Deckard's System Scanner v20071014.68
Run by Ours on 2008-06-01 20:39:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-06-02 01:40:24 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Ours.exe) ------------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-06-01 20:47:49
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\vbpdtvdp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\system32\lvhidsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\HP\KBD\kbd.exe
C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\NOPDB.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\EUBBEA.EXE
C:\Program Files\Trend Micro\OfficeScan Client\TSC.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Ours\Desktop\dss.exe
C:\Program Files\Trend Micro\HijackThis\Ours.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ycomp_adb.../search/ie.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ycomp_adb...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\vbpdtvdp.exe,
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: targetedbanner browser optimizer - {05fd6cbf-521c-70cc-d135-17147c23c9e7} - C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {0F452574-8D50-4E8B-923F-2045F98F69BB} - C:\WINDOWS\system32\cbXRIyxU.dll
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
O2 - BHO: {6a88b8fb-8ffe-edb8-ea74-fd3a63866678} - {87666836-a3df-47ae-8bde-eff8bf8b88a6} - C:\WINDOWS\system32\egivcram.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
O2 - BHO: (no name) - {9AEE7FA8-0DA7-4C8A-8B3E-FBB6B979C657} - C:\WINDOWS\system32\mlJArqqR.dll
O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [5cd0bccf] rundll32.exe "C:\WINDOWS\system32\udchydlh.dll",b
O4 - HKLM\..\Run: [{d10b2c7f-33f7-1d43-8f75-a6b3402f9956}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll" DllStart
O4 - HKLM\..\Run: [BM5fe38f53] Rundll32.exe "C:\WINDOWS\system32\qaobcsdf.dll",s
O4 - HKLM\..\RunServices: [LvHidSvc] C:\WINDOWS\system32\lvhidsvc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [SpyShredder] C:\Program Files\SpyShredder\SpyShredder.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
https://online.musicmatch.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebook.com/controls/Facebo...toUploader5.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} () -
http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1006.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.Email Removed.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1207005698253O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu...b?1207007319156O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://ajlovesweasel-1969.spaces.live.com/...ad/MsnPUpld.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://games.pogo.com/online2/pogo/bejewel...aploader_v6.cabO17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{600C79F4-1F00-4A7D-A8F5-4080020751EF}: NameServer = 208.38.65.37,208.38.65.35
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: mlJArqqR - C:\WINDOWS\system32\mlJArqqR.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE
O23 - Service: Lifeview HID Remote Controller Service (lvhidsvc) - Animation Technologies Inc. - C:\WINDOWS\system32\lvhidsvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\Speed Disk\NOPDB.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe
--
End of file - 15740 bytes
-- File Associations -----------------------------------------------------------
[color=\"red\"].cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*[/color]
[color=\"red\"].cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*[/color]
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 GBDevice - c:\windows\system32\drivers\gbdevice.sys <Not Verified; Symantec Corporation; Norton GoBack>
R0 GoBack2K - c:\windows\system32\drivers\goback2k.sys <Not Verified; Symantec Corporation; Norton GoBack>
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R2 BCMNTIO - c:\program files\checkit\diagnostics\bcmntio.sys
R2 MAPMEM - c:\program files\checkit\diagnostics\mapmem.sys
R2 MASPINT - c:\windows\system32\drivers\maspint.sys <Not Verified; MicroStaff Co.,Ltd.; Aspi32 Driver for WinNT>
R2 TM_CFW (Common Firewall Driver) - c:\program files\trend micro\officescan client\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Micro Common Firewall Module 1.2>
R3 LVCap138 (TV Card WDM Video Capture) - c:\windows\system32\drivers\lvcap138.sys <Not Verified; Animation Technologies Inc.; Lifeview ® LR138 TV Card>
R3 lvtuner (TV Card TV Tuner) - c:\windows\system32\drivers\lvtuner.sys <Not Verified; Animation Technologies Inc.; Lifeview ® TV Card>
S2 GBFSHook - c:\windows\system32\drivers\gbfshook.sys <Not Verified; Symantec Corporation; Norton GoBack>
S3 SDdriver - c:\windows\system32\drivers\sddriver.sys <Not Verified; Symantec Corporation; Norton Speed Disk>
S3 TnIDriver - c:\docume~1\ours\locals~1\temp\tnif6.tmp (file missing)
S3 USBVSP - c:\windows\system32\drivers\usbvsp.sys <Not Verified; Atmel Corporation; Atmel USB Serial Adapter>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 lvhidsvc (Lifeview HID Remote Controller Service) - c:\windows\system32\lvhidsvc.exe <Not Verified; Animation Technologies Inc.; Lifeview ® TV Card>
R2 ntrtscan (OfficeScanNT RealTime Scan) - "c:\program files\trend micro\officescan client\ntrtscan.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 OfcPfwSvc (OfficeScanNT Personal Firewall) - "c:\program files\trend micro\officescan client\ofcpfwsvc.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
R2 Speed Disk service - c:\progra~1\norton~1\norton~1\speedd~1\nopdb.exe <Not Verified; Symantec Corporation; Norton Speed Disk>
R2 tmlisten (OfficeScanNT Listener) - "c:\program files\trend micro\officescan client\tmlisten.exe" <Not Verified; Trend Micro Inc.; Trend Micro OfficeScan>
S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 6103
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6103
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
-- Scheduled Tasks -------------------------------------------------------------
2008-06-01 17:59:28 252 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-05-31 19:53:06 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-05-31 11:31:08 528 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Ours.job
2008-05-31 10:22:31 290 --a------ C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
-- Files created between 2008-05-01 and 2008-06-01 -----------------------------
2008-06-01 17:53:23 0 d-------- C:\Program Files\SpyShredder
2008-05-31 23:03:25 95232 --a------ C:\WINDOWS\system32\udchydlh.dll
2008-05-31 23:00:26 108544 --a------ C:\WINDOWS\system32\egivcram.dll
2008-05-31 22:49:07 104448 --a------ C:\WINDOWS\system32\qaobcsdf.dll
2008-05-31 10:54:25 0 d-------- C:\Program Files\Norton AntiVirus
2008-05-31 10:37:24 2147483647 --ahs---- C:\gobackio.bin
2008-05-31 10:36:40 0 d-------- C:\WINDOWS\Downloaded Installations
2008-05-31 10:19:47 0 d-------- C:\Program Files\Norton SystemWorks
2008-05-31 10:15:12 95232 --a------ C:\WINDOWS\system32\qkhsuygq.dll
2008-05-31 10:06:20 108544 --a------ C:\WINDOWS\system32\bwwpllkk.dll
2008-05-31 10:01:05 104448 --a------ C:\WINDOWS\system32\tllqamdi.dll
2008-05-31 09:59:45 0 d-------- C:\Program Files\Symantec
2008-05-31 09:57:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-31 09:48:55 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-05-31 09:23:58 0 d-------- C:\Program Files\SpyMaxx
2008-05-31 09:12:39 0 --a------ C:\Documents and Settings\Ours\urlbase.bin
2008-05-31 09:12:39 0 --a------ C:\Documents and Settings\Ours\ignoredomainsbase.bin
2008-05-31 09:11:59 0 d-------- C:\Program Files\AntispyStorm
2008-05-31 09:00:11 0 d-------- C:\Program Files\CheckIt
2008-05-31 08:57:55 63488 --a------ C:\WINDOWS\system32\qoMcyVNG.dll
2008-05-31 08:55:19 15360 --a------ C:\WINDOWS\mssys.exe
2008-05-31 00:00:27 29952 --a------ C:\WINDOWS\msupdate.exe
2008-05-30 22:02:01 861 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-05-30 22:01:53 0 d-------- C:\WINDOWS\system32\vntiho18
2008-05-30 22:01:44 63488 --a------ C:\WINDOWS\system32\rqRLecyw.dll
2008-05-30 22:01:20 18176 --a------ C:\WINDOWS\y.exe
2008-05-30 22:01:20 22784 --a------ C:\WINDOWS\xplugin.dll
2008-05-30 22:01:19 10496 --a------ C:\WINDOWS\x.exe
2008-05-30 22:01:19 23808 --a------ C:\WINDOWS\winmgnt.exe
2008-05-30 22:01:19 16640 --a------ C:\WINDOWS\window.exe
2008-05-30 22:01:19 25856 --a------ C:\WINDOWS\winajbm.dll
2008-05-30 22:01:18 9984 --a------ C:\WINDOWS\win64.exe
2008-05-30 22:01:18 23552 --a------ C:\WINDOWS\win32e.exe
2008-05-30 22:01:18 30720 --a------ C:\WINDOWS\wEmail Removedexe
2008-05-30 22:01:18 19456 --a------ C:\WINDOWS\users32.exe
2008-05-30 22:01:18 28672 --a------ C:\WINDOWS\time.exe
2008-05-30 22:01:17 26624 --a------ C:\WINDOWS\systemcritical.exe
2008-05-30 22:01:17 28160 --a------ C:\WINDOWS\systeem.exe
2008-05-30 22:01:17 15104 --a------ C:\WINDOWS\svcinit.exe
2008-05-30 22:01:17 14848 --a------ C:\WINDOWS\svchost32.exe
2008-05-30 22:01:17 28160 --a------ C:\WINDOWS\sistem.exe
2008-05-30 22:01:16 27136 --a------ C:\WINDOWS\searchword.dll
2008-05-30 22:01:16 23040 --a------ C:\WINDOWS\rundll16.exe
2008-05-30 22:01:16 10496 --a------ C:\WINDOWS\quicken.exe
2008-05-30 22:01:16 10496 --a------ C:\WINDOWS\qttasks.exe
2008-05-30 22:01:16 24832 --a------ C:\WINDOWS\olehelp.exe
2008-05-30 22:01:15 22272 --a------ C:\WINDOWS\notepad32.exe
2008-05-30 22:01:15 12032 --a------ C:\WINDOWS\mtwirl32.dll
2008-05-30 22:01:15 29952 --a------ C:\WINDOWS\mswsc20.dll
2008-05-30 22:01:15 15616 --a------ C:\WINDOWS\mswsc10.dll
2008-05-30 22:01:14 18944 --a------ C:\WINDOWS\msspi.dll
2008-05-30 22:01:14 17920 --a------ C:\WINDOWS\msconfd.dll
2008-05-30 22:01:14 22784 --a------ C:\WINDOWS\loader.exe
2008-05-30 22:01:14 31232 --a------ C:\WINDOWS\internet.exe
2008-05-30 22:01:13 24064 --a------ C:\WINDOWS\inetinf.exe
2008-05-30 22:01:13 17920 --a------ C:\WINDOWS\iexplorer.exe
2008-05-30 22:01:13 28928 --a------ C:\WINDOWS\iedll.exe
2008-05-30 22:01:13 31744 --a------ C:\WINDOWS\helpcvs.exe
2008-05-30 22:01:12 15616 --a------ C:\WINDOWS\gfmnaaa.dll
2008-05-30 22:01:12 11776 --a------ C:\WINDOWS\funny.exe
2008-05-30 22:01:12 20736 --a------ C:\WINDOWS\funniest.exe
2008-05-30 22:01:12 27904 --a------ C:\WINDOWS\explorer32.exe
2008-05-30 22:01:12 31232 --a------ C:\WINDOWS\explore.exe
2008-05-30 22:01:11 14080 --a------ C:\WINDOWS\editpad.exe
2008-05-30 22:01:11 14848 --a------ C:\WINDOWS\dnsrelay.dll
2008-05-30 22:01:11 15616 --a------ C:\WINDOWS\directx32.exe
2008-05-30 22:01:11 22016 --a------ C:\WINDOWS\ctrlpan.dll
2008-05-30 22:01:11 28672 --a------ C:\WINDOWS\ctfmon32.exe
2008-05-30 22:01:11 13056 --a------ C:\WINDOWS\cpan.dll
2008-05-30 22:01:10 27136 --a------ C:\WINDOWS\clrssn.exe
2008-05-30 22:01:10 20736 --a------ C:\WINDOWS\avpcc.dll
2008-05-30 22:01:10 11776 --a------ C:\WINDOWS\accesss.exe
2008-05-30 22:00:00 401972 --a------ C:\WINDOWS\system32\g3.exe
2008-05-30 21:48:43 805368 --ahs---- C:\WINDOWS\system32\UxyIRXbc.ini2
2008-05-30 21:48:22 276480 --a------ C:\WINDOWS\system32\cbXRIyxU.dll
2008-05-30 21:45:39 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-30 21:45:23 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-05-30 21:44:08 0 d-------- C:\Documents and Settings\LocalService\Application Data\NetMon
2008-05-30 21:44:01 0 d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-05-30 21:43:59 1989 --a------ C:\WINDOWS\uninstall_nmon.vbs
2008-05-30 21:43:59 0 d--hs---- C:\WINDOWS\RGVuc3RlZHRz
2008-05-30 21:43:57 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-05-30 21:43:55 4 --a------ C:\WINDOWS\system32\hljwugsf.bin
2008-05-30 21:43:51 89049 --a------ C:\WINDOWS\system32\vbpdtvdp.exe <Not Verified; Microsoft; XML Media>
2008-05-30 21:43:51 89049 --a------ C:\WINDOWS\lfn.exe <Not Verified; Microsoft; XML Media>
2008-05-30 21:43:42 41984 --a------ C:\WINDOWS\mrofinu1000106.exe
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\Ucom1
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\sIE6
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\ITMP
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\evd2
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\Dev3
2008-05-30 21:43:30 0 d-------- C:\WINDOWS\system32\4026c
2008-05-30 21:43:24 41984 --a------ C:\WINDOWS\mrofinu1188.exe
2008-05-30 21:43:13 0 d-------- C:\WINDOWS\system32\vntiho05
2008-05-30 21:43:07 63488 --a------ C:\WINDOWS\system32\mlJArqqR.dll
2008-05-30 12:20:39 0 d-------- C:\Program Files\Apple Software Update
2008-05-30 12:20:31 0 d-------- C:\Program Files\QuickTime
2008-05-30 12:20:15 0 d-------- C:\Program Files\iPod
2008-05-30 12:20:12 0 d-------- C:\Program Files\iTunes
2008-05-30 07:10:18 0 d-------- C:\Documents and Settings\Ours\Application Data\VideoEgg
2008-05-30 03:34:03 0 d-------- C:\Program Files\iPod(2)
2008-05-30 03:33:54 0 d-------- C:\Program Files\iTunes(2)
2008-05-30 03:12:20 0 d-------- C:\Program Files\Apple Software Update(2)
2008-05-26 11:03:56 365056 --a------ C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll
2008-05-24 08:43:36 4194304 --a------ C:\Documents and Settings\Ours\ntuser.dat
2008-05-22 20:04:08 0 d-------- C:\WINDOWS\Prefetch
2008-05-22 19:52:16 0 d-------- C:\WINDOWS\system32\scripting
2008-05-22 19:52:15 0 d-------- C:\WINDOWS\l2schemas
2008-05-22 19:52:14 0 d-------- C:\WINDOWS\system32\en
2008-05-22 19:52:13 0 d-------- C:\WINDOWS\system32\bits
2008-05-22 19:48:06 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-22 19:39:00 0 d-------- C:\WINDOWS\EHome
2008-05-13 21:13:15 0 d-------- C:\Documents and Settings\Kids.DENSTEDTS\Application Data\Google
2008-05-13 18:25:40 0 d-------- C:\Documents and Settings\Kids.DENSTEDTS\Application Data\Apple Computer
2008-05-11 21:47:35 0 d-------- C:\Documents and Settings\Ours\Application Data\PlayFirst
2008-05-11 21:47:35 0 d-------- C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-05-11 21:45:49 0 d-------- C:\Documents and Settings\Ours\Application Data\GameHouse
2008-05-11 21:45:46 0 d-------- C:\Program Files\GameHouse
2008-05-07 20:15:37 0 d-------- C:\Program Files\MyWebSearch
2008-05-07 20:14:46 0 d-------- C:\Program Files\FunWebProducts
2008-05-06 16:18:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-02 08:34:42 0 d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-02 08:30:31 0 d-------- C:\Program Files\Windows Live Favorites
-- Find3M Report ---------------------------------------------------------------
2008-05-31 21:00:13 0 d-------- C:\Program Files\Trend Micro
2008-05-31 10:13:21 0 d-------- C:\Program Files\Common Files
2008-05-31 09:22:47 0 d-------- C:\Program Files\SpywareBlaster
2008-05-30 22:16:39 0 d-------- C:\Documents and Settings\Ours\Application Data\Lavasoft
2008-05-22 19:52:49 0 d-------- C:\Program Files\Messenger
2008-05-22 19:52:13 0 d-------- C:\Program Files\Movie Maker
2008-05-22 19:47:46 0 d-------- C:\Program Files\Windows NT
2008-05-22 17:08:33 0 d-------- C:\Documents and Settings\Ours\Application Data\GARMIN
2008-05-19 20:35:25 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-06 16:18:26 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-06 16:17:14 0 d-------- C:\Documents and Settings\Ours\Application Data\AdobeUM
2008-05-04 07:16:38 0 d-------- C:\Program Files\Windows Live
2008-05-02 08:33:08 0 d-------- C:\Program Files\Windows Live Toolbar
2008-05-01 18:13:53 0 d-------- C:\Documents and Settings\Ours\Application Data\Apple Computer
2008-04-28 19:28:35 0 d-------- C:\Documents and Settings\Ours\Application Data\Adobe
2008-04-26 09:42:50 0 d-------- C:\Program Files\Oberon Media
2008-04-22 19:17:18 0 d-------- C:\Program Files\Coupons
2008-04-19 13:06:23 0 d-------- C:\Program Files\Microsoft Works
2008-04-16 17:26:24 0 d-------- C:\Documents and Settings\Ours\Application Data\PC Suite
2008-04-16 17:26:16 0 d-------- C:\Documents and Settings\Ours\Application Data\Nokia
2008-04-16 17:26:16 1110 --a------ C:\Documents and Settings\Ours\Application Data\NMM-MetaData.db
2008-04-14 19:36:56 0 d-------- C:\Documents and Settings\Ours\Application Data\Yahoo!
2008-04-13 17:10:38 0 d-------- C:\Program Files\LimeWire
2008-04-13 17:05:25 0 d-------- C:\Program Files\Incomplete
2008-04-13 16:56:07 0 d-------- C:\Documents and Settings\Ours\Application Data\SAMSUNG
2008-04-12 08:44:52 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-11 22:34:13 0 d-------- C:\Program Files\Samsung
2008-04-11 08:50:25 0 d-------- C:\Documents and Settings\Ours\Application Data\FUJIFILM
2008-04-05 15:14:31 0 d-------- C:\Documents and Settings\Ours\Application Data\Talkback
2008-04-05 15:13:57 0 --a----c- C:\WINDOWS\nsreg.dat
2008-04-05 15:13:54 0 d-------- C:\Documents and Settings\Ours\Application Data\Mozilla
2008-04-04 17:33:17 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-04 08:38:03 0 d-------- C:\Documents and Settings\Ours\Application Data\funkitron
2008-04-04 08:22:18 0 d-------- C:\Program Files\Common Files\Real
2008-04-04 08:22:17 774144 --a------ C:\Program Files\RngInterstitial.dll <Not Verified; RealNetworks, Inc.; RealNetworks, Inc. RngInterstitial>
2008-04-04 08:22:13 0 d-------- C:\Program Files\Real
2008-04-02 20:07:08 0 d-------- C:\Documents and Settings\Ours\Application Data\Sun
2008-04-02 18:09:18 0 d-------- C:\Documents and Settings\Ours\Application Data\InterVideo
2008-04-01 18:52:21 0 d-------- C:\Documents and Settings\Ours\Application Data\Google
2008-04-01 17:05:01 0 d-------- C:\Program Files\InterVideo Information Service
2008-04-01 17:05:01 0 d-------- C:\Program Files\Common Files\Ulead
2008-04-01 17:03:58 0 d-------- C:\Program Files\InterVideo
2008-04-01 17:03:26 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-01 16:51:05 0 d-------- C:\Program Files\Musicmatch
2008-04-01 16:50:06 0 d-------- C:\Documents and Settings\Ours\Application Data\Musicmatch
2008-04-01 16:48:41 0 d-------- C:\Program Files\Google
2008-04-01 16:41:12 0 d-------- C:\Program Files\Yahoo!
2008-04-01 16:32:57 0 d-------- C:\Program Files\Lavasoft
2008-04-01 16:32:02 0 d-------- C:\Documents and Settings\Ours\Application Data\MySpace
2008-04-01 16:31:59 0 d-------- C:\Program Files\MySpace
2008-04-01 16:29:49 0 d-------- C:\Program Files\DIFX
2008-04-01 16:29:35 0 d-------- C:\Program Files\Common Files\PCSuite
2008-04-01 16:29:31 0 d-------- C:\Program Files\Nokia
2008-04-01 16:29:31 0 d-------- C:\Program Files\Common Files\Nokia
2008-04-01 16:29:11 0 d-------- C:\Program Files\PC Connectivity Solution
2008-04-01 16:15:46 0 d-------- C:\Program Files\Java
2008-03-31 19:51:24 96577 --a----c- C:\WINDOWS\hpqins16.dat
2008-03-31 19:48:18 2064 --a----c- C:\Documents and Settings\Ours\Application Data\HPSU_48BitScanUpdate.log
2008-03-31 19:37:07 345 --a----c- C:\Documents and Settings\Ours\Application Data\HelpFilesUpdatePatch_PRINTHELPWRAPPER.log
2008-03-31 19:37:05 0 --a----c- C:\Documents and Settings\Ours\Application Data\HelpFilesUpdatePatch_HELPFILEREPLACE.log
2008-03-31 19:36:18 2799 --a----c- C:\Documents and Settings\Ours\Application Data\PatchUpdate_InstantShareJPG.log
2008-03-31 19:35:48 3596 --a----c- C:\Documents and Settings\Ours\Application Data\PatchUpdate_IZClosingDiscError.log
2008-03-31 19:34:32 137866 --a----c- C:\Documents and Settings\Ours\Application Data\Update_HP_RedboxHprblog_HPSU.log
2008-03-31 19:34:17 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll <Not Verified; Hewlett Packard; Hewlett Packard Rediscovery Library>
2008-03-31 19:32:01 112384 --a------ C:\WINDOWS\hpoins07.dat
2008-03-31 19:00:16 28672 --a------ C:\WINDOWS\system32\qttask.exe
2008-03-31 18:59:02 0 -rahs---- C:\MSDOS.SYS
2008-03-31 18:59:02 0 -rahs---- C:\IO.SYS
2008-03-31 18:59:02 0 --a------ C:\CONFIG.SYS
2008-03-31 18:59:02 0 --a------ C:\AUTOEXEC.BAT
2008-03-31 18:56:23 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-31 12:43:07 62 --ahs---- C:\Documents and Settings\Ours\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00110011-4b0b-44d5-9718-90c88817369b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05fd6cbf-521c-70cc-d135-17147c23c9e7}]
05/26/2008 11:03 AM 365056 --a------ C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{086ae192-23a6-48d6-96ec-715f53797e85}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F452574-8D50-4E8B-923F-2045F98F69BB}]
05/30/2008 09:48 PM 276480 --a------ C:\WINDOWS\system32\cbXRIyxU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{150fa160-130d-451f-b863-b655061432ba}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{467faeb2-5f5b-4c81-bae0-2a4752ca7f4e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5321e378-ffad-4999-8c62-03ca8155f0b3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{587dbf2d-9145-4c9e-92c2-1f953da73773}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{799a370d-5993-4887-9df7-0a4756a77d00}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87666836-a3df-47ae-8bde-eff8bf8b88a6}]
05/31/2008 11:00 PM 108544 --a------ C:\WINDOWS\system32\egivcram.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9AEE7FA8-0DA7-4C8A-8B3E-FBB6B979C657}]
05/30/2008 09:43 PM 63488 --a------ C:\WINDOWS\system32\mlJArqqR.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a55581dc-2cdb-4089-8878-71a080b22342}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b847676d-72ac-4393-bfff-43a1eb979352}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765721306}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3eebbe8-9cab-4c76-b26a-747e25ebb4c6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e7afff2a-1b57-49c7-bf6b-e5123394c970}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fd9bc004-8331-4457-b830-4759ff704c22}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [02/07/2006 04:16 PM]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 02:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/23/2005 11:36 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/23/2005 11:31 AM]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [02/04/2002 11:32 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 05:24 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/02/2005 05:44 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [03/20/2006 05:34 PM]
"AGRSMMSG"="AGRSMMSG.exe" [06/29/2004 09:06 AM C:\WINDOWS\AGRSMMSG.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [10/28/2006 01:38 AM]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [09/05/2006 09:22 PM]
"5cd0bccf"="C:\WINDOWS\system32\udchydlh.dll" [05/31/2008 11:03 PM]
"{d10b2c7f-33f7-1d43-8f75-a6b3402f9956}"="C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll" [05/26/2008 11:03 AM]
"BM5fe38f53"="C:\WINDOWS\system32\qaobcsdf.dll" [05/31/2008 10:49 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:12 PM]
"Windows update loader"="C:\Windows\xpupdate.exe" []
"SpyShredder"="C:\Program Files\SpyShredder\SpyShredder.exe" [06/01/2008 05:53 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"LvHidSvc"=C:\WINDOWS\system32\lvhidsvc.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
"Wallpaper"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceActiveDesktopOn"=1 (0x1)
"NoActiveDesktop"=2 (0x2)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9AEE7FA8-0DA7-4C8A-8B3E-FBB6B979C657}"= C:\WINDOWS\system32\mlJArqqR.dll [05/30/2008 09:43 PM 63488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\vbpdtvdp.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJArqqR]
mlJArqqR.dll 05/30/2008 09:43 PM 63488 C:\WINDOWS\system32\mlJArqqR.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\cbXRIyxU
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton GoBack.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Norton GoBack.lnk
backup=C:\WINDOWS\pss\Norton GoBack.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ours^Start Menu^Programs^Startup^TVR Schedule.lnk]
path=C:\Documents and Settings\Ours\Start Menu\Programs\Startup\TVR Schedule.lnk
backup=C:\WINDOWS\pss\TVR Schedule.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5cd0bccf]
rundll32.exe "C:\WINDOWS\system32\qkhsuygq.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM5fe38f53]
Rundll32.exe "C:\WINDOWS\system32\tllqamdi.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\mcntmkdm.exe DWram
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gStart]
C:\Garmin\gStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD3257
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{d10b2c7f-33f7-1d43-8f75-a6b3402f9956}]
C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll" DllStart
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- End of Deckard's System Scanner: finished at 2008-06-01 21:18:39 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel® Celeron® CPU 2.93GHz
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 759.48 MiB / 188.8 MiB
Pagefile Memory (total/avail): 1860.34 MiB / 1357.68 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1873.89 MiB
C: is Fixed (NTFS) - 74.52 GiB total, 24.57 GiB free.
D: is Removable (No Media)
E: is Removable (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is CDROM (No Media)
I: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - ST380011A - 74.53 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - C:
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Ours\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=DENSTEDTS
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Ours
LOGONSERVER=\\DENSTEDTS
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\PC Connectivity Solution\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Samsung\Samsung PC Studio 3\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Ours\LOCALS~1\Temp
TMP=C:\DOCUME~1\Ours\LOCALS~1\Temp
USERDOMAIN=DENSTEDTS
USERNAME=Ours
USERPROFILE=C:\Documents and Settings\Ours
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Ours
(admin)Kids.DENSTEDTS
-- Add/Remove Programs ---------------------------------------------------------
--> "C:\Program Files\InstallShield Installation Information\{F37167DD-4436-4641-90B6-329D60632DDA}\Setup.exe" REMOVEALL --u:{F37167DD-4436-4641-90B6-329D60632DDA}
--> C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Advanced System Optimizer 2 --> "C:\Program Files\Advanced System Optimizer\unins000.exe"
Agere Systems PCI Soft Modem --> agrsmdel
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
CheckIt Diagnostics --> C:\PROGRA~1\CheckIt\DIAGNO~1\UNWISE.EXE C:\PROGRA~1\CheckIt\DIAGNO~1\INSTALL.LOG
Component Framework --> MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
Connection Keep Alive --> MsiExec.exe /I{77364F85-6219-4CB8-AAA0-6D53368D683D}
Coupon Printer for Windows --> "C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
Deewoo Network Manager removal --> C:\WINDOWS\system32\mcntmkdm.exe -UPop
Enhanced Multimedia Keyboard Solution --> C:\HP\KBD\Install.exe /u
Enhancement Browser Tools Targetedbanner --> C:\WINDOWS\system32\{6f9e1a15-0180-d974-96f8-28400f250b1a}.dll-uninst.exe
FinePixViewer Ver.3.2 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{24ED4D80-8294-11D5-96CD-0040266301AD} /l1033
Form Fill (Windows Live Toolbar) --> MsiExec.exe /X{F5AF5CDA-76FC-4794-9F28-09B6D54E7431}
FUJIFILM USB Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490882C-6961-11D5-BAE5-00E0188E010B}\SETUP.EXE"
Garmin MapSource --> MsiExec.exe /X{4ACBBFC6-3F39-48DE-8D85-182736B2749B}
Garmin Training Center 3.3.2 --> MsiExec.exe /X{7834FE69-824C-4644-8107-899201C074C8}
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google SketchUp 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x9 -removeonly
Google SketchUp 6 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x9 -removeonly
Highlight Viewer (Windows Live Toolbar) --> MsiExec.exe /X{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Document Viewer 5.3 --> C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Image Zone 5.3 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Imaging Device Functions 5.3 --> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP PSC & OfficeJet 5.3.B --> "C:\Program Files\HP\Digital Imaging\{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}\setup\hpzscr01.exe" -datfile hposcr07.dat
HP Solution Center & Imaging Support Tools 5.3 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update --> MsiExec.exe /X{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}
ImageMixer VCD for FinePix --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D3AA158A-9421-4883-8767-E771B0964A1D}\setup.exe"
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Internet Worm Protection --> MsiExec.exe /I{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
InterVideo WinDVD 8 --> C:\Program Files\InstallShield Installation Information\{20471B27-D702-4FE8-8DEC-0702CC8C0A85}\setup.exe -runfromtemp -l0x0409
iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138}
J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
Java(tm) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
LimeWire PRO 4.9.23 --> "C:\Program Files\LimeWire\uninstall.exe"
LiveUpdate 3.1 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Map Button (Windows Live Toolbar) --> MsiExec.exe /X{7745B7A9-F323-4BB9-9811-01BF57A028DA}
Microsoft Compressi