Deckard's System Scanner v20071014.68
Run by Mark Toler on 2008-02-08 23:27:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
72: 2008-02-09 07:28:00 UTC - RP72 - Deckard's System Scanner Restore Point
71: 2008-02-09 01:38:54 UTC - RP71 - System Checkpoint
70: 2008-02-08 01:03:10 UTC - RP70 - System Checkpoint
69: 2008-02-07 00:33:17 UTC - RP69 - Installed SUPERAntiSpyware Free Edition
68: 2008-02-06 09:19:44 UTC - RP68 - System Checkpoint
-- First Restore Point --
1: 2008-01-09 06:02:09 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Mark Toler.exe) ------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:35 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
I:\WINDOWS\system32\PnkBstrA.exe
I:\Program Files\Viewpoint\Common\ViewpointService.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\WINDOWS\Explorer.EXE
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
I:\PROGRA~1\MICROS~2\rapimgr.exe
I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Microsoft ActiveSync\wcescomm.exe
I:\Documents and Settings\Mark Toler\Desktop\dss.exe
I:\PROGRA~1\TRENDM~1\HIJACK~1\Mark Toler.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - I:\Program Files\AOL Search\AOLSearch.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - I:\Program Files\AOL Search\AOLSearch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - I:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Player - {E5AF0624-F539-47D9-BA37-D8B339E858F4} - I:\WINDOWS\orgnavi.dll
O2 - BHO: (no name) - {F5CA6106-41BB-43B6-848B-4BBE5D37702B} - I:\Program Files\MSN Gaming Zone\homexyI:\WINDOWS\system32\smvt3\gyreo83122.exe.dll (file missing)
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - I:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [StartCCC] "I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [H/PC Connection Agent] "I:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "I:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-21-746137067-115176313-1801674531-1005\..\Run: [MSMSGS] "I:\Program Files\Messenger\msmsgs.exe" /background (User 'James Cothren')
O4 - HKUS\S-1-5-21-746137067-115176313-1801674531-1005\..\Run: [Yahoo! Pager] "I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User 'James Cothren')
O4 - HKUS\S-1-5-21-746137067-115176313-1801674531-1005\..\Run: [Aim6] "I:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User 'James Cothren')
O4 - HKUS\S-1-5-21-746137067-115176313-1801674531-1005\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background (User 'James Cothren')
O4 - HKUS\S-1-5-21-746137067-115176313-1801674531-1005\..\Run: [WebSUpdater] "C:\Program Files\winvi\wupda.exe" /background (User 'James Cothren')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] I:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] I:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: Deer Hunter 2005 Registration.lnk = I:\Program Files\Atari\Deer Hunter 2005\ATR1.EXE
O8 - Extra context menu item: &AOL Toolbar Search - i:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - I:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO20 - Winlogon Notify: !SASWinLogon - I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - I:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 8074 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 nwlnkfltt - i:\windows\system32\drivers\nwlnkfltt.sys
R1 SASDIFSV - i:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - i:\program files\superantispyware\saskutil.sys
R3 SASENUM - i:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 catchme - i:\docume~1\sethke~1\locals~1\temp\catchme.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Viewpoint Manager Service - "i:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Photo AIO Printer 964
Device ID: USB\VID_413C&PID_5114&MI_00\6&109D6489&0&0000
Manufacturer:
Name: Photo AIO Printer 964
PNP Device ID: USB\VID_413C&PID_5114&MI_00\6&109D6489&0&0000
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062111C1&REV_00\4&FB75CB&0&00A4
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062111C1&REV_00\4&FB75CB&0&00A4
Service:
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ROOT\MEDIA\0000
Manufacturer:
Name:
PNP Device ID: ROOT\MEDIA\0000
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-02-08 17:00:00 450 --a------ I:\WINDOWS\Tasks\RegCure Program Check.job
2008-02-07 03:00:00 384 --a------ I:\WINDOWS\Tasks\RegCure.job
-- Files created between 2008-01-08 and 2008-02-08 -----------------------------
2008-02-08 01:35:39 0 d-------- I:\Program Files\Trend Micro
2008-02-06 16:33:23 0 d-------- I:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-06 16:33:18 0 d-------- I:\Program Files\SUPERAntiSpyware
2008-02-06 16:33:18 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\SUPERAntiSpyware.com
2008-02-06 16:32:55 0 d-------- I:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 13:21:25 0 d-------- I:\WINDOWS\system32\ActiveScan
2008-02-05 04:53:02 0 d-------- I:\Documents and Settings\NetworkService\Start Menu
2008-02-05 00:16:57 11254 --a------ I:\WINDOWS\system32\locate.com
2008-02-05 00:16:57 0 d-------- I:\ISeeYouXP
2008-02-05 00:14:48 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Help
2008-02-05 00:11:35 118784 --a------ I:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-02-05 00:11:34 0 d-------- I:\Program Files\SpywareBlaster
2008-02-04 14:02:25 0 d-------- I:\Program Files\winvi
2008-02-03 20:13:15 232960 --a------ I:\WINDOWS\orgnavi.dll <Not Verified; Asus; >
2008-02-02 21:30:06 0 d-------- I:\Program Files\PurePlay
2008-02-02 21:30:06 0 d-------- I:\Documents and Settings\All Users\Application Data\PurePlay
2008-02-02 21:29:41 0 d-------- I:\WINDOWS\Downloaded Installations
2008-02-02 04:35:46 0 d-------- I:\Program Files\THQ
2008-02-02 03:21:22 0 d-------- I:\Documents and Settings\All Users\Application Data\Adobe
2008-02-02 03:20:22 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Leadertech
2008-02-02 03:18:58 0 d-------- I:\Program Files\Atari
2008-01-31 14:47:50 0 d-------- I:\Documents and Settings\James Cothren\Application Data\vlc
2008-01-31 01:47:57 0 d-------- I:\Program Files\Native Instruments
2008-01-27 23:54:24 0 d-------- I:\Program Files\DVD Decrypter
2008-01-27 23:49:56 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\vlc
2008-01-27 23:48:33 0 d-------- I:\Program Files\VideoLAN
2008-01-27 21:24:30 765952 --a------ I:\WINDOWS\system32\xvidcore.dll
2008-01-27 21:24:30 4762112 --a------ I:\WINDOWS\system32\NCMedia.dll
2008-01-27 21:24:30 383238 --a------ I:\WINDOWS\system32\libmp3lame-0.dll
2008-01-27 21:24:30 0 d-------- I:\Program Files\Smallvideosoft
2008-01-27 21:17:34 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\FMZilla
2008-01-27 21:17:18 0 d-------- I:\Program Files\Free Music Zilla
2008-01-27 21:02:17 0 d-------- I:\Downloads
2008-01-27 21:02:11 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Orbit
2008-01-27 04:05:23 0 d-------- I:\Program Files\Electronic Arts
2008-01-24 19:56:00 0 d-------- I:\Program Files\Activision Value
2008-01-23 23:42:21 0 dr-h----- I:\Documents and Settings\Mark Toler\Application Data\SecuROM
2008-01-23 15:07:24 0 d-------- I:\Program Files\Project64 1.6
2008-01-23 11:17:47 0 d-------- I:\Program Files\EA Sports
2008-01-23 10:35:31 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Hoyle FaceCreator
2008-01-23 10:35:28 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Hoyle Casino
2008-01-23 09:57:59 0 d-------- I:\Program Files\Smart Projects
2008-01-23 09:46:12 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\DAEMON Tools Pro
2008-01-23 09:45:57 0 d-------- I:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-01-23 09:44:24 0 d-------- I:\Program Files\DAEMON Tools Pro
2008-01-23 09:41:12 685816 --a------ I:\WINDOWS\system32\drivers\sptd.sys
2008-01-23 00:36:28 0 d-------- I:\Program Files\Windows Media Connect 2
2008-01-23 00:35:03 0 d-------- I:\WINDOWS\system32\drivers\UMDF
2008-01-23 00:31:02 131072 --a------ I:\WINDOWS\system32\dzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading ZIP DLL>
2008-01-23 00:31:02 110592 --a------ I:\WINDOWS\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-01-23 00:30:57 0 d-------- I:\Program Files\Windows Media Bonus Pack for Windows XP
2008-01-22 01:52:58 0 d-------- I:\Program Files\Madbeetle
2008-01-22 00:25:43 0 d-------- I:\WINDOWS\system32\LogFiles
2008-01-22 00:16:26 0 d-------- I:\Program Files\Microsoft ActiveSync
2008-01-20 01:46:39 0 d---s---- I:\Documents and Settings\Mark Toler\UserData
2008-01-19 17:50:51 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Viewpoint
2008-01-19 17:50:18 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\QQ Games Plugin
2008-01-19 17:50:13 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\acccore
2008-01-19 11:58:56 2 --a------ I:\WINDOWS\msdbc_4816979.dat
2008-01-19 11:55:39 0 d-a------ I:\Documents and Settings\All Users\Application Data\TEMP
2008-01-19 10:58:12 0 d-------- I:\Documents and Settings\James Cothren\Application Data\QQ Games Plugin
2008-01-19 10:57:42 0 d-------- I:\Documents and Settings\James Cothren\Application Data\acccore
2008-01-19 09:59:19 0 d-------- I:\Program Files\Nitto 1320 Legends
2008-01-18 22:54:19 0 d-------- I:\WINDOWS\Sun
2008-01-18 22:54:18 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Sun
2008-01-18 22:53:39 0 d-------- I:\Program Files\Java
2008-01-18 22:53:32 0 d-------- I:\Program Files\Common Files\Java
2008-01-18 21:26:07 0 d-------- I:\Documents and Settings\James Cothren\Application Data\MySpace
2008-01-17 20:00:05 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\WinRAR
2008-01-17 19:57:09 0 d-------- I:\DVDTemp
2008-01-17 19:56:55 0 d-------- I:\Program Files\Super_DVD_Creator_9.5
2008-01-16 09:55:43 4096 --a------ I:\WINDOWS\system32\crash
2008-01-15 22:43:54 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Azureus
2008-01-15 18:37:36 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Yahoo!
2008-01-15 03:32:18 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Yahoo!
2008-01-15 02:54:58 0 d-------- I:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-14 17:31:36 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\MySpace
2008-01-14 17:31:31 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Grisoft
2008-01-14 17:31:30 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\ATI
2008-01-14 15:37:00 0 d-------- I:\Documents and Settings\All Users\Application Data\Yahoo!
2008-01-14 15:36:20 0 d-------- I:\Program Files\Yahoo!
2008-01-10 18:18:34 0 d-------- I:\Program Files\Tencent
2008-01-10 18:07:57 0 d-------- I:\Program Files\AIMTunes
2008-01-10 18:07:53 0 d-------- I:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-01-10 18:07:40 0 d-------- I:\Program Files\AOL Search
2008-01-10 18:07:35 0 d-------- I:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-10 18:07:34 0 d-------- I:\Program Files\Viewpoint
2008-01-10 18:07:28 0 d-------- I:\Documents and Settings\All Users\Application Data\AOL
2008-01-10 18:07:28 0 d-------- I:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-10 18:07:11 0 d-------- I:\Program Files\Common Files\AOL
2008-01-10 18:06:19 0 d-------- I:\Program Files\AIM6
2008-01-10 17:21:33 0 d-------- I:\Program Files\MySpace
2008-01-10 14:44:33 0 d-------- I:\Documents and Settings\James Cothren\Application Data\ATI
2008-01-10 14:44:32 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Grisoft
2008-01-09 18:12:40 0 d-------- I:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-09 17:35:45 0 d-------- I:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-09 17:23:54 1238689 --a------ I:\MGtools.exe
2008-01-09 17:09:58 0 d-------- I:\Program Files\RegCure
2008-01-09 16:48:14 0 d-------- I:\WINDOWS\CSC
2008-01-09 16:38:50 40960 --a------ I:\WINDOWS\system32\ChCfg.exe
2008-01-09 16:38:09 0 d-------- I:\WINDOWS\system32\RTCOM
2008-01-09 16:37:21 487424 --a------ I:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-01-09 16:08:10 0 d-------- I:\Documents and Settings\All Users\Application Data\ATI
2008-01-09 16:07:10 0 --a------ I:\WINDOWS\ativpsrm.bin
2008-01-09 15:50:02 0 d-------- I:\Program Files\MozBackup
2008-01-09 15:44:15 0 d-------- I:\Program Files\FileASSASSIN
2008-01-09 14:41:53 593920 --a------ I:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-01-09 14:41:25 0 d-------- I:\Program Files\ATI Technologies
2008-01-09 14:40:33 0 d-------- I:\Program Files\Common Files\InstallShield
2008-01-09 14:36:25 0 d-------- I:\WINDOWS\OPTIONS
2008-01-09 14:36:25 0 d-------- I:\Program Files\Realtek
2008-01-09 14:31:22 86016 --a------ I:\WINDOWS\system32\drivers\nwlnkfltt.sys
2008-01-09 14:31:21 0 d-------- I:\WINDOWS\system32\smvt3
2008-01-09 14:31:21 0 d-------- I:\WINDOWS\system32\ache3
2008-01-09 14:31:18 0 d-------- I:\WINDOWS\system32\obe3
2008-01-09 14:31:14 0 d-------- I:\WINDOWS\system32\omp2
2008-01-09 14:31:12 0 d-------- I:\WINDOWS\system32\ardCo16
2008-01-09 14:31:09 111831 --a------ I:\WINDOWS\system32\ope66.exe
2008-01-09 14:30:40 352410 --a------ I:\WINDOWS\system32\ope5F.exe
2008-01-09 14:02:00 0 d-------- I:\Documents and Settings\All Users\Application Data\Azureus
2008-01-09 14:01:25 0 d-------- I:\Program Files\Azureus
2008-01-09 13:19:12 0 d-------- I:\Program Files\Alwil Software
2008-01-09 13:15:05 0 d-------- I:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-01-09 06:47:51 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Macromedia
2008-01-09 06:47:50 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Adobe
2008-01-09 06:44:35 0 d--h----- I:\Program Files\InstallShield Installation Information
2008-01-09 06:39:26 0 d-------- I:\WINDOWS\system32\appmgmt
2008-01-09 06:35:45 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Mozilla
2008-01-09 06:34:22 0 d-------- I:\Documents and Settings\Mark Toler\Application Data\Identities
2008-01-09 06:34:15 0 d--h----- I:\Documents and Settings\Mark Toler\Templates
2008-01-09 06:34:15 0 dr------- I:\Documents and Settings\Mark Toler\Start Menu
2008-01-09 06:34:15 0 dr-h----- I:\Documents and Settings\Mark Toler\SendTo
2008-01-09 06:34:15 0 dr-h----- I:\Documents and Settings\Mark Toler\Recent
2008-01-09 06:34:15 0 d--h----- I:\Documents and Settings\Mark Toler\PrintHood
2008-01-09 06:34:15 0 d--h----- I:\Documents and Settings\Mark Toler\NetHood
2008-01-09 06:34:15 0 dr------- I:\Documents and Settings\Mark Toler\My Documents
2008-01-09 06:34:15 0 d--h----- I:\Documents and Settings\Mark Toler\Local Settings
2008-01-09 06:34:15 0 dr------- I:\Documents and Settings\Mark Toler\Favorites
2008-01-09 06:34:15 0 d-------- I:\Documents and Settings\Mark Toler\Desktop
2008-01-09 06:34:15 0 d---s---- I:\Documents and Settings\Mark Toler\Cookies
2008-01-09 06:34:15 0 dr-h----- I:\Documents and Settings\Mark Toler\Application Data
2008-01-09 06:34:14 3407872 --ah----- I:\Documents and Settings\Mark Toler\NTUSER.DAT
2008-01-08 22:53:07 0 d---s---- I:\WINDOWS\system32\Microsoft
2008-01-08 22:24:08 0 d-------- I:\WUTemp
2008-01-08 22:10:12 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Macromedia
2008-01-08 22:10:12 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Adobe
2008-01-08 22:02:20 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Identities
2008-01-08 22:02:17 0 d--h----- I:\Documents and Settings\James Cothren\Templates
2008-01-08 22:02:17 0 dr------- I:\Documents and Settings\James Cothren\Start Menu
2008-01-08 22:02:17 0 dr-h----- I:\Documents and Settings\James Cothren\SendTo
2008-01-08 22:02:17 0 dr-h----- I:\Documents and Settings\James Cothren\Recent
2008-01-08 22:02:17 0 d--h----- I:\Documents and Settings\James Cothren\PrintHood
2008-01-08 22:02:17 1835008 --ah----- I:\Documents and Settings\James Cothren\NTUSER.DAT
2008-01-08 22:02:17 0 d--h----- I:\Documents and Settings\James Cothren\NetHood
2008-01-08 22:02:17 0 dr------- I:\Documents and Settings\James Cothren\My Documents
2008-01-08 22:02:17 0 d--h----- I:\Documents and Settings\James Cothren\Local Settings
2008-01-08 22:02:17 0 dr------- I:\Documents and Settings\James Cothren\Favorites
2008-01-08 22:02:17 0 d-------- I:\Documents and Settings\James Cothren\Desktop
2008-01-08 22:02:17 0 d---s---- I:\Documents and Settings\James Cothren\Cookies
2008-01-08 22:02:17 0 dr-h----- I:\Documents and Settings\James Cothren\Application Data
2008-01-08 22:02:17 0 d---s---- I:\Documents and Settings\James Cothren\Application Data\Microsoft
2008-01-08 22:02:04 0 d--hs---- I:\WINDOWS\Installer
2008-01-08 21:58:36 0 d--hs---- I:\System Volume Information
2008-01-08 21:58:35 1572864 --ah----- I:\Documents and Settings\NetworkService\NTUSER.DAT
2008-01-08 21:58:35 0 d--h----- I:\Documents and Settings\NetworkService\Local Settings
2008-01-08 21:58:35 0 d---s---- I:\Documents and Settings\NetworkService\Cookies
2008-01-08 21:58:35 0 d-------- I:\Documents and Settings\NetworkService\Application Data
2008-01-08 21:58:35 0 d---s---- I:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-01-08 21:58:35 1572864 --ah----- I:\Documents and Settings\LocalService\NTUSER.DAT
2008-01-08 21:58:35 0 d--h----- I:\Documents and Settings\LocalService\Local Settings
2008-01-08 21:58:35 0 d---s---- I:\Documents and Settings\LocalService\Cookies
2008-01-08 21:58:35 0 d-------- I:\Documents and Settings\LocalService\Application Data
2008-01-08 21:58:35 0 d---s---- I:\Documents and Settings\LocalService\Application Data\Microsoft
2008-01-08 21:58:31 0 d-------- I:\Documents and Settings\James Cothren\Application Data\Mozilla
2008-01-08 21:55:32 0 d-------- I:\WINDOWS\system32\xircom
2008-01-08 21:55:32 0 d-------- I:\Program Files\microsoft frontpage
2008-01-08 21:55:21 229376 ---h----- I:\Documents and Settings\Default User\NTUSER.DAT
2008-01-08 21:54:47 0 d--hs---- I:\Documents and Settings\All Users\DRM
2008-01-08 21:54:40 0 dr------- I:\WINDOWS\Offline Web Pages
2008-01-08 21:54:40 0 d---s---- I:\WINDOWS\Downloaded Program Files
2008-01-08 21:54:15 0 d-------- I:\WINDOWS\system32\DirectX
2008-01-08 21:53:25 0 d---s---- I:\WINDOWS\Tasks
2008-01-08 21:53:22 0 d-------- I:\Program Files\Common Files\MSSoap
2008-01-08 21:53:17 0 d-------- I:\WINDOWS\srchasst
2008-01-08 21:53:16 0 d-------- I:\WINDOWS\system32\Macromed
2008-01-08 21:53:14 0 d-------- I:\Program Files\Movie Maker
2008-01-08 21:53:09 0 d-------- I:\WINDOWS\PCHealth
2008-01-08 21:53:08 0 d-------- I:\WINDOWS\system32\Restore
2008-01-08 21:52:41 21640 --a------ I:\WINDOWS\system32\emptyregdb.dat
2008-01-08 21:52:38 0 d-------- I:\WINDOWS\Registration
2008-01-08 21:52:36 0 d--h----- I:\Program Files\WindowsUpdate
2008-01-08 21:52:36 0 d-------- I:\Program Files\Online Services
2008-01-08 21:52:33 0 d-------- I:\Program Files\Messenger
2008-01-08 21:52:27 0 d-------- I:\Program Files\MSN Gaming Zone
2008-01-08 21:51:47 0 d-------- I:\Program Files\Windows NT
2008-01-08 21:51:44 0 d-------- I:\WINDOWS\system32\MsDtc
2008-01-08 21:51:43 0 d-------- I:\WINDOWS\system32\Com
2008-01-08 20:39:03 0 d-------- I:\WINDOWS\system32\PreInstall
2008-01-08 20:39:01 0 d--h----- I:\WINDOWS\$hf_mig$
2008-01-08 20:34:23 1158 --a------ I:\WINDOWS\mozver.dat
2008-01-08 20:31:33 0 d-------- I:\WINDOWS\system32\SoftwareDistribution
2008-01-08 20:31:14 0 d-------- I:\Documents and Settings\LocalService\Start Menu
2008-01-08 20:30:51 0 d-------- I:\WINDOWS\SoftwareDistribution
2008-01-08 20:30:48 0 d-------- I:\WINDOWS\Prefetch
2008-01-08 20:25:26 0 d-------- I:\WINDOWS\peernet
2008-01-08 20:25:25 0 d-------- I:\WINDOWS\provisioning
2008-01-08 20:24:21 0 d-------- I:\WINDOWS\ServicePackFiles
2008-01-08 20:22:47 0 d-------- I:\WINDOWS\system32\ReinstallBackups
2008-01-08 20:22:07 0 --a------ I:\WINDOWS\nsreg.dat
2008-01-08 20:21:23 0 d-------- I:\WINDOWS\EHome
2008-01-08 20:07:05 0 d-------- I:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-01-08 13:40:20 0 d-------- I:\Program Files\Common Files\ODBC
2008-01-08 13:40:16 0 dr------- I:\Program Files
2008-01-08 13:40:16 0 d-------- I:\Program Files\Common Files
2008-01-08 13:40:16 0 d-------- I:\Program Files\Common Files\SpeechEngines
2008-01-08 13:39:57 0 d--h----- I:\Documents and Settings\Default User\Templates
2008-01-08 13:39:57 0 dr------- I:\Documents and Settings\Default User\Start Menu
2008-01-08 13:39:57 0 dr-h----- I:\Documents and Settings\Default User\SendTo
2008-01-08 13:39:57 0 d--h----- I:\Documents and Settings\Default User\Recent
2008-01-08 13:39:57 0 d--h----- I:\Documents and Settings\Default User\PrintHood
2008-01-08 13:39:57 0 d--h----- I:\Documents and Settings\Default User\NetHood
2008-01-08 13:39:57 0 d-------- I:\Documents and Settings\Default User\My Documents
2008-01-08 13:39:57 0 dr-h----- I:\Documents and Settings\Default User\Local Settings
2008-01-08 13:39:57 0 d-------- I:\Documents and Settings\Default User\Favorites
2008-01-08 13:39:57 0 d-------- I:\Documents and Settings\Default User\Desktop
2008-01-08 13:39:57 0 d---s---- I:\Documents and Settings\Default User\Cookies
2008-01-08 13:39:57 0 d--h----- I:\Documents and Settings\All Users\Templates
2008-01-08 13:39:57 0 dr------- I:\Documents and Settings\All Users\Start Menu
2008-01-08 13:39:57 0 d-------- I:\Documents and Settings\All Users\Favorites
2008-01-08 13:39:57 0 dr------- I:\Documents and Settings\All Users\Documents
2008-01-08 13:39:57 0 d-------- I:\Documents and Settings\All Users\Desktop
2008-01-08 13:39:47 0 d-------- I:\WINDOWS\system32\CatRoot2
2008-01-08 13:39:47 0 d-------- I:\WINDOWS\system32\CatRoot
2008-01-08 13:39:42 0 dr-h----- I:\Documents and Settings\Default User\Application Data
2008-01-08 13:39:42 0 d---s---- I:\Documents and Settings\Default User\Application Data\Microsoft
2008-01-08 13:39:42 0 dr-h----- I:\Documents and Settings\All Users\Application Data
2008-01-08 13:39:42 0 d---s---- I:\Documents and Settings\All Users\Application Data\Microsoft
2008-01-08 13:39:14 0 d-------- I:\Documents and Settings
2008-01-08 13:32:37 0 d-------- I:\WINDOWS
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\WinSxS
2008-01-08 13:32:37 0 dr------- I:\WINDOWS\Web
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\twain_32
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\wins
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\wbem
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\usmt
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\spool
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\ShellExt
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\Setup
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\ras
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\oobe
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\npp
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\mui
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\inetsrv
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\IME
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\icsxml
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\ias
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\export
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\drivers
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\drivers\etc
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\drivers\disdn
2008-01-08 13:32:37 0 dr-hs--c- I:\WINDOWS\system32\dllcache
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\dhcp
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\config
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\3com_dmi
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\3076
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\2052
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1054
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1042
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1041
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1037
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1033
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1031
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1028
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system32\1025
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\system
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\security
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Resources
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\repair
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\mui
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\msapps
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\msagent
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Media
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\java
2008-01-08 13:32:37 0 d--h----- I:\WINDOWS\inf
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\ime
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Help
2008-01-08 13:32:37 0 dr--s---- I:\WINDOWS\Fonts
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Driver Cache
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Debug
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Cursors
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Connection Wizard
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\Config
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\AppPatch
2008-01-08 13:32:37 0 d-------- I:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-01-22 00:17:50 2528 --a------ I:\Documents and Settings\Mark Toler\Application Data\$_hpcst$.hpc
2008-01-08 13:39:57 62 --ahs---- I:\Documents and Settings\Mark Toler\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}]
01/03/2008 08:27 AM 111968 --a------ I:\Program Files\AOL Search\AOLSearch.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E5AF0624-F539-47D9-BA37-D8B339E858F4}]
02/03/2008 08:14 PM 232960 --a------ I:\WINDOWS\orgnavi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5CA6106-41BB-43B6-848B-4BBE5D37702B}]
I:\Program Files\MSN Gaming Zone\homexyI:\WINDOWS\system32\smvt3\gyreo83122.exe.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [12/04/2007 05:00 AM]
"StartCCC"="I:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [11/10/2006 12:35 PM]
"RTHDCPL"="RTHDCPL.EXE" [07/26/2006 04:24 PM I:\WINDOWS\RTHDCPL.exe]
"!AVG Anti-Spyware"="I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 01:25 AM]
"SunJavaUpdateSched"="I:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="I:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]
"Aim6"="" []
"H/PC Connection Agent"="I:\Program Files\Microsoft ActiveSync\wcescomm.exe" [11/13/2006 01:39 PM]
"DAEMON Tools Pro Agent"="I:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [09/06/2007 05:08 AM]
"SUPERAntiSpyware"="I:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/27/2007 11:39 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=I:\Program Files\MySpace\IM\MySpaceIM.exe
I:\Documents and Settings\Mark Toler\Start Menu\Programs\Startup\
Deer Hunter 2005 Registration.lnk - I:\Program Files\Atari\Deer Hunter 2005\ATR1.EXE [8/27/2004 9:30:18 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFolderOptions"=0 (0x0)
"NoRun"=0 (0x0)
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= I:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
I:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 I:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- Hosts -----------------------------------------------------------------------
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1 www.032439.com
7886 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-02-08 23:29:50 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® D CPU 2.66GHz
CPU 1: Intel® Pentium® D CPU 2.66GHz
Percentage of Memory in Use: 40%
Physical Memory (total/avail): 1022.48 MiB / 605.23 MiB
Pagefile Memory (total/avail): 2459.17 MiB / 1758.8 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1927.01 MiB
C: is Fixed (FAT32) - 4.19 GiB total, 1.76 GiB free.
D: is Removable (No Media)
E: is Removable (No Media)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Fixed (NTFS) - 228.68 GiB total, 157.65 GiB free.
J: is CDROM (No Media)
K: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - HDT722525DLAT80 - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Unknown - 4.2 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 228.68 GiB - I:
\\.\PHYSICALDRIVE5 - Disk drive
\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device
\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device
\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device
\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: avast! antivirus 4.7.1098 [VPS 080208-0] v4.7.1098 (ALWIL Software)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"I:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="I:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"I:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="I:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"I:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="I:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"I:\\Program Files\\Azureus\\Azureus.exe"="I:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"I:\\Program Files\\Free Music Zilla\\FMZilla.exe"="I:\\Program Files\\Free Music Zilla\\FMZilla.exe:*:Enabled:FMZilla Module"
"I:\\Program Files\\Activision Value\\WSOP 2008\\WSOPBFTB.exe"="I:\\Program Files\\Activision Value\\WSOP 2008\\WSOPBFTB.exe:*:Enabled:WSOPBFTB"
"I:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="I:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"I:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="I:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:*:Disabled:ActiveSync RAPI Manager"
"I:\\Program Files\\EA Sports\\Madden NFL 08\\Updater.exe"="I:\\Program Files\\EA Sports\\Madden NFL 08\\Updater.exe:*:Enabled:Updater"
"I:\\Program Files\\Atari\\Deer Hunter 2005\\DH2005.exe"="I:\\Program Files\\Atari\\Deer Hunter 2005\\DH2005.exe:*:Enabled:DH2005"
"I:\\Program Files\\SopCast\\adv\\SopAdver.exe"="I:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"I:\\Program Files\\SopCast\\SopCast.exe"="I:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"I:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="I:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=I:\Documents and Settings\All Users
APPDATA=I:\Documents and Settings\Mark Toler\Application Data
CLIENTNAME=Console
CommonProgramFiles=I:\Program Files\Common Files
COMPUTERNAME=PIZZA-3GS6TD1TW
ComSpec=I:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=I:
HOMEPATH=\Documents and Settings\Mark Toler
LOGONSERVER=\\PIZZA-3GS6TD1TW
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=I:\WINDOWS\system32;I:\WINDOWS;I:\WINDOWS\system32\wbem;I:\Program Files\ATI Technologies\ATI.ACE\Core-Static
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 7, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0407
ProgramFiles=I:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=I:
SystemRoot=I:\WINDOWS
TEMP=I:\DOCUME~1\MARKTO~1\LOCALS~1\Temp
TMP=I:\DOCUME~1\MARKTO~1\LOCALS~1\Temp
USERDOMAIN=PIZZA-3GS6TD1TW
USERNAME=Mark Toler
USERPROFILE=I:\Documents and Settings\Mark Toler
windir=I:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Seth Keller
(admin)Mark Toler
(admin)James Cothren
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 I:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> I:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> I:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 6.0.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A00000000001}
Adobe Shockwave Player --> I:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE I:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
AIM 6 --> I:\Program Files\AIM6\uninst.exe
AIM Toolbar 5.0 --> "I:\Program Files\AOL\AIM Toolbar 5.0\uninstall.exe"
AIMTunes --> I:\Program Files\AIMTunes\Uninstall.exe
ATI - Software Uninstall Utility --> I:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center --> RunDll32 I:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "I:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Display Driver --> rundll32 I:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
avast! Antivirus --> rundll32 I:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
AVG Anti-Spyware 7.5 --> I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
Azureus Vuze --> I:\Program Files\Azureus\uninstall.exe
Bratz - 4 Real --> RunDll32 I:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "I:\Program Files\InstallShield Installation Information\{30BA35E4-2B14-440B-9C1C-FDAAAD1C4D6D}\setup.exe" -l0x9 -uninst
CleanUp! --> I:\Program Files\CleanUp!\uninstall.exe
Deer Hunter - The 2005 Season --> "I:\Program Files\Atari\Deer Hunter 2005\unins000.exe"
DVD Decrypter (Remove Only) --> "I:\Program Files\DVD Decrypter\uninstall.exe"
EA SPORTS online 2008 --> I:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
EA SPORTS™ NBA LIVE 08 --> MsiExec.exe /X{39C8EFBA-042B-11DC-A860-0EE955D89593}
FIFA 08 --> MsiExec.exe /X{0A2A5039-B37F-489D-B1DC-A5258DF9E697}
FileASSASSIN --> I:\Program Files\FileASSASSIN\uninst.exe
Free Music Zilla --> "I:\Program Files\Free Music Zilla\unins000.exe"
Freez FLV to MP3 Converter --> "I:\Program Files\Smallvideosoft\Freez FLV to MP3 Converter\unins000.exe"
High Definition Audio Driver Package - KB888111 --> "I:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "I:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HomeScreenBuilder --> MsiExec.exe /I{3EFE72B4-9B24-4AA4-B92F-2E4D4FE202EC}
IsoBuster 2.2 --> "I:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
Java 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Madden NFL 08 --> I:\Program Files\EA Sports\Madden NFL 08\EAUninstall.exe
Media Library Management Wizard --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\mplibwiz.inf,DefaultUninstall
Microsoft ActiveSync --> MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Compression Client Pack 1.0 for Windows XP --> "I:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "I:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Movie Maker Background Music Files --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\mmmusic.inf,DefaultUninstall
Movie Maker Sound Effects --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\mmsounds.inf,DefaultUninstall
Movie Maker Title Images --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\mmtitle.inf,DefaultUninstall
MozBackup 1.4.7 --> "I:\Program Files\MozBackup\unins000.exe"
Mozilla Firefox (2.0.0.12) --> I:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
MySpaceIM --> I:\Program Files\MySpace\IM\Uninstall.exe
Need for Speed™ ProStreet --> MsiExec.exe /X{CC419DDC-E0F0-4013-B25A-6FA036516F0D}
NHL® 08 --> MsiExec.exe /X{A7AA93B6-6909-4073-B4EC-45CCDEFD4665}
Nitto 1320 Legends Public Beta 0.9.9.72 --> "I:\Program Files\Nitto 1320 Legends\unins000.exe"
Panda ActiveScan --> I:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
Plus! MP3 Audio Converter LE --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\audcle.inf,DefaultUninstall
PurePlay Poker --> MsiExec.exe /X{19E16A54-962C-45D6-BDDE-FD01EBB1A086}
REALTEK GbE & FE Ethernet PCI NIC Driver --> I:\Program Files\InstallShield Installation Information\{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}\setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver --> RunDll32 I:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "I:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
RegCure 1.3.0.2 --> I:\Program Files\RegCure\uninst.exe
Spybot - Search & Destroy --> "I:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster v3.5.1 --> "I:\Program Files\SpywareBlaster\unins000.exe"
Super DVD Creator 9.5 --> "I:\Program Files\Super_DVD_Creator_9.5\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
VideoLAN VLC media player 0.8.6d --> I:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player --> I:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Media Bonus Pack for Windows XP --> RunDll32 advpack.dll,LaunchINFSection I:\WINDOWS\INF\wmbonus.inf,DefaultUninstall
Windows Media Format 11 runtime --> "I:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> I:\Program Files\WinRAR\uninstall.exe
World Series of Poker 2008: Battle for the Bracelets --> I:\Program Files\Activision Value\WSOP 2008\Uninstall.exe
Yahoo! Internet Mail --> I:\WINDOWS\system32\regsvr32 /u /s I:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> I:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U I:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> I:\PROGRA~1\Yahoo!\Common\unyt.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type603 / Error
Event Submitted/Written: 02/07/2008 01:10:46 PM
Event ID/Source: 11706 / MsiInstaller
Event Description:
Product: Microsoft ActiveSync -- Error.No valid source could be found for product Microsoft ActiveSync. The Windows Installer cannot continue.
Event Record #/Type602 / Warning
Event Submitted/Written: 02/07/2008 01:10:20 PM
Event ID/Source: 1001 / MsiInstaller
Event Description:
Detection of product '{99052DB7-9592-4522-A558-5417BBAD48EE}', feature 'ActiveSync' failed during request for component '{25AE009D-012F-4A42-A341-259F0FB629A0}'
Event Record #/Type601 / Warning
Event Submitted/Written: 02/07/2008 01:10:20 PM
Event ID/Source: 1004 / MsiInstaller
Event Description:
Detection of product '{99052DB7-9592-4522-A558-5417BBAD48EE}', feature 'ActiveSync', component '{13611E77-B9F9-43C7-85A6-1CB12FD67A1D}' failed. The resource 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows CE Services\Defname' does not exist.
Event R