MAIN
Deckard's System Scanner v20071014.68
Run by Finn on 2008-04-17 20:20:44
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Finn.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:21:37 PM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
D:\dss.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Finn.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AntiVirusPro] C:\Program Files\AntiVirusPro\AntiVirusPro.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoft...s/as2stubie.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1208060883875O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9176 bytes
-- Files created between 2008-03-17 and 2008-04-17 -----------------------------
2008-04-17 16:57:44 0 d-------- C:\WINDOWS\system32\appmgmt
2008-04-16 16:25:05 0 d-------- C:\Documents and Settings\Finn\Application Data\Sonic
2008-04-16 16:24:37 0 d-------- C:\Documents and Settings\Finn\Application Data\Leadertech
2008-04-16 16:14:11 0 d-------- C:\OTScanIt
2008-04-16 15:54:57 68096 --a------ C:\WINDOWS\zip.exe
2008-04-16 15:54:57 49152 --a------ C:\WINDOWS\VFind.exe
2008-04-16 15:54:57 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-04-16 15:54:57 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-04-16 15:54:57 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-04-16 15:54:57 98816 --a------ C:\WINDOWS\sed.exe
2008-04-16 15:54:57 80412 --a------ C:\WINDOWS\grep.exe
2008-04-16 15:54:57 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-04-16 15:43:54 0 d-------- C:\AOL OCP
2008-04-16 15:16:41 0 d-------- C:\My Videos
2008-04-14 23:42:04 0 d--h----- C:\WINDOWS\system32\Settings
2008-04-14 17:05:03 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-04-14 17:05:03 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-04-14 17:05:03 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-04-14 17:05:03 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-04-14 17:05:03 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-04-14 17:05:03 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-04-14 17:05:03 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-04-14 17:05:03 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-04-14 17:05:03 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-04-14 17:05:03 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-04-14 17:05:03 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-04-14 17:05:03 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-04-14 17:05:03 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-04-14 17:05:03 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-04-14 17:05:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-14 16:45:48 0 d--hs---- C:\WINDOWS\CSC
2008-04-13 18:15:55 0 d-------- C:\Documents and Settings\Finn\Application Data\Viewpoint
2008-04-13 03:00:47 0 d-------- C:\WINDOWS\system32\PreInstall
2008-04-12 23:56:34 0 d-------- C:\Documents and Settings\Finn\Application Data\Adobe
2008-04-12 23:39:03 0 d-------- C:\Documents and Settings\Finn\Application Data\Google
2008-04-12 23:38:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-04-12 23:38:35 0 d-------- C:\Program Files\Google
2008-04-12 23:27:10 0 d-------- C:\Program Files\Veoh Networks
2008-04-12 23:26:32 0 d-------- C:\WINDOWS\Downloaded Installations
2008-04-12 22:20:00 0 dr-h----- C:\$VAULT$.AVG
2008-04-12 21:50:44 0 d-------- C:\Program Files\Panda Security
2008-04-12 21:10:31 0 d-------- C:\Documents and Settings\Finn\Application Data\AVG7
2008-04-12 21:10:07 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-12 21:09:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-12 21:09:34 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-12 17:43:33 290 --a------ C:\Documents and Settings\Finn\Application Data\wklnhst.dat
2008-04-12 15:56:06 0 d-------- C:\Program Files\CONEXANT
2008-04-12 15:54:39 0 d-------- C:\Program Files\Broadcom
2008-04-12 15:51:49 0 d-------- C:\Program Files\SigmaTel
2008-04-12 15:49:49 0 d-------- C:\Program Files\DIFX
2008-04-12 15:48:10 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-04-12 14:46:32 0 d-------- C:\WINDOWS\system32\Lang
2008-04-12 14:46:28 0 d-------- C:\Intel
2008-04-12 14:43:14 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-12 14:12:41 0 d---s---- C:\Documents and Settings\Finn\UserData
2008-04-12 14:08:33 0 d-------- C:\Documents and Settings\Finn\Application Data\Malwarebytes
2008-04-12 14:08:27 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 14:08:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-12 14:06:32 167936 --a------ C:\WINDOWS\system32\drivers\qandr.sys
2008-04-12 13:37:35 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-04-12 13:37:16 6656 --a------ C:\WINDOWS\tions.dll
2008-04-12 13:26:55 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-04-12 13:19:58 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-04-12 03:32:38 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Intel
2008-04-12 03:32:38 0 d-------- C:\Documents and Settings\LocalService\Application Data\Intel
2008-04-12 03:32:38 0 d-------- C:\Documents and Settings\Finn\Application Data\Intel
2008-04-12 03:32:38 0 d-------- C:\Documents and Settings\Default User\Application Data\Intel
2008-04-12 03:32:31 376832 --a------ C:\WINDOWS\system32\AegisI5Installer.exe <Not Verified; ; AegisInstall Application>
2008-04-12 03:32:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Intel
2008-04-12 03:31:38 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-04-12 03:31:35 0 d-------- C:\Program Files\Intel
2008-04-12 03:31:20 0 d-------- C:\Documents and Settings\Finn\Contacts
2008-04-12 03:30:59 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-04-12 03:30:23 0 d-------- C:\Program Files\Real
2008-04-12 03:27:50 0 d-------- C:\Program Files\MSN Messenger
2008-04-12 03:19:59 0 d-------- C:\Documents and Settings\Finn\Application Data\Apple Computer
2008-04-12 03:19:45 0 d-------- C:\Program Files\iPod
2008-04-12 03:19:39 0 d-------- C:\Program Files\iTunes
2008-04-12 03:19:26 0 d-------- C:\Program Files\Bonjour
2008-04-12 03:18:51 0 d-------- C:\Program Files\QuickTime
2008-04-12 03:18:49 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-12 03:18:31 0 d-------- C:\Program Files\Apple Software Update
2008-04-12 03:18:10 0 d-------- C:\Program Files\Common Files\Apple
2008-04-12 03:18:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-12 03:15:31 0 d-------- C:\Documents and Settings\Finn\Application Data\QQ Games Plugin
2008-04-12 03:15:27 0 d-------- C:\Documents and Settings\Finn\Application Data\acccore
2008-04-12 03:12:06 0 d-------- C:\Program Files\Tencent
2008-04-12 03:11:24 0 d-------- C:\Program Files\AIMTunes
2008-04-12 03:09:24 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-04-12 03:08:34 0 d-------- C:\Program Files\AIM Search
2008-04-12 03:08:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-12 03:08:31 0 d-------- C:\Program Files\Viewpoint
2008-04-12 03:08:26 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-04-12 03:08:26 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-04-12 03:08:12 0 d-------- C:\Program Files\Common Files\AOL
2008-04-12 03:07:34 0 d-------- C:\Program Files\Microsoft Streets and Trips Essentials
2008-04-12 03:07:25 0 d-------- C:\Program Files\Microsoft Location Finder
2008-04-12 03:07:08 0 d-------- C:\Program Files\AIM6
2008-04-12 03:04:06 0 d-------- C:\Documents and Settings\Finn\Application Data\Macromedia
2008-04-12 03:03:34 0 d-------- C:\Program Files\Encarta
2008-04-12 02:57:58 0 d-------- C:\Program Files\Microsoft Digital Image 2006
2008-04-12 02:55:50 0 d-------- C:\Program Files\microsoft money 2006
2008-04-12 02:51:42 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-04-12 02:51:37 0 d-------- C:\WINDOWS\ShellNew
2008-04-12 02:46:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Citrix
2008-04-12 02:46:13 0 d-------- C:\Program Files\Citrix
2008-04-12 02:45:38 0 d-------- C:\Program Files\Microsoft Works
2008-04-12 02:42:51 0 d-------- C:\Program Files\Microsoft Works Suite 2006
2008-04-12 02:35:36 0 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-12 02:34:46 0 d-------- C:\Program Files\Common Files\TiVo Shared
2008-04-12 02:33:15 0 d-------- C:\WINDOWS\system32\DLA
2008-04-12 02:32:22 0 d-------- C:\Program Files\Roxio
2008-04-12 02:27:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-04-12 02:26:45 0 d-------- C:\Program Files\Trend Micro
2008-04-12 02:24:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-04-12 02:24:30 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-04-12 02:24:19 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-04-12 02:16:30 0 d-------- C:\WINDOWS\system32\vmm32
2008-04-12 02:16:29 0 d-------- C:\Program Files\Dell
2008-04-12 02:16:10 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-12 02:04:52 0 d-------- C:\Documents and Settings\Finn\Application Data\Identities
2008-04-12 02:02:00 0 d-------- C:\WINDOWS\RegisteredPackages
2008-04-12 01:56:10 0 d-------- C:\WINDOWS\system32\URTTemp
2008-04-12 01:55:42 0 d-------- C:\Program Files\RGB
2008-04-12 01:53:49 0 d-------- C:\Documents and Settings\All Users\Application Data\DIGStream
2008-04-12 01:53:48 0 d-------- C:\Program Files\DIGStream
2008-04-12 01:53:47 0 d-------- C:\Program Files\ESPNMotion
2008-04-12 01:53:43 0 d-------- C:\Program Files\GemMaster
2008-04-12 01:53:40 0 d-------- C:\Program Files\EnglishOtto
2008-04-12 01:48:23 0 d--h----- C:\Documents and Settings\Finn\Templates
2008-04-12 01:48:23 0 dr------- C:\Documents and Settings\Finn\Start Menu
2008-04-12 01:48:23 0 dr-h----- C:\Documents and Settings\Finn\SendTo
2008-04-12 01:48:23 0 dr-h----- C:\Documents and Settings\Finn\Recent
2008-04-12 01:48:23 0 d--h----- C:\Documents and Settings\Finn\PrintHood
2008-04-12 01:48:23 1835008 --ah----- C:\Documents and Settings\Finn\NTUSER.DAT
2008-04-12 01:48:23 0 d--h----- C:\Documents and Settings\Finn\NetHood
2008-04-12 01:48:23 0 dr------- C:\Documents and Settings\Finn\My Documents
2008-04-12 01:48:23 0 d--h----- C:\Documents and Settings\Finn\Local Settings
2008-04-12 01:48:23 0 dr------- C:\Documents and Settings\Finn\Favorites
2008-04-12 01:48:23 0 d-------- C:\Documents and Settings\Finn\Desktop
2008-04-12 01:48:23 0 d--hs---- C:\Documents and Settings\Finn\Cookies
2008-04-12 01:48:23 0 dr-h----- C:\Documents and Settings\Finn\Application Data
2008-04-12 01:47:32 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-04-12 01:47:29 0 d-------- C:\WINDOWS\Prefetch
2008-04-12 01:47:28 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-04-12 01:47:27 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-04-12 01:47:27 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-04-12 01:47:27 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-04-12 01:47:27 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-04-12 01:47:27 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-04-12 01:47:14 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-04-12 01:47:14 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-04-12 01:47:14 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-04-12 01:47:14 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-04-12 01:47:14 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-04-12 01:43:14 0 d-------- C:\WINDOWS\system32\xircom
2008-04-12 01:43:14 0 d-------- C:\Program Files\microsoft frontpage
2008-04-12 01:42:05 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-04-12 01:42:05 0 d-------- C:\DELL
2008-04-12 01:41:54 0 d--h----- C:\WINDOWS\$hf_mig$
2008-04-12 01:41:33 0 -rahs---- C:\MSDOS.SYS
2008-04-12 01:41:33 0 -rahs---- C:\IO.SYS
2008-04-12 01:41:33 0 --a------ C:\CONFIG.SYS
2008-04-12 01:41:33 0 --a------ C:\AUTOEXEC.BAT
2008-04-12 01:40:13 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-04-12 01:40:03 0 dr------- C:\WINDOWS\Offline Web Pages
2008-04-12 01:40:03 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-04-12 01:39:52 0 d--h----- C:\Program Files\WindowsUpdate
2008-04-12 01:39:30 0 d-------- C:\WINDOWS\system32\DirectX
2008-04-12 01:38:53 0 d---s---- C:\WINDOWS\Tasks
2008-04-12 01:38:52 0 d-------- C:\Program Files\Common Files\MSSoap
2008-04-12 01:38:47 0 d-------- C:\WINDOWS\srchasst
2008-04-12 01:38:46 0 d-------- C:\WINDOWS\system32\Macromed
2008-04-12 01:38:26 0 d-------- C:\WINDOWS\system32\Restore
2008-04-12 01:37:06 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-12 01:36:47 0 d-------- C:\WINDOWS\Registration
2008-04-12 01:36:39 0 d-------- C:\Program Files\Online Services
2008-04-12 01:35:43 0 d-------- C:\Program Files\Windows Plus
2008-04-12 01:35:23 0 d-------- C:\Program Files\Movie Maker
2008-04-12 01:33:39 0 d-------- C:\Program Files\Messenger
2008-04-12 01:33:36 0 d-------- C:\Program Files\MSN Gaming Zone
2008-04-12 01:32:49 0 d-------- C:\Program Files\Windows NT
2008-04-12 01:32:45 0 d-------- C:\WINDOWS\system32\MsDtc
2008-04-12 01:32:43 0 d-------- C:\WINDOWS\system32\Com
2008-04-11 19:26:03 0 d--hs---- C:\WINDOWS\Installer
2008-04-11 19:26:02 0 d-------- C:\Program Files\Common Files\ODBC
2008-04-11 19:25:58 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-04-11 19:25:57 0 dr------- C:\Program Files
2008-04-11 19:25:57 0 d-------- C:\Program Files\Common Files
2008-04-11 19:25:32 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-04-11 19:25:32 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-04-11 19:25:32 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-04-11 19:25:32 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-04-11 19:25:32 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-04-11 19:25:32 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-04-11 19:25:32 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-04-11 19:25:32 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-04-11 19:25:32 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-04-11 19:25:32 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-04-11 19:25:32 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-04-11 19:25:32 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-04-11 19:25:32 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-04-11 19:25:32 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-04-11 19:25:32 0 dr------- C:\Documents and Settings\All Users\Documents
2008-04-11 19:25:32 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-04-11 19:25:19 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-04-11 19:25:19 0 d-------- C:\WINDOWS\system32\CatRoot
2008-04-11 19:25:14 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-04-11 19:25:14 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-04-11 19:25:13 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-04-11 19:25:13 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-04-11 19:24:48 0 d-------- C:\Documents and Settings
2008-04-11 19:24:47 0 d--hs---- C:\System Volume Information
2008-04-11 19:15:46 0 d-------- C:\WINDOWS
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\WinSxS
2008-04-11 19:15:46 0 dr------- C:\WINDOWS\Web
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\twain_32
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\wins
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\wbem
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\usmt
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\spool
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\ShellExt
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\Setup
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\ras
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\oobe
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\npp
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\mui
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\inetsrv
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\IME
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\icsxml
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\ias
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\export
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\drivers
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-04-11 19:15:46 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\dhcp
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\config
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\3076
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\2052
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1054
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1042
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1041
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1037
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1033
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1031
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1028
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system32\1025
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\system
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\security
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Resources
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\repair
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Provisioning
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\PeerNet
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\pchealth
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\mui
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\msapps
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\msagent
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Media
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\java
2008-04-11 19:15:46 0 d--h----- C:\WINDOWS\inf
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\ime
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Help
2008-04-11 19:15:46 0 dr--s---- C:\WINDOWS\Fonts
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\ehome
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Driver Cache
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\dell
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Debug
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Cursors
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Connection Wizard
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\Config
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\AppPatch
2008-04-11 19:15:46 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-04-11 19:25:32 62 --ahs---- C:\Documents and Settings\Finn\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 01:56 PM]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [11/01/2005 03:12 AM]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [11/21/2006 02:02 PM]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [11/07/2005 05:20 AM]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [07/27/2004 04:50 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [07/27/2004 04:50 PM]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [10/08/2007 02:18 PM]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [10/08/2007 02:13 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"AntiVirusPro"="C:\Program Files\AntiVirusPro\AntiVirusPro.exe" []
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [03/30/2007 08:00 PM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [03/30/2007 08:00 PM]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [03/30/2007 07:59 PM]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [05/10/2007 10:22 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/12/2008 09:09 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [08/04/2006 04:15 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [03/25/2008 02:21 PM]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [01/19/2007 12:54 PM]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [04/01/2008 06:35 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/13/2008 01:44 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 05:00 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll 04/12/2008 03:45 PM 10792 C:\Program Files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
-- End of Deckard's System Scanner: finished at 2008-04-17 20:24:05 ------------