View Single Post
Old 06-09-2008, 04:49 AM   #1 (permalink)
xchocochips
Registered User
 
Join Date: Jun 2008
Posts: 27
OS: Windows XP SP2


No Icon No Taskbar Just Wallpaper

Hi there,

My computer had been acting strangely these past few days after I downloaded a video codec from a website. I forget which website. After I had downloaded it, my wallpaper changes to a blue one and when it come to the screensaver, there will be like insect eating it....

But luckily i managed to resolve the problem and revert it back to my normal wallpaper and screensaver. But unfortunately, the worst of all is still in my computer which is having no icon and taskbar and only the wallpaper. Sometime it appear and then disappear.
I tried many ways to remove it but to no avail.

Well, I hope you guys can resolve this A.S.A.P since I need this computer for work. Thanks in advance. Here is the log:


Deckard's System Scanner v20071014.68
Run by Home on 2008-06-09 18:21:29
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
57: 2008-06-09 10:21:51 UTC - RP1129 - Deckard's System Scanner Restore Point
56: 2008-06-09 0634 UTC - RP1128 - Restore Operation
55: 2008-06-06 15:16:34 UTC - RP1127 - Installed Ad-Aware
54: 2008-06-06 12:30:26 UTC - RP1126 - Installed AdwareAlert
53: 2008-06-06 11:54:53 UTC - RP1125 - Software Distribution Service 3.0


-- First Restore Point --
1: 2008-03-30 18:18:40 UTC - RP1073 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Home.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:25:48, on 09/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Documents and Settings\Home\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Home.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\imapi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07DF7501-A4E0-452E-B36C-170614D115D8} - (no file)
O2 - BHO: (no name) - {189A78B1-CEB8-45FD-9C12-4B9C8A965A58} - C:\WINDOWS\system32\tuvTlmLE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7298ECDD-7C93-4EF8-9296-3BE188269346} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {81DBF13B-9EE9-43D4-96E9-E1270DE1DDA7} - C:\WINDOWS\system32\byXPiIca.dll
O2 - BHO: (no name) - {8FC89E07-D848-41E5-A9AB-2CB71591EFAC} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {988E6186-A4F2-4192-BE95-7A91C8F458F2} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: QXK Olive - {C607C322-F4DF-44B7-98F5-FCAE55BADEA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MPTBox] C:\Program Files\Canon\MultiPASS4\MPTBox.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE KINSTONE USB PC Camera
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpeedBitVideoAccelerator] "C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Startup: ImationFlashDetect.lnk = C:\Program Files\Imation\ImationFlashDetect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - https://www.windowsonecare.com/insta...SSWebAgent.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by120fd.bay120.hotmail.msn.co...s/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/.../GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase8300.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O20 - Winlogon Notify: tuvTlmLE - C:\WINDOWS\SYSTEM32\tuvTlmLE.dll
O21 - SSODL: adgpfoxs - {693D26B7-D602-43B5-943E-5373D6065550} - (no file)
O21 - SSODL: erpobmsw - {30779CEC-6651-4432-A961-6A3A59A4B253} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe

--
End of file - 10891 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20071005-214200-383 O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll (file missing)
backup-20071005-214200-603 O2 - BHO: (no name) - {EB4B152B-81A7-411F-9967-C5BFD6AA69B2} - C:\WINDOWS\system32\geede.dll (file missing)
backup-20071005-214200-686 O2 - BHO: (no name) - {8BB99093-CF31-4AB9-9B4D-0EF876979162} - C:\WINDOWS\system32\woiiiuaa.dll (file missing)

-- File Associations -----------------------------------------------------------

.js - JSFile - shell\open\command - NOTEPAD.EXE %1
.vbs - VBSFile - shell\open\command - NOTEPAD.EXE %1


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 Teefer (Teefer for NT) - c:\windows\system32\drivers\teefer.sys <Not Verified; Sygate Technologies, Inc.; Sygate Teefer Driver>
R1 wpsdrvnt - c:\windows\system32\drivers\wpsdrvnt.sys <Not Verified; Sygate Technologies, Inc.; wpsdrvnt>
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path ManagerŪ (32-bit)>
R2 npkcrypt - c:\program files\wizet\maplestory\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
R2 sbbotdi - c:\program files\speedbit video accelerator\sbbotdi.sys <Not Verified; SpeedBit Ltd.; Speedbit TDI Driver>
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

S3 NSNDIS5 (NSNDIS5 NDIS Protocol Driver) - c:\windows\system32\nsndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); NetStumbler>
S3 ZSMC301b (KINSTONE USB PC Camera) - c:\windows\system32\drivers\usbvm31b.sys <Not Verified; VM; >


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 MpService - c:\program files\canon\multipass4\mpservic.exe <Not Verified; Canon Inc.; Canon MultiPASS>
R2 sp_rssrv (Spyware Terminator Realtime Shield Service) - "c:\program files\spyware terminator\sp_rsser.exe" <Not Verified; Crawler.com; Crawler Spyware Terminator>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-06-09 15:00:49 404 --a------ C:\WINDOWS\Tasks\Pareto UNS.job
2008-06-09 15:00:32 446 --a------ C:\WINDOWS\Tasks\ParetoLogic Anti-Spyware.job
2008-06-09 15:00:25 410 --a------ C:\WINDOWS\Tasks\ParetoLogic Update.job
2008-06-09 14:53:51 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2007-10-05 17:42:53 402 --ah----- C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job


-- Files created between 2008-05-09 and 2008-06-09 -----------------------------

2008-06-09 17:41:05 0 d-------- C:\Program Files\SpywareBlaster
2008-06-09 15:05:07 0 d-------- C:\Program Files\Enigma Software Group
2008-06-09 15:00:31 0 d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-06-09 15:00:24 0 d-------- C:\Program Files\ParetoLogic
2008-06-09 15:00:22 0 d-------- C:\Program Files\Common Files\ParetoLogic
2008-06-07 12:14:08 190196 --ahs---- C:\WINDOWS\system32\acIiPXyb.ini2
2008-06-07 12:13:28 320256 --a------ C:\WINDOWS\system32\byXPiIca.dll
2008-06-07 01:26:35 77312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-06-07 01:26:34 162304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-06-07 01:26:33 69632 --a------ C:\WINDOWS\system32\ztvcabinet.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) 2000 Operating System>
2008-06-07 01:26:32 75264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-06-07 01:26:31 153088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-06-07 01:26:25 0 d-------- C:\Documents and Settings\Home\Application Data\Simply Super Software
2008-06-07 01:26:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-06-07 01:26:24 0 d-------- C:\Program Files\Trojan Remover
2008-06-06 23:16:41 0 d-------- C:\Program Files\Lavasoft
2008-06-06 23:16:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-06 23:16:03 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-06 21:23:38 0 d-------- C:\Program Files\Panda Security
2008-06-06 14:50:49 0 dr-h----- C:\Documents and Settings\Home\Recent
2008-06-06 14:34:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-06-06 13:00:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-05 21:53:50 141312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-06-05 21:53:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-06-05 21:53:46 0 d-------- C:\Documents and Settings\Home\Application Data\Spyware Terminator
2008-06-05 21:53:41 0 d-------- C:\Program Files\Spyware Terminator
2008-06-05 20:39:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-06-05 19:09:20 0 d-------- C:\Program Files\IObit
2008-06-05 18:21:36 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-05 18:20:52 0 d-------- C:\Program Files\Spyware Doctor
2008-06-05 18:20:52 0 d-------- C:\Documents and Settings\Home\Application Data\PC Tools
2008-06-05 17:44:41 0 d-------- C:\Program Files\Windows Defender
2008-06-05 17:12:58 126453 --ahs---- C:\WINDOWS\system32\PYcJQXbc.ini2
2008-06-05 16:58:15 33920 --a------ C:\WINDOWS\system32\tuvTlmLE.dll
2008-06-03 22:19:13 0 d-------- C:\Documents and Settings\Home\EurekaLog
2008-06-02 02:27:28 487479 --a------ C:\WINDOWS\system32\SkinMagic.dll <Not Verified; Appspeed Inc.; Appspeed SkinMagic Toolkit>
2008-06-02 02:27:28 60273 --a------ C:\WINDOWS\system32\pthreadGC2.dll <Not Verified; Open Source Software community project; >
2008-06-02 02:27:28 7277568 --a------ C:\WINDOWS\system32\iPodmedia.dll
2008-06-02 02:27:28 719872 --a------ C:\WINDOWS\system32\devil.dll <Not Verified; Abysmal Software; Developer's Image Library (DevIL)>
2008-06-02 02:27:28 0 d-------- C:\WINDOWS\system32\avsplugin
2008-06-02 02:27:28 313344 --a------ C:\WINDOWS\system32\avisynth.dll <Not Verified; The Public; Avisynth 2.5>
2008-06-02 02:27:28 0 d-------- C:\Program Files\Smallvideosoft
2008-05-29 21:34:37 0 d-------- C:\Documents and Settings\Home\Application Data\Hamachi
2008-05-29 21:34:05 0 d-------- C:\Program Files\Hamachi
2008-05-28 19:37:05 0 d-------- C:\Program Files\Network Stumbler
2008-05-27 02:54:35 0 d-------- C:\Program Files\CubedLabs YouTube Download & Convert
2008-05-27 02:37:34 34 --ah----- C:\WINDOWS\system32\DVDRippper_sysquict.dat
2008-05-27 02:37:26 0 d-------- C:\Program Files\Abcc Free FLV to AVI WMV MPEG MP4 MOV Converter
2008-05-19 23:50:57 0 d-------- C:\Documents and Settings\Home\Application Data\WinRAR


-- Find3M Report ---------------------------------------------------------------

2008-06-09 15:00:22 0 d-------- C:\Program Files\Common Files
2008-06-09 13:33:38 0 d-------- C:\Documents and Settings\Home\Application Data\AVG7
2008-04-21 20:51:35 0 d-------- C:\Program Files\MSN Messenger
2008-04-21 20:50:44 0 d-------- C:\Program Files\Windows Live
2008-04-21 20:49:46 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-18 00:43:53 0 d-------- C:\Documents and Settings\Home\Application Data\Real
2008-04-18 00:38:01 0 d-------- C:\Program Files\Common Files\xing shared
2008-04-18 00:37:52 0 d-------- C:\Program Files\Common Files\Real
2008-04-18 00:37:34 0 d-------- C:\Program Files\Real
2008-03-21 15:05:29 32768 --a------ C:\WINDOWS\system32\GTGina.dll <Not Verified; Gemtek; GTGina Dynamic Link Library>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07DF7501-A4E0-452E-B36C-170614D115D8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{189A78B1-CEB8-45FD-9C12-4B9C8A965A58}]
05/06/2008 16:58 33920 --a------ C:\WINDOWS\system32\tuvTlmLE.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7298ECDD-7C93-4EF8-9296-3BE188269346}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{81DBF13B-9EE9-43D4-96E9-E1270DE1DDA7}]
07/06/2008 12:13 320256 --a------ C:\WINDOWS\system32\byXPiIca.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8FC89E07-D848-41E5-A9AB-2CB71591EFAC}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{988E6186-A4F2-4192-BE95-7A91C8F458F2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C607C322-F4DF-44B7-98F5-FCAE55BADEA0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [20/06/2005 18:53]
"SoundMan"="SOUNDMAN.EXE" [09/02/2004 16:54 C:\WINDOWS\SOUNDMAN.EXE]
"MPTBox"="C:\Program Files\Canon\MultiPASS4\MPTBox.exe" [01/11/2002 16:13]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/12/2007 01:41]
"nwiz"="nwiz.exe" [05/12/2007 01:41 C:\WINDOWS\system32\nwiz.exe]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [15/12/2004 19:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 01:11]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [17/04/2008 18:53]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [15/10/2004 19:40]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/10/2006 09:36]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [05/12/2007 01:41]
"SpeedBitVideoAccelerator"="C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe" [30/03/2008 00:06]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [18/04/2008 00:37]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [03/11/2006 19:20]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [10/04/2008 15:14]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [03/06/2008 20:33]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [23/01/2008 15:47]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 20:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [14/10/2004 00:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/09/2007 14:29]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [30/03/2006 16:45]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]
"ParetoLogic Anti-Spyware"="C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" [05/06/2008 03:14]

C:\Documents and Settings\Home\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [29/05/2008 21:34:05]
ImationFlashDetect.lnk - C:\Program Files\Imation\ImationFlashDetect.exe [21/01/2007 19:48:25]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 22:05:26]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispScrSavPage"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{189A78B1-CEB8-45FD-9C12-4B9C8A965A58}"= C:\WINDOWS\system32\tuvTlmLE.dll [05/06/2008 16:58 33920]
"{51C55F9E-C308-4c95-89AB-8858D8AFD819}"= C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll [05/06/2008 03:14 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvTlmLE]
tuvTlmLE.dll 05/06/2008 16:58 33920 C:\WINDOWS\system32\tuvTlmLE.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\byXPiIca

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

*Newly Created Service* - GTNDIS5



-- End of Deckard's System Scanner: finished at 2008-06-09 18:29:42 ------------

Last edited by xchocochips; 06-09-2008 at 04:55 AM.
xchocochips is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here