Deckard's System Scanner v20071014.68
Run by Owner on 2008-08-08 06:56:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-08-08 10:56:24 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 511 MiB (512 MiB recommended).
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:47 AM, on 8/8/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\S3apphk.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\AOL Companion\companion.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us5.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://us5.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {F574BF0D-F90E-EAA9-8761-EFC4AA5FF16E} - C:\WINDOWS\system32\sombzlmu.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [jbeschly] C:\WINDOWS\bbxpovzq.exe
O4 - HKLM\..\Run: [WinFavorites] c:\program files\winfavorites\WinFavorites.exe1
O4 - HKLM\..\Run: [CIPVF] C:\WINDOWS\CIPVF.exe
O4 - HKLM\..\Run: [iehelper] C:\Program Files\syslaunch.exe
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\xcafcqwz.exe
O4 - HKLM\..\Run: [PromulGate] "C:\Program Files\DelFin\PromulGate\PgMonitr.exe"
O4 - HKLM\..\Run: [Rundll16] C:\WINDOWS\rundll16.exe
O4 - HKLM\..\Run: [RealPlayerv2] AIM1.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [<h] c:\WINDOWS\System32\<head>
O4 - HKLM\..\Run: [<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859] c:\WINDOWS\System32\<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
O4 - HKLM\..\Run: [</h] c:\WINDOWS\System32\</html>
O4 - HKLM\..\Run: [<frame src="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCA] c:\WINDOWS\System32\<frame src="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">
O4 - HKLM\..\Run: [</frame] c:\WINDOWS\System32\</frameset>
O4 - HKLM\..\Run: [<nofra] c:\WINDOWS\System32\<noframes>
O4 - HKLM\..\Run: [<a href="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">Click here to go to beneditutti.com<] c:\WINDOWS\System32\<a href="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">Click here to go to beneditutti.com</a>.
O4 - HKLM\..\Run: [</nofra] c:\WINDOWS\System32\</noframes>
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Zero Knowledge Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKCU\..\Run: [] c:\WINDOWS\System32\
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [<h] c:\WINDOWS\System32\<head>
O4 - HKCU\..\Run: [<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859] c:\WINDOWS\System32\<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
O4 - HKCU\..\Run: [</h] c:\WINDOWS\System32\</html>
O4 - HKCU\..\Run: [<frame src="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCA] c:\WINDOWS\System32\<frame src="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">
O4 - HKCU\..\Run: [</frame] c:\WINDOWS\System32\</frameset>
O4 - HKCU\..\Run: [<nofra] c:\WINDOWS\System32\<noframes>
O4 - HKCU\..\Run: [<a href="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">Click here to go to beneditutti.com<] c:\WINDOWS\System32\<a href="http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM">Click here to go to beneditutti.com</a>.
O4 - HKCU\..\Run: [</nofra] c:\WINDOWS\System32\</noframes>
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -
http://www.imbum.com/Imbum.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1217888633296
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} -
http://download.overpro.com/WildApp.cab
O20 - AppInit_DLLs:
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 11051 bytes
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys <Not Verified; VERITAS Software, Inc.; >
R1 AFS2K - c:\windows\system32\drivers\afs2k.sys <Not Verified; Oak Technology Inc.; AFS>
R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys <Not Verified; VERITAS Software, Inc.; >
R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys <Not Verified; VERITAS Software, Inc.; >
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsndres - c:\windows\system32\dla\tfsndres.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys <Not Verified; VERITAS Software, Inc.; >
R3 Freedom (FREEDOM Miniport) - c:\windows\system32\drivers\freedom.sys <Not Verified; Zero-Knowledge Systems Inc.; Freedom>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-07-08 and 2008-08-08 -----------------------------
2008-08-06 21:09:14 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-08-06 21:09:09 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-06 21:09:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 19:18:45 0 d-------- C:\Program Files\Symantec
2008-08-04 18:28:10 0 d-------- C:\WINDOWS\System32\PreInstall
2008-08-04 18:28:09 0 d--h----- C:\WINDOWS\$hf_mig$
2008-08-04 18:27:17 0 d-------- C:\WINDOWS\System32\bits
2008-08-04 18:23:59 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-08-04 18:21:35 0 d-------- C:\WINDOWS\Prefetch
2008-08-04 18:15:58 0 d-------- C:\WINDOWS\ServicePackFiles
2008-08-04 18:15:58 0 d-------- C:\WINDOWS\ehome
2008-08-04 07:36:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-04 07:36:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-08-02 12:03:31 0 d-------- C:\Program Files\Trend Micro
2008-08-02 00:18:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
-- Find3M Report ---------------------------------------------------------------
2008-08-05 19:22:01 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-08-04 18:24:21 0 d--h----- C:\Program Files\WindowsUpdate
2008-08-04 18:15:58 0 d-------- C:\Program Files\Messenger
2008-08-04 18:15:51 0 d-------- C:\Program Files\Movie Maker
2008-08-03 14:37:43 0 d-------- C:\Program Files\Common Files
2008-08-02 00:59:23 0 d-------- C:\Program Files\Sqwire
2008-08-02 00:58:32 0 d-------- C:\Program Files\DownloadWare
2008-08-02 00:57:20 0 d-------- C:\Program Files\Free Offers from Freeze.com
2008-08-02 00:15:07 14830 --ah----- C:\WINDOWS\System32\fiz0
2008-08-01 23:48:06 49 --a------ C:\WINDOWS\mads.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F574BF0D-F90E-EAA9-8761-EFC4AA5FF16E}]
08/18/2001 08:00 AM 106496 --a------ C:\WINDOWS\system32\sombzlmu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 07:04 PM]
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [12/13/2001 02:05 AM]
"KBD"="C:\HP\KBD\KBD.EXE" [07/06/2001 11:56 PM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [12/19/2001 02:39 AM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [03/14/2002 01:25 PM]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [03/12/2002 06:28 AM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [03/12/2002 06:20 AM]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [03/09/2002 07:53 PM C:\WINDOWS\system32\nwiz.exe]
"S3apphk"="S3apphk.exe" [03/16/2002 01:51 AM C:\WINDOWS\system32\S3apphk.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [03/28/2002 04:50 AM]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [09/02/2002 06:01 PM]
"checktime"="c:\program files\HPSelect\Frontend\ct.exe" [01/26/2002 04:05 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [08/29/2003 06:32 PM]
"jbeschly"="C:\WINDOWS\bbxpovzq.exe" []
"WinFavorites"="c:\program files\winfavorites\WinFavorites.exe1" []
"CIPVF"="C:\WINDOWS\CIPVF.exe" []
"iehelper"="C:\Program Files\syslaunch.exe" []
"@"="c:\WINDOWS\System32\" [08/06/2008 09:59 PM]
"nvid"="C:\WINDOWS\System32\xcafcqwz.exe" []
"PromulGate"="C:\Program Files\DelFin\PromulGate\PgMonitr.exe" []
"Rundll16"="C:\WINDOWS\rundll16.exe" []
"RealPlayerv2"="AIM1.EXE" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/01/2008 01:25 AM]
"<h"="c:\WINDOWS\System32\<head>" []
"<title>beneditutti.com</title><meta name=keywords content=beneditutti.com><meta name=description content=beneditutti.com><meta name=robots content=INDEX"="" []
"</h"="c:\WINDOWS\System32\</html>" []
"<frame src=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCA"="c:\WINDOWS\System32\<frame src=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>" []
"</frame"="c:\WINDOWS\System32\</frameset>" []
"<nofra"="c:\WINDOWS\System32\<noframes>" []
"<a href=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>Click here to go to beneditutti.com<"="c:\WINDOWS\System32\<a href=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>Click here to go to beneditutti.com</a>." []
"</nofra"="c:\WINDOWS\System32\</noframes>" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\Program Files\Microsoft Works\WkDetect.exe" []
"Zero Knowledge Freedom"="C:\Program Files\Zero Knowledge\Freedom\Freedom.exe" []
"@"="c:\WINDOWS\System32\" [08/06/2008 09:59 PM]
"AIM"="C:\Program Files\AIM\aim.exe" [04/14/2004 05:45 PM]
"<h"="c:\WINDOWS\System32\<head>" []
"<title>beneditutti.com</title><meta name=keywords content=beneditutti.com><meta name=description content=beneditutti.com><meta name=robots content=INDEX, FOLLOW><meta name=revisit-after content=10><meta http-equiv=Content-Type content=text/htmlcharset=iso-8859"="c:\WINDOWS\System32\<title>beneditutti.com</title><meta name=keywords content=beneditutti.com><meta name=description content=beneditutti.com><meta name=robots content=INDEX, FOLLOW><meta name=revisit-after content=10><meta http-equiv=Content-Type content=text/htmlcharset=iso-8859-1>" []
"</h"="c:\WINDOWS\System32\</html>" []
"<frame src=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCA"="c:\WINDOWS\System32\<frame src=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>" []
"</frame"="c:\WINDOWS\System32\</frameset>" []
"<nofra"="c:\WINDOWS\System32\<noframes>" []
"<a href=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>Click here to go to beneditutti.com<"="c:\WINDOWS\System32\<a href=http://searchportal.information.com?epl=00470015UVsPWVALXVUMVV8BXQsDVwhAE0MXXBkCDlgTWWddVVgCAlM>Click here to go to beneditutti.com</a>." []
"</nofra"="c:\WINDOWS\System32\</noframes>" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [8/29/2003 6:30:46 PM]
AOL Companion.lnk - C:\Program Files\AOL Companion\companion.exe [8/29/2003 6:32:17 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- Hosts -----------------------------------------------------------------------
127.0.0.1
www.f1organizer.com #removed adware url
127.0.0.1
www.netpalnow.com #removed adware url
127.0.0.1
www.addictivetechnologies.com #removed adware url
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
8871 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-08-08 06:59:58 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 1.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) 4 CPU 2.00GHz
Percentage of Memory in Use: 71%
Physical Memory (total/avail): 510.52 MiB / 143.63 MiB
Pagefile Memory (total/avail): 1247.19 MiB / 402.03 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1889.4 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 51.01 GiB total, 37.3 GiB free.
D: is Fixed (FAT32) - 4.87 GiB total, 0.75 GiB free.
E: is CDROM (CDFS)
F: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD600AB-22CBA1 - 55.9 GiB - 2 partitions
\PARTITION0 - Unknown - 4.88 GiB - D:
\PARTITION1 (bootable) - Installable File System - 51.01 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before install.
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Owner\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AEDWARDS
ComSpec=C:\WINDOWS\system32\cmd.exe
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Owner
LOGONSERVER=\\AEDWARDS
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program files\PC-Doctor for Windows XP\WINDSAPI
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 4, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0204
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
USERDOMAIN=AEDWARDS
USERNAME=Owner
USERPROFILE=C:\Documents and Settings\Owner
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Owner
(admin)
-- Add/Remove Programs ---------------------------------------------------------
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> c:\WINDOWS\System32\\MSIEXEC.EXE /x {09DA4F91-2A09-4232-AB8C-6BC740096DE3}
--> c:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
--> c:\WINDOWS\System32\\MSIEXEC.EXE /x {8214CC02-6271-4DC8-B8DD-779933450264}
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{33AE85D9-0386-41AD-BD99-FDF3ABC19DBB}\setup.exe" -l0x9 -L0x9anything
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{854A5F01-D692-11D4-A984-009027EC0A9C}\setup.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{945E2519-C2B9-11D3-9D56-0060B0A4823E}\setup.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CD47EFC1-D692-11D4-A984-009027EC0A9C}\setup.exe"
--> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E7E518B2-B174-11D3-9D4E-0060B0A4823E}\setup.exe"
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
America Online (Choose which version to remove) --> C:\Program Files\Common Files\aolshare\Aolunins_us.exe
AOL Coach Version 1.0(Build:20030807.3) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
ArcSoft ShowBiz --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Arcsoft\Showbiz\Uninst.isu"
ArcSoft Software Suite --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\Software Suite\Uninst.isu"
Atomic Pop --> "C:\Program Files\wildtangent\apps\gamechannel.exe" \removeitem {6E657D86-77B8-4D97-9E31-7D374469D3CB}
DelFin Media Viewer --> C:\WINDOWS\unvise32.exe C:\Program Files\DelFin\PromulGate\uninstal.log
Diamond Mine 1.5y --> C:\Program Files\PopCap Games\Diamond Mine\UnGins.exe "C:\Program Files\PopCap Games\Diamond Mine\install.log"
Easy Internet Sign-up --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2B5DDB2C-0807-47FD-9C11-80EA761902C0}\Setup.exe" -l0x9
Enhanced MediaLoads --> "C:\Program Files\MediaLoads Enhanced\install.exe" "C:\Program Files\MediaLoads Enhanced\ME2.DLL",Uninstall
Freedom Security && Privacy Suite --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{4ECBA0D5-A114-4EE3-B3F3-A8CFDE2A6A79}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
hp center --> C:\WINDOWS\BWUnin-6.1.0.153.exe -AppId 137903
hp deskjet 3820 series (Remove only) --> C:\Program Files\hp deskjet 3820 series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=USB001 -vproduct=3820 -huninstall
HP DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
hp instant support --> C:\PROGRA~1\HEWLET~1\hpis\Uninstall.exe CeS
hp learning adventure --> c:\program files\HPSelect\Frontend\uninstall.exe
HP Memories Disc --> MsiExec.exe /X{103B9452-AAF9-4E8E-AE4F-DD44411B886F}
HP Photo Printing Software --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Printing\Uninstall.isu" -c"C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Printing\hpiunPC.dll
HP RecordNow --> MsiExec.exe /I{8214CC02-6271-4DC8-B8DD-779933450264}
IMBUM --> regsvr32 /s /u C:\WINDOWS\System32\Im6um.dll
Inactive HP Printer Drivers (Remove only) --> RunDll32 hpuninst.dll,InstallHinfSection UninstDefault 132 prntunin.inf
InetDctr --> C:\WINDOWS\System32\uninstidctr.exe
Intel(R) 845G Chipset Graphics Driver Software --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
KBD --> C:\HP\KBD\KBD.EXE uninstalled
Lernout & Hauspie TruVoice American English TTS Engine --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tv_enua.inf, Uninstall
LiveUpdate 3.3 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
Living Marine Aquarium Screen Saver --> C:\PROGRA~1\SCREEN~2.COM\LIVING~1\UNINSTAL.EXE /U C:\PROGRA~1\SCREEN~2.COM\LIVING~1\INSTALL.LOG
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MarketBrowser --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{35845E72-E34A-11D4-817D-005004D0F1FA}\Setup.exe" -uninst
MediaLoads --> "C:\Program Files\MediaLoads\v1\ml.exe" /R
Microsoft Money 2002 --> MsiExec.exe /I{E7298FD5-1386-11D5-8D6C-0050DAD32D95}
Microsoft Money 2002 System Pack --> MsiExec.exe /I{CF5193F7-6B37-11D5-B7D2-00AA00A204F1}
Microsoft Works 6.0 --> MsiExec.exe /I{A1B7B9B3-E1D2-41CA-9B4A-F18DC2710704}
Microsoft Works and Money 2002 Setup Launcher --> C:\Program Files\Microsoft Works and Money 2002\Setup\Launcher.exe \hp\tmp\src\
MUSICMATCH Jukebox --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Uninst.isu" -cC:\PROGRA~1\MUSICM~1\MUSICM~1\unmatch.dll
NVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nvhp.inf
PC-Doctor for Windows --> C:\WINDOWS\UNWISE.EXE C:\PROGRA~1\PC-DOC~1\INSTALL.LOG
Python 1.5 combined Win32 extensions --> C:\PROGRA~1\Python\UNWISE~1.EXE C:\PROGRA~1\Python\W32INST.LOG
Python 1.5.2 (final) --> C:\PROGRA~1\Python\UNWISE.EXE C:\PROGRA~1\Python\INSTALL.LOG
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
RingMaster from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\8c9c48d7-2d03-4a1f-a303-5bd22ccabae1\Uninstall.exe"
Snood for Windows version 3.01-W --> "C:\Program Files\Snood\unins000.exe"
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Speedway --> "C:\Program Files\wildtangent\apps\gamechannel.exe" \removeitem {D6CAB2F4-26A4-48F4-A35D-CA83063E3928}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Symantec Endpoint Protection --> MsiExec.exe /I{76B2BC31-2D96-4170-9C44-09E13B5555F3}
Tcl 8.0.5 for Windows --> C:\PROGRA~1\Tcl\UNWISE.EXE C:\PROGRA~1\Tcl\INSTALL.LOG
VERITAS StorageGuard --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
WildArcade --> C:\Program Files\WildArcade\BlasterBlocks\uninst.exe
Winamp3 (remove only) --> C:\Program Files\Winamp3\uninst-wa3.EXE
WordPerfect Office 2002 Try Before You Buy --> C:\WINDOWS\Corel\uninst32.exe
WordPerfect Office 2002 Try Before You Buy --> MsiExec.exe /I{29D88826-2AB9-11D5-8854-00902761A46D}
-- Application Event Log -------------------------------------------------------
Event Record #/Type2822 / Error
Event Submitted/Written: 08/07/2008 07:59:08 PM
Event ID/Source: 51 / Symantec AntiVirus
Event Description:
Security Risk Found!Downloader.MSCache in File: C:\Documents and Settings\Owner\Local Settings\Temp\DWHB674.tmp by: Auto-Protect scan. Action: Quarantine succeeded : Access denied. Action Description: The file was quarantined successfully.
Event Record #/Type2821 / Error
Event Submitted/Written: 08/07/2008 07:59:05 PM
Event ID/Source: 46 / Symantec AntiVirus
Event Description:
Security Risk Found!Downloader.MSCache in File: C:\Documents and Settings\Owner\Local Settings\Temp\DWHB674.tmp by: Auto-Protect scan. Action: Quarantine succeeded. Action Description: The file was quarantined successfully.
Event Record #/Type2820 / Error
Event Submitted/Written: 08/07/2008 07:58:58 PM
Event ID/Source: 51 / Symantec AntiVirus
Event Description:
Security Risk Found!Downloader.Trojan in File: C:\Documents and Settings\Owner\Local Settings\Temp\DWH11C3.tmp by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: The file was deleted successfully.
Event Record #/Type2819 / Error
Event Submitted/Written: 08/07/2008 07:58:50 PM
Event ID/Source: 46 / Symantec AntiVirus
Event Description:
Security Risk Found!Downloader.Trojan in File: C:\Documents and Settings\Owner\Local Settings\Temp\DWH11C3.tmp by: Auto-Protect scan. Action: Cleaned by Deletion. Action Description: The file was deleted successfully.
Event Record #/Type2807 / Error
Event Submitted/Written: 08/06/2008 07:32:29 PM
Event ID/Source: 13 / SescLU
Event Description:
LiveUpdate returned a non-critical error. Available content updates may have failed to install.
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type14523 / Error
Event Submitted/Written: 08/07/2008 08:32:49 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The IPSEC Services service terminated with the following error:
%%10045
Event Record #/Type14507 / Error
Event Submitted/Written: 08/07/2008 07:44:45 PM
Event ID/Source: 7003 / Service Control Manager
Event Description:
The SRTSP service depends on the following nonexistent service: FltMgr
Event Record #/Type14506 / Error
Event Submitted/Written: 08/07/2008 07:44:45 PM
Event ID/Source: 7003 / Service Control Manager
Event Description:
The SRTSP service depends on the following nonexistent service: FltMgr
Event Record #/Type14504 / Error
Event Submitted/Written: 08/07/2008 07:44:45 PM
Event ID/Source: 7003 / Service Control Manager
Event Description:
The SRTSP service depends on the following nonexistent service: FltMgr
Event Record #/Type14485 / Error
Event Submitted/Written: 08/06/2008 10:11:45 PM
Event ID/Source: 7003 / Service Control Manager
Event Description:
The SRTSP service depends on the following nonexistent service: FltMgr
-- End of Deckard's System Scanner: finished at 2008-08-08 06:59:58 ------------