OTMoveIt:C:\Windows\system32\drivers\ipfltdrvv.sys moved successfully.
[Custom Input]
< purity >
OTMoveIt2 v1.0.17 log created on 02042008_222807
MainDeckard's System Scanner v20071014.68
Run by Compaq_Owner on 2008-02-04 22:39:50
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
10: 2008-02-03 10:20:37 UTC - RP67 - Installed Adobe Reader 8.1.1
9: 2008-02-03 07:52:46 UTC - RP66 - Before Adobe uninstall
8: 2008-02-03 07:49:07 UTC - RP65 - Installed Windows Installer Clean Up
7: 2008-02-03 07:42:51 UTC - RP64 - Removed Adobe Reader 7.0.5
6: 2008-02-03 03:26:41 UTC - RP63 - Removed Adobe Reader 7.0.5
-- First Restore Point --
1: 2008-02-01 18:06:20 UTC - RP58 - Installed Java 6 Update 4
Performed disk cleanup.
Percentage of Memory in Use: 90% (more than 75%).Total Physical Memory: 1023 MiB (1024 MiB recommended).-- HijackThis (run as Compaq_Owner.exe) ----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41, on 2008-02-04
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
G:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
G:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Windows\system32\svchost.exe
G:\Program Files\Spyware Doctor\svcntaux.exe
G:\Program Files\Spyware Doctor\swdsvc.exe
G:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\Windows\system32\svchost.exe
G:\Program Files\ThreatFire\TFService.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
G:\Program Files\Gmail Notifier\gnotify.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Windows\System32\rundll32.exe
G:\Program Files\ThreatFire\TFTray.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
G:\Program Files\Mindjet\MindManager 6\MmReminderService.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
G:\Program Files\D-Link\Bluetooth Software\BTTray.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Media Player\setup_wm.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Compaq_Owner\Desktop\dss.exe
C:\HP\KBD\KBD.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe
G:\PROGRA~1\TRENDM~1\HIJACK~1\COMPAQ~1.EXE
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.h...a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotmail.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CmjBrowserHelperObject Object - {AC41D38F-B56D-40AD-94E0-B493D130C959} - G:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "G:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] G:\Program Files\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "G:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ThreatFire] G:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MMReminderService] G:\Program Files\Mindjet\MindManager 6\MMReminderService.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [uTorrent] "G:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [µTorrent] "G:\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = G:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: Download with GetRight - G:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - G:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send To &Bluetooth - G:\Program Files\D-Link\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - G:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - G:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - G:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - G:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {040F4385-8DAD-4306-94BF-B8291D841FAE} (USBAPTester Class) -
http://www.nintendo....a/usbaptest.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) -
http://www.windowsvi...iveXClient1.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cabO16 - DPF: {F4AF4B32-1AF4-4773-B1A3-75C699A1CB5D} (webSysInfo.ctlSysInfo) -
http://dev.cite.nie..../webSysInfo.ocxO20 - Winlogon Notify: !SASWinLogon - G:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - G:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Fix-It Task Manager - Avanquest Publishing USA, Inc. - G:\PROGRA~1\VCOM\Fix-It\mxtask.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - G:\Program Files\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - G:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - G:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: ThreatFire - PC Tools - G:\Program Files\ThreatFire\TFService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 15000 bytes
-- HijackThis Fixed Entries (G:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080202-010648-104 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080204-222415-590 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>
R1 SASDIFSV - \??\g:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - \??\g:\program files\superantispyware\saskutil.sys
R2 BTSERIAL (Bluetooth Serial Driver) - \??\c:\windows\system32\drivers\btserial.sys
R2 BTSLBCSP (Bluetooth Port Client Driver) - \??\c:\windows\system32\drivers\btslbcsp.sys
R2 MDC8021X (AEGIS Protocol (IEEE 802.1x) v2.3.1.9) - c:\windows\system32\drivers\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.9>
S3 SASENUM - \??\g:\program files\superantispyware\sasenum.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >
S3 NBService - g:\program files\nero 7\nero backitup\nbservice.exe
S3 WLSetupSvc (Windows Live Setup Service) - "c:\program files\windows live\installer\wlsetupsvc.exe" <Not Verified; Microsoft Corporation; Windows Live installer>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Process Modules -------------------------------------------------------------
C:\Windows\explorer.exe (pid 224)
2005-07-26 14:24:56 1019981 --a------ C:\Windows\System32\BTNeighborhood.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.2303>
2005-07-26 14:07:52 565309 --a------ C:\Windows\System32\wbtapi.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.2303>
2005-07-26 14:16:46 45056 --a------ C:\Windows\System32\btwpimif.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.2303>
2005-07-26 14:16:06 118784 --a------ C:\Windows\System32\btosif.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.2303>
2005-07-26 14:10:30 3096576 --a------ C:\Windows\System32\btrez.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.2303>
2004-09-17 13:55:20 50176 --a------ C:\Windows\System32\CSH.DLL <Not Verified; Blue Sky Software Corporation; What's This? Help Composer>
2007-01-29 13:06:14 28672 --a------ G:\Program Files\VCOM\Fix-It\WinHook.dll <Not Verified; Avanquest Publishing USA, Inc.; Fix-It Utilities>
-- :: 0 --------- C:\Users\COMPAQ~1\AppData\Local\Temp\IadHide5.dll
C:\Windows\System32\rundll32.exe (pid 3564)
2007-01-29 13:06:14 28672 --a------ G:\Program Files\VCOM\Fix-It\WinHook.dll <Not Verified; Avanquest Publishing USA, Inc.; Fix-It Utilities>
C:\Windows\System32\rundll32.exe (pid 3612)
2007-01-29 13:06:14 28672 --a------ G:\Program Files\VCOM\Fix-It\WinHook.dll <Not Verified; Avanquest Publishing USA, Inc.; Fix-It Utilities>
-- Scheduled Tasks -------------------------------------------------------------
2008-02-04 22:34:00 452 --a------ C:\Windows\Tasks\RegCure Program Check.job
2008-02-01 01:01:48 370 --a------ C:\Windows\Tasks\McQcTask.job
2008-01-22 16:59:02 386 --a------ C:\Windows\Tasks\RegCure.job
2008-01-04 11:40:04 284 --a------ C:\Windows\Tasks\AppleSoftwareUpdate.job
2007-09-15 01:00:08 278 --a------ C:\Windows\Tasks\McDefragTask.job
-- Files created between 2008-01-04 and 2008-02-04 -----------------------------
2008-02-04 01:28:32 68096 --a------ C:\Windows\system32\zip.exe
2008-02-04 01:28:32 98816 --a------ C:\Windows\system32\sed.exe
2008-02-04 01:28:32 80412 --a------ C:\Windows\system32\grep.exe
2008-02-04 01:28:32 73728 --a------ C:\Windows\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-03 15:49:34 0 d-------- C:\Program Files\Windows Installer Clean Up
2008-02-03 15:48:39 0 d-------- C:\Program Files\MSECACHE
2008-02-03 13:06:11 0 d-------- C:\Users\All Users\PC Tools
2008-02-03 12:49:57 0 d-a------ C:\Users\All Users\TEMP
2008-02-02 11:57:11 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-02-02 03:05:24 53248 --a------ C:\Windows\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-02-02 01:42:55 0 d-------- C:\Users\Compaq_Owner\.SunDownloadManager
2008-01-28 20:01:22 0 d-------- C:\Windows\pss
2008-01-28 19:32:14 0 d-------- C:\Users\All Users\Grisoft
2008-01-27 21:10:12 0 d-------- C:\VundoFix Backups
2008-01-16 23:26:38 0 d--h----- C:\_Backup
2008-01-16 23:24:23 0 d-------- C:\Users\All Users\VCOM
2008-01-16 23:20:51 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 19:51:58 0 d-------- C:\Users\All Users\NVIDIA
2008-01-16 15:27:40 0 d-------- C:\Windows\Panther
2008-01-16 15:27:22 94208 --a------ C:\Windows\system32\ipcoin5.dll <Not Verified; Microsoft Corporation; Microsoft IntelliPoint>
2008-01-16 15:27:22 20352 --a------ C:\Windows\system32\drivers\point32.sys <Not Verified; Microsoft Corporation; Microsoft IntelliPoint>
2008-01-16 15:27:21 94208 --a------ C:\Windows\system32\itpcoin4.dll <Not Verified; Microsoft Corporation; Microsoft IntelliType Pro>
2008-01-16 15:16:46 0 d--h----- C:\$WINDOWS.~Q
2008-01-16 15:13:27 0 d--h----- C:\$INPLACE.~TR
2008-01-16 13:23:32 0 d-------- C:\Users\All Users\DFX
2008-01-16 01:05:08 0 d--h----- C:\Users\All Users\CanonBJ
2008-01-16 00:50:13 0 d-------- C:\Program Files\Microsoft IntelliType Pro
2008-01-16 00:44:06 0 d-------- C:\Program Files\Microsoft IntelliPoint
2008-01-16 00:43:12 0 d-------- C:\Windows\PCHEALTH
2008-01-16 00:23:56 0 dr------- C:\Users\Compaq_Owner\Searches
2008-01-16 00:10:14 22732 --a------ C:\Windows\system32\emptyregdb.dat
2008-01-16 00:02:20 0 d-------- C:\Users\Default\WINDOWS
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Videos
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\Templates
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\Start Menu
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\SendTo
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Saved Games
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\Recent
2008-01-15 23:40:47 0 d--h----- C:\Users\Compaq_Owner\PrintHood
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Pictures
2008-01-15 23:40:47 5242880 --ahs---- C:\Users\Compaq_Owner\NTUSER.DAT
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\NetHood
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\My Documents
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Music
2008-01-15 23:40:47 0 d--h----- C:\Users\Compaq_Owner\Local Settings
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Links
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Favorites
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Downloads
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Documents <DOCUME~1>
2008-01-15 23:40:47 0 dr------- C:\Users\Compaq_Owner\Desktop
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\Cookies
2008-01-15 23:40:47 0 d--hs---- C:\Users\Compaq_Owner\Application Data
2008-01-15 23:40:47 0 d--h----- C:\Users\Compaq_Owner\AppData
2008-01-15 23:39:26 0 d-------- C:\Windows\system32\URTTEMP
2008-01-15 23:39:18 0 d--hs---- C:\Windows\Installer
2008-01-15 23:34:50 0 d-------- C:\Windows\system32\RTCOM
2008-01-15 23:33:15 0 d-------- C:\Windows\Debug
2008-01-15 23:29:12 0 d-------- C:\Windows\Prefetch
2008-01-15 23:07:22 0 d--hs---- C:\Boot
2008-01-05 21:29:07 0 d-------- C:\Users\All Users\GlobalSCAPE
2008-01-05 21:14:34 545 --a------ C:\Windows\UC.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\RAR.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\PKZIP.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\PKUNZIP.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\NOCLOSE.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\LHA.PIF
2008-01-05 21:14:34 545 --a------ C:\Windows\ARJ.PIF
2008-01-04 10:27:47 64752 --ah----- C:\Windows\system32\mlfcache.dat
-- Find3M Report ---------------------------------------------------------------
2008-02-04 22:36:07 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\uTorrent
2008-02-03 18:22:30 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-03 12:49:30 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\PC Tools
2008-02-02 11:56:32 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\SUPERAntiSpyware.com
2008-02-02 03:03:25 0 d-------- C:\Program Files\Google
2008-02-02 02:07:42 0 d-------- C:\Program Files\Java
2008-01-27 15:55:24 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\BSplayer Pro
2008-01-20 10:53:13 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Thinstall
2008-01-16 23:20:51 0 d-------- C:\Program Files\Common Files
2008-01-16 19:17:01 174 --ahs---- C:\Program Files\desktop.ini
2008-01-16 19:10:53 0 d-------- C:\Program Files\Windows Calendar
2008-01-16 19:10:50 0 d-------- C:\Program Files\Windows Mail
2008-01-16 19:10:47 0 d-------- C:\Program Files\Windows Defender
2008-01-16 19:10:31 0 d-------- C:\Program Files\Windows Sidebar
2008-01-16 16:00:45 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\ZoomBrowser EX
2008-01-16 15:13:56 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-16 00:17:22 0 d-------- C:\Program Files\McAfee
2008-01-15 23:59:42 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Windows Desktop Search
2008-01-15 23:59:42 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\WinBatch
2008-01-15 23:59:42 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\vlc
2008-01-15 23:59:42 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\VCOM
2008-01-15 23:59:41 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\U3
2008-01-15 23:59:41 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Teleca
2008-01-15 23:59:41 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Talkback
2008-01-15 23:59:03 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Sun
2008-01-15 23:59:03 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Sony Ericsson
2008-01-15 23:59:03 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\SmartDraw
2008-01-15 23:59:02 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\SiteAdvisor
2008-01-15 23:59:02 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Screenshot Sender
2008-01-15 23:59:02 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Real
2008-01-15 23:58:59 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\OpenOffice.org2
2008-01-15 23:58:58 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Mozilla
2008-01-15 23:58:52 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Media Player Classic
2008-01-15 23:58:52 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\McAfee
2008-01-15 23:58:52 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Macromedia
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Identities
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\HPQ
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Google
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\GlobalSCAPE
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\GetRightToGo
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\CyberLink
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Canon
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Avanquest
2008-01-15 23:58:46 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Apple Computer
2008-01-15 23:58:44 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Ahead
2008-01-15 23:58:44 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\AdobeUM
2008-01-15 23:58:44 0 d-------- C:\Users\Compaq_Owner\AppData\Roaming\Adobe
2008-01-15 23:47:57 0 d-------- C:\Program Files\Yahoo!
2008-01-15 23:47:55 0 d-------- C:\Program Files\Windows Live
2008-01-15 23:47:55 0 d-------- C:\Program Files\Tracker Software
2008-01-15 23:47:55 0 d-------- C:\Program Files\SystemRequirementsLab
2008-01-15 23:47:55 0 d-------- C:\Program Files\Symantec
2008-01-15 23:47:54 0 d-------- C:\Program Files\Sunbelt Software
2008-01-15 23:47:48 0 d-------- C:\Program Files\Sonic
2008-01-15 23:47:43 0 d-------- C:\Program Files\SiteAdvisor
2008-01-15 23:47:38 0 d-------- C:\Program Files\Real
2008-01-15 23:47:38 0 d-------- C:\Program Files\QuickTime
2008-01-15 23:47:28 0 d-------- C:\Program Files\PowerQuest
2008-01-15 23:47:28 0 d-------- C:\Program Files\PC-Doctor for DOS
2008-01-15 23:47:28 0 d-------- C:\Program Files\PC-Doctor 5 for Windows
2008-01-15 23:47:09 0 d-------- C:\Program Files\Online Services
2008-01-15 23:47:05 0 d-------- C:\Program Files\Oberon Media
2008-01-15 23:45:55 0 d-------- C:\Program Files\MSXML 6.0
2008-01-15 23:45:55 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-15 23:45:54 0 d-------- C:\Program Files\Microsoft.NET
2008-01-15 23:45:54 0 d-------- C:\Program Files\Microsoft Works
2008-01-15 23:45:54 0 d-------- C:\Program Files\microsoft frontpage
2008-01-15 23:45:54 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-15 23:45:54 0 d-------- C:\Program Files\McAfee.com
2008-01-15 23:45:22 0 d-------- C:\Program Files\iPod
2008-01-15 23:45:16 0 d-------- C:\Program Files\InterActual
2008-01-15 23:45:14 0 d-------- C:\Program Files\HP
2008-01-15 23:44:50 0 d-------- C:\Program Files\Hewlett-Packard
2008-01-15 23:44:42 0 d-------- C:\Program Files\Escntl
2008-01-15 23:44:39 0 d-------- C:\Program Files\CONEXANT
2008-01-15 23:44:35 0 d-------- C:\Program Files\Compaq Connections
2008-01-15 23:44:35 0 d-------- C:\Program Files\Common Files\xing shared
2008-01-15 23:44:35 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-15 23:44:34 0 d-------- C:\Program Files\Common Files\TiVo Shared
2008-01-15 23:44:34 0 d-------- C:\Program Files\Common Files\Teleca Shared
2008-01-15 23:44:33 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-15 23:44:33 0 d-------- C:\Program Files\Common Files\SureThing Shared
2008-01-15 23:44:33 0 d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-01-15 23:44:31 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-01-15 23:44:31 0 d-------- C:\Program Files\Common Files\Real
2008-01-15 23:44:29 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-15 23:44:29 0 d-------- C:\Program Files\Common Files\Oberon Media
2008-01-15 23:44:29 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-15 23:44:23 0 d-------- C:\Program Files\Common Files\McAfee
2008-01-15 23:44:23 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-01-15 23:44:23 0 d-a------ C:\Program Files\Common Files\LS Getting Started
2008-01-15 23:44:23 0 d-a------ C:\Program Files\Common Files\LightScribe
2008-01-15 23:44:22 0 d-------- C:\Program Files\Common Files\Java
2008-01-15 23:44:22 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-15 23:44:21 0 d-------- C:\Program Files\Common Files\HP
2008-01-15 23:44:20 0 d-------- C:\Program Files\Common Files\Canon
2008-01-15 23:44:09 0 d-------- C:\Program Files\Common Files\Apple
2008-01-15 23:44:09 0 d-------- C:\Program Files\Common Files\Ahead
2008-01-15 23:44:06 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-01-15 23:43:57 0 d-------- C:\Program Files\Canon
2008-01-15 23:43:57 0 d-------- C:\Program Files\AviSynth 2.5
2008-01-15 23:43:54 0 d-------- C:\Program Files\Apple Software Update
2007-12-18 13:06:09 203264 --a------ C:\Windows\system32\Žž–Y‚ę‚Ě–Ŕ‹{XNŠ[“Z[o[.scr <Not Verified; FIVESTAR interactive; ScreenTime For Flash>
2007-12-16 08:07:20 4096 --a------ C:\Windows\d3dx.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-16 17:19]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 20:34]
"iTunesHelper"="G:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 20:14]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2006-07-25 04:28]
"Sony Ericsson PC Suite"="G:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-28 01:07]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="G:\Program Files\Gmail Notifier\gnotify.exe" [2005-07-16 05:48]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 17:08]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-08-28 01:59]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-08-28 01:59]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-08-28 01:59]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 05:52 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42]
"SDTray"="G:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]
"ThreatFire"="G:\Program Files\ThreatFire\TFTray.exe" [2007-12-20 11:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-09-18 19:43]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40]
"MMReminderService"="G:\Program Files\Mindjet\MindManager 6\MMReminderService.exe" [2006-08-16 17:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-16 16:56]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-11-02 17:45]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"pdfSaver3"="C:\Program Files\Tracker Software\PDF-XChange 3\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20]
"uTorrent"="G:\Program Files\uTorrent\utorrent.exe" [2007-10-03 15:42]
"µTorrent"="G:\Program Files\uTorrent\uTorrent.exe" [2007-10-03 15:42]
C:\Users\Compaq_Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
OneNote 2007 Screen Clipper and Launcher.lnk - G:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - G:\Program Files\D-Link\Bluetooth Software\BTTray.exe [2005-07-26 14:28:52]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-09-18 20:03:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
G:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 G:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
WudfServiceGroup WUDFSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-02-04 22:45:12 ------------