main txt
and heres deckards...
MAIN.TXT
----------------------------------------------------
Deckard's System Scanner v20071014.68
Run by Jordan on 2008-06-02 01:18:10
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
54: 2008-06-02 05:18:15 UTC - RP54 - Deckard's System Scanner Restore Point
53: 2008-06-01 15:01:04 UTC - RP53 - Last known good configuration
52: 2008-06-01 15:00:16 UTC - RP52 - ComboFix created restore point
51: 2008-06-01 15:00:15 UTC - RP51 - System Checkpoint
50: 2008-06-01 15:00:14 UTC - RP50 - System Checkpoint
-- First Restore Point --
1: 2008-06-01 14:58:31 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Jordan.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:19:28 AM, on 6/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\Jordan\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Jordan.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {166BCB27-FCFD-4588-9BDB-44FC6A02EF35} - C:\WINDOWS\system32\urqPjGyV.dll (file missing)
O2 - BHO: (no name) - {5170872F-A9BD-4D9E-9DF2-FF8E4CB503F3} - C:\WINDOWS\system32\vtUlMfFU.dll (file missing)
O2 - BHO: {a62de3d5-f1ac-1f8a-b1d4-8508abfddb86} - {68bddfba-8058-4d1b-a8f1-ca1f5d3ed26a} - C:\WINDOWS\system32\imwfesld.dll
O2 - BHO: (no name) - {E54863BA-42B9-447F-BD94-A50156215BD7} - C:\WINDOWS\system32\fccdbBrR.dll (file missing)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BMbf54f06c] Rundll32.exe "C:\WINDOWS\system32\xniefnue.dll",s
O4 - HKLM\..\Run: [bc67c3f0] rundll32.exe "C:\WINDOWS\system32\gyyrtlox.dll",b
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DLIGHTER] C:\Program Files\Desktop Lighter\DLighter.exe /h
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: urqPjGyV - urqPjGyV.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 5153 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080528-195537-115 O4 - HKLM\..\RunOnce: [SpybotDeletingC1913] cmd /c del "C:\WINDOWS\system32\ssqNFWnl.dll_old"
backup-20080528-195537-218 O4 - HKCU\..\RunOnce: [SpybotDeletingB5534] command /c del "C:\WINDOWS\system32\ssqNFWnl.dll_old"
backup-20080528-195537-313 O4 - HKLM\..\RunOnce: [SpybotDeletingA9023] command /c del "C:\WINDOWS\system32\ssqNFWnl.dll_old"
backup-20080528-195537-533 O4 - HKLM\..\RunOnce: [SpybotDeletingC6120] cmd /c del "C:\WINDOWS\system32\ssqNFWnl.dll"
backup-20080528-195537-678 O4 - HKLM\..\RunOnce: [SpybotDeletingA4936] command /c del "C:\WINDOWS\system32\ssqNFWnl.dll"
backup-20080528-195537-752 O4 - HKCU\..\RunOnce: [SpybotDeletingD5310] cmd /c del "C:\WINDOWS\system32\ssqNFWnl.dll"
backup-20080528-195537-886 O4 - HKCU\..\RunOnce: [SpybotDeletingD7881] cmd /c del "C:\WINDOWS\system32\ssqNFWnl.dll_old"
backup-20080528-195537-929 O4 - HKCU\..\RunOnce: [SpybotDeletingB1000] command /c del "C:\WINDOWS\system32\ssqNFWnl.dll"
-- File Associations -----------------------------------------------------------
.scr - AutoCADScriptFile - shell\open\command - C:\WINDOWS\system32\notepad.exe "%1"
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)
S3 cpuz - c:\docume~1\jordan\locals~1\temp\rar$ex00.422\cpuz.sys (file missing)
S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_FF001179&REV_01\4&1B08A035&0&0030
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_10EC&DEV_8136&SUBSYS_FF001179&REV_01\4&1B08A035&0&0030
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Mass Storage Controller
Device ID: PCI\VEN_104C&DEV_803B&SUBSYS_FF001179&REV_00\4&B216F0A&0&22A4
Manufacturer:
Name: Mass Storage Controller
PNP Device ID: PCI\VEN_104C&DEV_803B&SUBSYS_FF001179&REV_00\4&B216F0A&0&22A4
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\TOS1900\2&DABA3FF&0
Manufacturer:
Name:
PNP Device ID: ACPI\TOS1900\2&DABA3FF&0
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-06-01 03:00:03 290 --a------ C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job
2008-05-26 16:48:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-02 and 2008-06-02 -----------------------------
2008-06-01 11:08:57 114176 --a------ C:\WINDOWS\system32\gyyrtlox.dll
2008-06-01 11:06:18 132096 --a------ C:\WINDOWS\system32\imwfesld.dll
2008-06-01 11:04:21 2560 --a------ C:\WINDOWS\system32\abllqeka.exe
2008-06-01 10:37:03 68096 --a------ C:\WINDOWS\zip.exe
2008-06-01 10:37:03 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-01 10:37:03 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-01 10:37:03 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-01 10:37:03 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-01 10:37:03 98816 --a------ C:\WINDOWS\sed.exe
2008-06-01 10:37:03 80412 --a------ C:\WINDOWS\grep.exe
2008-06-01 10:37:03 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-01 10:35:57 0 d-------- C:\VundoFix Backups
2008-06-01 00:36:06 0 d-------- C:\!KillBox
2008-05-30 12:39:33 0 dr-h----- C:\Documents and Settings\Jordan\Recent
2008-05-30 12:27:49 0 d--hs---- C:\WINDOWS\CSC
2008-05-29 22:35:57 0 d-------- C:\Program Files\CCleaner
2008-05-29 22:21:17 0 d-------- C:\WINDOWS\pss
2008-05-28 20:20:13 0 d-------- C:\Program Files\aKill
2008-05-28 19:59:31 0 d-------- C:\Program Files\Safer Networking
2008-05-28 17:31:48 0 d-------- C:\Program Files\File Shredder
2008-05-28 17:20:55 3145728 --a------ C:\Documents and Settings\Jordan\ntuser.dat
2008-05-27 13:26:39 0 d-------- C:\Documents and Settings\Jordan\Application Data\LimeWire
2008-05-27 13:26:30 0 d-------- C:\Program Files\LimeWire
2008-05-27 13:24:46 0 d-------- C:\WINDOWS\system32\SDA
2008-05-27 13:24:46 0 d-------- C:\Program Files\TOSHIBA
2008-05-26 12:14:45 0 d-------- C:\Program Files\FLAC
2008-05-26 11:35:49 0 d-------- C:\WINDOWS\RegisteredPackages
2008-05-26 11:35:07 0 d-------- C:\Program Files\Winamp
2008-05-26 11:35:07 0 d-------- C:\Documents and Settings\Jordan\Application Data\Winamp
2008-05-22 12:35:29 0 d-------- C:\Documents and Settings\Jordan\Application Data\Ahead
2008-05-22 12:34:15 0 d-------- C:\Program Files\Nero
2008-05-22 12:34:15 0 d-------- C:\Program Files\Common Files\Ahead
2008-05-22 10:40:29 0 d-------- C:\Westwood
2008-05-17 18:33:34 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-16 12:09:03 0 d-------- C:\Program Files\EA GAMES
2008-05-16 12:08:05 96256 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
2008-05-16 12:08:05 0 d-------- C:\Program Files\MagicDisc
2008-05-16 12:04:25 0 d-------- C:\Program Files\MagicISO
2008-05-15 13:52:05 0 d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-14 18:42:44 0 d-------- C:\Program Files\Sybase
2008-05-13 22:23:02 0 d-------- C:\Program Files\uTorrent
2008-05-13 22:22:53 0 d-------- C:\Documents and Settings\Jordan\Application Data\uTorrent
2008-05-12 20:12:03 0 d-------- C:\Documents and Settings\Jordan\Application Data\Google
2008-05-12 20:08:16 0 d-------- C:\Program Files\Google
2008-05-11 02:09:03 0 d-------- C:\Program Files\Apple Software Update
2008-05-10 15:01:04 0 d-------- C:\Program Files\AviSynth 2.5
2008-05-10 15:01:00 0 d-------- C:\Program Files\Red Kawa
2008-05-08 14:31:52 44 --a------ C:\WINDOWS\system32\'
2008-05-08 14:31:24 5760 --a------ C:\WINDOWS\system32\vnchelp.dll <Not Verified; RDV Soft; UltraVnc Kernel>
2008-05-08 03:00:45 0 d-------- C:\Program Files\MSXML 6.0
2008-05-06 21:02:52 0 d-------- C:\Program Files\AutoCAD 2009
2008-05-06 21:02:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-05-06 21:01:29 0 d-------- C:\Program Files\MSBuild
2008-05-06 20:59:45 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-05-06 20:59:09 0 d-------- C:\Program Files\Reference Assemblies
2008-05-06 20:56:57 0 d-------- C:\Program Files\Common Files\Autodesk Shared
2008-05-06 20:56:57 0 d-------- C:\Program Files\Autodesk
2008-05-06 20:56:57 0 d-------- C:\Documents and Settings\Jordan\Application Data\Autodesk
2008-05-06 20:40:49 0 d-------- C:\install
2008-05-06 13:57:44 0 d-------- C:\WINDOWS\Sun
2008-05-06 13:57:44 0 d-------- C:\Documents and Settings\Jordan\Application Data\Sun
2008-05-06 13:56:49 0 d-------- C:\Program Files\Java
2008-05-06 13:49:15 0 d-------- C:\Program Files\Common Files\Java
2008-05-06 13:38:27 269312 --a------ C:\WINDOWS\uninst.exe <Not Verified; Stirling Technologies, Inc.; InstallShield Deinstaller>
2008-05-06 13:38:27 0 d-------- C:\Documents and Settings\Jordan\WINDOWS
2008-05-04 12:58:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-04 12:58:47 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-02 00:38:03 0 d-------- C:\Program Files\Desktop Lighter
-- Find3M Report ---------------------------------------------------------------
2008-05-22 12:34:15 0 d-------- C:\Program Files\Common Files
2008-05-15 15:15:31 0 d-------- C:\Documents and Settings\Jordan\Application Data\Mozilla
2008-05-14 14:32:30 0 d-------- C:\Program Files\Need for Speed Underground 2
2008-05-04 12:59:53 0 d-------- C:\Documents and Settings\Jordan\Application Data\Adobe
2008-05-02 23:28:05 0 d-------- C:\Program Files\Buddy Icon Maker
2008-05-02 23:10:41 0 d-------- C:\Program Files\AIM6
2008-04-30 22:55:35 0 d-------- C:\Program Files\Messenger
2008-04-30 17:18:37 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-04-30 03:08:02 0 d-------- C:\Documents and Settings\Jordan\Application Data\ATI
2008-04-29 23:27:32 0 d-------- C:\Program Files\EphPod
2008-04-29 22:39:26 0 d-------- C:\Program Files\Common Files\DirectX
2008-04-29 22:31:32 0 d-------- C:\Program Files\DirectX 9.0c
2008-04-29 22:05:32 0 d-------- C:\Program Files\Volumouse
2008-04-29 22:04:57 39424 --a------ C:\WINDOWS\zipinst.exe <Not Verified; NirSoft; ZipInstaller>
2008-04-29 20:29:42 0 d-------- C:\Program Files\Realtek
2008-04-29 20:29:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-29 20:29:37 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-04-29 20:23:14 0 d-------- C:\Program Files\Infogrames
2008-04-29 20:14:51 0 d-------- C:\Documents and Settings\Jordan\Application Data\Macromedia
2008-04-29 20:14:48 1169 --a------ C:\WINDOWS\mozver.dat
2008-04-29 20:13:33 0 d-------- C:\Documents and Settings\Jordan\Application Data\Apple Computer
2008-04-29 20:13:29 0 d-------- C:\Program Files\iTunes
2008-04-29 20:13:21 0 d-------- C:\Program Files\iPod
2008-04-29 20:13:06 0 d-------- C:\Program Files\Bonjour
2008-04-29 20:13:00 0 d-------- C:\Program Files\QuickTime
2008-04-29 20:12:03 0 d-------- C:\Program Files\Common Files\Apple
2008-04-29 20:08:28 0 d-------- C:\Documents and Settings\Jordan\Application Data\WinRAR
2008-04-29 19:54:04 0 d-------- C:\Documents and Settings\Jordan\Application Data\acccore
2008-04-29 19:53:08 0 d-------- C:\Program Files\Colorizer
2008-04-29 19:51:42 0 d-------- C:\Program Files\AIM FightList
2008-04-29 19:47:08 0 d-------- C:\Documents and Settings\Jordan\Application Data\vlc
2008-04-29 19:46:36 0 d-------- C:\Program Files\VideoLAN
2008-04-29 19:44:40 0 d-------- C:\Program Files\Trend Micro
2008-04-29 19:38:00 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-29 19:37:09 0 d-------- C:\Program Files\ATI
2008-04-29 19:36:54 0 d-------- C:\Program Files\ATI Technologies
2008-04-29 19:36:30 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-29 19:33:37 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-29 19:13:16 0 d-------- C:\Documents and Settings\Jordan\Application Data\Identities
2008-04-29 19:08:13 0 d-------- C:\Program Files\microsoft frontpage
2008-04-29 19:07:53 0 -rahs---- C:\MSDOS.SYS
2008-04-29 19:07:53 0 -rahs---- C:\IO.SYS
2008-04-29 19:07:53 0 --a------ C:\CONFIG.SYS
2008-04-29 19:07:53 0 --a------ C:\AUTOEXEC.BAT
2008-04-29 19:06:32 0 d--h----- C:\Program Files\WindowsUpdate
2008-04-29 19:04:38 0 d-------- C:\Program Files\Common Files\MSSoap
2008-04-29 19:04:12 0 d-------- C:\Program Files\Movie Maker
2008-04-29 19:02:41 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-29 19:02:10 0 d-------- C:\Program Files\Online Services
2008-04-29 19:01:52 0 d-------- C:\Program Files\MSN Gaming Zone
2008-04-29 19:01:34 0 d-------- C:\Program Files\Windows NT
2008-04-29 12:19:46 0 d-------- C:\Program Files\Common Files\ODBC
2008-04-29 12:19:39 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-04-29 12:18:51 62 --ahs---- C:\Documents and Settings\Jordan\Application Data\desktop.ini
2008-03-28 21:05:00 593920 --a------ C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-03-05 18:07:48 520192 --a------ C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{166BCB27-FCFD-4588-9BDB-44FC6A02EF35}]
C:\WINDOWS\system32\urqPjGyV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5170872F-A9BD-4D9E-9DF2-FF8E4CB503F3}]
C:\WINDOWS\system32\vtUlMfFU.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68bddfba-8058-4d1b-a8f1-ca1f5d3ed26a}]
06/01/2008 11:06 AM 132096 --a------ C:\WINDOWS\system32\imwfesld.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E54863BA-42B9-447F-BD94-A50156215BD7}]
C:\WINDOWS\system32\fccdbBrR.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [02/21/2006 09:05 PM C:\WINDOWS\system32\atiptaxx.exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [01/21/2008 12:17 PM]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [10/04/2007 06:38 PM]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [01/28/2008 11:43 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"RTHDCPL"="RTHDCPL.EXE" [04/10/2008 04:52 PM C:\WINDOWS\RTHDCPL.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 11:50 AM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/01/2008 02:49 PM]
"BMbf54f06c"="C:\WINDOWS\system32\xniefnue.dll" []
"bc67c3f0"="C:\WINDOWS\system32\gyyrtlox.dll" [06/01/2008 11:08 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [03/25/2008 04:21 PM]
"DLIGHTER"="C:\Program Files\Desktop Lighter\DLighter.exe" [03/15/2008 02:30 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 12:24 PM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [09/03/2005 03:18 PM]
C:\Documents and Settings\Jordan\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [5/16/2008 12:08:05 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{166BCB27-FCFD-4588-9BDB-44FC6A02EF35}"= C:\WINDOWS\system32\urqPjGyV.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqPjGyV]
urqPjGyV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtUlMfFU
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\autorun.exe
readit\command- notepad readme.doc
-- End of Deckard's System Scanner: finished at 2008-06-02 01:19:53 ------------