View Single Post
Old 08-05-2008, 03:44 PM   #15 (permalink)
clearwaterbeach
Registered User
 
Join Date: Aug 2008
Posts: 28
OS: XP


Re: Possible Malware - Frequent Pop-Ups - winlogon.exe

Hijack This log below. Only got a main text, not sure if I was uspposed to get anythign else this time. Thanks.

Deckard's System Scanner v20071014.68
Run by Jeff on 2008-08-05 17:39:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 511 MiB (512 MiB recommended).


-- HijackThis (run as Jeff.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:39:19 PM, on 8/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Storage\dss.exe
C:\Storage\Jeff.exe
C:\WINDOWS\system32\drwtsn32.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06248AD4-5A88-45DE-B5AD-AEE02665C67E} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: (no name) - {107386EC-A603-4AAD-A16C-AC1EADD9D232} - (no file)
O2 - BHO: (no name) - {12C3D0E3-F025-4CDB-A722-93ED65D15668} - (no file)
O2 - BHO: (no name) - {1FF4B3C9-7811-4EA6-83E3-E9C27EA3142D} - (no file)
O2 - BHO: (no name) - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - (no file)
O2 - BHO: (no name) - {46707315-233D-48A6-B90E-B72F05A4B87D} - (no file)
O2 - BHO: {5e3e6a42-c3ae-4718-2674-8f7ba10ba574} - {475ab01a-b7f8-4762-8174-ea3c24a6e3e5} - C:\WINDOWS\system32\lfjsee.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {679C4E9F-13F0-4CB0-B18A-C063C2AEDBE9} - (no file)
O2 - BHO: (no name) - {6C7D76D5-B6E9-4BAB-B1CE-E61614FAD09F} - (no file)
O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - (no file)
O2 - BHO: (no name) - {7EF53E8C-4313-4975-B2CB-6BC88DA1252E} - (no file)
O2 - BHO: (no name) - {8632cd0c-947e-4ec6-b6cd-92b90420d0a6} - (no file)
O2 - BHO: (no name) - {86db3221-0e90-4124-b230-722fa4540cb5} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9C211FC8-D6B8-426B-8CC2-354E35D14225} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D810C572-36B2-43CB-9300-3BCEE18CD019} - (no file)
O2 - BHO: (no name) - {E8CE7677-2412-4A50-BE48-8EB7C917ED6A} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BMa3b56f89] Rundll32.exe "C:\WINDOWS\system32\efihcwoi.dll",s
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [RegDefRun] C:\Program Files\Auslogics\AusLogics Registry Defrag\reginfo.exe /r
O4 - HKUS\S-1-5-21-2341789756-790569725-1664016159-1009\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" (User 'Alex')
O4 - HKUS\S-1-5-21-2341789756-790569725-1664016159-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Alex')
O4 - HKUS\S-1-5-21-2341789756-790569725-1664016159-1009\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Alex')
O4 - HKUS\S-1-5-21-2341789756-790569725-1664016159-1009\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User 'Alex')
O4 - HKUS\S-1-5-21-2341789756-790569725-1664016159-1009\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (User 'Alex')
O4 - S-1-5-21-2341789756-790569725-1664016159-1009 Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (User 'Alex')
O4 - S-1-5-21-2341789756-790569725-1664016159-1009 User Startup: MEMonitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe (User 'Alex')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

--
End of file - 11594 bytes

-- Files created between 2008-07-05 and 2008-08-05 -----------------------------

2008-08-05 16:48:22 0 d-------- C:\WINDOWS\LastGood
2008-08-05 16:26:09 0 d-------- C:\cmdcons
2008-08-05 16:23:55 68096 --a------ C:\WINDOWS\zip.exe
2008-08-05 16:23:55 49152 --a------ C:\WINDOWS\VFind.exe
2008-08-05 16:23:55 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-08-05 16:23:55 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-08-05 16:23:55 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-08-05 16:23:55 98816 --a------ C:\WINDOWS\sed.exe
2008-08-05 16:23:55 80412 --a------ C:\WINDOWS\grep.exe
2008-08-05 16:23:55 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-08-05 16:23:46 105472 --a------ C:\WINDOWS\system32\lfjsee.dll
2008-08-05 16:23:44 105472 --a------ C:\WINDOWS\system32\binxavmf.dll
2008-08-05 16:20:42 91648 --a------ C:\WINDOWS\system32\efihcwoi.dll
2008-08-04 16:38:13 105472 --a------ C:\WINDOWS\system32\ysyjfc.dll
2008-08-04 16:38:11 105472 --a------ C:\WINDOWS\system32\nxteedks.dll
2008-08-04 16:36:53 2048 --a------ C:\WINDOWS\system32\csxkvkhg.exe
2008-08-04 16:26:53 2048 --a------ C:\WINDOWS\system32\dcsxkvkh.exe
2008-08-04 16:20:53 105472 --a------ C:\WINDOWS\system32\zqotbb.dll
2008-08-04 16:20:51 105472 --a------ C:\WINDOWS\system32\tsrxxeqw.dll
2008-08-04 16:20:40 83456 --a------ C:\WINDOWS\system32\fmgbocmm.dll
2008-08-04 16:20:05 91648 --a------ C:\WINDOWS\system32\ceihtsrx.dll
2008-08-04 16:18:27 91648 --a------ C:\WINDOWS\system32\hbhqygce.dll
2008-08-03 16:20:54 0 --a------ C:\WINDOWS\system32\omsjooiy.dll
2008-08-03 16:18:05 0 --a------ C:\WINDOWS\system32\qnvsjaoe.dll
2008-08-03 16:17:53 0 --a------ C:\WINDOWS\system32\axsayfrq.dll
2008-08-02 16:23:30 0 --a------ C:\WINDOWS\system32\jtkelgmj.dll
2008-08-02 16:17:30 0 --a------ C:\WINDOWS\system32\mrkfilju.dll
2008-08-02 10:13:28 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 22:28:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-01 16:18:31 114176 --a------ C:\WINDOWS\system32\mtrfnt.dll
2008-08-01 16:18:30 114176 --a------ C:\WINDOWS\system32\dgwdcycd.dll
2008-08-01 16:18:28 83456 --a------ C:\WINDOWS\system32\imqtqavp.dll
2008-07-31 11:42:31 105472 --a------ C:\WINDOWS\system32\wvirpw.dll
2008-07-31 11:42:30 105472 --a------ C:\WINDOWS\system32\mkxpgiki.dll
2008-07-31 11:42:22 91648 --a------ C:\WINDOWS\system32\ifcanguk.dll
2008-07-31 11:37:22 0 d-------- C:\VundoFix Backups
2008-07-30 11:43:58 105472 --a------ C:\WINDOWS\system32\dggqyb.dll
2008-07-30 11:43:54 105472 --a------ C:\WINDOWS\system32\warvqdls.dll
2008-07-30 11:42:22 83456 --a------ C:\WINDOWS\system32\mjejiywc.dll
2008-07-30 11:29:47 0 d-------- C:\WINDOWS\system32\kBin19


-- Find3M Report ---------------------------------------------------------------

2008-08-05 16:29:59 0 d-------- C:\Program Files\Common Files
2008-08-05 14:20:21 0 d-------- C:\Program Files\McAfee
2008-06-26 19:24:25 0 d-------- C:\Documents and Settings\Jeff\Application Data\McAfee
2008-06-22 11:16:41 0 d-------- C:\Documents and Settings\Jeff\Application Data\SiteAdvisor
2008-06-20 17:57:38 0 d-------- C:\Documents and Settings\Jeff\Application Data\Auslogics
2008-06-20 17:46:50 0 d-------- C:\Program Files\Advanced System Optimizer
2008-06-20 17:44:56 0 d-------- C:\Documents and Settings\Jeff\Application Data\Systweak
2008-06-20 16:46:14 0 d-------- C:\Documents and Settings\Jeff\Application Data\Uniblue
2008-06-20 14:36:05 0 d-------- C:\Documents and Settings\Jeff\Application Data\AdobeUM
2008-06-13 00:05:53 0 d-------- C:\Program Files\Apple Software Update
2008-06-12 23:57:38 0 d-------- C:\Program Files\iTunes
2008-06-12 23:57:06 0 d-------- C:\Program Files\iPod
2008-06-12 23:54:22 0 d-------- C:\Program Files\QuickTime
2008-06-01 09:51:35 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-05 20:48:27 848 --ahs--c- C:\WINDOWS\system32\KGyGaAvL.sys


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06248AD4-5A88-45DE-B5AD-AEE02665C67E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{107386EC-A603-4AAD-A16C-AC1EADD9D232}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{12C3D0E3-F025-4CDB-A722-93ED65D15668}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FF4B3C9-7811-4EA6-83E3-E9C27EA3142D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46707315-233D-48A6-B90E-B72F05A4B87D}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{475ab01a-b7f8-4762-8174-ea3c24a6e3e5}]
08/05/2008 04:23 PM 105472 --a------ C:\WINDOWS\system32\lfjsee.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{679C4E9F-13F0-4CB0-B18A-C063C2AEDBE9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6C7D76D5-B6E9-4BAB-B1CE-E61614FAD09F}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7EF53E8C-4313-4975-B2CB-6BC88DA1252E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8632cd0c-947e-4ec6-b6cd-92b90420d0a6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86db3221-0e90-4124-b230-722fa4540cb5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C211FC8-D6B8-426B-8CC2-354E35D14225}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D810C572-36B2-43CB-9300-3BCEE18CD019}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E8CE7677-2412-4A50-BE48-8EB7C917ED6A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [11/19/2003 06:48 PM]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [04/11/2004 12:43 PM]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [09/03/2003 09:12 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [04/11/2004 09:15 PM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [03/15/2004 02:04 AM]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 02:01 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [09/13/2004 04:49 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [10/03/2006 07:20 PM]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [03/30/2007 11:42 AM]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [01/16/2007 02:59 PM]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [01/08/2007 12:22 PM]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [06/08/2007 10:59 AM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [08/03/2007 11:33 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05/27/2008 10:50 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06/02/2008 11:13 AM]
"BMa3b56f89"="C:\WINDOWS\system32\efihcwoi.dll" [08/05/2008 04:20 PM]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 12:24 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:56 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
"RegDefRun"="C:\Program Files\Auslogics\AusLogics Registry Defrag\reginfo.exe" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ce62342-4c1d-11db-b594-00038a000015}]
AutoRun\command- E:\LaunchU3.exe




-- End of Deckard's System Scanner: finished at 2008-08-05 17:41:36 ------------

Last edited by clearwaterbeach; 08-05-2008 at 03:45 PM.
clearwaterbeach is offline