So I was wondering if anyone could help me. I ran that DSS program that you have available on here and it says I should post a log for someone to look at so here ya go.
Deckard's System Scanner v20071014.68
Run by Jamie on 2008-03-01 17:58:34
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
42: 2008-03-01 22:58:41 UTC - RP42 - Deckard's System Scanner Restore Point
41: 2008-03-01 21:45:53 UTC - RP41 - Installed Ad-Aware 2007
40: 2008-02-29 21:22:25 UTC - RP40 - System Checkpoint
39: 2008-02-28 12:02:09 UTC - RP39 - System Checkpoint
38: 2008-02-27 04:34:29 UTC - RP38 - System Checkpoint
-- First Restore Point --
1: 2008-01-30 01:58:09 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-03-01 17:59:43
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\mgmrwmrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\regsvr32.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Jamie\Desktop\dss.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cbsnews.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b652a4c2-1dd1-11b2-8632-cbb17eccefd0} - C:\WINDOWS\wzyfqpcd.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NAVSHEXT.DLL
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NAVSHEXT.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MDNS] C:\WINDOWS\system32\service.exe
O4 - HKLM\..\Run: [sjspmnyv] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\sjspmnyv.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\Program Files\webHancer\Programs\webhdll.dll
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: https://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: https://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: https://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: https://online.musicmatch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: https://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1201659533162
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.ma...t/ultrashim.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
--
End of file - 10126 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.1.0.1) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.1.0.1>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 RegSrvc - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; RegSrvc Module>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
R2 WLANKEEPER - c:\program files\intel\wireless\bin\wlkeeper.exe <Not Verified; Intel® Corporation; SSOFSet Service>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-01 17:14:25 412 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
-- Files created between 2008-02-01 and 2008-03-01 -----------------------------
2008-03-01 17:59:51 8704 --a------ C:\WINDOWS\xadbrk.dll
2008-03-01 17:59:51 9984 --a------ C:\WINDOWS\liqui.dll
2008-03-01 17:59:51 32512 --a------ C:\WINDOWS\kkcomp.dll
2008-03-01 17:59:50 23296 --a------ C:\WINDOWS\pbsysie.dll
2008-03-01 17:59:50 17920 --a------ C:\WINDOWS\liqad.dll
2008-03-01 17:59:50 29440 --a------ C:\WINDOWS\kvnab.exe
2008-03-01 17:59:50 15360 --a------ C:\WINDOWS\kvnab.dll
2008-03-01 17:59:50 15616 --a------ C:\WINDOWS\kvnab$.exe
2008-03-01 17:59:49 11520 --a------ C:\WINDOWS\wbeCheck.exe
2008-03-01 17:59:49 0 d-------- C:\Program Files\Accoona
2008-03-01 17:59:49 0 d-------- C:\Program Files\3721
2008-03-01 17:49:32 0 d-------- C:\Documents and Settings\Jamie\Application Data\Mozilla
2008-03-01 17:25:31 12544 --a------ C:\WINDOWS\vxddsk.exe
2008-03-01 17:25:31 15872 --a------ C:\WINDOWS\system32\vxddsk.exe
2008-03-01 17:03:59 21248 --a------ C:\WINDOWS\liqui-Uninstaller.exe
2008-03-01 17:03:59 28160 --a------ C:\WINDOWS\liqui.exe
2008-03-01 17:03:59 24320 --a------ C:\WINDOWS\fhfmm.exe
2008-03-01 17:03:58 9984 --a------ C:\WINDOWS\xadbrk_.exe
2008-03-01 17:03:58 9472 --a------ C:\WINDOWS\xadbrk.exe
2008-03-01 17:03:58 9472 --a------ C:\WINDOWS\liqad.exe
2008-03-01 17:03:58 12800 --a------ C:\WINDOWS\liqad$.exe
2008-03-01 17:03:58 10240 --a------ C:\WINDOWS\kkcomp.exe
2008-03-01 17:03:58 15872 --a------ C:\WINDOWS\kkcomp$.exe
2008-03-01 17:03:58 21248 --a------ C:\WINDOWS\fhfmm-Uninstaller.exe
2008-03-01 17:03:57 26368 --a------ C:\WINDOWS\hcwprn.exe
2008-03-01 17:03:57 22784 --a------ C:\WINDOWS\cbinst$.exe
2008-03-01 17:03:56 14336 --a------ C:\WINDOWS\wbeInst$.exe
2008-03-01 17:03:54 22272 --a------ C:\WINDOWS\ie_32.exe
2008-03-01 17:03:54 12032 --a------ C:\WINDOWS\aconti.exe
2008-03-01 17:03:54 0 d-------- C:\Program Files\amsys
2008-03-01 17:03:53 26112 --a------ C:\WINDOWS\xxxvideo.exe
2008-03-01 17:03:53 13312 --a------ C:\WINDOWS\hotporn.exe
2008-03-01 17:03:51 13312 --a------ C:\WINDOWS\wml.exe
2008-03-01 17:03:51 22016 --a------ C:\WINDOWS\764.exe
2008-03-01 17:03:51 0 d-------- C:\Program Files\akl
2008-03-01 16:59:53 0 d-------- C:\Program Files\e-zshopper
2008-03-01 16:45:56 0 d-------- C:\Program Files\Lavasoft
2008-03-01 16:45:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-01 16:45:21 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-01 13:42:33 18432 --a------ C:\WINDOWS\system32\msole32.exe
2008-03-01 13:42:33 23808 --a------ C:\WINDOWS\eventlowg.dll
2008-03-01 13:42:33 18944 --a------ C:\WINDOWS\daxtime.dll
2008-03-01 13:42:28 20992 --a------ C:\WINDOWS\settn.dll
2008-03-01 13:42:26 30976 --a------ C:\WINDOWS\iexplorr23.dll
2008-03-01 13:42:25 32256 --a------ C:\WINDOWS\jd2002.dll
2008-03-01 13:42:25 24576 --a------ C:\WINDOWS\adbar.dll
2008-03-01 13:42:24 30976 --a------ C:\WINDOWS\system32\ESHOPEE.exe
2008-03-01 13:42:24 23552 --a------ C:\WINDOWS\spredirect.dll
2008-03-01 13:42:18 0 d-------- C:\WINDOWS\system32\acespy
2008-03-01 13:42:18 30976 --a------ C:\WINDOWS\system32\ace16win.dll
2008-03-01 13:42:17 30976 --a------ C:\WINDOWS\ngd.dll
2008-03-01 13:42:16 8960 --a------ C:\WINDOWS\dp0.dll
2008-03-01 13:42:15 0 d-------- C:\Program Files\p2pnetworks
2008-03-01 13:42:12 8448 --a------ C:\WINDOWS\system32\wml.exe
2008-03-01 13:42:11 13312 --a------ C:\WINDOWS\pbar.dll
2008-03-01 13:42:11 9728 --a------ C:\WINDOWS\flt.dll
2008-03-01 13:42:11 30208 --a------ C:\WINDOWS\7search.dll
2008-03-01 13:27:14 0 d-------- C:\Program Files\webHancer
2008-03-01 13:27:06 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-03-01 13:27:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-01 13:27:02 89099 --a------ C:\WINDOWS\system32\mgmrwmrv.exe <Not Verified; Microsoft; runbll>
2008-03-01 13:27:01 86528 --a------ C:\WINDOWS\wzyfqpcd.dll
2008-03-01 13:27:01 0 d-------- C:\Program Files\Batco
2008-03-01 13:27:01 86528 --a------ C:\Documents and Settings\All Users\Application Data\sjspmnyv.dll
2008-03-01 13:26:28 0 d-------- C:\Program Files\QdrDrive
2008-03-01 13:26:11 385024 --a------ C:\WINDOWS\system32\WinNB57.dll <Not Verified; ; MBar IES AFF ATD>
2008-03-01 13:26:11 90112 --a------ C:\WINDOWS\system32\service.exe <Not Verified; M i r a r; M i r a r ErrorDnsTest>
2008-03-01 10:56:22 278793 --a------ C:\WINDOWS\system32\000070.exe
2008-02-23 20:47:35 0 d-------- C:\WINDOWS\Sun
2008-02-18 11:32:39 0 d-------- C:\WINDOWS\47D5D869FE574F2FA35883CFAA7B4968.TMP
2008-02-17 22:59:45 0 d-------- C:\Documents and Settings\Jamie\Application Data\MSNInstaller
2008-02-15 13:07:38 0 d-------- C:\HyperCD
2008-02-04 22:21:32 0 d-------- C:\Documents and Settings\Jamie\Application Data\Viewpoint
2008-02-04 21:57:28 0 d-------- C:\Documents and Settings\Jamie\Application Data\acccore
2008-02-04 21:56:39 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-04 21:56:14 0 d-------- C:\Program Files\AIM6
2008-02-03 23:02:43 0 d-------- C:\Documents and Settings\Jamie\Application Data\Corel Photo Album
2008-02-02 13:03:34 0 d-------- C:\Documents and Settings\Jamie\Application Data\Macromedia
-- Find3M Report ---------------------------------------------------------------
2008-03-01 17:13:53 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-01 16:58:21 0 d-------- C:\Program Files\RGB
2008-03-01 16:45:21 0 d-------- C:\Program Files\Common Files
2008-02-16 13:09:14 6580 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-02-16 13:09:13 88 -r-hs---- C:\WINDOWS\system32\E2681A3CD6.sys
2008-02-05 13:06:57 0 d-------- C:\Program Files\Common Files\AOL
2008-02-04 21:56:51 0 d-------- C:\Program Files\Viewpoint
2008-01-31 13:43:20 0 d-------- C:\Documents and Settings\Jamie\Application Data\AdobeUM
2008-01-31 13:43:12 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-31 13:43:12 0 d-------- C:\Documents and Settings\Jamie\Application Data\Adobe
2008-01-31 11:10:09 56 -r-hs---- C:\WINDOWS\system32\D63C1A68E2.sys
2008-01-30 04:41:46 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-01-29 22:38:43 0 d-------- C:\Program Files\DIGStream
2008-01-29 22:23:10 0 d-------- C:\Program Files\Norton AntiVirus
2008-01-29 22:08:27 0 d-------- C:\Program Files\MSXML 4.0
2008-01-29 21:14:35 32 --ahs---- C:\WINDOWS\system32\{67446532-51E5-4624-96E9-F86ED86446B6}.dat
2008-01-29 21:14:35 32 --ahs---- C:\WINDOWS\{266B1F73-8840-4A0E-ADE3-8A3A1F19F35D}.dat
2008-01-29 21:14:07 14 --a------ C:\WINDOWS\system32\SR2.dat
2008-01-29 21:13:41 0 d-------- C:\Program Files\Symantec
2008-01-29 21:13:21 0 d-------- C:\Documents and Settings\Jamie\Application Data\Symantec
2008-01-29 21:01:35 0 d--h----- C:\Documents and Settings\Jamie\Application Data\Gtek
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b652a4c2-1dd1-11b2-8632-cbb17eccefd0}]
03/01/2008 01:27 PM 86528 --a------ C:\WINDOWS\wzyfqpcd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb936323-19fa-4521-ba29-eca6a121bc78}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [09/29/2005 02:01 PM]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [10/14/2005 08:49 PM]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [10/14/2005 08:46 PM]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [10/14/2005 08:50 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [11/29/2005 04:56 AM]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/30/2004 02:59 PM]
"SigmatelSysTrayApp"="stsystra.exe" [09/09/2005 11:19 PM C:\WINDOWS\stsystra.exe]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [09/08/2005 05:20 AM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/19/2002 10:22 PM]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [08/19/2002 10:23 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/19/2006 11:25 AM]
"MDNS"="C:\WINDOWS\system32\service.exe" [03/01/2008 01:26 PM]
"sjspmnyv"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\sjspmnyv.dll" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 05:00 AM]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 09/07/2004 04:08 PM 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowLOMControl]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
-- End of Deckard's System Scanner: finished at 2008-03-01 18:01:11 ------------