Thanks for your help i really appreciate it here are the two files.
Deckard's System Scanner v20071014.68
Run by Me on 2008-03-25 12:07:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
32: 2008-03-25 12:07:40 UTC - RP427 - Deckard's System Scanner Restore Point
31: 2008-03-24 17:58:22 UTC - RP426 - ComboFix created restore point
30: 2008-03-24 12:36:06 UTC - RP425 - System Checkpoint
29: 2008-03-22 13:46:16 UTC - RP424 - Installed UFO Aftershock
28: 2008-03-21 15:26:26 UTC - RP423 - Installed Hearts of Iron 2
-- First Restore Point --
1: 2008-03-07 18:36:21 UTC - RP396 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Me.exe) --------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:47, on 25/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Documents and Settings\All Users\Application Data\nqlovazk\rwlilcbm.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe
D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\lanihmdw.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Me\My Documents\Downloads\Programs\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Me.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.comR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: 2nd &Speech Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [LXBRKsk] C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Yahoo! Pager] ~"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [gccsmzhw] C:\WINDOWS\system32\lanihmdw.exe
O4 - HKCU\..\Run: [mogdfrhv] C:\WINDOWS\system32\ilshwbat.exe
O4 - HKLM\..\Policies\Explorer\Run: [3qSKGYzPVO] C:\Documents and Settings\All Users\Application Data\nqlovazk\rwlilcbm.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PacificPoker - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk/
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.exe.imgfar...p1.0.0.15-3.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.co.../sysreqlab2.cabO16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamesp...nch/alaunch.cabO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://crucial.com/c.../cpcScanner.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\KService\KService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 13363 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 prosync1 (StarForce Protection Synchronization Driver v1) - c:\windows\system32\drivers\prosync1.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; Protection Technology; StarForce Protection System>
R2 atksgt - c:\windows\system32\drivers\atksgt.sys
R2 lirsgt - c:\windows\system32\drivers\lirsgt.sys
R3 Intels51 (Intel® 536EP Modem) - c:\windows\system32\drivers\intels51.sys <Not Verified; Intel Corporation; Intel® 536EP Modem Driver>
R3 Maplom - c:\windows\system32\drivers\maplom.sys <Not Verified; SlySoft Inc.; Game Jackal>
R3 Pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S3 catchme - c:\docume~1\me\locals~1\temp\catchme.sys (file missing)
S3 cel90xbe - c:\docume~1\me\locals~1\temp\cel90xbe.sys (file missing)
S3 NuVision (Hauppauge WinTV USB Pro (PAL I,D/K)) - c:\windows\system32\drivers\nuvision.sys <Not Verified; Hauppauge Computer Works; WinTV USB>
S3 SaiMini - c:\windows\system32\drivers\saimini.sys <Not Verified; Saitek; Configuration Software>
S3 SaiNtBus - c:\windows\system32\drivers\saibus.sys <Not Verified; Saitek; Configuration Software>
S3 Winacusb - c:\windows\system32\drivers\winacusb.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 StarWindServiceAE (StarWind AE Service) - c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe <Not Verified; Rocket Division Software; StarWind Alcohol Edition>
S2 KService - "c:\program files\kservice\kservice.exe" (file missing)
S3 nmraapache (Pure Networks Net2Go Service) - "c:\program files\pure networks\network magic\webserver\bin\nmraapache.exe" -k runservice <Not Verified; Pure Networks, Inc.; Pure Networks Net2Go Service>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Multimedia Audio Controller
Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_80B01043&REV_02\3&267A616A&0&FD
Manufacturer:
Name: Multimedia Audio Controller
PNP Device ID: PCI\VEN_8086&DEV_24D5&SUBSYS_80B01043&REV_02\3&267A616A&0&FD
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-03-22 17:29:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-03-22 01:00:37 370 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
-- Files created between 2008-02-25 and 2008-03-25 -----------------------------
2008-03-24 19:10:58 0 d-------- C:\Program Files\Trend Micro
2008-03-24 18:06:11 114688 --a------ C:\WINDOWS\system32\ilshwbat.exe
2008-03-24 17:57:41 68096 --a------ C:\WINDOWS\system32\zip.exe
2008-03-24 17:57:41 98816 --a------ C:\WINDOWS\system32\sed.exe
2008-03-24 17:57:41 80412 --a------ C:\WINDOWS\system32\grep.exe
2008-03-24 17:57:41 73728 --a------ C:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-24 14:33:31 0 d-------- C:\Documents and Settings\Me\Application Data\Grisoft
2008-03-24 14:27:43 0 d-------- C:\Documents and Settings\Me\Application Data\PC-Cleaner
2008-03-24 14:27:12 0 d-------- C:\Program Files\PC-Cleaner
2008-03-24 14:23:07 0 d-------- C:\Program Files\Enigma Software Group
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\winsystem.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32WINWGPX.EXE
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32winsystem.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32winlogonpc.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32vcatchpi.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32vbsys2.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32thun32.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32thun.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32temp#01.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32taack.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32taack.dat
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32sysreq.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32ssvchost.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32ssurf022.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32sncntr.exe
2008-03-24 13:58:42 0 d-------- C:\WINDOWS\system32smp
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32Rundl1.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32regm64.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32regc64.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32psoft1.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32psof1.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32ps1.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32newsd32.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32netode.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32mwin32.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32mtr2.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32msvchost.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32mssecu.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32msnbho.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32msgp.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32medup020.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32medup012.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32hxiwlgpm.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32hoproxy.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32emesx.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32dpcproxy.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32bdn.com
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32awtoolb.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32anticipator.dll
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\system32akttzn.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\mssecu.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\bdn.com
2008-03-24 13:58:42 4096 --a------ C:\WINDOWS\a.bat
2008-03-24 13:58:42 0 d-------- C:\Documents and Settings\Me\Desktopvirii
2008-03-24 13:58:42 4096 --a------ C:\Documents and Settings\Me\DesktopFWebdEditor.exe
2008-03-24 13:58:42 4096 --a------ C:\Documents and Settings\Me\Desktopfwebd.exe
2008-03-24 13:58:42 4096 --a------ C:\Documents and Settings\Me\Desktopfilemanagerclient.exe
2008-03-24 13:58:35 114688 --a------ C:\WINDOWS\system32\lanihmdw.exe
2008-03-24 13:58:35 0 d-------- C:\Documents and Settings\All Users\Application Data\nqlovazk
2008-03-21 13:06:41 0 d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-21 12:26:53 0 d-------- C:\Documents and Settings\Me\Application Data\Music Label
2008-03-21 12:24:56 0 d-------- C:\Program Files\Music Label 2008
2008-03-21 11:59:22 0 d-------- C:\Documents and Settings\Me\Application Data\Vso
2008-03-21 11:59:22 47360 --a------ C:\Documents and Settings\Me\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-03-21 11:59:19 217127 --a------ C:\WINDOWS\system32\drv43260.dll <Not Verified; RealNetworks, Inc.; RealVideo 9 (32-bit)>
2008-03-21 11:59:19 208935 --a------ C:\WINDOWS\system32\drv33260.dll <Not Verified; RealNetworks, Inc.; RealVideo 8 (32-bit)>
2008-03-21 11:59:19 176165 --a------ C:\WINDOWS\system32\drv23260.dll <Not Verified; RealNetworks, Inc.; RealVideo G2 (32-bit)>
2008-03-21 11:59:17 0 d-------- C:\Program Files\VSO
2008-03-20 14:14:03 0 d-------- C:\Program Files\DIFX
2008-03-20 14:13:47 0 d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-03-20 14:13:43 0 d-------- C:\Program Files\Pure Networks
2008-03-20 14:13:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-03-19 16:47:25 0 d-------- C:\Documents and Settings\Me\Application Data\Sierra Entertainment
2008-03-16 12:31:55 0 d--h----- C:\Program Files\Zero G Registry
2008-03-16 12:31:13 0 d--h----- C:\Documents and Settings\Me\InstallAnywhere
2008-03-16 12:30:42 0 d-------- C:\Documents and Settings\Me\Application Data\Sports Interactive
2008-03-12 19:24:23 4 --ah----- C:\Documents and Settings\Me\__iw3mp
2008-03-09 11:04:27 0 d-------- C:\Program Files\Internet Download Manager
2008-03-04 15:23:27 0 d-------- C:\WINDOWS\system32\AGEIA
2008-03-04 15:23:27 0 d-------- C:\Program Files\AGEIA Technologies
2008-03-02 20:15:51 0 d-------- C:\Program Files\GameSpy Arcade
2008-03-02 20:13:45 0 d-------- C:\GameSpy Arcade Setup
2008-03-02 20:12:51 0 d-------- C:\Program Files\Common Files\EasyInfo
2008-03-01 14:51:58 0 d-------- C:\Program Files\Universal Extractor
-- Find3M Report ---------------------------------------------------------------
2008-03-25 07:50:28 0 d-------- C:\Documents and Settings\Me\Application Data\AVG7
2008-03-25 07:45:31 0 d-------- C:\Documents and Settings\Me\Application Data\DMCache
2008-03-25 07:45:15 1324 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-22 13:46:17 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-21 11:59:34 34 --a------ C:\Documents and Settings\Me\Application Data\pcouffin.log
2008-03-21 11:59:24 1144 --a------ C:\Documents and Settings\Me\Application Data\pcouffin.inf
2008-03-21 11:59:24 7887 --a------ C:\Documents and Settings\Me\Application Data\pcouffin.cat
2008-03-21 11:09:50 0 d-------- C:\Documents and Settings\Me\Application Data\dvdcss
2008-03-20 14:13:47 0 d-------- C:\Program Files\Common Files
2008-03-17 20:20:48 0 d-------- C:\Documents and Settings\Me\Application Data\My Games
2008-03-13 10:00:27 0 d-------- C:\Documents and Settings\Me\Application Data\IDM
2008-03-10 18:59:46 555 --a------ C:\WINDOWS\checkip.dat
2008-03-04 15:22:53 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-02 14:25:32 0 d-------- C:\Program Files\The All-Seeing Eye
2008-02-25 21:37:57 0 d-------- C:\Program Files\Startup Select
2008-02-23 17:50:15 0 d-------- C:\Program Files\iTunes
2008-02-23 17:50:07 0 d-------- C:\Program Files\iPod
2008-02-05 19:20:04 0 d-------- C:\Program Files\7-Zip
2008-02-03 15:13:53 21840 --a-----t C:\WINDOWS\system32\SIntfNT.dll
2008-02-03 15:13:53 17212 --a-----t C:\WINDOWS\system32\SIntf32.dll
2008-02-03 15:13:53 12067 --a-----t C:\WINDOWS\system32\SIntf16.dll
2008-02-02 11:34:13 0 d-------- C:\Documents and Settings\Me\Application Data\FFSJ
2008-02-02 11:29:15 3698 --a------ C:\WINDOWS\unins000.dat
2008-02-02 11:29:08 704793 --a------ C:\WINDOWS\unins000.exe <Not Verified; ; Inno Setup>
2008-01-07 17:45:01 592 --a----c- C:\WINDOWS\chgkey.vbs
2008-01-02 14:39:01 34308 --a----c- C:\WINDOWS\system32\Chip.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [17/09/2007 00:07]
"nwiz"="nwiz.exe" [17/09/2007 00:07 C:\WINDOWS\system32\nwiz.exe]
"UpdReg"="C:\WINDOWS\Updreg.exe" [11/05/2000 01:00]
"AHQInit"="C:\Program Files\Creative\SBLive\Program\AHQInit.exe" [10/05/2001 16:49]
"AudioHQ"="C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE" [17/08/2001 17:01]
"Lexmark 3100 Series"="C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe" [04/09/2003 02:33]
"LXBRKsk"="C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe" [13/06/2003 14:57]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [09/07/2001 10:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 00:11]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [26/10/2005 16:17]
"Adobe Photo Downloader"="D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [06/06/2005 23:46]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [21/12/2007 14:00]
"AVG7_EMC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [21/12/2007 14:00]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [15/08/2007 16:42]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [17/09/2007 00:07]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [02/01/2008 20:15]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [20/03/2006 17:34]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [31/01/2008 23:13]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [19/02/2008 13:10]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [21/05/2007 10:01]
"antiviirus"="C:\Program Files\antiviirus.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [24/03/2008 16:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 04:56]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [05/10/2004 09:52]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [11/05/2007 08:46]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [02/01/2008 20:15]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [03/04/2007 22:29]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [02/07/2007 10:29]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [28/07/2007 15:38]
"Yahoo! Pager"="~C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" []
"gccsmzhw"="C:\WINDOWS\system32\lanihmdw.exe" [24/03/2008 13:58]
"mogdfrhv"="C:\WINDOWS\system32\ilshwbat.exe" [24/03/2008 18:06]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 22:05:26]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [10/12/2005 13:30:23]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"3qSKGYzPVO"=C:\Documents and Settings\All Users\Application Data\nqlovazk\rwlilcbm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{070c3474-606a-11dc-a007-0013d485e6d4}]
AutoRun\command- L:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c6c2c7a-dfa4-11db-9ecd-0013d485e6d4}]
AutoRun\command- L:\setupSNK.exe
-- End of Deckard's System Scanner: finished at 2008-03-25 12:10:23 ------------
Edited by jsharrison, 26 March 2008 - 06:14 AM.