Deckard's System Scanner v20071014.68
Run by Kris on 2008-06-12 20:04:23
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Kris.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:27 PM, on 6/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Documents and Settings\Kris\Desktop\dss.exe
C:\PROGRA~1\Trend Micro\HijackThis\Kris.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
Microsoft Update
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
--
End of file - 2786 bytes
-- Files created between 2008-05-12 and 2008-06-12 -----------------------------
2008-06-12 20:04:05 0 dr-h----- C:\Documents and Settings\Kris\Recent
2008-06-08 14:48:18 0 d-------- C:\Program Files\PeerGuardian2
2008-06-07 19:24:49 0 d-------- C:\WINDOWS\Logs
2008-06-03 19:37:12 0 d-------- C:\Program Files\LimeWire
2008-05-31 18:31:48 0 d-------- C:\Program Files\Winamp
2008-05-31 18:31:48 0 d-------- C:\Documents and Settings\Kris\Application Data\Winamp
2008-05-29 18:13:19 0 d-------- C:\Program Files\CCleaner
2008-05-28 18:46:07 0 d-------- C:\Documents and Settings\Kris\Application Data\Any Video Converter
2008-05-28 18:46:05 0 d-------- C:\Program Files\Any Video Converter
2008-05-27 21:05:51 0 d-------- C:\Program Files\QuickMediaConverter
2008-05-25 15:21:45 580114 --a------ C:\WINDOWS\system32\x264vfw.dll
2008-05-14 21:17:56 0 d-------- C:\Program Files\Bonjour
2008-05-14 21:17:13 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-14 21:16:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
-- Find3M Report ---------------------------------------------------------------
2008-06-12 19:13:01 0 d-------- C:\Program Files\a-squared Free
2008-06-11 21:37:52 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-06-08 21:12:40 9390251 --a------ C:\Program Files\vlc-0.8.6h-win32.exe
2008-06-08 18:34:52 0 d-------- C:\Documents and Settings\Kris\Application Data\uTorrent
2008-06-06 19:06:46 0 d-------- C:\Program Files\SpywareBlaster
2008-06-05 20:44:52 0 d-------- C:\Program Files\Microsoft Silverlight
2008-06-01 00:30:17 0 d-------- C:\Documents and Settings\Kris\Application Data\SiteAdvisor
2008-06-01 00:28:59 0 d-------- C:\Documents and Settings\Kris\Application Data\Mozilla
2008-05-29 19:38:27 0 d-------- C:\Documents and Settings\Kris\Application Data\dvdcss
2008-05-28 23:45:48 0 d-------- C:\Program Files\dvdSanta
2008-05-14 21:56:50 0 d-------- C:\Program Files\Common Files
2008-05-11 22:23:23 0 d-------- C:\Program Files\Avira
2008-05-08 23:53:35 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-30 21:05:22 2279607 --a------ C:\Program Files\TGTC_XP.pdf
2008-04-29 22:07:13 0 d-------- C:\Program Files\Foxit Software
2008-04-29 22:06:00 0 d-------- C:\Program Files\Trend Micro
2008-04-27 20:59:48 0 d-------- C:\Documents and Settings\Kris\Application Data\W Photo Studio Viewer
2008-04-27 03:01:00 33792 --a------ C:\Program Files\resume.doc
2008-04-23 21:11:24 0 d-------- C:\Program Files\Messenger
2008-04-23 21:11:07 0 d-------- C:\Program Files\Movie Maker
2008-04-20 13:40:22 0 d-------- C:\Program Files\DivX
2008-04-16 21:28:06 0 d-------- C:\Program Files\Lavasoft
2008-04-12 20:01:29 5720 --a------ C:\WINDOWS\mozver.dat
2008-03-31 16:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-31 16:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-31 16:25:46 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-03-31 16:25:46 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 16:25:46 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-21 15:30:08 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 15:28:54 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-03-21 15:28:54 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-03-21 15:28:20 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoRecentDocsNetHood"=01000000
"NoLowDiskSpaceChecks"=1 (0x1)
"NoSharedDocuments"=1 (0x1)
"NoInstrumentation"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk.disabled
backup=C:\WINDOWS\pss\Logitech SetPoint.lnk.disabledCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Smart Wizard Wireless Settings.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk
backup=C:\WINDOWS\pss\Smart Wizard Wireless Settings.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtxfiReg]
CTXFIREG.exe /FAIL1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"C:\Program Files\Winamp\winampa.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"gusvc"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MS Config.exe /auto
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"nwiz"=nwiz.exe /install
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- End of Deckard's System Scanner: finished at 2008-06-12 20:06:09 ------------