As requested, copy of
main.txtDeckard's System Scanner v20071014.68
Run by Nick on 2008-02-13 19:23:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
18: 2008-02-10 01:09:29 UTC - RP90 - Installed SUPERAntiSpyware Free Edition
17: 2008-02-09 22:18:15 UTC - RP89 - ComboFix created restore point
16: 2008-02-09 09:36:40 UTC - RP88 - Scheduled Checkpoint
15: 2008-02-07 21:48:04 UTC - RP87 - Windows Update
14: 2008-02-07 20:35:43 UTC - RP86 - Installed Ad-Aware 2007
-- First Restore Point --
1: 2008-02-04 23:47:44 UTC - RP72 - Windows Update
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Nick.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:27:24 PM, on 2/13/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\FDF\FAST2.EXE
C:\Windows\ehome\ehtray.exe
C:\Users\Nick\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\SyncServer.exe
C:\program files\internet explorer\ieuser.exe
C:\Users\Nick\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Nick.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...a...n&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...a...n&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...a...n&pf=laptopR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WAWifiMessage] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe"
O4 - HKLM\..\Run: [SynTPStart] "C:\Program Files\Synaptics\SynTP\SynTPStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] "C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] "C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [SecurDisc] "C:\Program Files\Nero\Nero8\InCD\NBHGui.exe"
O4 - HKLM\..\Run: [InCD] "C:\Program Files\Nero\Nero8\InCD\InCD.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [HPAdvisor] "C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" autoRun
O4 - HKCU\..\Run: [FAST Defrag] "C:\PROGRA~1\FDF\FAST2.EXE" -tray
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Nick\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewi...oOnlineScan.cabO16 - DPF: {389956FE-3A45-469C-B944-70308E06BAAC} (CVServerObject Object) -
http://argushighland...rg/videocom.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1005.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebo...toUploader3.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\deskscapes.dll
O22 - SharedTaskScheduler: Stardock Vista ControlPanel Extension - {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\DesktopControlPanel.dll
O22 - SharedTaskScheduler: StardockDreamController - {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - C:\PROGRA~1\Stardock\OBJECT~2\DESKSC~1\DreamControl.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 14387 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.js - jsfile - DefaultIcon - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe",7.js - jsfile - shell\open\command - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SASDIFSV - \??\c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - \??\c:\program files\superantispyware\saskutil.sys
R3 SASENUM - \??\c:\program files\superantispyware\sasenum.sys
S0 OemBiosDevice (Royalty OEM BIOS Extension) - c:\windows\system32\drivers\royal.sys <Not Verified; PARADOX; SLP Kernel-Mode Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 CLCapSvc (CyberLink Background Capture Service (CBCS)) - "c:\program files\hp\quickplay\kernel\tv\clcapsvc.exe" <Not Verified; ; CLCapSvc Module>
R2 HP Health Check Service - "c:\program files\hewlett-packard\hp health check\hphc_service.exe" <Not Verified; Hewlett-Packard; HP Health Check Service>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S2 CLSched (CyberLink Task Scheduler (CTS)) - "c:\program files\hp\quickplay\kernel\tv\clsched.exe" <Not Verified; ; CLSched Module>
S2 RoxLiveShare9 (LiveShare P2P Server 9) - "c:\program files\common files\roxio shared\9.0\sharedcom\roxliveshare9.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4d36e97d-e325-11ce-bfc1-08002be10318}
Description: Plug and Play Software Device Enumerator
Device ID: ROOT\SYSTEM\0000
Manufacturer: (Standard system devices)
Name: Plug and Play Software Device Enumerator
PNP Device ID: ROOT\SYSTEM\0000
Service: swenum
-- Files created between 2008-01-13 and 2008-02-13 -----------------------------
2008-02-12 15:50:23 0 d-------- C:\Program Files\iPhoneRingToneMaker
2008-02-12 11:30:14 0 d-------- C:\Program Files\ZiPhoneGUI
2008-02-11 17:02:39 56016 --a------ C:\ziphone
2008-02-11 17:02:39 276480 --a------ C:\ziphone.exe <Not Verified; Zibri; ZiPhone>
2008-02-11 17:02:35 33550336 --a------ C:\zibri.dat
2008-02-11 17:02:35 0 d-------- C:\V_ZiPhone
2008-02-11 17:02:35 311296 --a------ C:\QTMLClient.dll <Not Verified; Apple Inc.; QuickTime>
2008-02-11 17:02:35 1085440 --a------ C:\iTunesMobileDevice.dll <Not Verified; Apple Inc.; iTunesMobileDevice>
2008-02-11 12:21:15 0 d-------- C:\Program Files\ElcomSoft
2008-02-10 14:55:41 0 d-------- C:\Program Files\Sophos
2008-02-09 21:45:56 0 d-------- C:\Program Files\Trend Micro
2008-02-09 20:21:09 53248 --a------ C:\Windows\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-02-09 19:11:11 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-02-09 19:10:37 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-02-09 16:17:47 68096 --a------ C:\Windows\system32\zip.exe
2008-02-09 16:17:47 98816 --a------ C:\Windows\system32\sed.exe
2008-02-09 16:17:47 80412 --a------ C:\Windows\system32\grep.exe
2008-02-09 16:17:47 73728 --a------ C:\Windows\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-09 14:02:39 0 d-------- C:\bintheredunthat
2008-02-09 13:53:46 0 d-------- C:\BFU
2008-02-09 11:12:42 0 d-------- C:\VundoFix Backups
2008-02-07 14:36:36 0 d-------- C:\Program Files\Lavasoft
2008-02-07 14:36:34 0 d-------- C:\Users\All Users\Lavasoft
2008-02-07 13:57:37 0 d-------- C:\Users\All Users\ESET
2008-02-07 11:44:42 0 d-------- C:\Users\All Users\Avg7
2008-02-07 00:19:37 86144 --a------ C:\Windows\system32\drivers\cdr4xxpp.sys
2008-02-07 00:17:37 25600 -r-hs---- C:\Windows\winini.exe
2008-02-07 00:00:35 0 d-------- C:\Program Files\Nero
2008-02-07 00:00:34 0 d-------- C:\Users\All Users\Nero
2008-02-07 00:00:34 0 d-------- C:\Program Files\Common Files\Nero
2008-02-05 19:32:20 249856 --a------ C:\Windows\system32\pdfmona.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-02-05 19:32:20 51716 --a------ C:\Windows\system32\pdf995mon.dll
2008-02-05 19:32:20 0 d-------- C:\Users\All Users\pdf995
2008-02-05 19:30:36 0 d-------- C:\Program Files\TaxCut07
2008-02-05 19:30:36 0 d-------- C:\Program Files\PDF995
2008-02-05 19:29:29 0 d-------- C:\Users\All Users\TaxCut
2008-02-05 14:56:36 0 d-------- C:\Users\All Users\FLEXnet
2008-02-05 14:43:31 0 d-------- C:\Program Files\Common Files\Control Panels
2008-02-05 14:39:44 0 d-------- C:\Users\All Users\ALM
2008-02-05 13:18:18 0 d-------- C:\Program Files\Bonjour
2008-02-05 13:09:44 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-31 22:44:42 256 --a------ C:\Windows\system32\pool.bin
2008-01-31 21:45:09 0 d-------- C:\Program Files\Common Files\Research In Motion
2008-01-31 12:32:15 0 d-------- C:\Windows\pss
2008-01-31 10:06:48 0 d-------- C:\Users\All Users\Stardock
2008-01-30 21:53:49 0 d-------- C:\Users\All Users\Webroot
2008-01-30 21:53:49 0 d-------- C:\Program Files\Webroot
2008-01-30 21:49:24 164 --a------ C:\install.dat
2008-01-30 21:08:27 0 dr------- C:\Users\Administrator\Searches
2008-01-30 21:08:16 0 dr------- C:\Users\Administrator\Contacts
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Templates
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Start Menu
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\SendTo
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Recent
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\PrintHood
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\NetHood
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\My Documents
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Local Settings
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Cookies
2008-01-30 21:08:07 0 d--hs---- C:\Users\Administrator\Application Data
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Videos
2008-01-30 21:08:06 0 d-------- C:\Users\Administrator\video
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Saved Games
2008-01-30 21:08:06 0 d-------- C:\Users\Administrator\Roaming
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Pictures
2008-01-30 21:08:06 1048576 --a------ C:\Users\Administrator\NTUSER.DAT
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Music
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Links
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Favorites
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Downloads
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Documents
2008-01-30 21:08:06 0 dr------- C:\Users\Administrator\Desktop
2008-01-30 21:08:06 0 d--h----- C:\Users\Administrator\AppData
2008-01-30 18:02:48 0 d-------- C:\Users\All Users\Office Genuine Advantage
2008-01-29 19:53:40 0 d-------- C:\Users\All Users\InstallShield
2008-01-29 19:32:24 0 d-------- C:\Program Files\Research In Motion
2008-01-25 14:46:23 32 --a------ C:\Windows\go
2008-01-25 14:46:07 0 d-------- C:\Windows\vf_hip
2008-01-25 14:46:06 0 d-------- C:\Program Files\Hide IP Platinum
2008-01-25 14:32:20 0 d-------- C:\Program Files\ProxyShell
2008-01-20 16:32:58 0 d-------- C:\Program Files\FDF
2008-01-20 16:22:48 0 d-------- C:\Program Files\CCleaner
2008-01-16 22:29:47 0 d-------- C:\Program Files\iPod
2008-01-16 22:29:34 0 d-------- C:\Program Files\iTunes
2008-01-16 22:26:19 0 d-------- C:\Program Files\QuickTime
2008-01-16 15:56:48 0 d-------- C:\Program Files\LimeWire
2008-01-16 00:04:04 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
-- Find3M Report ---------------------------------------------------------------
2008-02-13 19:27:02 0 d-------- C:\Users\Nick\AppData\Roaming\DNA
2008-02-12 15:51:09 0 d-------- C:\Users\Nick\AppData\Roaming\iPhoneRingToneMaker
2008-02-11 12:46:05 0 d-------- C:\Users\Nick\AppData\Roaming\BitTorrent
2008-02-10 15:28:52 0 d-------- C:\Program Files\MySpace
2008-02-09 19:10:37 0 d-------- C:\Users\Nick\AppData\Roaming\SUPERAntiSpyware.com
2008-02-09 19:09:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-07 13:03:56 0 d-------- C:\Users\Nick\AppData\Roaming\Research In Motion
2008-02-07 00:09:14 0 d-------- C:\Users\Nick\AppData\Roaming\Nero
2008-02-07 00:00:34 0 d-------- C:\Program Files\Common Files
2008-02-06 12:55:27 0 d-------- C:\Users\Nick\AppData\Roaming\LimeWire
2008-02-06 10:46:48 0 d-------- C:\Program Files\UseNeXT
2008-02-06 10:45:06 0 d-------- C:\Users\Nick\AppData\Roaming\UseNeXT
2008-02-06 00:28:31 0 d-------- C:\Users\Nick\AppData\Roaming\Adobe
2008-02-05 19:31:58 0 d-------- C:\Users\Nick\AppData\Roaming\TaxCut
2008-02-05 14:47:10 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-04 20:43:12 0 d-------- C:\Users\Nick\AppData\Roaming\Move Networks
2008-01-31 22:26:54 0 d-------- C:\Program Files\Roxio
2008-01-31 22:26:44 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-01-31 22:26:40 0 d-------- C:\Program Files\Common Files\PX Storage Engine
2008-01-31 17:53:22 0 d-------- C:\Users\Nick\AppData\Roaming\dvdcss
2008-01-31 17:00:17 0 d-------- C:\Users\Nick\AppData\Roaming\Roxio
2008-01-31 10:06:37 0 d-------- C:\Program Files\Stardock
2008-01-30 21:53:49 0 d-------- C:\Users\Nick\AppData\Roaming\Webroot
2008-01-30 20:50:44 0 d-------- C:\Program Files\Microsoft Games
2008-01-29 20:10:19 0 d-------- C:\Users\Nick\AppData\Roaming\InstallShield
2008-01-29 19:50:05 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-27 12:57:59 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-27 12:57:19 0 d-------- C:\Program Files\Hewlett-Packard
2008-01-16 15:11:48 0 d-------- C:\Users\Nick\AppData\Roaming\iMP3Tunes
2008-01-11 01:01:26 0 d-------- C:\Program Files\Windows Mail
2008-01-11 01:01:23 0 d-------- C:\Program Files\Windows Sidebar
2008-01-03 23:18:41 0 d-------- C:\Program Files\RocketDock
2008-01-03 22:36:54 0 d-------- C:\Program Files\Common Files\Stardock
2008-01-02 11:31:06 0 d-------- C:\Program Files\BitLocker
2008-01-01 16:38:48 0 d-------- C:\Program Files\No1 DVD Ripper
2008-01-01 15:30:51 0 d-------- C:\Program Files\Xilisoft
2008-01-01 14:35:41 0 d-------- C:\Program Files\Cucusoft
2007-12-30 22:29:23 0 d-------- C:\Users\Nick\AppData\Roaming\DivX
2007-12-30 18:46:23 0 d-------- C:\Users\Nick\AppData\Roaming\Apple Computer
2007-12-30 18:18:38 0 d-------- C:\Users\Nick\AppData\Roaming\MySpace
2007-12-29 15:06:32 0 d-------- C:\Program Files\DivX
2007-12-29 14:01:14 0 d-------- C:\Users\Nick\AppData\Roaming\Hewlett-Packard
2007-12-29 12:14:21 0 d-------- C:\Users\Nick\AppData\Roaming\Identities
2007-12-29 00:48:23 174 --ahs---- C:\Program Files\desktop.ini
2007-12-29 00:43:25 0 d-------- C:\Program Files\Windows Calendar
2007-12-29 00:43:13 0 d-------- C:\Program Files\Windows Defender
2007-12-28 22:47:07 0 d-------- C:\Program Files\MSBuild
2007-12-28 22:41:57 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2007-12-28 22:20:27 0 d-------- C:\Program Files\HandyOEM
2007-12-28 22:09:05 162 --a------ C:\Windows\system32\LOG
2007-12-28 22:01:51 21316 --a------ C:\Windows\system32\emptyregdb.dat
2007-12-28 21:54:23 0 d-------- C:\Users\Nick\AppData\Roaming\WildTangent
2007-12-28 21:54:21 0 d-------- C:\Users\Nick\AppData\Roaming\Macromedia
2007-12-28 21:54:21 0 d-------- C:\Users\Nick\AppData\Roaming\HP
2007-12-28 21:54:20 0 d-------- C:\Users\Nick\AppData\Roaming\GTek
2007-12-28 21:54:20 0 d-------- C:\Users\Nick\AppData\Roaming\CyberLink
2007-12-28 21:43:06 0 d-------- C:\Program Files\Yahoo!
2007-12-28 21:43:05 0 d-------- C:\Program Files\Vongo
2007-12-28 21:43:05 0 d-------- C:\Program Files\SP38015
2007-12-28 21:42:49 0 d-------- C:\Program Files\Realtek
2007-12-28 21:42:49 0 d-------- C:\Program Files\Real
2007-12-28 21:42:42 0 d-------- C:\Program Files\Online Services
2007-12-28 21:42:37 0 d-------- C:\Program Files\muvee Technologies
2007-12-28 21:42:36 0 d-------- C:\Program Files\Microsoft.NET
2007-12-28 21:42:36 0 d-------- C:\Program Files\Microsoft Works
2007-12-28 21:42:13 0 d-------- C:\Program Files\Java
2007-12-28 21:42:03 0 d-------- C:\Program Files\iQmetrix
2007-12-28 21:41:59 0 d-------- C:\Program Files\Intel
2007-12-28 21:41:58 0 d-------- C:\Program Files\HPQ
2007-12-28 21:41:53 0 d-------- C:\Program Files\HP Games
2007-12-28 21:37:35 0 d-------- C:\Program Files\HP
2007-12-28 21:33:46 0 d-------- C:\Program Files\earthlink totalaccess
2007-12-28 21:33:45 0 d-------- C:\Program Files\DNA
2007-12-28 21:33:45 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-28 21:33:45 0 d-------- C:\Program Files\Common Files\SureThing Shared
2007-12-28 21:33:30 0 d-------- C:\Program Files\Common Files\muvee Technologies
2007-12-28 21:33:22 0 d-------- C:\Program Files\Common Files\LightScribe
2007-12-28 21:33:21 0 d-------- C:\Program Files\Common Files\Java
2007-12-28 21:33:21 0 d-------- C:\Program Files\Common Files\HP
2007-12-28 21:33:10 0 d-------- C:\Program Files\Common Files\Apple
2007-12-28 21:33:07 0 d-------- C:\Program Files\BitTorrent
2007-12-28 21:33:07 0 d-------- C:\Program Files\Apple Software Update
2007-12-28 21:33:04 0 d-------- C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2007-12-28 21:29:51 0 d-------- C:\Program Files\Motorola
2007-12-28 21:29:35 0 d-------- C:\Program Files\Synaptics
2007-12-27 18:30:22 0 d-------- C:\Users\Nick\AppData\Roaming\WinRAR
2007-12-25 00:37:22 28915 --a------ C:\Users\Nick\AppData\Roaming\UserTile.png
2007-12-25 00:37:22 0 d-------- C:\Users\Nick\AppData\Roaming\PeerNetworking
2007-12-24 23:25:03 0 d-------- C:\Program Files\MSXML 4.0
2007-12-24 23:19:29 0 d-------- C:\Program Files\Common Files\SWF Studio
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile-based device management"="%windir%\WindowsMobile\wmdSync.exe" []
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [12/29/2007 12:28 AM]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [01/10/2007 05:12 PM]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [09/15/2007 02:29 AM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [09/15/2007 02:50 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [10/09/2006 02:43 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/10/2008 03:27 PM]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [04/23/2007 07:11 PM]
"Persistence"="C:\Windows\system32\igfxpers.exe" [10/18/2007 09:18 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [01/15/2008 03:22 AM]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [10/18/2007 09:19 AM]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [02/12/2007 08:37 AM]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [03/01/2007 02:18 PM]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [02/17/2005 12:11 AM]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [06/05/2007 09:12 AM]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [10/18/2007 09:18 AM]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [05/10/2007 10:46 PM]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [03/20/2007 04:40 PM]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [03/01/2007 02:57 PM]
"SecurDisc"="C:\Program Files\Nero\Nero8\InCD\NBHGui.exe" [12/13/2007 10:02 PM]
"InCD"="C:\Program Files\Nero\Nero8\InCD\InCD.exe" [12/13/2007 10:02 PM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [12/03/2007 02:21 PM]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [12/21/2007 08:21 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/10/2008 07:46 PM]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [09/11/2006 04:40 AM]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [03/20/2007 04:23 PM]
"FAST Defrag"="C:\PROGRA~1\FDF\FAST2.exe" [08/24/2005 12:12 PM]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [11/02/2006 06:34 AM]
"BitTorrent DNA"="C:\Users\Nick\Program Files\DNA\btdna.exe" [02/12/2008 04:03 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 06:33 AM]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [12/13/2007 07:10 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [06/21/2007 02:06 PM]
C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [10/26/2006 9:24:54 PM]
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [1/3/2008 10:36:54 PM]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [10/23/2006 2:48:20 AM]
Desktop Manager.lnk - C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe [8/17/2007 9:14:08 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile wcescomm rapimgr
LocalServiceRestricted WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-02-13 19:28:53 ------------
Copy of
extra.txtDeckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft® Windows Vista™ Ultimate (build 6000)
Architecture: X86; Language: English
CPU 0: Intel® Core2 Duo CPU T5250 @ 1.50GHz
Percentage of Memory in Use: 49%
Physical Memory (total/avail): 2037.81 MiB / 1024.31 MiB
Pagefile Memory (total/avail): 4293.63 MiB / 3076.32 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1908.04 MiB
C: is Fixed (NTFS) - 224.6 GiB total, 121.49 GiB free.
D: is Fixed (NTFS) - 8.28 GiB total, 1.82 GiB free.
E: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - FUJITSU MHY2250BH - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 224.6 GiB - C:
\PARTITION1 - Installable File System - 8.28 GiB - D:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AV: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)
AS: ESET NOD32 Antivirus 3.0 v3.0 (ESET, spol. s r. o.)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)
AS: Spy Sweeper v5.5.7.124 (Webroot Software Inc)
Disabled[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Nick\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=NICK-SI
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Nick
LOCALAPPDATA=C:\Users\Nick\AppData\Local
LOGONSERVER=\\NICK-SI
NUMBER_OF_PROCESSORS=2
OnlineServices=Online Services
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PAYMENTECH_HOME=C:\Program Files\iQmetrix\RetailiQ\Paymentech\
PAYMENTECH_LOGDIR=C:\Program Files\iQmetrix\RetailiQ\Paymentech\logs
PCBRAND=Pavilion
PLATFORM=MCD
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Nick\AppData\Local\Temp
TMP=C:\Users\Nick\AppData\Local\Temp
USERDOMAIN=NICK-SI
USERNAME=Nick
USERPART=E:
USERPROFILE=C:\Users\Nick
windir=C:\Windows
-- User Profiles ---------------------------------------------------------------
Nick
Mcx1
Administrator
(new local, admin, net ready)-- Add/Remove Programs ---------------------------------------------------------
--> "C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
--> "C:\Program Files\HP Games\Blackhawk Striker 2\Uninstall.exe"
--> "C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
--> "C:\Program Files\HP Games\Bookworm Deluxe\Uninstall.exe"
--> "C:\Program Files\HP Games\Bounce Symphony\Uninstall.exe"
--> "C:\Program Files\HP Games\Cake Mania\Uninstall.exe"
--> "C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
--> "C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
--> "C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
--> "C:\Program Files\HP Games\Family Feud\Uninstall.exe"
--> "C:\Program Files\HP Games\FATE\Uninstall.exe"
--> "C:\Program Files\HP Games\Final Drive Fury\Uninstall.exe"
--> "C:\Program Files\HP Games\Flip Words\Uninstall.exe"
--> "C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
--> "C:\Program Files\HP Games\Jewel Quest\Uninstall.exe"
--> "C:\Program Files\HP Games\Lemonade Tycoon 2\Uninstall.exe"
--> "C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
--> "C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
--> "C:\Program Files\HP Games\Otto\Uninstall.exe"
--> "C:\Program Files\HP Games\Penguins!\Uninstall.exe"
--> "C:\Program Files\HP Games\Phoenix Assault\Uninstall.exe"
--> "C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
--> "C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
--> "C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
--> "C:\Program Files\HP Games\SCRABBLE\Uninstall.exe"
--> "C:\Program Files\HP Games\Snowboard SuperJam\Uninstall.exe"
--> "C:\Program Files\HP Games\SpongeBob SquarePants Krabby Quest\Uninstall.exe"
--> "C:\Program Files\HP Games\Super Granny\Uninstall.exe"
--> "C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
--> "C:\Program Files\HP Games\Wheel of Fortune\Uninstall.exe"
--> "C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Windows\NuNInst.exe /UNINSTALL
--> C:\Windows\UNNeroBackItUp.exe /UNINSTALL
--> C:\Windows\UNNeroMediaHome.exe /UNINSTALL
--> C:\Windows\UNNeroShowTime.exe /UNINSTALL
--> C:\Windows\UNNeroVision.exe /UNINSTALL
--> C:\Windows\UNRecode.exe /UNINSTALL
#1 DVD Ripper 6.2.3 --> C:\Program Files\No1 DVD Ripper\uninst.exe
Activation Assistant for the 2007 Microsoft Office suites --> "C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Add or Remove Adobe Creative Suite 3 Master Collection --> C:\Program Files\Common Files\Adobe\Installers\915239ded2552e78978d0dbab7657a5\Setup.exe
Adobe After Effects CS3 --> MsiExec.exe /I{EB0202F7-016A-410C-ADE4-40F848CCC661}
Adobe After Effects CS3 Presets --> MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}
Adobe After Effects CS3 Template Projects & Footage --> MsiExec.exe /I{73E81E9B-7319-43AD-B7CC-1C61405E5089}
Adobe After Effects CS3 Third Party Content --> MsiExec.exe /I{7ECEF10B-F1C2-4FD5-861F-A3FCB4653304}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Audition 3.0 --> msiexec /I {53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe BridgeTalk Plugin CS3 --> MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Contribute CS3 --> MsiExec.exe /I{FC9E08AA-CD59-4C59-BEF9-87E05B9E37D7}
Adobe Creative Suite 3 Master Collection --> MsiExec.exe /I{60B28ECA-78BC-4D18-AB63-4A9A93BF881D}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe Dreamweaver CS3 --> MsiExec.exe /I{7C10F5C7-F00F-4BD3-A110-C7D240D2DD25}
Adobe Encore CS3 --> MsiExec.exe /I{54B2EAD9-A110-43F7-B010-2859A1BD2AFE}
Adobe Encore CS3 Codecs --> MsiExec.exe /I{B8B7A4D8-80E1-4DAE-BD33-7FD535BA3931}
Adobe Encore CS3 Library --> MsiExec.exe /I{F1D93F5B-881F-49E3-BA56-B4B8FA991059}
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Extension Manager CS3 --> MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
Adobe Fireworks CS3 --> MsiExec.exe /I{7DFC1012-D346-46CE-B03E-FF79125AE029}
Adobe Flash CS3 --> MsiExec.exe /I{6B52140A-F189-4945-BFFC-DB3F00B8C589}
Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
Adobe Flash Player 9 Plugin --> MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Video Encoder --> MsiExec.exe /I{2EFFFC71-1E66-454E-A6E6-CEEC800B96D2}
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}
Adobe Illustrator CS3 --> MsiExec.exe /I{F08E8D2E-F132-4742-9C87-D5FF223A016A}
Adobe InDesign CS3 --> MsiExec.exe /I{CB3F8375-B600-4B9F-83C9-238ED1E583FD}
Adobe InDesign CS3 Icon Handler --> MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe MotionPicture Color Files --> MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
Adobe Premiere Pro CS3 --> MsiExec.exe /I{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}
Adobe Premiere Pro CS3 Functional Content --> MsiExec.exe /I{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}
Adobe Premiere Pro CS3 Third Party Content --> MsiExec.exe /I{485ACF57-F364-440A-8496-E1E81C8FA1AA}
Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A80000000002}
Adobe Setup --> MsiExec.exe /I{4DC49A9A-6DD0-40D2-A851-527764DA8379}
Adobe SING CS3 --> MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}
Adobe Soundbooth CS3 --> MsiExec.exe /I{A6B23EFA-6590-482C-A11F-5ACE1B91F5B9}
Adobe Soundbooth CS3 Codecs --> MsiExec.exe /I{0327FA9D-975C-448C-A086-577D57BB25B8}
Adobe Soundbooth CS3 Scores --> MsiExec.exe /I{92A300C0-E97B-48CC-9702-AB1AAED167E1}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe Version Cue CS3 Server --> MsiExec.exe /I{1D58229F-C505-45CA-8223-F35F3A34B963}
Adobe Video Profiles --> MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
Adobe WAS CS3 --> MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP DVA Panels CS3 --> MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
Adobe XMP Panels CS3 --> MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
Advanced Archive Password Recovery (remove only) --> C:\Program Files\ElcomSoft\ARCHPR\uninstall.exe
AHV content for Acrobat and Flash --> MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
Apple Mo