My apologies, Essexboy, I thought it had been 3 days already.
What do you mean by continue to the end? The last time I thanked the person very much and thought we were all good. is there a process I need to go through to close the topic out?
Here is the output from Deckard's.
Thank you for helping me out.
Deckard's System Scanner v20071014.68
Run by Brian Daniel on 2008-08-11 21:05:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
70: 2008-08-12 03:06:42 UTC - RP150 - Deckard's System Scanner Restore Point
69: 2008-08-11 22:41:46 UTC - RP149 - System Checkpoint
68: 2008-08-10 21:41:46 UTC - RP148 - System Checkpoint
67: 2008-08-09 20:41:43 UTC - RP147 - System Checkpoint
66: 2008-08-08 19:41:47 UTC - RP146 - System Checkpoint
-- First Restore Point --
1: 2008-05-14 12:25:38 UTC - RP81 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 256 MiB (512 MiB recommended).-- HijackThis (run as Brian Daniel.exe) ----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:08:20 PM, on 8/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Documents and Settings\TEMP.BRIAN\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Brian Daniel.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft....k/?LinkId=74005R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
O4 - HKLM\..\Run: [MSN6.EXE] C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-4283021946-953129233-1774555873-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...01/mcinsctl.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail....es/MSNPUpld.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1169764031499O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 6546 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080711-211015-838 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20080711-211238-701 O4 - HKLM\..\Run: [Microsoft] ticuwx.exe
backup-20080713-082426-229 O4 - HKLM\..\RunServices: [Microsoft] jsxbju.exe
backup-20080713-082442-520 O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
backup-20080803-174614-265 O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
-- File Associations -----------------------------------------------------------
.bat - batfile - shell\edit\command - blank.cmd - cmdfile - shell\edit\command - blank.inf - inffile - shell\open\command - blank.ini - inifile - shell\open\command - notepad.exe %1.reg - regfile - shell\open\command - regedit.exe "%1" %*.reg - regfile - shell\edit\command - blank.scr - AutoCADScript - shell\open\command - C:\WINDOWS\NOTEPAD.EXE "%1".txt - txtfile - shell\open\command - notepad.exe %1.vbs - VBSFile - shell\edit\command - blank-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 MPFP - c:\windows\system32\drivers\mpfp.sys <Not Verified; McAfee, Inc.; McAfee Personal Firewall Plus>
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys <Not Verified; SUPERAdBlocker.com and SUPERAntiSpyware.com; SUPERAntiSpyware>
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys <Not Verified; SUPERAdBlocker.com and SUPERAntiSpyware.com; SUPERAntiSpyware>
R1 SbcpHid - c:\windows\system32\drivers\sbcphid.sys
R2 Fallback - c:\windows\system32\drivers\hsf_fall.sys <Not Verified; Conexant; SoftK56>
R2 Fsks - c:\windows\system32\drivers\hsf_fsks.sys <Not Verified; Conexant; SoftK56>
R2 K56 - c:\windows\system32\drivers\hsf_k56k.sys <Not Verified; Conexant; SoftK56>
R2 mdmxsdk - c:\windows\system32\drivers\mdmxsdk.sys <Not Verified; Conexant; Diagnostic Interface>
R2 SoftFax - c:\windows\system32\drivers\hsf_faxx.sys <Not Verified; Conexant; SoftK56>
R2 SpeakerPhone - c:\windows\system32\drivers\hsf_spkp.sys <Not Verified; Conexant; SoftK56>
R2 Tones - c:\windows\system32\drivers\hsf_tone.sys <Not Verified; Conexant; SoftK56>
R2 V124 - c:\windows\system32\drivers\hsf_v124.sys <Not Verified; Conexant; SoftK56>
R3 aeaudio - c:\windows\system32\drivers\aeaudio.sys <Not Verified; Andrea Electronics Corporation; Andrea Audio Driver>
R3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys <Not Verified; Conexant Systems; SoftK56>
R3 HSFHWBS2 - c:\windows\system32\drivers\hsfhwbs2.sys <Not Verified; Conexant Systems; SoftK56>
R3 MODEMCSA (Unimodem Streaming Filter Device) - c:\windows\system32\drivers\modemcsa.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SUPERAdBlocker.com and SUPERAntiSpyware.com; SUPERAntiSpyware>
R3 smwdm - c:\windows\system32\drivers\smwdm.sys <Not Verified; Analog Devices, Inc.; SoundMAX Digital Audio Driver>
R3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys <Not Verified; Conexant Systems; SoftK56>
S3 ac97intc (Intel® 82801 Audio Driver Install Service (WDM)) - c:\windows\system32\drivers\ac97intc.sys <Not Verified; Intel Corporation; Intel® Integrated Controller Hub Audio Driver>
S3 basic2 - c:\windows\system32\drivers\hsf_bsc2.sys <Not Verified; Conexant; SoftK56>
S3 Dot4 HPH09 - c:\windows\system32\drivers\hphid409.sys <Not Verified; HP; HP Dot4 Windows 2000>
S3 Dot4Print HPH09 (Print Class Driver for IEEE-1284.4 HPH09) - c:\windows\system32\drivers\hphipr09.sys <Not Verified; HP; HP Dot4Print>
S3 Dot4Storage HPH09 (Storage Class Driver for IEEE-1284.4 (HPH09)) - c:\windows\system32\drivers\hphs2k09.sys <Not Verified; Hewlett-Packard; Escher>
S3 EL90XBC (3Com EtherLink XL 90XB/C Adapter Driver) - c:\windows\system32\drivers\el90xbc5.sys <Not Verified; 3Com Corporation; 3Com EtherLink PCI>
S3 hsf_msft - c:\windows\system32\drivers\hsf_msft.sys <Not Verified; Conexant; SoftK56>
S3 Rksample - c:\windows\system32\drivers\hsf_samp.sys <Not Verified; Conexant; SoftK56>
S3 SDTHOOK - c:\windows\system32\drivers\sdthook.sys <Not Verified; Panda Software; Panda® Antivirus>
S3 XIRLINK (IBM PC Camera) - c:\windows\system32\drivers\c-itnt.sys <Not Verified; Xirlink, Inc; C-it Digital Video PC Camera>
S4 cbidf - c:\windows\system32\drivers\cbidf2k.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
S4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys <Not Verified; Mylex Corporation; Mylex Disk Array Controller Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AdobeActiveFileMonitor4.0 (Adobe Active File Monitor V4) - c:\program files\adobe\photoshop elements 4.0\photoshopelementsfileagent.exe
R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >
S4 Pml Driver - c:\windows\system32\hphipm09.exe <Not Verified; HP; HP PML>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Parallel Device
Device ID: ROOT\LEGACY_HPFECP06\0000
Manufacturer:
Name: Parallel Device
PNP Device ID: ROOT\LEGACY_HPFECP06\0000
Service: HPFECP06
-- Scheduled Tasks -------------------------------------------------------------
2008-08-01 01:01:19 366 --a------ C:\WINDOWS\Tasks\McQcTask.job
2008-07-15 01:31:55 364 --a------ C:\WINDOWS\Tasks\McDefragTask.job
-- Files created between 2008-07-11 and 2008-08-11 -----------------------------
2008-08-09 23:02:32 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\SUPERAntiSpyware.com
2008-08-07 20:45:31 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\Macromedia
2008-08-07 20:42:17 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\MSN6
2008-08-07 19:42:24 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\Adobe
2008-08-07 19:38:12 0 dr-h----- C:\Documents and Settings\TEMP.BRIAN\SendTo
2008-08-07 19:38:12 0 dr-h----- C:\Documents and Settings\TEMP.BRIAN\Recent
2008-08-07 19:38:12 0 d--h----- C:\Documents and Settings\TEMP.BRIAN\PrintHood
2008-08-07 19:38:12 0 d--h----- C:\Documents and Settings\TEMP.BRIAN\NetHood
2008-08-07 19:38:12 0 dr------- C:\Documents and Settings\TEMP.BRIAN\My Documents
2008-08-07 19:38:12 0 d--h----- C:\Documents and Settings\TEMP.BRIAN\Local Settings
2008-08-07 19:38:12 0 dr------- C:\Documents and Settings\TEMP.BRIAN\Favorites
2008-08-07 19:38:12 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Desktop
2008-08-07 19:38:12 0 d--hs---- C:\Documents and Settings\TEMP.BRIAN\Cookies
2008-08-07 19:38:12 0 dr-h----- C:\Documents and Settings\TEMP.BRIAN\Application Data
2008-08-07 19:38:12 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\Symantec
2008-08-07 19:38:12 0 d-------- C:\Documents and Settings\TEMP.BRIAN\Application Data\Identities
2008-08-07 19:38:11 0 d--h----- C:\Documents and Settings\TEMP.BRIAN\Templates
2008-08-07 19:38:11 0 dr------- C:\Documents and Settings\TEMP.BRIAN\Start Menu
2008-08-07 19:38:10 1572864 --ah----- C:\Documents and Settings\TEMP.BRIAN\NTUSER.DAT
2008-08-04 13:35:29 17144 --a------ C:\WINDOWS\system32\drivers\mbam.sys <Not Verified; Malwarebytes Corporation; Malwarebytes' Anti-Malware>
2008-08-04 13:35:26 38472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys <Not Verified; Malwarebytes Corporation; Malwarebytes' Anti-Malware>
2008-08-04 13:35:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 13:35:23 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-04 13:34:57 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-19 21:54:03 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-19 21:50:02 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-19 21:47:53 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-11 20:43:37 0 d-------- C:\Program Files\Trend Micro
-- Find3M Report ---------------------------------------------------------------
2008-08-04 13:34:57 0 d-------- C:\Program Files\Common Files
2008-07-08 18:13:10 0 d-------- C:\Program Files\McAfee
2008-07-02 18:43:10 0 d-------- C:\Program Files\Common Files\McAfee
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSN6.EXE"="C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE" [11/27/2002 02:54 PM]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [04/10/2002 03:44 PM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [09/09/2005 12:18 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [10/06/2003 02:16 PM]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [08/23/2001 05:24 AM]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [03/21/2006 07:30 PM]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [03/21/2006 01:19 PM]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [01/31/2007 08:52 PM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [12/14/2005 10:10 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [10/15/2004 04:03 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:56 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Startup Wizard]
"C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
"C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon03]
C:\WINDOWS\System32\hphmon03.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
-- End of Deckard's System Scanner: finished at 2008-08-11 21:09:24 ------------