Deckard's System Scanner v20071014.68
Run by phuqtoo on 2008-04-21 04:30:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2008-04-21 11:30:17 UTC - RP4 - Deckard's System Scanner Restore Point
3: 2008-04-21 07:37:31 UTC - RP3 - wrks good
2: 2008-04-21 05:16:21 UTC - RP2 - Software Distribution Service 3.0
1: 2008-04-20 16:04:33 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 248 MiB (512 MiB recommended).-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-21 04:34:00
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\phuqtoo\Desktop\downloads\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157F2 - REG:system.ini: Shell=
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PCPitStopEraser] C:\Program Files\PCPitstop\Erase\PCPitStopErase.exe /remindme
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resour ... ase370.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windows ... 8579834921O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 4827 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 ATITool (ATITool Overclocking Utility) - c:\windows\system32\drivers\atitool.sys <Not Verified; ; Low-Level Driver>
R3 BLKWGU(Belkin) (Belkin Wireless G USB Network Adapter(Belkin)) - c:\windows\system32\drivers\blkwgu.sys <Not Verified; Belkin Corporation; Wireless G USB Network Adapter>
R3 ZDPSp50 (ZDPSp50 NDIS Protocol Driver) - c:\windows\system32\drivers\zdpsp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-04-21 04:09:09 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
-- Files created between 2008-03-21 and 2008-04-21 -----------------------------
2008-04-20 22:21:17 0 d-------- C:\Program Files\MSXML 6.0
2008-04-20 16:38:24 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\MySpace
2008-04-20 16:38:11 0 d-------- C:\Program Files\MySpace
2008-04-20 13:38:15 0 d-------- C:\WINDOWS\system32\NtmsData
2008-04-20 12:28:19 0 d-------- C:\Program Files\ATITool
2008-04-20 12:23:29 0 d-------- C:\Program Files\DISKdata
2008-04-20 12:13:36 0 d-------- C:\Program Files\TFM
2008-04-20 12:12:35 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-04-20 12:10:52 0 d-------- C:\Program Files\2BrightSparks
2008-04-20 12:08:28 0 d-------- C:\Program Files\windirstat
2008-04-20 05:49:30 0 d-------- C:\Program Files\Paint.NET
2008-04-20 05:46:35 0 d-------- C:\Program Files\Windows Defender
2008-04-20 05:39:22 0 d-------- C:\WINDOWS\system32\appmgmt
2008-04-20 03:56:12 0 d-------- C:\Program Files\MSBuild
2008-04-20 03:56:06 0 d-------- C:\Program Files\Windows Live Safety Center
2008-04-20 03:46:26 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-04-20 03:44:23 0 d-------- C:\Program Files\Reference Assemblies
2008-04-20 03:42:14 0 d-------- C:\d21dcdc1d3836728af332c
2008-04-20 03:41:01 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-20 03:35:43 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-20 00:05:54 0 d-------- C:\WINDOWS\system32\LogFiles
2008-04-19 19:29:46 0 d-------- C:\WINDOWS\network diagnostic
2008-04-19 19:12:09 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-04-19 19:10:40 0 d-------- C:\WINDOWS\Prefetch
2008-04-19 18:44:13 0 d--hs---- C:\WINDOWS\CSC
2008-04-19 17:39:31 0 d-------- C:\WINDOWS\ServicePackFiles
2008-04-19 15:38:05 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\AVG7
2008-04-19 15:37:43 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-19 15:37:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-19 15:37:07 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-19 15:20:48 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-04-19 15:20:42 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-04-19 15:20:20 11264 --a------ C:\WINDOWS\system32\SpOrder.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(TM) Operating System>
2008-04-19 15:18:26 0 d-------- C:\WINDOWS\Internet Logs
2008-04-19 11:09:16 0 d-------- C:\Program Files\ReflexiveArcade
2008-04-19 10:36:14 0 d-------- C:\WINDOWS\peernet
2008-04-19 10:36:13 0 d-------- C:\WINDOWS\provisioning
2008-04-19 10:28:08 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-04-19 10:25:13 0 d-------- C:\Program Files\Common Files\HP
2008-04-19 10:23:30 0 d-------- C:\WINDOWS\EHome
2008-04-19 10:22:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-04-19 10:19:13 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-04-19 10:18:36 0 d-------- C:\Program Files\HP
2008-04-19 10:01:14 2828 -----n--- C:\WINDOWS\hphmdl15.dat
2008-04-19 10:01:14 137528 --a------ C:\WINDOWS\HPHins15.dat
2008-04-19 07:49:13 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\vlc
2008-04-19 07:45:00 0 d-------- C:\Program Files\VideoLAN
2008-04-19 06:25:03 0 d-------- C:\WINDOWS\system32\URTTemp
2008-04-19 05:36:11 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\gtk-2.0
2008-04-19 04:46:15 0 d-------- C:\Program Files\PCPitstop
2008-04-19 02:29:16 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\MSN6
2008-04-19 02:29:16 0 d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-04-19 01:52:52 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Wireshark
2008-04-19 00:21:57 171280 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:57 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:56 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:56 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
2008-04-19 00:21:56 6550 --a------ C:\WINDOWS\jautoexp.dat
2008-04-19 00:21:48 113 --a------ C:\WINDOWS\system32\zonedon.reg
2008-04-19 00:21:48 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2008-04-19 00:21:48 171792 --a------ C:\WINDOWS\system32\wjview.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:47 286992 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:47 21264 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:46 947472 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:46 154384 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:46 172304 --a------ C:\WINDOWS\system32\jview.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:46 15120 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:45 404752 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:45 63248 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:45 187152 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:21:43 49424 --a------ C:\WINDOWS\system32\clspack.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
2008-04-19 00:18:32 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-04-19 00:18:26 0 d-------- C:\WINDOWS\RegisteredPackages
2008-04-19 00:10:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-18 23:48:08 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Opera
2008-04-18 23:47:56 0 d-------- C:\Program Files\Opera
2008-04-18 22:16:57 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Macromedia
2008-04-18 22:16:57 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Adobe
2008-04-18 22:11:16 300 --a------ C:\WINDOWS\DNSTask.dat
2008-04-18 22:02:49 0 d-------- C:\Program Files\WinPcap
2008-04-18 22:00:39 0 d-------- C:\Program Files\Wireshark
2008-04-18 21:48:06 0 d-------- C:\WINDOWS\system32\PreInstall
2008-04-18 21:48:03 0 d--h----- C:\WINDOWS\$hf_mig$
2008-04-18 21:47:01 0 d-------- C:\WINDOWS\system32\bits
2008-04-18 21:37:26 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-04-18 21:37:10 0 d--hs---- C:\Documents and Settings\phuqtoo\UserData
2008-04-18 21:29:35 0 d-------- C:\Program Files\InstallShield Installation Information
2008-04-18 21:29:03 402944 -ra------ C:\WINDOWS\system32\drivers\BLKWGU.sys <Not Verified; Belkin Corporation; Wireless G USB Network Adapter>
2008-04-18 21:28:09 0 d-------- C:\Program Files\Belkin
2008-04-18 21:27:49 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-18 21:19:08 0 d-------- C:\Program Files\Tall Emu
2008-04-18 21:17:20 0 d-------- C:\WINDOWS\Downloaded Installations
2008-04-18 21:15:12 86016 --a------ C:\WINDOWS\unvise32qt.exe <Not Verified; MindVision; Installer VISE 2.8.3>
2008-04-18 21:14:50 0 d-------- C:\WINDOWS\system32\QuickTime
2008-04-18 21:14:50 0 d-------- C:\Program Files\QuickTime
2008-04-18 21:14:31 0 d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-04-18 21:07:57 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Talkback
2008-04-18 21:07:49 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-18 21:07:47 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Mozilla
2008-04-18 20:17:03 0 d-------- C:\WINDOWS\pss
2008-04-18 20:12:24 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-04-18 20:10:29 0 d--hs---- C:\WINDOWS\Installer
2008-04-18 20:10:26 0 d-------- C:\Documents and Settings\phuqtoo\Application Data\Identities
2008-04-18 20:10:14 0 dr------- C:\Documents and Settings\phuqtoo\Favorites
2008-04-18 20:10:14 0 d-------- C:\Documents and Settings\phuqtoo\Desktop
2008-04-18 20:10:14 0 d--hs---- C:\Documents and Settings\phuqtoo\Cookies
2008-04-18 20:10:14 0 dr-h----- C:\Documents and Settings\phuqtoo\Application Data
2008-04-18 20:10:13 0 d--h----- C:\Documents and Settings\phuqtoo\Templates
2008-04-18 20:10:13 0 dr------- C:\Documents and Settings\phuqtoo\Start Menu
2008-04-18 20:10:13 0 dr-h----- C:\Documents and Settings\phuqtoo\SendTo
2008-04-18 20:10:13 0 dr-h----- C:\Documents and Settings\phuqtoo\Recent
2008-04-18 20:10:13 0 d--h----- C:\Documents and Settings\phuqtoo\PrintHood
2008-04-18 20:10:13 3932160 --ah----- C:\Documents and Settings\phuqtoo\NTUSER.DAT
2008-04-18 20:10:13 0 d--h----- C:\Documents and Settings\phuqtoo\NetHood
2008-04-18 20:10:13 0 dr------- C:\Documents and Settings\phuqtoo\My Documents
2008-04-18 20:10:13 0 d--h----- C:\Documents and Settings\phuqtoo\Local Settings
2008-04-18 20:09:14 0 d--hs---- C:\System Volume Information
2008-04-18 20:09:11 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-04-18 20:09:11 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-04-18 20:09:11 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-04-18 20:09:11 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-04-18 20:09:11 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-04-18 20:09:11 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-04-18 20:09:11 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-04-18 20:09:11 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-04-18 20:09:11 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-04-18 20:09:11 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-04-18 19:10:10 0 d-------- C:\WINDOWS\system32\xircom
2008-04-18 19:10:09 0 d-------- C:\Program Files\microsoft frontpage
2008-04-18 19:09:54 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-04-18 19:09:48 0 -rahs---- C:\MSDOS.SYS
2008-04-18 19:09:48 0 -rahs---- C:\IO.SYS
2008-04-18 19:09:48 0 --a------ C:\CONFIG.SYS
2008-04-18 19:09:48 0 --a------ C:\AUTOEXEC.BAT
2008-04-18 19:08:39 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-04-18 19:08:26 0 dr------- C:\WINDOWS\Offline Web Pages
2008-04-18 19:08:26 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-04-18 19:07:54 0 d-------- C:\WINDOWS\system32\DirectX
2008-04-18 19:07:19 0 d---s---- C:\WINDOWS\Tasks
2008-04-18 19:07:17 0 d-------- C:\Program Files\Common Files\MSSoap
2008-04-18 19:07:13 0 d-------- C:\WINDOWS\system32\Macromed
2008-04-18 19:07:13 0 d-------- C:\WINDOWS\srchasst
2008-04-18 19:07:11 0 d-------- C:\Program Files\Movie Maker
2008-04-18 19:07:07 0 d-------- C:\WINDOWS\PCHealth
2008-04-18 19:07:05 0 d-------- C:\WINDOWS\system32\Restore
2008-04-18 19:06:22 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-18 19:06:06 0 d-------- C:\WINDOWS\Registration
2008-04-18 19:05:59 0 d--h----- C:\Program Files\WindowsUpdate
2008-04-18 19:05:59 0 d-------- C:\Program Files\Online Services
2008-04-18 19:05:51 0 d-------- C:\Program Files\Messenger
2008-04-18 19:05:42 0 d-------- C:\Program Files\MSN Gaming Zone
2008-04-18 19:04:45 0 d-------- C:\Program Files\Windows NT
2008-04-18 19:04:38 0 d-------- C:\WINDOWS\system32\MsDtc
2008-04-18 19:04:37 0 d-------- C:\WINDOWS\system32\Com
2008-04-18 11:58:24 0 d-------- C:\Program Files\Common Files\ODBC
2008-04-18 11:58:21 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-04-18 11:58:20 0 dr------- C:\Program Files
2008-04-18 11:58:20 0 d-------- C:\Program Files\Common Files
2008-04-18 11:57:57 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-04-18 11:57:57 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-04-18 11:57:57 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-04-18 11:57:57 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\Default User\NetHood
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-04-18 11:57:57 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-04-18 11:57:57 0 d--hs---- C:\Documents and Settings\Default User\Cookies
2008-04-18 11:57:57 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-04-18 11:57:57 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-04-18 11:57:57 0 dr------- C:\Documents and Settings\All Users\Documents
2008-04-18 11:57:57 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-04-18 11:57:45 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-04-18 11:57:45 0 d-------- C:\WINDOWS\system32\CatRoot
2008-04-18 11:57:40 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-04-18 11:57:40 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-04-18 11:57:39 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-04-18 11:57:39 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-04-18 11:53:10 0 d-------- C:\Documents and Settings
2008-04-18 10:13:04 0 d-------- C:\WINDOWS
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\WinSxS
2008-04-18 10:13:04 0 dr------- C:\WINDOWS\Web
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\twain_32
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\wins
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\wbem
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\usmt
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\spool
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\ShellExt
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\Setup
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\ras
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\oobe
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\npp
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\mui
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\inetsrv
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\IME
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\icsxml
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\ias
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\export
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\drivers
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-04-18 10:13:04 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\dhcp
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\config
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\3076
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\2052
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1054
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1042
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1041
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1037
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1033
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1031
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1028
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system32\1025
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\system
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\security
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Resources
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\repair
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\mui
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\msapps
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\msagent
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Media
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\java
2008-04-18 10:13:04 0 d--h----- C:\WINDOWS\inf
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\ime
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Help
2008-04-18 10:13:04 0 dr--s---- C:\WINDOWS\Fonts
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Driver Cache
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Debug
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Cursors
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Connection Wizard
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\Config
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\AppPatch
2008-04-18 10:13:04 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-04-18 11:57:57 62 --ahs---- C:\Documents and Settings\phuqtoo\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/18/2008 09:15 PM]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [11/02/2004 09:03 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [11/02/2004 08:59 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/19/2008 03:37 PM]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 01:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"PCPitStopEraser"="C:\Program Files\PCPitstop\Erase\PCPitStopErase.exe" [12/23/2005 09:07 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [02/01/2008 01:32 PM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\phuqtoo\Start Menu\Programs\Startup\
SyncBack.lnk - C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe [4/20/2008 12:10:52 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Belkin Wireless USB Utility.lnk - C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe [10/28/2005 11:23:10 AM]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc
*Newly Created Service* - SYSMONLOG
*Newly Created Service* - WMIAPSRV
-- End of Deckard's System Scanner: finished at 2008-04-21 04:39:17 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel(R) Celeron(R) CPU 2.53GHz
Percentage of Memory in Use: 68%
Physical Memory (total/avail): 247.48 MiB / 79.15 MiB
Pagefile Memory (total/avail): 605.73 MiB / 296.7 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1902.16 MiB
C: is Fixed (NTFS) - 9.77 GiB total, 3.03 GiB free.
D: is Fixed (Unformatted) - 0 GiB total, 0 GiB free.
E: is Removable (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is CDROM (CDFS)
\\.\PHYSICALDRIVE0 - ST340015A - 37.27 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 9.77 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 27.49 GiB - D:
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: AVG 7.5.524 v7.5.524 (Grisoft)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\phuqtoo\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=PHUQTOO-YZGVIYD
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\phuqtoo
LOGONSERVER=\\PHUQTOO-YZGVIYD
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 3, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0303
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\phuqtoo\LOCALS~1\Temp
TMP=C:\DOCUME~1\phuqtoo\LOCALS~1\Temp
USERDOMAIN=PHUQTOO-YZGVIYD
USERNAME=phuqtoo
USERPROFILE=C:\Documents and Settings\phuqtoo
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
phuqtoo
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player Plugin --> C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
Agere Systems PCI Soft Modem --> agrsmdel
ATITool Overclocking Utility --> "C:\Program Files\ATITool\Uninstall.exe"
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
Belkin Wireless USB Utility --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{A6359CCF-215D-43D9-8366-479D231F2A72}
DISKdata --> C:\PROGRA~1\DISKdata\UNWISE.EXE C:\PROGRA~1\DISKdata\INSTALL.LOG
HijackThis 1.99.1 --> C:\DOCUME~1\phuqtoo\LOCALS~1\Temp\Temporary Directory 1 for hijackthis1991.zip\HijackThis.exe /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Deskjet Printer Driver Software 9.0 --> C:\Program Files\HP\Digital Imaging\{03E66394-42F0-4745-85F7-0A2F8F35C09F}\setup\hpzscr01.exe -datfile hphscr15.dat -showdisconnect -forcereboot
Intel(R) Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mozilla Firefox (2.0.0.12) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MySpaceIM --> C:\Program Files\MySpace\IM\Uninstall.exe
Opera 9.27 --> MsiExec.exe /X{503D6E3E-1A48-44F5-BB7C-EB3B593FAED0}
Paint.NET v3.22 --> MsiExec.exe /X{96C267DA-0926-4C11-B4E7-4D3EF85130D0}
PC Pitstop Erase 1.0.6.85 --> "C:\Program Files\PCPitstop\Erase\unins000.exe"
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
SyncBack --> "C:\Program Files\2BrightSparks\SyncBack\unins000.exe"
TFM CPUsage --> "C:\Program Files\TFM\CPUsage\unins000.exe"
VideoLAN VLC media player 0.8.4a --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Defender --> MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Wireshark 1.0.0 --> "C:\Program Files\Wireshark\uninstall.exe"
XML Paper Specification Shared Components Pack 1.0 -->
-- Application Event Log -------------------------------------------------------
Event Record #/Type296 / Warning
Event Submitted/Written: 04/20/2008 10:15:57 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.
Event Record #/Type294 / Warning
Event Submitted/Written: 04/20/2008 09:45:04 PM
Event ID/Source: 1015 / EvntAgnt
Event Description:
TraceLevel parameter not located in registry;
Default trace level used is 32.
Event Record #/Type293 / Warning
Event Submitted/Written: 04/20/2008 09:45:04 PM
Event ID/Source: 1003 / EvntAgnt
Event Description:
TraceFileName parameter not located in registry;
Default trace file used is .
Event Record #/Type289 / Warning
Event Submitted/Written: 04/20/2008 04:51:10 PM
Event ID/Source: 1015 / EvntAgnt
Event Description:
TraceLevel parameter not located in registry;
Default trace level used is 32.
Event Record #/Type288 / Warning
Event Submitted/Written: 04/20/2008 04:51:10 PM
Event ID/Source: 1003 / EvntAgnt
Event Description:
TraceFileName parameter not located in registry;
Default trace file used is .
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1051 / Error
Event Submitted/Written: 04/19/2008 11:04:45 AM
Event ID/Source: 11 / PlugPlayManager
Event Description:
The device Root\LEGACY_AVG7CORE\0000 disappeared from the system without first being prepared for removal.
Event Record #/Type1032 / Error
Event Submitted/Written: 04/19/2008 11:00:21 AM
Event ID/Source: 7006 / Service Control Manager
Event Description:
The ScRegSetValueExW call failed for ImagePath with the following error:
%%5
Event Record #/Type1000 / Error
Event Submitted/Written: 04/19/2008 10:49:00 AM
Event ID/Source: 20 / Windows Update Agent
Event Description:
Installation Failure: Windows failed to install the following update with error 0x80070005: Windows XP Service Pack 2.
Event Record #/Type999 / Error
Event Submitted/Written: 04/19/2008 10:47:31 AM
Event ID/Source: 4374 / NtServicePack
Event Description:
Windows XP Service Pack 2 installation failed, leaving Windows XP partially updated.
Service Pack 2 installation did not complete.
Event Record #/Type991 / Warning
Event Submitted/Written: 04/19/2008 10:40:19 AM
Event ID/Source: 1007 / Dhcp
Event Description:
Your computer has automatically configured the IP address for the Network
Card with network address 00173F8D1791. The IP address being used is 169.254.142.125.
-- End of Deckard's System Scanner: finished at 2008-04-21 04:39:17 ------------