Here is the main.txt log
Deckard's System Scanner v20071014.68
Run by Matthew on 2008-05-31 07:14:52
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
26: 2008-05-30 00:29:47 UTC - RP50 - Windows Update
25: 2008-05-29 14:13:57 UTC - RP49 - Device Driver Package Install: Microsoft Bluetooth Radios
24: 2008-05-29 14:13:44 UTC - RP48 - Device Driver Package Install: Microsoft Mice and other pointing devices
23: 2008-05-29 01:45:32 UTC - RP47 - Windows Update
22: 2008-05-28 23:57:52 UTC - RP45 - Removed SUPERAntiSpyware Free Edition
-- First Restore Point --
1: 2008-05-22 07:00:34 UTC - RP23 - Windows Update
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Matthew.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:15:23, on 5/31/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\Matthew\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Matthew.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://internetsearc...ce.com/ie6.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://internetsearchservice.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://internetsearchservice.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {34CF6660-9BD3-431A-BA32-6B511D4126DA} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {51D81DD5-55B7-497F-95DB-D356429BB54E} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RestartNeroSetup] "C:\Users\Matthew\AppData\Local\Temp\OnlineUpdate8\SetupXu.exe" MODE="update" STARTMODE="2" USERSEL="3" FAMILYNAME="Nero 8" RUNSETUPXU="1" UPGRADE="1"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB3738] command /c del "C:\Program Files\NetProject\sbmntr.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD983] cmd /c del "C:\Program Files\NetProject\sbmntr.exe_old"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 6338 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080531-070946-186 R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.combackup-20080531-070946-308 O4 - HKCU\..\RunOnce: [SpybotDeletingB3738] command /c del "C:\Program Files\NetProject\sbmntr.exe_old"
backup-20080531-070946-315 O3 - Toolbar: (no name) - {51D81DD5-55B7-497F-95DB-D356429BB54E} - (no file)
backup-20080531-070946-446 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://internetsearchservice.combackup-20080531-070946-617 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://internetsearchservice.combackup-20080531-070946-713 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://internetsearchservice.combackup-20080531-070946-800 O4 - HKCU\..\RunOnce: [SpybotDeletingD983] cmd /c del "C:\Program Files\NetProject\sbmntr.exe_old"
backup-20080531-070946-827 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://internetsearc...ce.com/ie6.htmlbackup-20080531-070946-837 R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://internetsearchservice.combackup-20080531-070946-912 O2 - BHO: (no name) - {34CF6660-9BD3-431A-BA32-6B511D4126DA} - (no file)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
All drivers whitelisted.
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-04-30 and 2008-05-31 -----------------------------
2008-05-30 21:49:51 1409 --a------ C:\Windows\mozver.dat
2008-05-29 10:13:33 0 d-------- C:\Program Files\Microsoft IntelliPoint
2008-05-29 06:56:30 0 d-------- C:\Users\All Users\FLEXnet
2008-05-28 19:01:51 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-05-28 19:00:10 0 d-------- C:\Program Files\Trend Micro
2008-05-28 18:25:36 0 d-------- C:\VundoFix Backups
2008-05-28 18:19:43 2648 --a------ C:\Windows\system32\tmp.reg
2008-05-28 18:16:43 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-05-28 18:16:43 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-05-28 18:16:43 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-05-28 18:16:43 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-05-28 18:16:43 53248 --a------ C:\Windows\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-05-28 18:16:43 82944 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-28 18:16:43 51200 --a------ C:\Windows\system32\dumphive.exe
2008-05-28 18:16:43 82944 --a------ C:\Windows\system32\404Fix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-05-28 09:06:16 0 d--h----- C:\$AVG8.VAULT$
2008-05-28 08:29:07 0 d-------- C:\Windows\system32\drivers\Avg
2008-05-28 08:29:04 0 d-------- C:\Users\All Users\avg8
2008-05-28 08:29:04 0 d-------- C:\Program Files\AVG
2008-05-28 08:20:59 0 d-------- C:\Program Files\Enigma Software Group
2008-05-28 07:56:53 0 d-------- C:\Windows\Content.IE5
2008-05-27 23:35:32 0 d-------- C:\Users\All Users\Lavasoft
2008-05-27 23:35:32 0 d-------- C:\Program Files\Lavasoft
2008-05-27 23:35:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-27 23:30:39 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-26 23:29:58 0 d-------- C:\Users\All Users\Xfire
2008-05-26 23:29:58 0 d-------- C:\Program Files\Xfire
2008-05-26 22:13:09 0 d-------- C:\Program Files\Logitech
2008-05-26 14:00:06 0 d-------- C:\Program Files\Dl_cats
2008-05-26 13:59:26 0 d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-05-26 13:59:21 0 d-------- C:\Program Files\Dell
2008-05-26 13:58:45 45056 --a------ C:\Windows\system32\DLPRMON.DLL <Not Verified; ; Dell Fax Solutions Software>
2008-05-26 13:58:45 32768 --a------ C:\Windows\system32\DLPMONUI.DLL <Not Verified; ; Dell Fax Solutions Software>
2008-05-26 13:58:25 98345 --a------ C:\Windows\system32\IMHOST32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-05-26 13:58:25 339968 --a------ C:\Windows\system32\IMGMAN32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-05-26 13:58:24 0 d-------- C:\Users\All Users\DellFaxCtr
2008-05-26 13:58:20 0 d-------- C:\Program Files\Dell PC Fax
2008-05-26 13:58:16 274432 --a------ C:\Windows\system32\dlcxinst.dll
2008-05-26 13:58:16 323584 --a------ C:\Windows\system32\dlcxhcp.dll <Not Verified; ; Printer Communication System>
2008-05-26 13:58:16 0 d-------- C:\Program Files\Dell Photo AIO Printer 926
2008-05-25 21:34:13 152576 --a------ C:\Windows\system32\SPWizUI.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-25 18:10:47 0 d-------- C:\Users\All Users\Steam
2008-05-25 18:10:32 0 d-------- C:\Users\All Users\PopCap Games
2008-05-25 17:30:07 0 d-------- C:\Program Files\Nvidia Omega Drivers
2008-05-25 17:20:27 0 d-------- C:\Program Files\DIFX
2008-05-25 03:00:27 0 d-------- C:\Program Files\MSXML 4.0
2008-05-23 20:43:40 0 d-------- C:\Ubuntu
2008-05-23 20:20:53 0 d-------- C:\Users\All Users\Nero
2008-05-23 20:20:53 0 d-------- C:\Program Files\Nero
2008-05-23 20:20:53 0 d-------- C:\Program Files\Common Files\Nero
2008-05-22 23:08:35 0 d-------- C:\Program Files\CodeGazer
2008-05-22 22:38:01 0 --a------ C:\Windows\nsreg.dat
2008-05-22 18:29:40 0 d-------- C:\Windows\nvidia icons
2008-05-21 18:42:53 0 d-------- C:\Program Files\Bonjour
2008-05-21 18:42:22 0 d-------- C:\Program Files\Emergent Music LLC
2008-05-21 18:41:37 0 d-------- C:\Program Files\Ruckus Player
2008-05-21 18:28:41 0 d-------- C:\Program Files\uTorrent
2008-05-20 23:58:55 0 d-------- C:\Windows\Panther
2008-05-20 23:58:13 0 d-------- C:\Windows\system32\OEM
2008-05-20 23:58:13 34 -rah----- C:\Windows\DELL_VERSION
2008-05-20 23:04:14 0 d-------- C:\Windows\SoftwareDistribution
2008-05-20 23:03:01 0 d-------- C:\Windows\Debug
2008-05-20 22:59:48 0 d-------- C:\Windows\Prefetch
2008-05-20 22:29:43 0 d-------- C:\Windows\system32\Macromed
2008-05-20 22:20:07 0 d-------- C:\Program Files\Common Files\Steam
2008-05-20 22:20:06 0 d-------- C:\Program Files\Steam
2008-05-20 22:07:58 0 d-------- C:\Users\All Users\NVIDIA
2008-05-20 21:48:14 1726 --a------ C:\Windows\ndinst.exe
2008-05-20 21:48:14 0 -rahs---- C:\MSDOS.SYS
2008-05-20 21:48:14 0 -rahs---- C:\IO.SYS
2008-05-20 21:33:14 15781 --a------ C:\Windows\system32\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.9>
2008-05-20 21:33:13 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-20 21:32:57 0 d-------- C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2008-05-20 21:08:41 0 d-------- C:\Users\All Users\Adobe
2008-05-20 20:53:36 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-20 20:52:58 0 d--hs---- C:\Windows\Installer
2008-05-20 20:52:58 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-20 20:31:14 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-20 20:14:46 0 dr------- C:\Users\Matthew\Searches
2008-05-20 20:14:38 0 dr------- C:\Users\Matthew\Contacts
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Templates
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Start Menu
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\SendTo
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Recent
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\PrintHood
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\NetHood
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\My Documents
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Local Settings
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Cookies
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Application Data
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Videos
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Saved Games
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Pictures
2008-05-20 20:14:33 2359296 --ahs---- C:\Users\Matthew\NTUSER.DAT
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Music
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Links
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Favorites
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Downloads
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Documents
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Desktop
2008-05-20 20:14:33 0 d--h----- C:\Users\Matthew\AppData
2008-05-18 23:17:36 0 d-------- C:\NVIDIA
-- Find3M Report ---------------------------------------------------------------
2008-05-28 18:20:19 35 --a------ C:\Users\Matthew\AppData\Roaming\SetValue.bat
2008-05-28 18:20:19 691 --a------ C:\Users\Matthew\AppData\Roaming\GetValue.vbs
2008-05-28 00:17:21 0 d-------- C:\Users\Matthew\AppData\Roaming\DellFaxCtr
2008-05-27 23:35:01 0 d-------- C:\Program Files\Common Files
2008-05-27 23:22:09 0 d-------- C:\Users\Matthew\AppData\Roaming\Xfire
2008-05-25 23:47:59 0 d-------- C:\Users\Matthew\AppData\Roaming\Adobe
2008-05-25 21:50:38 174 --ahs---- C:\Program Files\desktop.ini
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Sidebar
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Photo Gallery
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Mail
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Collaboration
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Calendar
2008-05-25 21:45:05 0 d-------- C:\Program Files\Movie Maker
2008-05-25 21:45:02 0 d-------- C:\Program Files\Windows Defender
2008-05-25 19:46:53 0 d-------- C:\Users\Matthew\AppData\Roaming\uTorrent
2008-05-23 20:21:55 0 d-------- C:\Users\Matthew\AppData\Roaming\Nero
2008-05-22 22:37:59 0 d-------- C:\Users\Matthew\AppData\Roaming\Mozilla
2008-05-21 19:22:12 0 d-------- C:\Users\Matthew\AppData\Roaming\goombah
2008-05-21 18:43:56 0 d-------- C:\Users\Matthew\AppData\Roaming\Ruckus Network
2008-05-20 22:29:44 0 d-------- C:\Users\Matthew\AppData\Roaming\Macromedia
2008-05-20 21:09:08 0 d-------- C:\Users\Matthew\AppData\Roaming\AdobeUM
2008-05-20 20:14:39 0 d-------- C:\Users\Matthew\AppData\Roaming\Identities
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34CF6660-9BD3-431A-BA32-6B511D4126DA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [01/18/2008 23:38]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"RestartNeroSetup"="C:\Users\Matthew\AppData\Local\Temp\OnlineUpdate8\SetupXu.exe" []
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [05/02/2008 22:46]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [05/02/2008 22:46]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [11/03/2006 18:09]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [01/12/2007 12:57]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [11/03/2006 18:04]
"DLCXCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [10/16/2006 01:31]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [05/28/2008 08:29]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [02/05/2007 19:52]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [05/26/2008 22:13]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [01/18/2008 23:33]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingB3738"=command /c del "C:\Program Files\NetProject\sbmntr.exe_old"
"SpybotDeletingD983"=cmd /c del "C:\Program Files\NetProject\sbmntr.exe_old"
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [5/26/2008 22:13:17]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableUIADesktopToggle"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52daf334-26d6-11dd-86d7-0019d1405841}]
AutoRun\command- G:\Autorun.exe /run
Shell00\Command- G:\Autorun.exe /run
Shell01\Command- G:\Autorun.exe /action
Shell02\Command- G:\Autorun.exe /uninstall
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7c04fd80-2cfe-11dd-bba4-001839142802}]
AutoRun\command- H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb233278-26e1-11dd-ad00-806e6f6e6963}]
AutoRun\command- E:\Setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-05-31 07:17:20 ------------