Deckard's System Scanner v20070905.67
Run by Administrator on 2007-10-02 13:55:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
14: 2007-10-02 17:55:59 UTC - RP14 - Deckard's System Scanner Restore Point
13: 2007-10-02 09:00:51 UTC - RP13 - Software Distribution Service 2.0
12: 2007-10-01 09:00:47 UTC - RP12 - Software Distribution Service 2.0
11: 2007-09-30 09:02:14 UTC - RP11 - Software Distribution Service 2.0
10: 2007-09-29 09:01:14 UTC - RP10 - Software Distribution Service 2.0
-- First Restore Point --
1: 2007-09-20 17:19:37 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Administrator.exe) ---------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-10-02 13:57:36
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\HP Software Update\hpwuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\hpzipm12.exe
C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Desktop\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://ie.search.msn...st/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://ie.search.msn...st/srchasst.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsof...search.asp?p=%s
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer,Search = http://ie.search.msn...st/srchasst.htm
R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O2 - BHO: (no name) - {1E93F526-BA7A-4FE1-AAB4-DE5F642EA538} - C:\WINDOWS\system32\jkklj.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O4 - HKEY_LOCAL_MACHINE\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [POINTER] point32.exe
O4 - HKEY_LOCAL_MACHINE\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKEY_LOCAL_MACHINE\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKEY_LOCAL_MACHINE\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKEY_LOCAL_MACHINE\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKEY_LOCAL_MACHINE\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKEY_LOCAL_MACHINE\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKEY_LOCAL_MACHINE\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\aqavbpqu.dll",sitypnow
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet.exe (file missing)
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra 'Tools' menuitem: (no name) - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://online.musicmatch.com (HKEY_LOCAL_MACHINE)
O16 - DPF: Yahoo! Checkers () - http://download2.gam...nts/y/kt4_x.cab
O16 - DPF: Yahoo! Pool 2 () - http://download.game...ts/y/pote_x.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.ma...director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} () - http://www.driveclea...leanerstart.cab
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://download.micr...D0C/wmv9dmo.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} () - http://appldnld.appl...meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} () - http://download.mcaf...99/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1125028123703
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125028184375
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (Download Helper Class) - http://activex.micro...n7/dlhelper.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} () - http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe /ServiceStart
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - "C:\Program Files\Viewpoint\Common\ViewpointService.exe"
O23 - Service: WMP54GSSVC - GEMTEKS - "C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe" "WMP54GSv1_1.exe"
-- HijackThis Fixed Entries (C:\DOCUME~1\ADMINI~1.GRI\Desktop\backups\) --------
backup-20070914-123319-599 O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.4\webbuying.exe
backup-20070914-134553-890 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
backup-20070914-135242-824 O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
backup-20070915-104611-818 O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalci....1.11_en_dl.cab
backup-20070915-120537-840 O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
backup-20070915-121059-190 O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
backup-20070917-123739-542 O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\lsimsscy.dll",forkonce
backup-20070917-174325-529 O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6145\SiteAdv.exe
backup-20070917-174536-110 O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6145\SAService.exe
backup-20070917-182334-537 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
backup-20070917-184810-609 O2 - BHO: (no name) - {391DB133-9FDF-4D12-8E5B-AF073CAAA01E} - C:\Program Files\ComPlus Applications\hoqezilox83122.dll
backup-20070917-184810-742 O2 - BHO: (no name) - {C29CEC8A-502F-4E7E-90B2-AEBA280A4A29} - C:\WINDOWS\system32\jkklj.dll
backup-20070917-184810-776 O2 - BHO: (no name) - {40A5150E-2518-405C-847C-EE7DDBC1CB9B} - C:\Program Files\ComPlus Applications\hoqezilox4444.dll
backup-20070917-184810-856 O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\avepuiax.dll
backup-20070917-184813-563 O2 - BHO: (no name) - {D2C5A912-37A6-4F7C-ACAA-621336AF31C2} - C:\WINDOWS\System32\yhh.dll (file missing)
backup-20070918-011108-209 O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\cirsdsug.dll",forkonce
backup-20070918-111604-544 O2 - BHO: (no name) - {C29CEC8A-502F-4E7E-90B2-AEBA280A4A29} - C:\WINDOWS\system32\jkklj.dll
backup-20070918-111604-816 O2 - BHO: (no name) - {8291AB12-31A1-1F72-F1AA-621336AF31C3} - C:\WINDOWS\System32\tkb.dll (file missing)
backup-20070918-111631-141 O2 - BHO: (no name) - {C29CEC8A-502F-4E7E-90B2-AEBA280A4A29} - C:\WINDOWS\system32\jkklj.dll
backup-20070918-111704-300 O2 - BHO: (no name) - {C29CEC8A-502F-4E7E-90B2-AEBA280A4A29} - C:\WINDOWS\system32\jkklj.dll
backup-20070918-142515-518 O2 - BHO: (no name) - {B6C6AADF-15AF-4B50-A32B-78B2E975E089} - C:\WINDOWS\system32\jkklj.dll
backup-20070920-184738-141 O2 - BHO: (no name) - {F7E6FE4D-71AD-4268-95C9-26094E5DE6C9} - C:\WINDOWS\system32\jkklj.dll
backup-20070920-184748-523 O2 - BHO: (no name) - {F7E6FE4D-71AD-4268-95C9-26094E5DE6C9} - C:\WINDOWS\system32\jkklj.dll
backup-20070920-185845-717 O2 - BHO: (no name) - {4F4E2653-7B3A-4EE2-8986-660DCE307319} - C:\WINDOWS\system32\jkklj.dll
backup-20070920-191605-564 O2 - BHO: (no name) - {56C44384-239F-4A7B-85A7-1F4BAFFCE387} - C:\WINDOWS\system32\jkklj.dll
backup-20070920-191612-460 O2 - BHO: (no name) - {56C44384-239F-4A7B-85A7-1F4BAFFCE387} - C:\WINDOWS\system32\jkklj.dll
backup-20070921-092947-755 O2 - BHO: (no name) - {B85CF7EA-F7E3-4D25-8E98-BB5E73463ED5} - C:\WINDOWS\system32\jkklj.dll
backup-20070921-121238-853 O2 - BHO: (no name) - {B85CF7EA-F7E3-4D25-8E98-BB5E73463ED5} - C:\WINDOWS\system32\jkklj.dll
backup-20070923-102909-408 O2 - BHO: (no name) - {B85CF7EA-F7E3-4D25-8E98-BB5E73463ED5} - C:\WINDOWS\system32\jkklj.dll
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
R3 ialm - c:\windows\system32\drivers\ialmnt5.sys <Not Verified; Intel Corporation; Intel Graphics Accelerator Drivers for Windows NT®>
R3 SAMFILT - c:\windows\system32\drivers\samfilt.sys <Not Verified; Dolphin, Inc.; Dolphin Keyboard Filter>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
S2 McAfeeFramework (McAfee Framework Service) - c:\program files\network associates\common framework\frameworkservice.exe /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Linksys Wireless-G PCI Network Adapter with SpeedBooster
Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00421737&REV_02\4&1A671D0C&0&28F0
Manufacturer: Linksys
Name: Linksys Wireless-G PCI Network Adapter with SpeedBooster
PNP Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_00421737&REV_02\4&1A671D0C&0&28F0
Service: BCM43XX
-- Scheduled Tasks -------------------------------------------------------------
2007-10-02 10:48:58 754 --a------ C:\WINDOWS\Tasks\wrSpySweeper20060913113143.job
2007-10-01 01:01:13 368 --a------ C:\WINDOWS\Tasks\McQcTask.job
2007-09-17 16:03:03 366 --a------ C:\WINDOWS\Tasks\McDefragTask.job
-- Files created between 2007-09-02 and 2007-10-02 -----------------------------
2007-10-02 13:57:52 77376 --a------ C:\WINDOWS\system32\vtsnsjjq.dll
2007-10-02 13:30:05 3010 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-02 13:29:41 0 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-02 13:29:41 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2007-10-02 13:29:41 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2007-10-02 13:29:41 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2007-10-02 13:29:41 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-02 13:09:14 0 d-------- C:\WINDOWS\ERUNT
2007-10-01 19:40:01 87104 --a------ C:\WINDOWS\system32\aqavbpqu.dll
2007-10-01 14:01:00 87104 --a------ C:\WINDOWS\system32\jxrrbpjs.dll
2007-09-30 23:30:36 85056 --a------ C:\WINDOWS\system32\sxbdlpyq.dll
2007-09-30 22:02:32 85056 --a------ C:\WINDOWS\system32\tdkvhmcv.dll
2007-09-30 21:34:21 85056 --a------ C:\WINDOWS\system32\ecukuekj.dll
2007-09-30 19:29:10 85056 --a------ C:\WINDOWS\system32\yafauewj.dll
2007-09-30 16:08:38 85056 --a------ C:\WINDOWS\system32\aubuwrxh.dll
2007-09-30 13:03:00 85056 --a------ C:\WINDOWS\system32\jotwiogr.dll
2007-09-29 07:10:57 1531103 ---hs---- C:\WINDOWS\system32\jlkkj.ini2
2007-09-28 07:28:45 85056 --a------ C:\WINDOWS\system32\bdrecrtw.dll
2007-09-25 10:47:18 425480 --a------ C:\syssqtu.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-25 02:16:56 84032 --a------ C:\WINDOWS\system32\phbujudp.dll
2007-09-24 19:42:12 0 d-------- C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Application Data\U3
2007-09-21 14:00:36 425480 --a------ C:\sysnwlk.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-21 14:00:30 425480 --a------ C:\sysnftf.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-20 18:50:49 0 d-------- C:\VundoFix Backups
2007-09-20 15:55:01 425480 --a------ C:\syscvhu.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-20 15:54:57 425480 --a------ C:\syscoso.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-20 04:58:53 425480 --a------ C:\sysytms.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-20 04:58:48 425480 --a------ C:\sysamwn.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-20 04:58:38 425480 --a------ C:\sysoqsv.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-19 18:52:00 425480 --a------ C:\syslnwx.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-19 13:42:55 425480 --a------ C:\sysdeyo.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-19 08:32:17 425480 --a------ C:\syspifl.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-19 08:32:13 425480 --a------ C:\sysfaqw.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-19 00:58:08 0 d-------- C:\Program Files\RogueRemover FREE
2007-09-18 17:10:03 425480 --a------ C:\sysqfrb.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-18 12:17:27 425480 --a------ C:\syswnlm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-09-17 16:06:57 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\SiteAdvisor
2007-09-17 16:06:40 0 d-------- C:\Program Files\SiteAdvisor
2007-09-17 16:06:39 0 d-------- C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Application Data\SiteAdvisor
2007-09-17 16:02:15 0 d-------- C:\Program Files\McAfee.com
2007-09-17 16:02:02 0 d-------- C:\Program Files\Common Files\McAfee
2007-09-17 16:01:48 0 d-------- C:\Program Files\McAfee
2007-09-17 15:55:14 262144 --a------ C:\Documents and Settings\All Users.WINDOWS\NTUSER.DAT
2007-09-17 15:13:48 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Desktop
2007-09-17 15:13:35 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SiteAdvisor
2007-09-17 14:56:45 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2007-09-17 00:25:50 75328 --a------ C:\WINDOWS\system32\lwtjxqta.exe <Not Verified; ; DDC>
2007-09-15 00:24:13 1531458 ---hs---- C:\WINDOWS\system32\jlkkj.bak2
2007-09-14 12:41:11 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMonitor
2007-09-14 12:26:11 39936 --a------ C:\WINDOWS\wbun.exe
2007-09-14 12:23:58 1984101 ---hs---- C:\WINDOWS\system32\jlkkj.bak1
2007-09-14 12:23:34 244832 --a------ C:\WINDOWS\system32\jkklj.dll
2007-09-14 12:22:24 0 d-------- C:\Program Files\WinAble
2007-09-14 12:19:25 169147 --a------ C:\WINDOWS\TTC-4444.exe
2007-09-14 12:18:56 932 --a------ C:\WINDOWS\system32\winpfz32.sys
2007-09-14 12:18:44 0 d-------- C:\WINDOWS\system32\H2
2007-09-14 12:18:44 0 d-------- C:\WINDOWS\system32\GRB3
2007-09-14 12:18:44 0 d-------- C:\WINDOWS\system32\DLL2
2007-09-14 12:18:44 0 d-------- C:\WINDOWS\system32\A1
2007-09-14 12:18:29 0 d-------- C:\WINDOWS\system32\f02WtR
2007-09-14 12:18:29 0 d-------- C:\Temp
-- Find3M Report ---------------------------------------------------------------
2007-10-02 13:25:38 0 d-a------ C:\Program Files\Common Files
2007-10-01 19:37:01 0 d-------- C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Application Data\AdobeUM
2007-10-01 13:43:12 0 d-------- C:\Program Files\Steam
2007-09-18 22:45:38 0 d-------- C:\Program Files\Full Tilt Poker
2007-09-18 10:56:16 0 d-------- C:\Program Files\popupwithcast
2007-09-17 15:05:14 0 d-------- C:\Program Files\Common Files\Network Associates
2007-09-17 15:05:13 0 d-------- C:\Program Files\Network Associates
2007-09-15 10:52:22 0 d-------- C:\Program Files\PokerStars
2007-09-14 13:19:30 0 d-------- C:\Program Files\ewido anti-spyware 4.0
2007-08-17 13:45:31 0 d-------- C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Application Data\LimeWire
2007-08-16 20:09:20 0 d-------- C:\Program Files\Bodog Poker
2007-08-12 13:38:19 0 d-------- C:\Documents and Settings\Administrator.GRIFFIN-M7SLOIC\Application Data\Viewpoint
2007-08-10 14:52:03 0 d-------- C:\Program Files\Blaze Video Magic
2007-07-12 21:24:51 1420 --a------ C:\WINDOWS\unins000.dat
2007-07-12 21:24:32 668938 --a------ C:\WINDOWS\unins000.exe <Not Verified; ; Inno Setup>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E93F526-BA7A-4FE1-AAB4-DE5F642EA538}]
09/14/2007 12:23 PM 244832 --a------ C:\WINDOWS\system32\jkklj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89AD4D75-2429-462e-BD4E-443F233F6033}]
10/02/2007 01:57 PM 77376 --a------ C:\WINDOWS\system32\vtsnsjjq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [06/19/2002 07:05 PM]
"POINTER"="point32.exe" []
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [01/07/2004 01:01 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [08/04/2003 05:28 PM]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [12/22/2003 08:38 AM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [08/06/2004 03:50 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [11/03/2005 09:06 PM]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [01/19/2006 11:06 AM]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [07/22/2007 08:29 PM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [08/03/2007 11:33 PM]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [08/03/2005 01:47 AM]
"SearchIndexer"="C:\WINDOWS\system32\aqavbpqu.dll" [10/01/2007 07:40 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [08/18/2005 02:49 PM]
"Aim6"="" []
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/24/2005 2:05:26 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [9/16/2003 5:19:24 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/18/1999 12:05:56 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"=0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\system32\\jkklj
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b741cc22-6af7-11dc-a3b1-000874be7061}]
AutoRun\command- E:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2007-10-02 13:59:14 ------------