Thanks Essexboy
Deckard's System Scanner v20071014.68
Run by Robert Edwards on 2008-08-01 18:31:27
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
24: 2008-08-01 17:31:38 UTC - RP557 - Deckard's System Scanner Restore Point
23: 2008-08-01 07:31:38 UTC - RP556 - System Checkpoint
22: 2008-07-31 00:59:59 UTC - RP555 - System Checkpoint
21: 2008-07-29 22:43:56 UTC - RP554 - System Checkpoint
20: 2008-07-28 21:48:45 UTC - RP553 - Revo Uninstaller's restore point - Security Task Manager 1.7f
-- First Restore Point --
1: 2008-07-08 00:46:09 UTC - RP534 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Robert Edwards.exe) --------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:33:27, on 01/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Cacheman\Cacheman.exe
C:\Program Files\USB Safely Remove\USBSafelyRemove.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\speakerguard\SpeakerGuard.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\Screensaver Control\ScreensaverControl.exe
C:\Program Files\Uniblue\ProcessLibrary\qaccess.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Robert Edwards\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Robert Edwards.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealOne Player\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe"
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe /hidden
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Cacheman] C:\PROGRA~1\Cacheman\Cacheman.exe
O4 - HKCU\..\Run: [USB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startup
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm &2 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zon...kr.cab56986.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.t...ivex/hcImpl.cabO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://go.divx.com/p...owserPlugin.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://flashcasino....-en/FlashAX.cabO16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.c...driveragent.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zon...er.cab56986.cabO18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 11071 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20070927-172429-789 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
backup-20080514-161511-111 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
backup-20080514-161511-321 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - (no file)
backup-20080514-161511-332 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.pics.bleu.ro/backup-20080514-161511-415 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.pics.bleu.ro/backup-20080514-161511-507 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
backup-20080514-161511-940 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
backup-20080516-001705-509 O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
backup-20080516-001705-993 O8 - Extra context menu item: Download with ImTOO Download YouTube Video - C:\Program Files\ImTOO\Download YouTube Video\upod_link.HTM
backup-20080708-012643-842 O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - Unknown owner - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe (file missing)
backup-20080708-012706-291 O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - Unknown owner - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe (file missing)
backup-20080708-140929-306 O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - Unknown owner - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe (file missing)
backup-20080708-140929-428 O20 - Winlogon Notify: efcYPjJy - efcYPjJy.dll (file missing)
backup-20080708-140929-614 O4 - HKLM\..\Run: [BM4f1e5dd8] Rundll32.exe "C:\WINDOWS\system32\nqypfmuh.dll",s
backup-20080708-140929-673 O2 - BHO: (no name) - {7E6B5923-3D2D-46DF-8B07-84F48BFB55EC} - C:\WINDOWS\system32\efcYPjJy.dll (file missing)
backup-20080708-140929-760 O4 - HKLM\..\Run: [4c2d6e44] rundll32.exe "C:\WINDOWS\system32\oissqjcd.dll",b
backup-20080708-140929-980 O2 - BHO: (no name) - {B6A12BD4-2AAE-4984-B784-8CE06A6237C8} - C:\WINDOWS\system32\fccyvSKe.dll (file missing)
backup-20080708-141114-730 O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - Unknown owner - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe (file missing)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 giveio - c:\windows\system32\giveio.sys
R0 speedfan - c:\windows\system32\speedfan.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R3 Dvd43 - c:\windows\system32\drivers\dvd43.sys <Not Verified; Fengtao Software Inc.; DVD43>
R3 Pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
S2 EZWINIT - c:\windows\system32\drivers\ezwinit.sys <Not Verified; USTC; anchor chips ezloader>
S2 EZWRITER - c:\windows\system32\drivers\ezwriter.sys
S3 FreshIO - c:\program files\freshdevices\freshdiagnose\freshio.sys (file missing)
S3 jgameenp - c:\docume~1\robert~1\locals~1\temp\jgameenp.sys (file missing)
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Diskeeper - "c:\program files\executive software\diskeeper\dkservice.exe" <Not Verified; Executive Software International, Inc.; Diskeeper Disk Defragmenter>
R2 FolderSize (Folder Size) - "c:\program files\foldersize\foldersizesvc.exe" <Not Verified; Brio; Folder Size for Windows>
R2 RioMSC (Rio MSC Manager) - c:\windows\system32\riomsc.exe <Not Verified; Digital Networks North America, Inc.; Rio Mass Storage Class Device Manager>
S3 ServiceLayer - "c:\program files\pc connectivity solution\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution>
S4 TUWinStylerThemeSvc (TuneUp WinStyler Theme Service) - "c:\program files\tuneup utilities 2006\winstylerthemesvc.exe" (file missing)
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia 5200
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 5200
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
-- Files created between 2008-07-01 and 2008-08-01 -----------------------------
2008-08-01 00:33:16 0 dr-h----- C:\Documents and Settings\Robert Edwards\Recent
2008-07-31 01:35:49 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\HouseCall 6.6
2008-07-29 11:41:05 0 d-------- C:\Documents and Settings\Robert Edwards\.housecall6.6
2008-07-27 12:38:21 0 d-------- C:\Program Files\AnVir Task Manager
2008-07-27 11:00:09 0 d-------- C:\Documents and Settings\LocalService\Application Data\SACore
2008-07-26 19:34:51 0 d-------- C:\Program Files\Common Files\McAfee
2008-07-26 19:34:08 0 d-------- C:\Program Files\McAfee
2008-07-26 02:32:14 217127 --a------ C:\WINDOWS\system32\drv43260.dll <Not Verified; RealNetworks, Inc.; RealVideo 9 (32-bit)>
2008-07-26 02:32:14 208935 --a------ C:\WINDOWS\system32\drv33260.dll <Not Verified; RealNetworks, Inc.; RealVideo 8 (32-bit)>
2008-07-26 02:32:14 176165 --a------ C:\WINDOWS\system32\drv23260.dll <Not Verified; RealNetworks, Inc.; RealVideo G2 (32-bit)>
2008-07-26 02:32:14 65602 --a------ C:\WINDOWS\system32\cook3260.dll <Not Verified; RealNetworks, Inc.; RealPlayer 10>
2008-07-26 02:32:13 626688 --a------ C:\WINDOWS\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2008-07-26 02:32:10 0 d-------- C:\Program Files\VSO
2008-07-10 13:03:50 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\USBSafelyRemove
2008-07-10 13:03:37 0 d-------- C:\Program Files\USB Safely Remove
2008-07-10 12:50:59 0 d-------- C:\Program Files\Sony
2008-07-10 12:50:30 0 d-------- C:\Program Files\Common Files\Sony Shared
2008-07-09 04:04:52 0 d-------- C:\Program Files\TweakNow WinSecret
2008-07-09 04:04:52 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\TweakNow WinSecret
2008-07-09 04:03:13 0 d-------- C:\Program Files\TweakNow RegCleaner Std
2008-07-07 20:38:46 0 d-------- C:\WINDOWS\Icons
2008-07-07 20:36:19 3407872 --a------ C:\Documents and Settings\Administrator\ntuser.dat
2008-07-07 20:36:15 18612224 --a------ C:\Documents and Settings\Robert Edwards\ntuser.dat
2008-07-07 20:35:37 405 --ahs---- C:\WINDOWS\system32\eKSvyccf.ini2
2008-07-07 19:50:24 0 d-------- C:\Program Files\TellyPrompter
2008-07-07 19:36:25 0 d-------- C:\Documents and Settings\LocalService\Desktop
2008-07-07 19:35:37 0 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-07-07 19:35:37 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-07 08:40:49 56108 --a------ C:\WINDOWS\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
2008-07-05 23:14:23 0 d-------- C:\Program Files\Blaze Media Pro
2008-07-05 23:14:08 0 d-------- C:\Documents and Settings\All Users\Application Data\{CFAB4006-0AE0-414D-866A-DCB2C46553CF}
2008-07-04 21:39:23 0 d-------- C:\Program Files\AVI DivX to DVD SVCD VCD Converter
2008-07-03 20:35:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-07-03 20:35:09 0 d-------- C:\Program Files\AOL Games
2008-07-02 23:56:35 0 d-------- C:\Program Files\ShrinkTo5Basic
-- Find3M Report ---------------------------------------------------------------
2008-08-01 18:24:35 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-00000009-00001102-00000002-00201102}.dat
2008-08-01 18:24:35 24 --a------ C:\WINDOWS\system32\DVCState-{00000000-00000000-00000009-00001102-00000002-00201102}.dat
2008-08-01 18:01:49 0 d-------- C:\Program Files\SpeedFan
2008-08-01 09:40:37 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\BitTorrent
2008-07-31 00:24:30 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Microgaming
2008-07-29 17:27:10 0 d-------- C:\Program Files\Avant Browser
2008-07-28 22:39:39 0 d-------- C:\Program Files\Yahoo!
2008-07-28 14:16:36 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\AVG7
2008-07-28 11:52:48 0 d-------- C:\Program Files\PowerISO
2008-07-28 01:11:41 0 d-------- C:\Program Files\ladbrokesMPP
2008-07-26 19:34:51 0 d-------- C:\Program Files\Common Files
2008-07-26 03:31:56 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Vso
2008-07-26 03:31:55 668 --a------ C:\Documents and Settings\Robert Edwards\Application Data\vso_ts_preview.xml
2008-07-26 03:13:05 0 d-------- C:\Program Files\SpywareBlaster
2008-07-26 03:11:54 0 d-------- C:\Program Files\a-squared Free
2008-07-09 15:13:48 2320000 --a------ C:\WINDOWS\system32\TUKernel.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-09 15:05:52 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 14:40:10 0 d-------- C:\Program Files\Paint.NET
2008-07-09 03:52:54 0 d-------- C:\Program Files\Full Tilt Poker
2008-07-07 17:05:03 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\VideoReDo-TVSuite
2008-07-04 17:50:16 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Audacity
2008-07-01 22:32:28 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Ashampoo
2008-06-30 19:36:10 0 d-------- C:\Program Files\GNU
2008-06-24 11:40:13 0 d-------- C:\Program Files\Recover Keys
2008-06-22 18:59:20 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Hyperionics
2008-06-22 18:54:31 0 d-------- C:\Program Files\CD Recovery Toolbox Free
2008-06-22 18:16:20 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\DNA
2008-06-22 18:12:09 0 d-------- C:\Program Files\Betfair
2008-06-16 19:08:25 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-14 15:28:49 3532 --a------ C:\drmHeader.bin
2008-06-13 20:56:06 0 d-------- C:\Documents and Settings\Robert Edwards\Application Data\Nokia Multimedia Player
2008-06-12 18:40:52 0 d-------- C:\Program Files\QuickTime Alternative
2008-06-11 17:05:31 0 d-------- C:\Program Files\JetAudio
2008-06-08 23:49:59 0 d-------- C:\Program Files\Java
2008-06-03 23:14:51 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-03 19:54:29 0 d-------- C:\Program Files\BitTorrent
2008-06-03 19:54:23 0 d-------- C:\Program Files\DNA
2008-05-28 00:16:44 61440 --a------ C:\WINDOWS\system32\NormalizeDSP.dll
2008-05-23 14:12:58 323584 --a------ C:\WINDOWS\system32\AudioGenie2.dll <Not Verified; Stefan Toengi; audiogenie Module>
2008-05-18 15:27:49 304 --a------ C:\WINDOWS\
[email protected]2008-05-16 11:49:12 20472 --a------ C:\Documents and Settings\Robert Edwards\Application Data\NMM-MetaData.db
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
23/07/2008 12:21 120608 --a------ c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupDelayer"="C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe" [16/03/2007 02:16]
"DVD43"="C:\PROGRA~1\DVDIDL~1\DVDIdlePro.exe" [03/08/2006 18:38]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [31/08/2007 12:01]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [14/04/2008 18:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cacheman"="C:\PROGRA~1\Cacheman\Cacheman.exe" [31/07/2003 15:13]
"USB Safely Remove"="C:\Program Files\USB Safely Remove\USBSafelyRemove.exe" [14/07/2008 19:07]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"NoAdminPage"=1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDIDL~1\DVDShell.dll [09/10/2004 15:18 49152]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [13/05/2008 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\fccyvSKe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PolicyAgent"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Cacheman"=C:\PROGRA~1\Cacheman\Cacheman.exe
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
"InkSaver"=C:\Program Files\InkSaver\InkSaver.exe hide
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"Disc Detector"=C:\Program Files\Creative\ShareDLL\CtNotify.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
-- Hosts -----------------------------------------------------------------------
127.0.0.1 babe.the-killer.bz
127.0.0.1 www.babe.the-killer.bz
127.0.0.1 babe.k-lined.com
127.0.0.1 www.babe.k-lined.com
127.0.0.1 did.i-used.cc
127.0.0.1 www.did.i-used.cc
127.0.0.1 coolwwwsearch.com
127.0.0.1 www.coolwwwsearch.com
127.0.0.1 coolwebsearch.com
127.0.0.1 www.coolwebsearch.com
9198 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-08-01 18:34:02 ------------