Deckard's System Scanner v20071014.68
Run by Robert on 2008-06-02 15:34:20
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
108: 2008-06-02 22:34:33 UTC - RP108 - Deckard's System Scanner Restore Point
107: 2008-06-02 12:26:00 UTC - RP107 - System Checkpoint
106: 2008-05-31 12:53:02 UTC - RP106 - System Checkpoint
105: 2008-05-30 12:32:21 UTC - RP105 - System Checkpoint
104: 2008-05-29 12:20:41 UTC - RP104 - System Checkpoint
-- First Restore Point --
1: 2008-04-01 20:32:04 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Robert.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:36:13 PM, on 6/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\LClock\LClock.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ViStart\ViStart.exe
C:\Program Files\ViOrb\ViOrb.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\HotKeyBind\HotKeyBind.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Documents and Settings\Robert\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Robert.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.comcast.netR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {F608C2D0-846D-4F0E-E47A-88367C887707} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [CmUsbAudio] RunDll32 cmcnfg2.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MbarInstall] C:\DOCUME~1\Robert\LOCALS~1\Temp\temD.tmp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [viwc] C:\WINDOWS\system32\viwc.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [ViStart] C:\Program Files\ViStart\ViStart.exe
O4 - HKCU\..\Run: [ViOrb] C:\Program Files\ViOrb\ViOrb.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [HotKeyBind.exe] C:\Program Files\HotKeyBind\HotKeyBind.exe
O4 - HKCU\..\Run: [BitDownload] "C:\Program Files\BitDownload\BitDownload.exe" /minimized
O4 - HKCU\..\Run: [Pollthis] C:\DOCUME~1\Robert\APPLIC~1\TESTIN~1\16firstitch.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - S-1-5-18 Startup: Epson printer Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Epson printer Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE (User 'Default user')
O4 - Startup: Epson printer Registration.lnk = E:\Titles\Ereg\EPSONREG.EXE
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster Platinum 18\Remind.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ComcastHSI - {DCDD459D-4C53-4D86-A3CB-0988FBFF5469} -
http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Support - {F7F99157-5D50-4898-9A92-F817A5504524} -
http://www.comcastsupport.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://drm.christianbook.comO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
--
End of file - 8283 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 PenClass (Pen Class) - c:\windows\system32\drivers\penclass.sys <Not Verified; Wacom Technology Corporation; Wacom Pen Class Driver>
R1 OMCI - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Computer Corporation; OMCI Driver>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R2 CDRPDACC (Arrowkey Device Access) - c:\program files\321studios\shared\cdrpdacc.sys <Not Verified; Arrowkey; CD Device Access>
R3 cmpci (Turtle Beach Riviera) - c:\windows\system32\drivers\cmaudio.sys <Not Verified; C-Media Inc; C-Media Audio Driver (WDM)>
R3 Pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
S3 DSDrv4 - c:\program files\dscaler\dsdrv4.sys
S3 HSF_DP - c:\windows\system32\drivers\hsf_dp.sys (file missing)
S3 HSFHWBS2 - c:\windows\system32\drivers\hsfhwbs2.sys (file missing)
S3 winachsf - c:\windows\system32\drivers\hsf_cnxt.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_8086&DEV_1039&SUBSYS_01421028&REV_81\4&3B1CAF2B&0&40F0
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_8086&DEV_1039&SUBSYS_01421028&REV_81\4&3B1CAF2B&0&40F0
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-06-02 15:00:00 264 --ah----- C:\WINDOWS\Tasks\AB258A26914A06CE.job
2008-05-28 08:44:07 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-05-02 and 2008-06-02 -----------------------------
2008-06-01 14:10:47 1855488 -ra------ C:\WINDOWS\system32\drivers\MIXER.EXE <Not Verified; C-Media Electronic Inc. (www.cmedia.com.tw); Mixer>
2008-06-01 14:10:46 765952 -ra------ C:\WINDOWS\system32\drivers\CRLDS3D.DLL <Not Verified; Sensaura Ltd; Sensaura 3DPA>
2008-06-01 14:10:45 139264 -ra------ C:\WINDOWS\system32\drivers\CMUNINST.EXE <Not Verified; C-Media Electronics Inc.; CMIUninst Application>
2008-06-01 14:10:45 135168 -ra------ C:\WINDOWS\system32\drivers\CMUNINST.DAT <Not Verified; C-Media Electronics Inc.; CMIUninst Application>
2008-06-01 14:10:45 32768 -ra------ C:\WINDOWS\system32\drivers\CMNPROP.DLL <Not Verified; C-Media Corporation; CMI8738/CMI9738 Audio Device>
2008-06-01 14:10:45 1127 -ra------ C:\WINDOWS\system32\drivers\cmijack.dat
2008-06-01 14:10:45 3360 -ra------ C:\WINDOWS\system32\drivers\cmiainfo.sys
2008-06-01 14:10:44 436 -ra------ C:\WINDOWS\system32\drivers\cmaudio.dat
2008-06-01 14:10:06 0 d-------- C:\Program Files\Common Files\Voyetra
2008-06-01 14:10:02 0 d-------- C:\Program Files\Common Files\Turtle Beach
2008-06-01 14:08:54 0 d-------- C:\Program Files\Voyetra Turtle Beach
2008-05-31 02:30:06 0 d-------- C:\Documents and Settings\All Users\Application Data\ALM
2008-05-31 02:19:16 0 d-------- C:\Program Files\PowerISO
2008-05-29 17:04:31 0 d-------- C:\Program Files\Trend Micro
2008-05-27 22:57:28 0 d-------- C:\Program Files\testinsidebalm
2008-05-27 16:03:11 0 d-------- C:\Program Files\dng4ps2
2008-05-27 16:01:28 0 d-------- C:\Program Files\DNG4PS-2
2008-05-27 15:11:25 0 d-------- C:\Program Files\ComcastUI
2008-05-27 12:16:17 0 d-------- C:\Program Files\support.com
2008-05-27 12:16:07 0 d-------- C:\Program Files\Common Files\SupportSoft
2008-05-23 09:15:47 0 d-------- C:\Program Files\Easy MPEG AVI DIVX WMV RM to DVD
2008-05-22 09:37:14 47360 --a------ C:\Documents and Settings\Robert\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-05-22 09:37:13 0 d-------- C:\Documents and Settings\Robert\Application Data\Vso
2008-05-22 09:37:08 0 d-------- C:\Program Files\FlyDVDCopier
2008-05-20 16:53:12 0 d-------- C:\Program Files\WSRMacros
2008-05-17 22:01:17 0 d-------- C:\CLOVERFIELD_DOM
2008-05-16 10:50:12 0 d-------- C:\Documents and Settings\Robert\Application Data\ImgBurn
2008-05-16 08:59:44 0 d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-05-16 08:59:42 0 d-------- C:\Program Files\DVD Shrink
2008-05-15 09:45:55 0 d-------- C:\Documents and Settings\Robert\Application Data\Any Video Converter
2008-05-15 09:45:50 0 d-------- C:\Program Files\Any Video Converter
2008-05-14 11:06:25 0 d-------- C:\Documents and Settings\Robert\Application Data\WinFF
2008-05-14 11:06:22 0 d-------- C:\Program Files\WinFF
2008-05-13 22:45:35 0 d-------- C:\Documents and Settings\Robert\Application Data\Opera
2008-05-13 22:45:14 0 d-------- C:\Program Files\Opera
2008-05-13 00:22:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Logishrd
2008-05-13 00:22:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-05-12 23:51:48 0 d-------- C:\Program Files\Common Files\LogiShrd
2008-05-12 23:46:00 0 d-------- C:\Program Files\Logitech
2008-05-12 18:55:31 0 d-------- C:\Documents and Settings\Robert\Application Data\Coolbox
2008-05-12 18:55:08 0 d-------- C:\Program Files\MobiDVD
2008-05-08 18:00:37 0 d-------- C:\Program Files\MediaCoder
2008-05-08 10:01:41 0 d-------- C:\videooutput
2008-05-08 10:01:39 765952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-05-08 10:01:39 383238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll
2008-05-08 10:01:38 3086336 --a------ C:\WINDOWS\system32\flvvideo.dll
2008-05-08 10:01:37 3086336 --a------ C:\WINDOWS\system32\NCMedia.dll
2008-05-08 09:59:31 487479 --a------ C:\WINDOWS\system32\SkinMagic.dll <Not Verified; Appspeed Inc.; Appspeed SkinMagic Toolkit>
2008-05-08 09:59:31 66048 --a------ C:\WINDOWS\system32\cygz.dll
2008-05-08 09:59:31 1872821 --a------ C:\WINDOWS\system32\cygwin1.dll <Not Verified; Red Hat; Cygwin>
2008-05-08 09:59:30 6664208 --a------ C:\WINDOWS\system32\dvdripcore.dll
2008-05-08 09:59:30 0 d-------- C:\Program Files\Smallvideosoft
2008-05-08 09:55:54 0 d-------- C:\Documents and Settings\Robert\Application Data\DVD Flick
2008-05-08 09:55:42 0 d-------- C:\Program Files\DVD Flick
2008-05-05 18:34:39 0 d-------- C:\Program Files\iPod
2008-05-05 18:34:30 0 d-------- C:\Program Files\iTunes
2008-05-05 18:34:14 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-05 18:33:54 0 d-------- C:\Program Files\Common Files\Apple
2008-05-05 18:32:50 0 d-------- C:\Program Files\Apple Software Update
2008-05-05 18:32:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-03 14:24:59 0 d-------- C:\Program1
2008-05-03 14:23:19 0 d-------- C:\Program Files\Common Files\Download Manager
-- Find3M Report ---------------------------------------------------------------
2008-06-02 15:34:02 0 d-------- C:\Documents and Settings\Robert\Application Data\Zoom Player
2008-06-02 03:55:45 0 d-------- C:\Program Files\BitDownload
2008-06-02 03:55:40 0 d-------- C:\Documents and Settings\Robert\Application Data\BitDownload
2008-06-02 03:54:28 0 d-------- C:\Documents and Settings\Robert\Application Data\WTablet
2008-06-02 03:54:17 0 d-------- C:\Program Files\ViStart
2008-06-01 23:08:53 0 d-------- C:\Program Files\Wyzo
2008-06-01 14:10:06 0 d-------- C:\Program Files\Common Files
2008-06-01 14:08:54 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-31 05:15:26 0 d-------- C:\Documents and Settings\Robert\Application Data\Azureus
2008-05-31 04:03:49 0 d-------- C:\Program Files\Tablet
2008-05-31 03:22:02 0 d-------- C:\Documents and Settings\Robert\Application Data\Adobe
2008-05-31 00:02:13 0 d-------- C:\Documents and Settings\Robert\Application Data\LimeWire
2008-05-27 22:57:51 0 d-------- C:\Documents and Settings\Robert\Application Data\testinsidebalm
2008-05-27 16:26:11 0 d-------- C:\Program Files\GameSpot
2008-05-27 16:26:11 0 d-------- C:\Program Files\FBrowsingAdvisor
2008-05-27 16:26:10 0 d-------- C:\Program Files\DivX
2008-05-27 16:26:08 0 d-------- C:\Program Files\321Studios
2008-05-27 16:26:07 0 d-------- C:\Program Files\AIM
2008-05-24 23:57:57 0 d-------- C:\Program Files\DScaler
2008-05-24 03:45:20 0 d-------- C:\Documents and Settings\Robert\Application Data\AVG7
2008-05-22 16:01:30 0 d-------- C:\Program Files\Mozilla Firefox 3 Beta 5
2008-05-22 09:37:32 34 --a------ C:\Documents and Settings\Robert\Application Data\pcouffin.log
2008-05-22 09:37:15 1144 --a------ C:\Documents and Settings\Robert\Application Data\pcouffin.inf
2008-05-22 09:37:15 7887 --a------ C:\Documents and Settings\Robert\Application Data\pcouffin.cat
2008-05-18 23:41:08 0 d-------- C:\Program Files\SurfingEnhancer
2008-05-16 09:50:08 0 d-------- C:\Documents and Settings\Robert\Application Data\dvdcss
2008-05-05 18:34:59 0 d-------- C:\Documents and Settings\Robert\Application Data\Apple Computer
2008-05-03 14:35:41 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-02 08:43:33 0 d-------- C:\Program Files\Azureus
2008-05-02 00:46:49 0 d-------- C:\Program Files\SmartEnhancer
2008-05-01 11:45:48 0 d-------- C:\Program Files\DVD Decrypter
2008-05-01 11:43:23 0 d-------- C:\Program Files\Ahead
2008-05-01 11:41:04 0 d-------- C:\Program Files\vso
2008-05-01 11:27:13 0 d-------- C:\Documents and Settings\Robert\Application Data\Wyzo
2008-05-01 11:23:10 0 d-------- C:\Documents and Settings\Robert\Application Data\.wyzo
2008-04-30 10:50:04 0 d-------- C:\Program Files\Elaborate Bytes
2008-04-30 10:25:23 0 d-------- C:\Program Files\LimeWire
2008-04-30 09:38:04 0 --a------ C:\WINDOWS\system32\taskkill.exe
2008-04-30 09:38:03 0 --a------ C:\WINDOWS\b.exe
2008-04-28 09:08:44 6096 --a------ C:\Program Files\install.log
2008-04-26 01:49:58 0 d-------- C:\Program Files\HotKeyBind
2008-04-25 09:41:22 13356 --a------ C:\WINDOWS\system32\winupsvc.exe
2008-04-25 09:41:22 13356 --a------ C:\WINDOWS\system32\winsvcup.exe
2008-04-25 09:41:21 13356 --a------ C:\WINDOWS\system32\mswinup.exe
2008-04-24 22:39:05 0 d-------- C:\Program Files\PlayMP3z
2008-04-22 08:53:27 0 d-------- C:\Program Files\Sonic
2008-04-20 17:16:10 0 d-------- C:\Documents and Settings\Robert\Application Data\Sony
2008-04-20 04:27:58 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-14 18:25:36 0 d-------- C:\Program Files\Bagatrix
2008-04-13 16:27:04 0 d-------- C:\Program Files\Zoom Player
2008-04-13 09:40:42 0 d-------- C:\Documents and Settings\Robert\Application Data\Real
2008-04-12 15:19:17 0 d-------- C:\Program Files\Common Files\xing shared
2008-04-12 15:19:08 0 d-------- C:\Program Files\Common Files\Real
2008-04-12 15:07:23 0 d-------- C:\Program Files\Real
2008-04-12 04:39:08 0 d-------- C:\Documents and Settings\Robert\Application Data\Mozilla
2008-04-12 01:24:42 0 d-------- C:\Program Files\QuickTime
2008-04-11 22:37:31 0 d-------- C:\Documents and Settings\Robert\Application Data\Publish Providers
2008-04-11 22:23:34 0 d-------- C:\Program Files\Sony
2008-04-11 22:22:52 0 d-------- C:\Program Files\Sony Setup
2008-04-11 22:07:26 0 d-------- C:\Program Files\Vstplugins
2008-04-11 22:00:51 0 d-------- C:\Documents and Settings\Robert\Application Data\Sony Setup
2008-04-11 20:54:32 0 d-------- C:\Program Files\DScaler5
2008-04-11 20:54:00 0 d-------- C:\Program Files\ffdshow
2008-04-11 20:53:13 0 d-------- C:\Program Files\CD Audio Reader Filter
2008-04-11 20:53:09 0 d-------- C:\Program Files\OpenSource Flash Video Splitter
2008-04-11 20:53:08 0 d-------- C:\Program Files\RealMedia
2008-04-11 20:52:55 0 d-------- C:\Program Files\SHOUTcast Source
2008-04-11 20:52:43 0 d-------- C:\Program Files\Haali
2008-04-11 20:52:40 0 d-------- C:\Program Files\DSP-worx
2008-04-11 20:52:24 0 d-------- C:\Program Files\DirectVobSub
2008-04-11 09:49:51 0 d-------- C:\Program Files\PowerDataRecovery
2008-04-11 02:10:25 0 d-------- C:\Program Files\WinTV
2008-04-09 20:32:58 0 d-------- C:\Documents and Settings\Robert\Application Data\Leadertech
2008-04-09 20:29:36 0 d-------- C:\Program Files\EPSON
2008-04-09 20:29:15 0 d-------- C:\Program Files\EPSON Print CD
2008-04-09 19:23:00 61678 --a------ C:\Documents and Settings\Robert\Application Data\PFP100JPR.{PB
2008-04-09 19:23:00 12358 --a------ C:\Documents and Settings\Robert\Application Data\PFP100JCM.{PB
2008-04-09 19:22:59 0 d-------- C:\Documents and Settings\Robert\Application Data\Corel
2008-04-08 21:16:53 0 d-------- C:\Program Files\MP3Gain
2008-04-08 09:56:52 252 --a------ C:\xcrashdump.dat
2008-04-04 14:00:42 0 d-------- C:\Documents and Settings\Robert\Application Data\Audacity
2008-04-04 13:32:34 0 d-------- C:\Program Files\Thomson
2008-04-04 13:29:48 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-03 18:17:58 0 d-------- C:\Program Files\Lavasoft
2008-04-03 17:53:59 0 d-------- C:\Documents and Settings\Robert\Application Data\Sun
2008-04-03 11:10:29 0 d-------- C:\Program Files\MSXML 4.0
2008-04-03 03:49:11 0 d-------- C:\Program Files\Java
2008-04-03 03:43:41 0 d-------- C:\Documents and Settings\Robert\Application Data\Winamp
2008-04-03 02:57:32 0 d-------- C:\Program Files\Common Files\NSV
2008-04-03 02:53:08 0 d-------- C:\Documents and Settings\Robert\Application Data\Google
2008-04-03 00:41:37 0 d-------- C:\Program Files\WinFlip
2008-04-03 00:33:43 0 d-------- C:\Program Files\Vista Sidebar
2008-04-02 21:55:05 0 d-------- C:\Program Files\Viewpoint
2008-04-02 21:34:22 0 d-------- C:\Documents and Settings\Robert\Application Data\Aim
2008-04-02 21:33:51 0 d-------- C:\Program Files\AOD
2008-04-02 17:51:19 0 d-------- C:\Program Files\Common Files\Java
2008-04-02 16:29:31 0 d-------- C:\Documents and Settings\Robert\Application Data\MSN6
2008-04-02 15:58:47 0 d-------- C:\Documents and Settings\Robert\Application Data\ViStart
2008-04-02 15:58:05 0 d-------- C:\Program Files\Google
2008-04-02 15:57:15 0 d-------- C:\Documents and Settings\Robert\Application Data\Styler
2008-04-02 15:57:08 0 d-------- C:\Program Files\VisualTooltip
2008-04-02 15:57:08 0 d-------- C:\Program Files\ViOrb
2008-04-02 15:57:08 0 d-------- C:\Program Files\TrueTransparency
2008-04-02 15:57:07 0 d-------- C:\Program Files\Styler
2008-04-02 15:57:06 0 d-------- C:\Program Files\LClock
2008-04-02 15:50:07 0 d-------- C:\Documents and Settings\Robert\Application Data\DivX
2008-04-02 15:49:11 0 d-------- C:\Documents and Settings\Robert\Application Data\WinRAR
2008-04-02 15:46:49 0 d-------- C:\Program Files\Messenger
2008-04-02 14:52:43 0 d-------- C:\Program Files\QuickGamma
2008-04-02 14:35:57 0 d-------- C:\Program Files\Winamp
2008-04-02 14:22:45 0 d-------- C:\Documents and Settings\Robert\Application Data\vlc
2008-04-02 14:18:57 0 d-------- C:\Program Files\VideoLAN
2008-04-02 14:10:34 0 d-------- C:\Documents and Settings\Robert\Application Data\Macromedia
2008-04-02 13:53:29 0 d-------- C:\Documents and Settings\Robert\Application Data\Talkback
2008-04-02 13:53:21 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-02 11:26:06 0 d-------- C:\Program Files\UIU
2008-04-02 00:51:23 0 d-------- C:\Program Files\Bonjour
2008-04-02 00:51:21 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-02 00:45:10 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-01 14:16:12 2272 --a------ C:\WINDOWS\system32\w95inf16.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-04-01 14:16:11 4608 --a------ C:\WINDOWS\system32\w95inf32.dll <Not Verified; Microsoft Corporation; Microsoft® Plus! for Windows® 95>
2008-04-01 13:26:09 0 -rahs---- C:\MSDOS.SYS
2008-04-01 13:26:09 0 -rahs---- C:\IO.SYS
2008-04-01 13:26:09 0 --a------ C:\CONFIG.SYS
2008-04-01 13:26:09 0 --a------ C:\AUTOEXEC.BAT
2008-04-01 13:23:57 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-01 05:17:03 62 --ahs---- C:\Documents and Settings\Robert\Application Data\desktop.ini
2008-03-31 14:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-31 14:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-31 14:25:46 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-03-31 14:25:46 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 14:25:46 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-21 13:30:08 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 13:28:54 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-03-21 13:28:54 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-03-21 13:28:20 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F608C2D0-846D-4F0E-E47A-88367C887707}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [02/25/2004 07:52 PM C:\WINDOWS\mixer.exe]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [12/17/2001 12:18 PM]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [04/01/2008 11:49 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/15/2008 08:25 AM]
"EPSON Stylus Photo R220 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.exe" [03/09/2005 05:00 AM]
"CmUsbAudio"="cmcnfg2.cpl" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/28/2008 11:37 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/12/2008 03:18 PM]
"MbarInstall"="C:\DOCUME~1\Robert\LOCALS~1\Temp\temD.tmp.exe" []
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [02/08/2007 01:12 AM]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [02/08/2007 01:13 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"viwc"="C:\WINDOWS\system32\viwc.exe" [11/30/2007 05:56 AM]
"LClock"="C:\Program Files\LClock\LClock.exe" [09/20/2004 01:27 AM]
"ViStart"="C:\Program Files\ViStart\ViStart.exe" [11/26/2007 07:27 PM]
"ViOrb"="C:\Program Files\ViOrb\ViOrb.exe" [11/19/2007 01:01 PM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"HotKeyBind.exe"="C:\Program Files\HotKeyBind\HotKeyBind.exe" [11/15/2004 11:30 PM]
"BitDownload"="C:\Program Files\BitDownload\BitDownload.exe" [04/04/2007 06:18 AM]
"Pollthis"="C:\DOCUME~1\Robert\APPLIC~1\TESTIN~1\16firstitch.exe" [05/27/2008 10:57 PM]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
*Newly Created Service* - SCDEMU
-- Hosts -----------------------------------------------------------------------
127.0.0.1 .supercocklol.com
127.0.0.1 www..webloyalty.com
127.0.0.1 007guard.com
127.0.0.1 www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 010402.com
8078 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-06-02 15:37:29 ------------