Deckard's System Scanner v20071014.68
Run by DADDY on 2008-02-08 19:31:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
13: 2008-02-08 23:41:57 UTC - RP14 - Windows Update
12: 2008-02-08 23:36:25 UTC - RP13 - Removed Seagate*DiscWizard
11: 2008-02-08 22:53:05 UTC - RP12 - Installed AVG 7.5
10: 2008-02-08 22:00:07 UTC - RP11 - Windows Update
9: 2008-02-07 02:41:57 UTC - RP10 - Windows Update
-- First Restore Point --
1: 2008-02-04 23:07:37 UTC - RP2 - Device Driver Package Install: ATI Technologies Inc. Display adapters
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-08 19:40:02
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\System32\csrss.exe
C:\Windows\System32\wininit.exe
C:\Windows\System32\csrss.exe
C:\Windows\System32\services.exe
C:\Windows\System32\lsass.exe
C:\Windows\System32\lsm.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\winlogon.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\SLsvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\taskeng.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\SearchIndexer.exe
C:\Windows\System32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\DADDY\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\71ZP3NUT\dss[1].exe
C:\Windows\System32\taskeng.exe
C:\Windows\System32\notepad.exe
C:\Windows\System32\SearchProtocolHost.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\SearchFilterHost.exe
C:\Windows\System32\FirewallControlPanel.exe
C:\Windows\System32\rundll32.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\Program Files\Spyware Doctor\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://download.microsoft.com/downlo...eckControl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://prerelease.trendmicro-europe....vex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\system32\avgwlntf.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
--
End of file - 6520 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 51056 - \??\c:\windows\system32\51056.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft 6to4 Adapter
Device ID: ROOT\*6TO4MP\0000
Manufacturer: Microsoft
Name: Microsoft 6to4 Adapter
PNP Device ID: ROOT\*6TO4MP\0000
Service: tunnel
Class GUID:
Description: Scanner Interface
Device ID: USB\VID_043D&PID_008A&MI_00\7&2727A618&0&0000
Manufacturer:
Name: Scanner Interface
PNP Device ID: USB\VID_043D&PID_008A&MI_00\7&2727A618&0&0000
Service:
-- Files created between 2008-01-08 and 2008-02-08 -----------------------------
2008-02-08 19:15:43 2560 --a------ C:\Windows\_MSRSTRT.EXE
2008-02-08 18:38:22 0 d-------- C:\Windows\system32\appmgmt
2008-02-08 18:12:58 0 dr-h----- C:\$VAULT$.AVG
2008-02-08 17:53:21 0 d-------- C:\Users\All Users\avg7
2008-02-07 20:25:32 0 d-------- C:\Users\All Users\Seagate
2008-02-05 15:52:20 32768 --a------ C:\Windows\system32\drivers\tifsfilt.sys <Not Verified; Acronis; Acronis True Image>
2008-02-05 15:51:59 0 d-------- C:\Program Files\Common Files\Seagate
2008-02-05 15:45:57 0 d-------- C:\Program Files\BitLocker
2008-02-05 15:45:28 0 --a------ C:\Windows\ativpsrm.bin
2008-02-04 23:05:09 1732 --a------ C:\Windows\system32\drivers\nvphy.bin
2008-02-04 22:43:26 0 d-------- C:\Users\All Users\Grisoft
2008-02-04 22:18:02 0 -rahs---- C:\MSDOS.SYS
2008-02-04 22:18:02 0 -rahs---- C:\IO.SYS
2008-02-04 20:36:44 0 d-------- C:\Windows\system32\HouseCall 6.6
2008-02-04 20:27:31 0 d-------- C:\Windows\SoftwareDistribution
2008-02-04 20:25:26 0 d-------- C:\Windows\Debug
2008-02-04 20:25:26 0 d-------- C:\Windows\CSC
2008-02-04 20:24:11 0 d-------- C:\Windows\Prefetch
2008-02-04 20:23:50 0 d--hs---- C:\System Volume Information
2008-02-04 20:23:02 0 d-------- C:\Windows\Panther
2008-02-04 20:22:48 0 d--hs---- C:\Boot
2008-02-04 20:02:26 0 d-------- C:\Windows\system32\Macromed
2008-02-04 19:48:41 0 d-------- C:\Users\All Users\Windows Genuine Advantage
2008-02-04 19:44:18 7 --a------ C:\Windows\system32\CurrentName.dat
2008-02-04 19:41:44 4096 --a------ C:\Windows\system32\51056.sys
2008-02-04 19:21:52 0 d-------- C:\Users\All Users\PC Tools
2008-02-04 19:20:51 0 d-------- C:\Program Files\7-Zip
2008-02-04 19:15:36 0 d-------- C:\Program Files\Common Files\PC Tools
2008-02-04 19:08:47 0 d-a------ C:\Users\All Users\TEMP
2008-02-04 18:55:00 0 d-------- C:\Program Files\Privacy Guardian
2008-02-04 18:54:29 0 d-------- C:\Program Files\Spyware Doctor
2008-02-04 18:28:03 0 d-------- C:\Program Files\DivX
2008-02-04 18:26:49 0 d-------- C:\Program Files\Winamp3
2008-02-04 18:25:54 2650 --a------ C:\Windows\mozver.dat
2008-02-04 18:23:06 0 d-------- C:\Users\All Users\ATI
2008-02-04 18:08:22 0 d-------- C:\Program Files\Common Files\ATI Technologies
2008-02-04 18:07:09 0 d--hs---- C:\Windows\Installer
2008-02-04 18

42 0 d-------- C:\Program Files\ATI Technologies
2008-02-04 18

38 0 d-------- C:\Program Files\ATI
2008-02-04 18:02:10 0 d-------- C:\Program Files\Common Files\InstallShield
2008-02-04 17:48:14 0 dr------- C:\Users\DADDY\Searches
2008-02-04 17:48:04 0 dr------- C:\Users\DADDY\Contacts
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Videos
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Templates <TEMPLA~1>
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Start Menu <STARTM~1>
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\SendTo
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Saved Games <SAVEDG~1>
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Recent
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\PrintHood <PRINTH~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Pictures
2008-02-04 17:48:00 1048576 --ahs---- C:\Users\DADDY\NTUSER.DAT
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\NetHood
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\My Documents <MYDOCU~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Music
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Local Settings <LOCALS~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Links
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Favorites <FAVORI~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Downloads <DOWNLO~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Documents <DOCUME~1>
2008-02-04 17:48:00 0 dr------- C:\Users\DADDY\Desktop
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Cookies
2008-02-04 17:48:00 0 d--hs---- C:\Users\DADDY\Application Data <APPLIC~1>
2008-02-04 17:48:00 0 d--h----- C:\Users\DADDY\AppData
-- Find3M Report ---------------------------------------------------------------
2008-02-08 17:59:35 0 d-------- C:\Users\DADDY\AppData\Roaming\AVG7
2008-02-05 15:51:59 0 d-------- C:\Program Files\Common Files
2008-02-05 15:25:59 174 --ahs---- C:\Program Files\desktop.ini
2008-02-04 23:12:58 0 d-------- C:\Program Files\Windows Calendar
2008-02-04 23:12:53 0 d-------- C:\Program Files\Windows Mail
2008-02-04 23:12:50 0 d-------- C:\Program Files\Windows Defender
2008-02-04 23:12:29 0 d-------- C:\Program Files\Microsoft Games
2008-02-04 23:12:28 0 d-------- C:\Program Files\Windows Sidebar
2008-02-04 22:43:49 0 d-------- C:\Users\DADDY\AppData\Roaming\Grisoft
2008-02-04 21:55:41 0 d-------- C:\Users\DADDY\AppData\Roaming\HouseCall 6.6
2008-02-04 20:07:26 0 d-------- C:\Users\DADDY\AppData\Roaming\Macromedia
2008-02-04 20:07:26 0 d-------- C:\Users\DADDY\AppData\Roaming\Adobe
2008-02-04 19:10:11 0 d-------- C:\Users\DADDY\AppData\Roaming\PC Tools
2008-02-04 18:41:07 0 d-------- C:\Users\DADDY\AppData\Roaming\Mozilla
2008-02-04 18:23:06 0 d-------- C:\Users\DADDY\AppData\Roaming\ATI
2008-02-04 17:48:06 0 d-------- C:\Users\DADDY\AppData\Roaming\Identities
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [02/04/2008 10:59 PM]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35 PM]
"WinampAgent"="C:\Program Files\Winamp3\winampa.exe" [07/23/2002 11:58 AM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 04:25 AM]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [08/08/2007 05:51 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [02/08/2008 05:57 PM]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [12/10/2007 02:53 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll,ShowWelcomeCenter" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 02/08/2008 05:53 PM 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-02-08 19:42:25 --------
any search engines i use come up in japanese. i have run trendmicro "house call", avg av free scans, avg as free scans, spyware doctor scans & came up w/"Hijacker.ShopNav". thought i healed PC but still have same search engine results. possible mbr virus? it's been 5 weeks already. formatted maxtor 200gb hd 5x's w/same result. even tried installing win xp w/same results. i'm not a PC whiz just a tinkerer & am not familiar w/using DoS so couldn't run "fdisk" or "fixmbr". getting pretty frustrated 2 say the least! PLZ HELP!!! thanx in advance!!! muchas gracias!
my specs:
Windows Vista Ultimate
AMD Athlon 64 X2 DualCore Processor 4400+
2 GB RAM
ATI Radeon X1550