MAIN.TXT
Deckard's System Scanner v20071014.68
Run by Rob on 2008-01-06 12:46:52
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-01-06 20:46:55 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Rob.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:48:26 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\Rob\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Rob.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: TweakMASTER PRO Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HDSPTray2] hdspmix.exe.sav
O4 - HKLM\..\Run: [HDSPTray1] hdsp32.exe.sav
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Norton Ghost 12.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: ColorVisionStartup.lnk = C:\Program Files\ColorVision\Utility\ColorVisionStartup.exe
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\IEShellExt.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.burj-al-a.../ipix/ipixx.cabO16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: HauppaugeTVServer - Hauppauge Computer Works - C:\PROGRA~1\WinTV\HCWTVS~1.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
--
End of file - 7569 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) --------------------
backup-20080106-100019-113 O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
backup-20080106-100019-717 O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
backup-20080106-100019-927 O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
backup-20080106-100019-938 O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
backup-20080106-100040-494 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
backup-20080106-100108-283 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
backup-20080106-102231-241 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
backup-20080106-102231-846 O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
backup-20080106-102231-878 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
backup-20080106-102304-796 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
backup-20080106-102304-995 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 AACmgt - c:\windows\system32\drivers\aacmgt.sys <Not Verified; Adaptec, Inc.; Adaptec RAID Controller>
R0 IFP800 (iriver Internet Audio Player IFP-800) - c:\windows\system32\drivers\ifp800.sys <Not Verified; iRiver, Inc.; IFP-100>
R0 viasraid - c:\windows\system32\drivers\viasraid.sys <Not Verified; VIA Technologies inc,.ltd; Raid controller 6420 driver>
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD>
R1 NetworkX - c:\windows\system32\ckldrv.sys
R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R3 hdsp (RME Hammerfall Audio Device) - c:\windows\system32\drivers\hdsp.sys <Not Verified; RME; Hammerfall DSP>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
S0 ntcdrdrv - c:\windows\system32\drivers\ntcdrdrv.sys (file missing)
S2 P1C1394 (Phase One 1394 Camera Driver) - c:\windows\system32\drivers\p1c1394.sys (file missing)
S3 ATI Remote Wonder II - c:\windows\system32\drivers\atirwvd.sys (file missing)
S3 cvspydr2 (ColorVision Spyder 2) - c:\windows\system32\drivers\cvspydr2.sys <Not Verified; Colorvision Inc; cvspydr2 Driver>
S3 fd_dbus (FutureDial USB Composite Device driver (WDM)) - c:\windows\system32\drivers\fd_dbus.sys <Not Verified; MCCI; FutureDial USB Composite Device>
S3 fd_dmdfl (FutureDial USB Modem Filter) - c:\windows\system32\drivers\fd_dmdfl.sys <Not Verified; MCCI; FutureDial USB Modem Filter Driver>
S3 fd_dmdm (FutureDial USB Modem Drivers) - c:\windows\system32\drivers\fd_dmdm.sys <Not Verified; MCCI; FutureDial USB Modem>
S3 GVCplDrv - c:\windows\system32\drivers\gvcpldrv.sys
S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S3 pgfilter - c:\program files\peerguardian2\pgfilter.sys (file missing)
S3 WmaCDriverV32 - c:\windows\system32\drivers\wmacdriverv32.sys <Not Verified; Windows ® 2000/XP; Windows ® 2000/XP Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Crypkey License - crypserv.exe <Not Verified; CrypKey (Canada) Ltd.; CrypKey Software Licensing System>
S2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" (file missing)
S3 HauppaugeTVServer - c:\progra~1\wintv\hcwtvs~1.exe <Not Verified; Hauppauge Computer Works; Hauppauge TV Server>
S4 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
S4 ScsiAccess - c:\program files\photodex\proshowproducer\scsiaccess.exe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\B394FEE01800
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\B394FEE01800
Service: NIC1394
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RAID Controller
Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\3&267A616A&0&40
Manufacturer:
Name: RAID Controller
PNP Device ID: PCI\VEN_105A&DEV_3373&SUBSYS_80F51043&REV_02\3&267A616A&0&40
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-01-06 10:28:34 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-01-06 02:10:30 376 --a------ C:\WINDOWS\Tasks\JkDefrag.job
2008-01-04 23:58:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2007-12-06 and 2008-01-06 -----------------------------
2008-01-03 14:54:28 110592 --a------ C:\WINDOWS\system32\JkDefragScreenSaver.scr <Not Verified; J.C. Kessels; JkDefrag>
2008-01-03 14:54:28 237568 --a------ C:\WINDOWS\system32\JkDefragScreenSaver.exe <Not Verified; J.C. Kessels; JkDefrag>
2008-01-03 14:54:28 69632 --a------ C:\WINDOWS\system32\Contig.exe <Not Verified; Sysinternals; Sysinternals Contig>
2008-01-02 15:33:20 0 d-------- C:\Documents and Settings\LocalService\Application Data\Identities
2008-01-02 11:48:45 215144 -ra------ C:\WINDOWS\patchw32.dll
2008-01-02 11:48:03 215144 -ra------ C:\WINDOWS\pw32a.dll
2008-01-02 11:18:07 0 d-------- C:\Program Files\Symantec
2008-01-02 11:18:07 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-02 10:48:58 0 d-------- C:\Program Files\JkDefrag
2007-12-30 13:16:43 0 d--h----- C:\Program Files\Zero G Registry
2007-12-30 13:10:26 0 dr-h----- C:\Documents and Settings\Rob\Recent
2007-12-29 19:21:22 0 d-------- C:\Documents and Settings\LocalService\Application Data\Acronis
2007-12-29 18:56:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Acronis
2007-12-29 18:53:46 0 d-------- C:\Program Files\Acronis
2007-12-24 08:25:46 12 -r-h----- C:\Documents and Settings\All Users\Application Data\DirectoryService
2007-12-24 08:25:46 268 -r-h----- C:\Documents and Settings\All Users\Application Data\Desktop Pictures
2007-12-20 10:52:57 0 d-------- C:\Program Files\Scriptocean
2007-12-19 09:30:01 0 d-------- C:\Program Files\ACW
2007-12-17 16:13:32 59204 --ah----- C:\WINDOWS\system32\mlfcache.dat
2007-12-17 15:14:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Ashampoo
2007-12-17 15:14:22 0 d-------- C:\Program Files\Ashampoo
2007-12-17 13:43:42 0 d-------- C:\Documents and Settings\Rob\Application Data\Nero
2007-12-17 13:39:38 0 d-------- C:\Program Files\Common Files\Nero
2007-12-17 13:39:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-12-14 14:43:47 0 d-------- C:\Program Files\AVSMedia
2007-12-13 09:02:25 0 d-------- C:\Documents and Settings\Rob\Application Data\ArcSoft
2007-12-13 09:02:08 0 d-------- C:\Program Files\ArcSoft
2007-12-11 23:11:39 0 d--h----- C:\WINDOWS\$hf_mig$
2007-12-10 15:42:20 286720 --a------ C:\WINDOWS\system32\hcwzblast.dll <Not Verified; Zilog; IRblaster>
2007-12-10 15:42:20 65603 --a------ C:\WINDOWS\system32\hcwIRblast.dll <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:40:26 28672 --a------ C:\WINDOWS\system32\hcwsched.dll <Not Verified; Hauppauge Computer Works; HCW Scheduler>
2007-12-10 15:39:18 36921 --a------ C:\WINDOWS\system32\hcwutl32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:39:18 716873 --a------ C:\WINDOWS\system32\hcwtvwnd.dll <Not Verified; Hauppauge Computer Works; HCWTVWND>
2007-12-10 15:39:18 254008 --a------ C:\WINDOWS\system32\hcwpnp32.dll <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:39:18 163840 --a------ C:\WINDOWS\system32\hcwChDB.dll <Not Verified; ; HcwChDB Dynamic Link Library>
2007-12-10 15:39:18 90190 --a------ C:\WINDOWS\system32\Bt848WST.DLL <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:39:06 106559 --a------ C:\WINDOWS\system32\hcwTVDlg.dll <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:39:06 11264 --a------ C:\WINDOWS\system32\hcwhook.dll <Not Verified; Hauppauge Computer Works; HCW hcwhook>
2007-12-10 15:39:06 213050 --a------ C:\WINDOWS\system32\hcwChan.dll <Not Verified; Hauppauge Computer Works; WinTV>
2007-12-10 15:38:59 393216 --a------ C:\WINDOWS\system32\hcwsnbd9.dll <Not Verified; Snowbound Software Corporation (www.Snowbnd.com); SnowBound RasterMaster for NT/W2000>
2007-12-10 15:38:58 98360 --a------ C:\WINDOWS\system32\hcwi2c32.dll <Not Verified; Hauppauge Computer Works, Inc.; WinTV>
-- Find3M Report ---------------------------------------------------------------
2008-01-05 18:01:09 0 d-------- C:\Program Files\WinTV
2008-01-04 23:31:52 0 d-------- C:\Program Files\Quicken
2008-01-03 14:56:47 25992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe <Not Verified; Sysinternals - www.sysinternals.com; Page File Defragmenter>
2008-01-02 13:30:16 0 d-------- C:\Documents and Settings\Rob\Application Data\Symantec
2008-01-02 11:37:49 0 d-------- C:\Program Files\Norton Ghost
2008-01-02 11:18:07 0 d-------- C:\Program Files\Common Files
2008-01-02 11:13:39 0 d-------- C:\Documents and Settings\Rob\Application Data\Azureus
2007-12-29 19:12:23 0 d-------- C:\Program Files\Azureus
2007-12-29 18:59:55 0 d-------- C:\Program Files\DivX
2007-12-24 08:25:46 268 -r-h----- C:\Documents and Settings\Rob\Application Data\Dance
2007-12-19 09:21:09 0 d-------- C:\Program Files\BitPim
2007-12-17 16:12:53 0 d-------- C:\Documents and Settings\Rob\Application Data\Adobe
2007-12-17 13:39:39 0 d-------- C:\Program Files\Nero
2007-12-14 14:47:21 0 d-------- C:\Program Files\Common Files\AVSMedia
2007-12-14 14:41:43 0 d-------- C:\Program Files\Common Files\Download Manager
2007-12-13 09:02:08 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-11 12:15:50 0 d-------- C:\Documents and Settings\Rob\Application Data\Creative
2007-12-09 21:55:10 0 d-------- C:\Documents and Settings\Rob\Application Data\Canon
2007-12-09 12:24:40 0 d-------- C:\Program Files\DVD Decrypter
2007-12-05 12:09:30 0 d-------- C:\Program Files\Wise Disk Cleaner
2007-12-04 15:28:28 0 d-------- C:\Program Files\Common Files\Adobe
2007-12-02 17:41:15 0 d-------- C:\Documents and Settings\Rob\Application Data\Zeon
2007-12-02 17:04:21 0 d-------- C:\Program Files\LG Drivers
2007-12-02 16:57:15 0 d-------- C:\Program Files\LG Electronics
2007-11-22 22:19:33 0 d-------- C:\Documents and Settings\Rob\Application Data\Google
2007-11-14 12:58:06 0 d-------- C:\Program Files\iTunes
2007-11-14 12:57:41 0 d-------- C:\Program Files\iPod
2007-11-14 12:55:22 0 d-------- C:\Program Files\QuickTime
2007-11-14 11:47:32 0 d-------- C:\Program Files\Amara - Slide Show Builder
2007-11-14 11:46:50 0 d-------- C:\Program Files\Amara - News Ticker
2007-11-14 11:46:30 0 d-------- C:\Program Files\Amara - Menu Builder
2007-11-14 11:46:06 0 d-------- C:\Program Files\Amara - Intro and Banner Builder
2007-11-04 17:14:14 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2007-11-04 17:14:14 114688 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions © Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL Library>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 06:20 PM]
"HDSPTray2"="hdspmix.exe.sav" []
"HDSPTray1"="hdsp32.exe.sav" []
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [11/27/2006 03:19 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [12/04/2007 05:00 AM]
"Norton Ghost 12.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe" [10/05/2007 12:33 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/19/2007 08:16 PM]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 09:19 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [10/23/2007 02:18 PM]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [12/21/2007 04:34 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"WIAWizardMenu"=RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ColorVisionStartup.lnk - C:\Program Files\ColorVision\Utility\ColorVisionStartup.exe [1/31/2006 11:23:15 AM]
*Newly Created Service* - VPROEVENTMONITOR
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
-- End of Deckard's System Scanner: finished at 2008-01-06 12:48:55 ------------
Edited by goldberg96, 06 January 2008 - 05:12 PM.