Deckard's System Scanner v20071014.68
Run by Owner on 2008-06-14 21:22:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
52: 2008-06-15 01:22:30 UTC - RP590 - Deckard's System Scanner Restore Point
51: 2008-06-15 01:10:19 UTC - RP589 - Removed Quivic
50: 2008-06-15 01:09:31 UTC - RP588 - Removed Power Tab Editor 1.7
49: 2008-06-15 00:59:22 UTC - RP587 - Removed Call of Duty(R) 2
48: 2008-06-14 18:07:04 UTC - RP586 - System Checkpoint
-- First Restore Point --
1: 2008-05-14 04:29:14 UTC - RP539 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 8.01 GiB (less than 15%) free.
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:27:38 PM, on 6/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRA~1\AVG\AVG8\avgscanx.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ultimate-guitar.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W3506
O1 - Hosts: pybot - Search & Destroy
O1 - Hosts: oy
O1 - Hosts: pybot - Search & Destroy
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Program Files\ContextTool\ContextTool-2.dll (file missing)
O2 - BHO: dcads - {2ba98f33-d8d3-1ef8-06c1-26503e3bebf1} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {606A6CD9-F64B-ECEB-4B15-FF8DBC2686BE} - (no file)
O2 - BHO: dcads - {733716E1-76D2-4003-AC39-845281C0EF85} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Console] wkssvc.exe
O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,[email protected]
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://xiah.gamescampus.com/luncher/GamesCampus.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures05.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.solidstatenetworks.com/demos/onrpg/solidstateion.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: sQusiStub.dll,avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
--
End of file - 8819 bytes
-- File Associations -----------------------------------------------------------
.js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S2 npkcrypt - c:\nexon\maplestory\npkcrypt.sys (file missing)
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 XDva143 - c:\windows\system32\xdva143.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8139/810x Family Fast Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8139/810x Family Fast Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
Service: RTL8023xp
-- Files created between 2008-05-14 and 2008-06-14 -----------------------------
2008-06-14 21:26:37 0 d-------- C:\Program Files\Trend Micro
2008-06-14 12:21:13 0 d-------- C:\Program Files\Enigma Software Group
2008-06-13 13:48:40 0 d-------- C:\Documents and Settings\Owner\Application Data\WinPatrol
2008-06-13 13:46:20 0 d-------- C:\Program Files\BillP Studios
2008-06-13 13:19:34 0 d--h----- C:\$AVG8.VAULT$
2008-06-13 13:04:40 1669152 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-13 12:58:39 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-13 12:58:32 0 d-------- C:\Program Files\AVG
2008-06-13 12:58:31 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-13 12:37:53 0 d-------- C:\Program Files\Lavasoft
2008-06-13 12:37:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-13 12:19:00 0 d-------- C:\Program Files\ZoneAlarmSB
2008-06-13 12:12:59 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-13 12:12:51 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-06-13 12:11:57 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-06-13 12:10:39 0 d-------- C:\WINDOWS\Internet Logs
2008-06-10 22:36:33 0 d-------- C:\Program Files\Sony
2008-06-10 17:20:35 0 d-------- C:\Program Files\SSI
2008-06-10 17:20:29 376832 -----n--- C:\WINDOWS\Pool of Radiance remove.exe <Not Verified; Edgies; Pool of Radiance II Installer Application>
2008-06-10 17:20:29 195856 -ra------ C:\WINDOWS\dsetup32.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows® 95 and 98>
2008-06-10 17:20:29 40208 -ra------ C:\WINDOWS\dsetup.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows® 95 and 98>
2008-06-06 16:02:19 0 d-------- C:\Documents and Settings\Owner\Application Data\Filter Forge Freepack 1 - Metals
2008-06-06 15:59:55 1030144 --a------ C:\WINDOWS\system32\dbghelp-xfw.dll <Not Verified; Microsoft Corporation; Debugging Tools for Windows(R)>
2008-06-06 15:59:50 0 d-------- C:\Program Files\Filter Forge Freepack 1 - Metals
2008-06-03 11:51:51 0 d-------- C:\WINDOWS\system32\Adobe
2008-05-31 13:20:40 0 d-------- C:\Program Files\PartyGaming
2008-05-28 20:54:42 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-05-25 03:01:30 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-24 18:02:57 0 d-------- C:\Program Files\Apprentice
2008-05-24 17:59:22 0 d-------- C:\Program Files\Magic Workstation
2008-05-23 23:19:57 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-23 23:19:48 0 d-------- C:\Program Files\Windows Live
2008-05-23 23:19:37 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-21 19:08:42 0 d-------- C:\Program Files\Triple Triad Extreme
2008-05-16 18:51:06 0 d-------- C:\Program Files\Activision
-- Find3M Report ---------------------------------------------------------------
2008-06-14 20:52:29 0 d-------- C:\Program Files\Common Files\stardock
2008-06-13 13:12:02 0 d-------- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-06-13 13:03:08 0 d-------- C:\Program Files\Trillian
2008-06-13 12:36:56 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-13 12:27:27 0 d-------- C:\Program Files\Outspark
2008-06-13 12:09:38 0 d-------- C:\Program Files\America's Army
2008-06-12 13:35:48 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-06-11 13:28:05 0 d-------- C:\Program Files\lx_cats
2008-06-10 22:36:33 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-10 22:24:24 10565 --a------ C:\WINDOWS\mozver.dat
2008-06-03 11:53:15 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2008-05-25 03:01:30 0 d-------- C:\Program Files\Common Files
2008-05-17 16:03:52 0 d-------- C:\Program Files\Macromedia
2008-05-17 16:03:52 0 d-------- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-05-17 16:03:34 0 d-------- C:\Program Files\Common Files\Macromedia
2008-05-13 15:29:25 0 d-------- C:\Program Files\LimeWire
2008-05-11 23:23:24 0 d-------- C:\Documents and Settings\Owner\Application Data\FaxCtr
2008-05-11 23:14:35 0 d-------- C:\Program Files\Lexmark Fax Solutions
2008-05-11 23:13:09 0 d-------- C:\Program Files\Lexmark 3400 Series
2008-05-06 16:16:44 0 d-------- C:\Program Files\NCSoft
2008-05-06 16:12:13 0 d--h----- C:\Documents and Settings\Owner\Application Data\ijjigame
2008-05-02 20:25:50 0 d-------- C:\Program Files\QuickTime
2008-04-30 18:44:43 0 d-------- C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-04-30 17:17:09 0 d-------- C:\Program Files\Turbine
2008-04-15 21:45:09 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-04-15 17:16:20 0 d-------- C:\Program Files\VstPlugins
2008-04-15 17:09:42 0 d-------- C:\Program Files\AGEIA Technologies
2008-04-15 17:08:51 0 d-------- C:\Program Files\Netdevil
2008-03-30 13:03:02 3120 --a------ C:\WINDOWS\system32\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
C:\Program Files\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ba98f33-d8d3-1ef8-06c1-26503e3bebf1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{606A6CD9-F64B-ECEB-4B15-FF8DBC2686BE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{733716E1-76D2-4003-AC39-845281C0EF85}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
02/05/2008 10:26 PM 267592 --a------ C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [02/05/2008 10:26 PM 267592]
[-HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [12/09/2005 09:44 PM]
"RTHDCPL"="RTHDCPL.EXE" [04/17/2006 06:34 PM C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 09:43 PM C:\WINDOWS\Alcmtr.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [03/20/2006 05:34 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Windows Console"="wkssvc.exe" []
"lxcymon.exe"="C:\Program Files\Lexmark 3400 Series\lxcymon.exe" [06/25/2007 10:34 AM]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [06/25/2007 10:35 AM]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [11/21/2006 01:27 PM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [04/02/2008 08:07 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/13/2008 12:58 PM]
"RegistryMechanic"="" []
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [04/25/2008 01:31 PM]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [01/23/2008 03:47 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:00 PM]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 11:16:50 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sQusiStub.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6040f5d7-3c2e-11db-902e-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
126 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-14 21:29:13 ------------
Run by Owner on 2008-06-14 21:22:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
52: 2008-06-15 01:22:30 UTC - RP590 - Deckard's System Scanner Restore Point
51: 2008-06-15 01:10:19 UTC - RP589 - Removed Quivic
50: 2008-06-15 01:09:31 UTC - RP588 - Removed Power Tab Editor 1.7
49: 2008-06-15 00:59:22 UTC - RP587 - Removed Call of Duty(R) 2
48: 2008-06-14 18:07:04 UTC - RP586 - System Checkpoint
-- First Restore Point --
1: 2008-05-14 04:29:14 UTC - RP539 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 8.01 GiB (less than 15%) free.
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:27:38 PM, on 6/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRA~1\AVG\AVG8\avgscanx.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ultimate-guitar.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W3506
O1 - Hosts: pybot - Search & Destroy
O1 - Hosts: oy
O1 - Hosts: pybot - Search & Destroy
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Program Files\ContextTool\ContextTool-2.dll (file missing)
O2 - BHO: dcads - {2ba98f33-d8d3-1ef8-06c1-26503e3bebf1} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {606A6CD9-F64B-ECEB-4B15-FF8DBC2686BE} - (no file)
O2 - BHO: dcads - {733716E1-76D2-4003-AC39-845281C0EF85} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Console] wkssvc.exe
O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,[email protected]
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://xiah.gamescampus.com/luncher/GamesCampus.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures05.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://www.solidstatenetworks.com/demos/onrpg/solidstateion.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{5C101001-4489-4F22-8D1E-1C75272EB670}: NameServer = 65.24.7.10,65.24.7.11
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: sQusiStub.dll,avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
--
End of file - 8819 bytes
-- File Associations -----------------------------------------------------------
.js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S2 npkcrypt - c:\nexon\maplestory\npkcrypt.sys (file missing)
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 XDva143 - c:\windows\system32\xdva143.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8139/810x Family Fast Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8139/810x Family Fast Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_D6018086&REV_10\4&2A3BFE78&0&10A4
Service: RTL8023xp
-- Files created between 2008-05-14 and 2008-06-14 -----------------------------
2008-06-14 21:26:37 0 d-------- C:\Program Files\Trend Micro
2008-06-14 12:21:13 0 d-------- C:\Program Files\Enigma Software Group
2008-06-13 13:48:40 0 d-------- C:\Documents and Settings\Owner\Application Data\WinPatrol
2008-06-13 13:46:20 0 d-------- C:\Program Files\BillP Studios
2008-06-13 13:19:34 0 d--h----- C:\$AVG8.VAULT$
2008-06-13 13:04:40 1669152 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-13 12:58:39 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-13 12:58:32 0 d-------- C:\Program Files\AVG
2008-06-13 12:58:31 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-13 12:37:53 0 d-------- C:\Program Files\Lavasoft
2008-06-13 12:37:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-13 12:19:00 0 d-------- C:\Program Files\ZoneAlarmSB
2008-06-13 12:12:59 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-13 12:12:51 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-06-13 12:11:57 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-06-13 12:10:39 0 d-------- C:\WINDOWS\Internet Logs
2008-06-10 22:36:33 0 d-------- C:\Program Files\Sony
2008-06-10 17:20:35 0 d-------- C:\Program Files\SSI
2008-06-10 17:20:29 376832 -----n--- C:\WINDOWS\Pool of Radiance remove.exe <Not Verified; Edgies; Pool of Radiance II Installer Application>
2008-06-10 17:20:29 195856 -ra------ C:\WINDOWS\dsetup32.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows® 95 and 98>
2008-06-10 17:20:29 40208 -ra------ C:\WINDOWS\dsetup.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Windows® 95 and 98>
2008-06-06 16:02:19 0 d-------- C:\Documents and Settings\Owner\Application Data\Filter Forge Freepack 1 - Metals
2008-06-06 15:59:55 1030144 --a------ C:\WINDOWS\system32\dbghelp-xfw.dll <Not Verified; Microsoft Corporation; Debugging Tools for Windows(R)>
2008-06-06 15:59:50 0 d-------- C:\Program Files\Filter Forge Freepack 1 - Metals
2008-06-03 11:51:51 0 d-------- C:\WINDOWS\system32\Adobe
2008-05-31 13:20:40 0 d-------- C:\Program Files\PartyGaming
2008-05-28 20:54:42 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-05-25 03:01:30 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-24 18:02:57 0 d-------- C:\Program Files\Apprentice
2008-05-24 17:59:22 0 d-------- C:\Program Files\Magic Workstation
2008-05-23 23:19:57 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-23 23:19:48 0 d-------- C:\Program Files\Windows Live
2008-05-23 23:19:37 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-21 19:08:42 0 d-------- C:\Program Files\Triple Triad Extreme
2008-05-16 18:51:06 0 d-------- C:\Program Files\Activision
-- Find3M Report ---------------------------------------------------------------
2008-06-14 20:52:29 0 d-------- C:\Program Files\Common Files\stardock
2008-06-13 13:12:02 0 d-------- C:\Documents and Settings\Owner\Application Data\OpenOffice.org2
2008-06-13 13:03:08 0 d-------- C:\Program Files\Trillian
2008-06-13 12:36:56 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-13 12:27:27 0 d-------- C:\Program Files\Outspark
2008-06-13 12:09:38 0 d-------- C:\Program Files\America's Army
2008-06-12 13:35:48 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-06-11 13:28:05 0 d-------- C:\Program Files\lx_cats
2008-06-10 22:36:33 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-10 22:24:24 10565 --a------ C:\WINDOWS\mozver.dat
2008-06-03 11:53:15 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2008-05-25 03:01:30 0 d-------- C:\Program Files\Common Files
2008-05-17 16:03:52 0 d-------- C:\Program Files\Macromedia
2008-05-17 16:03:52 0 d-------- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-05-17 16:03:34 0 d-------- C:\Program Files\Common Files\Macromedia
2008-05-13 15:29:25 0 d-------- C:\Program Files\LimeWire
2008-05-11 23:23:24 0 d-------- C:\Documents and Settings\Owner\Application Data\FaxCtr
2008-05-11 23:14:35 0 d-------- C:\Program Files\Lexmark Fax Solutions
2008-05-11 23:13:09 0 d-------- C:\Program Files\Lexmark 3400 Series
2008-05-06 16:16:44 0 d-------- C:\Program Files\NCSoft
2008-05-06 16:12:13 0 d--h----- C:\Documents and Settings\Owner\Application Data\ijjigame
2008-05-02 20:25:50 0 d-------- C:\Program Files\QuickTime
2008-04-30 18:44:43 0 d-------- C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-04-30 17:17:09 0 d-------- C:\Program Files\Turbine
2008-04-15 21:45:09 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-04-15 17:16:20 0 d-------- C:\Program Files\VstPlugins
2008-04-15 17:09:42 0 d-------- C:\Program Files\AGEIA Technologies
2008-04-15 17:08:51 0 d-------- C:\Program Files\Netdevil
2008-03-30 13:03:02 3120 --a------ C:\WINDOWS\system32\6ffdbcaf-f6c1-42d3-a4a9-c7957224a70b.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
C:\Program Files\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ba98f33-d8d3-1ef8-06c1-26503e3bebf1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{606A6CD9-F64B-ECEB-4B15-FF8DBC2686BE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{733716E1-76D2-4003-AC39-845281C0EF85}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
02/05/2008 10:26 PM 267592 --a------ C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [02/05/2008 10:26 PM 267592]
[-HKEY_CLASSES_ROOT\CLSID\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [12/09/2005 09:44 PM]
"RTHDCPL"="RTHDCPL.EXE" [04/17/2006 06:34 PM C:\WINDOWS\RTHDCPL.exe]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 09:43 PM C:\WINDOWS\Alcmtr.exe]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [03/20/2006 05:34 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Windows Console"="wkssvc.exe" []
"lxcymon.exe"="C:\Program Files\Lexmark 3400 Series\lxcymon.exe" [06/25/2007 10:34 AM]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [06/25/2007 10:35 AM]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [11/21/2006 01:27 PM]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [04/02/2008 08:07 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/13/2008 12:58 PM]
"RegistryMechanic"="" []
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [04/25/2008 01:31 PM]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [01/23/2008 03:47 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 03:00 PM]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 11:16:50 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=sQusiStub.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6040f5d7-3c2e-11db-902e-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
126 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-14 21:29:13 ------------
Attachments
-
19.6 KB Views: 34