1
Tech Clinic / lots of trojans
« on: May 04, 2008, 06:02:10 PM »
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-05-04 19:03:24
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:26 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
C:\WINDOWS\system32\rsvp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Intel® Alert Service (AlertService) - Unknown owner - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Intel® Quick Resume technology (ELService) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel® Viiv(tm) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
--
End of file - 4122 bytes
-- Files created between 2008-04-04 and 2008-05-04 -----------------------------
2008-05-04 16:43:06 0 d-------- C:\Program Files\Avira
2008-05-04 16:43:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-04 14:20:12 430 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-04 14:19:38 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-04 14:19:38 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-05-04 14:19:38 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-05-04 14:19:38 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-05-04 14:19:38 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-04 14:19:38 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-04 14:19:38 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-04 14:19:37 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-05-03 07:59:39 0 d-------- C:\Program Files\Ultra MP3 CD Burner
2008-05-03 00:33:52 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 00:33:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-01 20:38:26 0 d-------- C:\cabs
2008-05-01 20:38:17 24519680 --a------ C:\Program Files\D00643-001-001.exe
2008-05-01 20:03:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\teamspeak2
2008-05-01 20:03:13 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-05-01 19:56:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2008-05-01 19:56:18 0 d-------- C:\Program Files\Viewpoint
2008-05-01 19:56:17 0 d-------- C:\Program Files\AOD
2008-05-01 19:56:15 0 d-------- C:\Program Files\AIM
2008-04-30 21:13:12 68096 --a------ C:\WINDOWS\zip.exe
2008-04-30 21:13:12 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-30 21:13:12 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-30 21:13:12 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-30 21:13:12 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-30 21:13:12 98816 --a------ C:\WINDOWS\sed.exe
2008-04-30 21:13:12 80412 --a------ C:\WINDOWS\grep.exe
2008-04-30 21:13:12 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-29 23:33:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-04-29 23:29:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-04-29 23:29:21 0 d-------- C:\Program Files\DNA
2008-04-29 23:29:21 0 d-------- C:\Program Files\BitTorrent
2008-04-29 23:29:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-04-29 23:27:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-29 23:27:07 0 d-------- C:\Program Files\Uniblue
2008-04-29 23:11:39 0 d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-04-29 23:11:35 0 d-------- C:\Program Files\Security Task Manager
2008-04-29 22:41:30 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-29 22:41:25 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-29 22:41:25 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-29 22:40:04 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-29 21:27:37 0 d-------- C:\Program Files\Trend Micro
2008-04-29 20:06:57 0 d-------- C:\WINDOWS\BDOSCAN8
2008-04-29 18:40:22 0 d-------- C:\Program Files\TweakNow RegCleaner Std
2008-04-29 18:33:54 0 d-------- C:\WINDOWS\SxsCaPendDel
2008-04-29 18:15:13 0 d-------- C:\WINDOWS\pss
2008-04-17 11:58:32 0 d-------- C:\Program Files\iPod
-- Find3M Report ---------------------------------------------------------------
2008-05-01 19:06:59 0 d-------- C:\Program Files\Messenger
2008-05-01 19:06:58 0 d-------- C:\Program Files\iTunes
2008-05-01 19:06:58 0 d-------- C:\Program Files\Digital Media Reader
2008-04-30 16:13:18 6754 --a------ C:\Documents and Settings\Administrator\Application Data\wklnhst.dat
2008-04-29 23:17:46 0 d-------- C:\Program Files\Intel
2008-04-29 22:40:04 0 d-------- C:\Program Files\Common Files
2008-04-29 22:23:43 0 d-------- C:\Program Files\Google
2008-04-29 22:09:33 0 d-------- C:\Program Files\Java
2008-04-29 22:08:07 0 d-------- C:\Program Files\Netscape Internet Service
2008-04-29 22:07:52 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-29 22:07:52 0 d-------- C:\Program Files\CyberLink
2008-04-29 22:04:19 0 d-------- C:\Program Files\Common Files\AOL
2008-04-29 21:59:34 0 d-------- C:\Program Files\The Weather Channel FW
2008-04-29 21:57:01 0 d-------- C:\Program Files\Common Files\Real
2008-04-29 18:28:12 0 d-------- C:\Program Files\Hewlett-Packard
2008-04-29 18:27:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-02-12 15:56:24 1158 --a------ C:\WINDOWS\mozver.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [01/05/2006 05:28 AM]
"SigmatelSysTrayApp"="sttray.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [04/29/2008 11:29 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Awola]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Extended Warranty]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Registration]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
"C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
NA
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrnSys Executable]
C:\Program Files\Hewlett-Packard\hp print screen utility\PrnSys.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask .exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
sttray.exe
-- End of Deckard's System Scanner: finished at 2008-05-04 19:03:44 ------------
seems to be running really good and smooth
Run by Administrator on 2008-05-04 19:03:24
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Administrator.exe) ---------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:26 PM, on 5/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
C:\WINDOWS\system32\rsvp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\ADMINI~1.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Intel® Alert Service (AlertService) - Unknown owner - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe (file missing)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Intel® Quick Resume technology (ELService) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel® Viiv(tm) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
--
End of file - 4122 bytes
-- Files created between 2008-04-04 and 2008-05-04 -----------------------------
2008-05-04 16:43:06 0 d-------- C:\Program Files\Avira
2008-05-04 16:43:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-04 14:20:12 430 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-04 14:19:38 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-04 14:19:38 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-05-04 14:19:38 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-05-04 14:19:38 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-05-04 14:19:38 82944 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-04 14:19:38 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-04 14:19:38 82944 --a------ C:\WINDOWS\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-04 14:19:37 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-05-03 07:59:39 0 d-------- C:\Program Files\Ultra MP3 CD Burner
2008-05-03 00:33:52 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 00:33:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-01 20:38:26 0 d-------- C:\cabs
2008-05-01 20:38:17 24519680 --a------ C:\Program Files\D00643-001-001.exe
2008-05-01 20:03:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\teamspeak2
2008-05-01 20:03:13 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-05-01 19:56:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2008-05-01 19:56:18 0 d-------- C:\Program Files\Viewpoint
2008-05-01 19:56:17 0 d-------- C:\Program Files\AOD
2008-05-01 19:56:15 0 d-------- C:\Program Files\AIM
2008-04-30 21:13:12 68096 --a------ C:\WINDOWS\zip.exe
2008-04-30 21:13:12 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-30 21:13:12 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-30 21:13:12 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-30 21:13:12 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-30 21:13:12 98816 --a------ C:\WINDOWS\sed.exe
2008-04-30 21:13:12 80412 --a------ C:\WINDOWS\grep.exe
2008-04-30 21:13:12 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-29 23:33:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-04-29 23:29:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-04-29 23:29:21 0 d-------- C:\Program Files\DNA
2008-04-29 23:29:21 0 d-------- C:\Program Files\BitTorrent
2008-04-29 23:29:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-04-29 23:27:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-29 23:27:07 0 d-------- C:\Program Files\Uniblue
2008-04-29 23:11:39 0 d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-04-29 23:11:35 0 d-------- C:\Program Files\Security Task Manager
2008-04-29 22:41:30 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-29 22:41:25 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-29 22:41:25 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-29 22:40:04 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-29 21:27:37 0 d-------- C:\Program Files\Trend Micro
2008-04-29 20:06:57 0 d-------- C:\WINDOWS\BDOSCAN8
2008-04-29 18:40:22 0 d-------- C:\Program Files\TweakNow RegCleaner Std
2008-04-29 18:33:54 0 d-------- C:\WINDOWS\SxsCaPendDel
2008-04-29 18:15:13 0 d-------- C:\WINDOWS\pss
2008-04-17 11:58:32 0 d-------- C:\Program Files\iPod
-- Find3M Report ---------------------------------------------------------------
2008-05-01 19:06:59 0 d-------- C:\Program Files\Messenger
2008-05-01 19:06:58 0 d-------- C:\Program Files\iTunes
2008-05-01 19:06:58 0 d-------- C:\Program Files\Digital Media Reader
2008-04-30 16:13:18 6754 --a------ C:\Documents and Settings\Administrator\Application Data\wklnhst.dat
2008-04-29 23:17:46 0 d-------- C:\Program Files\Intel
2008-04-29 22:40:04 0 d-------- C:\Program Files\Common Files
2008-04-29 22:23:43 0 d-------- C:\Program Files\Google
2008-04-29 22:09:33 0 d-------- C:\Program Files\Java
2008-04-29 22:08:07 0 d-------- C:\Program Files\Netscape Internet Service
2008-04-29 22:07:52 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-29 22:07:52 0 d-------- C:\Program Files\CyberLink
2008-04-29 22:04:19 0 d-------- C:\Program Files\Common Files\AOL
2008-04-29 21:59:34 0 d-------- C:\Program Files\The Weather Channel FW
2008-04-29 21:57:01 0 d-------- C:\Program Files\Common Files\Real
2008-04-29 18:28:12 0 d-------- C:\Program Files\Hewlett-Packard
2008-04-29 18:27:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-02-12 15:56:24 1158 --a------ C:\WINDOWS\mozver.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [01/05/2006 05:28 AM]
"SigmatelSysTrayApp"="sttray.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [04/29/2008 11:29 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Awola]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Extended Warranty]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gateway Registration]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
"C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
NA
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrnSys Executable]
C:\Program Files\Hewlett-Packard\hp print screen utility\PrnSys.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask .exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
sttray.exe
-- End of Deckard's System Scanner: finished at 2008-05-04 19:03:44 ------------
seems to be running really good and smooth
:\;E:\;F:\;