hi..
when ever i browse the net automatically new window opens and some site below pages open one a lap top ad and
the other one
kindly help me out.
below are the logs
i also get the exproler error now and then.. i remember this had started after i had clicked on some icon which i had downloaded after that i dont remember its name
attached are the logs
Deckard's System Scanner v20071014.68
Run by Surender on 2008-06-16 23:42:13
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Surender.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:42:16, on 16-06-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Windows\PLFSetL.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Surender\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EX E
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Surender\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Surender.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.crawler.com/search/dispat...=%s&tbid=60327
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://en.in.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://sg.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://sg.rd.yahoo.com/customize/ie/...rch.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [googletalk] C:\Users\Surender\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Surender\AppData\Local\Temp\khfEVllj.dll, c
O4 - HKCU\..\Run: [BM273daae2] Rundll32.exe "C:\Users\Surender\AppData\Local\Temp\jnnxupts.dll ",s
O4 - HKCU\..\Run: [240e997e] rundll32.exe "C:\Users\Surender\AppData\Local\Temp\nywqmwtt.dll ",b
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://img4.orkut.com/activex/10036/photouploader.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://dl8-cdn-01.sun.com/s/ESD42/JS...ws-i586-jc.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Inc. - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
--
End of file - 12099 bytes
-- Files created between 2008-05-16 and 2008-06-16 -----------------------------
2008-06-16 23:11:10 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-06-16 19:45:52 0 d-------- C:\Program Files\Crawler
2008-06-16 19:45:36 141312 --a------ C:\Windows\system32\drivers\sp_rsdrv2.sys
2008-06-16 19:45:36 0 d-------- C:\Users\All Users\Spyware Terminator
2008-06-16 19:45:32 0 d-------- C:\Program Files\Spyware Terminator
2008-06-15 21:57:59 0 d-------- C:\Users\All Users\Lavasoft
2008-06-15 21:57:59 0 d-------- C:\Program Files\Lavasoft
2008-06-15 21:56:29 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-15 21:45:06 0 d-------- C:\Program Files\Trend Micro
2008-06-14 00:34:25 0 --a------ C:\Windows\nsreg.dat
2008-06-10 21:36:51 0 d-------- C:\Users\Surender\Incomplete
2008-06-10 21:32:58 0 d-------- C:\Program Files\Sun
2008-06-10 21:31:29 0 d-------- C:\Program Files\Java
2008-06-10 21:29:44 0 d-------- C:\Program Files\Common Files\Java
2008-06-10 21:19:32 0 d-------- C:\Program Files\LimeWire
2008-06-08 01:13:46 0 d-------- C:\Program Files\iPod
2008-06-08 01:13:42 0 d-------- C:\Program Files\iTunes
2008-06-08 01:12:31 0 d-------- C:\Program Files\Bonjour
2008-06-08 01:11:30 0 d-------- C:\Program Files\QuickTime
2008-06-08 01:11:29 0 d-------- C:\Users\All Users\Apple Computer
2008-06-08 01:10:40 0 d-------- C:\Program Files\Apple Software Update
2008-06-08 01:09:51 0 d-------- C:\Users\All Users\Apple
2008-06-08 01:09:51 0 d-------- C:\Program Files\Common Files\Apple
2008-06-08 01:04:23 0 d-------- C:\Program Files\Common Files\xing shared
2008-06-08 01:03:55 0 d-------- C:\Program Files\Real
2008-06-08 01:03:50 0 d-------- C:\Program Files\Common Files\Real
2008-06-08 01:02:12 0 d-------- C:\Users\All Users\Google
2008-06-08 01:02:06 0 d-------- C:\Program Files\Google
2008-06-07 17:28:24 0 d-------- C:\Users\All Users\PlayFirst
2008-06-07 17:17:37 0 d-------- C:\Users\All Users\Oberon Games
2008-06-07 14:33:41 0 d-------- C:\Program Files\AC3Filter
2008-06-04 00:15:46 0 d-------- C:\Program Files\Common Files\L&H
2008-06-04 00:15:16 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-06-04 00:13:44 0 d-------- C:\Windows\PCHEALTH
2008-06-04 00:13:44 0 d-------- C:\Program Files\Microsoft.NET
2008-06-03 09:59:01 0 d-------- C:\QUARANTINE
2008-06-03 09:36:20 1495552 --a------ C:\Windows\system32\epoPGPsdk.dll <Not Verified; PGP Corporation; PGPsdk>
2008-06-03 09:36:20 0 d-------- C:\Program Files\Common Files\Cisco Systems
2008-06-03 09:36:19 0 d-------- C:\Users\All Users\McAfee
2008-06-03 09:32:57 0 d-------- C:\Program Files\McAfee
2008-06-03 09:32:57 0 d-------- C:\Program Files\Common Files\McAfee
2008-06-02 19:45:11 0 d-------- C:\Program Files\Winamp
2008-06-02 19:41:06 0 d-------- C:\Program Files\Common Files\PX Storage Engine
2008-06-02 19:40:57 0 d-------- C:\Program Files\DivX
2008-06-02 08:41:25 0 d-a------ C:\Users\All Users\TEMP
2008-06-02 08:39:17 0 d-------- C:\Users\Surender\Bluetooth Software
2008-06-02 08:37:04 0 dr------- C:\Users\Surender\Searches
2008-06-02 08:36:53 0 dr------- C:\Users\Surender\Contacts
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Templates
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Start Menu
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\SendTo
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Recent
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\PrintHood
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\NetHood
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\My Documents
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Local Settings
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Cookies
2008-06-02 08:36:36 0 d--hs---- C:\Users\Surender\Application Data
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Videos
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Saved Games
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Pictures
2008-06-02 08:36:35 2359296 --ahs---- C:\Users\Surender\NTUSER.DAT
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Music
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Links
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Favorites
2008-06-02 08:36:35 0 d-------- C:\Users\Surender\Downloads
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Documents
2008-06-02 08:36:35 0 dr------- C:\Users\Surender\Desktop
2008-06-02 08:36:35 0 d--h----- C:\Users\Surender\AppData
2008-06-02 01:41:46 0 d-------- C:\Program Files\MSXML 4.0
2008-06-02 01:26:47 0 d-------- C:\Users\All Users\Yahoo!
2008-06-02 01:22:20 0 d-------- C:\Users\All Users\ZoomBrowser
2008-06-02 01:22:03 0 d-------- C:\Program Files\Canon
2008-06-02 01:20:56 0 d-------- C:\Program Files\Common Files\Canon
2008-06-02 00:25:30 0 d-------- C:\softwares
2008-06-01 23:57:18 0 d-------- C:\Program Files\uTorrent
-- Find3M Report ---------------------------------------------------------------
2008-06-16 23:39:33 0 d-------- C:\Users\Surender\AppData\Roaming\uTorrent
2008-06-16 20:28:02 12 --a------ C:\Windows\bthservsdp.dat
2008-06-16 20:13:52 0 d-------- C:\Users\Surender\AppData\Roaming\Spyware Terminator
2008-06-15 21:56:29 0 d-------- C:\Program Files\Common Files
2008-06-14 16:53:20 0 d-------- C:\Users\Surender\AppData\Roaming\Mozilla
2008-06-14 16:18:06 0 d-------- C:\Program Files\Yahoo!
2008-06-14 16:16:53 0 d-------- C:\Program Files\Acer GameZone
2008-06-14 15:45:40 0 d-------- C:\Users\Surender\AppData\Roaming\LimeWire
2008-06-14 00:34:20 0 d-------- C:\Users\Surender\AppData\Roaming\.wyzo
2008-06-12 23:48:24 0 d-------- C:\Program Files\Windows Mail
2008-06-08 17:11:18 0 d-------- C:\Users\Surender\AppData\Roaming\Google
2008-06-08 01:14:07 0 d-------- C:\Users\Surender\AppData\Roaming\Apple Computer
2008-06-08 01:05:22 0 d-------- C:\Users\Surender\AppData\Roaming\Real
2008-06-07 17:38:08 0 d--hs---- C:\Users\Surender\AppData\Roaming\.#
2008-06-07 17:28:24 0 d-------- C:\Users\Surender\AppData\Roaming\PlayFirst
2008-06-03 23:45:31 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-03 23:42:34 0 d-------- C:\Users\Surender\AppData\Roaming\Adobe
2008-06-03 23:37:14 0 d-------- C:\Program Files\Microsoft Works
2008-06-03 00:03:44 0 d-------- C:\Users\Surender\AppData\Roaming\WinRAR
2008-06-02 19:48:15 0 d-------- C:\Users\Surender\AppData\Roaming\Winamp
2008-06-02 19:42:22 0 d-------- C:\Users\Surender\AppData\Roaming\DivX
2008-06-02 08:37:30 0 d-------- C:\Users\Surender\AppData\Roaming\Symantec
2008-06-02 08:37:12 0 d-------- C:\Users\Surender\AppData\Roaming\Macromedia
2008-06-02 08:36:55 0 d-------- C:\Users\Surender\AppData\Roaming\Identities
2008-06-02 02:32:41 0 d-------- C:\Users\Surender\AppData\Roaming\ZoomBrowser EX
2008-06-02 00:45:52 0 d-------- C:\Users\Surender\AppData\Roaming\Yahoo!
2008-04-01 05:25:48 823296 --a------ C:\Windows\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 05:25:48 823296 --a------ C:\Windows\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 05:25:46 802816 --a------ C:\Windows\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-04-01 05:25:46 831488 --a------ C:\Windows\system32\divx_xx0a.dll
2008-04-01 05:25:46 682496 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-22 04:30:08 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-03-22 04:28:54 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-03-22 04:28:54 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-03-22 04:28:20 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [21-01-2008 10:23]
"Adobe Reader Speed Launcher"="c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [08-03-2007 20:38]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [29-08-2007 04:43]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [29-08-2007 04:43]
"Persistence"="C:\Windows\system32\igfxpers.ex e" [29-08-2007 04:43]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [23-01-2008 02:14]
"PLFSetL"="C:\Windows\PLFSetL.exe" [06-07-2007 03:35]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [08-09-2007 03:35]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [03-01-2008 16:55]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [10-10-2007 21:41]
"eRecoveryService"="" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [27-03-2008 14:35]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [30-11-2006 08:50]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [17-11-2006 13:39]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [08-06-2008 01:03]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [28-03-2008 23:37]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30-03-2008 10:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [25-03-2008 04:28]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [21-01-2008 10:23]
"googletalk"="C:\Users\Surender\AppData\Roaming\Go ogle\Google Talk\googletalk.exe" [02-01-2007 05:22]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [31-08-2007 08:43]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [08-06-2008 01:02]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [02-06-2008 00:46]
"cmds"="C:\Users\Surender\AppData\Local\Temp\khfEV llj.dll,c" []
"BM273daae2"="C:\Users\Surender\AppData\Local\Temp \jnnxupts.dll,s" []
"240e997e"="C:\Users\Surender\AppData\Local\Temp\n ywqmwtt.dll,b" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28-01-2008 11:43]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe [3/17/2008 2:40:36 PM]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [8/29/2007 9:23:22 AM]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2/12/2008 4:28:19 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableUIADesktopToggle"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-06-16 23:42:45 ------------