Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-27 20:55:49
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:57 PM, on 5/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Steam\Steam.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: {43c434df-85fc-5d4b-2ea4-17e23793c3e7} - {7e3c3973-2e71-4ae2-b4d5-cf58fd434c34} - C:\WINDOWS\system32\oguelbcv.dll
O2 - BHO: (no name) - {DBE9DC0E-0F1B-4AB0-B484-E77FAAF2FA5B} - C:\WINDOWS\system32\urqOFvtt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [bc68bcd3] rundll32.exe "C:\WINDOWS\system32\pddvgkns.dll",b
O4 - HKLM\..\Run: [BMbf5b8f4f] Rundll32.exe "C:\WINDOWS\system32\ffrejwte.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.co.../sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1205359119676
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.co.../sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
--
End of file - 8845 bytes
-- Files created between 2008-04-27 and 2008-05-27 -----------------------------
2008-05-27 20:49:54 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-05-27 20:49:48 0 d-------- C:\Program Files\Uniblue
2008-05-27 20:42:10 0 d-------- C:\!Submit
2008-05-27 20:06:58 0 d-------- C:\WINDOWS\system32\appmgmt
2008-05-27 19:46:46 133632 --a------ C:\WINDOWS\system32\oguelbcv.dll
2008-05-27 19:42:26 116224 --a------ C:\WINDOWS\system32\pddvgkns.dll
2008-05-27 19:40:55 126976 --a------ C:\WINDOWS\system32\ffrejwte.dll
2008-05-27 19:40:16 823007 --ahs---- C:\WINDOWS\system32\ttvFOqru.ini2
2008-05-27 19:40:11 370688 -----n--- C:\WINDOWS\system32\urqOFvtt.dll
2008-05-27 19:26:06 0 d-------- C:\VundoFix Backups
2008-05-27 19:19:51 0 d-------- C:\Program Files\Trend Micro
2008-05-27 17:12:21 0 d--h----- C:\Documents and Settings\Administrator.ME\Templates
2008-05-27 17:12:21 0 dr------- C:\Documents and Settings\Administrator.ME\Start Menu
2008-05-27 17:12:21 0 dr-h----- C:\Documents and Settings\Administrator.ME\SendTo
2008-05-27 17:12:21 0 d--h----- C:\Documents and Settings\Administrator.ME\Recent
2008-05-27 17:12:21 0 d--h----- C:\Documents and Settings\Administrator.ME\PrintHood
2008-05-27 17:12:21 0 d--h----- C:\Documents and Settings\Administrator.ME\NetHood
2008-05-27 17:12:21 0 d-------- C:\Documents and Settings\Administrator.ME\My Documents
2008-05-27 17:12:21 0 d--h----- C:\Documents and Settings\Administrator.ME\Local Settings
2008-05-27 17:12:21 0 d-------- C:\Documents and Settings\Administrator.ME\Favorites
2008-05-27 17:12:21 0 d-------- C:\Documents and Settings\Administrator.ME\Desktop
2008-05-27 17:12:21 0 d--hs---- C:\Documents and Settings\Administrator.ME\Cookies
2008-05-27 17:12:21 0 dr-h----- C:\Documents and Settings\Administrator.ME\Application Data
2008-05-27 17:12:21 0 d---s---- C:\Documents and Settings\Administrator.ME\Application Data\Microsoft
2008-05-27 17:12:20 1835008 --ah----- C:\Documents and Settings\Administrator.ME\NTUSER.DAT
2008-05-27 17:06:13 0 d-------- C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-05-27 16:36:21 821285 --ahs---- C:\WINDOWS\system32\XGfNVvut.ini2
2008-05-27 16:36:04 0 d-------- C:\WINDOWS\system32\NtmsData
2008-05-26 22:53:18 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-26 22:53:18 0 d-------- C:\Documents and Settings\Administrator\Cookies
2008-05-26 22:53:18 0 d-------- C:\Documents and Settings\Administrator\Application Data
2008-05-26 22:53:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-05-26 22:53:17 0 d-------- C:\Documents and Settings\Administrator\Templates
2008-05-26 22:53:17 2359296 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-05-26 22:53:17 0 d-------- C:\Documents and Settings\Administrator\Local Settings
2008-05-26 22:51:18 0 d-------- C:\WINDOWS\pss
2008-05-26 20:34:27 116736 --a------ C:\WINDOWS\system32\cuvnbdkj.dll
2008-05-26 20:33:30 822204 --ahs---- C:\WINDOWS\system32\qtELnUvw.ini2
2008-05-26 20:28:52 58368 --a------ C:\WINDOWS\system32\ssqpQHbX.dll
2008-05-26 20:28:48 32 --a------ C:\WINDOWS\go
2008-05-26 19:19:58 0 d-------- C:\Program Files\MSXML 4.0
2008-05-26 04:05:47 0 d-------- C:\Documents and Settings\Owner\Application Data\Atari
2008-05-26 04:04:12 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-05-26 04:03:50 0 d-------- C:\Documents and Settings\Owner\Application Data\Leadertech
2008-05-26 04:03:44 197120 --a------ C:\WINDOWS\patchw32.dll
2008-05-26 04:03:43 0 d-------- C:\Program Files\Common Files\PocketSoft
2008-05-26 03:59:50 0 d-------- C:\Program Files\Atari
2008-05-26 03:56:02 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-05-26 03:51:41 717296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-26 03:51:34 0 d-------- C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-05-26 03:41:12 0 d-------- C:\Program Files\MagicISO
2008-05-26 03:10:24 0 d-------- C:\Program Files\NeroInstall.bak
2008-05-26 03:09:18 0 d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-05-26 03:05:21 0 d-------- C:\Program Files\Nero
2008-05-26 03:05:21 0 d-------- C:\Program Files\Common Files\Nero
2008-05-26 03:05:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-25 23:47:11 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-05-25 23:47:11 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-05-25 23:47:11 76354 --a------ C:\WINDOWS\War3Unin.dat
2008-05-25 23:44:12 0 d-------- C:\Program Files\Warcraft III
2008-05-25 18:16:26 2829 --a------ C:\WINDOWS\W2BNEUnin.pif
2008-05-25 18:16:26 20256 --a------ C:\WINDOWS\W2BNEUnin.dat
2008-05-25 18:16:25 98304 --a------ C:\WINDOWS\W2BNEUnin.exe <Not Verified; Blizzard Entertainment; Warcraft II Battle.net Edition Uninstaller>
2008-05-25 18:15:42 0 d-------- C:\Program Files\Warcraft II BNE
2008-05-25 03:12:20 5702 --ah----- C:\WINDOWS\nod32restoretemdono.reg
2008-05-25 03:09:33 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-05-25 01:15:23 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-25 01:14:05 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-25 00:37:41 0 d-------- C:\Documents and Settings\Owner\Application Data\DivX
2008-05-25 00:36:35 0 d-------- C:\Program Files\DivX
2008-05-24 19:57:49 0 d-------- C:\Program Files\PeerGuardian2
2008-05-24 19:52:53 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-24 19:39:03 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-24 19:39:01 0 d-------- C:\Program Files\fraps
2008-05-24 19:34:44 0 d-------- C:\Program Files\Lavasoft
2008-05-24 19:34:43 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-24 17:40:32 0 d-------- C:\WINDOWS\Sun
2008-05-24 17:40:32 0 d-------- C:\Documents and Settings\Owner\Application Data\Sun
2008-05-24 17:39:28 0 d-------- C:\Program Files\Java
2008-05-24 17:37:02 0 d-------- C:\Program Files\Common Files\Java
2008-05-21 19:11:08 2560 --a------ C:\WINDOWS\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-05-21 19:11:07 0 d-------- C:\Downloads
2008-05-21 19:10:33 0 d-------- C:\Program Files\BitComet
2008-05-19 22:46:41 0 d-------- C:\Documents and Settings\Owner\Application Data\Hamachi
2008-05-19 22:46:20 0 d-------- C:\Program Files\Hamachi
2008-05-19 19:59:56 17801 --a------ C:\WINDOWS\system32\drivers\AegisP.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
2008-05-19 19:59:51 0 d-------- C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster
2008-05-17 23:48:43 0 d-------- C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-05-17 23:48:30 0 d-------- C:\Program Files\iPod
2008-05-17 23:48:26 0 d-------- C:\Program Files\iTunes
2008-05-17 23:48:12 0 d-------- C:\Program Files\Bonjour
2008-05-17 23:47:30 0 d-------- C:\Program Files\QuickTime
2008-05-17 23:47:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-17 23:47:11 0 d-------- C:\Program Files\Apple Software Update
2008-05-17 23:47:05 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-17 23:46:31 0 d-------- C:\Program Files\Common Files\Apple
2008-05-17 23:46:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-16 19:06:41 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-16 18:19:45 0 d-------- C:\Program Files\PartyGaming
2008-05-16 03:15:52 0 d-------- C:\WINDOWS\nvidia icons
2008-05-16 03:15:45 0 d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
2008-05-16 03:15:40 0 d-------- C:\WINDOWS\NV38043620.TMP
2008-05-16 03:14:11 0 d-------- C:\NVIDIA
2008-05-16 01:25:19 0 d-------- C:\Program Files\SystemRequirementsLab
2008-05-16 00:52:20 0 d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-05-16 00:49:57 0 d-------- C:\Documents and Settings\Owner\Application Data\Command & Conquer 3 Kane's Wrath
2008-05-15 22:11:13 0 d-------- C:\WINDOWS\nview
2008-05-15 20:50:23 0 d-------- C:\Documents and Settings\Owner\Application Data\Command & Conquer 3 Tiberium Wars
2008-05-15 20:41:08 0 d-------- C:\Program Files\Electronic Arts
2008-05-15 19:28:26 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2008-05-15 19:27:08 0 d-------- C:\Documents and Settings\Owner\Application Data\Xfire
2008-05-15 19:27:05 0 d-------- C:\Program Files\Xfire
2008-05-15 02:19:55 1160 --a------ C:\WINDOWS\mozver.dat
2008-05-15 02:16:41 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-15 02:16:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-05-12 22:07:17 0 d-------- C:\Documents and Settings\Owner\Application Data\Ventrilo
2008-05-12 22:07:04 0 d-------- C:\Program Files\Ventrilo
2008-05-12 22:06:42 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-12 18:53:16 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-05-12 18:50:16 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-05-12 18:50:16 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-05-12 18:50:08 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-05-12 18:50:08 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 18:50:08 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-05-12 18:50:08 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 18:50:06 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 18:49:39 0 d-------- C:\Documents and Settings\Owner\Application Data\Aim
2008-05-12 18:49:34 0 d-------- C:\Program Files\Viewpoint
2008-05-12 18:49:34 0 d-------- C:\Program Files\AOD
2008-05-12 18:49:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-12 18:49:31 0 d-------- C:\Program Files\AIM
2008-05-12 18:49:02 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-12 18:43:19 0 d-------- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-05-12 18:43:14 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2008-05-12 18:35:34 0 d-------- C:\Documents and Settings\Owner\Application Data\WinRAR
2008-05-12 16:48:51 0 d-------- C:\Documents and Settings\Owner\Application Data\Ahead
2008-05-12 16:48:22 0 d-------- C:\Logs
2008-05-12 14:10:35 0 d-------- C:\Program Files\Steam
2008-05-12 11:49:48 94208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-05-12 11:49:48 15872 --a------ C:\WINDOWS\system32\GTNDIS5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2008-05-11 23:43:08 967 --a------ C:\WINDOWS\ScUnin.pif
2008-05-11 23:43:08 94208 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2008-05-11 23:43:08 35190 --a------ C:\WINDOWS\scunin.dat
2008-05-11 23:42:06 0 d-------- C:\Program Files\Starcraft
2008-05-10 21:34:43 292 --a------ C:\WINDOWS\PowerReg.dat
2008-05-10 21:34:40 45568 --a------ C:\WINDOWS\UniFish3.exe
2008-05-10 19:50:30 0 d-------- C:\Program Files\3DO
2008-05-10 19:49:50 0 d-------- C:\Program Files\directx
2008-05-10 19:49:32 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-05-10 18:09:42 0 d-------- C:\Westwood
2008-05-10 17:43:56 0 dr-h----- C:\Documents and Settings\Owner\Application Data\SecuROM
2008-05-10 17:32:52 0 d-------- C:\Program Files\Flagship Studios
2008-05-10 17:31:29 0 d--hs---- C:\WINDOWS\Installer
2008-05-10 14:50:13 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-05-10 14:50:09 0 d-------- C:\Program Files\World of Warcraft
2008-05-01 11:06:16 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-05-01 11:02:58 0 d-------- C:\WINDOWS\WinSxS
2008-05-01 11:02:57 0 dr------- C:\WINDOWS\Web
2008-05-01 11:02:57 0 d-------- C:\WINDOWS\twain_32
2008-05-01 11:02:56 0 d---s---- C:\WINDOWS\Tasks
2008-05-01 11:02:55 0 d-------- C:\WINDOWS\system32\xircom
2008-05-01 11:02:52 0 d-------- C:\WINDOWS\system32\wins
2008-05-01 11:02:43 0 d-------- C:\WINDOWS\system32\wbem
2008-05-01 11:02:41 0 d-------- C:\WINDOWS\system32\usmt
2008-05-01 11:02:38 0 d-------- C:\WINDOWS\system32\spool
2008-05-01 11:02:37 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-01 11:02:36 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-01 11:02:34 0 d-------- C:\WINDOWS\system32\Setup
2008-05-01 11:02:33 0 d-------- C:\WINDOWS\system32\Restore
2008-05-01 11:02:32 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-01 11:02:31 0 d-------- C:\WINDOWS\system32\ras
2008-05-01 11:02:30 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-01 11:02:27 0 d-------- C:\WINDOWS\system32\oobe
2008-05-01 11:02:24 0 d-------- C:\WINDOWS\system32\npp
2008-05-01 11:02:19 0 d-------- C:\WINDOWS\system32\mui
2008-05-01 11:02:13 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-01 11:02:10 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-01 11:02:09 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-01 11:02:05 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-01 11:02:05 0 d-------- C:\WINDOWS\system32\IME
2008-05-01 11:02:02 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-01 11:02:02 0 d-------- C:\WINDOWS\system32\ias
2008-05-01 11:02:00 0 d-------- C:\WINDOWS\system32\export
2008-05-01 11:01:54 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-01 11:01:54 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-01 11:01:53 0 d-------- C:\WINDOWS\system32\drivers
2008-05-01 11:00:52 0 dr-hs---- C:\WINDOWS\system32\dllcache
2008-05-01 11:00:51 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-01 11:00:50 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-01 11:00:44 0 d-------- C:\WINDOWS\system32\config
2008-05-01 11:00:44 0 d-------- C:\WINDOWS\system32\Com
2008-05-01 11:00:41 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-01 11:00:38 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\3076
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\2052
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1054
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1042
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1041
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1037
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1033
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1031
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1028
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system32\1025
2008-05-01 11:00:36 0 d-------- C:\WINDOWS\system
2008-05-01 11:00:35 0 d-------- C:\WINDOWS\srchasst
2008-05-01 11:00:21 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-01 11:00:20 0 d-------- C:\WINDOWS\security
2008-05-01 11:00:18 0 d-------- C:\WINDOWS\Resources
2008-05-01 11:00:18 0 d-------- C:\WINDOWS\repair
2008-05-01 11:00:18 0 d-------- C:\WINDOWS\Registration
2008-05-01 11:00:18 0 d-------- C:\WINDOWS\Provisioning
2008-05-01 11:00:15 0 d-------- C:\WINDOWS\Prefetch
2008-05-01 11:00:15 0 d-------- C:\WINDOWS\PeerNet
2008-05-01 11:00:02 0 d-------- C:\WINDOWS\pchealth
2008-05-01 11:00:02 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-01 11:00:01 0 d-------- C:\WINDOWS\network diagnostic
2008-05-01 11:00:01 0 d-------- C:\WINDOWS\mui
2008-05-01 11:00:00 0 d-------- C:\WINDOWS\msapps
2008-05-01 11:00:00 0 d-------- C:\WINDOWS\msagent
2008-05-01 10:59:59 0 d-------- C:\WINDOWS\Media
2008-05-01 10:59:54 0 d-------- C:\WINDOWS\java
2008-05-01 10:59:30 0 d--h----- C:\WINDOWS\inf
2008-05-01 10:59:30 0 d-------- C:\WINDOWS\ime
2008-05-01 10:59:06 0 d-------- C:\WINDOWS\Help
2008-05-01 10:59:02 0 dr--s---- C:\WINDOWS\Fonts
2008-05-01 10:59:01 0 d-------- C:\WINDOWS\ehome
2008-05-01 10:58:54 0 d-------- C:\WINDOWS\Driver Cache
2008-05-01 10:58:54 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-01 10:58:53 0 d-------- C:\WINDOWS\Debug
2008-05-01 10:58:52 0 d-------- C:\WINDOWS\Cursors
2008-05-01 10:58:52 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-01 10:58:52 0 d-------- C:\WINDOWS\Config
2008-05-01 10:58:51 0 d-------- C:\WINDOWS\AppPatch
2008-05-01 10:58:51 0 d-------- C:\WINDOWS\addins
2008-05-01 10:57:47 0 d-------- C:\WINDOWS
2008-05-01 10:57:47 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-01 10:57:43 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-01 10:57:42 0 d-------- C:\Program Files\Windows NT
2008-05-01 10:57:36 0 d-------- C:\Program Files\Seagate
2008-05-01 10:57:36 0 d-------- C:\Program Files\Online Services
2008-05-01 10:57:34 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-01 10:57:31 0 d-------- C:\Program Files\Movie Maker
2008-05-01 10:57:31 0 d-------- C:\Program Files\microsoft frontpage
2008-05-01 10:57:31 0 d-------- C:\Program Files\Messenger
2008-05-01 10:57:29 0 d-------- C:\Program Files\Intel
2008-05-01 10:57:28 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-01 10:57:27 0 d-------- C:\Program Files\Google
2008-05-01 10:57:25 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-01 10:57:08 0 d-------- C:\Program Files\Common Files\Seagate
2008-05-01 10:57:08 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-01 10:57:08 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-01 10:57:06 0 d-------- C:\Program Files\Common Files\LightScribe
2008-05-01 10:57:05 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-01 10:57:02 0 d-------- C:\Program Files\Common Files\Ahead
2008-05-01 10:56:57 0 d-------- C:\Program Files\Common Files
2008-05-01 10:56:57 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-01 10:56:56 0 d-------- C:\Program Files\Analog Devices
2008-05-01 10:56:40 0 d-------- C:\Program Files\Ahead
2008-05-01 10:56:21 0 dr------- C:\Program Files
2008-05-01 10:56:21 0 d-------- C:\Intel
2008-05-01 10:56:11 0 d-------- C:\IBMTOOLS
2008-05-01 10:56:11 0 d--hs---- C:\Documents and Settings\Owner\UserData
2008-05-01 10:56:11 0 d--h----- C:\Documents and Settings\Owner\Templates
2008-05-01 10:56:11 0 dr------- C:\Documents and Settings\Owner\Start Menu
2008-05-01 10:56:11 0 dr-h----- C:\Documents and Settings\Owner\SendTo
2008-05-01 10:56:11 0 d--h----- C:\Documents and Settings\Owner\PrintHood
2008-05-01 10:56:10 6287360 --a------ C:\Documents and Settings\Owner\NTUSER.DAT
2008-05-01 10:56:10 0 d--h----- C:\Documents and Settings\Owner\NetHood
2008-05-01 10:56:10 0 dr------- C:\Documents and Settings\Owner\My Documents
2008-05-01 10:56:03 0 d--h----- C:\Documents and Settings\Owner\Local Settings
2008-05-01 10:56:03 0 dr------- C:\Documents and Settings\Owner\Favorites
2008-05-01 10:55:01 0 d-------- C:\Documents and Settings\Owner\Desktop
2008-05-01 10:55:01 0 d--hs---- C:\Documents and Settings\Owner\Cookies
2008-05-01 10:55:01 0 dr-h----- C:\Documents and Settings\Owner\Application Data
2008-05-01 10:55:01 0 d-------- C:\Documents and Settings\Owner\Application Data\Identities
2008-05-01 10:55:00 1441792 --a------ C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-05-01 10:55:00 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-05-01 10:55:00 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-05-01 10:55:00 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-05-01 10:55:00 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-05-01 10:55:00 1445888 --a------ C:\Documents and Settings\LocalService\NTUSER.DAT
2008-05-01 10:54:59 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-05-01 10:54:59 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-05-01 10:54:59 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-05-01 10:54:59 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-05-01 10:54:59 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-05-01 10:54:59 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-05-01 10:54:59 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-01 10:54:59 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-05-01 10:54:59 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-05-01 10:54:58 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-05-01 10:54:58 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-05-01 10:54:58 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-05-01 10:54:58 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-05-01 10:54:58 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-05-01 10:54:58 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-05-01 10:54:58 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-05-01 10:54:58 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-05-01 10:54:58 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-05-01 10:54:57 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-05-01 10:54:57 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-05-01 10:54:56 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-05-01 10:54:55 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-01 10:54:55 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-05-01 10:54:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-01 10:54:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-01 10:54:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Seagate
2008-05-01 10:54:54 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-05-01 10:54:53 0 d-------- C:\Documents and Settings
2008-05-01 10:54:53 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-05-01 10:54:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-05-01 10:54:53 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-01 10:54:32 0 d--hs---- C:\System Volume Information
-- Find3M Report ---------------------------------------------------------------
2008-05-02 22:46:00 1630208 --a------ C:\WINDOWS\system32\nwiz.exe
2008-05-02 22:46:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-05-02 22:46:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-05-02 22:46:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-05-02 22:46:00 1486848 --a------ C:\WINDOWS\system32\nview.dll
2008-05-02 22:46:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-05-02 22:46:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-05-02 22:46:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
2008-03-12 12:30:45 0 -rahs---- C:\MSDOS.SYS
2008-03-12 12:30:45 0 -rahs---- C:\IO.SYS
2008-03-12 12:30:45 0 --a------ C:\CONFIG.SYS
2008-03-12 12:30:45 0 --a------ C:\AUTOEXEC.BAT
2008-03-12 12:26:01 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-12 05:12:49 62 --ahs---- C:\Documents and Settings\Owner\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7e3c3973-2e71-4ae2-b4d5-cf58fd434c34}]
05/27/2008 07:46 PM 133632 --a------ C:\WINDOWS\system32\oguelbcv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DBE9DC0E-0F1B-4AB0-B484-E77FAAF2FA5B}]
05/27/2008 07:40 PM 370688 --------- C:\WINDOWS\system32\urqOFvtt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [04/05/2005 02:22 PM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [04/05/2005 02:19 PM]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [04/05/2005 02:23 PM]
"Adobe Reader Speed Laun9:04 PM 5/27/20089:04 PM 5/27/2008C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [04/19/2007 09:24 PM]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [04/19/2007 09:38 PM]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [04/19/2007 09:29 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [05/02/2008 10:46 PM]
"nwiz"="nwiz.exe" [05/02/2008 10:46 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [05/02/2008 10:46 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [02/28/2008 09:59 AM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [02/18/2008 04:29 PM]
"bc68bcd3"="C:\WINDOWS\system32\pddvgkns.dll" [05/27/2008 07:42 PM]
"BMbf5b8f4f"="C:\WINDOWS\system32\ffrejwte.dll" [05/27/2008 07:40 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [02/28/2008 05:07 PM]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [04/01/2008 02:39 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Spybot - Search & Destroy"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap C:\WINDOWS\system32\urqOFvtt
-- End of Deckard's System Scanner: finished at 2008-05-27 20:56:45 ------------