ushpen25
2008-07-20, 14:46
Hello, i got a virus in my computer which really made my computer slow. Some of the drives in the My Computer were gone. But still I manage to remove those possible malware, spyware and viruses in my computer i guess coz there's still .dll files left in my system32 that has infected by a trojan that cant be deleted by a Spybot Search and Destroy.
I have made a HJT Log. Here it is.
Deckard's System Scanner v20071014.68
Run by * on 2007-07-20 19:37:26
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as *.exe) ---------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37: VIRUS ALERT!, on 7/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\*\My Documents\Downloads\Programs\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\7CF3~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {245A2B98-510E-4069-A6CD-09313268C0DB} - C:\WINDOWS\system32\xxyxYqpn.dll
O2 - BHO: (no name) - {2A65BE74-EC8D-401E-93DF-5BDA3DC05505} - C:\WINDOWS\system32\iifghhEt.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: {653f1854-1259-55c8-44e4-6ae29f7b2b5c} - {c5b2b7f9-2ea6-4e44-8c55-95214581f356} - C:\WINDOWS\system32\lijrdz.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: qndsfmao - {3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [3cf160d6] rundll32.exe "C:\WINDOWS\system32\uqjbmdix.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA8678] command /c del "C:\WINDOWS\system32\iifghhEt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6323] cmd /c del "C:\WINDOWS\system32\iifghhEt.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: iifghhEt - C:\WINDOWS\SYSTEM32\iifghhEt.dll
O21 - SSODL: kvxqmtre - {8C66CBC2-40D1-41A8-B7B6-3C44CEE457E0} - C:\WINDOWS\kvxqmtre.dll (file missing)
O21 - SSODL: evgratsm - {CDFB613B-B940-4454-8538-B12306D6FC79} - C:\WINDOWS\evgratsm.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
--
End of file - 7576 bytes
-- Files created between 2007-06-20 and 2007-07-20 -----------------------------
2008-07-19 18:20:35 0 d--hs---- C:\WINDOWS\Installer
2008-07-19 18:20:34 0 d-------- C:\Program Files\Common Files\ODBC
2008-07-19 18:20:31 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-07-19 18:20:30 0 dr------- C:\Program Files
2008-07-19 18:20:30 0 d-------- C:\Program Files\Common Files
2008-07-19 18:20:14 155136 --a------ C:\WINDOWS\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\Templates <TEMPLA~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\Default User\Start Menu <STARTM~1>
2008-07-19 18:20:04 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\PrintHood <PRINTH~1>
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\My Documents <MYDOCU~1>
2008-07-19 18:20:04 0 dr-h----- C:\Documents and Settings\Default User\Local Settings <LOCALS~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\Favorites <FAVORI~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-07-19 18:20:04 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\All Users\Templates <TEMPLA~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\All Users\Start Menu <STARTM~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\All Users\Favorites <FAVORI~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\All Users\Documents
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-07-19 18:18:13 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-07-19 18:18:13 0 d-------- C:\WINDOWS\system32\CatRoot
2008-07-19 18:18:07 0 dr-h----- C:\Documents and Settings\Default User\Application Data <APPLIC~1>
2008-07-19 18:18:07 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-07-19 18:18:07 0 dr-h----- C:\Documents and Settings\All Users\Application Data <APPLIC~1>
2008-07-19 18:18:07 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-07-19 18:17:45 0 d-------- C:\Documents and Settings
2008-07-19 18:17:44 0 d--hs---- C:\System Volume Information
2008-07-19 18:12:31 0 d-------- C:\WINDOWS
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\WinSxS
2008-07-19 18:12:31 0 dr------- C:\WINDOWS\Web
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\twain_32
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\wins
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\wbem
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\usmt
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\spool
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ShellExt
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\Setup
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ras
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\oobe
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\npp
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\mui
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\inetsrv
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\IME
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\icsxml
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ias
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\export
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-07-19 18:12:31 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\dhcp
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\config
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\3076
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\2052
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1054
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1042
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1041
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1037
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1033
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1031
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1028
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1025
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\security
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Resources
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\repair
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Provisioning
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\PeerNet
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\pchealth
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\mui
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\msapps
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\msagent
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Media
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\java
2008-07-19 18:12:31 0 d--h----- C:\WINDOWS\inf
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\ime
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Help
2008-07-19 18:12:31 0 dr--s---- C:\WINDOWS\Fonts
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\ehome
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Driver Cache
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Debug
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Cursors
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Connection Wizard
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Config
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\AppPatch
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\addins
2008-07-19 10:54:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-07-19 10:54:22 0 d-------- C:\Program Files\GRETECH
2008-07-19 10:54:18 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-19 10:49:37 0 d-------- C:\WINDOWS\system32\Lang
2008-07-19 10:49:36 0 d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-07-19 10:49:36 0 d-------- C:\Documents and Settings\*\Application Data\ATI
2008-07-19 10:46:18 0 d-------- C:\WINDOWS\system32\RTCOM
2008-07-19 10:44:37 4864 -ra------ C:\WINDOWS\system32\drivers\PortIo.sys <Not Verified; Windows (R) Codename Longhorn DDK provider; Windows (R) Codename Longhorn DDK driver>
2008-07-19 10:43:02 0 d-------- C:\Program Files\Common Files\ATI Technologies
2008-07-19 10:39:44 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-07-19 10:39:12 307200 -ra------ C:\WINDOWS\system32\atiiiexx.dll <Not Verified; ATI Technologies Inc.; ATI Display Driver Utilities>
2008-07-19 10:39:10 368640 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll <Not Verified; Advanced Micro Devices, Inc.; Catalyst® Control Centre>
2008-07-19 10:39:09 3107788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-07-19 10:39:09 887724 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-07-19 10:39:09 3107788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-07-19 10:39:09 165782 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-07-19 10:35:46 0 d-------- C:\Program Files\ATI Technologies
2008-07-19 10:35:44 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-19 10:35:18 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-19 10:34:02 0 d-------- C:\Documents and Settings\*\Application Data\Identities
2008-07-19 10:33:44 0 dr------- C:\Documents and Settings\*\My Documents <MYDOCU~1>
2008-07-19 10:33:44 0 d--h----- C:\Documents and Settings\*\Local Settings <LOCALS~1>
2008-07-19 10:33:44 0 dr------- C:\Documents and Settings\*\Favorites <FAVORI~1>
2008-07-19 10:33:44 0 d-------- C:\Documents and Settings\*\Desktop
2008-07-19 10:33:44 0 d---s---- C:\Documents and Settings\*\Cookies
2008-07-19 10:33:44 0 dr-h----- C:\Documents and Settings\*\Application Data <APPLIC~1>
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\Templates <TEMPLA~1>
2008-07-19 10:33:43 0 dr------- C:\Documents and Settings\*\Start Menu <STARTM~1>
2008-07-19 10:33:43 0 dr-h----- C:\Documents and Settings\*\SendTo
2008-07-19 10:33:43 0 dr-h----- C:\Documents and Settings\*\Recent
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\PrintHood <PRINTH~1>
2008-07-19 10:33:43 2097152 --ah----- C:\Documents and Settings\*\NTUSER.DAT
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\NetHood
2008-07-19 10:32:53 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-07-19 10:32:51 0 d-------- C:\WINDOWS\Prefetch
2008-07-19 10:32:49 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-07-19 10:32:48 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-07-19 10:32:48 0 d--h----- C:\Documents and Settings\LocalService\Local Settings <LOCALS~1>
2008-07-19 10:32:48 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-07-19 10:32:48 0 d-------- C:\Documents and Settings\LocalService\Application Data <APPLIC~1>
2008-07-19 10:32:48 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-07-19 10:32:02 225280 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-07-19 10:32:02 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings <LOCALS~1>
2008-07-19 10:32:02 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-07-19 10:32:02 0 d-------- C:\Documents and Settings\NetworkService\Application Data <APPLIC~1>
2008-07-19 10:32:02 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-07-19 10:28:49 0 d-------- C:\WINDOWS\system32\xircom
2008-07-19 10:28:49 0 d-------- C:\Program Files\microsoft frontpage
2008-07-19 10:28:37 262144 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-07-19 10:27:27 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-07-19 10:27:17 0 dr------- C:\WINDOWS\Offline Web Pages
2008-07-19 10:27:17 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-07-19 10:27:07 0 d--h----- C:\Program Files\WindowsUpdate
2008-07-19 10:26:45 0 d-------- C:\WINDOWS\system32\DirectX
2008-07-19 10:26:10 0 d---s---- C:\WINDOWS\Tasks
2008-07-19 10:26:09 0 d-------- C:\Program Files\Common Files\MSSoap
2008-07-19 10:26:06 0 d-------- C:\WINDOWS\srchasst
2008-07-19 10:26:05 0 d-------- C:\WINDOWS\system32\Macromed
2008-07-19 10:26:01 285696 --a------ C:\WINDOWS\system32\wuauclt1.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:25:56 0 d-------- C:\Program Files\Movie Maker
2008-07-19 10:25:48 0 d-------- C:\WINDOWS\system32\Restore
2008-07-19 10:25:42 321536 --a------ C:\WINDOWS\system32\mstask.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:25:08 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-07-19 10:24:54 0 d-------- C:\WINDOWS\Registration
2008-07-19 10:24:48 0 d-------- C:\Program Files\Online Services
2008-07-19 10:24:43 0 d-------- C:\Program Files\Messenger
2008-07-19 10:24:39 0 d-------- C:\Program Files\MSN Gaming Zone
2008-07-19 10:24:27 152064 --a------ C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:24:18 117760 --a------ C:\WINDOWS\system32\calc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:54 180736 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:54 0 d-------- C:\Program Files\Windows NT
2008-07-19 10:23:53 439808 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:52 657408 --a------ C:\WINDOWS\system32\mstscax.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:51 0 d-------- C:\WINDOWS\system32\MsDtc
2008-07-19 10:23:49 0 d-------- C:\WINDOWS\system32\Com
2008-01-23 05:38:04 2845696 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys <Not Verified; ATI Technologies Inc.; ATI Radeon WindowsNT Miniport Driver>
2008-01-23 04:43:42 272384 --a------ C:\WINDOWS\system32\ati2dvag.dll <Not Verified; ATI Technologies Inc.; ATI Radeon WindowsNT Display Driver>
2008-01-23 04:36:44 9949184 --a------ C:\WINDOWS\system32\atioglx2.dll <Not Verified; ATI Technologies Inc.; ATI OpenGL driver>
2008-01-23 04:35:58 147456 --a------ C:\WINDOWS\system32\atipdlxx.dll <Not Verified; ATI Technologies, Inc.; ATI Desktop Component>
2008-01-23 04:35:48 122880 --a------ C:\WINDOWS\system32\Oemdspif.dll <Not Verified; ATI Technologies, Inc.; ATI Driver Interface Component>
2008-01-23 04:35:42 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe <Not Verified; ATI Technologies, Inc.; ATI Default Resolution Update>
2008-01-23 04:35:34 43520 --a------ C:\WINDOWS\system32\ati2edxx.dll <Not Verified; ATI Technologies, Inc.; ATI External Device Utility>
2008-01-23 04:35:20 122880 --a------ C:\WINDOWS\system32\ati2evxx.dll <Not Verified; ATI Technologies Inc.; ATI External Event Utility for Windows>
2008-01-23 04:34:06 512000 --a------ C:\WINDOWS\system32\ati2evxx.exe <Not Verified; ATI Technologies Inc.; ATI External Event Utility for Windows>
2008-01-23 04:33:16 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL <Not Verified; ATI Technologies Inc.; ATI Radeon Family>
2008-01-23 04:25:36 3121920 --a------ C:\WINDOWS\system32\ati3duag.dll <Not Verified; ATI Technologies Inc.; ATI Technologies Inc. Radeon DirectX Universal Driver>
2008-01-23 04:15:00 1664256 --a------ C:\WINDOWS\system32\ativvaxx.dll <Not Verified; ATI Technologies Inc.; ATI Technologies Inc. Radeon Video Acceleration Universal Driver>
2008-01-23 04:04:26 46080 --a------ C:\WINDOWS\system32\amdpcom32.dll <Not Verified; Advanced Micro Devices, Inc.; Advanced Micro Devices, Inc. Radeon PCOM Universal Driver>
2008-01-23 04:01:10 385024 --a------ C:\WINDOWS\system32\atikvmag.dll <Not Verified; ATI Technologies Inc.; Virtual Command And Memory Manager>
2008-01-23 03:59:22 17408 --a------ C:\WINDOWS\system32\atitvo32.dll <Not Verified; ATI Technologies Inc.; ATI RageTheater/ImpacTV COM interface>
2008-01-23 03:58:36 49152 --a------ C:\WINDOWS\system32\drivers\ati2erec.dll <Not Verified; ATI Technologies Inc.; eRecord>
2008-01-23 03:58:02 5435392 --a------ C:\WINDOWS\system32\atioglxx.dll <Not Verified; ATI Technologies Inc.; ATI OpenGL driver>
2008-01-23 03:57:16 163840 --a------ C:\WINDOWS\system32\atiok3x2.dll <Not Verified; ATI Technologies Inc.; Ring 0 x2 Component>
2008-01-23 03:53:52 503808 --a------ C:\WINDOWS\system32\ati2cqag.dll <Not Verified; ATI Technologies Inc.; ATI Radeon Family>
2007-07-20 18:56:36 0 d-------- C:\Documents and Settings\*\Application Data\WinRAR
2007-07-20 14:10:09 0 d-------- C:\Program Files\LimeWire
2007-07-20 13:53:26 0 d-------- C:\Program Files\EPSON
2007-07-20 13:53:03 65536 --a------ C:\WINDOWS\system32\EEBUtil.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 55808 --a------ C:\WINDOWS\system32\EEBSDKIF.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON Bidirectional Printer>
2007-07-20 13:53:03 110592 --a------ C:\WINDOWS\system32\EEBDSCVR.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 131072 --a------ C:\WINDOWS\system32\EEBAPI.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 69632 --a------ C:\WINDOWS\system32\EBAPI.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:02 0 d-------- C:\Program Files\Common Files\EPSON
2007-07-20 08:54:07 0 d-------- C:\Program Files\SpywareGuard
2007-07-20 08:49:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-07-20 07:10:26 0 d-------- C:\Program Files\Trend Micro
2007-07-20 06:12:59 116864 --a------ C:\WINDOWS\system32\lijrdz.dll
2007-07-20 06:12:56 116864 --a------ C:\WINDOWS\system32\kmbrgabn.dll
2007-07-20 06:11:03 93184 --a------ C:\WINDOWS\system32\uqjbmdix.dll
2007-07-20 02:19:00 0 d-------- C:\Program Files\Panda Security
2007-07-20 02:11:50 0 d-------- C:\Documents and Settings\Test\Application Data\Macromedia
2007-07-20 02:10:49 0 d-------- C:\Documents and Settings\Test\Application Data\Mozilla
2007-07-20 02:09:28 0 d-------- C:\Documents and Settings\Test\Application Data\AVGTOOLBAR
2007-07-20 02:08:52 0 d-------- C:\Documents and Settings\Test\Application Data\TmpRecentIcons
2007-07-20 02:08:51 0 d-------- C:\Documents and Settings\Test\Application Data\ATI
2007-07-20 02:08:34 0 d-------- C:\Documents and Settings\Test\Application Data\Identities
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Favorites <FAVORI~1>
2007-07-20 02:07:51 0 d-------- C:\Documents and Settings\Test\Desktop
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Cookies
2007-07-20 02:07:51 0 dr-h----- C:\Documents and Settings\Test\Application Data <APPLIC~1>
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Application Data\Microsoft
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\Templates <TEMPLA~1>
2007-07-20 02:07:50 0 dr------- C:\Documents and Settings\Test\Start Menu <STARTM~1>
2007-07-20 02:07:50 0 dr-h----- C:\Documents and Settings\Test\SendTo
2007-07-20 02:07:50 0 d--hs---- C:\Documents and Settings\Test\Recent
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\PrintHood <PRINTH~1>
2007-07-20 02:07:50 786432 --ah----- C:\Documents and Settings\Test\NTUSER.DAT
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\NetHood
2007-07-20 02:07:50 0 d---s---- C:\Documents and Settings\Test\My Documents <MYDOCU~1>
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\Local Settings <LOCALS~1>
2007-07-20 00:25:10 0 d-------- C:\Documents and Settings\*\Application Data\TmpRecentIcons
2007-07-19 22:53:21 116864 --a------ C:\WINDOWS\system32\fwhbwk.dll
2007-07-19 22:53:16 116864 --a------ C:\WINDOWS\system32\gxftedky.dll
2007-07-19 22:52:08 193479 --ahs---- C:\WINDOWS\system32\npqYxyxx.ini2
2007-07-19 22:51:56 322816 --a------ C:\WINDOWS\system32\xxyxYqpn.dll
2007-07-19 22:44:09 32640 -----n--- C:\WINDOWS\system32\iifghhEt.dll
2007-07-19 22:43:31 454656 --a------ C:\WINDOWS\kgxmotapktx.dll
2007-07-19 22:43:29 155648 --a------ C:\WINDOWS\agpqlrfm.exe
2007-07-19 22:35:26 0 d--h----- C:\$AVG8.VAULT$
2007-07-19 17:09:44 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-19 16:42:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-07-19 16:09:09 0 -rahs---- C:\MSDOS.SYS
2007-07-19 16:09:09 0 -rahs---- C:\IO.SYS
2007-07-19 16:09:09 0 --a------ C:\CONFIG.SYS
2007-07-19 16:09:09 0 --a------ C:\AUTOEXEC.BAT
2007-07-19 16:09:07 0 --a------ C:\WINDOWS\ativpsrm.bin
2007-07-19 16:09:06 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-07-19 16:08:58 0 d-------- C:\Program Files\SpywareBlaster
2007-07-19 16:02:46 0 d-------- C:\Documents and Settings\*\Application Data\IDM
2007-07-19 16:02:46 0 d-------- C:\Documents and Settings\*\Application Data\DMCache
2007-07-19 16:02:42 0 d-------- C:\Program Files\Internet Download Manager
2007-07-19 15:57:51 0 d-------- C:\Documents and Settings\*\Application Data\Macromedia
2007-07-19 15:51:24 0 d-------- C:\WINDOWS\pss
2007-07-19 15:42:46 0 --a------ C:\WINDOWS\nsreg.dat
2007-07-19 15:42:41 0 d-------- C:\Documents and Settings\*\Application Data\Mozilla
2007-07-19 15:40:23 0 d-------- C:\Program Files\Common Files\LightScribe
2007-07-19 15:39:39 0 d-------- C:\Documents and Settings\*\Application Data\Ahead
2007-07-19 15:37:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-07-19 15:37:15 0 d-------- C:\Program Files\Nero
2007-07-19 15:37:15 0 d-------- C:\Program Files\Common Files\Ahead
2007-07-19 15:36:30 0 d-------- C:\WINDOWS\RegisteredPackages
2007-07-19 12:24:06 0 d-------- C:\Documents and Settings\*\Application Data\GRETECH
2007-07-19 11:32:03 0 d-------- C:\Program Files\Microsoft Works
2007-07-19 11:31:53 0 d-------- C:\Program Files\MSBuild
2007-07-19 11:30:38 0 d-------- C:\Program Files\Microsoft.NET
2007-07-19 11:28:47 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2007-07-19 11:27:39 0 d-------- C:\WINDOWS\SHELLNEW
2007-07-19 11:26:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-07-19 11:26:25 0 dr-h----- C:\MSOCache
2007-07-19 11:18:47 0 d-------- C:\Program Files\Microsoft Student
2007-07-19 11:18:25 0 d-------- C:\Program Files\Learning Essentials
2007-07-19 11:10:45 0 d-------- C:\Program Files\VideoLAN
2007-07-19 11:09:56 0 d-------- C:\Program Files\Yahoo!
2007-07-19 11:08:56 0 d-------- C:\Program Files\Winamp
2007-07-19 11:08:27 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-07-19 11:08:23 0 d-------- C:\Program Files\CyberLink
2007-07-19 11:07:52 0 d-------- C:\Documents and Settings\*\Application Data\NCH Swift Sound
2007-07-19 11:07:42 0 d-------- C:\Program Files\NCH Swift Sound
2007-07-19 11:06:29 0 d-------- C:\WINDOWS\ferrarie themes
2007-07-19 11:05:31 0 d-------- C:\Documents and Settings\*\Application Data\Adobe
2007-07-19 11:03:30 63385 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-07-19 11:01:58 6116 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-07-19 11:01:38 0 d-------- C:\WINDOWS\BricoPacks
2007-07-19 11:00:09 0 d-------- C:\WINDOWS\system32\drivers\Avg
2007-07-19 11:00:09 0 d-------- C:\Documents and Settings\*\Application Data\AVGTOOLBAR
2007-07-19 10:59:57 0 d-------- C:\Program Files\AVG
2007-07-19 10:59:57 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
-- Find3M Report ---------------------------------------------------------------
2008-07-19 18:20:04 62 --ahs---- C:\Documents and Settings\*\Application Data\desktop.ini
2007-07-19 11:03:29 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A2B98-510E-4069-A6CD-09313268C0DB}]
07/19/2007 22:52: VIRUS ALERT! 322816 --a------ C:\WINDOWS\system32\xxyxYqpn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}]
07/19/2007 22:44: VIRUS ALERT! 32640 --------- C:\WINDOWS\system32\iifghhEt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
07/19/2007 17:06: VIRUS ALERT! 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5b2b7f9-2ea6-4e44-8c55-95214581f356}]
07/20/2007 06:12: VIRUS ALERT! 116864 --a------ C:\WINDOWS\system32\lijrdz.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [07/19/2007 17:06: VIRUS ALERT! 2055960]
[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35: VIRUS ALERT!]
"RTHDCPL"="RTHDCPL.EXE" [12/19/2006 11:12: VIRUS ALERT! C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [05/16/2006 18:04: VIRUS ALERT! C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 18:43: VIRUS ALERT! C:\WINDOWS\ALCMTR.EXE]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [07/19/2007 17:06: VIRUS ALERT!]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 00:47: VIRUS ALERT!]
"3cf160d6"="C:\WINDOWS\system32\uqjbmdix.dll" [07/20/2007 06:11: VIRUS ALERT!]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 00:56: VIRUS ALERT!]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [12/23/2006 18:05: VIRUS ALERT!]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/14/2008 22:42: VIRUS ALERT!]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42: VIRUS ALERT!]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Spybot - Search & Destroy"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
"SpybotDeletingA8678"=command /c del "C:\WINDOWS\system32\iifghhEt.dll"
"SpybotDeletingC6323"=cmd /c del "C:\WINDOWS\system32\iifghhEt.dll"
C:\Documents and Settings\ÿ\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [5/21/2006 3:43:08 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [7/20/2007 1:52:56 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"NoDispCPL"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoToolbarCustomize"=1 (0x1)
"StartMenuLogoff"=1 (0x1)
"NoStartMenuMorePrograms"=0 (0x0)
"NoSetFolders"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}"= C:\WINDOWS\system32\iifghhEt.dll [07/19/2007 22:44: VIRUS ALERT! 32640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"kvxqmtre"= {8C66CBC2-40D1-41A8-B7B6-3C44CEE457E0} - C:\WINDOWS\kvxqmtre.dll [ ]
"evgratsm"= {CDFB613B-B940-4454-8538-B12306D6FC79} - C:\WINDOWS\evgratsm.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifghhEt]
iifghhEt.dll 07/19/2007 22:44: VIRUS ALERT! 32640 C:\WINDOWS\system32\iifghhEt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\xxyxYqpn
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
-- End of Deckard's System Scanner: finished at 2007-07-20 19:38:38 ------------
I have made a HJT Log. Here it is.
Deckard's System Scanner v20071014.68
Run by * on 2007-07-20 19:37:26
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as *.exe) ---------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:37: VIRUS ALERT!, on 7/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\*\My Documents\Downloads\Programs\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\7CF3~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {245A2B98-510E-4069-A6CD-09313268C0DB} - C:\WINDOWS\system32\xxyxYqpn.dll
O2 - BHO: (no name) - {2A65BE74-EC8D-401E-93DF-5BDA3DC05505} - C:\WINDOWS\system32\iifghhEt.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: {653f1854-1259-55c8-44e4-6ae29f7b2b5c} - {c5b2b7f9-2ea6-4e44-8c55-95214581f356} - C:\WINDOWS\system32\lijrdz.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: qndsfmao - {3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [3cf160d6] rundll32.exe "C:\WINDOWS\system32\uqjbmdix.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA8678] command /c del "C:\WINDOWS\system32\iifghhEt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6323] cmd /c del "C:\WINDOWS\system32\iifghhEt.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: iifghhEt - C:\WINDOWS\SYSTEM32\iifghhEt.dll
O21 - SSODL: kvxqmtre - {8C66CBC2-40D1-41A8-B7B6-3C44CEE457E0} - C:\WINDOWS\kvxqmtre.dll (file missing)
O21 - SSODL: evgratsm - {CDFB613B-B940-4454-8538-B12306D6FC79} - C:\WINDOWS\evgratsm.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
--
End of file - 7576 bytes
-- Files created between 2007-06-20 and 2007-07-20 -----------------------------
2008-07-19 18:20:35 0 d--hs---- C:\WINDOWS\Installer
2008-07-19 18:20:34 0 d-------- C:\Program Files\Common Files\ODBC
2008-07-19 18:20:31 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-07-19 18:20:30 0 dr------- C:\Program Files
2008-07-19 18:20:30 0 d-------- C:\Program Files\Common Files
2008-07-19 18:20:14 155136 --a------ C:\WINDOWS\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\Templates <TEMPLA~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\Default User\Start Menu <STARTM~1>
2008-07-19 18:20:04 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\PrintHood <PRINTH~1>
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\My Documents <MYDOCU~1>
2008-07-19 18:20:04 0 dr-h----- C:\Documents and Settings\Default User\Local Settings <LOCALS~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\Favorites <FAVORI~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-07-19 18:20:04 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-07-19 18:20:04 0 d--h----- C:\Documents and Settings\All Users\Templates <TEMPLA~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\All Users\Start Menu <STARTM~1>
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\All Users\Favorites <FAVORI~1>
2008-07-19 18:20:04 0 dr------- C:\Documents and Settings\All Users\Documents
2008-07-19 18:20:04 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-07-19 18:18:13 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-07-19 18:18:13 0 d-------- C:\WINDOWS\system32\CatRoot
2008-07-19 18:18:07 0 dr-h----- C:\Documents and Settings\Default User\Application Data <APPLIC~1>
2008-07-19 18:18:07 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-07-19 18:18:07 0 dr-h----- C:\Documents and Settings\All Users\Application Data <APPLIC~1>
2008-07-19 18:18:07 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-07-19 18:17:45 0 d-------- C:\Documents and Settings
2008-07-19 18:17:44 0 d--hs---- C:\System Volume Information
2008-07-19 18:12:31 0 d-------- C:\WINDOWS
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\WinSxS
2008-07-19 18:12:31 0 dr------- C:\WINDOWS\Web
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\twain_32
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\wins
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\wbem
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\usmt
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\spool
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ShellExt
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\Setup
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ras
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\oobe
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\npp
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\mui
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\inetsrv
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\IME
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\icsxml
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\ias
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\export
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-07-19 18:12:31 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\dhcp
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\config
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\3076
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\2052
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1054
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1042
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1041
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1037
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1033
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1031
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1028
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system32\1025
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\system
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\security
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Resources
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\repair
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Provisioning
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\PeerNet
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\pchealth
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\mui
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\msapps
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\msagent
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Media
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\java
2008-07-19 18:12:31 0 d--h----- C:\WINDOWS\inf
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\ime
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Help
2008-07-19 18:12:31 0 dr--s---- C:\WINDOWS\Fonts
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\ehome
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Driver Cache
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Debug
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Cursors
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Connection Wizard
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\Config
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\AppPatch
2008-07-19 18:12:31 0 d-------- C:\WINDOWS\addins
2008-07-19 10:54:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-07-19 10:54:22 0 d-------- C:\Program Files\GRETECH
2008-07-19 10:54:18 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-19 10:49:37 0 d-------- C:\WINDOWS\system32\Lang
2008-07-19 10:49:36 0 d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-07-19 10:49:36 0 d-------- C:\Documents and Settings\*\Application Data\ATI
2008-07-19 10:46:18 0 d-------- C:\WINDOWS\system32\RTCOM
2008-07-19 10:44:37 4864 -ra------ C:\WINDOWS\system32\drivers\PortIo.sys <Not Verified; Windows (R) Codename Longhorn DDK provider; Windows (R) Codename Longhorn DDK driver>
2008-07-19 10:43:02 0 d-------- C:\Program Files\Common Files\ATI Technologies
2008-07-19 10:39:44 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-07-19 10:39:12 307200 -ra------ C:\WINDOWS\system32\atiiiexx.dll <Not Verified; ATI Technologies Inc.; ATI Display Driver Utilities>
2008-07-19 10:39:10 368640 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll <Not Verified; Advanced Micro Devices, Inc.; Catalyst® Control Centre>
2008-07-19 10:39:09 3107788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-07-19 10:39:09 887724 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-07-19 10:39:09 3107788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-07-19 10:39:09 165782 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-07-19 10:35:46 0 d-------- C:\Program Files\ATI Technologies
2008-07-19 10:35:44 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-19 10:35:18 0 d-------- C:\Program Files\Common Files\InstallShield
2008-07-19 10:34:02 0 d-------- C:\Documents and Settings\*\Application Data\Identities
2008-07-19 10:33:44 0 dr------- C:\Documents and Settings\*\My Documents <MYDOCU~1>
2008-07-19 10:33:44 0 d--h----- C:\Documents and Settings\*\Local Settings <LOCALS~1>
2008-07-19 10:33:44 0 dr------- C:\Documents and Settings\*\Favorites <FAVORI~1>
2008-07-19 10:33:44 0 d-------- C:\Documents and Settings\*\Desktop
2008-07-19 10:33:44 0 d---s---- C:\Documents and Settings\*\Cookies
2008-07-19 10:33:44 0 dr-h----- C:\Documents and Settings\*\Application Data <APPLIC~1>
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\Templates <TEMPLA~1>
2008-07-19 10:33:43 0 dr------- C:\Documents and Settings\*\Start Menu <STARTM~1>
2008-07-19 10:33:43 0 dr-h----- C:\Documents and Settings\*\SendTo
2008-07-19 10:33:43 0 dr-h----- C:\Documents and Settings\*\Recent
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\PrintHood <PRINTH~1>
2008-07-19 10:33:43 2097152 --ah----- C:\Documents and Settings\*\NTUSER.DAT
2008-07-19 10:33:43 0 d--h----- C:\Documents and Settings\*\NetHood
2008-07-19 10:32:53 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-07-19 10:32:51 0 d-------- C:\WINDOWS\Prefetch
2008-07-19 10:32:49 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-07-19 10:32:48 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-07-19 10:32:48 0 d--h----- C:\Documents and Settings\LocalService\Local Settings <LOCALS~1>
2008-07-19 10:32:48 0 d---s---- C:\Documents and Settings\LocalService\Cookies
2008-07-19 10:32:48 0 d-------- C:\Documents and Settings\LocalService\Application Data <APPLIC~1>
2008-07-19 10:32:48 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-07-19 10:32:02 225280 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-07-19 10:32:02 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings <LOCALS~1>
2008-07-19 10:32:02 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-07-19 10:32:02 0 d-------- C:\Documents and Settings\NetworkService\Application Data <APPLIC~1>
2008-07-19 10:32:02 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-07-19 10:28:49 0 d-------- C:\WINDOWS\system32\xircom
2008-07-19 10:28:49 0 d-------- C:\Program Files\microsoft frontpage
2008-07-19 10:28:37 262144 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-07-19 10:27:27 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-07-19 10:27:17 0 dr------- C:\WINDOWS\Offline Web Pages
2008-07-19 10:27:17 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-07-19 10:27:07 0 d--h----- C:\Program Files\WindowsUpdate
2008-07-19 10:26:45 0 d-------- C:\WINDOWS\system32\DirectX
2008-07-19 10:26:10 0 d---s---- C:\WINDOWS\Tasks
2008-07-19 10:26:09 0 d-------- C:\Program Files\Common Files\MSSoap
2008-07-19 10:26:06 0 d-------- C:\WINDOWS\srchasst
2008-07-19 10:26:05 0 d-------- C:\WINDOWS\system32\Macromed
2008-07-19 10:26:01 285696 --a------ C:\WINDOWS\system32\wuauclt1.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:25:56 0 d-------- C:\Program Files\Movie Maker
2008-07-19 10:25:48 0 d-------- C:\WINDOWS\system32\Restore
2008-07-19 10:25:42 321536 --a------ C:\WINDOWS\system32\mstask.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:25:08 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-07-19 10:24:54 0 d-------- C:\WINDOWS\Registration
2008-07-19 10:24:48 0 d-------- C:\Program Files\Online Services
2008-07-19 10:24:43 0 d-------- C:\Program Files\Messenger
2008-07-19 10:24:39 0 d-------- C:\Program Files\MSN Gaming Zone
2008-07-19 10:24:27 152064 --a------ C:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:24:18 117760 --a------ C:\WINDOWS\system32\calc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:54 180736 --a------ C:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:54 0 d-------- C:\Program Files\Windows NT
2008-07-19 10:23:53 439808 --a------ C:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:52 657408 --a------ C:\WINDOWS\system32\mstscax.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 10:23:51 0 d-------- C:\WINDOWS\system32\MsDtc
2008-07-19 10:23:49 0 d-------- C:\WINDOWS\system32\Com
2008-01-23 05:38:04 2845696 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys <Not Verified; ATI Technologies Inc.; ATI Radeon WindowsNT Miniport Driver>
2008-01-23 04:43:42 272384 --a------ C:\WINDOWS\system32\ati2dvag.dll <Not Verified; ATI Technologies Inc.; ATI Radeon WindowsNT Display Driver>
2008-01-23 04:36:44 9949184 --a------ C:\WINDOWS\system32\atioglx2.dll <Not Verified; ATI Technologies Inc.; ATI OpenGL driver>
2008-01-23 04:35:58 147456 --a------ C:\WINDOWS\system32\atipdlxx.dll <Not Verified; ATI Technologies, Inc.; ATI Desktop Component>
2008-01-23 04:35:48 122880 --a------ C:\WINDOWS\system32\Oemdspif.dll <Not Verified; ATI Technologies, Inc.; ATI Driver Interface Component>
2008-01-23 04:35:42 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe <Not Verified; ATI Technologies, Inc.; ATI Default Resolution Update>
2008-01-23 04:35:34 43520 --a------ C:\WINDOWS\system32\ati2edxx.dll <Not Verified; ATI Technologies, Inc.; ATI External Device Utility>
2008-01-23 04:35:20 122880 --a------ C:\WINDOWS\system32\ati2evxx.dll <Not Verified; ATI Technologies Inc.; ATI External Event Utility for Windows>
2008-01-23 04:34:06 512000 --a------ C:\WINDOWS\system32\ati2evxx.exe <Not Verified; ATI Technologies Inc.; ATI External Event Utility for Windows>
2008-01-23 04:33:16 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL <Not Verified; ATI Technologies Inc.; ATI Radeon Family>
2008-01-23 04:25:36 3121920 --a------ C:\WINDOWS\system32\ati3duag.dll <Not Verified; ATI Technologies Inc.; ATI Technologies Inc. Radeon DirectX Universal Driver>
2008-01-23 04:15:00 1664256 --a------ C:\WINDOWS\system32\ativvaxx.dll <Not Verified; ATI Technologies Inc.; ATI Technologies Inc. Radeon Video Acceleration Universal Driver>
2008-01-23 04:04:26 46080 --a------ C:\WINDOWS\system32\amdpcom32.dll <Not Verified; Advanced Micro Devices, Inc.; Advanced Micro Devices, Inc. Radeon PCOM Universal Driver>
2008-01-23 04:01:10 385024 --a------ C:\WINDOWS\system32\atikvmag.dll <Not Verified; ATI Technologies Inc.; Virtual Command And Memory Manager>
2008-01-23 03:59:22 17408 --a------ C:\WINDOWS\system32\atitvo32.dll <Not Verified; ATI Technologies Inc.; ATI RageTheater/ImpacTV COM interface>
2008-01-23 03:58:36 49152 --a------ C:\WINDOWS\system32\drivers\ati2erec.dll <Not Verified; ATI Technologies Inc.; eRecord>
2008-01-23 03:58:02 5435392 --a------ C:\WINDOWS\system32\atioglxx.dll <Not Verified; ATI Technologies Inc.; ATI OpenGL driver>
2008-01-23 03:57:16 163840 --a------ C:\WINDOWS\system32\atiok3x2.dll <Not Verified; ATI Technologies Inc.; Ring 0 x2 Component>
2008-01-23 03:53:52 503808 --a------ C:\WINDOWS\system32\ati2cqag.dll <Not Verified; ATI Technologies Inc.; ATI Radeon Family>
2007-07-20 18:56:36 0 d-------- C:\Documents and Settings\*\Application Data\WinRAR
2007-07-20 14:10:09 0 d-------- C:\Program Files\LimeWire
2007-07-20 13:53:26 0 d-------- C:\Program Files\EPSON
2007-07-20 13:53:03 65536 --a------ C:\WINDOWS\system32\EEBUtil.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 55808 --a------ C:\WINDOWS\system32\EEBSDKIF.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON Bidirectional Printer>
2007-07-20 13:53:03 110592 --a------ C:\WINDOWS\system32\EEBDSCVR.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 131072 --a------ C:\WINDOWS\system32\EEBAPI.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:03 69632 --a------ C:\WINDOWS\system32\EBAPI.dll <Not Verified; SEIKO EPSON CORPORATION; Enhanced EPSON Bi-directional API>
2007-07-20 13:53:02 0 d-------- C:\Program Files\Common Files\EPSON
2007-07-20 08:54:07 0 d-------- C:\Program Files\SpywareGuard
2007-07-20 08:49:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-07-20 07:10:26 0 d-------- C:\Program Files\Trend Micro
2007-07-20 06:12:59 116864 --a------ C:\WINDOWS\system32\lijrdz.dll
2007-07-20 06:12:56 116864 --a------ C:\WINDOWS\system32\kmbrgabn.dll
2007-07-20 06:11:03 93184 --a------ C:\WINDOWS\system32\uqjbmdix.dll
2007-07-20 02:19:00 0 d-------- C:\Program Files\Panda Security
2007-07-20 02:11:50 0 d-------- C:\Documents and Settings\Test\Application Data\Macromedia
2007-07-20 02:10:49 0 d-------- C:\Documents and Settings\Test\Application Data\Mozilla
2007-07-20 02:09:28 0 d-------- C:\Documents and Settings\Test\Application Data\AVGTOOLBAR
2007-07-20 02:08:52 0 d-------- C:\Documents and Settings\Test\Application Data\TmpRecentIcons
2007-07-20 02:08:51 0 d-------- C:\Documents and Settings\Test\Application Data\ATI
2007-07-20 02:08:34 0 d-------- C:\Documents and Settings\Test\Application Data\Identities
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Favorites <FAVORI~1>
2007-07-20 02:07:51 0 d-------- C:\Documents and Settings\Test\Desktop
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Cookies
2007-07-20 02:07:51 0 dr-h----- C:\Documents and Settings\Test\Application Data <APPLIC~1>
2007-07-20 02:07:51 0 d---s---- C:\Documents and Settings\Test\Application Data\Microsoft
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\Templates <TEMPLA~1>
2007-07-20 02:07:50 0 dr------- C:\Documents and Settings\Test\Start Menu <STARTM~1>
2007-07-20 02:07:50 0 dr-h----- C:\Documents and Settings\Test\SendTo
2007-07-20 02:07:50 0 d--hs---- C:\Documents and Settings\Test\Recent
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\PrintHood <PRINTH~1>
2007-07-20 02:07:50 786432 --ah----- C:\Documents and Settings\Test\NTUSER.DAT
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\NetHood
2007-07-20 02:07:50 0 d---s---- C:\Documents and Settings\Test\My Documents <MYDOCU~1>
2007-07-20 02:07:50 0 d--h----- C:\Documents and Settings\Test\Local Settings <LOCALS~1>
2007-07-20 00:25:10 0 d-------- C:\Documents and Settings\*\Application Data\TmpRecentIcons
2007-07-19 22:53:21 116864 --a------ C:\WINDOWS\system32\fwhbwk.dll
2007-07-19 22:53:16 116864 --a------ C:\WINDOWS\system32\gxftedky.dll
2007-07-19 22:52:08 193479 --ahs---- C:\WINDOWS\system32\npqYxyxx.ini2
2007-07-19 22:51:56 322816 --a------ C:\WINDOWS\system32\xxyxYqpn.dll
2007-07-19 22:44:09 32640 -----n--- C:\WINDOWS\system32\iifghhEt.dll
2007-07-19 22:43:31 454656 --a------ C:\WINDOWS\kgxmotapktx.dll
2007-07-19 22:43:29 155648 --a------ C:\WINDOWS\agpqlrfm.exe
2007-07-19 22:35:26 0 d--h----- C:\$AVG8.VAULT$
2007-07-19 17:09:44 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-19 16:42:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-07-19 16:09:09 0 -rahs---- C:\MSDOS.SYS
2007-07-19 16:09:09 0 -rahs---- C:\IO.SYS
2007-07-19 16:09:09 0 --a------ C:\CONFIG.SYS
2007-07-19 16:09:09 0 --a------ C:\AUTOEXEC.BAT
2007-07-19 16:09:07 0 --a------ C:\WINDOWS\ativpsrm.bin
2007-07-19 16:09:06 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-07-19 16:08:58 0 d-------- C:\Program Files\SpywareBlaster
2007-07-19 16:02:46 0 d-------- C:\Documents and Settings\*\Application Data\IDM
2007-07-19 16:02:46 0 d-------- C:\Documents and Settings\*\Application Data\DMCache
2007-07-19 16:02:42 0 d-------- C:\Program Files\Internet Download Manager
2007-07-19 15:57:51 0 d-------- C:\Documents and Settings\*\Application Data\Macromedia
2007-07-19 15:51:24 0 d-------- C:\WINDOWS\pss
2007-07-19 15:42:46 0 --a------ C:\WINDOWS\nsreg.dat
2007-07-19 15:42:41 0 d-------- C:\Documents and Settings\*\Application Data\Mozilla
2007-07-19 15:40:23 0 d-------- C:\Program Files\Common Files\LightScribe
2007-07-19 15:39:39 0 d-------- C:\Documents and Settings\*\Application Data\Ahead
2007-07-19 15:37:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-07-19 15:37:15 0 d-------- C:\Program Files\Nero
2007-07-19 15:37:15 0 d-------- C:\Program Files\Common Files\Ahead
2007-07-19 15:36:30 0 d-------- C:\WINDOWS\RegisteredPackages
2007-07-19 12:24:06 0 d-------- C:\Documents and Settings\*\Application Data\GRETECH
2007-07-19 11:32:03 0 d-------- C:\Program Files\Microsoft Works
2007-07-19 11:31:53 0 d-------- C:\Program Files\MSBuild
2007-07-19 11:30:38 0 d-------- C:\Program Files\Microsoft.NET
2007-07-19 11:28:47 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2007-07-19 11:27:39 0 d-------- C:\WINDOWS\SHELLNEW
2007-07-19 11:26:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-07-19 11:26:25 0 dr-h----- C:\MSOCache
2007-07-19 11:18:47 0 d-------- C:\Program Files\Microsoft Student
2007-07-19 11:18:25 0 d-------- C:\Program Files\Learning Essentials
2007-07-19 11:10:45 0 d-------- C:\Program Files\VideoLAN
2007-07-19 11:09:56 0 d-------- C:\Program Files\Yahoo!
2007-07-19 11:08:56 0 d-------- C:\Program Files\Winamp
2007-07-19 11:08:27 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-07-19 11:08:23 0 d-------- C:\Program Files\CyberLink
2007-07-19 11:07:52 0 d-------- C:\Documents and Settings\*\Application Data\NCH Swift Sound
2007-07-19 11:07:42 0 d-------- C:\Program Files\NCH Swift Sound
2007-07-19 11:06:29 0 d-------- C:\WINDOWS\ferrarie themes
2007-07-19 11:05:31 0 d-------- C:\Documents and Settings\*\Application Data\Adobe
2007-07-19 11:03:30 63385 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-07-19 11:01:58 6116 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-07-19 11:01:38 0 d-------- C:\WINDOWS\BricoPacks
2007-07-19 11:00:09 0 d-------- C:\WINDOWS\system32\drivers\Avg
2007-07-19 11:00:09 0 d-------- C:\Documents and Settings\*\Application Data\AVGTOOLBAR
2007-07-19 10:59:57 0 d-------- C:\Program Files\AVG
2007-07-19 10:59:57 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
-- Find3M Report ---------------------------------------------------------------
2008-07-19 18:20:04 62 --ahs---- C:\Documents and Settings\*\Application Data\desktop.ini
2007-07-19 11:03:29 218624 --a------ C:\WINDOWS\system32\uxtheme.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A2B98-510E-4069-A6CD-09313268C0DB}]
07/19/2007 22:52: VIRUS ALERT! 322816 --a------ C:\WINDOWS\system32\xxyxYqpn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}]
07/19/2007 22:44: VIRUS ALERT! 32640 --------- C:\WINDOWS\system32\iifghhEt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
07/19/2007 17:06: VIRUS ALERT! 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5b2b7f9-2ea6-4e44-8c55-95214581f356}]
07/20/2007 06:12: VIRUS ALERT! 116864 --a------ C:\WINDOWS\system32\lijrdz.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [07/19/2007 17:06: VIRUS ALERT! 2055960]
[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35: VIRUS ALERT!]
"RTHDCPL"="RTHDCPL.EXE" [12/19/2006 11:12: VIRUS ALERT! C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [05/16/2006 18:04: VIRUS ALERT! C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 18:43: VIRUS ALERT! C:\WINDOWS\ALCMTR.EXE]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [07/19/2007 17:06: VIRUS ALERT!]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 00:47: VIRUS ALERT!]
"3cf160d6"="C:\WINDOWS\system32\uqjbmdix.dll" [07/20/2007 06:11: VIRUS ALERT!]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 00:56: VIRUS ALERT!]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [12/23/2006 18:05: VIRUS ALERT!]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [07/14/2008 22:42: VIRUS ALERT!]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42: VIRUS ALERT!]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Spybot - Search & Destroy"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
"SpybotDeletingA8678"=command /c del "C:\WINDOWS\system32\iifghhEt.dll"
"SpybotDeletingC6323"=cmd /c del "C:\WINDOWS\system32\iifghhEt.dll"
C:\Documents and Settings\ÿ\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [5/21/2006 3:43:08 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [7/20/2007 1:52:56 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"NoDispCPL"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoToolbarCustomize"=1 (0x1)
"StartMenuLogoff"=1 (0x1)
"NoStartMenuMorePrograms"=0 (0x0)
"NoSetFolders"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}"= C:\WINDOWS\system32\iifghhEt.dll [07/19/2007 22:44: VIRUS ALERT! 32640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"kvxqmtre"= {8C66CBC2-40D1-41A8-B7B6-3C44CEE457E0} - C:\WINDOWS\kvxqmtre.dll [ ]
"evgratsm"= {CDFB613B-B940-4454-8538-B12306D6FC79} - C:\WINDOWS\evgratsm.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifghhEt]
iifghhEt.dll 07/19/2007 22:44: VIRUS ALERT! 32640 C:\WINDOWS\system32\iifghhEt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\xxyxYqpn
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
-- End of Deckard's System Scanner: finished at 2007-07-20 19:38:38 ------------