Main:
Deckard's System Scanner v20071014.68
Run by Sam on 2008-03-26 21:58:01
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
22: 2008-03-26 21:58:05 UTC - RP22 - Deckard's System Scanner Restore Point
21: 2008-03-26 20:59:03 UTC - RP21 - Installed Sentinel Protection Installer 7.4.0
20: 2008-03-26 19:59:07 UTC - RP20 - Installed Java 6 Update 5
19: 2008-03-25 20:23:52 UTC - RP19 - Installed 4oD.
18: 2008-03-25 20:22:30 UTC - RP18 - Removed 4oD.
-- First Restore Point --
1: 2008-03-23 18:19:46 UTC - RP1 - System Checkpoint
Performed disk cleanup.
System Drive C: has 30.18 GiB (less than 15%) free.-- HijackThis (run as Sam.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:58:15, on 26/03/2008
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WinGate\WinGate.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\DivX\DivX Player\DivX Player.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Sam\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Sam.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.daemon-search.com/startpageR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.15\MediaManager\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
http://catalog.updat...b?1198884106419O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} -
http://messenger.zon...1/GAME_UNO1.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
http://messenger.zon...ro.cab56649.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.ad...ash/swflash.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Sentinel Keys Server (SentinelKeysServer) - SafeNet, Inc. - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Qbik WinGate Engine (WinGateEngine) - Qbik Software NZ Ltd - C:\Program Files\WinGate\WinGate.exe
--
End of file - 9628 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080324-201332-751 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
backup-20080324-201332-971 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.104.67.250:8080
backup-20080324-201333-594 O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
backup-20080324-225927-762 O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,71.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*.hlp - hlpfile - DefaultIcon - C:\WINDOWS\System32\shell32.dll,23.inf - inffile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69.ini - inifile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,69.reg - regfile - shell\open\command - regedit.exe"%1" %*.scr - scrfile - shell\open\command - "%1" %*.txt - txtfile - DefaultIcon - C:\WINDOWS\system32\shell32.dll,70-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 QbikHkXP (Wingate NDIS Hook Driver) - c:\windows\\systemroot\system32\drivers\qbikhkxp.sys (file missing)
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R3 ovt519 (Eye Toy) - c:\windows\system32\drivers\ov519vid.sys <Not Verified; OmniVision Technologies, Inc.; Dual Mode USB Camera 519>
R3 SBAPIFS - c:\windows\system32\drivers\sbapifs.sys (file missing)
S1 rxp - c:\windows\system32\drivers\rxp.sys (file missing)
S3 Ad-Watch Connect Filter (Ad-Watch Connect Kernel Filter) - c:\windows\system32\drivers\nsdriver.sys <Not Verified; Lavasoft AB; Ad-Watch Connections>
S3 Ad-Watch Real-Time Scanner (AW Real-Time Scanner) - c:\windows\system32\drivers\awrtpd.sys <Not Verified; Lavasoft AB; Ad-Watch Beta>
S3 Ad-Watch Registry Filter (Ad-Watch Registry Kernel Filter) - c:\windows\system32\drivers\awrtrd.sys <Not Verified; Lavasoft AB; Ad-Watch Registry Protection>
S3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys (file missing)
S3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 WinGateEngine (Qbik WinGate Engine) - c:\program files\wingate\wingate.exe <Not Verified; Qbik Software NZ Ltd; WinGate>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Process Modules -------------------------------------------------------------
C:\WINDOWS\system32\winlogon.exe (pid 740)
2003-02-26 22:27:44 36864 --a------ C:\WINDOWS\system32\wbsys.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4.x for x86 machines>
2007-04-19 12:41:36 294912 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>
2001-12-20 23:34:52 24576 --a------ C:\Program Files\AlienGUIse\fastload.dll <Not Verified; Stardock; fLoad>
C:\WINDOWS\system32\svchost.exe (pid 976)
2003-02-26 22:27:44 36864 --a------ C:\WINDOWS\system32\wbsys.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4.x for x86 machines>
C:\WINDOWS\system32\svchost.exe (pid 1180)
2003-02-26 22:27:44 36864 --a------ C:\WINDOWS\system32\wbsys.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4.x for x86 machines>
C:\WINDOWS\system32\svchost.exe (pid 684)
2003-02-26 22:27:44 36864 --a------ C:\WINDOWS\system32\wbsys.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4.x for x86 machines>
2003-10-15 17:52:50 16426 -ra------ C:\WINDOWS\system32\ov519usd.dll <Not Verified; OmniVision Technologies Inc.; Dual Mode USB Camera 519>
C:\WINDOWS\explorer.exe (pid 3968)
2003-02-26 22:27:44 36864 --a------ C:\WINDOWS\system32\wbsys.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4.x for x86 machines>
2003-02-26 22:24:32 28740 --a------ C:\Program Files\AlienGUIse\wbhelp.dll <Not Verified; Stardock.Net, Inc; WindowBlinds 4 for Win32 x86 machines>
2006-12-20 12:55:48 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>
-- Scheduled Tasks -------------------------------------------------------------
2008-03-24 17:06:07 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-02-26 and 2008-03-26 -----------------------------
2008-09-18 20:43:03 0 d-------- C:\Documents and Settings\Sam\Application Data\Ventrilo
2008-09-18 20:33:18 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-26 20:59:08 0 d-------- C:\WINDOWS\LastGood
2008-03-26 20:59:06 0 d-------- C:\Program Files\SafeNet Sentinel
2008-03-26 20:59:05 0 d-------- C:\Program Files\Common Files\SafeNet Sentinel
2008-03-26 20:58:38 0 d-------- C:\WINDOWS\Downloaded Installations
2008-03-26 20:51:09 0 d-------- C:\Program Files\SystemRequirementsLab
2008-03-26 20:50:18 0 d-------- C:\Program Files\NewTek
2008-03-26 20:50:03 0 d-------- C:\Documents
2008-03-26 20:44:00 0 d-------- C:\Documents and Settings\Sam\Application Data\SystemRequirementsLab
2008-03-26 20:02:32 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-03-25 20:23:54 0 d-------- C:\Program Files\Kontiki
2008-03-25 20:23:54 0 d-------- C:\Program Files\Channel4
2008-03-25 20:02:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-03-25 20:01:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Channel4
2008-03-25 16:14:43 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-25 16:14:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-24 22:57:17 0 d-------- C:\Documents and Settings\Sam\Application Data\Malwarebytes
2008-03-24 22:56:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-24 22:56:50 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-24 20:14:47 0 d-------- C:\hostxpert 4.2 - host manager
2008-03-24 17:51:58 0 d-------- C:\Documents and Settings\Sam\Application Data\Nero
2008-03-24 17:48:30 0 d-------- C:\Program Files\Nero
2008-03-24 17:48:30 0 d-------- C:\Program Files\Common Files\Nero
2008-03-24 17:48:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-24 17:35:33 0 d-------- C:\Program Files\Trend Micro
2008-03-24 03:34:51 0 dr-h----- C:\$VAULT$.AVG
2008-03-24 00:51:06 18124832 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-24 00:48:03 0 d-------- C:\Documents and Settings\Sam\Application Data\AVG7
2008-03-24 00:47:58 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-24 00:47:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-24 00:33:22 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-24 00:33:19 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-03-24 00:32:56 0 d-------- C:\WINDOWS\system32\ZoneLabs
2008-03-24 00:32:38 0 d-------- C:\WINDOWS\Internet Logs
2008-03-24 00:00:30 0 d-------- C:\My Drivers
2008-03-23 23:59:00 0 d-------- C:\Program Files\Common Files\AVSMedia
2008-03-23 23:58:34 0 d-------- C:\Program Files\WinDriver Ghost
2008-03-23 23:58:27 261632 --a------ C:\WINDOWS\system32\mcdvd_32.dll <Not Verified; MainConcept; MainConcept DV Codec "2.0.4>
2008-03-23 23:58:27 0 d-------- C:\Program Files\AVSMedia
2008-03-23 23:35:25 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-23 19:21:26 0 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-03-23 18:47:22 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-03-23 18:47:22 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-03-23 18:47:22 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-03-23 18:47:22 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-03-23 18:47:22 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-03-23 18:47:22 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-03-23 18:47:22 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-03-23 18:47:22 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-03-23 18:47:22 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-03-23 18:47:22 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-03-23 18:47:22 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-03-23 18:47:22 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-03-23 18:47:22 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-03-23 18:47:22 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-03-23 18:34:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-23 18:22:20 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-23 17:59:21 7688719 --a------ C:\WINDOWS\system32\SBSP.dat
2008-03-23 17:59:19 104 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-23 17:59:19 153 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-23 14:28:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-23 14:18:26 68096 --a------ C:\WINDOWS\system32\zip.exe
2008-03-23 14:18:26 98816 --a------ C:\WINDOWS\system32\sed.exe
2008-03-23 14:18:26 80412 --a------ C:\WINDOWS\system32\grep.exe
2008-03-23 14:18:26 73728 --a------ C:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-23 00:01:04 0 d-------- C:\Documents and Settings\Sam\Application Data\Amazon
2008-03-23 00:00:53 0 d-------- C:\Program Files\Amazon
2008-03-22 22:32:05 0 d-------- C:\Program Files\LogMeIn
2008-03-21 21:27:28 0 d-------- C:\Program Files\CDRWIN 6
2008-03-21 21:25:34 0 d-------- C:\Program Files\PowerISO
2008-03-21 17:31:47 0 d-------- C:\Program Files\DVD Decrypter
2008-03-20 17:03:11 0 d-------- C:\Program Files\Dorgem
2008-03-20 16:42:22 0 d-------- C:\Program Files\VirtualDJ
2008-03-20 16:41:49 0 d-------- C:\Documents and Settings\Sam\Application Data\DAEMON Tools Pro
2008-03-20 16:41:37 0 d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-03-20 16:38:59 0 d-------- C:\Program Files\DAEMON Tools Pro
2008-03-19 16:43:32 307200 -ra------ C:\WINDOWS\vidcap32.exe <Not Verified; Microsoft Corporation; Microsoft Windows>
2008-03-19 16:43:32 25211 -ra------ C:\WINDOWS\system32\drivers\ov519cmd.sys <Not Verified; OmniVision Technologies Inc.; Dual Mode USB Camera 519>
2008-03-19 16:43:32 200704 -ra------ C:\WINDOWS\sel3110.exe <Not Verified; ; select Application>
2008-03-19 16:43:32 61440 -ra------ C:\WINDOWS\ov519dib.dll <Not Verified; OmniVision Technologies, Inc.; OmniVision USB Camera OV519>
2008-03-19 16:43:32 135168 -ra------ C:\WINDOWS\ov519cap.exe <Not Verified; OmniVision Technologies, Inc.; OmniVision USB Camera OV519>
2008-03-19 16:43:32 40960 -ra------ C:\WINDOWS\CleanDev.exe <Not Verified; ; CleanDevice>
2008-03-19 16:43:32 32528 -ra------ C:\WINDOWS\amcap.exe
2008-03-19 16:43:31 16426 -ra------ C:\WINDOWS\system32\ov519usd.dll <Not Verified; OmniVision Technologies Inc.; Dual Mode USB Camera 519>
2008-03-19 16:43:31 40960 -ra------ C:\WINDOWS\system32\ov519ext.dll <Not Verified; OmniVision Technologies Inc.; Dual Mode USB Camera 519>
2008-03-19 16:43:31 174530 -ra------ C:\WINDOWS\system32\drivers\ov519vid.sys <Not Verified; OmniVision Technologies, Inc.; Dual Mode USB Camera 519>
2008-03-19 16:43:31 0 d-------- C:\WINDOWS\OvtCam
2008-03-16 20:36:28 0 d-------- C:\Runtime
2008-03-16 20:33:06 90112 --a------ C:\WINDOWS\unvise32.exe <Not Verified; MindVision Software; Installer VISE>
2008-03-16 20:32:56 0 d-------- C:\Program Files\DAZ
2008-03-16 20:32:56 0 d-------- C:\Program Files\Common Files\DAZ
2008-03-16 14:41:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-15 20:13:02 0 d-------- C:\SecondLife
2008-03-14 23:11:04 475616 --a------ C:\WINDOWS\system32\drivers\qbikhkxp.sys
2008-03-14 23:11:02 0 d-------- C:\Program Files\Qbik Licensing
2008-03-14 23:11:01 0 d-------- C:\Program Files\WinGate
2008-03-14 23:10:40 1056768 --a------ C:\WINDOWS\system32\roboex32.dll <Not Verified; eHelp Corporation.; RoboHELP for WinHelp 9>
2008-03-14 23:10:40 49152 --a------ C:\WINDOWS\system32\inetwh32.dll <Not Verified; Blue Sky Software Corporation.; Blue Sky Software - INETWH32>
2008-03-14 23:08:17 208896 --a------ C:\WINDOWS\system32\wgsrvins.dll <Not Verified; ; WGITools Dynamic Link Library>
2008-03-14 23:08:17 11264 --a------ C:\WINDOWS\system32\sporder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT Operating System>
2008-03-14 21:20:19 0 d-------- C:\Documents and Settings\Sam\Application Data\SecondLife
2008-03-14 21:19:26 0 d-------- C:\Program Files\SecondLife
2008-03-14 20:03:02 0 d-------- C:\bonus
2008-03-14 02:39:49 11580 --a------ C:\WINDOWS\SurfSite
2008-03-14 02:36:56 0 d-------- C:\Program Files\Surfstats8400
2008-03-13 19:17:41 70656 --a------ C:\WINDOWS\system32\vspell32.dll <Not Verified; Visual Components, Inc.; VisualSpeller>
2008-03-13 19:17:41 84992 --a------ C:\WINDOWS\system32\Ledit32.dll <Not Verified; AY Software Corporation; >
2008-03-13 19:17:40 503808 --a------ C:\WINDOWS\system32\ChilkatFTPx.dll <Not Verified; Chilkat Software, Inc.; Chilkat FTP ActiveX>
2008-03-13 19:17:40 0 d-------- C:\Program Files\PageBreeze
2008-03-13 15:38:40 233472 --a------ C:\WINDOWS\system32\Ilda32.dll <Not Verified; Creative Development LTD; >
2008-03-13 15:38:40 18944 --a------ C:\WINDOWS\system32\BORLNDMM.DLL <Not Verified; Inprise Corporation; Borland Memory Manager>
2008-03-13 15:38:39 0 d-------- C:\Program Files\CoffeeCup Software
2008-03-13 11:49:16 0 d--h----- C:\Documents and Settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2008-03-13 11:43:57 0 d-------- C:\Program Files\Stardock Games
2008-03-11 20:18:45 0 d-------- C:\Program Files\PowerDataRecovery
2008-03-11 19:48:20 0 d-------- C:\Program Files\Data Doctor Recovery FAT (Demo)
2008-03-11 16:32:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2008-03-11 16:31:20 0 d-------- C:\Program Files\Sunbelt Software
2008-03-09 20:51:06 0 d-------- C:\Documents and Settings\Sam\Application Data\Command & Conquer 3 Tiberium Wars
2008-03-09 14:37:13 0 d-------- C:\Program Files\Lavasoft
2008-03-09 14:37:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-09 14:29:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-09 14:29:32 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-09 14:29:32 0 d-------- C:\Documents and Settings\Sam\Application Data\SUPERAntiSpyware.com
2008-03-09 12:31:09 0 d-------- C:\Program Files\Infogrames
2008-03-09 00:57:02 0 d-------- C:\WINDOWS\aod
2008-03-09 00:04:12 0 d-------- C:\Program Files\AVI Codec Pack
2008-03-09 00:04:09 0 d-------- C:\WINDOWS\system32\quicktime
2008-03-08 23:48:53 0 d-------- C:\Documents and Settings\Sam\Application Data\Opera
2008-03-08 23:48:46 0 d-------- C:\Program Files\Opera
2008-03-08 23:40:27 0 d--h----- C:\WINDOWS\$hf_mig$
2008-03-08 19:38:53 0 d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers Headquarters
2008-03-08 19:29:33 0 d-------- C:\Program Files\Driver Magician
2008-03-08 19:17:55 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
2008-03-08 17:31:08 0 d-------- C:\WINDOWS\WinRAR
2008-03-08 16:41:42 0 d-------- C:\Program Files\RegVac Registry Cleaner
2008-03-08 16:23:10 0 d-------- C:\Documents and Settings\Sam\Application Data\MozillaControl
2008-03-08 16:22:46 0 d-------- C:\WINDOWS\'Full Speed' Internet Booster + Performance Tests
2008-03-08 16:22:36 0 d-------- C:\aidualc3
2008-03-08 13:30:28 0 d-------- C:\Documents and Settings\Sam\Application Data\Microsoft Games
2008-03-08 13:20:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-03-07 18:53:31 0 d-------- C:\Documents and Settings\Sam\Application Data\Atari
2008-03-07 17:43:14 0 d-------- C:\Program Files\THQ
2008-03-07 14:48:38 0 d-------- C:\Program Files\EA GAMES
2008-03-07 14:48:37 442368 -ra------ C:\WINDOWS\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-03-07 12:47:12 0 d-------- C:\Documents and Settings\Sam\Application Data\Leadertech
2008-03-07 12:47:06 197120 --a------ C:\WINDOWS\patchw32.dll
2008-03-07 12:47:05 0 d-------- C:\Program Files\Common Files\PocketSoft
2008-03-07 12:44:05 0 d-------- C:\Program Files\Atari
2008-03-07 12:41:12 529 --a------ C:\WINDOWS\eReg.dat
2008-03-07 12:41:06 0 d-------- C:\Program Files\Maxis
2008-03-06 21:41:21 0 d-------- C:\Documents and Settings\All Users\Application Data\SimCity Societies
2008-03-06 21:24:19 0 d-------- C:\Program Files\Electronic Arts
2008-03-06 16:34:48 246784 --a------ C:\WINDOWS\system32\sqlite3.dll
2008-03-06 00:06:11 0 d-------- C:\Games
2008-03-02 23:46:25 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-01 23:10:09 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 23:09:56 0 d-------- C:\Program Files\Windows Live
2008-03-01 23:09:44 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 13:53:53 0 d-------- C:\Program Files\Team Fortress 2
2008-02-29 19:02:24 0 d-------- C:\Program Files\CamStudio
2008-02-27 19:51:10 0 d-------- C:\Documents and Settings\Sam\Application Data\InstallShield Installation Information
2008-02-27 19:23:07 0 d-------- C:\Program Files\Unreal Tournament 3
2008-02-27 18:39:55 0 d-------- C:\Documents and Settings\Sam\Application Data\mIRC
2008-02-26 17:07:14 0 d-------- C:\Documents and Settings\Sam\Application Data\Sierra Entertainment
2008-02-26 16:42:36 0 d-------- C:\WINDOWS\85EBB28365AF4C539EBE7C0A232762F7.TMP
2008-02-26 16:34:08 0 d-------- C:\Program Files\Sierra Entertainment
-- Find3M Report ---------------------------------------------------------------
2008-03-26 20:59:05 0 d-------- C:\Program Files\Common Files
2008-03-26 20:49:01 0 d-------- C:\Documents and Settings\Sam\Application Data\BitTorrent
2008-03-26 20:00:36 0 d-------- C:\Program Files\Java
2008-03-25 20:15:34 0 d-------- C:\Program Files\Windows Media Connect 2
2008-03-25 19:54:23 0 d-------- C:\Documents and Settings\Sam\Application Data\Adobe
2008-03-25 14:12:40 0 d-------- C:\Program Files\MagicISO
2008-03-25 14:12:40 0 d-------- C:\Documents and Settings\Sam\Application Data\DNA
2008-03-24 00:27:47 0 d-------- C:\Documents and Settings\Sam\Application Data\GlarySoft
2008-03-23 23:41:53 0 d-------- C:\Program Files\Common Files\Ahead
2008-03-23 16:14:16 0 d-------- C:\Documents and Settings\Sam\Application Data\LimeWire
2008-03-22 22:05:07 3478 --a------ C:\WINDOWS\mozver.dat
2008-03-14 21:20:50 0 d-------- C:\Documents and Settings\Sam\Application Data\Mozilla
2008-03-10 02:29:43 0 d-------- C:\Program Files\Glary Utilities
2008-03-09 20:02:47 0 d-------- C:\Program Files\LimeWire
2008-03-09 12:44:56 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-09 12:38:13 0 d-------- C:\Program Files\Stardock
2008-03-09 01:04:00 1611 --a------ C:\Program Files\INSTALL.LOG
2008-03-08 13:15:00 0 d-------- C:\Program Files\Microsoft Games
2008-03-07 00:54:10 0 d-------- C:\Documents and Settings\Sam\Application Data\Apple Computer
2008-02-27 19:22:07 0 d-------- C:\Program Files\AGEIA Technologies
2008-02-26 16:12:50 0 d-------- C:\Program Files\AlienGUIse
2008-02-26 16:06:41 0 d-------- C:\Program Files\Common Files\Stardock
2008-02-26 15:57:27 0 d-------- C:\Program Files\Game Cam v1.4
2008-02-20 20:40:18 0 d-------- C:\Documents and Settings\Sam\Application Data\Help
2008-02-20 19:34:55 0 d-------- C:\Documents and Settings\Sam\Application Data\Ahead
2008-02-18 22:18:06 0 --a------ C:\program1
2008-02-08 22:24:54 0 d-------- C:\Documents and Settings\Sam\Application Data\Macromedia
2008-02-08 22:10:54 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-02-08 22:10:01 0 d-------- C:\Program Files\Common Files\Macromedia
2008-02-08 22:09:15 0 d-------- C:\Program Files\Macromedia
2008-01-31 17:35:47 0 d-------- C:\Program Files\Web Publish
2008-01-27 17:48:33 0 d-------- C:\Documents and Settings\Sam\Application Data\DAEMON Tools
2008-01-27 17:43:49 0 d-------- C:\Program Files\DaemonScript
2008-01-26 17:12:30 0 dr-h----- C:\Documents and Settings\Sam\Application Data\SecuROM
2008-01-04 21:58:50 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:57:22 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-01-04 21:57:22 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-01-04 21:57:12 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-04 21:57:10 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-01-04 21:57:10 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-04 21:56:24 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-31 19:13:51 134377 --a------ C:\Documents and Settings\Sam\Application Data\Cosmos Prefs
2007-12-29 14:06:07 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-12-29 01:24:50 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-28 22:50:19 0 -rahs---- C:\MSDOS.SYS
2007-12-28 22:50:19 0 -rahs---- C:\IO.SYS
2007-12-28 22:50:19 0 --a------ C:\CONFIG.SYS
2007-12-28 22:50:19 0 --a------ C:\AUTOEXEC.BAT
2007-12-28 22:48:04 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-12-28 22:42:25 62 --ahs---- C:\Documents and Settings\Sam\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [30/10/2006 12:44]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [30/10/2006 12:44]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [10/11/2006 12:35]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [18/12/2006 13:34]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [13/03/2008 23:11]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [24/03/2008 00:47]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [20/09/2007 09:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [01/12/2007 08:26]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 15/11/2007 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 20/12/2001 23:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wbsys.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBCSSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinGate Engine Monitor.lnk]
backup=C:\WINDOWS\pss\WinGate Engine Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinGate VPN Monitor.lnk]
backup=C:\WINDOWS\pss\WinGate VPN Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
"C:\Program Files\DNA\btdna.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
"C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
"C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SiteAdvisor Service"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"odserv"=3 (0x3)
"MpfService"=2 (0x2)
"McNASvc"=2 (0x2)
"MSK80Service"=2 (0x2)
"NBService"=3 (0x3)
"McSysmon"=3 (0x3)
"mcmscsvc"=2 (0x2)
"McODS"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"LogMeIn"=2 (0x2)
"LMIMaint"=2 (0x2)
"LanmanServer"=2 (0x2)
"Bonjour Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
"McENUI"=C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
"MskAgentexe"=C:\Program Files\McAfee\MSK\MskAgent.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SBCSTray"=C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
"4oD"="C:\Program Files\Kontiki\KHost.exe" -all
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
*Newly Created Service* - SBAPIFS
*Newly Created Service* - SENTINEL
*Newly Created Service* - SENTINELKEYSSERVER
*Newly Created Service* - SENTINELPROTECTIONSERVER
-- End of Deckard's System Scanner: finished at 2008-03-26 21:59:31 ------------
Extra:
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel® Core2 Duo CPU E4500 @ 2.20GHz
Percentage of Memory in Use: 35%
Physical Memory (total/avail): 2047.11 MiB / 1325.05 MiB
Pagefile Memory (total/avail): 3939.05 MiB / 3213.03 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1905.8 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 232.88 GiB total, 30.18 GiB free.
D: is CDROM (No Media)
I: is CDROM (No Media)
J: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - MAXTOR S TM325082 SCSI Disk Device - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Sam\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=SAM-7F54CEF626E
ComSpec=C:\WINDOWS\system32\cmd.exe
CYGWIN=tty
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Sam
LOGONSERVER=\\SAM-7F54CEF626E
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem;C:\Program Files\Smart Projects\IsoBuster
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_03\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Sam\LOCALS~1\Temp
TMP=C:\DOCUME~1\Sam\LOCALS~1\Temp
tvdumpflags=8
USERDOMAIN=SAM-7F54CEF626E
USERNAME=Sam
USERPROFILE=C:\Documents and Settings\Sam
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI
-- User Profiles ---------------------------------------------------------------
Sam
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> MsiExec /X{45235788-142C-44BE-8A4D-DDE9A84492E5}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
4oD --> MsiExec.exe /I {8B7443F5-E141-42A0-AB61-ED2331AAD606}
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
Ad-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings --> C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exe
Adobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}
Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2 --> C:\Program Files\Common Files\Adobe\Installers\3e054d2218e7aa282c2369d939e58ff\Setup.exe
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{77D2A9D3-5800-43E3-B274-87841BC87DB2}
Adobe Flash Player 9 ActiveX --> MsiExec.exe /X{8E9DB7EF-5DD3-499E-BA2A-A1F3153A4DF8}
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\719d6f144d0c086a0dfa7ff76bb9ac1\Setup.exe
Adobe Photoshop CS3 --> MsiExec.exe /I{3D7E3EC9-46CF-4359-9289-39CE01DFB82F}
Adobe Premiere Pro CS3 --> C:\Program Files\Common Files\Adobe\Installers\32fdd767b4383606e8168e834af5d90\Setup.exe
Adobe Premiere Pro CS3 --> MsiExec.exe /I{58DCEEE5-532E-44F4-B1D7-A146EF9E9FDA}
Adobe Premiere Pro CS3 Functional Content --> MsiExec.exe /I{50F102CA-4BE2-41A9-9810-5BB05EB91B9A}
Adobe Premiere Pro CS3 Third Party Content --> MsiExec.exe /I{485ACF57-F364-440A-8496-E1E81C8FA1AA}
Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81100000003}
Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}
Adobe Setup --> MsiExec.exe /I{8AE03988-8C8C-40EE-BDC7-76781BEF1B1D}
Adobe Setup --> MsiExec.exe /I{BB81360F-041C-4CF7-B15E-71380D154244}
Adobe Setup --> MsiExec.exe /I{FF11004C-F42A-4A31-9BCF-7F5C8FDBE53C}
Adobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP DVA Panels CS3 --> MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
Adobe XMP Panels CS3 --> MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
Age of Empires III --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{7B9CC60A-9B81-46A3-A953-76B6BF9EEC97}
AGEIA PhysX v7.09.13 --> MsiExec.exe /X{45235788-142C-44BE-8A4D-DDE9A84492E5}
AlienGUIse Theme Manager --> C:\PROGRA~1\ALIENG~1\thememgr.exe /uninstallwise
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
ATI - Software Uninstall Utility --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x6974
ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI HYDRAVISION --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{083F79E4-6FE9-46FB-A6C6-4F8862742947}\setup.exe"
ATI Parental Control & Encoder --> MsiExec.exe /I{36CDA33B-909B-4719-97D1-C4B99309BDC7}
ATI Problem Report Wizard --> MsiExec.exe /X{5DA6F06A-B389-407B-BF8C-1548767914D8}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
AVI Codec Pack --> C:\Program Files\AVI Codec Pack\uninstall.exe
AVIVO --> MsiExec.exe /X{5399ACAF-7B15-43D5-9233-4E797B184FD2}
AVS DVDMenu Editor 1.2.1.19 --> "C:\Program Files\Common Files\AVSMedia\AVS DVDMenu Editor\unins000.exe"
AVS Video Tools 5.6 --> "C:\Program Files\AVSMedia\VideoTools\unins000.exe"
BitTorrent --> "C:\Program Files\BitTorrent\BitTorrent.exe" /UNINSTALL
CamStudio --> C:\Program Files\CamStudio\uninstall.exe
CDRWIN 6.1 --> MsiExec.exe /I{C8310658-4019-4934-A7AC-AD1E35EDD8F5}
D-Link VGA Webcam --> C:\WINDOWS\CleanDev.exe C:\WINDOWS\ov519.TXT
DaemonScript --> MsiExec.exe /X{0A21D2E9-F8A2-4CF9-88D7-E04A1C4C90AE}
Data Doctor Recovery FAT (Demo) 3.0.1.5 --> C:\Program Files\Data Doctor Recovery FAT (Demo)\Uninstall.exe
DawnOfWar --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{362D5167-9716-44BE-89FD-BF9EB6EF814B}
DAZ|Mimic 3.1 --> C:\WINDOWS\unvise32.exe C:\Program Files\DAZ\Mimic 3.1\DAZ Mimic Uninstall.log
DAZ|Studio1.8.1.5 --> C:\WINDOWS\unvise32.exe C:\Program Files\DAZ\Studio\DAZ Studio Uninstall.log
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUP