woohoo! it worked!!!:banana:
Main.txt Log
Deckard's System Scanner v20071014.68
Run by LAURA on 2008-05-22 00:12:51
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
32: 2008-05-22 07:13:00 UTC - RP151 - Deckard's System Scanner Restore Point
31: 2008-05-21 13:19:20 UTC - RP150 - Removed Ad-Aware 2007
30: 2008-05-20 23:00:09 UTC - RP149 - Installed Ad-Aware 2007
29: 2008-05-20 22:59:07 UTC - RP148 - Removed Ad-Aware 2007
28: 2008-05-20 22:41:49 UTC - RP147 - Installed Ad-Aware 2007
-- First Restore Point --
1: 2008-04-27 16:30:54 UTC - RP120 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as LAURA.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:09 AM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
H:\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\LAURA.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User 'Default user')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Real-time Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\iPod\bin\iPodService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
--
End of file - 5689 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080519-211824-376 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R2 V7 - c:\windows\system32\drivers\v7.sys <Not Verified; IBM Corporation; IBM V7 Driver for Windows NT/2000>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Tmntsrv (Trend NT Realtime Service) - "c:\program files\trend micro\pc-cillin 2000\tmntsrv.exe" <Not Verified; Trend Micro Inc.; Trend Pc-cillin 7.61>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-04-22 and 2008-05-22 -----------------------------
2008-05-21 06:05:59 0 d-------- C:\Documents and Settings\LAURA\Application Data\MSN6
2008-05-21 06:05:59 0 d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-20 18:52:44 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sony Corporation
2008-05-20 18:52:44 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-20 18:52:43 1310720 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-05-20 15:42:02 0 d-------- C:\Program Files\Lavasoft
2008-05-20 15:42:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 23:50:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-19 21:43:28 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-19 21:43:18 0 d-------- C:\Documents and Settings\LAURA\Application Data\Mozilla
2008-05-03 09:48:00 270709 --a------ C:\WINDOWS\system32\000060.exe
2008-05-02 12:45:08 229518 --a------ C:\WINDOWS\system32\000090.exe
2008-04-26 07:39:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-04-26 04:04:55 0 d-------- C:\WINDOWS\system32\xcsDd06
2008-04-26 04:04:55 0 d-------- C:\Temp
2008-04-26 04:04:18 0 d-------- C:\Program Files\Bat
-- Find3M Report ---------------------------------------------------------------
2008-05-22 00:06:27 50 --a------ C:\AUTOEXEC.BAT
2008-05-21 14:27:32 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-21 11:00:36 0 d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-19 21:38:25 0 d-------- C:\Program Files\Common Files\AOL
2008-05-19 21:09:11 0 d-------- C:\Program Files\Trend Micro
2008-05-19 20:53:48 0 d-------- C:\Program Files\Common Files
2008-04-29 01:03:28 0 d-------- C:\Documents and Settings\LAURA\Application Data\Apple Computer
2008-04-04 15:35:54 0 d-------- C:\Documents and Settings\LAURA\Application Data\acccore
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [04/26/2001 12:02 PM]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [12/18/2001 08:09 PM]
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [12/18/2001 07:58 PM]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [04/21/2008 10:23 AM]
"Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [09/22/2003 11:01 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
C:\Documents and Settings\LAURA\Start Menu\Programs\Startup\
Bat - Auto Update.lnk - C:\Program Files\Bat\Bat.exe [4/26/2008 4:04:12 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [1/21/2008 10:26:12 PM]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [1/28/2008 9:00:59 PM]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [1/28/2008 9:00:50 PM]
Real-time Monitor.lnk - C:\WINDOWS\Installer\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\_106B5A0.exe [12/19/2001 3:59:22 PM]
VAIO Action Setup (Server).lnk - C:\Program Files\Sony\VAIO Action Setup\VAServ.exe [12/19/2001 3:24:36 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2008-05-22 00:16:24 ------------
Extra.txt Log
Deckard's System Scanner v20071014.68
Run by LAURA on 2008-05-22 00:12:51
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
32: 2008-05-22 07:13:00 UTC - RP151 - Deckard's System Scanner Restore Point
31: 2008-05-21 13:19:20 UTC - RP150 - Removed Ad-Aware 2007
30: 2008-05-20 23:00:09 UTC - RP149 - Installed Ad-Aware 2007
29: 2008-05-20 22:59:07 UTC - RP148 - Removed Ad-Aware 2007
28: 2008-05-20 22:41:49 UTC - RP147 - Installed Ad-Aware 2007
-- First Restore Point --
1: 2008-04-27 16:30:54 UTC - RP120 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as LAURA.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:09 AM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Trend Micro\PC-cillin 2000\PNTIOMON.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\Trend Micro\PC-cillin 2000\pccntupd.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
H:\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\LAURA.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe (User 'Default user')
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Real-time Monitor.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\iPod\bin\iPodService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
--
End of file - 5689 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080519-211824-376 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R2 V7 - c:\windows\system32\drivers\v7.sys <Not Verified; IBM Corporation; IBM V7 Driver for Windows NT/2000>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Tmntsrv (Trend NT Realtime Service) - "c:\program files\trend micro\pc-cillin 2000\tmntsrv.exe" <Not Verified; Trend Micro Inc.; Trend Pc-cillin 7.61>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-04-22 and 2008-05-22 -----------------------------
2008-05-21 06:05:59 0 d-------- C:\Documents and Settings\LAURA\Application Data\MSN6
2008-05-21 06:05:59 0 d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-05-20 18:52:44 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-05-20 18:52:44 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-20 18:52:44 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-05-20 18:52:44 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sony Corporation
2008-05-20 18:52:44 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-05-20 18:52:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-20 18:52:43 1310720 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-05-20 15:42:02 0 d-------- C:\Program Files\Lavasoft
2008-05-20 15:42:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 23:50:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-19 21:43:28 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-19 21:43:18 0 d-------- C:\Documents and Settings\LAURA\Application Data\Mozilla
2008-05-03 09:48:00 270709 --a------ C:\WINDOWS\system32\000060.exe
2008-05-02 12:45:08 229518 --a------ C:\WINDOWS\system32\000090.exe
2008-04-26 07:39:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-04-26 04:04:55 0 d-------- C:\WINDOWS\system32\xcsDd06
2008-04-26 04:04:55 0 d-------- C:\Temp
2008-04-26 04:04:18 0 d-------- C:\Program Files\Bat
-- Find3M Report ---------------------------------------------------------------
2008-05-22 00:06:27 50 --a------ C:\AUTOEXEC.BAT
2008-05-21 14:27:32 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-21 11:00:36 0 d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-05-19 21:38:25 0 d-------- C:\Program Files\Common Files\AOL
2008-05-19 21:09:11 0 d-------- C:\Program Files\Trend Micro
2008-05-19 20:53:48 0 d-------- C:\Program Files\Common Files
2008-04-29 01:03:28 0 d-------- C:\Documents and Settings\LAURA\Application Data\Apple Computer
2008-04-04 15:35:54 0 d-------- C:\Documents and Settings\LAURA\Application Data\acccore
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZTgServerSwitch"="c:\program files\support.com\client\lserver\server.vbs" [04/26/2001 12:02 PM]
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe" [12/18/2001 08:09 PM]
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe" [12/18/2001 07:58 PM]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [04/21/2008 10:23 AM]
"Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [09/22/2003 11:01 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
C:\Documents and Settings\LAURA\Start Menu\Programs\Startup\
Bat - Auto Update.lnk - C:\Program Files\Bat\Bat.exe [4/26/2008 4:04:12 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [1/21/2008 10:26:12 PM]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [1/28/2008 9:00:59 PM]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [1/28/2008 9:00:50 PM]
Real-time Monitor.lnk - C:\WINDOWS\Installer\{A839294B-70A9-11D5-9F5A-0050DAD742CD}\_106B5A0.exe [12/19/2001 3:59:22 PM]
VAIO Action Setup (Server).lnk - C:\Program Files\Sony\VAIO Action Setup\VAServ.exe [12/19/2001 3:24:36 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2008-05-22 00:16:24 ------------