Deckard's System Scanner v20071014.68
Run by Matthew on 2008-06-11 22:29:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Matthew.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:29, on 2008-06-11
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\AIM\AIM Pro\aimpro.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Matthew\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Matthew.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RestartNeroSetup] "C:\Users\Matthew\AppData\Local\Temp\OnlineUpdate8\SetupXu.exe" MODE="update" STARTMODE="2" USERSEL="3" FAMILYNAME="Nero 8" RUNSETUPXU="1" UPGRADE="1"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 5612 bytes
-- Files created between 2008-05-11 and 2008-06-11 -----------------------------
2008-06-08 17:32:15 161792 --a------ C:\Windows\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-08 14:16:37 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-06-08 14:16:34 0 d-------- C:\Program Files\AIM
2008-06-07 23:08:09 68096 --a------ C:\Windows\zip.exe
2008-06-07 23:08:09 49152 --a------ C:\Windows\VFind.exe
2008-06-07 23:08:09 212480 --a------ C:\Windows\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-07 23:08:09 136704 --a------ C:\Windows\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-07 23:08:09 98816 --a------ C:\Windows\sed.exe
2008-06-07 23:08:09 80412 --a------ C:\Windows\grep.exe
2008-06-07 23:08:09 89504 --a------ C:\Windows\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-05 18:25:31 0 d-------- C:\Users\Matthew\DoctorWeb
2008-05-31 12:13:26 0 d-------- C:\Users\All Users\Malwarebytes
2008-05-31 12:13:25 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-30 21:49:51 1409 --a------ C:\Windows\mozver.dat
2008-05-29 10:13:33 0 d-------- C:\Program Files\Microsoft IntelliPoint
2008-05-29 06:56:30 0 d-------- C:\Users\All Users\FLEXnet
2008-05-28 19:01:51 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-05-28 19:00:10 0 d-------- C:\Program Files\Trend Micro
2008-05-28 18:25:36 0 d-------- C:\VundoFix Backups
2008-05-28 18:19:43 2710 --a------ C:\Windows\system32\tmp.reg
2008-05-28 18:16:43 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-05-28 18:16:43 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-05-28 18:16:43 86528 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-05-28 18:16:43 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-05-28 18:16:43 51200 --a------ C:\Windows\system32\dumphive.exe
2008-05-28 09:06:16 0 d--h----- C:\$AVG8.VAULT$
2008-05-28 08:29:07 0 d-------- C:\Windows\system32\drivers\Avg
2008-05-28 08:29:04 0 d-------- C:\Users\All Users\avg8
2008-05-28 08:29:04 0 d-------- C:\Program Files\AVG
2008-05-28 08:20:59 0 d-------- C:\Program Files\Enigma Software Group
2008-05-28 07:56:53 0 d-------- C:\Windows\Content.IE5
2008-05-27 23:35:32 0 d-------- C:\Users\All Users\Lavasoft
2008-05-27 23:35:32 0 d-------- C:\Program Files\Lavasoft
2008-05-27 23:35:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-27 23:30:39 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-26 23:29:58 0 d-------- C:\Users\All Users\Xfire
2008-05-26 23:29:58 0 d-------- C:\Program Files\Xfire
2008-05-26 22:13:09 0 d-------- C:\Program Files\Logitech
2008-05-26 14:00:06 0 d-------- C:\Program Files\Dl_cats
2008-05-26 13:59:26 0 d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-05-26 13:59:21 0 d-------- C:\Program Files\Dell
2008-05-26 13:58:45 45056 --a------ C:\Windows\system32\DLPRMON.DLL <Not Verified; ; Dell Fax Solutions Software>
2008-05-26 13:58:45 32768 --a------ C:\Windows\system32\DLPMONUI.DLL <Not Verified; ; Dell Fax Solutions Software>
2008-05-26 13:58:25 98345 --a------ C:\Windows\system32\IMHOST32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-05-26 13:58:25 339968 --a------ C:\Windows\system32\IMGMAN32.DLL <Not Verified; Data Techniques, Inc.; ImageMan Image Processing Toolkit>
2008-05-26 13:58:24 0 d-------- C:\Users\All Users\DellFaxCtr
2008-05-26 13:58:20 0 d-------- C:\Program Files\Dell PC Fax
2008-05-26 13:58:16 274432 --a------ C:\Windows\system32\dlcxinst.dll
2008-05-26 13:58:16 323584 --a------ C:\Windows\system32\dlcxhcp.dll <Not Verified; ; Printer Communication System>
2008-05-26 13:58:16 0 d-------- C:\Program Files\Dell Photo AIO Printer 926
2008-05-25 21:34:13 152576 --a------ C:\Windows\system32\SPWizUI.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-25 18:10:47 0 d-------- C:\Users\All Users\Steam
2008-05-25 18:10:32 0 d-------- C:\Users\All Users\PopCap Games
2008-05-25 17:30:07 0 d-------- C:\Program Files\Nvidia Omega Drivers
2008-05-25 17:20:27 0 d-------- C:\Program Files\DIFX
2008-05-25 03:00:27 0 d-------- C:\Program Files\MSXML 4.0
2008-05-23 20:43:40 0 d-------- C:\Ubuntu
2008-05-23 20:20:53 0 d-------- C:\Users\All Users\Nero
2008-05-23 20:20:53 0 d-------- C:\Program Files\Nero
2008-05-23 20:20:53 0 d-------- C:\Program Files\Common Files\Nero
2008-05-22 23:08:35 0 d-------- C:\Program Files\CodeGazer
2008-05-22 22:38:01 0 --a------ C:\Windows\nsreg.dat
2008-05-22 18:29:40 0 d-------- C:\Windows\nvidia icons
2008-05-21 18:42:53 0 d-------- C:\Program Files\Bonjour
2008-05-21 18:42:22 0 d-------- C:\Program Files\Emergent Music LLC
2008-05-21 18:41:37 0 d-------- C:\Program Files\Ruckus Player
2008-05-21 18:28:41 0 d-------- C:\Program Files\uTorrent
2008-05-20 23:58:55 0 d-------- C:\Windows\Panther
2008-05-20 23:58:13 0 d-------- C:\Windows\system32\OEM
2008-05-20 23:58:13 34 -rah----- C:\Windows\DELL_VERSION
2008-05-20 23:04:14 0 d-------- C:\Windows\SoftwareDistribution
2008-05-20 23:03:01 0 d-------- C:\Windows\Debug
2008-05-20 22:59:48 0 d-------- C:\Windows\Prefetch
2008-05-20 22:29:43 0 d-------- C:\Windows\system32\Macromed
2008-05-20 22:20:07 0 d-------- C:\Program Files\Common Files\Steam
2008-05-20 22:20:06 0 d-------- C:\Program Files\Steam
2008-05-20 22:07:58 0 d-------- C:\Users\All Users\NVIDIA
2008-05-20 21:48:14 1726 --a------ C:\Windows\ndinst.exe
2008-05-20 21:48:14 0 -rahs---- C:\MSDOS.SYS
2008-05-20 21:48:14 0 -rahs---- C:\IO.SYS
2008-05-20 21:33:14 15781 --a------ C:\Windows\system32\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.9>
2008-05-20 21:33:13 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-20 21:32:57 0 d-------- C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2008-05-20 21:08:41 0 d-------- C:\Users\All Users\Adobe
2008-05-20 20:53:36 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-20 20:52:58 0 d--hs---- C:\Windows\Installer
2008-05-20 20:52:58 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-20 20:31:14 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-20 20:14:46 0 dr------- C:\Users\Matthew\Searches
2008-05-20 20:14:38 0 dr------- C:\Users\Matthew\Contacts
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Templates
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Start Menu
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\SendTo
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Recent
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\PrintHood
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\NetHood
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\My Documents
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Local Settings
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Cookies
2008-05-20 20:14:34 0 d--hs---- C:\Users\Matthew\Application Data
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Videos
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Saved Games
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Pictures
2008-05-20 20:14:33 2621440 --ahs---- C:\Users\Matthew\NTUSER.DAT
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Music
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Links
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Favorites
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Downloads
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Documents
2008-05-20 20:14:33 0 dr------- C:\Users\Matthew\Desktop
2008-05-20 20:14:33 0 d--h----- C:\Users\Matthew\AppData
2008-05-18 23:17:36 0 d-------- C:\NVIDIA
-- Find3M Report ---------------------------------------------------------------
2008-06-11 03:07:08 0 d-------- C:\Program Files\Windows Mail
2008-06-08 14:16:52 0 d-------- C:\Users\Matthew\AppData\Roaming\acccore
2008-06-08 14:16:51 0 d-------- C:\Users\Matthew\AppData\Roaming\AIMPro
2008-06-08 14:16:37 0 d-------- C:\Program Files\Common Files
2008-06-08 14:16:20 0 d-------- C:\Users\Matthew\AppData\Roaming\AIM
2008-06-08 14:09:03 0 d-------- C:\Users\Matthew\AppData\Roaming\uTorrent
2008-05-31 12:13:33 0 d-------- C:\Users\Matthew\AppData\Roaming\Malwarebytes
2008-05-28 18:20:19 35 --a------ C:\Users\Matthew\AppData\Roaming\SetValue.bat
2008-05-28 18:20:19 691 --a------ C:\Users\Matthew\AppData\Roaming\GetValue.vbs
2008-05-28 00:17:21 0 d-------- C:\Users\Matthew\AppData\Roaming\DellFaxCtr
2008-05-27 23:22:09 0 d-------- C:\Users\Matthew\AppData\Roaming\Xfire
2008-05-25 23:47:59 0 d-------- C:\Users\Matthew\AppData\Roaming\Adobe
2008-05-25 21:50:38 174 --ahs---- C:\Program Files\desktop.ini
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Sidebar
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Photo Gallery
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Collaboration
2008-05-25 21:45:05 0 d-------- C:\Program Files\Windows Calendar
2008-05-25 21:45:05 0 d-------- C:\Program Files\Movie Maker
2008-05-25 21:45:02 0 d-------- C:\Program Files\Windows Defender
2008-05-23 20:21:55 0 d-------- C:\Users\Matthew\AppData\Roaming\Nero
2008-05-22 22:37:59 0 d-------- C:\Users\Matthew\AppData\Roaming\Mozilla
2008-05-21 19:22:12 0 d-------- C:\Users\Matthew\AppData\Roaming\goombah
2008-05-21 18:43:56 0 d-------- C:\Users\Matthew\AppData\Roaming\Ruckus Network
2008-05-20 22:29:44 0 d-------- C:\Users\Matthew\AppData\Roaming\Macromedia
2008-05-20 21:09:08 0 d-------- C:\Users\Matthew\AppData\Roaming\AdobeUM
2008-05-20 20:14:39 0 d-------- C:\Users\Matthew\AppData\Roaming\Identities
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-18 23:38]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" []
"RestartNeroSetup"="C:\Users\Matthew\AppData\Local\Temp\OnlineUpdate8\SetupXu.exe" []
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-02 22:46]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-02 22:46]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-11-03 18:09]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 12:57]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 18:04]
"DLCXCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 01:31]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-28 08:29]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 19:52]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" [2007-10-09 03:45]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-05-26 22:13]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 23:33]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-05-26 22:13:17]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableUIADesktopToggle"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-06-11 22:30:55 ------------