Deckard's System Scanner v20070611.50
Run by Dea on 2007-07-02 at 20:07:30
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2007-07-03 00:07:35 UTC - RP28 - Deckard's System Scanner Restore Point
1: 2007-07-01 23:56:05 UTC - RP27 - Installed Windows XP Service Pack 1.
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Dea.exe) -------------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-07-02 20:12:07
Platform: Windows XP Service Pack 1 (5.01.2600)
MSIE: Internet Explorer (6.00.2800.1106)
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lexmark 4300 Series\lxcemon.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\?ppPatch\chkntfs.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\?ystem32\m?iexec.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Desktop\dss.exe
C:\Program Files\HijackThis\Dea.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
O2 - BHO: (no name) - {01bb4672-d0ea-47ac-8263-7cea626a63db} - C:\WINDOWS\system32\logmib.dll (file missing)
O2 - BHO: (no name) - {32644A88-8F4C-D0BA-1A15-8B8DCA57D5BC} - C:\WINDOWS\system32\vouiu.dll
O2 - BHO: (no name) - {45677555-FD71-48B2-9102-02B3A5D246BC} - C:\WINDOWS\system32\reginix86a.dll
O2 - BHO: (no name) - {A24B57F8-505D-4fc5-9960-740E304D1ABA} - C:\WINDOWS\system32\tmp31.tmp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\System32\lsasss.exe
O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\ddaxvv.dll",realset
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Luat] "C:\WINDOWS\System32\PPPATC~1\chkntfs.exe" -vt yazb
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Qphh] "C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\?ystem32\m?iexec.exe"
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1183330443836
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} () -
http://installs.spamblockerutility.c...kerutility.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} () - ms-its:mhtml:file://c:\\nores.mht!
http://adxtend.net/code/chm/xpre.chm::/xpreload.ocx
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O20 - Winlogon Notify: logmib - C:\WINDOWS\System32\
-- File Associations -----------------------------------------------------------
.bat - batfile - shell\edit\command - NOTEDAD.EXE %1
.ini - inifile - shell\open\command - NOTEDAD.EXE %1
.reg - regfile - shell\edit\command - NOTEDAD.EXE %1
.txt - txtfile - shell\open\command - NOTEDAD.EXE %1
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Scheduled Tasks -------------------------------------------------------------
2007-07-02 20:00:00 350 --a------ C:\WINDOWS\Tasks\At21.job
2007-07-01 19:00:00 350 --a------ C:\WINDOWS\Tasks\At20.job
2007-07-01 18:00:00 350 --a------ C:\WINDOWS\Tasks\At19.job
2007-06-11 14:00:00 350 --a------ C:\WINDOWS\Tasks\At15.job
2007-06-11 13:00:00 350 --a------ C:\WINDOWS\Tasks\At14.job
2007-06-10 16:00:01 350 --a------ C:\WINDOWS\Tasks\At17.job
2007-06-10 15:00:00 350 --a------ C:\WINDOWS\Tasks\At16.job
2007-06-04 12:02:17 350 --a------ C:\WINDOWS\Tasks\At13.job
2007-05-29 17:01:31 350 --a------ C:\WINDOWS\Tasks\At18.job
2007-05-28 21:00:54 350 --a------ C:\WINDOWS\Tasks\At22.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At9.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At8.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At7.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At6.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At5.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At4.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At3.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At24.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At23.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At2.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At12.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At11.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At10.job
2007-05-19 19:05:34 350 --a------ C:\WINDOWS\Tasks\At1.job
-- Files created between 2007-06-02 and 2007-07-02 -----------------------------
2007-07-01 19:55:45 0 d-------- C:\WINDOWS\Prefetch
2007-07-01 19:48:29 0 d-------- C:\WINDOWS\ServicePackFiles
2007-07-01 19:48:29 0 d-------- C:\WINDOWS\ehome
2007-07-01 18:51:44 0 d-------- C:\ie-spyad
2007-07-01 18:49:28 0 d-------- C:\Program Files\SpywareBlaster
2007-07-01 17:09:47 97280 --a------ C:\WINDOWS\System32\reginix86a.exe
2007-07-01 17:09:47 152064 --a------ C:\WINDOWS\System32\reginix86a.dll
2007-07-01 17:09:43 97280 --a------ C:\WINDOWS\System32\reginia_redux.exe
2007-07-01 17:08:02 60928 --a------ C:\WINDOWS\System32\vouiu.dll
2007-07-01 17:08:02 0 d-------- C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\?ystem32
2007-06-27 18:42:13 0 d-------- C:\WINDOWS\System32\ActiveScan
2007-06-27 18:32:58 97280 --a------ C:\WINDOWS\System32\monterreyo_redux.exe
2007-06-20 19:50:18 97280 --a------ C:\WINDOWS\System32\monterreyn_redux.exe
2007-06-11 14:02:12 0 d-------- C:\Tune
2007-06-10 14:56:58 97280 --a------ C:\WINDOWS\monterreyj_redux.exe
2007-06-10 14:46:05 42752 --a------ C:\WINDOWS\System32\drivers\ousbehci.sys <Not Verified; OrangeWare Corporation; USB 2.0 Enhanced Host Controller Driver>
2007-06-10 14:46:05 55552 --a------ C:\WINDOWS\System32\drivers\ousb2hub.sys <Not Verified; OrangeWare Corporation; USB 2.0 Hub Driver>
2007-06-10 14:46:05 0 d-------- C:\WINDOWS\Drivers
2007-06-04 11:38:16 97280 --a------ C:\WINDOWS\System32\monterreyj_redux.exe
2007-06-04 11:15:38 1733 --a------ C:\WINDOWS\checkip.dat
-- Find3M Report ---------------------------------------------------------------
2007-07-02 19:57:04 36864 --a------ C:\WINDOWS\System32\Explorer.exe <Not Verified; Microsoft; 23f>
2007-07-02 19:53:50 0 d-------- C:\Program Files\Lx_cats
2007-07-02 19:53:37 355 ---hs---- C:\WINDOWS\vvxadd.ini2
2007-07-01 19:55:16 0 d-------- C:\Program Files\Messenger
2007-07-01 17:19:29 0 d-------- C:\Program Files\Lexmark 4300 Series
2007-07-01 17:08:05 2 --a------ C:\WINDOWS\System32\wcpsvtr.exe
2007-06-10 14:19:54 32768 --a------ C:\WINDOWS\System32\mp43.exe <Not Verified; Microsoft; gfb>
2007-06-10 14:19:54 32768 --a------ C:\WINDOWS\NOTEDAD.EXE <Not Verified; Microsoft; gfb>
2007-06-04 14:13:40 0 d-------- C:\Program Files\SurfAccuracy
2007-06-04 14:13:39 0 d-------- C:\Program Files\SideFind
2007-06-04 13:28:43 0 d-------- C:\Program Files\ISTsvc
2007-06-04 13:28:38 0 d-------- C:\Program Files\Ipwindows
2007-06-04 13:28:34 0 d-------- C:\Program Files\Internet Optimizer
2007-05-29 17:38:33 0 d-------- C:\Program Files\??pPatch
2007-05-28 20:47:00 0 d-------- C:\Program Files\Kaspersky Lab
2007-05-28 20:44:05 86016 --a------ C:\WINDOWS\System32\regapi.exe
2007-05-28 18:49:45 106580 --a------ C:\WINDOWS\ddaxvv.dll
2007-05-28 18:43:20 0 d-------- C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\.BitTornado
2007-05-28 18:41:31 0 d-------- C:\Program Files\BitTornado
2007-05-28 12:39:43 0 d-------- C:\Program Files\InetGet2
2007-05-13 10:00:38 0 d-------- C:\Program Files\Outerinfo
2007-04-29 19:33:07 40183 ---hs---- C:\Program Files\Common Files\Yazzle1275OinUninstaller.exe
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{01bb4672-d0ea-47ac-8263-7cea626a63db} C:\WINDOWS\system32\logmib.dll [x]
{32644A88-8F4C-D0BA-1A15-8B8DCA57D5BC} C:\WINDOWS\System32\vouiu.dll
{45677555-FD71-48B2-9102-02B3A5D246BC} C:\WINDOWS\system32\reginix86a.dll
{A24B57F8-505D-4fc5-9960-740E304D1ABA} C:\WINDOWS\System32\tmp31.tmp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Lexmark_X79-55"="C:\\WINDOWS\\System32\\lsasss.exe"
"lxcemon.exe"="\"C:\\Program Files\\Lexmark 4300 Series\\lxcemon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 4300 Series\\ezprint.exe\""
"FaxCenterServer"="\"C:\\Program Files\\Lexmark Fax Solutions\\fm3032.exe\" /s"
"setup"="rundll32.exe \"C:\\WINDOWS\\ddaxvv.dll\",realset"
"LXCECATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCEtime.dll,_RunDLLEntry@16"
"IESet"="IExplorer.dll .dbt"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Luat"="\"C:\\WINDOWS\\System32\\PPPATC~1\\chkntfs.exe\" -vt yazb"
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""
"Qphh"="\"C:\\Documents and Settings\\Dea.DEA-UVIOJM1M7QK\\Application Data\\?ystem32\\m?iexec.exe\""
"IESet"="IExplorer.dll .dbt"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"IESet"="IExplorer.dll .dbt"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"IESet"="IExplorer.dll .dbt"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\logmib
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
-- End of Deckard's System Scanner: finished at 2007-07-02 at 20:17:15 ---------
Logfile of HijackThis v1.99.1
Scan saved at 8:16:58 PM, on 7/2/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lexmark 4300 Series\lxcemon.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\PPPATC~1\chkntfs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\?ystem32\m?iexec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
C:\WINDOWS\System32\lxcecoms.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Dea.exe
O2 - BHO: (no name) - {01bb4672-d0ea-47ac-8263-7cea626a63db} - C:\WINDOWS\system32\logmib.dll (file missing)
O2 - BHO: (no name) - {32644A88-8F4C-D0BA-1A15-8B8DCA57D5BC} - C:\WINDOWS\System32\vouiu.dll
O2 - BHO: (no name) - {45677555-FD71-48B2-9102-02B3A5D246BC} - C:\WINDOWS\system32\reginix86a.dll
O2 - BHO: (no name) - {A24B57F8-505D-4fc5-9960-740E304D1ABA} - C:\WINDOWS\System32\tmp31.tmp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\System32\lsasss.exe
O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\ddaxvv.dll",realset
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Luat] "C:\WINDOWS\System32\PPPATC~1\chkntfs.exe" -vt yazb
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Qphh] "C:\Documents and Settings\Dea.DEA-UVIOJM1M7QK\Application Data\?ystem32\m?iexec.exe"
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: MemTurbo.lnk = C:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1183330443836
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} -
http://installs.spamblockerutility.c...kerutility.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!
http://adxtend.net/code/chm/xpre.chm::/xpreload.ocx
O20 - AppInit_DLLs:
O20 - Winlogon Notify: logmib - C:\WINDOWS\
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxcecoms.exe