Sorry about that! Here'e the Main text log again.
Deckard's System Scanner v20071014.68
Run by Alan on 2008-03-28 17:27:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
16: 2008-03-28 21:27:56 UTC - RP16 - Deckard's System Scanner Restore Point
15: 2008-03-28 04:11:25 UTC - RP15 - RegCure Backup
14: 2008-03-28 04:11:21 UTC - RP14 - RegCure Backup
13: 2008-03-27 05:00:39 UTC - RP13 - RegCure Backup
12: 2008-03-27 02:13:15 UTC - RP12 - RegCure Backup
-- First Restore Point --
1: 2008-03-25 23:12:27 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Alan.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:28:51 PM, on 3/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\vVX6000.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Nero\PHOTOS~1\data\xtras\mssysmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Alan\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Alan.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.cnn.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ResChangerXP] C:\Program Files\ResChanger XP\ResChangerXP.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\PHOTOS~1\data\xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
https://www-secure.s...abs/tgctlsr.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2....re/HPDEXAXO.cabO16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) -
http://www.gamehouse...se/ghplayer.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) -
http://www.yougamers...eminfo/MSC3.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: (no name) -
http://www.beemovie....1600x1200_3.jpg--
End of file - 13126 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080328-000826-717 F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\system32\patch.exe
-- File Associations -----------------------------------------------------------
.scr - AutoCADScriptFile - shell\open\command - C:\WINDOWS\system32\notepad.exe "%1"-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD>
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R3 catchme - c:\docume~1\alan\locals~1\temp\catchme.sys (file missing)
R3 NVR0Dev - c:\windows\nvoclock.sys <Not Verified; NVidia Corp.; NVidia System Utility Driver>
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 ForceWare Intelligent Application Manager (IAM) - c:\program files\nvidia corporation\networkaccessmanager\bin\nsvcappflt.exe <Not Verified; ; app_filter Module>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 nTuneService (nTune Service) - c:\program files\nvidia corporation\ntune\ntuneservice.exe /startservice <Not Verified; NVIDIA; NVIDIA nTune>
R2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not Verified; Prolific Technology Inc.; IoctlSvc Application>
S2 Viewpoint Manager Service -
S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-28 17:21:49 436 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2008-03-28 17:21:40 446 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-03-27 01:00:45 370 --a------ C:\WINDOWS\Tasks\RegCure.job
2008-03-25 17:19:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-03-23 09:37:57 620 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Alan.job
2008-03-17 06:29:23 360 --a------ C:\WINDOWS\Tasks\XoftSpySE.job
2008-02-29 23:41:31 388 --a------ C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1204342846.job
-- Files created between 2008-02-28 and 2008-03-28 -----------------------------
2008-03-28 17:17:24 0 d-------- C:\WINDOWS\ERUNT
2008-03-27 06:58:08 0 d-------- C:\WINDOWS\system32\Futuremark
2008-03-26 19:36:02 0 d-------- C:\Documents and Settings\NetworkService\Start Menu
2008-03-26 13:38:11 0 d-------- C:\Documents and Settings\Kim\Application Data\Grisoft
2008-03-26 06:28:44 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-03-25 21:44:52 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-25 21:44:49 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-25 21:44:48 0 d-------- C:\Documents and Settings\Alan\Application Data\SUPERAntiSpyware.com
2008-03-25 20:09:31 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-03-25 18:55:45 0 d-------- C:\Program Files\Trend Micro
2008-03-25 18:25:11 0 d-------- C:\Documents and Settings\Alan\Application Data\Grisoft
2008-03-25 18:25:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-24 19:35:10 0 d-------- C:\Documents and Settings\Alan\Application Data\Ashampoo
2008-03-24 19:32:55 0 d-------- C:\Program Files\Ashampoo
2008-03-23 18:43:12 0 d-------- C:\Program Files\MSXML 6.0
2008-03-23 17:08:08 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-03-23 17:08:08 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-03-23 17:08:08 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-03-23 17:08:08 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-03-23 17:08:08 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-03-23 17:08:08 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-03-23 17:08:08 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-03-23 17:08:08 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-03-23 17:08:08 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-03-23 17:08:08 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-03-23 17:08:08 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-03-23 17:08:08 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-03-23 17:08:08 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-03-23 17:08:08 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-03-23 17:08:08 0 d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-03-23 01:51:51 0 d-------- C:\Program Files\DVDFab Platinum 4
2008-03-22 23:45:39 0 d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-03-22 23:39:31 0 d-------- C:\Program Files\SlySoft
2008-03-22 13:29:18 0 d-------- C:\Program Files\Common Files\Autodesk Shared
2008-03-22 13:29:18 0 d-------- C:\Program Files\AutoCAD 2009
2008-03-22 13:29:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-03-22 13:29:18 0 d-------- C:\Documents and Settings\Alan\Application Data\Autodesk
2008-03-22 13:26:30 0 d-------- C:\WINDOWS\system32\XPSViewer
2008-03-22 13:26:07 0 d-------- C:\Program Files\Reference Assemblies
2008-03-22 13:06:31 0 d-------- C:\Program Files\PowerISO
2008-03-22 12:24:40 86588244 --a------ C:\SYM_REGISTRY_BACKUP.reg
2008-03-22 11:39:19 0 d-------- C:\Documents and Settings\Alan\Application Data\Sun
2008-03-20 20:16:42 0 d-------- C:\Documents and Settings\Alan\Application Data\NeroDCTemplates
2008-03-20 20:09:46 0 d-------- C:\Program Files\Common Files\LightScribe
2008-03-20 20:09:44 0 d-------- C:\Softpaq
2008-03-18 22:39:21 0 d-------- C:\Program Files\NeroInstall.bak
2008-03-17 15:56:14 0 d-------- C:\Documents and Settings\Alan\Application Data\NeroDigital™
2008-03-17 15:53:51 0 d-------- C:\Program Files\DVD Region+CSS Free
2008-03-17 15:37:51 0 d-------- C:\Program Files\PeerGuardian2
2008-03-15 18:32:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Gtek
2008-03-15 18:32:20 0 d-------- C:\Documents and Settings\Alan\Application Data\GTek
2008-03-14 20:48:56 0 d-------- C:\Program Files\AVSMedia
2008-03-14 20:45:22 0 d-------- C:\Documents and Settings\Alan\Application Data\Pegasys Inc
2008-03-14 20:24:22 0 d-------- C:\Documents and Settings\Alan\Application Data\AVSMedia
2008-03-14 20:24:18 0 d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-03-14 20:21:51 0 d-------- C:\Program Files\Common Files\AVSMedia
2008-03-14 20:21:12 139264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-03-14 20:21:12 524288 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-03-14 20:21:12 413760 --a------ C:\WINDOWS\system32\mpg4c32.dll <Not Verified; Microsoft Corporation; Microsoft MPEG-4 Video Codec>
2008-03-14 20:21:12 261632 --a------ C:\WINDOWS\system32\mcdvd_32.dll <Not Verified; MainConcept; MainConcept DV Codec "2.0.4>
2008-03-14 20:21:12 638976 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivXNetworks, Inc.; DivX Video for Windows Codec>
2008-03-14 20:20:36 0 d-------- C:\Program Files\Common Files\Download Manager
2008-03-14 20:04:46 33408 --a------ C:\WINDOWS\system32\drivers\CDRBSDRV.SYS <Not Verified; B.H.A Corporation; B's Recorder GOLD>
2008-03-14 20:04:34 0 d-------- C:\Program Files\Pegasys Inc
2008-03-14 19:23:35 0 d-------- C:\Documents and Settings\Alan\Application Data\DVDFab
2008-03-14 17:21:30 0 d-------- C:\Documents and Settings\Alan\Application Data\BitTorrent
2008-03-14 17:21:18 0 d-------- C:\Program Files\DNA
2008-03-14 17:21:18 0 d-------- C:\Documents and Settings\Alan\Application Data\DNA
2008-03-14 17:21:17 0 d-------- C:\Program Files\BitTorrent
2008-03-13 10:03:03 0 d-------- C:\Program Files\iPod
2008-03-13 10:02:59 0 d-------- C:\Program Files\iTunes
2008-03-11 14:37:47 0 d-------- C:\Documents and Settings\Kim\Application Data\Microsoft Games
2008-03-11 13:30:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-03-11 13:20:30 0 d-------- C:\Program Files\Microsoft Games
2008-03-09 22:40:19 0 d-------- C:\Documents and Settings\Alan\Application Data\Apple Computer
2008-03-09 15:17:50 0 d-------- C:\Documents and Settings\All Users\Application Data\GameHouse
2008-03-09 11:09:41 0 d-------- C:\Program Files\LimeWire
2008-03-09 10:52:00 0 d-------- C:\Program Files\Common Files\eSellerate
2008-03-08 00:05:49 0 d-------- C:\Documents and Settings\Alan\Application Data\Ventrilo
2008-03-08 00:03:18 0 d-------- C:\Program Files\Ventrilo
2008-03-08 00:03:00 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-08 00:02:07 968 --a------ C:\WINDOWS\uninstallcopymoveto.vbs
2008-03-07 23:33:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-03-07 23:33:52 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-07 15:35:25 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer
2008-03-07 12:15:44 0 d-------- C:\Program Files\Incomplete
2008-03-07 08:05:53 0 d-------- C:\Documents and Settings\Kim\Application Data\Apple Computer
2008-03-07 08:05:33 0 d-------- C:\Program Files\Bonjour
2008-03-07 08:05:10 0 d-------- C:\Program Files\QuickTime
2008-03-07 08:05:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-07 08:04:58 0 d-------- C:\Program Files\Apple Software Update
2008-03-07 08:04:46 0 d-------- C:\Program Files\Common Files\Apple
2008-03-07 08:04:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-07 07:43:31 0 d-------- C:\Program Files\SystemRequirementsLab
2008-03-06 18:30:30 0 d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
2008-03-06 18:24:05 0 d-------- C:\Documents and Settings\Alan\Application Data\Xfire
2008-03-06 18:24:04 0 d-------- C:\Program Files\Xfire
2008-03-06 04:07:30 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-03-06 00:54:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-06 00:54:15 0 d-------- C:\Program Files\Yahoo!
2008-03-05 18:22:35 0 d-------- C:\Program Files\Windows Media Connect 2
2008-03-05 18:21:28 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-05 18:20:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-03-05 11:37:17 0 d-------- C:\Documents and Settings\Kim\Application Data\FunWebProducts
2008-03-05 08:02:56 0 d-------- C:\Documents and Settings\Kim\Shared
2008-03-05 08:02:53 0 d-------- C:\Documents and Settings\Kim\Incomplete
2008-03-05 08:02:46 0 d-------- C:\Documents and Settings\Kim\Application Data\LimeWire
2008-03-04 13:23:37 0 d-------- C:\Documents and Settings\Kim\Application Data\Simple Star
2008-03-04 13:04:25 313 --ah----- C:\Documents and Settings\Alan\hpothb07.dat
2008-03-04 13:04:17 0 --ah----- C:\Documents and Settings\Kim\hpothb07.dat
2008-03-04 13:03:28 0 d-------- C:\Documents and Settings\Kim\Application Data\Hewlett-Packard
2008-03-04 00:36:31 0 d-------- C:\Program Files\XoftSpySE
2008-03-03 23:24:35 0 d-------- C:\Program Files\RegCure
2008-03-02 18:14:28 0 d-------- C:\Program Files\PokerStars.NET
2008-03-02 17:39:00 0 d-------- C:\Documents and Settings\Kim\Application Data\Google
2008-03-02 13:27:51 0 d-------- C:\Documents and Settings\Alan\Application Data\Google
2008-03-02 13:27:26 0 d-------- C:\Documents and Settings\Alan\Application Data\AdobeUM
2008-03-02 13:12:02 32 --a------ C:\WINDOWS\go
2008-03-02 13:11:58 0 d-------- C:\WINDOWS\vf_hip
2008-03-02 13:11:57 0 d-------- C:\Program Files\Hide IP Platinum
2008-03-02 13:02:59 221184 --a------ C:\WINDOWS\system32\xtbaksm.dat
2008-03-02 13:02:58 0 d-------- C:\WINDOWS\system32\xtupdate
2008-03-02 13:02:49 0 d-------- C:\WINDOWS\system32\IOSUBSYS
2008-03-02 13:02:49 41 -rah----- C:\WINDOWS\system32\bn.dll
2008-03-02 12:05:46 0 d-------- C:\Documents and Settings\Kim\Contacts
2008-03-02 11:52:12 0 d-------- C:\WINDOWS\Sun
2008-03-02 11:52:12 0 d-------- C:\Documents and Settings\Kim\Application Data\Sun
2008-03-02 11:52:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-03-02 11:52:02 0 d-------- C:\Program Files\Google
2008-03-02 11:51:35 0 d-------- C:\Program Files\Java
2008-03-02 11:51:21 0 d-------- C:\Program Files\Common Files\Java
2008-03-02 11:48:34 0 d-------- C:\Documents and Settings\Kim\Application Data\Macromedia
2008-03-02 11:48:18 0 d-------- C:\Documents and Settings\Kim\Application Data\acccore
2008-03-02 11:46:41 0 d-------- C:\Documents and Settings\Kim\Application Data\Adobe
2008-03-01 22:46:05 0 d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-01 13:33:45 0 d-------- C:\WINDOWS\system32\Defaults
2008-03-01 13:32:50 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-03-01 13:32:50 86016 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions © Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL Library>
2008-03-01 13:32:34 3072 --a------ C:\WINDOWS\CTXFIRES.DLL <Not Verified; ; CTxfiRes Dynamic Link Library>
2008-03-01 13:32:34 10240 --a------ C:\WINDOWS\CTDCRES.DLL <Not Verified; Creative Technology Ltd; Creative Audio Product>
2008-03-01 13:13:27 0 d-------- C:\Program Files\Ares
2008-03-01 12:26:25 0 d-------- C:\Documents and Settings\Alan\Application Data\UseNeXT
2008-03-01 12:18:47 0 d-------- C:\Documents and Settings\Alan\Application Data\acccore
2008-03-01 12:17:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-01 12:17:07 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-03-01 12:17:07 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-03-01 12:16:53 0 d-------- C:\Program Files\Common Files\AOL
2008-03-01 12:16:42 0 d-------- C:\Program Files\AIM6
2008-03-01 04:04:44 0 d-------- C:\Documents and Settings\Kim\Application Data\Windows Desktop Search
2008-03-01 04:04:44 0 d-------- C:\Documents and Settings\Kim\Application Data\Nero
2008-03-01 04:04:36 0 d-------- C:\Documents and Settings\Kim\Application Data\Identities
2008-03-01 04:04:30 0 dr-h----- C:\Documents and Settings\Kim\Recent
2008-03-01 04:04:30 0 d--h----- C:\Documents and Settings\Kim\PrintHood
2008-03-01 04:04:30 0 d--h----- C:\Documents and Settings\Kim\NetHood
2008-03-01 04:04:30 0 dr------- C:\Documents and Settings\Kim\My Documents
2008-03-01 04:04:30 0 d--h----- C:\Documents and Settings\Kim\Local Settings
2008-03-01 04:04:30 0 dr------- C:\Documents and Settings\Kim\Favorites
2008-03-01 04:04:30 0 d-------- C:\Documents and Settings\Kim\Desktop
2008-03-01 04:04:30 0 d--hs---- C:\Documents and Settings\Kim\Cookies
2008-03-01 04:04:30 0 d--h----- C:\Documents and Settings\Kim\Application Data
2008-03-01 04:04:30 0 d---s---- C:\Documents and Settings\Kim\Application Data\Microsoft
2008-03-01 04:04:29 0 d--h----- C:\Documents and Settings\Kim\Templates
2008-03-01 04:04:29 0 dr------- C:\Documents and Settings\Kim\Start Menu
2008-03-01 04:04:29 0 dr-h----- C:\Documents and Settings\Kim\SendTo
2008-03-01 04:04:29 2359296 --ah----- C:\Documents and Settings\Kim\NTUSER.DAT
2008-03-01 03:45:56 0 d-------- C:\Documents and Settings\Alan\Application Data\Windows Desktop Search
2008-03-01 03:45:29 0 d-------- C:\Program Files\Windows Desktop Search
2008-03-01 01:59:55 0 d-------- C:\Program Files\GameSpot
2008-03-01 01:09:32 0 d-------- C:\Program Files\Activision
2008-03-01 01:06:54 0 d--hs---- C:\WINDOWS\ftpcache
2008-03-01 01:00:01 0 d-------- C:\WINDOWS\system32\appmgmt
2008-03-01 00:26:10 0 d-------- C:\Program Files\Microsoft LifeCam
2008-03-01 00:21:09 0 d-------- C:\Documents and Settings\Alan\Contacts
2008-03-01 00:20:23 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-03-01 00:17:23 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 00:17:20 0 d-------- C:\Program Files\Windows Live
2008-03-01 00:17:14 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-01 00:11:17 0 d-------- C:\Program Files\MSXML 4.0
2008-03-01 00:02:29 0 d-------- C:\WINDOWS\network diagnostic
2008-02-29 23:47:56 0 d-------- C:\WINDOWS\system32\PreInstall
2008-02-29 23:41:26 0 d-------- C:\Documents and Settings\Alan\Application Data\Hewlett-Packard
2008-02-29 23:32:17 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-02-29 23:22:57 0 d-------- C:\Program Files\Hewlett-Packard
2008-02-29 23:20:59 0 d-------- C:\Documents and Settings\Alan\Application Data\Help
2008-02-29 23:16:33 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-02-29 23:16:33 47360 --a------ C:\Documents and Settings\Alan\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-02-29 23:16:32 0 d-------- C:\Documents and Settings\Alan\Application Data\Vso
2008-02-29 23:16:20 352410 --a------ C:\WINDOWS\opeC2.exe
2008-02-29 23:12:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Simple Star
2008-02-29 23:11:24 335872 --a------ C:\WINDOWS\Nero PhotoShow.scr <Not Verified; Nero AG / Nero Inc.; Nero PhotoShow Screen Saver>
2008-02-29 23:11:18 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2008-02-29 23:11:18 38912 --a------ C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2008-02-29 23:07:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Simple Star Shared
2008-02-29 23:07:06 0 d-------- C:\Program Files\Common Files\Simple Star Shared
2008-02-29 23:06:07 0 d-------- C:\Documents and Settings\Alan\Application Data\Macromedia
2008-02-29 23:03:17 0 d-------- C:\Documents and Settings\Alan\Application Data\Simple Star
2008-02-29 23:02:04 0 d-------- C:\Documents and Settings\Alan\Application Data\Nero
2008-02-29 23:00:37 0 d-------- C:\Program Files\Nero
2008-02-29 23:00:37 0 d-------- C:\Program Files\Common Files\Nero
2008-02-29 23:00:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-02-29 22:55:35 0 d-------- C:\WINDOWS\RegisteredPackages
2008-02-29 22:45:44 0 d-------- C:\Program Files\Microsoft Works
2008-02-29 22:45:40 0 d-------- C:\Program Files\MSBuild
2008-02-29 22:32:15 0 d-------- C:\WINDOWS\SHELLNEW
2008-02-29 22:31:49 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-29 22:30:34 0 dr-h----- C:\MSOCache
2008-02-29 22:21:58 0 d-------- C:\Documents and Settings\Alan\Application Data\Adobe
2008-02-29 22:06:25 0 d-------- C:\NVIDIA
2008-02-29 22:04:16 286720 --a------ C:\WINDOWS\iun506.exe <Not Verified; Indigo Rose Corporation; Setup Factory 5.0 Uninstaller>
2008-02-29 22:04:16 0 d-------- C:\Program Files\ResChanger XP
2008-02-29 21:53:51 0 d-------- C:\Documents and Settings\Alan\Application Data\Creative
2008-02-29 21:51:20 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-02-29 21:50:23 0 d-------- C:\WINDOWS\system32\Data
2008-02-29 21:36:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Creative
2008-02-29 21:31:30 41984 -----n--- C:\WINDOWS\CTRegRun.exe <Not Verified; Creative Technology Ltd; Creative On-line Registration System>
2008-02-29 21:31:25 0 d-------- C:\Program Files\Creative
2008-02-29 21:27:12 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2008-02-29 21:27:12 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-02-29 21:27:12 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-02-29 21:27:12 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-02-29 21:27:12 1474560 --a------ C:\WINDOWS\system32\nview.dll
2008-02-29 21:27:12 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-02-29 21:27:12 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-02-29 21:27:12 425984 --a------ C:\WINDOWS\system32\keystone.exe
2008-02-29 21:27:12 0 d-------- C:\WINDOWS\nview
2008-02-29 21:22:04 0 d-------- C:\WINDOWS\system32\EVGA
2008-02-29 20:54:36 0 d-------- C:\WINDOWS\system32\LogFiles
2008-02-29 20:54:31 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-29 20:54:00 0 d-------- C:\Program Files\NVIDIA Corporation
2008-02-29 20:52:09 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-02-29 20:52:05 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-02-29 20:51:00 0 d-------- C:\WINDOWS\NV23082312.TMP
2008-02-29 20:50:11 0 d-------- C:\Program Files\Common Files\InstallShield
2008-02-29 20:39:46 0 d--h----- C:\WINDOWS\PIF
2008-02-29 20:26:10 16618 -----n--- C:\WINDOWS\hpomdl01.dat
2008-02-29 20:26:10 20454 --a------ C:\WINDOWS\hpoins01.dat
2008-02-29 20:15:54 0 d-------- C:\Program Files\Norton Internet Security
2008-02-29 20:15:25 0 d-------- C:\Program Files\Symantec
2008-02-29 20:15:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-29 20:15:09 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-29 20:10:05 0 d-------- C:\Documents and Settings\Alan\Application Data\Identities
2008-02-29 20:10:00 0 dr------- C:\Documents and Settings\Alan\Favorites
2008-02-29 20:10:00 0 d-------- C:\Documents and Settings\Alan\Desktop
2008-02-29 20:10:00 0 d--hs---- C:\Documents and Settings\Alan\Cookies
2008-02-29 20:10:00 0 dr-h----- C:\Documents and Settings\Alan\Application Data
2008-02-29 20:09:59 0 d--h----- C:\Documents and Settings\Alan\Templates
2008-02-29 20:09:59 0 dr------- C:\Documents and Settings\Alan\Start Menu
2008-02-29 20:09:59 0 dr-h----- C:\Documents and Settings\Alan\SendTo
2008-02-29 20:09:59 0 dr-h----- C:\Documents and Settings\Alan\Recent
2008-02-29 20:09:59 0 d--h----- C:\Documents and Settings\Alan\PrintHood
2008-02-29 20:09:59 3145728 --ah----- C:\Documents and Settings\Alan\NTUSER.DAT
2008-02-29 20:09:59 0 d--h----- C:\Documents and Settings\Alan\NetHood
2008-02-29 20:09:59 0 dr------- C:\Documents and Settings\Alan\My Documents
2008-02-29 20:09:59 0 d--h----- C:\Documents and Settings\Alan\Local Settings
2008-02-29 20:08:35 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-02-29 20:08:34 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-02-29 20:08:34 0 d-------- C:\WINDOWS\Prefetch
2008-02-29 20:08:33 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-02-29 20:08:33 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-02-29 20:08:33 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-02-29 20:08:33 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-02-29 20:08:33 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-02-29 19:22:20 262144 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-02-29 19:22:20 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-02-29 19:22:20 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-02-29 19:22:20 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-02-29 19:22:20 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-02-29 19:19:39 0 d-------- C:\WINDOWS\system32\xircom
2008-02-29 19:19:39 0 d-------- C:\Program Files\microsoft frontpage
2008-02-29 19:19:32 262144 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-02-29 19:19:29 0 d--h----- C:\WINDOWS\$hf_mig$
2008-02-29 19:19:20 0 -rahs---- C:\MSDOS.SYS
2008-02-29 19:19:20 0 -rahs---- C:\IO.SYS
2008-02-29 19:19:20 0 --a------ C:\CONFIG.SYS
2008-02-29 19:19:20 0 --a------ C:\AUTOEXEC.BAT
2008-02-29 19:18:45 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-02-29 19:18:39 0 dr------- C:\WINDOWS\Offline Web Pages
2008-02-29 19:18:39 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-02-29 19:18:32 0 d--h----- C:\Program Files\WindowsUpdate
2008-02-29 19:18:14 0 d-------- C:\WINDOWS\system32\DirectX
2008-02-29 19:17:20 0 d---s---- C:\WINDOWS\Tasks
2008-02-29 19:17:18 0 d-------- C:\Program Files\Common Files\MSSoap
2008-02-29 19:17:12 0 d-------- C:\WINDOWS\srchasst
2008-02-29 19:17:10 0 d-------- C:\WINDOWS\system32\Macromed
2008-02-29 19:16:58 0 d-------- C:\Program Files\Movie Maker
2008-02-29 19:16:44 0 d-------- C:\WINDOWS\system32\Restore
2008-02-29 19:16:08 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-02-29 19:15:58 0 d-------- C:\WINDOWS\Registration
2008-02-29 19:15:54 0 d-------- C:\Program Files\Online Services
2008-02-29 19:15:49 0 d-------- C:\Program Files\Messenger
2008-02-29 19:15:44 0 d-------- C:\Program Files\MSN Gaming Zone
2008-02-29 19:14:47 0 d-------- C:\Program Files\Windows NT
2008-02-29 19:14:41 0 d-------- C:\WINDOWS\system32\MsDtc
2008-02-29 19:14:39 0 d-------- C:\WINDOWS\system32\Com
2008-02-29 14:06:03 0 d--hs---- C:\WINDOWS\Installer
2008-02-29 14:06:02 0 d-------- C:\Program Files\Common Files\ODBC
2008-02-29 14:05:58 0 dr------- C:\Program Files
2008-02-29 14:05:58 0 d-------- C:\Program Files\Common Files
2008-02-29 14:05:58 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-02-29 14:05:31 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-02-29 14:05:31 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-02-29 14:05:31 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-02-29 14:05:31 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-02-29 14:05:31 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-02-29 14:05:31 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-02-29 14:05:31 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-02-29 14:05:31 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-02-29 14:05:31 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-02-29 14:05:31 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-02-29 14:05:31 0 d--hs---- C:\Documents and Settings\Default User\Cookies
2008-02-29 14:05:31 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-02-29 14:05:31 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-02-29 14:05:31 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-02-29 14:05:31 0 dr------- C:\Documents and Settings\All Users\Documents
2008-02-29 14:05:31 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-02-29 14:05:16 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-02-29 14:05:16 0 d-------- C:\WINDOWS\system32\CatRoot
2008-02-29 14:05:10 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-02-29 14:05:10 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-02-29 14:05:10 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-02-29 14:05:10 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-02-29 14:04:44 0 d-------- C:\Documents and Settings
2008-02-29 14:04:43 0 d--hs---- C:\System Volume Information
2008-02-29 13:53:17 0 d-------- C:\WINDOWS
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\WinSxS
2008-02-29 13:53:17 0 dr------- C:\WINDOWS\Web
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\twain_32
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\wins
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\wbem
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\usmt
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\spool
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\ShellExt
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\Setup
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\ras
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\oobe
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\npp
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\mui
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\inetsrv
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\IME
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\icsxml
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\ias
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\export
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\drivers
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-02-29 13:53:17 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\dhcp
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\config
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\3076
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\2052
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1054
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1042
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1041
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1037
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1033
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1031
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1028
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system32\1025
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\system
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\security
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Resources
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\repair
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Provisioning
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\PeerNet
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\pchealth
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\mui
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\msapps
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\msagent
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Media
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\java
2008-02-29 13:53:17 0 d--h----- C:\WINDOWS\inf
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\ime
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Help
2008-02-29 13:53:17 0 dr--s---- C:\WINDOWS\Fonts
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\ehome
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Driver Cache
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Debug
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Cursors
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Connection Wizard
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\Config
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\AppPatch
2008-02-29 13:53:17 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-03-23 01:51:55 34 --a------ C:\Documents and Settings\Alan\Application Data\pcouffin.log
2008-03-23 01:51:53 1144 --a------ C:\Documents and Settings\Alan\Application Data\pcouffin.inf
2008-03-23 01:51:53 7887 --a------ C:\Documents and Settings\Alan\Application Data\pcouffin.cat
2008-03-01 01:59:58 5584 --a------ C:\Program Files\install.log
2008-02-29 14:05:31 62 --ahs---- C:\Documents and Settings\Alan\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/10/2007 01:59 AM]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [01/14/2007 03:11 AM]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [09/13/2006 11:12 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [12/05/2007 02:41 AM]
"nwiz"="nwiz.exe" [12/05/2007 02:41 AM C:\WINDOWS\system32\nwiz.exe]
"ResChangerXP"="C:\Program Files\ResChanger XP\ResChangerXP.exe" [02/14/2002 03:33 PM]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [12/05/2007 02:41 AM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 06:38 PM]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 01:47 AM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [02/18/2008 04:29 PM]
"VX6000"="C:\WINDOWS\vVX6000.exe" [10/13/2006 06:04 PM]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [10/13/2006 06:01 PM]
"CTHelper"="CTHELPER.EXE" [08/11/2006 03:56 PM C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [08/11/2006 03:56 PM C:\WINDOWS\system32\CTXFIHLP.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 05:25 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [02/01/2008 12:13 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 11:16 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 01:10 PM]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [02/28/2008 09:59 AM]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [03/17/2006 10:24 PM]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 05:25 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\PHOTOS~1\data\xtras\mssysmgr.exe" [04/27/2007 02:16 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 12:24 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [01/03/2008 12:15 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [02/28/2006 08:00 AM]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.ex