Hi Don --
Thanks for the help. No problem on the delays -- whatever help you guys can offer will be greatly appreciated.
I followed the instructions (twice) but only got one Notepad file: main.txt (below). There was no extra.txt that came up.
If you need any other information, please let me know.
Thanks again for your help.
Deckard's System Scanner v20070711.54
Run by Clipper44 on 2007-07-17 at 10:09:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as clipper44.exe) -----------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:09:37 AM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\PROGRA~1\YAHOO!\YOP\yop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Documents and Settings\Clipper44\Desktop\dss.exe
C:\HIJACK~1\Clipp4~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c.../search/ie.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapp...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://red.clientapp...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapp...rch/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\YAHOO!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} (EModelNonVersionSpecificViewControl Class) -
http://www.solidwork...anguage=EnglishO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{10562D72-3D72-4531-B8CB-94FF4AA6FDA2}: NameServer = 68.94.156.1,68.94.157.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{10562D72-3D72-4531-B8CB-94FF4AA6FDA2}: NameServer = 68.94.156.1,68.94.157.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
-- Files created between 2007-06-17 and 2007-07-17 -----------------------------
2007-07-15 08:08:58 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Walgreens
2007-07-11 17:44:00 0 dr-h----- C:\Documents and Settings\Clipper44\Recent
2007-07-11 00:36:24 8576 --a------ C:\WINDOWS\system32\drivers\jcivngepjysw.sys <Not Verified; Panda Software International; RKPavProc Driver>
2007-07-11 00:28:36 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-07-10 21:41:59 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-07-10 21:41:25 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-07-10 21:41:25 0 d-------- C:\Documents and Settings\Clipper44\Application Data\SUPERAntiSpyware.com
2007-07-10 21:16:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-10 19:58:41 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Grisoft
2007-07-10 19:58:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-07-10 18:15:26 118784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2007-07-10 18:15:25 0 d-------- C:\Program Files\SpywareBlaster
2007-07-10 15:45:39 0 d-------- C:\HijackThis
2007-07-09 08:04:04 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Skype
2007-07-09 08:03:28 0 d-------- C:\Program Files\Skype
2007-07-09 08:03:27 0 d-------- C:\Program Files\Common Files\Skype
2007-07-09 08:03:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2007-07-07 11:54:11 0 d-------- C:\Program Files\MSXML 6.0
2007-07-07 09:35:04 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-07-07 09:24:26 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Motive
2007-07-06 18:17:01 0 d-------- C:\Dial-a-fix-v0.60.0.24
2007-07-06 17:11:53 0 d-------- C:\WINDOWS\Motive
2007-07-06 17:11:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Motive
2007-07-06 17:11:43 0 d-------- C:\Program Files\Common Files\Motive
2007-07-06 17:11:21 0 d-------- C:\Program Files\SBC LightSpeed Self Support Tool
2007-07-06 17:11:20 0 d-------- C:\Program Files\SBC Self Support Tool
2007-07-06 17:11:09 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:08 171280 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:08 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:08 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
2007-07-06 17:11:08 6550 --a------ C:\WINDOWS\jautoexp.dat
2007-07-06 17:11:02 113 --a------ C:\WINDOWS\system32\zonedon.reg
2007-07-06 17:11:02 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2007-07-06 17:11:02 171792 --a------ C:\WINDOWS\system32\wjview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:02 286992 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:02 21264 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 947472 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 154384 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 172304 --a------ C:\WINDOWS\system32\jview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 15120 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 404752 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 63248 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:01 187152 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 17:11:00 49424 --a------ C:\WINDOWS\system32\clspack.exe <Not Verified; Microsoft Corporation; Microsoft® Windows ® Operating System>
2007-07-06 14:21:33 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-07-06 13:45:02 0 d-------- C:\wua
2007-07-06 13:44:19 0 d-------- C:\Documents and Settings\Clipper44\Application Data\WinRAR
2007-07-05 19:51:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-07-05 16:52:23 0 d-------- C:\Program Files\Microsoft Bootvis
2007-07-02 22:25:06 0 d-------- C:\Program Files\Lame
2007-07-02 19:42:50 0 d-------- C:\Documents and Settings\Clipper44\Application Data\U3
2007-07-01 23:12:52 25088 -----n--- C:\WINDOWS\system32\CTSVCCTL.EXE <Not Verified; Creative Technology Ltd; Creative Service Control>
2007-07-01 23:12:52 44032 -----n--- C:\WINDOWS\system32\CTSVCCDA.EXE <Not Verified; Creative Technology Ltd; Creative Service for CDROM Access>
2007-07-01 23:12:29 0 d-------- C:\Program Files\Common Files\Creative
2007-07-01 23:10:32 0 d-------- C:\Documents and Settings\All Users\Application Data\Creative
2007-07-01 20:18:26 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Creative
2007-07-01 19:35:29 41984 -----n--- C:\WINDOWS\Ctregrun.exe <Not Verified; Creative Technology Ltd; Creative On-line Registration System>
2007-07-01 19:28:08 0 d-------- C:\Program Files\Audible
2007-07-01 19:23:27 0 d--h----- C:\Program Files\Creative Installation Information
2007-07-01 19:18:46 0 d-------- C:\Program Files\Creative
2007-06-23 02:19:43 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2007-06-22 08:18:01 0 d-------- C:\WINDOWS\SxsCaPendDel
2007-06-21 16:59:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-06-21 11:03:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2007-06-21 08:20:32 0 d--hs---- C:\FOUND.002
-- Find3M Report ---------------------------------------------------------------
2007-06-30 00:05:24 32 --a------ C:\WINDOWS\system32\msvcsv60.dll
2007-06-30 00:05:24 32 --a------ C:\WINDOWS\msocreg32.dat
2007-06-06 20:46:04 946176 --a------ C:\WINDOWS\system32\bca2kcpan.exe <Not Verified; Behringer Spezielle Studiotechnik GmbH; BCA2000 Control Panel>
2007-06-06 20:46:04 32768 --a------ C:\WINDOWS\system32\bca2kasio.dll <Not Verified; Behringer Spezielle Studiotechnik GmbH; bca2kasio>
2007-06-06 17:39:34 0 d-------- C:\Program Files\Common Files\Digidesign
2007-06-06 17:39:18 0 d-------- C:\Program Files\Native Instruments
2007-06-06 17:39:14 0 d-------- C:\Program Files\GPO Tracktion 3 Edition
2007-06-06 17:24:30 0 d--h----- C:\Program Files\Zero G Registry
2007-06-06 17:24:30 0 d-------- C:\Program Files\Submersible
2007-06-06 17:20:18 0 d-------- C:\Program Files\Apple Software Update
2007-06-06 17:16:36 0 d-------- C:\Program Files\IK Multimedia
2007-06-06 17:16:14 0 d-------- C:\Documents and Settings\Clipper44\Application Data\InstallShield
2007-06-06 17:04:12 0 d-------- C:\Documents and Settings\Clipper44\Application Data\Tracktion 3
2007-06-06 17:04:02 0 d-------- C:\Program Files\Tracktion 3
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn6\yt.dll
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"LaunchApp"="Alaunch"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SoundMan"="SOUNDMAN.EXE"
"AGRSMMSG"="AGRSMMSG.exe"
"SiSPower"="Rundll32.exe SiSPower.dll,ModeAgent"
"SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
"PCMService"="\"C:\\Program Files\\Arcade\\PCMService.exe\""
"LManager"="C:\\Program Files\\Launch Manager\\QtZgAcer.EXE"
"CaAvTray"="\"C:\\Program Files\\Yahoo!\\Antivirus\\CAVTray.exe\""
"CAVRID"="\"C:\\Program Files\\Yahoo!\\Antivirus\\CAVRID.exe\""
"lxcgmon.exe"="\"C:\\Program Files\\Lexmark 2300 Series\\lxcgmon.exe\""
"EzPrint"="\"C:\\Program Files\\Lexmark 2300 Series\\ezprint.exe\""
"YOP"="C:\\PROGRA~1\\YAHOO!\\YOP\\yop.exe /autostart"
"LXCGCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCGtime.dll,_RunDLLEntry@16"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"YSearchProtection"="C:\\Program Files\\Yahoo!\\Search Protection\\SearchProtection.exe"
"CTSyncU.exe"="\"C:\\Program Files\\Creative\\Sync Manager Unicode\\CTSyncU.exe\""
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecliscecli\
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e98cc48c-28f5-11dc-a673-000e9bd52d16}]
Shell\AutoRun\command F:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2007-07-17 at 10:10:10 ---------