main.txt
Deckard's System Scanner v20071014.68
Run by Elliott on 2008-03-29 22:25:02
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Elliott.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:26:03, on 29/03/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\ProgramData\uncjmbaz\gvklmhun.exe
C:\ProgramData\egkcukbf\chefqven.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Elliott\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Elliott.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [oizwubvz] C:\ProgramData\oizwubvz\gvyxilol.exe
O4 - HKCU\..\Run: [FpyoukPQ0m] C:\ProgramData\uncjmbaz\gvklmhun.exe
O4 - HKCU\..\Run: [egkcukbf] C:\ProgramData\egkcukbf\chefqven.exe
O4 - HKCU\..\Run: [ynlatdwo] C:\ProgramData\ynlatdwo\gjclevmh.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [tjyhfuid] C:\ProgramData\tjyhfuid\qjyxgzcx.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 8908 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 SASENUM - \??\c:\program files\superantispyware\sasenum.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 RegSrvc (Intel® PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel® PROSet/Wireless Registry Service>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-29 10:30:15 422 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{8A90457D-2790-4DE6-9CE9-1ECABBC22DDD}.job
2008-03-27 22:56:56 504 --a------ C:\Windows\Tasks\Norton Security Online - Run Full System Scan - Elliott.job
-- Files created between 2008-02-29 and 2008-03-29 -----------------------------
2008-03-29 19:57:43 0 d-------- C:\Windows\system32\Adobe
2008-03-28 21:46:58 0 d-------- C:\Users\All Users\tjyhfuid
2008-03-28 17:23:41 0 d-------- C:\Program Files\Trend Micro
2008-03-28 17:11:26 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-03-28 17:05:09 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-28 17:04:50 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 15:24:06 0 --a------ C:\Windows\nsreg.dat
2008-03-28 15:23:12 0 d-------- C:\Users\All Users\Grisoft
2008-03-28 14:51:40 0 d-------- C:\Users\All Users\ynlatdwo
2008-03-28 13:38:03 0 d-------- C:\Users\All Users\egkcukbf
2008-03-28 11:43:09 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-27 23:07:47 5130 --a------ C:\Windows\system32\tmp.reg
2008-03-27 23:06:32 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-03-27 23:06:32 82432 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-03-27 23:06:31 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-03-27 23:06:31 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-03-27 23:06:31 51200 --a------ C:\Windows\system32\dumphive.exe
2008-03-27 23:06:30 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-03-27 23:06:30 53248 --a------ C:\Windows\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-03-27 23:06:26 0 d-------- C:\Users\Elliott\SmitfraudFix
2008-03-27 17:32:34 0 d-------- C:\Users\Elliott\Desktopvirii
2008-03-27 17:32:33 4096 --a------ C:\Users\Elliott\DesktopFWebdEditor.exe
2008-03-27 17:32:33 4096 --a------ C:\Users\Elliott\Desktopfwebd.exe
2008-03-27 17:32:33 4096 --a------ C:\Users\Elliott\Desktopfilemanagerclient.exe
2008-03-27 17:32:27 0 d-------- C:\Users\All Users\uncjmbaz
2008-03-27 17:32:26 0 d-------- C:\Users\All Users\oizwubvz
2008-03-25 12:49:32 0 d-------- C:\Program Files\Common Files\Microsoft Games
2008-03-24 21:23:19 0 d-------- C:\Users\All Users\Age of Empires 3
2008-03-22 09:44:07 61568 -ra------ C:\Windows\VIEWER.EXE <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:07 17536 -ra------ C:\Windows\VIEWENU.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:07 93504 -ra------ C:\Windows\QTW16DEL.EXE <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:07 74496 -ra------ C:\Windows\PLAYER.EXE <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:07 16928 -ra------ C:\Windows\PLAYENU.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 73712 -ra------ C:\Windows\system\QTOLE.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 4176 -ra------ C:\Windows\system\QTNOTIFY.EXE <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 14544 -ra------ C:\Windows\system\QTIMCMGR.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 429424 -ra------ C:\Windows\system\QTIM.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 8304 -ra------ C:\Windows\system\QTHNDLR.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:06 4320 -ra------ C:\Windows\system\MCIQTENU.DLL <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:44:03 2037248 -ra------ C:\Windows\QTINSTAL.EXE <Not Verified; Apple Computer, Inc.; QuickTime for Windows>
2008-03-22 09:43:51 161792 --a------ C:\Windows\uninst95.exe <Not Verified; Syracuse Language Systems; GENERIC UNINSTALL Application>
2008-03-22 09:43:49 298880 --a------ C:\Windows\system32\VBAR2.DLL <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-03-22 09:43:49 1984 --a------ C:\Windows\system32\VBAJET.DLL <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-03-22 09:43:49 51712 --a------ C:\Windows\system32\OLE2PROX.DLL <Not Verified; Microsoft Corporation; Microsoft OLE 2.02 for Windows>
2008-03-22 09:43:49 57328 --a------ C:\Windows\system32\OLE2CONV.DLL <Not Verified; Microsoft Corporation; Microsoft Graphic Filters>
2008-03-22 09:43:49 27026 --a------ C:\Windows\system32\OLE2.REG
2008-03-22 09:43:49 64080 --a------ C:\Windows\system32\ODBCTL16.DLL <Not Verified; Microsoft Corporation; Microsoft Open Database Connectivity>
2008-03-22 09:43:49 246928 --a------ C:\Windows\system32\ODBCJT16.DLL <Not Verified; Microsoft Corporation; Microsoft ODBC Desktop Driver Pack 2.>
2008-03-22 09:43:49 92576 --a------ C:\Windows\system32\ODBCINST.DLL <Not Verified; Microsoft Corporation; Microsoft Open Database Connectivity>
2008-03-22 09:43:49 88896 --a------ C:\Windows\system32\ODBCCURS.DLL <Not Verified; Microsoft Corporation; Microsoft Open Database Connectivity>
2008-03-22 09:43:49 56240 --a------ C:\Windows\system32\ODBC.DLL <Not Verified; Microsoft Corporation; Microsoft Open Database Connectivity>
2008-03-22 09:43:48 6496 --a------ C:\Windows\system32\ODBCADM.EXE <Not Verified; ; Microsoft Open Database Connectivity>
2008-03-22 09:43:48 15936 --a------ C:\Windows\system32\MSJETINT.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet Database Engine>
2008-03-22 09:43:48 11232 --a------ C:\Windows\system32\MSJETERR.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet Database Engine>
2008-03-22 09:43:48 10304 --a------ C:\Windows\system32\MSCPXLT.DLL <Not Verified; Microsoft Corporation; Microsoft Open Database Connectivity>
2008-03-22 09:43:48 995056 --a------ C:\Windows\system32\MSAJT200.DLL <Not Verified; Microsoft Corporation; Microsoft® Access>
2008-03-22 09:43:47 7168 --a------ C:\Windows\system32\DISPDIB.DLL <Not Verified; Microsoft Corporation; Microsoft Video for Windows>
2008-03-22 09:43:47 0 d-------- C:\OLDDRIVR
2008-03-22 09:43:34 299520 --a------ C:\Windows\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-03-22 09:43:29 0 -rahs---- C:\MSDOS.SYS
2008-03-22 09:43:29 0 -rahs---- C:\IO.SYS
2008-03-20 10:34:42 0 d-------- C:\Program Files\Symantec
2008-03-20 10:34:40 0 d-------- C:\Users\All Users\Symantec
2008-03-20 10:34:26 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-20 10:33:53 0 d-------- C:\Users\All Users\Yahoo!
2008-03-20 10:33:53 0 d-------- C:\graphics
2008-03-20 10:23:45 0 d-------- C:\Program Files\Yahoo!
2008-03-15 13:03:36 0 d-------- C:\Users\Elliott\My Google Gadgets
2008-03-11 18:28:31 0 d-------- C:\Users\All Users\Alfac
2008-03-11 18:28:17 0 d-------- C:\Program Files\DECAdry
2008-03-09 19:32:29 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-03-09 19:31:36 0 d-------- C:\Program Files\Microsoft.NET
2008-03-09 19:29:43 0 dr-h----- C:\MSOCache
2008-03-06 19:16:59 0 d-------- C:\Windows\PCHEALTH
2008-03-06 19:13:01 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-06 19:12:56 0 d-------- C:\Program Files\Windows Live
2008-03-06 19:12:24 0 d-------- C:\Users\All Users\WLInstaller
2008-03-05 22:16:10 0 d-------- C:\Users\All Users\Roxio
2008-03-05 21:18:28 0 d-------- C:\Program Files\MSXML 4.0
2008-03-05 20:44:28 0 d-------- C:\Users\All Users\NVIDIA
2008-03-05 20:43:55 0 dr------- C:\Users\Elliott\Searches
2008-03-05 20:43:44 0 dr------- C:\Users\Elliott\Contacts
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Videos
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Templates
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Start Menu
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\SendTo
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Saved Games
2008-03-05 20:42:50 0 d-------- C:\Users\Elliott\Roaming
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Recent
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\PrintHood
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Pictures
2008-03-05 20:42:50 2883584 --ahs---- C:\Users\Elliott\NTUSER.DAT
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\NetHood
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\My Documents
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Music
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Local Settings
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Links
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Favorites
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Downloads
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Documents
2008-03-05 20:42:50 0 dr------- C:\Users\Elliott\Desktop
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Cookies
2008-03-05 20:42:50 0 d--hs---- C:\Users\Elliott\Application Data
2008-03-05 20:42:50 0 d--h----- C:\Users\Elliott\AppData
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Templates
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Start Menu
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Favorites
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Documents
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Desktop
2008-03-05 20:39:20 0 d--hs---- C:\Users\All Users\Application Data
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Templates
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Start Menu
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\SendTo
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Recent
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\PrintHood
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\NetHood
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\My Documents
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Local Settings
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Cookies
2008-03-05 20:39:19 0 d--hs---- C:\Users\Default\Application Data
-- Find3M Report ---------------------------------------------------------------
2008-03-29 19:26:56 27525 --a------ C:\Users\Elliott\AppData\Roaming\nvModes.001
2008-03-28 17:05:09 0 d-------- C:\Users\Elliott\AppData\Roaming\SUPERAntiSpyware.com
2008-03-28 17:04:50 0 d-------- C:\Program Files\Common Files
2008-03-28 15:24:00 0 d-------- C:\Users\Elliott\AppData\Roaming\Mozilla
2008-03-28 15:23:40 0 d-------- C:\Users\Elliott\AppData\Roaming\Grisoft
2008-03-27 23:07:48 35 --a------ C:\Users\Elliott\AppData\Roaming\SetValue.bat
2008-03-27 23:07:48 691 --a------ C:\Users\Elliott\AppData\Roaming\GetValue.vbs
2008-03-25 13:16:53 27525 --a------ C:\Users\Elliott\AppData\Roaming\nvModes.dat
2008-03-25 12:49:39 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-22 10:57:28 0 d-------- C:\Program Files\Microsoft Games
2008-03-21 09:38:16 0 d-------- C:\Users\Elliott\AppData\Roaming\Adobe
2008-03-20 10:43:43 0 d-------- C:\Users\Elliott\AppData\Roaming\Yahoo!
2008-03-15 12:05:01 0 d-------- C:\Users\Elliott\AppData\Roaming\PeerNetworking
2008-03-15 11:46:31 31007 --a------ C:\Users\Elliott\AppData\Roaming\UserTile.png
2008-03-14 20:39:39 0 d-------- C:\Users\Elliott\AppData\Roaming\CyberLink
2008-03-11 21:34:42 0 d-------- C:\Program Files\Windows Mail
2008-03-11 18:41:08 0 d-------- C:\Users\Elliott\AppData\Roaming\Alfac
2008-03-11 18:25:27 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-06 16:37:51 0 d-------- C:\Users\Elliott\AppData\Roaming\Google
2008-03-06 16:12:09 0 d-------- C:\Users\Elliott\AppData\Roaming\Macromedia
2008-03-05 22:53:22 0 d-------- C:\Program Files\Windows Sidebar
2008-03-05 22:16:10 0 d-------- C:\Users\Elliott\AppData\Roaming\Roxio
2008-03-05 21:26:56 0 d-------- C:\Users\Elliott\AppData\Roaming\Creative
2008-03-05 20:58:18 0 d-------- C:\Users\Elliott\AppData\Roaming\Intel
2008-03-05 20:43:46 0 d-------- C:\Users\Elliott\AppData\Roaming\Identities
2008-02-28 13:03:39 0 d-------- C:\Program Files\DellTPad
2008-02-28 12:56:32 0 d-------- C:\Program Files\Windows Calendar
2008-02-28 12:52:00 0 d-------- C:\Program Files\Windows Defender
2008-02-28 05:39:28 0 d-------- C:\Program Files\Dell
2008-02-28 05:38:55 0 d-------- C:\Program Files\Tiscali
2008-02-28 05:38:44 0 d-------- C:\Program Files\Microsoft Works
2008-02-28 05:38:01 0 d-------- C:\Program Files\Roxio
2008-02-28 05:38:01 0 d-------- C:\Program Files\Common Files\SureThing Shared
2008-02-28 05:36:59 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-02-28 05:36:56 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-02-28 05:36:55 0 d-------- C:\Program Files\Common Files\PX Storage Engine
2008-02-28 05:34:33 0 d-------- C:\Program Files\CyberLink
2008-02-28 05:33:04 0 d-------- C:\Program Files\Dell Support Center
2008-02-28 05:32:58 0 d-------- C:\Program Files\Common Files\supportsoft
2008-02-28 05:31:02 0 d-------- C:\Program Files\Google
2008-02-28 05:30:35 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-28 05:29:39 0 d-------- C:\Program Files\Online Services
2008-02-28 05:25:17 0 d-------- C:\Program Files\Intel
2008-02-28 05:24:43 76 -r-hs---- C:\Windows\CT4CET.bin
2008-02-28 05:24:31 0 d-------- C:\Program Files\Creative
2008-02-28 05:24:21 0 d-------- C:\Program Files\Common Files\Reallusion
2008-02-28 05:23:41 0 d-------- C:\Program Files\Creative Live! Cam
2008-02-28 05:22:59 0 d-------- C:\Program Files\Fingerprint Reader Suite
2008-02-28 05:21:06 0 d-------- C:\Program Files\Intel, Inc
2008-02-28 05:20:09 0 d-------- C:\Program Files\Java
2008-02-28 05:20:09 0 d-------- C:\Program Files\Common Files\Java
2008-02-28 05:11:16 174 --ahs---- C:\Program Files\desktop.ini
2008-02-28 05:09:25 0 d-------- C:\Program Files\Sigmatel
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [28/02/2008 12:51]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [25/05/2007 06:03]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [07/09/2007 08:50]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [28/08/2007 05:51]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [03/12/2007 04:28]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [28/09/2007 06:24]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [28/09/2007 06:24]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [28/09/2007 06:24]
"NVHotkey"="C:\Windows\system32\nvHotkey.dll" [28/09/2007 06:24]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [28/02/2008 05:20]
"PSQLLauncher"="C:\Program Files\Fingerprint Reader Suite\launcher.exe" [16/04/2007 22:50]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [27/07/2007 16:43]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [21/03/2007 13:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/05/2007 03:06]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [28/02/2008 05:31]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [15/11/2007 09:24]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [01/11/2007 15:39]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [26/06/2007 13:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [10/01/2007 05:59]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 09:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [05/03/2008 21:19]
"oizwubvz"="C:\ProgramData\oizwubvz\gvyxilol.exe" [27/03/2008 17:32]
"FpyoukPQ0m"="C:\ProgramData\uncjmbaz\gvklmhun.exe" [27/03/2008 17:32]
"egkcukbf"="C:\ProgramData\egkcukbf\chefqven.exe" [28/03/2008 13:38]
"ynlatdwo"="C:\ProgramData\ynlatdwo\gjclevmh.exe" [28/03/2008 14:51]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [29/02/2008 16:03]
"tjyhfuid"="C:\ProgramData\tjyhfuid\qjyxgzcx.exe" [28/03/2008 21:47]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [07/09/2007 16:27:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"DisableCAD"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 16/04/2007 23:04 86528 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee94f040-e5ba-11dc-be59-806e6f6e6963}]
AutoRun\command- E:\autorun.exe
directx\command- E:\DirectX9\dxsetup.exe
setup\command- E:\setup.exe
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-03-29 22:27:04 ------------