Also, I ran DDS and here are the results of main.txt :
Deckard's System Scanner v20071014.68
Run by Mindy on 2008-05-27 01:23:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
5: 2008-05-27 05:23:38 UTC - RP5 - Deckard's System Scanner Restore Point
4: 2008-05-25 22:12:45 UTC - RP4 - Installed Adobe Reader 7.1.0
3: 2008-05-25 07:00:40 UTC - RP3 - Software Distribution Service 3.0
2: 2008-05-22 15:38:15 UTC - RP2 - System Checkpoint
1: 2008-05-17 03:29:37 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Mindy.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:56 AM, on 5/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Mindy\Desktop\DeckardsSystemScanner.exe
C:\PROGRA~1\HIJACK~1\Mindy.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://quote.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail....es/MSNPUpld.cabO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O24 - Desktop Component 0: (no name) - (no file)
--
End of file - 5567 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\HIJACK~1\backups\) --------------------
backup-20080512-220410-684 O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) -
http://dlm.tools.aka...vex-2.2.2.1.cabbackup-20080514-023742-177 O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} (20-20 Technologies 3D Room Planner) -
http://bestbuy.mvm.c...yerAX_Win32.cabbackup-20080514-023742-392 O4 - HKLM\..\Run: [BM978c092d] Rundll32.exe "C:\WINDOWS\system32\grfsdkwp.dll",s
backup-20080514-023742-612 O4 - HKLM\..\Run: [94bf3ab1] rundll32.exe "C:\WINDOWS\system32\mqcywjyv.dll",b
backup-20080514-023742-695 O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu72.exe 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9
B1894E754BE54C29159A7DBE80DC744B6CDE3F546CAC59B6
backup-20080514-023743-660 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080514-023852-804 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080514-024025-968 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080516-210719-556 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
backup-20080516-235211-292 O24 - Desktop Component 0: (no name) - (no file)
backup-20080516-235211-512 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080516-235211-595 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080516-235245-679 O24 - Desktop Component 0: (no name) - (no file)
backup-20080516-235245-857 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080517-001009-105 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080517-001010-758 O24 - Desktop Component 0: (no name) - (no file)
backup-20080517-192502-205 O24 - Desktop Component 0: (no name) - (no file)
backup-20080517-192502-226 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080517-192502-425 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080518-215408-214 O24 - Desktop Component 0: (no name) - (no file)
backup-20080518-215408-434 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080518-215408-454 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080522-002112-147 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080522-002112-599 O24 - Desktop Component 0: (no name) - (no file)
backup-20080522-002205-375 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080522-002205-771 O24 - Desktop Component 0: (no name) - (no file)
backup-20080524-235821-105 O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
backup-20080524-235821-135 O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
backup-20080524-235821-223 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080524-235821-268 O2 - BHO: (no name) - {9BD91E8B-54A2-49C4-8663-78441FA3D5D7} - (no file)
backup-20080524-235821-289 O2 - BHO: (no name) - {8E765AA0-AD0D-43F9-94C2-4436BCEE9135} - C:\WINDOWS\system32\tuvSMCsR.dll (file missing)
backup-20080524-235821-328 O2 - BHO: (no name) - {7C5E650A-A8BE-4905-9577-678019D84836} - C:\WINDOWS\system32\hgGvssPJ.dll (file missing)
backup-20080524-235821-335 O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
backup-20080524-235821-343 O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
backup-20080524-235821-409 O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
backup-20080524-235821-490 O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
backup-20080524-235821-607 O2 - BHO: (no name) - {C100CAFF-F206-4E48-BE7A-3E6759C87B69} - C:\WINDOWS\system32\awtsPJCS.dll (file missing)
backup-20080524-235821-608 O2 - BHO: (no name) - {EA56FF57-D7D2-4381-938E-8CC5688E77AB} - C:\WINDOWS\system32\iifeeEVp.dll (file missing)
backup-20080524-235821-637 O2 - BHO: (no name) - {351714C1-2644-4294-AEC1-C1335759AB18} - (no file)
backup-20080524-235821-644 O20 - Winlogon Notify: xxyvuusR - xxyvuusR.dll (file missing)
backup-20080524-235821-669 O2 - BHO: (no name) - {3B9911E6-004F-44B6-8876-41C55327FBA4} - C:\WINDOWS\system32\khfDsrsS.dll (file missing)
backup-20080524-235821-773 O2 - BHO: (no name) - {8CA25AAA-0C23-405B-8659-EC2CA1E9F6BB} - (no file)
backup-20080524-235821-785 O4 - HKLM\..\Run: [94bf3ab1] rundll32.exe "C:\WINDOWS\system32\gnyqyqla.dll",b
backup-20080524-235821-819 O2 - BHO: (no name) - {8446934C-C4E8-41C7-8A8A-8018598B90FC} - C:\WINDOWS\system32\geBuuuVl.dll (file missing)
backup-20080524-235821-843 O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
backup-20080524-235821-846 O2 - BHO: (no name) - {396F834C-7B1D-41C0-BB9A-23C2871EDCC9} - C:\WINDOWS\system32\nnnoMcbA.dll (file missing)
backup-20080524-235821-857 O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
backup-20080524-235821-877 O2 - BHO: (no name) - {E6581958-B13F-4B3A-AA7F-6000A3411C5F} - C:\WINDOWS\system32\urqNDTLb.dll (file missing)
backup-20080524-235821-894 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080524-235821-932 O24 - Desktop Component 0: (no name) - (no file)
backup-20080524-235821-933 O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
backup-20080524-235821-936 O2 - BHO: (no name) - {3FF5C030-F851-4C96-AB5F-DC12F0F15043} - C:\WINDOWS\system32\hgGywTLc.dll (file missing)
backup-20080524-235821-997 O2 - BHO: (no name) - {B3102264-D09D-4322-B625-503FBF18DD7E} - C:\WINDOWS\system32\xxyvuusR.dll (file missing)
backup-20080525-000002-142 O4 - HKLM\..\Run: [BM978c092d] Rundll32.exe "C:\WINDOWS\system32\sfpsblkg.dll",s
backup-20080525-000002-204 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080525-000002-488 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-011735-771 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-011735-992 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe
backup-20080525-024049-229 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe (file missing)
backup-20080525-024049-404 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-024049-610 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080525-024232-411 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-024232-589 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe (file missing)
backup-20080525-031009-217 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe (file missing)
backup-20080525-031009-381 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-184239-214 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-184239-570 O4 - HKLM\..\Run: [{75b4086e-464b-7af1-2a25-41ea92e3d567}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
backup-20080525-184239-748 O2 - BHO: gooochi browser optimizer - {e9e9f2b9-b2bd-6c20-9bc5-482bce81f5e3} - C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll
backup-20080525-184239-819 O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\winself.exe (file missing)
backup-20080525-191315-950 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-193223-480 O2 - BHO: {7a901220-111b-2768-7bd4-ad76f1039918} - {8199301f-67da-4db7-8672-b111022109a7} - C:\WINDOWS\system32\itsaqopw.dll (file missing)
backup-20080525-193408-574 O24 - Desktop Component 0: (no name) - (no file)
backup-20080525-195221-382 O24 - Desktop Component 0: (no name) - (no file)
backup-20080527-001728-303 O24 - Desktop Component 0: (no name) - (no file)
backup-20080527-003416-842 O24 - Desktop Component 0: (no name) - (no file)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys <Not Verified; VERITAS Software, Inc.; >
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys <Not Verified; VERITAS Software, Inc.; >
R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys <Not Verified; VERITAS Software, Inc.; >
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.1.0.1) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.1.0.1>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys <Not Verified; VERITAS Software, Inc.; >
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsndres - c:\windows\system32\dla\tfsndres.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys <Not Verified; VERITAS Software, Inc.; >
R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys <Not Verified; VERITAS Software, Inc.; >
R3 catchme - c:\docume~1\mindy\locals~1\temp\catchme.sys (file missing)
S3 grmnusb - c:\windows\system32\drivers\grmnusb.sys <Not Verified; GARMIN Corp.; Garmin USB GPS>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 RegSrvc - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; RegSrvc Module>
R2 WLANKEEPER - c:\program files\intel\wireless\bin\wlkeeper.exe <Not Verified; Intel® Corporation; SSOFSet Service>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-04-27 and 2008-05-27 -----------------------------
2008-05-27 00:54:47 0 d-------- C:\WINDOWS\ERUNT
2008-05-25 23:48:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-25 23:07:48 0 d-------- C:\Program Files\Spybot
2008-05-25 18:13:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-24 16:18:14 2624 --a------ C:\WINDOWS\system32\dgxrrmpe.exe
2008-05-24 15:59:30 0 d-------- C:\Documents and Settings\Mindy\Application Data\Desktopicon
2008-05-24 00:02:16 2624 --a------ C:\WINDOWS\system32\qktnsxxt.exe
2008-05-23 22:13:54 2624 --a------ C:\WINDOWS\system32\naviussx.exe
2008-05-23 20:24:41 2624 --a------ C:\WINDOWS\system32\ksaphepn.exe
2008-05-23 19:20:06 2624 --a------ C:\WINDOWS\system32\dlmtyuks.exe
2008-05-22 23:16:58 2624 --a------ C:\WINDOWS\system32\pufxxldr.exe
2008-05-21 23:26:32 2624 --a------ C:\WINDOWS\system32\jveqmrff.exe
2008-05-21 22:33:46 2624 --a------ C:\WINDOWS\system32\pshktmtw.exe
2008-05-21 17:18:39 0 d-------- C:\VundoFix
2008-05-20 23:01:47 2624 --a------ C:\WINDOWS\system32\fbvdgawd.exe
2008-05-19 20:53:57 2624 --a------ C:\WINDOWS\system32\vbdmeqro.exe
2008-05-19 16:43:23 0 d-------- C:\SIC_TrendMicroDiagnostic
2008-05-18 20:49:47 2112 --a------ C:\WINDOWS\system32\sqtxgnch.exe
2008-05-18 20:48:58 3648 --a------ C:\WINDOWS\system32\mgfcsjsg.dll
2008-05-17 20:36:51 2112 --a------ C:\WINDOWS\system32\huqvdthg.exe
2008-05-17 20:27:51 3648 --a------ C:\WINDOWS\system32\xxjpranf.dll
2008-05-16 20:31:20 2112 --a------ C:\WINDOWS\system32\hntkvvma.exe
2008-05-16 20:25:20 3648 --a------ C:\WINDOWS\system32\uoshguxy.dll
2008-05-14 22:29:55 2112 --a------ C:\WINDOWS\system32\yywfaqjr.exe
2008-05-14 22:23:59 3648 --a------ C:\WINDOWS\system32\gjfidxuh.dll
2008-05-13 18:39:09 2112 --a------ C:\WINDOWS\system32\jausoatn.exe
2008-05-13 07:38:36 3648 --a------ C:\WINDOWS\system32\flkfpptt.dll
2008-05-12 22:11:50 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-12 07:38:07 2112 --a------ C:\WINDOWS\system32\mkxqfkvd.exe
2008-05-11 01:05:34 0 d-------- C:\Documents and Settings\Mindy\.housecall6.6
2008-05-10 00:13:52 2112 --a------ C:\WINDOWS\system32\pshjrhxb.exe
2008-05-09 00:05:58 2112 --a------ C:\WINDOWS\system32\facrkghr.exe
2008-05-08 00:50:27 2048 --a------ C:\WINDOWS\system32\vilwrdpb.exe
2008-05-08 00:45:16 105984 --a------ C:\WINDOWS\system32\fsmfvnfp.dll
2008-05-08 00:44:22 1040561 --ahs---- C:\WINDOWS\system32\XwabLRqr.ini2
2008-05-07 00:22:48 2112 --a------ C:\WINDOWS\system32\gfbtgjaa.exe
2008-05-07 00:19:33 417933 --ahs---- C:\WINDOWS\system32\tAHOonmp.ini2
2008-05-06 23:16:26 10752 --a------ C:\WINDOWS\DCEBoot.exe
2008-05-05 12:25:18 329728 --a------ C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll
2008-05-04 05:26:41 416115 --ahs---- C:\WINDOWS\system32\bIiSCJjl.ini2
2008-05-03 22:00:06 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-03 21:59:59 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-05-03 21:59:57 87979 --a------ C:\WINDOWS\lfn.exe <Not Verified; Microsoft; XML Media>
2008-05-02 22:26:02 400023 --a------ C:\Documents and Settings\Mindy\g50.exe
2008-05-01 18:44:50 298306 --a------ C:\Documents and Settings\Mindy\gside.exe
2008-04-28 07:51:15 0 d-------- C:\Documents and Settings\NetworkService\Start Menu
-- Find3M Report ---------------------------------------------------------------
2008-05-26 00:32:14 0 d-------- C:\Program Files\Common Files
2008-05-25 18:13:04 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-25 18:11:41 0 d-------- C:\Documents and Settings\Mindy\Application Data\AdobeUM
2008-05-18 21:50:42 0 d-------- C:\Program Files\Google
2008-05-04 02:06:13 0 d-------- C:\Program Files\WildTangent
2008-05-04 00:02:40 0 d-------- C:\Program Files\Common Files\AOL
2008-05-03 21:51:35 79072 --a------ C:\Documents and Settings\Mindy\Application Data\GDIPFONTCACHEV1.DAT
2008-05-03 20:23:09 17177 --a------ C:\WINDOWS\system32\nvModes.dat
2008-04-05 02:44:09 935 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-03-12 07:58:14 200766 --a------ C:\WINDOWS\system32\kwinnldo.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [12/15/2006 08:51 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/14/2005 01:08 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [04/13/2006 04:20 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/10/2004 06:00 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [4/23/2008 3:38:16 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 09/07/2004 05:08 PM 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\hgGvssPJ
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photags AutoDetect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Photags AutoDetect.lnk
backup=C:\WINDOWS\pss\Photags AutoDetect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mindy^Start Menu^Programs^Startup^Connection Manager.lnk]
path=C:\Documents and Settings\Mindy\Start Menu\Programs\Startup\Connection Manager.lnk
backup=C:\WINDOWS\pss\Connection Manager.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mindy^Start Menu^Programs^Startup^Deewoo.lnk]
path=C:\Documents and Settings\Mindy\Start Menu\Programs\Startup\Deewoo.lnk
backup=C:\WINDOWS\pss\Deewoo.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mindy^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Mindy\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\94bf3ab1]
rundll32.exe "C:\WINDOWS\system32\pcuijhrm.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM978c092d]
Rundll32.exe "C:\WINDOWS\system32\jcoxvaxq.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\kwinnldo.exe CHD003
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\horykyf]
C:\Program Files\Windows Media Player\horykyf22011.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
"C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowLOMControl]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spa_start]
C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uaol]
"C:\PROGRA~1\COMMON~1\ASEMBL~1\fast.exe" -vt yazb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{75b4086e-464b-7af1-2a25-41ea92e3d567}]
C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{11c05ee8-f8f2-19d5-ae81-0b5173b380e0}.dll" DllInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{F3-3A-A1-1E-ZN}]
C:\WINDOWS\system32\kmdsrngj.exe CHD003
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
-- End of Deckard's System Scanner: finished at 2008-05-27 01:25:25 ------------