Deckard's System Scanner v20071014.68
Run by Joe on 2008-06-08 09:20:06
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
46: 2008-06-08 16:20:09 UTC - RP46 - Deckard's System Scanner Restore Point
45: 2008-06-07 22:33:18 UTC - RP45 - Installed OpenOffice.org 2.4
44: 2008-06-07 22:33:12 UTC - RP44 - Removed OpenOffice.org Installer 1.0
43: 2008-06-07 22:32:43 UTC - RP43 - Installed Java 6 Update 4
42: 2008-06-07 18:14:04 UTC - RP42 - Installed Project64 1.6
-- First Restore Point --
1: 2008-05-23 17:16:14 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Joe.exe) -------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:34 AM, on 6/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\windows\softwaredistribution\download\install\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Joe\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Joe.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1211563830937O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1211607403468O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\windows\softwaredistribution\download\install\STacSV.exe
--
End of file - 5759 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*.js - jsfile - DefaultIcon - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe",7.js - jsfile - shell\open\command - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R4 AvgTdiX (AVG8 Network Redirector) - c:\windows\system32\drivers\avgtdix.sys (file missing)
S2 LMIInfo (LogMeIn Kernel Information Provider) - c:\program files\logmein\x86\rainfo.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_544E8086&REV_01\3&61AAA01&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_544E8086&REV_01\3&61AAA01&0&FB
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-06-08 09:00:00 482 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
-- Files created between 2008-05-08 and 2008-06-08 -----------------------------
2008-06-07 15:35:51 0 d-------- C:\Documents and Settings\Joe\Application Data\OpenOffice.org2
2008-06-07 15:33:22 0 d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-07 15:31:58 0 d-------- C:\Program Files\OpenOffice.org 2.4 (en-US) Installation Files
2008-06-07 11:14:04 0 d-------- C:\Program Files\Project64 1.6
2008-06-07 10:38:00 0 d-------- C:\Documents and Settings\Joe\Application Data\ESET
2008-06-07 10:37:21 0 d-------- C:\WINDOWS\LastGood
2008-06-07 10:36:59 0 d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-06-07 10:35:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-06-07 10:14:48 0 d-------- C:\WINDOWS\5888428E699C4E71BF7194EE06B497DA.TMP
2008-06-03 16:53:18 0 d-------- C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-06-02 20:52:29 0 d-------- C:\WINDOWS\Sun
2008-06-02 20:52:29 0 d-------- C:\Documents and Settings\Joe\Application Data\Sun
2008-06-02 20:51:22 0 d-------- C:\Program Files\Java
2008-06-02 20:49:09 0 d-------- C:\Program Files\Common Files\Java
2008-06-02 20:36:10 0 d-------- C:\Program Files\Trend Micro
2008-06-02 19:37:42 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-31 16:11:36 0 d-------- C:\Program Files\Microsoft.NET
2008-05-31 16:11:36 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-31 16:11:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-31 07:52:49 0 d-------- C:\Program Files\Notepad++
2008-05-31 07:52:49 0 d-------- C:\Documents and Settings\Joe\Application Data\Notepad++
2008-05-29 12:30:58 0 d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-29 12:30:55 0 d-------- C:\Program Files\TuneUp Utilities 2008
2008-05-29 12:21:55 0 d-------- C:\Documents and Settings\Joe\Application Data\TuneUp Software
2008-05-28 09:51:51 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-27 20:51:34 0 d-------- C:\Program Files\QuickTime
2008-05-27 20:50:34 0 d-------- C:\Program Files\Bonjour
2008-05-27 20:45:54 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-27 09:12:08 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-27 09:12:04 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-27 09:12:04 0 d-------- C:\Documents and Settings\Joe\Application Data\SUPERAntiSpyware.com
2008-05-27 09:11:52 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 19:02:44 0 d-------- C:\WINDOWS\system32\appmgmt
2008-05-24 16:39:45 0 d-------- C:\Program Files\Tensons
2008-05-24 16:26:29 0 d-------- C:\Documents and Settings\Joe\Application Data\WebStripper
2008-05-24 16:26:17 0 d-------- C:\Program Files\Solent
2008-05-24 15:30:53 0 d-------- C:\Documents and Settings\Joe\Application Data\AVGTOOLBAR
2008-05-24 15:30:49 0 d-------- C:\Program Files\AVG
2008-05-24 10:56:33 14 --a------ C:\WINDOWS\system32\SystemInfo32.sys
2008-05-24 10:55:45 0 d-------- C:\Program Files\DVD X Studios
2008-05-24 10:55:45 0 d-------- C:\Documents and Settings\All Users\Application Data\DVD X Studios
2008-05-24 10:33:26 0 d-------- C:\Program Files\FlashFXP
2008-05-24 10:33:26 0 d-------- C:\Documents and Settings\All Users\Application Data\FlashFXP
2008-05-24 09:55:22 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2008-05-24 09:55:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-05-23 22:39:44 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-23 21:37:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-23 21:37:00 0 d-------- C:\Documents and Settings\Joe\Application Data\gtk-2.0
2008-05-23 21:31:33 0 d-------- C:\Program Files\Messenger Plus! Live
2008-05-23 21:07:07 0 d-------- C:\Documents and Settings\Joe\Contacts
2008-05-23 21:04:23 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-23 20:57:04 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-23 20:56:46 0 d-------- C:\Program Files\Windows Live
2008-05-23 20:56:38 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-23 17:35:39 0 d-------- C:\Program Files\7-Zip
2008-05-23 17:25:27 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-05-23 17:25:27 0 d-------- C:\Documents and Settings\Joe\Application Data\skypePM
2008-05-23 17:24:55 0 d-------- C:\Documents and Settings\Joe\Application Data\Skype
2008-05-23 17:19:36 0 d-------- C:\Program Files\Skype
2008-05-23 17:19:36 0 d-------- C:\Program Files\Common Files\Skype
2008-05-23 17:19:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-05-23 17:12:49 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-23 17:12:46 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-05-23 17:12:00 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-23 17:12:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-23 15:18:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-05-23 15:18:44 0 d-------- C:\Documents and Settings\Joe\Application Data\Azureus
2008-05-23 15:16:23 0 d-------- C:\Program Files\Azureus
2008-05-23 12:39:23 0 d-------- C:\Documents and Settings\Joe\Application Data\Macromedia
2008-05-23 12:39:22 0 d-------- C:\Documents and Settings\Joe\Application Data\Adobe
2008-05-23 12:39:18 1796 --a------ C:\WINDOWS\mozver.dat
2008-05-23 12:35:00 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-23 12:34:12 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-23 12:34:12 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-23 12:31:07 0 d-------- C:\WINDOWS\system32\URTTemp
2008-05-23 12:14:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-05-23 12:13:12 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-23 12:13:10 0 d-------- C:\Documents and Settings\Joe\Application Data\Mozilla
2008-05-23 12:12:04 0 d-------- C:\WINDOWS\Prefetch
2008-05-23 12:00:29 0 d-------- C:\WINDOWS\system32\scripting
2008-05-23 12:00:29 0 d-------- C:\WINDOWS\l2schemas
2008-05-23 12:00:28 0 d-------- C:\WINDOWS\system32\en
2008-05-23 12:00:28 0 d-------- C:\WINDOWS\system32\bits
2008-05-23 11:59:26 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-23 11:57:54 0 d-------- C:\WINDOWS\network diagnostic
2008-05-23 11:56:54 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-23 11:55:21 0 d-------- C:\Documents and Settings\Joe\Application Data\.purple
2008-05-23 10:53:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-23 10:53:18 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-23 10:52:11 0 d-------- C:\Program Files\Pidgin
2008-05-23 10:52:04 0 d-------- C:\Program Files\Common Files\GTK
2008-05-23 10:49:33 0 d-------- C:\WINDOWS\nview
2008-05-23 10:49:09 0 d-------- C:\NVIDIA
2008-05-23 10:48:10 40960 --a------ C:\WINDOWS\system32\SFIMLARK.dll <Not Verified; Sonic Focus, Inc; Sonic Focus SFIMLARK>
2008-05-23 10:48:10 61440 --a------ C:\WINDOWS\system32\SFIDLOCK.dll <Not Verified; Sonic Focus, Inc; Silicon Pixels SFIDLOCK>
2008-05-23 10:48:10 266240 --a------ C:\WINDOWS\system32\IASMXDLL.dll <Not Verified; Sonic Focus, Inc; Sonic Focus IASMXDLL>
2008-05-23 10:48:10 274432 --a------ C:\WINDOWS\system32\IASDLL.dll <Not Verified; Sonic Focus, Inc; Sonic Focus IASDLL>
2008-05-23 10:48:10 53248 --a------ C:\WINDOWS\system32\IASBB.dll <Not Verified; Sonic Focus, Inc; IASBB>
2008-05-23 10:48:09 0 d-------- C:\Program Files\Intel Audio Studio
2008-05-23 10:47:16 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-23 10:47:16 0 d-------- C:\Program Files\IDT
2008-05-23 10:47:13 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-23 10:31:24 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-23 10:25:30 0 d--hs---- C:\Documents and Settings\Joe\UserData
2008-05-23 10:23:22 0 d-------- C:\Program Files\Intel
2008-05-23 10:16:03 0 d-------- C:\Documents and Settings\Joe\Application Data\Identities
2008-05-23 10:15:56 0 d--h----- C:\Documents and Settings\Joe\Templates <TEMPLA~1>
2008-05-23 10:15:56 0 dr------- C:\Documents and Settings\Joe\Start Menu <STARTM~1>
2008-05-23 10:15:56 0 dr-h----- C:\Documents and Settings\Joe\SendTo
2008-05-23 10:15:56 0 dr-h----- C:\Documents and Settings\Joe\Recent
2008-05-23 10:15:56 0 d--h----- C:\Documents and Settings\Joe\PrintHood <PRINTH~1>
2008-05-23 10:15:56 2097152 --ah----- C:\Documents and Settings\Joe\NTUSER.DAT
2008-05-23 10:15:56 0 d--h----- C:\Documents and Settings\Joe\NetHood
2008-05-23 10:15:56 0 dr------- C:\Documents and Settings\Joe\My Documents <MYDOCU~1>
2008-05-23 10:15:56 0 d--h----- C:\Documents and Settings\Joe\Local Settings <LOCALS~1>
2008-05-23 10:15:56 0 dr------- C:\Documents and Settings\Joe\Favorites <FAVORI~1>
2008-05-23 10:15:56 0 d-------- C:\Documents and Settings\Joe\Desktop
2008-05-23 10:15:56 0 d--hs---- C:\Documents and Settings\Joe\Cookies
2008-05-23 10:15:56 0 dr-h----- C:\Documents and Settings\Joe\Application Data <APPLIC~1>
2008-05-23 10:11:32 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-23 10:11:30 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-23 10:11:30 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-05-23 10:11:30 0 d-------- C:\Documents and Settings\LocalService\Application Data <APPLIC~1>
2008-05-23 10:11:30 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-05-23 10:11:29 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-05-23 10:11:29 0 d--h----- C:\Documents and Settings\LocalService\Local Settings <LOCALS~1>
2008-05-23 10:11:13 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-05-23 10:11:13 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings <LOCALS~1>
2008-05-23 10:11:13 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-05-23 10:11:13 0 d-------- C:\Documents and Settings\NetworkService\Application Data <APPLIC~1>
2008-05-23 10:11:13 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-05-23 10:08:57 0 d-------- C:\WINDOWS\system32\xircom
2008-05-23 10:08:57 0 d-------- C:\Program Files\microsoft frontpage
2008-05-23 10:08:48 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-05-23 10:08:46 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-23 10:08:36 0 -rahs---- C:\MSDOS.SYS
2008-05-23 10:08:36 0 -rahs---- C:\IO.SYS
2008-05-23 10:08:36 0 --a------ C:\CONFIG.SYS
2008-05-23 10:08:36 0 --a------ C:\AUTOEXEC.BAT
2008-05-23 10:07:48 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-05-23 10:07:39 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-23 10:07:39 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-23 10:07:30 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-23 10:07:13 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-23 10:06:48 0 d---s---- C:\WINDOWS\Tasks
2008-05-23 10:06:47 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-23 10:06:44 0 d-------- C:\WINDOWS\srchasst
2008-05-23 10:06:43 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-23 10:06:37 0 d-------- C:\Program Files\Movie Maker
2008-05-23 10:06:31 0 d-------- C:\WINDOWS\system32\Restore
2008-05-23 10:05:59 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 10:05:46 0 d-------- C:\WINDOWS\Registration
2008-05-23 10:05:41 0 d-------- C:\Program Files\Online Services
2008-05-23 10:05:36 0 d-------- C:\Program Files\Messenger
2008-05-23 10:05:33 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-23 10:05:02 0 d-------- C:\Program Files\Windows NT
2008-05-23 10:05:00 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-23 10:04:58 0 d-------- C:\WINDOWS\system32\Com
2008-05-23 03:59:17 0 d--hs---- C:\WINDOWS\Installer
2008-05-23 03:59:16 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-23 03:59:13 0 dr------- C:\Program Files
2008-05-23 03:59:13 0 d-------- C:\Program Files\Common Files
2008-05-23 03:59:13 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-23 03:58:54 0 d--h----- C:\Documents and Settings\Default User\Templates <TEMPLA~1>
2008-05-23 03:58:54 0 dr------- C:\Documents and Settings\Default User\Start Menu <STARTM~1>
2008-05-23 03:58:54 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-23 03:58:54 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-05-23 03:58:54 0 d--h----- C:\Documents and Settings\Default User\PrintHood <PRINTH~1>
2008-05-23 03:58:54 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-05-23 03:58:54 0 d-------- C:\Documents and Settings\Default User\My Documents <MYDOCU~1>
2008-05-23 03:58:54 0 dr-h----- C:\Documents and Settings\Default User\Local Settings <LOCALS~1>
2008-05-23 03:58:54 0 d-------- C:\Documents and Settings\Default User\Favorites <FAVORI~1>
2008-05-23 03:58:54 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-05-23 03:58:54 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-05-23 03:58:54 0 d--h----- C:\Documents and Settings\All Users\Templates <TEMPLA~1>
2008-05-23 03:58:54 0 dr------- C:\Documents and Settings\All Users\Start Menu <STARTM~1>
2008-05-23 03:58:54 0 d-------- C:\Documents and Settings\All Users\Favorites <FAVORI~1>
2008-05-23 03:58:54 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-23 03:58:44 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-23 03:58:44 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-23 03:58:39 0 dr-h----- C:\Documents and Settings\Default User\Application Data <APPLIC~1>
2008-05-23 03:58:39 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-05-23 03:58:39 0 dr-h----- C:\Documents and Settings\All Users\Application Data <APPLIC~1>
2008-05-23 03:58:39 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-05-23 03:58:21 0 d--hs---- C:\System Volume Information
2008-05-23 03:58:21 0 d-------- C:\Documents and Settings
2008-05-23 03:52:45 0 d-------- C:\WINDOWS
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\WinSxS
2008-05-23 03:52:45 0 dr------- C:\WINDOWS\Web
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\twain_32
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\wins
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\wbem
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\usmt
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\spool
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\Setup
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\ras
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\oobe
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\npp
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\mui
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\IME
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\ias
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\export
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\drivers
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-23 03:52:45 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\config
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\3076
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\2052
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1054
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1042
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1041
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1037
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1033
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1031
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1028
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system32\1025
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\system
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\security
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Resources
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\repair
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Provisioning
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\PeerNet
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\pchealth
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\mui
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\msapps
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\msagent
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Media
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\java
2008-05-23 03:52:45 0 d--h----- C:\WINDOWS\inf
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\ime
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Help
2008-05-23 03:52:45 0 dr--s---- C:\WINDOWS\Fonts
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\ehome
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Driver Cache
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Debug
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Cursors
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\Config
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\AppPatch
2008-05-23 03:52:45 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-05-23 03:58:54 62 --ahs---- C:\Documents and Settings\Joe\Application Data\desktop.ini
2008-03-24 11:35:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2008-03-24 11:35:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2008-03-24 11:35:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2008-03-24 11:35:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2008-03-24 11:35:00 1482752 --a------ C:\WINDOWS\system32\nview.dll
2008-03-24 11:35:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2008-03-24 11:35:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2008-03-24 11:35:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [01/24/2008 06:35 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [03/24/2008 11:35 AM]
"nwiz"="nwiz.exe" [03/24/2008 11:35 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [03/24/2008 11:35 AM]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [04/10/2008 08:07 PM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [03/25/2008 04:28 AM]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [04/23/2008 02:57 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 05:12 PM]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 05:12 PM]
C:\Documents and Settings\Joe\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [3/16/2005 7:16:50 PM]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [1/21/2008 3:41:28 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 05/28/2008 12:32 PM 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
*Newly Created Service* - EAMON
*Newly Created Service* - EASDRV
*Newly Created Service* - EKRN
*Newly Created Service* - EPFW
*Newly Created Service* - EPFWTDI
-- End of Deckard's System Scanner: finished at 2008-06-08 09:22:36 ------------