Deckard's System Scanner v20071014.68
Run by Clive on 2008-02-09 21:57:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
17: 2008-02-09 21:58:01 UTC - RP205 - Deckard's System Scanner Restore Point
16: 2008-02-09 04:46:58 UTC - RP204 - Installed PL-2303 USB-to-Serial
15: 2008-02-07 10:26:15 UTC - RP203 - System Checkpoint
14: 2008-02-05 17:15:42 UTC - RP202 - Removed Zoom ADSL USB Modem
13: 2008-02-04 22:37:18 UTC - RP201 - RegCure Backup
-- First Restore Point --
1: 2008-02-02 11:34:41 UTC - RP189 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Clive.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:11, on 09/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\Super Antispy\SUPERAntiSpyware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Clive\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Clive.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://g.msn.co.uk/0...S01?FORM=TOOLBRR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.ukR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.yahoo.co.ukR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.ukR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.EXE /P17 "EPSON PictureMate" /O6 "USB002" /M "PictureMate"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVDtoiPodConverter_upgrade] "C:\Program Files\E-Zsoft\DVDtoiPodConverter\DVDtoiPodConverter.exe" /upgrade
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] F:\Super Antispy\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -
https://support.micr...veX/MSDcode.cabO16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) -
http://support.f-sec...m/ols/fscax.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {29710C4C-4F0F-4A36-8312-CB5614829804} (DriverDetectiveNonMembers.nonmembers) -
http://www.drivershq...etective-nm.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase8300.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1188826928031O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.co.../sysreqlab2.cabO16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1188826913781O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.co...iaSmartScan.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) -
http://www.autodesk....ViewerSetup.cabO16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1....loadManager.ocxO16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://www.driverage...driveragent.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logme...trl.cab?lmi=100O20 - Winlogon Notify: !SASWinLogon - F:\Super Antispy\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VideoAcceleratorEngine - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
--
End of file - 11472 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080203-023721-933 O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 AsIO - c:\windows\system32\drivers\asio.sys
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 SASDIFSV - f:\super antispy\sasdifsv.sys
R1 SASKUTIL - f:\super antispy\saskutil.sys
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R2 MaVctrl - c:\windows\system32\drivers\mavc2k.sys <Not Verified; Mobile Action Technology Inc.; Handset Manager>
R2 sbbotdi - c:\program files\speedbit video accelerator\sbbotdi.sys <Not Verified; SpeedBit Ltd.; Speedbit TDI Driver>
R3 SASENUM - f:\super antispy\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S1 AmdK8 (AMD Processor Driver) - c:\windows\system32\drivers\amdk8.sys (file missing)
S2 ADILOADER (General Purpose USB Driver (adildr.sys)) - c:\windows\system32\drivers\adildr.sys (file missing)
S2 ASInsHelp - c:\windows\system32\drivers\asinshelp32.sys (file missing)
S2 CSS DVP - c:\windows\system32\drivers\css-dvp.sys (file missing)
S3 adiusbaw (USB ADSL WAN Adapter) - c:\windows\system32\drivers\adiusbaw.sys (file missing)
S3 alcan5wn (SpeedTouch USB ADSL PPP Networking Driver (NDISWAN)) - c:\windows\system32\drivers\alcan5wn.sys <Not Verified; THOMSON; SpeedTouch USB>
S3 alcaudsl (SpeedTouch ADSL Modem ATM Transport) - c:\windows\system32\drivers\alcaudsl.sys <Not Verified; THOMSON; SpeedTouch USB>
S3 BLKWGU(Belkin) (Belkin Wireless G USB Network Adapter(Belkin)) - c:\windows\system32\drivers\blkwgu.sys (file missing)
S3 catchme - c:\docume~1\clive\locals~1\temp\catchme.sys (file missing)
S3 D500M - c:\windows\system32\drivers\d500m.sys <Not Verified; Mobile Action Technology Inc.; Handset Manager>
S3 D500U - c:\windows\system32\drivers\d500u.sys <Not Verified; Mobile Action Technology Inc.; Handset Manager>
S3 ddxgb - c:\docume~1\clive\locals~1\temp\ddxgb.sys (file missing)
S3 ENTECH - c:\windows\system32\drivers\entech.sys (file missing)
S3 MaRdPnp - c:\windows\system32\drivers\mardp2k.sys <Not Verified; Mobile Action Technology Inc.; Handset Manager>
S3 pepifilter (Volume Adapter) - c:\windows\system32\drivers\lv302af.sys (file missing)
S3 PID_08A0 (Labtec WebCam Pro(PID_08A0)) - c:\windows\system32\drivers\lv302av.sys (file missing)
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
S4 bgsvcgen (B's Recorder GOLD Library General Service) - c:\windows\system32\bgsvcgen.exe <Not Verified; B.H.A Corporation; B's Recorder GOLD8>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-09 21:46:21 422 --ah----- C:\WINDOWS\Tasks\User_Feed_Synchronization-{74E2B50E-8BF4-45D9-89C4-D788AF61B4F0}.job
2008-02-09 21:10:00 254 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-02-09 17:00:00 448 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-02-09 17:00:00 438 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2008-01-04 19:02:04 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-11-19 09:45:17 362 --a------ C:\WINDOWS\Tasks\XoftSpySE.job
2007-11-19 09:45:17 372 --a------ C:\WINDOWS\Tasks\RegCure.job
-- Files created between 2008-01-09 and 2008-02-09 -----------------------------
2008-02-03 12:26:49 0 d-------- C:\Program Files\Alwil Software
2008-02-03 09:39:13 0 dr-h----- C:\Documents and Settings\Clive\Recent
2008-02-03 06:45:57 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-02-03 04:15:10 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-03 04:15:04 0 d-------- C:\Documents and Settings\Clive\Application Data\SUPERAntiSpyware.com
2008-02-03 03:25:05 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-02-03 03:11:53 0 d-------- C:\Documents and Settings\Clive\Application Data\Grisoft
2008-02-03 03:11:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-03 02:34:11 0 d-------- C:\Program Files\Trend Micro
2008-02-03 02:02:46 0 d--h----- C:\WINDOWS\system32\GroupPolicy
2008-02-03 01:24:57 0 d-------- C:\WINDOWS\ERUNT
2008-02-03 00:55:57 0 d-------- C:\Program Files\Microsoft Silverlight
2008-01-24 14:11:03 0 d-------- C:\Program Files\ImTOO
2008-01-24 12:13:28 0 d-------- C:\Program Files\iPod
2008-01-24 12:13:23 0 d-------- C:\Program Files\iTunes
2008-01-20 16:46:50 0 d-------- C:\Program Files\Any Video Converter
2008-01-20 16:34:04 0 d-------- C:\Program Files\Bonjour
2008-01-20 15:51:28 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-20 14:38:48 0 d-------- C:\Program Files\PQDVD
2008-01-19 20:05:12 0 -----n--- C:\WINDOWS\hpimdl01.dat
2008-01-19 20:05:12 47796 --a------ C:\WINDOWS\hpiins01.dat
2008-01-19 19:58:48 0 d-------- C:\Program Files\My Company Name
2008-01-19 19:36:46 0 d-------- C:\Program Files\Hewlett Packard
2008-01-19 19:36:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-19 18:42:25 0 d-------- C:\Program Files\Free iPod Video Converter
2008-01-18 23:13:01 0 d-------- C:\E-Zsoft
2008-01-18 23:12:06 0 d-------- C:\Program Files\E-Zsoft
2008-01-18 16:04:26 164352 --a------ C:\WINDOWS\system32\unrar.dll
2008-01-18 16:04:24 217088 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-01-18 16:04:24 564224 --a------ C:\WINDOWS\system32\x264vfw.dll
2008-01-18 16:04:24 39936 --a------ C:\WINDOWS\system32\huffyuv.dll <Not Verified; Disappearing Inc.; Huffyuv>
2008-01-18 16:04:23 282624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-01-18 16:04:23 1559040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-01-18 16:04:23 630784 --a------ C:\WINDOWS\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2008-01-18 16:04:23 438272 --a------ C:\WINDOWS\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-01-18 16:04:22 682496 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-18 16:04:21 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-01-18 16:04:20 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-01-18 16:04:20 0 d-------- C:\Documents and Settings\Clive\Application Data\Real
2008-01-18 16:04:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Real
2008-01-15 15:16:27 0 d-------- C:\Program Files\Kontiki
2008-01-15 15:16:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-01-09 21:54:54 0 d-------- C:\Documents and Settings\Clive\Application Data\Media Player Classic
2008-01-09 18:02:01 0 d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-01-09 18:01:47 0 d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-01-09 18:01:41 0 d-------- C:\Program Files\NCH Software
2008-01-09 18:00:27 0 d-------- C:\Program Files\NCH Swift Sound
2008-01-09 18:00:27 0 d-------- C:\Documents and Settings\Clive\Application Data\NCH Swift Sound
-- Find3M Report ---------------------------------------------------------------
2008-02-09 04:45:06 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-02-04 22:33:07 0 d-------- C:\Program Files\RegScrubXP
2008-02-03 12:26:02 0 d-------- C:\Program Files\Virgin Broadband
2008-02-03 12:25:35 0 d-------- C:\Documents and Settings\Clive\Application Data\Virgin Broadband
2008-02-03 12:25:34 0 d-------- C:\Program Files\Common Files\PestPatrol
2008-02-03 12:25:31 0 d-------- C:\Program Files\Common Files\Command Software
2008-02-03 10:12:27 0 d-------- C:\Program Files\Talex update utility
2008-02-03 07:29:25 0 d-------- C:\Program Files\Windows Live Toolbar
2008-02-03 07:24:22 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-02-03 07:24:17 0 d-------- C:\Program Files\LogMeIn
2008-02-03 07:17:34 0 d-------- C:\Program Files\DAP
2008-02-03 06:38:04 0 d-------- C:\Program Files\fsupport
2008-02-03 00:45:09 0 d-------- C:\Program Files\XoftSpySE
2008-02-01 16:02:09 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-01-26 17:45:07 0 d-------- C:\Program Files\SAMSUNG
2008-01-26 17:45:07 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-26 17:39:27 0 d-------- C:\Documents and Settings\Clive\Application Data\Samsung
2008-01-24 12:13:56 0 d-------- C:\Documents and Settings\Clive\Application Data\Apple Computer
2008-01-19 20:10:26 0 d-------- C:\Program Files\HP
2008-01-19 19:58:48 0 d-------- C:\Program Files\Common Files\HP
2008-01-19 19:57:56 0 d-------- C:\Program Files\Hewlett-Packard
2008-01-19 19:36:36 0 d-------- C:\Program Files\Common Files
2008-01-19 18:19:36 0 d-------- C:\Program Files\DivX
2008-01-18 17:52:09 0 d-------- C:\Program Files\Google
2008-01-18 11:47:30 0 d-------- C:\Program Files\QuickTime
2008-01-15 15:16:59 0 d-------- C:\Documents and Settings\Clive\Application Data\Kontiki
2008-01-15 15:16:58 0 d-------- C:\Program Files\KService
2008-01-13 14:24:07 0 d-------- C:\Documents and Settings\Clive\Application Data\Adobe
2008-01-07 10:26:50 0 d-------- C:\Program Files\SpeedBit Video Accelerator
2008-01-05 15:47:58 0 d-------- C:\Program Files\Avex
2008-01-05 15:19:15 0 d-------- C:\Documents and Settings\Clive\Application Data\dvdcss
2008-01-04 19:02:00 0 d-------- C:\Program Files\Apple Software Update
2008-01-04 19:01:36 0 d-------- C:\Program Files\Common Files\Apple
2007-12-30 11:37:07 0 d-------- C:\Program Files\FinePixViewer
2007-12-30 10:52:11 0 d-------- C:\Program Files\PIXELA
2007-12-30 10:51:28 0 d-------- C:\Documents and Settings\Clive\Application Data\FUJIFILM
2007-12-30 10:47:17 0 d-------- C:\Documents and Settings\Clive\Application Data\InstallShield
2007-12-19 15:44:01 0 d-------- C:\Program Files\Paragon Software
2007-11-19 09:36:57 23392 --a------ C:\WINDOWS\system32\emptyregdb.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 00:11]
"PCguard"="C:\Program Files\Virgin Broadband\PCguard\Rps.exe" [24/01/2007 17:53]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [09/07/2001 10:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [09/08/2004 05:03]
"EPSON PictureMate"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0P1.exe" [10/10/2003 03:00]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [17/11/2006 15:49]
"Logitech Utility"="Logi_MwX.Exe" [17/12/2003 08:50 C:\WINDOWS\LOGI_MWX.EXE]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [17/01/2006 12:03]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [17/01/2006 12:03]
"LogMeIn GUI"="C:\Program Files\LogMeIn\LogMeInSystray.exe" [06/10/2006 18:55]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 18:51]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [27/10/2007 09:41]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [20/12/2004 17:12]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [06/12/2004 11:06]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/01/2008 15:27]
"DVDtoiPodConverter_upgrade"="C:\Program Files\E-Zsoft\DVDtoiPodConverter\DVDtoiPodConverter.exe" [06/12/2007 11:25]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [13/09/2004 15:49]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/11/2007 18:36]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 09:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/2007 13:00]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [27/11/2007 11:58]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [28/02/2006 12:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [26/06/2006 16:13]
"SUPERAntiSpyware"="F:\Super Antispy\SUPERAntiSpyware.exe" [27/02/2007 11:39]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktop"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
F:\Super Antispy\SASWINLO.dll 27/02/2007 11:39 282624 F:\Super Antispy\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2008-02-09 21:59:41 ------------