Further to my posting about 10 minutes ago, having uninstalled Panda earlier this morning, I tried to use your original DSS programme again and this time it worked so I could get a read-out after all, which is as below.
This scan is without Panda and without Roxio's GoBack3 De Luxe running.
Deckard's System Scanner v20071014.68Run by Victor on 2008-02-05 23:07:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 3 Restore Point(s) --
3: 2008-02-05 23:06:23 UTC - RP33 - Deckard's System Scanner Restore Point
2: 2008-02-05 10:03:36 UTC - RP32 - System Checkpoint
1: 2008-02-05 00:31:24 UTC - RP31 - Deckard's System Scanner Restore Point
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Victor.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:08:17, on 05/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PD91Agent.exe
C:\WINDOWS\system32\SLEE81.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Everstrike Software\Universal Shield 3.3.1\US30Service.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\4t Explorer Sweeper\4t-swp.exe
C:\Program Files\Accent Composer\ACompose.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\X2Net\SmartBoard\X2Net_SmartBoard.exe
C:\Program Files\Roxio\GoBack\GBTray.exe
C:\Program Files\X2Net\SmartBoard\X2Net_SmartBoard.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Victor\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Victor.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
O2 - BHO: ICHlprObj Class - {1f0c8547-2639-4c91-b8aa-c7eca24c3163} - C:\PROGRA~1\ALADDI~1\INTERN~1\ic3hlpr.dll
O2 - BHO: PopupFilter Class - {1F2E844B-8211-46ff-8262-772F03295CF4} - C:\PROGRA~1\ALADDI~1\INTERN~1\PopFiltr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ExplorerView by GetData - {6E48A5AF-4EE0-42E4-AC31-6BA0D9572285} - C:\PROGRA~1\GetData\EXPLOR~1\EXPLOR~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Smart Type Assistant] C:\Program Files\Smart Type Assistant\sta.exe
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - HKCU\..\Run: [4t Explorer Sweeper] C:\Program Files\4t Explorer Sweeper\4t-swp.exe -start
O4 - HKCU\..\Run: [ACompose] C:\Program Files\Accent Composer\ACompose.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [SSS7] "C:\Program Files\Steganos Security Suite 7\SSS7.exe" -firstboot (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [SSS7] "C:\Program Files\Steganos Security Suite 7\SSS7.exe" -firstboot (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SSS7] "C:\Program Files\Steganos Security Suite 7\SSS7.exe" -firstboot (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SSS7] "C:\Program Files\Steganos Security Suite 7\SSS7.exe" -firstboot (User 'Default user')
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: X2Net SmartBoard.lnk = C:\Program Files\X2Net\SmartBoard\X2Net_SmartBoard.exe
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MWOL &Dictionary - res://C:\WINDOWS\_MWOLTB.DLL/23/219
O8 - Extra context menu item: MWOL &Thesaurus - res://C:\WINDOWS\_MWOLTB.DLL/23/220
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O15 - Trusted Zone:
http://www.pandasoftware.co.ukO15 - Trusted Zone:
http://www.pandasoftware.comO15 - Trusted Zone:
http://www.vposters.me.ukO15 - Trusted Zone:
http://*.windowsupdate.comO15 - Trusted Zone:
http://download.windowsupdate.com O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (Installer Class) -
http://www.nanoscan....s/ascinstie.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1131226363515O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1140702945796O17 - HKLM\System\CCS\Services\Tcpip\..\{8B7F24A8-6DC2-414D-B946-3C6C1D11F3E8}: NameServer = 80.189.92.2 80.189.94.2
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Fix-It Task Manager - V Communications, Inc. - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PD91Engine.exe
O23 - Service: Steganos Live Encryption Engine 8.1 [Service] (SLEE_81_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE81.exe
O23 - Service: US30Service - Unknown owner - C:\Program Files\Everstrike Software\Universal Shield 3.3.1\US30Service.exe
--
End of file - 9404 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080118-205211-471 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080118-205211-887 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080119-115139-586 O4 - Startup: AutoBackup Launcher.lnk = C:\Program Files\Memeo\AutoBackup\MemeoLauncher.exe
backup-20080122-131843-946 O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe
backup-20080122-225230-507 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
backup-20080122-225231-647 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
backup-20080122-225232-215 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
backup-20080122-225311-496 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
backup-20080122-225856-624 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 GBDevice - c:\windows\system32\drivers\gbdevice.sys <Not Verified; Roxio, Inc.; GoBack>
R0 GoBack2K - c:\windows\system32\drivers\goback2k.sys <Not Verified; Roxio, Inc.; GoBack>
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R2 Dev_CBIDDRV - c:\windows\system32\drivers\cbid.sys <Not Verified; TwinSSoft Co.; CBId NT direct hardware access driver>
R2 GBFSHook - c:\windows\system32\drivers\gbfshook.sys <Not Verified; Roxio, Inc.; GoBack>
R2 MediaLock - c:\windows\system32\drivers\medialock.sys
R2 SLEE_81_DRIVER (Steganos Live Encryption Engine 8.1 [Driver]) - c:\windows\system32\drivers\slee81.sys
R2 US30Sys - c:\program files\everstrike software\universal shield 3.3.1\us30xp.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
R3 US30Kbd - c:\program files\everstrike software\universal shield 3.3.1\us30kbd2k.sys
S1 Uim_IM (UIM Drive Backup Image Plugin) - c:\windows\system32\drivers\uim_im.sys (file missing)
S1 UimBus (Universal Image Mounter Controller) - c:\windows\system32\drivers\uimbus.sys (file missing)
S2 windrvNT - c:\windows\system32\windrvnt.sys (file missing)
S3 DLPortIO (DriverLINX Port I/O Driver) - c:\windows\system32\drivers\dlportio.sys
S3 mxInsMon - c:\program files\aladdin systems\internet cleanup\mxinsmon.sys
S3 pxark - c:\windows\system32\drivers\pxark.sys <Not Verified; ; Prevx CSI>
S3 USBNIC (USBNIC Network Adapter) - c:\windows\system32\drivers\usbnic.sys <Not Verified; UTStarcom Co.Ltd; USB Miniport Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Fix-It Task Manager - c:\progra~1\vcom\fix-it\mxtask.exe -service <Not Verified; V Communications, Inc.; >
R2 GBPoll - c:\program files\roxio\goback\gbpoll.exe <Not Verified; Roxio, Inc.; GoBack>
R2 SLEE_81_SERVICE (Steganos Live Encryption Engine 8.1 [Service]) - c:\windows\system32\slee81.exe
R2 US30Service - c:\program files\everstrike software\universal shield 3.3.1\us30service.exe
S3 FirebirdServerMAGIXInstance (Firebird Server - MAGIX Instance) -
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S4 UPnPService - c:\program files\common files\magix shared\upnpservice\upnpservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-02-05 03:30:02 404 --a------ C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job
2008-02-05 01:41:02 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-01-21 00:00:02 496 --a------ C:\WINDOWS\Tasks\Basic clean-up.job
-- Files created between 2008-01-05 and 2008-02-05 -----------------------------
2008-02-03 00:22:45 2147483647 --ahs---- C:\gobackio.bin
2008-02-03 00:22:13 156301 -ra------ C:\WINDOWS\system32\drivers\GoBack2K.sys <Not Verified; Roxio, Inc.; GoBack>
2008-02-03 00:22:13 15248 -ra------ C:\WINDOWS\system32\drivers\GBFSHook.sys <Not Verified; Roxio, Inc.; GoBack>
2008-02-03 00:22:13 3913 -ra------ C:\WINDOWS\system32\drivers\GBDevice.sys <Not Verified; Roxio, Inc.; GoBack>
2008-02-03 00:21:58 0 d-------- C:\Program Files\Roxio
2008-01-25 01:06:13 0 d-------- C:\Documents and Settings\LocalService\Application Data\Acronis
2008-01-25 01:02:49 0 d-------- C:\Documents and Settings\All Users\Application Data\Acronis
2008-01-23 04:57:41 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-21 12:27:41 0 d-------- C:\Program Files\Panda Security
2008-01-20 21:54:27 0 d-------- C:\Documents and Settings\Victor\Application Data\ErrorSmart
2008-01-20 21:54:18 0 d-------- C:\Program Files\ErrorSmart
2008-01-19 12:27:02 0 d-------- C:\Downloads
2008-01-19 12:27:01 0 d-------- C:\Documents and Settings\Victor\Application Data\GetRightToGo
2008-01-18 20:58:02 0 d-------- C:\WINDOWS\Prefetch
2008-01-18 20:50:56 0 d-------- C:\Program Files\Trend Micro
2008-01-18 17:03:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Tanagra
2008-01-18 16:42:54 0 d-------- C:\Program Files\Seagate
2008-01-17 13:57:37 30820 --a------ C:\WINDOWS\system32\drivers\hotcore.sys <Not Verified; Paragon Software Group; HotBackup>
2008-01-17 13:08:29 0 d-------- C:\Program Files\Paragon Software
2008-01-16 13:34:33 0 d-------- C:\Program Files\Common Files\Panda Software
2008-01-15 02:40:47 0 d-------- C:\Program Files\JoshMadison
-- Find3M Report ---------------------------------------------------------------
2008-01-22 23:01:36 114 --a------ C:\sccfg.sys
2008-01-20 23:05:00 16826 --ah----- C:\Program Files\dmw.GID
2008-01-18 18:27:30 23388 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-12-28 15:03:36 0 d-------- C:\Documents and Settings\Victor\Application Data\LaCie
2007-12-20 08:11:04 0 d-------- C:\Program Files\FinePix_USB
2007-12-08 23:29:58 0 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2007-12-07 00:30:02 0 d-------- C:\Program Files\Raxco
2007-12-06 22:42:04 0 d-------- C:\Program Files\PrevxCSI
2007-12-06 22:26:46 0 d-------- C:\Documents and Settings\Victor\Application Data\PrevxCSI
2007-12-06 10:29:54 0 d-------- C:\Program Files\MSXML 6.0
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"DSLSTATEXE"="C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe" [04/06/2004 14:37]
"Logitech Utility"="Logi_MwX.Exe" [17/12/2003 09:50 C:\WINDOWS\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [04/10/2007 17:14 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [04/10/2007 17:14]
"SoundMan"="SOUNDMAN.EXE" [27/03/2003 08:34 C:\WINDOWS\SOUNDMAN.EXE]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [04/10/2007 17:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smart Type Assistant"="C:\Program Files\Smart Type Assistant\sta.exe" [13/02/2003 20:01]
"TClockEx"="C:\Program Files\TClockEx\TCLOCKEX.EXE" [14/03/1999 01:33]
"4t Explorer Sweeper"="C:\Program Files\4t Explorer Sweeper\4t-swp.exe" [29/04/2002 14:46]
"ACompose"="C:\Program Files\Accent Composer\ACompose.exe" [18/01/2000 10:19]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 00:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SSS7"="C:\Program Files\Steganos Security Suite 7\SSS7.exe" -firstboot
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
C:\Documents and Settings\Victor\Start Menu\Programs\Startup\
WordWeb Pro.lnk - C:\Program Files\WordWeb\wweb32.exe [05/11/2005 14:02:31]
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [20/10/2005 12:04:08]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [14/12/2004 04:44:06]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13/02/2001 01:01:04]
X2Net SmartBoard.lnk - C:\Program Files\X2Net\SmartBoard\X2Net_SmartBoard.exe [08/12/2007 13:45:14]
GoBack.lnk - C:\Program Files\Roxio\GoBack\GBTray.exe [03/02/2008 00:21:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"=0 (0x0)
"NoDispAppearancePage"=0 (0x0)
"NoDispBackgroundPage"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"DisableLockWorkstation"=0 (0x0)
"DisableChangePassword"=0 (0x0)
"HideLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"=0 (0x0)
"NoChangeKeyboardNavigationIndicators"=0 (0x0)
"NoChangeAnimation"=0 (0x0)
"NoAddPrinter"=0 (0x0)
"NoDeletePrinter"=0 (0x0)
"RestrictCpl"=0 (0x0)
"DisallowCpl"=0 (0x0)
"NoViewOnDrive"=0 (0x0)
"RestrictRun"=0 (0x0)
"DisallowRun"=0 (0x0)
"NoRecycleFiles"=0 (0x0)
"ForceRecycleBinSize"=0 (0x0)
"NoSharedDocuments"=0 (0x0)
"NoPropertiesMyComputer"=0 (0x0)
"NoPropertiesMyDocuments"=0 (0x0)
"NoPropertiesRecycleBin"=0 (0x0)
"NoManageMyComputerVerb"=0 (0x0)
"NoCustomizeWebView"=0 (0x0)
"NoSaveSettings"=0 (0x0)
"NoViewContextMenu"=0 (0x0)
"NoFileMenu"=0 (0x0)
"NoShellSearchButton"=0 (0x0)
"ClearRecentDocsOnExit"=0 (0x0)
"NoWinKeys"=0 (0x0)
"NoFileAssociate"=0 (0x0)
"NoDFSTab"=0 (0x0)
"NoHardwareTab"=0 (0x0)
"NoSecurityTab"=0 (0x0)
"NoInstrumentation"=0 (0x0)
"NoCustomizeThisFolder"=0 (0x0)
"NoWebView"=0 (0x0)
"DontShowSuperHidden"=0 (0x0)
"NoOnlinePrintsWizard"=0 (0x0)
"NoPublishingWizard"=0 (0x0)
"NoRun"=0 (0x0)
"NoSetTaskbar"=0 (0x0)
"NoSMConfigurePrograms"=0 (0x0)
"NoRecentDocsMenu"=0 (0x0)
"NoSMMyPictures"=0 (0x0)
"NoStartMenuMyMusic"=0 (0x0)
"NoSMMyDocs"=0 (0x0)
"NoStartMenuNetworkPlaces"=0 (0x0)
"NoFavoritesMenu"=0 (0x0)
"NoSMHelp"=0 (0x0)
"NoHelp"=0 (0x0)
"NoNetworkConnections"=0 (0x0)
"NoCommonGroups"=0 (0x0)
"NoFind"=0 (0x0)
"NoWindowsUpdate"=0 (0x0)
"NoFolderOptions"=0 (0x0)
"NoChangeStartMenu"=0 (0x0)
"NoRecentDocsHistory"=0 (0x0)
"NoStartMenuMFUprogramsList"=0 (0x0)
"NoStartMenuPinnedList"=0 (0x0)
"NoUserNameInStartMenu"=0 (0x0)
"NoStartMenuMorePrograms"=0 (0x0)
"NoStartMenuEjectPC"=0 (0x0)
"NoSimpleStartMenu"=0 (0x0)
"ForceStartMenuLogoff"=0 (0x0)
"StartMenuLogoff"=0 (0x0)
"NoStartMenuSubFolders"=0 (0x0)
"NoDisconnect"=0 (0x0)
"NoNtSecurity"=0 (0x0)
"NoSetFolders"=0 (0x0)
"GreyMSIAds"=0 (0x0)
"ForceMaxRecentDocs"=0 (0x0)
"NoSMBalloonTip"=0 (0x0)
"NoSMBalloonTips"=0 (0x0)
"NoTrayContextMenu"=0 (0x0)
"NoTrayItemsDisplay"=0 (0x0)
"LockTaskbar"=0 (0x0)
"HideClock"=0 (0x0)
"NoToolbarsOnTaskbar"=0 (0x0)
"NoStartBanner"=00000000
"NoTaskGrouping"=0 (0x0)
"NoActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"ForceActiveDesktopOn"=0 (0x0)
"NoWebServices"=0 (0x0)
"NoFileUrl"=0 (0x0)
"NoInternetIcon"=0 (0x0)
"NoBandCustomize"=0 (0x0)
"NoToolbarCustomize"=0 (0x0)
"NoExpandedNewMenu"=0 (0x0)
"SpecifyDefaultButtons"=0 (0x0)
"NoNetConnectDisconnect"=0 (0x0)
"NoRecentDocsNetHood"=0 (0x0)
"EnforceShellExtensionSecurity"=0 (0x0)
"NoLowDiskSpaceChecks"=0 (0x0)
"NoClose"=0 (0x0)
"NoLogOff"=0 (0x0)
"NoRunasInstallPrompt"=0 (0x0)
"PromptRunasInstallNetPath"=1 (0x1)
"NoResolveTrack"=0 (0x0)
"NoResolveSearch"=0 (0x0)
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoDevMgrUpdate"=0 (0x0)
"NoDesktopCleanupWizard"=0 (0x0)
"NoThumbnailCache"=0 (0x0)
"ForceCopyAclwithFile"=0 (0x0)
"StartRunNoHOMEPATH"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\RestrictRun]
"0?"=apvxdwin.exe
"2?"=logi_mwx.exe
"3?"=msfg.exe
"4?"=inicio.exe
"5?"=fpdisp5a.exe
"6?"=acrotray.exe
"7?"=realsched.exe
"8?"=dslstat.exe
"9?"=dslagent.exe
"10?"=apdproxy.exe
"11?"=newadmin.exe
"12?"=gbtray.exe
"13?"=x2net_smartboard.exe
"14?"=reader_sl.exe
"15?"=osa.exe
"16?"=sta.exe
"17?"=tclockex.exe
"18?"=4t-swp.exe
"19?"=acompose.exe
"20?"=wweb32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6809e580-a3a7-11d1-9a00-00a0c945b006}"= C:\Program Files\Roxio\GoBack\ShellExt.dll [10/09/2001 08:10 516096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"upnphost"=3 (0x3)
"Schedule"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Magnifying Glass"="C:\Program Files\Virtual Magnifying Glass\Magnifying Glass.exe"
"SSS7"="C:\Program Files\Steganos Security Suite 7\SSS7.exe" -boot
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_5 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"Norman ACP"=C:\Program Files\Norman Access Control Privacy\nrmenctb.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"Visualware Security Suite"="C:\Program Files\Visualware Security Suite\tscore.exe" -autostartup
"DesktopIcon"=C:\Program Files\Visualware Security Suite\desktopicon.exe
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"MediaLock"=C:\Program Files\VCOM\MediaLock\MLock.exe /S
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
-- End of Deckard's System Scanner: finished at 2008-02-05 23:09:48 ------------