Okay, here are the results. Thanks for the help, by the way.
What's next?
MAIN .TXTDeckard's System Scanner v20071014.68
Run by Nina on 2008-02-08 17:03:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
15: 2008-02-08 06:42:55 UTC - RP98 - Installed Rhapsody Player Engine
14: 2008-02-08 06:37:49 UTC - RP97 - Device Driver Package Install: NCH Swift Sound Sound, video and game controllers
13: 2008-02-08 06:11:15 UTC - RP96 - Removed Rhapsody Player Engine
12: 2008-02-07 20:59:54 UTC - RP95 - Windows Update
11: 2008-02-07 14:52:33 UTC - RP94 - Scheduled Checkpoint
-- First Restore Point --
1: 2008-02-02 04:23:41 UTC - RP83 - Windows Update
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Nina.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:06:00 PM, on 2/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AD Killer\adkiller.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\Nina\Desktop\dss.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcvsshld.exe
C:\Windows\system32\conime.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Nina.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AD Killer] C:\Program Files\AD Killer\adkiller.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {00000000-CB06-433A-9302-77436F840932} - C:\Program Files\AD Killer\adkiller.exe
O9 - Extra 'Tools' menuitem: &AD Killer - {00000000-CB06-433A-9302-77436F840932} - C:\Program Files\AD Killer\adkiller.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 11392 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SASDIFSV - \??\c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - \??\c:\program files\superantispyware\saskutil.sys
R3 NCHSSVAD (SoundTap Recorder) - c:\windows\system32\drivers\nchssvad.sys <Not Verified; NCH Swift Sound; NCH Swift Sound Virtual Audio Device>
R3 SASENUM - \??\c:\program files\superantispyware\sasenum.sys
S3 btwmodem (Bluetooth Modem) - c:\windows\system32\drivers\btwmodem.sys <Not Verified; Broadcom Corporation.; Bluetooth Software 5.1.0.1700>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 Creative Labs Licensing Service - "c:\program files\common files\creative labs shared\service\creativelicensing.exe" <Not Verified; Creative Labs; Creative Labs Licensing Service>
R2 RegSrvc (Intel® PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel® PROSet/Wireless Registry Service>
R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter
S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
-- Scheduled Tasks -------------------------------------------------------------
2008-02-08 16:59:28 416 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{C7F9AEE9-C00E-454D-B760-B440F4F34A40}.job
2008-02-01 01:00:00 348 --a------ C:\Windows\Tasks\McQcTask.job
2008-01-15 20:07:29 356 --a------ C:\Windows\Tasks\McDefragTask.job
-- Files created between 2008-01-08 and 2008-02-08 -----------------------------
2008-02-08 00:43:15 0 d-------- C:\Program Files\Real
2008-02-08 00:37:39 26112 --a------ C:\Windows\system32\drivers\nchssvad.sys <Not Verified; NCH Swift Sound; NCH Swift Sound Virtual Audio Device>
2008-02-08 00:37:36 0 d-------- C:\Program Files\NCH Swift Sound
2008-02-07 23:26:55 0 d-------- C:\Program Files\Microsoft Silverlight
2008-02-05 18:55:32 0 d-------- C:\Users\Nina\.thumbnails <THUMBN~1>
2008-02-02 19:11:59 0 d-------- C:\Program Files\Easy MP3 Sound Recorder
2008-02-02 17:45:03 0 d-------- C:\Users\All Users\NCH Swift Sound
2008-02-01 22:30:33 0 d-------- C:\Program Files\Family Feud
2008-01-30 23:09:29 0 d-------- C:\Users\Nina\.gimp-2.4 <GIMP-2~1.4>
2008-01-30 19:07:17 53248 --a------ C:\Windows\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-01-30 18:21:14 0 d-------- C:\Program Files\Trend Micro
2008-01-29 17:03:51 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-01-29 17:03:37 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-01-29 16:46:10 0 d-------- C:\Users\All Users\Prevx
2008-01-29 09:50:54 0 d-------- C:\Program Files\AD Killer
2008-01-28 23:11:35 0 d-------- C:\Users\All Users\Lavasoft
2008-01-28 23:11:35 0 d-------- C:\Program Files\Lavasoft
2008-01-28 23:10:26 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-28 21:29:02 0 d-------- C:\Program Files\Common Files\Scanner
2008-01-28 21:28:58 0 d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-01-28 21:27:39 0 d-------- C:\Users\All Users\Yahoo! Companion
2008-01-28 21:26:01 0 d-------- C:\Windows\cache
2008-01-26 20:08:26 0 d-------- C:\Users\Nina\Bluetooth Software <BLUETO~1>
2008-01-26 02:33:58 0 dr------- C:\Users\Nina\Contacts
2008-01-26 01:46:21 0 d-------- C:\Program Files\WinFF
2008-01-26 00:52:53 0 d-------- C:\Program Files\WordWeb
2008-01-25 22:00:44 0 d-------- C:\Users\All Users\Sony Online Entertainment
2008-01-25 22:00:44 0 d-------- C:\Program Files\Sony Online Entertainment
2008-01-24 20:40:02 2560 --a------ C:\Windows\_MSRSTRT.EXE
2008-01-24 14:50:29 150528 --a------ C:\Windows\unSpySweeper.exe <Not Verified; Webroot Software, Inc.; >
2008-01-24 14:50:28 0 d-------- C:\Program Files\Webroot
2008-01-24 14:33:02 0 d-------- C:\Users\Nina\Random Files <RANDOM~1>
2008-01-23 12:08:21 0 d-------- C:\Program Files\Common Files\Deterministic Networks
2008-01-23 11:18:24 0 d-------- C:\Program Files\Cisco Systems
2008-01-23 10:42:09 0 d-------- C:\Program Files\MSXML 4.0
2008-01-23 00:42:31 0 d-------- C:\Program Files\WIDCOMM
2008-01-23 00:38:44 0 d-------- C:\Users\All Users\Yahoo!
2008-01-22 23:39:40 0 d-------- C:\Program Files\EA GAMES
2008-01-22 23:39:39 442368 -ra------ C:\Windows\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-01-22 23:29:36 0 d--h----- C:\Windows\msdownld.tmp
2008-01-22 23:29:28 0 d-------- C:\Windows\system32\directx
2008-01-22 23:27:47 0 d-------- C:\Program Files\Yahoo!
2008-01-22 23:22:07 0 d-------- C:\Program Files\iPod
2008-01-22 23:22:04 0 d-------- C:\Program Files\iTunes
2008-01-22 23:21:14 0 d-------- C:\Program Files\Bonjour
2008-01-22 23:20:29 0 d-------- C:\Program Files\QuickTime
2008-01-22 23:20:27 0 d-------- C:\Users\All Users\Apple Computer
2008-01-22 23:20:03 0 d-------- C:\Program Files\Apple Software Update
2008-01-22 23:19:12 0 d-------- C:\Program Files\Common Files\Apple
2008-01-22 23:19:11 0 d-------- C:\Users\All Users\Apple
2008-01-22 23:18:20 0 d-------- C:\Program Files\GIMP-2.0
2008-01-22 21:21:33 0 d-------- C:\Windows\system32\vmm32
2008-01-22 17:47:59 25088 -----n--- C:\Windows\system32\CTSVCCTL.EXE <Not Verified; Creative Technology Ltd; Creative Service Control>
2008-01-22 17:47:58 44032 -----n--- C:\Windows\system32\CTSVCCDA.EXE <Not Verified; Creative Technology Ltd; Creative Service for CDROM Access>
2008-01-22 17:15:37 0 d-------- C:\Intel
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Templates <TEMPLA~1>
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Start Menu <STARTM~1>
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\SendTo
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Recent
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\PrintHood <PRINTH~1>
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\NetHood
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\My Documents <MYDOCU~1>
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Local Settings <LOCALS~1>
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Cookies
2008-01-22 17:14:12 0 d--hs---- C:\Users\Nina\Application Data <APPLIC~1>
2008-01-22 17:14:11 2359296 --ahs---- C:\Users\Nina\NTUSER.DAT
2008-01-22 17:14:11 0 dr------- C:\Users\Nina\Favorites <FAVORI~1>
2008-01-22 17:14:11 0 dr------- C:\Users\Nina\Desktop
2008-01-22 17:14:11 0 d--h----- C:\Users\Nina\AppData
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Templates <TEMPLA~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Start Menu <STARTM~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\SendTo
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Recent
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\PrintHood <PRINTH~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\NetHood
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\My Documents <MYDOCU~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Local Settings <LOCALS~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Cookies
2008-01-22 17:13:29 0 d--hs---- C:\Users\Default\Application Data <APPLIC~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Templates <TEMPLA~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Start Menu <STARTM~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Favorites <FAVORI~1>
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Documents
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Desktop
2008-01-22 17:13:29 0 d--hs---- C:\Users\All Users\Application Data <APPLIC~1>
2008-01-16 03:15:06 0 d-------- C:\Program Files\DellTPad
2008-01-16 03:04:48 0 d-------- C:\Windows\Users
2008-01-16 03:00:12 0 d------c- C:\doctemp
2008-01-16 02:58:26 0 d-------- C:\Windows\system32\oem
2008-01-16 02:58:24 0 d-------- C:\Drivers
2008-01-16 02:58:24 0 d------c- C:\DELL
2008-01-15 20:01:50 0 d-------- C:\Users\All Users\Dell
2008-01-15 19:59:57 0 d-------- C:\Users\All Users\CyberLink
2008-01-15 19:59:20 0 d-------- C:\Program Files\CyberLink
2008-01-15 19:58:58 0 d-------- C:\Users\All Users\SupportSoft
2008-01-15 19:58:33 0 d-------- C:\Program Files\Dell Support Center
2008-01-15 19:58:33 0 d-------- C:\Program Files\Common Files\supportsoft
2008-01-15 19:57:00 143360 --a------ C:\Windows\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-01-15 19:56:07 0 d-------- C:\Program Files\McAfee.com
2008-01-15 19:56:06 0 d-------- C:\Program Files\Common Files\McAfee
2008-01-15 19:56:04 0 d-------- C:\Program Files\McAfee
2008-01-15 19:56:01 0 d-------- C:\Users\All Users\McAfee
2008-01-15 19:55:54 0 d-------- C:\Users\All Users\Google
2008-01-15 19:55:15 0 d-------- C:\Users\All Users\Adobe
2008-01-15 19:55:09 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-15 19:53:36 0 d-------- C:\Program Files\Dell DataSafe Online
2008-01-15 19:52:13 0 d-------- C:\Program Files\Microsoft Works
2008-01-15 19:51:55 0 d-------- C:\Windows\PCHEALTH
2008-01-15 19:51:55 0 d-------- C:\Program Files\Microsoft.NET
2008-01-15 19:50:30 0 d-------- C:\Users\All Users\Microsoft Help
2008-01-15 19:49:47 0 dr-h----- C:\MSOCache
2008-01-15 19:48:02 0 d-------- C:\Users\All Users\Roxio
2008-01-15 19:45:46 0 d-------- C:\Users\All Users\InstallShield
2008-01-15 19:45:31 0 d-------- C:\Users\All Users\Sonic
2008-01-15 19:44:54 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-01-15 19:44:39 0 d-------- C:\Windows\Downloaded Installations
2008-01-15 19:44:31 126976 --a------ C:\Windows\system32\Imsmudlg.exe <Not Verified; Intel® Corporation; Uninstset Installation Utility>
2008-01-15 19:44:31 0 d-------- C:\Windows\system32\ENU
2008-01-15 19:39:13 76 -r-hs---- C:\Windows\CT4CET.bin
2008-01-15 19:37:48 0 d-------- C:\Program Files\Creative Live! Cam
2008-01-15 19:37:33 0 d-------- C:\Program Files\Dell
2008-01-15 19:36:50 0 d-------- C:\Program Files\Intel, Inc
2008-01-15 19:36:38 0 d-------- C:\Users\Default\Roaming
2008-01-15 19:36:20 0 d-------- C:\Users\All Users\Intel
2008-01-15 19:36:17 0 d-------- C:\Program Files\Intel
2008-01-15 19:35:19 0 d-------- C:\Program Files\Common Files\Creative
2008-01-15 19:35:15 0 d--h----- C:\Program Files\Creative Installation Information
2008-01-15 19:35:01 66560 -----n--- C:\Windows\system32\CmdRtr.dll
2008-01-15 19:35:01 101376 -----n--- C:\Windows\system32\APOMngr.dll
2008-01-15 19:35:00 409600 --a------ C:\Windows\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-01-15 19:35:00 114688 --a------ C:\Windows\system32\OpenAL32.dll <Not Verified; Portions © Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL Library>
2008-01-15 19:34:22 0 d-------- C:\Program Files\Creative
2008-01-15 19:34:17 0 d-------- C:\Users\All Users\Creative
2008-01-15 19:34:16 0 d-------- C:\Users\All Users\Creative Labs
2008-01-15 19:34:15 0 d-------- C:\Program Files\Common Files\Creative Labs Shared
2008-01-15 19:33:42 0 d-------- C:\Program Files\Digital Line Detect
2008-01-15 19:33:07 0 d-------- C:\Program Files\NetWaiting
2008-01-15 19:33:03 0 d-------- C:\Program Files\Modem Diagnostic Tool
2008-01-15 19:32:56 0 d-------- C:\Windows\java
2008-01-15 19:32:56 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-15 19:32:54 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-15 19:32:46 0 d-------- C:\Program Files\Java
2008-01-15 19:32:46 0 d-------- C:\Program Files\Common Files\Java
2008-01-15 19:31:52 12 --a------ C:\Windows\bthservsdp.dat
2008-01-15 19:30:42 0 d--hs---- C:\Windows\Installer
2008-01-15 19:29:42 0 d-------- C:\Windows\system32\Macromed
2008-01-15 19:21:58 0 d-------- C:\Windows\SoftwareDistribution
2008-01-15 19:21:16 0 d-------- C:\Program Files\CONEXANT
2008-01-15 19:21:03 0 d-------- C:\Program Files\Sigmatel
2008-01-15 19:19:55 0 d--hs---- C:\System Volume Information
-- Find3M Report ---------------------------------------------------------------
2008-02-08 00:37:36 0 d-------- C:\Users\Nina\AppData\Roaming\NCH Swift Sound
2008-02-05 18:55:36 0 d-------- C:\Users\Nina\AppData\Roaming\gtk-2.0
2008-02-02 19:56:36 0 d-------- C:\Users\Nina\AppData\Roaming\Creative
2008-02-02 18:01:41 0 d-------- C:\Users\Nina\AppData\Roaming\InstallShield
2008-02-02 17:45:19 0 d-------- C:\Users\Nina\AppData\Roaming\Recordpad
2008-01-29 17:03:37 0 d-------- C:\Users\Nina\AppData\Roaming\SUPERAntiSpyware.com
2008-01-29 16:46:51 0 d-------- C:\Users\Nina\AppData\Roaming\PrevxCSI
2008-01-28 23:10:26 0 d-------- C:\Program Files\Common Files
2008-01-28 21:39:18 0 d-------- C:\Program Files\Windows Mail
2008-01-28 21:27:39 0 d-------- C:\Users\Nina\AppData\Roaming\Yahoo!
2008-01-27 04:23:17 0 d-------- C:\Users\Nina\AppData\Roaming\Tunebite
2008-01-26 16:05:29 0 d-------- C:\Users\Nina\AppData\Roaming\LimeWire
2008-01-26 01:46:26 0 d-------- C:\Users\Nina\AppData\Roaming\Winff
2008-01-24 20:18:57 0 d-------- C:\Users\Nina\AppData\Roaming\Real
2008-01-24 00:47:44 0 d-------- C:\Users\Nina\AppData\Roaming\Adobe
2008-01-23 19:45:44 0 d-------- C:\Users\Nina\AppData\Roaming\CyberLink
2008-01-23 10:49:58 0 d-------- C:\Program Files\Windows Sidebar
2008-01-23 10:48:46 0 d-------- C:\Users\Nina\AppData\Roaming\Roxio
2008-01-22 23:22:24 0 d-------- C:\Users\Nina\AppData\Roaming\Apple Computer
2008-01-22 23:02:15 0 d-------- C:\Users\Nina\AppData\Roaming\Earthlink
2008-01-22 21:17:48 0 d-------- C:\Users\Nina\AppData\Roaming\Intel
2008-01-22 20:59:34 0 d-------- C:\Users\Nina\AppData\Roaming\Google
2008-01-22 20:57:13 0 d-------- C:\Users\Nina\AppData\Roaming\Macromedia
2008-01-22 17:15:06 0 d-------- C:\Users\Nina\AppData\Roaming\Identities
2008-01-16 03:10:26 0 d-------- C:\Program Files\Windows Calendar
2008-01-16 03:07:05 0 d-------- C:\Program Files\Windows Defender
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
10/01/2007 07:55 AM 329024 --a------ c:\PROGRA~1\mcafee\msk\mcapbho.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [01/16/2008 03:07 AM]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [09/07/2007 12:49 AM]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [08/27/2007 11:51 PM]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [11/12/2007 05:07 AM]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [12/14/2007 09:54 PM]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [12/14/2007 09:53 PM]
"Persistence"="C:\Windows\system32\igfxpers.exe" [12/14/2007 09:53 PM]
"Windows Mobile Device Center"="%windir%\WindowsMobile\wmdc.exe" []
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [07/27/2007 04:43 PM]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [03/21/2007 01:00 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
"@"="" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 07:51 PM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [08/03/2007 10:33 PM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [10/09/2007 06:57 PM]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [11/01/2007 03:39 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/10/2008 03:27 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 03:22 AM]
"AD Killer"="C:\Program Files\AD Killer\adkiller.exe" [05/05/2003 07:26 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [10/09/2007 06:56 PM]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [11/02/2006 06:35 AM]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [02/25/2004 11:48 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/23/2008 10:45 AM]
C:\Users\Nina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [10/26/2006 8:24:54 PM]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [1/26/2008 12:52:55 AM]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [6/7/2006 5:05:38 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [1/15/2008 7:34:02 PM]
VPN Client.lnk - C:\Windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [1/23/2008 12:11:09 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs BthServ
WindowsMobile wcescomm rapimgr
LocalServiceRestricted WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-02-08 17:07:44 ------------
Edited by allsmiles, 08 February 2008 - 05:19 PM.