Ok, i've done the scan and here are the results:
Deckard's System Scanner v20071014.68
Run by Allen Liu on 2008-07-28 17:59:37
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
24: 2008-07-28 07:59:46 UTC - RP264 - Deckard's System Scanner Restore Point
23: 2008-07-27 07:07:47 UTC - RP263 - Software Distribution Service 3.0
22: 2008-07-23 08:27:07 UTC - RP262 - Software Distribution Service 3.0
21: 2008-07-23 08:04:31 UTC - RP261 - System Checkpoint
20: 2008-07-21 06:22:28 UTC - RP260 - System Checkpoint
-- First Restore Point --
1: 2008-06-26 11:05:02 UTC - RP241 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 448 MiB (512 MiB recommended).-- HijackThis (run as Allen Liu.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:03:40 PM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Allen Liu\Desktop\dss.exe
C:\WINDOWS\system32\u0NmE487.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Allen Liu.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [wosa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\woso.exe
O4 - HKLM\..\Run: [fysa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\fyso.exe
O4 - HKLM\..\Run: [jtsa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\jtso.exe
O4 - HKLM\..\Run: [wlsa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wlso.exe
O4 - HKLM\..\Run: [wgsa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wgso.exe
O4 - HKLM\..\Run: [wmsa] C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wmso.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\admin\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 7953 bytes
-- File Associations -----------------------------------------------------------
.reg - regfile - shell\open\command - regedit.exe "%1" %*.scr - scrfile - shell\open\command - "%1" %*-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 xfilt (VIA SATA IDE Hot-plug Driver) - c:\windows\system32\drivers\xfilt.sys <Not Verified; VIA Technologies,Inc; VIA filter driver>
S3 FETNDIS (VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver) - c:\windows\system32\drivers\fetnd5.sys (file missing)
S3 NPF (Netgroup Packet Filter) - c:\windows\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
S3 S3chipid - c:\docume~1\allenl~1\locals~1\temp\s3chipid.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 RichVideo (Cyberlink RichVideo Service(CRVS)) - "c:\program files\cyberlink\shared files\richvideo.exe" <Not Verified; ; RichVideo Module>
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
S3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer: ATK
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-07-28 18:00:16 350 --a------ C:\WINDOWS\Tasks\At43.job
2008-07-27 23:00:10 350 --a------ C:\WINDOWS\Tasks\At48.job
2008-07-27 22:00:10 350 --a------ C:\WINDOWS\Tasks\At47.job
2008-07-27 21:00:11 350 --a------ C:\WINDOWS\Tasks\At46.job
2008-07-27 20:00:10 350 --a------ C:\WINDOWS\Tasks\At45.job
2008-07-27 19:03:29 350 --a------ C:\WINDOWS\Tasks\At44.job
2008-07-27 17:04:37 350 --a------ C:\WINDOWS\Tasks\At42.job
2008-07-19 16:28:23 350 --a------ C:\WINDOWS\Tasks\At41.job
2008-07-16 15:14:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-07-16 15:00:00 350 --a------ C:\WINDOWS\Tasks\At40.job
2008-07-16 14:00:00 350 --a------ C:\WINDOWS\Tasks\At39.job
2008-07-16 13:03:29 350 --a------ C:\WINDOWS\Tasks\At38.job
2008-07-16 12:04:35 350 --a------ C:\WINDOWS\Tasks\At37.job
2008-07-13 00:46:00 350 --a------ C:\WINDOWS\Tasks\At25.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At36.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At35.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At34.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At33.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At32.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At31.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At30.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At29.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At28.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At27.job
2008-07-12 11:51:20 350 --a------ C:\WINDOWS\Tasks\At26.job
-- Files created between 2008-06-28 and 2008-07-28 -----------------------------
2008-07-27 22:41:31 0 d-------- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Mozilla
2008-07-27 21:54:18 0 d-------- C:\Program Files\Trend Micro
2008-07-23 18:26:30 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\Malwarebytes
2008-07-23 18:25:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-23 18:25:08 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-23 18:24:17 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-19 15:44:16 23 --a------ C:\Documents and Settings\Allen Liu\jagex_runescape_preferences.dat
2008-07-12 12:00:18 0 dr------- C:\Documents and Settings\NetworkService.NT AUTHORITY\Favorites
2008-07-12 11:51:17 35842 --a------ C:\WINDOWS\system32\u0NmE487.exe
2008-07-04 14:19:39 4682 --a------ C:\WINDOWS\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
2008-07-04 14:19:09 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-07-04 14:03:42 0 d--h----- C:\Documents and Settings\Allen Liu\Application Data\ijjigame
2008-06-28 22:40:35 0 d-------- C:\WINDOWS\system32\SolidStateNetworks
-- Find3M Report ---------------------------------------------------------------
2008-07-28 17:51:50 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\Skype
2008-07-28 17:50:12 0 d-------- C:\Program Files\Symantec AntiVirus
2008-07-23 22:00:13 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\LimeWire
2008-07-23 18:24:17 0 d-------- C:\Program Files\Common Files
2008-07-22 19:32:46 0 d-------- C:\Program Files\Online Services
2008-07-22 19:32:33 0 d-------- C:\Program Files\Windows NT
2008-07-22 17:45:18 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\Mozilla
2008-07-21 22:18:32 0 d-------- C:\Program Files\Winamp
2008-07-14 12:04:30 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\uTorrent
2008-07-07 20:52:13 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-28 22:40:36 1726 --a------ C:\WINDOWS\mozver.dat
2008-06-19 17:41:57 0 d-------- C:\Documents and Settings\Allen Liu\Application Data\Adobe
2008-05-10 15:33:51 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [03/09/2005 01:33 PM C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [03/13/2005 03:33 AM C:\WINDOWS\system32\VTTrayp.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [04/08/2005 03:52 PM]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [04/17/2005 12:30 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/02/2006 10:54 AM]
"wosa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\woso.exe" []
"fysa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\fyso.exe" []
"jtsa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\jtso.exe" []
"wlsa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wlso.exe" []
"wgsa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wgso.exe" []
"wmsa"="C:\DOCUME~1\ALLENL~1\LOCALS~1\Temp\wmso.exe" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/2006 03:40 PM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/23/2006 03:10 PM]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [12/05/2006 10:55 PM]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/03/2004 09:32 PM]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [08/23/2001 10:00 PM]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/03/2004 09:31 PM]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/03/2004 09:32 PM]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/03/2004 09:32 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [01/31/2008 10:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 12:10 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [03/18/2008 06:28 PM]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [07/21/2006 01:06 PM]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe" [03/16/2005 07:16 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{06E6B6B6-BE3C-6E23-6C8E-B833E2CE63B8}"= C:\Program Files\Internet Explorer\PLUGINS\BinNice.dll [ ]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^admin^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\admin\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VideoraiPodConverter]
C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe -t
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"IDriverT"=3 (0x3)
-- End of Deckard's System Scanner: finished at 2008-07-28 18:04:16 ------------