Hi Mike,
Thanks for the reply. I've run dss. Here is my main.txt:
Deckard's System Scanner v20071014.68
Run by Compaq_Administrator on 2008-05-18 12:56:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-05-18 16:57:03 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Percentage of Memory in Use: 78% (more than 75%).Total Physical Memory: 447 MiB (512 MiB recommended).-- HijackThis (run as Compaq_Administrator.exe) --------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:34 PM, on 5/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\WINDOWS\cfgmng32.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\svcprs32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\mdmcls32.exe
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdMgr.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CAGlobal.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Light\CAGlobalLight.exe
C:\Documents and Settings\Compaq_Administrator\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Compaq_Administrator.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.h...a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.h...a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.redirect.h...a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.h...a...&pf=desktopR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [dvHighMem] C:\WINDOWS\cfgmng32.exe
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://*.trymedia.com (HKLM)
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) -
http://www.trendsecu...vex/TmHcmsX.CABO16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) -
http://ipgweb.cce.hp...ads/sysinfo.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe
--
End of file - 10809 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S0 ftsata2 - c:\windows\system32\drivers\ftsata2.sys (file missing)
S1 intelppm (Intel Processor Driver) - c:\windows\system32\drivers\intelppm.sys (file missing)
S3 SymIM (Symantec Network Security Intermediate Filter Service) - c:\windows\system32\drivers\symim.sys (file missing)
S3 SymIMMP - c:\windows\system32\drivers\symim.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 WinSvchostManager (WinSock Svchost Manager) - c:\windows\system32\svcprs32.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-18 02:15:18 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
-- Files created between 2008-04-18 and 2008-05-18 -----------------------------
2008-05-18 12:59:19 0 d-------- C:\Program Files\Trend Micro
2008-05-13 19:00:24 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\WinBatch
2008-05-11 17:41:46 0 d-------- C:\Program Files\Windows Defender
2008-05-07 01:59:59 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-07 01:59:46 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-07 01:59:45 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\SUPERAntiSpyware.com
2008-05-06 20:32:04 0 d-------- C:\Program Files\Lavasoft
2008-05-06 20:32:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-06 19:56:33 0 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-06 07:19:38 0 d-------- C:\WINDOWS\CAVTemp
2008-05-06 07:01:54 0 d-------- C:\Program Files\MSXML 4.0
2008-05-06 00:59:01 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\AdobeUM
2008-05-06 00:25:01 6 --a------ C:\WINDOWS\system32\mkghj.dll
2008-05-05 23:21:40 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\CallingID
2008-05-05 23:21:32 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-05 23:21:09 0 d-------- C:\WINDOWS\Downloaded Installations
2008-05-05 23:21:05 0 d-------- C:\Program Files\Common Files\Scanner
2008-05-05 23:20:33 1564771 --a------ C:\WINDOWS\system32\winsflt.dll
2008-05-05 23:20:33 2732032 --a------ C:\WINDOWS\system32\win32cpr.dll
2008-05-05 23:20:33 823296 --a------ C:\WINDOWS\system32\svcprs32.exe
2008-05-05 23:20:33 1212416 --a------ C:\WINDOWS\system32\mdmcls32.exe
2008-05-05 23:20:32 1830912 --a------ C:\WINDOWS\system32\winsflte.dll <Not Verified; PureSight Inc; PureSight Classification SDK>
2008-05-05 23:20:32 11333632 --a------ C:\WINDOWS\cfgmng32.exe
2008-05-05 23:20:28 7440 --a------ C:\WINDOWS\system32\sporder.dll <Not Verified; Microsoft Corporation; Microsoft® Windows NT® Operating System>
2008-05-05 23:20:28 0 d-------- C:\WINDOWS\rnapxs
2008-05-05 23:18:51 0 d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-05-05 23:18:49 0 d-------- C:\Program Files\CA
2008-05-05 23:16:17 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\GetRightToGo
2008-05-05 22:01:32 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-05 21:58:52 0 d--hs---- C:\Documents and Settings\Compaq_Administrator\UserData
2008-05-05 18:49:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-05 18:42:33 0 d-------- C:\Program Files\Common Files\Java
2008-05-05 18:10:25 0 d-------- C:\WINDOWS\pss
2008-05-05 17:56:07 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-05 17:41:51 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\HPQ
2008-05-05 17:26:06 0 d-------- C:\WINDOWS\system32\appmgmt
2008-05-05 07:58:42 0 d-------- C:\Documents and Settings\Compaq_Administrator\.housecall6.6
2008-05-05 07:58:24 0 d-------- C:\WINDOWS\Sun
2008-05-05 07:58:24 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Sun
2008-05-05 03:35:36 0 dr-h----- C:\Documents and Settings\Compaq_Administrator\Recent
2008-05-05 03:35:25 0 dr-hs---- C:\cmdcons
2008-05-05 03:35:22 0 d-------- C:\WINDOWS\setup.pss
2008-05-05 03:30:37 0 dr------- C:\Documents and Settings\Compaq_Administrator\Favorites
2008-05-05 03:30:37 0 d-------- C:\Documents and Settings\Compaq_Administrator\Desktop
2008-05-05 03:30:37 0 d--hs---- C:\Documents and Settings\Compaq_Administrator\Cookies
2008-05-05 03:30:37 0 dr-h----- C:\Documents and Settings\Compaq_Administrator\Application Data
2008-05-05 03:30:37 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Real
2008-05-05 03:30:37 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Intuit
2008-05-05 03:30:37 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Identities
2008-05-05 03:30:36 0 d-------- C:\Documents and Settings\Compaq_Administrator\WINDOWS
2008-05-05 03:30:36 0 d--h----- C:\Documents and Settings\Compaq_Administrator\Templates
2008-05-05 03:30:36 0 dr------- C:\Documents and Settings\Compaq_Administrator\Start Menu
2008-05-05 03:30:36 0 dr-h----- C:\Documents and Settings\Compaq_Administrator\SendTo
2008-05-05 03:30:36 0 d--h----- C:\Documents and Settings\Compaq_Administrator\PrintHood
2008-05-05 03:30:36 1572864 --ah----- C:\Documents and Settings\Compaq_Administrator\NTUSER.DAT
2008-05-05 03:30:36 0 d--h----- C:\Documents and Settings\Compaq_Administrator\NetHood
2008-05-05 03:30:36 0 dr------- C:\Documents and Settings\Compaq_Administrator\My Documents
2008-05-05 03:30:36 0 d--h----- C:\Documents and Settings\Compaq_Administrator\Local Settings
2008-05-05 03:29:47 262144 --a------ C:\Documents and Settings\All Users\NTUSER.DAT
2008-05-05 03:29:03 0 d-------- C:\Documents and Settings\Default User\WINDOWS
2008-05-05 03:29:03 0 d-------- C:\Documents and Settings\Default User\Application Data\Real
2008-05-05 03:29:03 0 d-------- C:\Documents and Settings\Default User\Application Data\Intuit
2008-05-05 03:27:49 0 d-------- C:\WINDOWS\Prefetch
2008-05-05 03:24:57 0 d--hs---- C:\System Volume Information
2008-05-05 03:23:30 246 --a------ C:\WINDOWS\system\hpsysdrv.dat
2008-05-05 03:13:16 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-05-05 03:13:16 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-05 03:13:16 0 d--h----- C:\Documents and Settings\Default User\Local Settings
2008-05-05 03:13:16 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-05-05 03:13:15 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-05-05 03:12:00 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-05 03:11:46 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-05 03:11:46 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-05 03:11:46 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-05 03:11:45 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-05-05 03:11:43 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-05-05 03:11:43 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-05 03:09:54 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-05 03:07:05 0 dr-hs---- C:\WINDOWS\system32\dllcache
2008-05-05 01:45:17 0 d-------- C:\Program Files\AWS
2008-05-05 01:45:17 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\WeatherBug
2008-05-05 01:40:50 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Symantec
2008-05-05 01:15:46 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-05-05 01:14:17 0 d-------- C:\WINDOWS\ShellNew
2008-05-05 01:09:56 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\HP
2008-05-05 01:08:26 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-05-05 00:52:27 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Adobe
2008-05-05 00:52:22 1160 --a------ C:\WINDOWS\mozver.dat
2008-05-05 00:45:55 1395 -----n--- C:\WINDOWS\hpfmdl05.dat
2008-05-05 00:45:55 78994 --a------ C:\WINDOWS\hpfins05.dat
2008-05-05 00:41:17 0 d-------- C:\my pictures
2008-05-05 00:40:10 0 d-------- C:\work_stuff
2008-05-05 00:38:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-05 00:38:11 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla
2008-05-05 00:36:30 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-05 00:36:25 0 d-------- C:\Documents and Settings\Compaq_Administrator\Application Data\Macromedia
-- Find3M Report ---------------------------------------------------------------
2008-05-13 19:05:30 0 d-------- C:\Program Files\HP
2008-05-13 19:05:24 0 d-------- C:\Program Files\Hewlett-Packard
2008-05-13 18:59:28 327890 --a------ C:\Documents and Settings\Compaq_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
2008-05-05 23:21:32 0 d-------- C:\Program Files\Common Files
2008-05-05 23:20:28 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-05 23:20:25 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-05 18:43:05 0 d-------- C:\Program Files\Java
2008-05-05 18:17:37 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-19 05:47:00 1845248 --a------ C:\WINDOWS\system32\win32k.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [09/30/2005 12:01 AM]
"ftutil2"="ftutil2.dll" [06/07/2004 05:05 PM C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [06/13/2006 11:05 PM C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [08/03/2005 02:19 AM C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/09/2006 06:50 PM]
"nwiz"="nwiz.exe" [05/09/2006 06:50 PM C:\WINDOWS\system32\nwiz.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [07/23/2005 01:14 AM]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [02/16/2006 01:34 AM]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [04/10/2008 12:06 AM]
"dvHighMem"="C:\WINDOWS\cfgmng32.exe" [11/14/2007 12:34 PM]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [03/11/2008 01:46 AM]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [05/05/2008 11:21 PM]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 07:20 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 07:24 PM]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [08/29/2007 10:55 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 04:03 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe [8/1/2006 5:14:47 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5/11/2005 11:23:26 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 1:01:04 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\LinkAdvisor\CIDLinkAdvisor.dll [10/15/2007 09:40 PM 1373624]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
-- End of Deckard's System Scanner: finished at 2008-05-18 13:00:46 ------------