Andrew: Scan # 2
Deckard's System Scanner v20071014.68
Run by friend on 2008-03-31 19:15:12
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Performed disk cleanup.
-- HijackThis (run as friend.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:15, on 2008-03-31
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINNT\system32\TpKmpSVC.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\tp4serv.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINNT\system32\RaConfig2500.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Documents and Settings\friend\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\friend.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RaConfig2500.lnk = C:\WINNT\system32\RaConfig2500.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,26/mcgdmgr.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINNT\System32\ibmpmsvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINNT\system32\TpKmpSVC.exe
--
End of file - 7660 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080327-175437-810 O3 - Toolbar: (no name) - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)
backup-20080327-175441-838 O21 - SSODL: buprestidae - {b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - (no file)
backup-20080327-175444-814 O22 - SharedTaskScheduler: buprestidae - {b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - (no file)
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 Smapint - c:\winnt\system32\drivers\smapint.sys <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
R1 TDSMAPI - c:\winnt\system32\drivers\tdsmapi.sys
R1 TPHKDRV - c:\winnt\system32\drivers\tphkdrv.sys <Not Verified; IBM Corporation; ThinkPad OnScreenDisplay>
R1 TPPWR - c:\winnt\system32\drivers\tppwr.sys <Not Verified; IBM Corp.; IBM ThinkPad Utility>
R1 TSMAPIP - c:\winnt\system32\drivers\tsmapip.sys
R2 EGATHDRV (IBM Access Support) - c:\winnt\system32\egathdrv.sys
R2 LBeepKE - c:\winnt\system32\drivers\lbeepke.sys <Not Verified; Logitech Inc.; Logitech SetPoint>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 NAL (Nal Service ) - c:\winnt\system32\drivers\iqvw32.sys <Not Verified; Intel Corporation; Intel® iQVW32.SYS>
S3 sdthook - c:\winnt\system32\drivers\sdthook.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 TpKmpSVC (IBM KCU Service) - c:\winnt\system32\tpkmpsvc.exe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Device
Device ID: PCI\VEN_8086&DEV_2483&SUBSYS_02201014&REV_02\3&61AAA01&0&FB
Manufacturer:
Name: PCI Device
PNP Device ID: PCI\VEN_8086&DEV_2483&SUBSYS_02201014&REV_02\3&61AAA01&0&FB
Service:
-- Process Modules -------------------------------------------------------------
C:\WINNT\system32\WINLOGON.EXE (pid 160)
2007-04-19 12:41:36 294912 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>
2005-06-16 22:23:08 24576 --a------ C:\WINNT\system32\tphklock.dll
C:\WINNT\explorer.exe (pid 1508)
2006-09-01 10:30:30 44544 --a------ C:\Program Files\Logitech\SetPoint\lgscroll.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2006-12-20 12:55:48 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>
2001-07-03 09:17:06 24576 --a------ C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll
-- Scheduled Tasks -------------------------------------------------------------
2008-03-07 21:39:36 334 --a------ C:\WINNT\Tasks\McQcTask.job
2008-01-26 12:01:36 412 --a------ C:\WINNT\Tasks\Auto-scheduled task of Free Registry Fix.job
2005-11-29 00:43:58 300 --a------ C:\WINNT\Tasks\BMMTask.job
-- Files created between 2008-02-29 and 2008-03-31 -----------------------------
2008-03-31 19:09:14 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_4a8.dat
2008-03-30 20:01:51 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_4e8.dat
2008-03-30 20:01:29 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_608.dat
2008-03-30 16:42:06 0 d-------- C:\Documents and Settings\All Users\Application Data\pdf995
2008-03-30 16:42:05 249856 --a------ C:\WINNT\system32\pdfmona.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-03-30 16:42:05 51716 --a------ C:\WINNT\system32\pdf995mon.dll
2008-03-30 16:24:00 0 d-------- C:\Documents and Settings\friend\Application Data\TaxCut
2008-03-30 16:20:47 0 d-a------ C:\Program Files\TaxCut07
2008-03-30 16:20:47 0 d-a------ C:\Program Files\PDF995
2008-03-30 16:18:43 0 d-------- C:\Documents and Settings\All Users\Application Data\TaxCut
2008-03-28 21:45:55 0 d-------- C:\Documents and Settings\friend\Application Data\Logitech
2008-03-28 21:29:52 3712 --a------ C:\WINNT\system32\drivers\LBeepKE.sys <Not Verified; Logitech Inc.; Logitech SetPoint>
2008-03-28 21:29:51 69632 --a------ C:\WINNT\system32\KemXML.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2008-03-28 21:29:51 110592 --a------ C:\WINNT\system32\KemWnd.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2008-03-28 21:29:51 131072 --a------ C:\WINNT\system32\KemUtil.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2008-03-28 21:29:51 155648 --a------ C:\WINNT\system32\kemutb.dll <Not Verified; Logitech Inc.; Logitech SetPoint>
2008-03-28 21:29:47 0 d-a------ C:\Program Files\Common Files\Logitech
2008-03-28 21:29:30 0 d-a------ C:\Program Files\Logitech
2008-03-28 19:16:02 0 d-a------ C:\Program Files\Panda Security
2008-03-27 22:10:06 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-27 22:09:43 0 d-a------ C:\Program Files\SUPERAntiSpyware
2008-03-27 22:09:43 0 d-------- C:\Documents and Settings\friend\Application Data\SUPERAntiSpyware.com
2008-03-27 22:08:44 0 d-a------ C:\Program Files\Common Files\Wise Installation Wizard
2008-03-27 21:45:17 0 d---s---- C:\Documents and Settings\friend\UserData
2008-03-27 19:26:03 0 d-------- C:\Documents and Settings\friend\Application Data\Malwarebytes
2008-03-27 19:25:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-27 19:25:51 0 d-a------ C:\Program Files\Malwarebytes' Anti-Malware
2008-03-27 19:14:23 0 d-------- C:\Documents and Settings\friend\Application Data\Adobe
2008-03-27 19:11:42 0 d-------- C:\Documents and Settings\friend\Application Data\Mozilla
2008-03-27 17:56:44 0 d-------- C:\Documents and Settings\friend\Application Data\Google
2008-03-27 17:52:00 0 d-------- C:\Documents and Settings\friend\Application Data\Share-to-Web Upload Folder
2008-03-27 17:50:18 0 d-------- C:\Documents and Settings\friend\Application Data\Identities
2008-03-27 17:47:57 0 dr------- C:\Documents and Settings\friend\Favorites
2008-03-27 17:47:57 0 d-------- C:\Documents and Settings\friend\Desktop
2008-03-27 17:47:57 0 d---s---- C:\Documents and Settings\friend\Cookies
2008-03-27 17:47:57 0 d--h----- C:\Documents and Settings\friend\Application Data
2008-03-27 17:47:57 0 d-------- C:\Documents and Settings\friend\Application Data\Macromedia
2008-03-27 17:47:56 0 d--h----- C:\Documents and Settings\friend\Templates
2008-03-27 17:47:56 0 d-------- C:\Documents and Settings\friend\Start Menu
2008-03-27 17:47:56 0 d--h----- C:\Documents and Settings\friend\SendTo
2008-03-27 17:47:56 0 dr-h----- C:\Documents and Settings\friend\Recent
2008-03-27 17:47:56 0 d--h----- C:\Documents and Settings\friend\PrintHood
2008-03-27 17:47:56 0 d--h----- C:\Documents and Settings\friend\NetHood
2008-03-27 17:47:56 0 d-------- C:\Documents and Settings\friend\My Documents
2008-03-27 17:47:56 0 d--h----- C:\Documents and Settings\friend\Local Settings
2008-03-27 17:47:55 618496 --ah----- C:\Documents and Settings\friend\NTUSER.DAT
2008-03-27 17:46:17 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_5bc.dat
2008-03-26 22:41:28 25600 --a------ C:\WINNT\system32\WS2Fix.exe
2008-03-26 22:41:28 289144 --a------ C:\WINNT\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-26 22:41:28 86528 --a------ C:\WINNT\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-26 22:41:28 82432 --a------ C:\WINNT\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-26 22:41:28 51200 --a------ C:\WINNT\system32\dumphive.exe
2008-03-26 22:41:27 288417 --a------ C:\WINNT\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-26 22:41:27 53248 --a------ C:\WINNT\system32\Process.exe
2008-03-26 20:54:45 2396 --a------ C:\WINNT\system32\tmp.reg
2008-03-26 18:13:30 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_500.dat
2008-03-26 18:13:13 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_4b0.dat
2008-03-26 18:12:55 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_324.dat
2008-03-25 20:13:30 68096 --a------ C:\WINNT\system32\zip.exe
2008-03-25 20:13:30 98816 --a------ C:\WINNT\system32\sed.exe
2008-03-25 20:13:30 80412 --a------ C:\WINNT\system32\grep.exe
2008-03-25 20:13:30 73728 --a------ C:\WINNT\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-24 20:02:08 2359 --a------ C:\WINNT\mozver.dat
2008-03-23 21:20:22 0 d-------- C:\Documents and Settings\fr.bak\Application Data\Printer Info Cache
2008-03-23 11:55:17 0 d-a------ C:\Program Files\Hewlett-Packard
2008-03-23 10:00:05 0 d-a------ C:\Program Files\CCleaner
2008-03-22 16:38:42 3840 --a------ C:\WINNT\system32\drivers\BANTExt.sys
2008-03-22 16:38:42 0 d-a------ C:\Program Files\Belarc
2008-03-20 21:27:46 0 d-------- C:\Documents and Settings\fr.bak\Application Data\Image Zone Express
2008-03-17 22:20:46 0 d-a------ C:\Program Files\Trend Micro
2008-03-14 21:08:29 0 --a------ C:\WINNT\nsreg.dat
2008-03-14 21:08:25 0 d-------- C:\Documents and Settings\fr.bak\Application Data\Mozilla
2008-03-09 10:16:34 0 d-------- C:\WINNT\system32\Windows Media
2008-03-09 10:13:17 0 d--h---c- C:\WINNT\$NtUpdateRollupPackUninstall$
2008-03-09 10:13:04 0 d-------- C:\WINNT\msiinst.tmp
2008-03-09 09:46:20 0 d-------- C:\Documents and Settings\fr.bak\Application Data\Lavasoft
2008-03-08 13:17:01 0 d-------- C:\monitor
2008-03-08 13:11:00 0 d--h----- C:\WINNT\PIF
2008-03-08 09:14:53 0 d-------- C:\Documents and Settings\fr.bak\Application Data\McAfee
2008-03-08 08:52:19 0 d-------- C:\WINNT\system32\BITS
2008-03-07 22:00:15 0 d-------- C:\WINNT\system32\SoftwareDistribution
2008-03-07 21:42:30 143360 --a------ C:\WINNT\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-03-07 21:39:23 0 d-a------ C:\Program Files\McAfee.com
2008-03-07 21:39:22 0 d-a------ C:\Program Files\Common Files\McAfee
2008-03-07 21:39:16 0 d-a------ C:\Program Files\McAfee
2008-03-07 21:32:08 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-06 21:26:28 0 d-------- C:\WINNT\SoftwareDistribution
2008-03-06 18:55:08 0 d-------- C:\Documents and Settings\fr.bak\Application Data\Adobe
-- Find3M Report ---------------------------------------------------------------
2008-03-28 21:29:30 0 d-ah----- C:\Program Files\InstallShield Installation Information
2008-03-27 22:08:44 0 d-a------ C:\Program Files\Common Files
2008-03-11 22:16:58 0 d-a------ C:\Program Files\RegistryFix
2008-03-11 22:16:19 0 d-a------ C:\Program Files\Free Registry Fix
2008-03-07 21:58:51 0 d-ah----- C:\Program Files\WindowsUpdate
2008-02-13 22:01:17 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_410.dat
2008-01-17 10:59:28 16384 --a-----t C:\WINNT\system32\Perflib_Perfdata_3d0.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="tp4serv.exe" [05-07-13 03:55 C:\WINNT\system32\tp4serv.exe]
"Synchronization Manager"="mobsync.exe" [03-06-19 14:05 C:\WINNT\system32\mobsync.exe]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [02-10-23 10:15 ]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [05-08-29 14:15 ]
"TP4EX"="tp4ex.exe" [05-08-24 01:10 C:\WINNT\system32\TP4EX.exe]
"BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [05-04-20 01:38 ]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [05-09-01 02:21 ]
"tgcmd"="C:\Program Files\support.com\bin\tgcmd.exe" [02-04-24 20:37 ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [08-01-11 22:16 ]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [01-07-03 09:11 ]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [06-07-19 12:03 ]
"@"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [08-02-29 16:03 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-03-28 21:39:31]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 22:05:56]
RaConfig2500.lnk - C:\WINNT\system32\RaConfig2500.exe [2005-12-10 11:14:22]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-12-31 10:12:11]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [06-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 07-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 05-07-05 23:45 28672 C:\WINNT\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
tphklock.dll 05-06-16 22:23 24576 C:\WINNT\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
-- End of Deckard's System Scanner: finished at 2008-03-31 19:16:45 ------------
Will watch for further instructions. Thanks.