I'll post the two logs in separate posts, so to start with here is the main.txt file:
Deckard's System Scanner v20071014.68
Run by Patrick on 2008-04-14 14:44:57
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
5: 2008-04-14 18:45:08 UTC - RP321 - Deckard's System Scanner Restore Point
4: 2008-04-14 08:09:49 UTC - RP320 - System Checkpoint
3: 2008-04-13 08:00:34 UTC - RP319 - Software Distribution Service 3.0
2: 2008-04-13 02:45:26 UTC - RP318 - ComboFix created restore point
1: 2008-04-13 02:05:52 UTC - RP317 - Last known good configuration
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 7.8 GiB (less than 15%) free.
-- HijackThis (run as Patrick.exe) ---------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-14 14:46:40
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SYSTEM32\spoolsv.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Common Files\AOL\1102894033\EE\aolsoftware.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\SYSTEM32\rylslcnu.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Folding@Home\winFAH.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\Program Files\McAfee.com\VSO\McShield.exe
C:\Program Files\McAfee.com\Agent\McTskshd.exe
C:\WINDOWS\webshots.scr
C:\WINDOWS\SYSTEM32\nvsvc32.exe
C:\Program Files\Folding@Home\FahCore_81.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WLService.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WMP54GS.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\AOL\1102894033\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1102894033\EE\aolsoftware.exe
C:\WINDOWS\SYSTEM32\svchost.exe
C:\WINDOWS\SYSTEM32\wuauclt.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Documents and Settings\Patrick\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ebay.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft...amp;ar=iesearch
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\Program Files\McAfee.com\VSO\mcvsshl.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102894033\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOLAspSunset2] C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [itdetvcx] C:\WINDOWS\system32\rylslcnu.exe
O4 - HKCU\..\Run: [Btevzcro] "C:\Program Files\Common Files\?ssembly\t?skmgr.exe"
O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
O4 - Startup: Folding@Home 5.03.lnk = C:\Program Files\Folding@Home\winFAH.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - CmdMapping - (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
https://online.musicmatch.com (HKLM)
O16 - DPF: ActiveGS.cab () -
http://www.virtualap...om/activegs.cab
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} () -
http://download.micr...0367/wmavax.CAB
O16 - DPF: {01118400-3E00-11D2-8470-0060089874ED} (SdcNetCheckCtl Class) -
http://activex.micro...jects/ocget.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://fpdownload.ma...director/sw.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} () -
http://66.154.44.68/cam/Install.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () -
http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {450D402A-2E53-4A74-B4F3-3E42B126AE50} (NCPlusViewer Control) -
http://216.116.108.1...CPlusViewer.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by13fd.bay13....es/MsnPUpld.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -
http://www.webshots....SDownloader.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1146442096046
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://128.197.197.2...sCamControl.cab
O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) -
http://www.scubatoys...am/h263ctrl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.ma...ash/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) -
http://download.game...outLauncher.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{431378BB-15D0-4D3C-A222-4B7933735D6E}: NameServer = 192.168.1.1
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O20 - Winlogon Notify: efcCSjge - C:\WINDOWS\system32\efcCSjge.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\SYSTEM32\DRIVERS\dcfssvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\Mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - C:\Program Files\McAfee.com\VSO\McShield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\McTskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah DVD Burner\NMSAccess.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\SYSTEM32\nvsvc32.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G Wireless Network Monitor\WLService.exe
--
End of file - 13777 bytes
-- HijackThis Fixed Entries (C:\HIJACK~1\backups\) -----------------------------
backup-20070618-142255-195 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
backup-20070618-142255-423 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
backup-20070618-142255-474 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
backup-20070618-142256-189 O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\system32\krvxtvjj.dll (file missing)
backup-20070618-142256-366 O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
backup-20070618-142256-829 O4 - HKLM\..\Run: [szarkrmf.exe] C:\Documents and Settings\All Users\Application Data\szarkrmf.exe
-- File Associations -----------------------------------------------------------
.bat - batfile - shell\edit\command - C:\I386\NOTEPAD.EXE %1
.cmd - cmdfile - shell\edit\command - C:\I386\NOTEPAD.EXE %1
.inf - inffile - shell\open\command - C:\I386\NOTEPAD.EXE %1
.ini - inifile - shell\open\command - C:\I386\NOTEPAD.EXE %1
.js - JSFile - DefaultIcon - unable to read value
.js - JSFile - shell\open\command - unable to read value
.reg - regfile - shell\edit\command - C:\I386\NOTEPAD.EXE %1
.txt - txtfile - shell\open\command - notepad.exe %1
.vbs - VBSFile - shell\edit\command - C:\I386\NOTEPAD.EXE %1
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 agp440 (Intel AGP Bus Filter) - c:\windows\\systemroot\system32\drivers\agp440.sys (file missing)
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>
R2 Sentinel - c:\windows\system32\drivers\sentinel.sys <Not Verified; Rainbow Technologies, Inc.; Sentinel System Driver>
R3 aeaudio - c:\windows\system32\drivers\aeaudio.sys <Not Verified; Andrea Electronics Corporation; Andrea Audio Driver>
R3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys
R3 mohfilt - c:\windows\system32\drivers\mohfilt.sys <Not Verified; Intel Corporation; Intel® 537EP V9x DFV PCI Modem>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
R3 smwdm - c:\windows\system32\drivers\smwdm.sys <Not Verified; Analog Devices, Inc.; SoundMAX Digital Audio Driver>
S3 BVRPMPR5 (BVRPMPR5 NDIS Protocol Driver) - d:\instal~e\core\bvrpmpr5.sys (file missing)
S3 catchme - c:\docume~1\patrick\locals~1\temp\catchme.sys (file missing)
S3 iAimTV2 - c:\windows\system32\drivers\watv03nt.sys (file missing)
S3 MBAMCatchMe - c:\program files\malwarebytes' anti-malware\catchme.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S4 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
S4 Dcfssvc - c:\windows\system32\drivers\dcfssvc.exe <Not Verified; Eastman Kodak Company; Kodak DC File System Driver (Win32)>
S4 FirebirdGuardianDefaultInstance (Firebird Guardian - DefaultInstance) - c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s <Not Verified; The Firebird Project; Firebird SQL Server>
S4 FirebirdServerDefaultInstance (Firebird Server - DefaultInstance) - c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s <Not Verified; The Firebird Project; Firebird SQL Server>
S4 NMSAccess - c:\program files\cheetah burner\cheetah dvd burner\nmsaccess.exe
S4 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter
S4 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-04-12 15:48:01 440 --a------ C:\WINDOWS\Tasks\EasyShare Registration Task.job
2008-04-11 17:10:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-03-14 and 2008-04-14 -----------------------------
2008-04-13 01:48:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-13 01:48:31 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-12 21:57:31 0 d-------- C:\Program Files\Inet_Get_2
2008-04-12 21:56:36 3648 --a------ C:\WINDOWS\system32\jfyitfhv.dll
2008-04-12 21:50:20 0 d-------- C:\Program Files\Bat
2008-04-12 21:48:06 14848 --a------ C:\jkLv.exe
2008-04-12 21:38:37 0 d-------- C:\Program Files\Alwil Software
2008-04-12 20:53:04 0 d-------- C:\Documents and Settings\All Users\Application Data\nmtqnqvk
2008-04-12 20:53:03 98304 --a------ C:\WINDOWS\system32\rylslcnu.exe
2008-04-12 20:52:50 0 d-------- C:\WINDOWS\cuawsppw
2008-04-12 20:52:50 70144 --a------ C:\Documents and Settings\All Users\Application Data\ufinqxgt.dll
2008-04-12 20:52:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-04-12 20:52:45 196096 --a------ C:\WINDOWS\qrexkxwz.dll
2008-04-12 20:51:40 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-04-12 20:51:30 38400 --a------ C:\WINDOWS\mrofinu72.exe
2008-04-12 20:50:44 14848 --a------ C:\nwlu.exe
2008-04-12 04:42:14 17801 --a------ C:\WINDOWS\system32\drivers\AegisP.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
2008-04-12 04:41:54 0 d-------- C:\Program Files\Linksys Wireless-G Wireless Network Monitor
2008-04-12 01:46:18 1396831 --a------ C:\WINDOWS\system32\AegisE5.dll <Not Verified; Meetinghouse Data Communications; AEGIS Client API>
2008-04-12 01:46:16 147456 --a------ C:\WINDOWS\system32\ssleay32.dll
2008-04-12 01:46:16 651264 --a------ C:\WINDOWS\system32\libeay32.dll
2008-04-12 01:46:09 0 d-------- C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster
2008-04-11 15:34:39 0 d-------- C:\erunt2
2008-04-11 10:48:26 11264 --a------ C:\WINDOWS\b138.exe
2008-04-08 19:33:56 68096 --a------ C:\WINDOWS\b155.exe
2008-04-08 17:16:15 0 d-------- C:\combofix log
2008-04-08 16:45:28 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-08 16:45:27 68096 --a------ C:\WINDOWS\zip.exe
2008-04-08 16:45:27 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-08 16:45:27 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-08 16:45:27 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-08 16:45:27 98816 --a------ C:\WINDOWS\sed.exe
2008-04-08 16:45:27 80412 --a------ C:\WINDOWS\grep.exe
2008-04-08 16:45:27 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-08 15:44:04 0 d-------- C:\WINDOWS\ERUNT
2008-04-06 22:39:42 0 d-------- C:\Documents and Settings\Patrick\Application Data\Malwarebytes
2008-04-06 22:39:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-06 22:30:35 0 d-------- C:\erunt
2008-04-06 22:09:08 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-04-06 22:09:08 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-04-06 22:09:08 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-04-06 22:09:08 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-04-06 19:52:29 77824 --a------ C:\TaskManagerFix.exe <Not Verified; Task Manager Fix; TaskManagerFix>
2008-04-06 18:42:36 0 d--h----- C:\WINDOWS\PIF
2008-04-06 02:02:04 691545 --a------ C:\WINDOWS\unins000.exe
2008-04-06 02:02:04 2542 --a------ C:\WINDOWS\unins000.dat
2008-04-05 16:26:25 12800 --a------ C:\WINDOWS\system\wing32.dll <Not Verified; Microsoft Corporation; WinG>
2008-04-05 16:24:36 12800 --a------ C:\WINDOWS\system32\wing32.dll <Not Verified; Microsoft Corporation; WinG>
2008-04-04 23:57:11 295 --a------ C:\WINDOWS\EReg077.dat
2008-04-04 23:57:00 0 d-------- C:\Program Files\The Learning Company
-- Find3M Report ---------------------------------------------------------------
2008-04-14 00:09:01 54027 --a------ C:\logfile
2008-04-13 23:28:11 0 d-------- C:\Program Files\mIRC
2008-04-13 02:32:33 0 d-------- C:\Program Files\Soulseek-Test
2008-04-12 23:58:51 0 d-------- C:\Program Files\Infws nt
2008-04-12 22:02:05 0 d-------- C:\Program Files\Common Files
2008-04-12 15:43:27 0 d-------- C:\Program Files\Folding@Home
2008-04-12 04:42:01 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-06 18:20:35 0 d-------- C:\Program Files\Java
2008-03-26 02:34:23 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-05 03:48:16 0 d-------- C:\Program Files\AIM6
2008-02-23 23:50:24 0 d-------- C:\Program Files\LucasArts
2008-02-20 01:30:04 0 d-------- C:\Program Files\Zeallsoft
2008-02-19 21:47:06 0 d-------- C:\Program Files\Flash Video Recorder
2008-02-19 21:46:48 1795119 --a------ C:\FlashVideoRecorder.exe <Not Verified; Flash Video Recorder; FVR>
2008-02-19 18:48:55 0 d-------- C:\Program Files\America Online 9.0a
2008-01-28 02:07:52 41472 --ah----- C:\Documents and Settings\Patrick\Application Data\RBShell400.dll
2008-01-28 02:07:52 75776 --ah----- C:\Documents and Settings\Patrick\Application Data\rbqt450.DLL
2008-01-28 02:07:52 64512 --ah----- C:\Documents and Settings\Patrick\Application Data\rbap450.dll
2008-01-28 02:07:51 26112 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSResStreamPlugin3552.dll
2008-01-28 02:07:51 27648 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSRegistrationPlugin3542.dll
2008-01-28 02:07:51 29184 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSRectPlugin3542.dll
2008-01-28 02:07:51 32768 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSProcessPlugin3543.dll
2008-01-28 02:07:51 65024 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSPicturePlugin3542.dll
2008-01-28 02:07:51 37888 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSPictureMacPlugin3552.dll
2008-01-28 02:07:51 33792 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSIconPlugin3542.dll
2008-01-28 02:07:51 34304 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSEncryptPlugin3543.dll
2008-01-28 02:07:51 52224 --ah----- C:\Documents and Settings\Patrick\Application Data\EHZComp.dll
2008-01-28 02:07:51 19968 --ah----- C:\Documents and Settings\Patrick\Application Data\EHMD5.dll
2008-01-28 02:07:51 18432 --ah----- C:\Documents and Settings\Patrick\Application Data\EHEncrypt.dll
2008-01-28 02:07:50 25600 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSVersionPlugin3581.dll
2008-01-28 02:07:50 27136 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSUsernamePlugin3541.dll
2008-01-28 02:07:50 48640 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSResPlugin3542.dll
2008-01-28 02:07:50 55808 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSQuickTimePlugin3549.dll
2008-01-28 02:07:50 30720 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSMemoryPlugin3542.dll
2008-01-28 02:07:50 44032 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSMainPlugin3542.dll
2008-01-28 02:07:50 29696 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSMacOSXPlugin3545.dll
2008-01-28 02:07:50 36352 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSFolderitemsPlugin3542.dll
2008-01-28 02:07:50 36352 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSFolderitemsCreatePlugin3542.dll
2008-01-28 02:07:49 53760 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSWinPlugin3544.dll
2008-01-28 02:07:49 42496 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSRegistryPlugin3544.dll
2008-01-28 02:07:49 61440 --ah----- C:\Documents and Settings\Patrick\Application Data\MBSQTImporterPlugin3549.dll
2008-01-28 01:16:03 15612734 --a------ C:\WINDOWS\Endless Ocean Saver.SCR
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63F7460B-C831-4142-A4AA-5EC303EC4343}]
03/07/2008 10:15 PM 413696 --a------ C:\Program Files\Bat\Bat.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [09/03/2003 09:12 PM]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [08/26/2003 08:47 PM]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [07/08/2005 07:18 PM]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [09/22/2005 07:29 PM]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [01/11/2006 01:05 PM]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [08/10/2005 01:49 PM]
"nwiz"="nwiz.exe" [12/05/2007 02:41 AM C:\WINDOWS\SYSTEM32\nwiz.exe]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 02:01 AM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [01/19/2006 12:06 PM]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [08/11/2005 11:02 PM]
"HostManager"="C:\Program Files\Common Files\AOL\1102894033\ee\AOLSoftware.exe" [09/25/2006 08:52 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06/29/2007 07:24 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [07/10/2007 10:18 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/23/2007 03:33 PM]
"AOLAspSunset2"="C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 02:41 AM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [03/29/2008 02:37 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 12:24 PM]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 12:09 PM]
"Aim6"="" []
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [11/15/2007 10:23 AM]
"itdetvcx"="C:\WINDOWS\system32\rylslcnu.exe" [04/12/2008 08:53 PM]
"Btevzcro"="C:\Program Files\Common Files\?ssembly\t?skmgr.exe" []
C:\Documents and Settings\Patrick\Start Menu\Programs\Startup\
Bat - Auto Update.lnk - C:\Program Files\Bat\Bat.exe [4/12/2008 9:49:40 PM]
DESKTOP.INI [9/3/2002 10:00:00 AM]
Folding@Home 5.03.lnk - C:\Program Files\Folding@Home\winFAH.exe [9/21/2007 9:46:31 PM]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [4/16/2004 5:17:53 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [9/28/2005 12:36:49 AM]
DESKTOP.INI [9/3/2002 10:00:00 AM]
Kodak EasyShare software.lnk - C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [9/19/2007 5:33:46 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcCSjge]
efcCSjge.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Patrick^Start Menu^Programs^Startup^Internet Explorer.lnk]
path=C:\Documents and Settings\Patrick\Start Menu\Programs\Startup\Internet Explorer.lnk
backup=C:\WINDOWS\pss\Internet Explorer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Patrick^Start Menu^Programs^Startup^Windows Media Player.lnk]
path=C:\Documents and Settings\Patrick\Start Menu\Programs\Startup\Windows Media Player.lnk
backup=C:\WINDOWS\pss\Windows Media Player.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1102894033\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow! Deluxe]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WANMiniportService"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"sprtsvc_dellsupportcenter"=2 (0x2)
"NMSAccess"=2 (0x2)
"mdhcp"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"FirebirdServerDefaultInstance"=3 (0x3)
"FirebirdGuardianDefaultInstance"=2 (0x2)
"DSBrokerService"=3 (0x3)
"Dcfssvc"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-04-14 14:50:42 ------------