Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93105 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Very Slow Logon And Logout


  • Please log in to reply
1 reply to this topic

#1 SpyComm

SpyComm

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 04 April 2007 - 11:24 AM

Hello guys,

My PC is really slow at log-on and log-off. Sometimes also many applications are slow.
Here is my log for your review, using Deckard's System Scanner + HijackThis
Thank you in advance for your time and support.
Maurizio

==========================================================

Deckard's System Scanner v20070318.32
Run by Maurizio Pedrini on 2007-04-04 at 20:25:21
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Maurizio Pedrini.exe) ------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 20:25:22, on 04/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Rollback\RollbackClnt.exe
C:\Program Files\Rollback\shdserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Pinnacle\PCTV USB2\Remote\Remoterm.exe
C:\Program Files\Rollback\RollbackTray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\nMtsk.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\USB Phone\U.S.RoboticsUSBPhone.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\eFax Messenger 4.2\J2GTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\SnagIt\SnagIt32.exe
C:\Program Files\SyncBack\SyncBack.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\SnagIt\TSCHelp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Pinnacle\Shared Files\Filter\server.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\Common Files\Logitech\WebColct\webcolct.exe
C:\Documents and Settings\Maurizio Pedrini\Desktop\dss.exe
C:\DOCUME~1\MAURIZ~1\Desktop\MAURIZ~1.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\SnagIt\SnagItBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\SnagIt\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [PD0870 STISvc] RunDLL32.exe P0870Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCTVUSB2Remote] C:\Program Files\Pinnacle\PCTV USB2\Remote\Remoterm.exe
O4 - HKLM\..\Run: [Rollback] "C:\Program Files\Rollback\RollbackTray.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [nMTaskBarService] nMtsk.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [U.S. Robotics USB Phone] C:\Program Files\USB Phone\U.S.RoboticsUSBPhone.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: SnagIt 8.lnk = C:\Program Files\SnagIt\SnagIt32.exe
O4 - Startup: SyncBack.lnk = C:\Program Files\SyncBack\SyncBack.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: eFax 4.2.lnk = C:\Program Files\eFax Messenger 4.2\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Internet Security 6.0\ie_banner_deny.htm
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1161284256921
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe (file missing)
O23 - Service: nMtskBar Service (nMtskService) - Intracom S.A. - C:\WINDOWS\nMtsk.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RollbackClientService - Unknown owner - C:\Program Files\Rollback\RollbackClnt.exe
O23 - Service: SHDSERV - Horizon Datasys, Inc. - C:\Program Files\Rollback\shdserv.exe


-- Files created between 2007-03-04 and 2007-04-04 -----------------------------

2007-04-04 18:42:17 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Help
2007-04-02 14:09:39 0 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield<INSTAL~1>
2007-04-02 14:03:39 150016 --a------ C:\WINDOWS\system32\libxslt.dll
2007-04-02 14:03:39 721920 --a------ C:\WINDOWS\system32\libxml2.dll
2007-04-02 14:03:39 51200 --a------ C:\WINDOWS\system32\libexslt.dll
2007-04-02 14:03:39 878080 --a------ C:\WINDOWS\system32\iconv.dll
2007-04-02 14:02:18 57344 -ra------ C:\WINDOWS\system32\libsyslic1.dll<LIBSYS~2.DLL>
2007-04-01 19:21:14 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Shared
2007-04-01 19:21:07 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Incomplete<INCOMP~1>
2007-04-01 15:41:40 0 d-------- C:\WINDOWS\Logo Design Studio<LOGODE~1>
2007-04-01 15:41:40 0 d-------- C:\Program Files\Logo Design Studio<LOGODE~1>
2007-03-31 19:12:38 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Itsth
2007-03-30 13:26:28 0 d-------- C:\WINDOWS\system32\DRM
2007-03-29 14:26:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage<OFFICE~1>
2007-03-27 21:36:25 737280 --a------ C:\WINDOWS\iun6002.exe
2007-03-27 14:28:11 32592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-03-27 14:25:53 0 d-------- C:\Program Files\Microsoft Works<MIF2B0~1>
2007-03-27 14:25:36 0 d-------- C:\Program Files\MSBuild
2007-03-27 14:17:04 0 d-------- C:\Program Files\Microsoft Visual Studio 8<MICROS~4>
2007-03-27 14:15:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help<MICROS~2>
2007-03-27 14:12:34 0 dr-h----- C:\MSOCache
2007-03-27 13:57:44 0 d-------- C:\Program Files\PowerISO
2007-03-26 23:04:07 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\uTorrent
2007-03-26 23:04:05 0 d-------- C:\Program Files\uTorrent
2007-03-26 21:29:08 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Zeon
2007-03-26 21:29:05 0 d--h----- C:\WINDOWS\system32\GroupPolicy<GROUPP~1>
2007-03-26 21:29:03 322 --a------ C:\WINDOWS\dorp.dat
2007-03-26 21:28:36 0 d-------- C:\Program Files\Nitro PDF<NITROP~1>
2007-03-26 21:27:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Zeon
2007-03-24 18:52:32 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\WinRAR
2007-03-23 20:31:14 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\COWON
2007-03-23 20:27:17 0 d-------- C:\Program Files\JetAudio
2007-03-18 13:17:56 420 --a------ C:\WINDOWS\system32\ucjzdfiv_navps.dat<UCJZDF~2.DAT>
2007-03-18 13:17:56 218653 --a------ C:\WINDOWS\system32\ucjzdfiv_nav.dat<UCJZDF~1.DAT>
2007-03-18 13:17:56 4584 --a------ C:\WINDOWS\system32\ucjzdfiv.dat
2007-03-16 12:00:17 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Screenshot Sender<SCREEN~1>
2007-03-12 12:54:26 2855 --a------ C:\WINDOWS\system32\mem.PIF
2007-03-11 19:24:58 74396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-03-11 19:24:58 75932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-03-11 19:24:16 0 d-------- C:\Program Files\Kaspersky Internet Security 6.0<KASPER~1.0>
2007-03-11 19:24:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab<KASPER~1>
2007-03-11 19:24:13 170528 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-03-11 19:24:13 7194912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-03-08 14:53:50 0 d-------- C:\Program Files\Common Files\Skype


-- Find3M Report ---------------------------------------------------------------

2007-04-04 20:25:15 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Free Download Manager<FREEDO~1>
2007-04-04 20:18:27 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Skype
2007-04-04 04:13:54 0 d-------- C:\Program Files\SyncBack
2007-04-03 18:42:23 0 d---s---- C:\Documents and Settings\Maurizio Pedrini\Application Data\Microsoft<MICROS~1>
2007-04-03 14:32:06 0 d--h----- C:\Program Files\InstallShield Installation Information<INSTAL~1>
2007-04-02 15:59:04 0 d-------- C:\Program Files\Google
2007-04-02 15:45:10 0 d-------- C:\Program Files\Mozilla Thunderbird<MOZILL~2>
2007-04-02 14:04:44 0 d-------- C:\Program Files\Common Files\InstallShield<INSTAL~1>
2007-03-29 16:17:05 0 d-------- C:\Program Files\PeekShowsX<PEEKSH~1>
2007-03-29 15:38:49 0 d-------- C:\Program Files\Common Files\ODBC
2007-03-29 14:17:45 74 --a------ C:\Documents and Settings\Maurizio Pedrini\Application Data\fspro2_1.tmp
2007-03-29 14:02:44 6234 --a------ C:\Documents and Settings\Maurizio Pedrini\Application Data\fspro2_0.tmp
2007-03-29 12:32:46 0 d-------- C:\Documents and Settings\Maurizio Pedrini\Application Data\Mozilla
2007-03-28 15:52:40 0 d-------- C:\Program Files\MSN Messenger<MSNMES~1>
2007-03-27 13:01:33 0 d-------- C:\Program Files\VoipDiscount<VOIPDI~1>
2007-03-26 22:10:33 0 d-------- C:\Program Files\Maxtor
2007-03-26 20:38:17 0 --a------ C:\WINDOWS\system32\eFax_4_2_Port<EFAX_4~1>
2007-03-24 19:26:59 0 d-------- C:\Program Files\eyeBeam 1.5<EYEBEA~1.5>
2007-03-08 18:36:28 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 18:36:28 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 18:36:28 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 16:47:48 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-08 14:53:50 0 d-------- C:\Program Files\Skype
2007-02-17 17:33:15 0 d-------- C:\Program Files\Logitech
2007-02-13 14:16:24 0 d-------- C:\Program Files\Java
2007-02-11 18:34:14 0 d-------- C:\Program Files\Free Download Manager<FREEDO~1>
2007-02-08 15:43:11 0 d-------- C:\Program Files\Intuwave Ltd<INTUWA~1>
2007-01-30 00:04:00 200768 --a------ C:\WINDOWS\system32\klogon.dll
2007-01-19 13:53:04 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01:14 17408 --a------ C:\WINDOWS\system32\corpol.dll


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Creative MediaSource Go"="\"C:\\Program Files\\Creative\\MediaSource\\Go\\CTCMSGo.exe\" /SCB"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"U.S. Robotics USB Phone"="C:\\Program Files\\USB Phone\\U.S.RoboticsUSBPhone.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"Free Download Manager"="C:\\Program Files\\Free Download Manager\\fdm.exe -autorun"
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"CTDVDDET"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDET.EXE\""
"SBDrvDet"="C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"CTHelper"="CTHELPER.EXE"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe /r"
"eFax 4.2"="\"C:\\Program Files\\eFax Messenger 4.2\\J2GDllCmd.exe\" /R"
"PD0870 STISvc"="RunDLL32.exe P0870Pin.dll,RunDLL32EP 513"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"MaxtorOneTouch"="C:\\Program Files\\Maxtor\\OneTouch\\utils\\Onetouch.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"PCTVUSB2Remote"="C:\\Program Files\\Pinnacle\\PCTV USB2\\Remote\\Remoterm.exe"
"Rollback"="\"C:\\Program Files\\Rollback\\RollbackTray.exe\""
"CTxfiHlp"="CTXFIHLP.EXE"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"nMTaskBarService"="nMtsk.exe"
"googletalk"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe /autostart"
"AVP"="\"C:\\Program Files\\Kaspersky Internet Security 6.0\\avp.exe\""
"PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"LTMSG"="LTMSG.exe 7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\KASPER~1.0\adialhk.dll"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=hex:00,00,00,00
"GreyMSIAds"=dword:00000001

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0

HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
UxTuneUp


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{894e4cdd-5f95-11db-b51b-806d6172696f}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL index.html

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{894e4cde-5f95-11db-b51b-806d6172696f}]
Shell\AutoRun\command J:\SETUP.EXE /UPDATE


-- End of Deckard's System Scanner: finished at 2007-04-04 at 20:26:59 ---------

Edited by SpyComm, 04 April 2007 - 11:31 AM.

    Advertisements

Register to Remove


#2 shelf life

shelf life

    SuperMember

  • Visiting Fellow
  • PipPipPipPipPip
  • 3,191 posts

Posted 11 April 2007 - 05:05 PM

hi SpyComm, at first glance i dont see any malware in the log. do you have a antimalware application on your computer? you also seem to have a load of apps that start at bootup. we can probably get rid of some. you can start them when needed form the start>programs menu. shelf life EDIT: this has a antispyware component? Kaspersky Internet Security 6.0
How Can I Reduce My Risk?

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users