Deckard's System Scanner v20071014.68
Run by Curtis on 2008-03-25 22:36:49
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 511 MiB (512 MiB recommended).-- HijackThis (run as Curtis.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:36:57 PM, on 3/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Curtis\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Curtis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.toggle.co....php?rvs=hompagR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1183350288453O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 7823 bytes
-- Files created between 2008-02-25 and 2008-03-25 -----------------------------
2008-03-24 23:54:34 0 d-------- C:\Documents and Settings\Curtis\Application Data\Malwarebytes
2008-03-24 23:54:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-24 23:54:09 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-24 23:50:37 0 d-------- C:\Program Files\Common Files\Java
2008-03-22 09:49:16 0 d-------- C:\Documents and Settings\Curtis\SmitfraudFix <SMITFR~1>
2008-03-22 09:45:42 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-03-22 09:45:42 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-03-22 09:45:42 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-03-22 09:45:42 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-03-22 09:45:42 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-03-22 09:45:42 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-03-22 09:45:42 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-03-22 09:45:42 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-03-22 09:45:42 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-03-22 09:45:42 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-03-22 09:45:42 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-03-22 09:45:42 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-03-22 09:45:42 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-03-22 09:45:42 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-03-22 06:25:13 0 d-------- C:\Program Files\Trend Micro
2008-03-22 06:18:15 2124 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-22 06:17:54 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-22 06:17:54 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-22 06:17:54 86528 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-22 06:17:54 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-22 06:17:54 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-03-22 06:17:54 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-22 06:17:54 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-22 06:04:59 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-21 22:20:36 0 d-------- C:\Program Files\Propellerhead
2008-03-21 22:20:32 0 d-------- C:\WINDOWS\Recent
2008-03-21 22:20:10 0 d-------- C:\Program Files\Common Files\Apple
2008-03-21 22:19:59 0 d-------- C:\Program Files\Acoustica MP3 CD Burner
2008-03-21 22:19:56 0 dr-h----- C:\Documents and Settings\Curtis\Recent
2008-03-21 22:19:54 0 d-------- C:\Documents and Settings\All Users\Application Data\{CFAB4006-0AE0-414D-866A-DCB2C46553CF}
2008-03-21 20:34:00 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-21 20:34:00 0 d-------- C:\Documents and Settings\Curtis\Application Data\SUPERAntiSpyware.com
2008-03-21 12:49:26 9437184 --a------ C:\Documents and Settings\Curtis\ntuser.dat
2008-03-18 21:38:35 0 d-------- C:\WINDOWS\system32\URTTemp
2008-03-08 01:35:30 0 d-------- C:\DVDVideoSoft
2008-03-08 00:12:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-03-08 00:10:46 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-03-07 15:35:18 0 d-------- C:\Program Files\iPod
2008-03-07 15:34:59 0 d-------- C:\Program Files\iTunes
2008-03-07 15:33:33 0 d-------- C:\Program Files\QuickTime
2008-03-05 01:46:50 0 d-------- C:\Program Files\Free TV Player
2008-03-02 12:22:16 0 d-------- C:\Documents and Settings\Curtis\Application Data\Help
2008-03-01 23:41:24 233472 --a------ C:\WINDOWS\system32\REX Shared Library.dll <Not Verified; Propellerhead Software AB; REX SDK>
2008-03-01 23:41:24 368640 --a------ C:\WINDOWS\system32\ReWire.dll <Not Verified; Propellerhead Software AB; ReWire>
2008-03-01 23:41:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
2008-03-01 23:41:14 0 d-------- C:\Documents and Settings\Curtis\Application Data\Propellerhead Software
2008-03-01 17:17:17 0 d-------- C:\Documents and Settings\Curtis\EurekaLog
2008-03-01 13:02:30 0 d--h----- C:\WINDOWS\PIF
2008-03-01 11:55:16 135168 --a------ C:\WINDOWS\system32\DSKernel2.dll <Not Verified; LEAD Technologies, Inc.; LEADTOOLS Multimedia Filter Pack>
2008-03-01 11:54:57 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2008-03-01 11:54:13 0 d-------- C:\Program Files\Replay Converter
-- Find3M Report ---------------------------------------------------------------
2008-03-24 23:51:54 0 d-------- C:\Program Files\Java
2008-03-24 23:50:37 0 d-------- C:\Program Files\Common Files
2008-03-24 23:07:06 4729 --a------ C:\Documents and Settings\Curtis\Application Data\.googlewebacchosts
2008-03-23 22:01:33 0 d-------- C:\Documents and Settings\Curtis\Application Data\AVG7
2008-03-23 21:59:27 0 d-------- C:\Program Files\LimeWire
2008-03-23 13:41:48 0 d-------- C:\Documents and Settings\Curtis\Application Data\uTorrent
2008-03-22 21:50:31 0 d-------- C:\Program Files\Messenger
2008-03-22 21:50:31 0 d-------- C:\Program Files\MagicISO
2008-03-22 21:50:30 0 d-------- C:\Program Files\Incomplete
2008-03-22 21:50:28 0 d-------- C:\Program Files\Waves
2008-03-22 21:50:28 0 d-------- C:\Program Files\TVUPlayer
2008-03-22 21:50:25 0 d-------- C:\Program Files\Movie Maker
2008-03-22 21:50:24 0 d-------- C:\Program Files\DivX
2008-03-22 06:04:19 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-21 22:20:47 0 d-------- C:\Program Files\Real
2008-03-21 22:19:26 0 d-------- C:\Program Files\Steinberg
2008-03-21 20:41:10 0 d-------- C:\Program Files\Rhapsody
2008-03-20 20:57:39 0 d-------- C:\Documents and Settings\Curtis\Application Data\LimeWire
2008-03-18 20:23:53 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-08 01:31:59 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-03-08 01:31:53 0 d-------- C:\Program Files\DVDVideoSoft
2008-03-08 00:13:43 0 d-------- C:\Documents and Settings\Curtis\Application Data\Adobe
2008-03-08 00:10:38 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-05 01:46:40 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-04 19:57:37 2054 --a------ C:\WINDOWS\mozver.dat
2008-03-02 22:05:54 0 d-------- C:\Documents and Settings\Curtis\Application Data\Simple Star
2008-02-24 20:56:12 0 d-------- C:\Documents and Settings\Curtis\Application Data\Acoustica
2008-02-24 00:44:45 2551 --a------ C:\WINDOWS\unins000.dat
2008-02-24 00:27:44 691545 --a------ C:\WINDOWS\unins000.exe
2008-02-23 23:44:08 4 --a------ C:\WINDOWS\system32\4CF712
2008-02-06 00:32:10 0 d-------- C:\Documents and Settings\Curtis\Application Data\Steinberg
2008-02-01 20:53:22 0 d-------- C:\Program Files\Google
2008-01-30 04:32:26 0 d-------- C:\Documents and Settings\Curtis\Application Data\MSN6
2008-01-29 21:44:01 2560 --a------ C:\WINDOWS\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-01-25 18:05:34 0 d-------- C:\Program Files\BitComet
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [02/01/2008 12:13 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 02:10 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [12/07/2007 08:03 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 12:43 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
"C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
"C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TransferAgent"=
"OESYFplugin"=
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"Pando"="C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized
"BitComet"="C:\Program Files\BitComet\BitComet.exe" /tray
"<NO NAME>"=
"PhotoShow Deluxe Media Manager"=C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SigmatelSysTrayApp"=stsystra.exe
"REGSHAVE"=C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe
"{83-32-2A-A2-ZN}"=C:\DOCUME~1\Curtis\LOCALS~1\Temp\TICHA001.exe CHA001
"WinZip E-Mail Companion OEAPI"="C:\Program Files\WinZip E-Mail Companion\loadwzco.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09d01485-4165-11dc-8a3b-00123f93b1e2}]
AutoRun\command- D:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2008-03-25 22:37:15 ------------