Deckard's System Scanner v20071014.68
Run by Kristoff on 2007-12-05 15:39:05
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
11: 2007-12-05 13:34:56 UTC - RP31 - Installed AVG 7.5
10: 2007-12-02 20:31:43 UTC - RP30 - Scheduled Checkpoint
9: 2007-12-01 08:43:59 UTC - RP29 - Windows Update
8: 2007-11-29 21:52:21 UTC - RP28 - Installed Macromedia Dreamweaver 8
7: 2007-11-28 11:02:11 UTC - RP27 - Windows Update
-- First Restore Point --
1: 2007-11-23 19:50:56 UTC - RP20 - Device Driver Package Install: Microsoft Microsoft Common Controller For Windows Class
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 1022 MiB (1024 MiB recommended).-- HijackThis (run as Kristoff.exe) --------------------------------------------
logfile has no content; running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-12-05 15:40:19
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal
Running processes:
C:\Windows\System32\dwm.exe
C:\Windows\System32\taskeng.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Windows\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\SearchFilterHost.exe
C:\Users\Kristoff\Documents\Downloads\dss.exe
C:\Program Files\Trend Micro\HijackThis\Kristoff.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.winningelevenblog.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11926E4A-BECE-4512-B77C-23A3D2B2481A} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SNM] "C:\Program Files\SpyNoMore\SNM.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\system32\vtsqn.dll,c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} () -
http://www.update.microsoft.com/windows ... 3416061234O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shoc ... wflash.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00A80AD.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\system32\avgwlntf.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATI Smart - Unknown owner - C:\Windows\System32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgrssvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 7382 bytes
-- File Associations -----------------------------------------------------------
.js - JSFile - DefaultIcon - "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe",2-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SASDIFSV - \??\c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - \??\c:\program files\superantispyware\saskutil.sys
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R3 3xHybrid (Philips SAA713x PCI Card) - c:\windows\system32\drivers\3xhybrid.sys <Not Verified; Philips Semiconductors GmbH; Philips Semiconductors 3xHybrid>
S3 SASENUM - \??\c:\program files\superantispyware\sasenum.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 CLCapSvc (CyberLink Background Capture Service (CBCS)) - "c:\program files\home cinema\powercinema\kernel\tv\clcapsvc.exe" <Not Verified; ; CLCapSvc Module>
R2 CLSched (CyberLink Task Scheduler (CTS)) - "c:\program files\home cinema\powercinema\kernel\tv\clsched.exe" <Not Verified; ; CLSched Module>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 RichVideo (Cyberlink RichVideo Service(CRVS)) - "c:\program files\cyberlink\shared files\richvideo.exe" <Not Verified; ; RichVideo Module>
S2 CyberLink Media Library Service - "c:\program files\home cinema\powercinema\kernel\clml_ntservice\clmlserver.exe" <Not Verified; Cyberlink; Cyberlink Media Library Server>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S3 WLSetupSvc (Windows Live Setup Service) - "c:\program files\windows live\installer\wlsetupsvc.exe" <Not Verified; Microsoft Corporation; Windows Live installer>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID:
Description: Bluetooth Peripheral Device
Device ID: BTHENUM\{00000002-0000-1000-8000-0002EE000002}_VID&00000000_PID&C039\7&4BE3142&0&001963EC9BCC_C00000000
Manufacturer:
Name: Bluetooth Peripheral Device
PNP Device ID: BTHENUM\{00000002-0000-1000-8000-0002EE000002}_VID&00000000_PID&C039\7&4BE3142&0&001963EC9BCC_C00000000
Service:
-- Scheduled Tasks -------------------------------------------------------------
2007-11-29 19:03:05 284 --a------ C:\Windows\Tasks\AppleSoftwareUpdate.job
-- Files created between 2007-11-05 and 2007-12-05 -----------------------------
2007-12-05 13:35:23 0 d-------- C:\Users\All Users\Grisoft
2007-12-04 00:30:44 0 d-------- C:\Users\All Users\Avg7
2007-12-04 00:21:35 0 d-------- C:\Updates
2007-12-03 22:58:51 766464 --a------ C:\Windows\system32\Fireside_Christmas_3D_Screensaver.scr <Not Verified; 3Planesoft; Fireside Christmas 3D Screensaver>
2007-12-03 22:58:51 8421376 --a------ C:\Windows\system32\Fireside Christmas 3D Screensaver.exe <Not Verified; 3Planesoft; Fireside Christmas 3D Screensaver>
2007-12-03 22:58:51 0 d-------- C:\Program Files\Fireside Christmas 3D Screensaver
2007-12-03 22:56:52 780288 --a------ C:\Windows\system32\Fireplace_3D_Screensaver.scr <Not Verified; 3Planesoft; Fireplace 3D Screensaver>
2007-12-03 22:56:52 3451392 --a------ C:\Windows\system32\Fireplace 3D Screensaver.exe <Not Verified; 3Planesoft; Fireplace 3D Screensaver>
2007-12-03 22:56:52 0 d-------- C:\Program Files\Fireplace 3D Screensaver
2007-12-03 22:56:17 799744 --a------ C:\Windows\system32\Tropical_Fish_3D_Screensaver.scr <Not Verified; 3Planesoft; Tropical Fish 3D Screensaver>
2007-12-03 22:56:17 7265792 --a------ C:\Windows\system32\Tropical Fish 3D Screensaver.exe <Not Verified; 3Planesoft; Tropical Fish 3D Screensaver>
2007-12-03 22:56:17 0 d-------- C:\Program Files\Tropical Fish 3D Screensaver
2007-12-03 22:55:43 413696 --a------ C:\Windows\system32\3Planesoft_Screensaver_Manager.scr <Not Verified; 3Planesoft; 3Planesoft Screensaver Manager>
2007-12-03 22:55:43 0 d-------- C:\Windows\system32\3Planesoft
2007-12-03 22:55:43 0 d-------- C:\Program Files\3Planesoft Screensaver Manager
2007-12-03 22:55:40 8933376 --a------ C:\Windows\system32\Watermill 3D Screensaver.exe <Not Verified; 3Planesoft; Watermill 3D Screensaver>
2007-12-03 22:55:39 782848 --a------ C:\Windows\system32\Watermill_3D_Screensaver.scr <Not Verified; 3Planesoft; Watermill 3D Screensaver>
2007-12-03 22:55:39 0 d-------- C:\Program Files\Watermill 3D Screensaver
2007-12-03 22:01:20 32 --a------ C:\Windows\go
2007-12-03 22:01:17 0 d-------- C:\Windows\vf_hip
2007-12-03 22:01:16 0 d-------- C:\Program Files\Hide IP Platinum
2007-12-02 00:06:06 0 d-------- C:\Program Files\High-Logic
2007-11-23 20:11:00 0 d-------- C:\Users\All Users\Nero
2007-11-23 20:11:00 0 d-------- C:\Program Files\Common Files\Nero
2007-11-23 16:02:19 0 d-------- C:\Windows\system32\E177E04D548C4006A465EEB92D3DE021
2007-11-23 16:01:44 0 d-------- C:\Users\All Users\Ipswitch
2007-11-23 16:01:41 0 d-------- C:\Program Files\Ipswitch
2007-11-23 14:47:44 0 d-------- C:\Program Files\DVDlabPro2
2007-11-23 00:51:48 32 --a------ C:\Users\All Users\ezsid.dat
2007-11-22 20:55:03 0 d-------- C:\Users\Kristoff\Fonts
2007-11-22 20:45:40 0 d-------- C:\Users\All Users\Adobe Systems
2007-11-22 20:28:41 0 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-11-22 11:59:22 0 d-------- C:\Program Files\PSCS2
2007-11-21 11:16:23 0 d-------- C:\Program Files\Trend Micro
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Templates
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Start Menu
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\SendTo
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Recent
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\PrintHood
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\NetHood
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\My Documents
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Local Settings
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Cookies
2007-11-20 21:52:42 0 d--hs---- C:\Users\Mcx1\Application Data
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Videos
2007-11-20 21:52:41 0 d-------- C:\Users\Mcx1\Saved Games
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Pictures
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Music
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Links
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Favorites
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Downloads
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Documents
2007-11-20 21:52:41 0 dr------- C:\Users\Mcx1\Desktop
2007-11-20 21:52:41 0 d--h----- C:\Users\Mcx1\AppData
2007-11-20 21:52:40 524288 --a------ C:\Users\Mcx1\NTUSER.DAT
2007-11-20 21:08:05 0 d-------- C:\Windows\Panther
2007-11-20 21:06:07 0 d-------- C:\Windows\system32\OEM
2007-11-20 21:06:07 59 --a------ C:\Windows\DELL_VERSION
2007-11-20 20:57:15 0 d--h----- C:\$WINDOWS.~Q
2007-11-20 20:53:22 0 d--h----- C:\$INPLACE.~TR
2007-11-20 18:17:47 0 d-------- C:\Program Files\Frameworkx
2007-11-20 17:21:32 0 d-------- C:\Program Files\MSXML 4.0
2007-11-20 15:27:42 0 d-------- C:\Program Files\PowerISO
2007-11-20 14:53:51 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2007-11-20 14:52:52 0 d-------- C:\Program Files\SUPERAntiSpyware
2007-11-20 14:51:36 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-20 14:10:54 0 d-------- C:\Windows\PCHEALTH
2007-11-20 14:07:48 0 dr------- C:\Users\Kristoff\Searches
2007-11-20 14:05:58 171136 -rahs---- C:\grldr
2007-11-20 13:53:36 22668 --a------ C:\Windows\system32\emptyregdb.dat
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Videos
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\Templates
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\Start Menu
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\SendTo
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Saved Games
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\Recent
2007-11-20 13:19:25 0 d--h----- C:\Users\Kristoff\PrintHood
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Pictures
2007-11-20 13:19:25 2359296 --ahs---- C:\Users\Kristoff\ntuser.dat
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\NetHood
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\My Documents
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Music
2007-11-20 13:19:25 0 d--h----- C:\Users\Kristoff\Local Settings
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Links
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Favorites
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Downloads
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Documents
2007-11-20 13:19:25 0 dr------- C:\Users\Kristoff\Desktop
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\Cookies
2007-11-20 13:19:25 0 d--hs---- C:\Users\Kristoff\Application Data
2007-11-20 13:19:25 0 d--h----- C:\Users\Kristoff\AppData
2007-11-20 13:17:55 0 d-------- C:\Windows\system32\URTTEMP
2007-11-20 13:17:48 0 d--hs---- C:\Windows\Installer
2007-11-20 13:14:59 2428 --a------ C:\Windows\bthservsdp.dat
2007-11-20 13:14:28 0 --a------ C:\Windows\system32\atiicdxx.dat
2007-11-20 13:14:17 882688 -ra------ C:\Windows\system32\drivers\3xHybrid.sys <Not Verified; Philips Semiconductors GmbH; Philips Semiconductors 3xHybrid>
2007-11-20 13:14:17 3072 -ra------ C:\Windows\system32\34CoInstaller.dll
2007-11-20 13:12:33 0 d-------- C:\Windows\Debug
2007-11-20 13:12:33 0 d-------- C:\Windows\CSC
2007-11-20 13:09:22 0 d-------- C:\Windows\Prefetch
2007-11-20 12:49:24 0 d--hs---- C:\Boot
2007-11-20 08:13:33 1152 --a------ C:\Windows\system32\windrv.sys
2007-11-16 12:44:38 0 d-------- C:\Program Files\Skype
2007-11-16 12:44:38 0 d-------- C:\Program Files\Common Files\Skype
2007-11-16 12:44:29 0 d-------- C:\Users\All Users\Skype
2007-11-14 19:09:11 0 d-------- C:\Program Files\Google
2007-11-12 23:18:02 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-12 23:17:55 0 d-------- C:\Program Files\Windows Live
2007-11-12 23:17:47 0 d-------- C:\Users\All Users\WLInstaller
2007-11-10 15:33:14 0 d-------- C:\Program Files\VirtualDJ
2007-11-08 22:40:10 0 d-------- C:\Program Files\iPod
2007-11-08 22:40:07 0 d-------- C:\Program Files\iTunes
2007-11-08 17:26:39 40 --a------ C:\Users\Kristoff\language.dat
2007-11-06 15:35:10 0 d-------- C:\Users\All Users\Macromedia
2007-11-06 15:35:04 0 d-------- C:\Program Files\Common Files\Macromedia
2007-11-06 15:35:03 0 d-------- C:\Program Files\Macromedia
-- Find3M Report ---------------------------------------------------------------
2007-12-05 13:54:55 0 d-------- C:\Users\Kristoff\AppData\Roaming\AVG7
2007-12-04 15:35:11 0 d-------- C:\Users\Kristoff\AppData\Roaming\Skype
2007-12-04 15:35:08 0 d-------- C:\Users\Kristoff\AppData\Roaming\skypePM
2007-12-04 00:13:34 0 d-------- C:\Users\Kristoff\AppData\Roaming\Azureus
2007-11-29 21:57:54 0 d-------- C:\Users\Kristoff\AppData\Roaming\Macromedia
2007-11-23 20:16:21 0 d-------- C:\Users\Kristoff\AppData\Roaming\Nero
2007-11-23 20:11:00 0 d-------- C:\Program Files\Nero
2007-11-23 20:11:00 0 d-------- C:\Program Files\Common Files
2007-11-23 16:02:03 0 d-------- C:\Users\Kristoff\AppData\Roaming\Ipswitch
2007-11-23 16:01:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-23 00:04:38 0 d-------- C:\Users\Kristoff\AppData\Roaming\X10 Commander
2007-11-22 21:22:57 0 d-------- C:\Users\Kristoff\AppData\Roaming\Opera
2007-11-22 20:46:28 0 d-------- C:\Users\Kristoff\AppData\Roaming\Adobe
2007-11-22 20:29:05 0 d-------- C:\Program Files\Common Files\Adobe
2007-11-22 11:59:29 0 d-------- C:\Program Files\Common Files\InstallShield
2007-11-20 17:54:15 174 --ahs---- C:\Program Files\desktop.ini
2007-11-20 17:50:58 0 d-------- C:\Program Files\Windows Calendar
2007-11-20 17:50:55 0 d-------- C:\Program Files\Windows Mail
2007-11-20 17:50:47 0 d-------- C:\Program Files\Windows Defender
2007-11-20 14:52:51 0 d-------- C:\Users\Kristoff\AppData\Roaming\SUPERAntiSpyware.com
2007-11-20 13:40:51 0 d-------- C:\Users\Kristoff\AppData\Roaming\Thunderbird
2007-11-20 13:40:49 0 d-------- C:\Users\Kristoff\AppData\Roaming\Sun
2007-11-20 13:40:48 0 d-------- C:\Users\Kristoff\AppData\Roaming\Sports Interactive
2007-11-20 13:40:47 0 d-------- C:\Users\Kristoff\AppData\Roaming\Real
2007-11-20 13:40:46 0 d-------- C:\Users\Kristoff\AppData\Roaming\Mozilla
2007-11-20 13:40:42 0 d-------- C:\Users\Kristoff\AppData\Roaming\MailWasherPro
2007-11-20 13:40:39 0 d-------- C:\Users\Kristoff\AppData\Roaming\Identities
2007-11-20 13:40:39 0 d-------- C:\Users\Kristoff\AppData\Roaming\Google
2007-11-20 13:40:39 0 d-------- C:\Users\Kristoff\AppData\Roaming\CyberLink
2007-11-20 13:40:38 0 d-------- C:\Users\Kristoff\AppData\Roaming\Bookmarks
2007-11-20 13:40:37 0 d-------- C:\Users\Kristoff\AppData\Roaming\ATI
2007-11-20 13:40:36 0 d-------- C:\Users\Kristoff\AppData\Roaming\Apple Computer
2007-11-20 13:40:36 0 d-------- C:\Users\Kristoff\AppData\Roaming\Ahead
2007-11-20 13:32:03 0 d--h----- C:\Program Files\Zero G Registry
2007-11-20 13:32:03 0 d-------- C:\Program Files\Xvid
2007-11-20 13:32:01 0 d-------- C:\Program Files\WebCamDV
2007-11-20 13:31:47 0 d-------- C:\Program Files\Sports Interactive
2007-11-20 13:31:46 0 d-------- C:\Program Files\Samsung
2007-11-20 13:31:40 0 d-------- C:\Program Files\Real
2007-11-20 13:31:39 0 d-------- C:\Program Files\QuickTime
2007-11-20 13:31:29 0 d-------- C:\Program Files\MSN Gaming Zone
2007-11-20 13:31:29 0 d-------- C:\Program Files\Mozilla Thunderbird
2007-11-20 13:31:24 0 d-------- C:\Program Files\Microsoft.NET
2007-11-20 13:31:24 0 d-------- C:\Program Files\Microsoft Works
2007-11-20 13:30:53 0 d-------- C:\Program Files\microsoft frontpage
2007-11-20 13:30:53 0 d-------- C:\Program Files\Microsoft ActiveSync
2007-11-20 13:30:53 0 d-------- C:\Program Files\MailWasher
2007-11-20 13:30:53 0 d-------- C:\Program Files\MagicISO
2007-11-20 13:30:22 0 d-------- C:\Program Files\Java
2007-11-20 13:29:58 0 d-------- C:\Program Files\Home Cinema
2007-11-20 13:28:31 0 d-------- C:\Program Files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2007-11-20 13:28:30 0 d-------- C:\Program Files\CyberLink
2007-11-20 13:28:30 0 d-------- C:\Program Files\CopyPod
2007-11-20 13:28:30 0 d-------- C:\Program Files\Common Files\xing shared
2007-11-20 13:28:30 0 d-------- C:\Program Files\Common Files\X10
2007-11-20 13:28:29 0 d-------- C:\Program Files\Common Files\Real
2007-11-20 13:28:27 0 d-------- C:\Program Files\Common Files\ODBC
2007-11-20 13:28:27 0 d-------- C:\Program Files\Common Files\MSSoap
2007-11-20 13:28:22 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2007-11-20 13:28:22 0 d-------- C:\Program Files\Common Files\LightScribe
2007-11-20 13:28:21 0 d-------- C:\Program Files\Common Files\Java
2007-11-20 13:28:20 0 d-------- C:\Program Files\Common Files\Download Manager
2007-11-20 13:28:20 0 d-------- C:\Program Files\Common Files\Control Panels
2007-11-20 13:28:04 0 d-------- C:\Program Files\Common Files\Apple
2007-11-20 13:28:04 0 d-------- C:\Program Files\Common Files\Ahead
2007-11-20 13:25:02 0 d-------- C:\Program Files\Bonjour
2007-11-20 13:25:02 0 d-------- C:\Program Files\Azureus
2007-11-20 13:25:02 0 d-------- C:\Program Files\ATI Technologies
2007-11-20 13:24:50 0 d-------- C:\Program Files\Apple Software Update
2007-11-20 13:24:46 0 d-------- C:\Program Files\Alwil Software
2007-11-13 13:46:22 0 d-------- C:\Program Files\MSN Messenger
2007-10-26 20:29:00 114 --a------ C:\Users\Kristoff\AppData\Roaming\Default.PLS
2007-10-26 15:59:12 0 d-------- C:\Program Files\Windows Media Connect 2
2007-09-16 20:54:32 720 --a------ C:\Windows\mozver.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11926E4A-BECE-4512-B77C-23A3D2B2481A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [20/11/2007 17:36]
"BluetoothAuthenticationAgent"="rundll32.exe" [02/11/2006 09:45 C:\Windows\System32\rundll32.exe]
"SNM"="C:\Program Files\SpyNoMore\SNM.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [25/09/2007 00:11]
"SoundMan"="SOUNDMAN.EXE" [09/03/2007 16:28 C:\Windows\SOUNDMAN.EXE]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/11/2007 18:36]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [01/03/2007 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [20/09/2007 09:51]
"NWEReboot"="" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [05/12/2007 13:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18/10/2007 11:34]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [02/11/2006 12:34]
"cmds"="C:\WINDOWS\system32\vtsqn.dll,c" []
C:\Users\Kristoff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [16/03/2005 19:16:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 05/12/2007 13:35 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c00A80AD.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
WudfServiceGroup WUDFSvc
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGMFX86
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2007-12-05 15:41:48 ------------