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E39B56FF-BDFB-4C7B-A07A-001962168FE9}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EBFBDC98-F19F-4B00-B97F-19FDA259C069}]
08/02/2008 06:53 PM 118784 --a------ C:\WINDOWS\system32\aenhbmtx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [10/14/2004 02:42 PM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07/09/2008 09:05 AM]
"Modem Booster"="C:\Program Files\inKline Global\Modem Booster\ModemBtr.exe" [10/10/2003 12:53 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" [04/02/2007 10:35 AM]
"Flashget"="C:\Program Files\FlashGet\flashget.exe" [09/20/2007 03:21 AM]
"SmartRAM"="C:\Program Files\IObit\Advanced WindowsCare V2 Pro\MemCleaner.exe" [10/29/2007 04:43 PM]
"e016fcf0"="C:\WINDOWS\system32\ccvwtpvc.dll" [08/06/2008 07:01 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=0 (0x0)
"LinkResolveIgnoreLinkInfo"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{80F1B0D1-9425-4197-8B12-3FA84C28F7F7}"= C:\WINDOWS\system32\qoMfCsRH.dll [07/30/2008 08:45 AM 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qoMfCsRH]
qoMfCsRH.dll 07/30/2008 08:45 AM 36864 C:\WINDOWS\system32\qoMfCsRH.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtqroNh
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\e016fcf0]
rundll32.exe "C:\WINDOWS\system32\hqmobnei.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8972 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-08-06 20:13:08 ------------