Deckard's System Scanner v20071014.68
Run by Owner on 2007-12-14 16:11:00
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
59: 2007-12-14 22:11:18 UTC - RP147 - Deckard's System Scanner Restore Point
58: 2007-12-11 23:10:01 UTC - RP146 - System Checkpoint
57: 2007-12-10 18:46:53 UTC - RP145 - System Checkpoint
56: 2007-12-09 17:33:15 UTC - RP144 - System Checkpoint
55: 2007-12-08 16:59:02 UTC - RP143 - System Checkpoint
-- First Restore Point --
1: 2007-10-12 21:54:18 UTC - RP89 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 448 MiB (512 MiB recommended).-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:12:39 PM, on 12/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\cron\cron.exe
C:\Program Files\CVSNT\cvslock.exe
C:\Program Files\CVSNT\cvsservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\Common Files\soft602\pdfSaver.exe
C:\Program Files\GiPo@Utilities\DesktopUtilities.3\m2tray.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Pegtop\PStart\PStart.exe
C:\Program Files\LeechGet 2006\LeechGet.exe
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe
C:\Program Files\SlickRun\sr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Software by Design\StayLive.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\java.exe
C:\PROGRA~1\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Netscape ISP Dialer\LiteDialer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Netscape ISP Dialer\aoltpsdL.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Owner\Desktop\dss\dss.exe
C:\PROGRA~1\Trend Micro\HijackThis\Owner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [602PC SUITE PDF Saver] "C:\Program Files\Common Files\soft602\pdfSaver.exe"
O4 - HKLM\..\Run: [m2tray] C:\Program Files\GiPo@Utilities\DesktopUtilities.3\m2tray.exe /s
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [music SUBST] C:\sub.bat
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [PegtopPStart] C:\Program Files\Pegtop\PStart\PStart.exe
O4 - HKCU\..\Run: [LeechGet] "C:\Program Files\LeechGet 2006\LeechGet.exe" -intray
O4 - HKCU\..\Run: [pdfSaver3] "C:\Program Files\PDF\pdfSaver\pdfSaver3.exe"
O4 - HKCU\..\Run: [SlickRun] "C:\Program Files\SlickRun\sr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: run_startmenu.cmd
O4 - Global Startup: StayAlive.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: Download using LeechGet -
file://C:\Program Files\LeechGet 2006\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard -
file://C:\Program Files\LeechGet 2006\\Wizard.html
O8 - Extra context menu item: Parse with LeechGet -
file://C:\Program Files\LeechGet 2006\\Parser.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) -
http://entriq.vo.llnwd.net/o1/NBCUniver ... _0_0_5.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{4938DB19-FBE8-44D4-9EAD-FD9AAF6B63C4}: NameServer = 205.188.146.145
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB6C7B86-822A-4255-83AE-3B11E9F7EB83}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: cron - nnSoft - C:\Program Files\cron\cron.exe
O23 - Service: CVSNT Locking Service 2.5.03.2382 (CVSLock) - Unknown owner - C:\Program Files\CVSNT\cvslock.exe
O23 - Service: CVSNT Dispatch service 2.5.03.2382 (cvsnt) - March Hare Software Ltd - C:\Program Files\CVSNT\cvsservice.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9036 bytes
-- File Associations -----------------------------------------------------------
.txt - txtfile - DefaultIcon - C:\Program Files\Win32Pad\win32pad.exe,0.txt - txtfile - shell\open\command - C:\Program Files\Win32Pad\win32pad.exe "%L"-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R3 EuMusDesignVirtualAudioCableWdm (Virtual Audio Cable (WDM)) - c:\windows\system32\drivers\vrtaucbl.sys <Not Verified; Eugene V. Muzychenko; Virtual Audio Cable>
R3 msvad_simple (SoliCall) - c:\windows\system32\drivers\solicall.sys <Not Verified; SoliCall; Driver>
R3 SunkFilt (Alcor Micro Corp - 9360) - c:\windows\system32\drivers\sunkfilt.sys <Not Verified; Alcor Micro Corp.; SunkFilt>
S3 SunkFilt39 (Alcor Micro Corp - 3239) - c:\windows\system32\drivers\sunkfilt39.sys <Not Verified; Alcor Micro Corp.; SunkFilt39>
S3 Sunkfiltp (HP && Alcor Micro Corp for Phison) - c:\windows\system32\drivers\sunkfiltp.sys (file missing)
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - c:\program files\gizmo project\mdnsresponder.exe <Not Verified; Apple Computer, Inc.; Bonjour>
R2 cron - c:\program files\cron\cron.exe <Not Verified; nnSoft; nnCron LITE>
R2 CVSLock (CVSNT Locking Service 2.5.03.2382) - "c:\program files\cvsnt\cvslock.exe"
R2 cvsnt (CVSNT Dispatch service 2.5.03.2382) - "c:\program files\cvsnt\cvsservice.exe" <Not Verified; March Hare Software Ltd; cvsnt>
R2 UPHClean (User Profile Hive Cleanup) - c:\program files\uphclean\uphclean.exe <Not Verified; Microsoft Corporation; User Profile Hive Cleanup Service>
S3 Imapi Helper - "c:\program files\alex feinman\iso recorder\imapihelper.exe" <Not Verified; Alex Feinman; ISO Recorder>
S4 GCALDaemon - "c:\program files\gcaldaemon\bin\wrapper.exe" -s "c:\program files\gcaldaemon\conf\nt-service.cfg"
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-12-11 09:55:37 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2007-11-14 and 2007-12-14 -----------------------------
2007-12-11 11:40:40 0 d-------- C:\Program Files\Trend Micro
2007-12-11 10:12:33 0 d-------- C:\Documents and Settings\Owner\Application Data\TrojanHunter
2007-12-10 20:41:50 0 d-------- C:\Program Files\a-squared Free
2007-12-10 19:15:01 0 d-------- C:\Documents and Settings\Owner\.housecall6.6
2007-12-10 17:02:40 0 d-------- C:\Program Files\TrojanHunter 5.0
2007-12-10 15:53:03 0 dr-h----- C:\Documents and Settings\Owner\Recent
2007-12-03 19:51:23 0 d-------- C:\Program Files\TortoiseCVS
2007-12-03 15:48:44 0 d-------- C:\Documents and Settings\Owner\Application Data\Subversion
2007-12-03 15:47:57 0 d-------- C:\Program Files\TortoiseSVN
2007-11-26 14:46:24 0 d-------- C:\Documents and Settings\Owner\Bluetooth Software
2007-11-26 14:42:32 0 d-------- C:\Program Files\WIDCOMM
2007-11-26 14:36:35 67384 -ra------ C:\WINDOWS\system32\drivers\btwusb.sys <Not Verified; Broadcom Corporation.; Bluetooth Software 5.1.0.1400>
2007-11-26 14:36:24 77824 -ra------ C:\WINDOWS\system32\btw_ci.dll <Not Verified; Broadcom Corporation.; Bluetooth Software 5.1.0.1400>
2007-11-20 18:02:36 0 d-------- C:\My Web Sites
2007-11-20 18:01:51 0 d-------- C:\Program Files\WinHTTrack
2007-11-20 15:39:08 0 d-------- C:\Program Files\MSECache
2007-11-16 09:16:17 0 d-------- C:\Program Files\Apple Software Update
2007-11-16 09:13:49 0 d-------- C:\Program Files\On Hand Software
-- Find3M Report ---------------------------------------------------------------
2007-12-14 15:30:34 0 d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-12-14 15:29:12 0 d-------- C:\Program Files\cron
2007-12-11 15:54:29 0 d-------- C:\Program Files\Mozilla Thunderbird
2007-12-11 15:01:56 0 d-------- C:\Program Files\cvsnt
2007-12-11 10:40:53 0 d-------- C:\Program Files\Common Files
2007-12-01 17:27:40 0 d-------- C:\Program Files\Gizmo Project
2007-11-26 23:11:27 0 d-------- C:\Documents and Settings\Owner\Application Data\SlickRun
2007-11-16 10:20:42 0 d-------- C:\Documents and Settings\Owner\Application Data\Apple Computer
2007-11-16 09:19:05 0 d-------- C:\Program Files\QuickTime
2007-11-12 21:51:02 0 d-------- C:\Program Files\cg4ie
2007-11-12 19:41:52 0 d-------- C:\Documents and Settings\Owner\Application Data\GmailNotifier.Net
2007-11-12 19:32:06 0 d-------- C:\Program Files\GmailNotifer.NET
2007-11-11 22:39:09 0 d-------- C:\Program Files\WinSCP
2007-11-10 19:37:18 0 d-------- C:\Program Files\XMLTV GUI
2007-11-10 19:35:12 0 d-------- C:\Documents and Settings\Owner\Application Data\VSRevoGroup
2007-11-10 19:33:14 0 d-------- C:\Program Files\VS Revo Group
2007-11-08 19:18:16 0 d-------- C:\Documents and Settings\Owner\Application Data\Netscape ISP Dialer
2007-11-08 19:18:14 0 d-------- C:\Program Files\Netscape ISP Dialer
2007-11-04 16:30:25 0 d-------- C:\Program Files\USB Detect and Launch
2007-11-03 00:25:15 0 d-------- C:\Program Files\Winamp
2007-10-23 08:56:51 0 d-------- C:\Documents and Settings\Owner\Application Data\uTorrent
2007-10-20 23:35:12 0 d-------- C:\Program Files\Java
2007-10-18 21:42:14 0 d-------- C:\Program Files\Miranda IM
2007-10-13 23:08:48 0 --a------ C:\WINDOWS\system32\Gnostice Print2eDoc Port
2007-09-19 21:36:36 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [01/24/2006 05:07 PM 220672]
[-HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/13/2002 02:42 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [07/12/2004 03:50 AM]
"nwiz"="nwiz.exe" [07/12/2004 03:50 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [07/12/2004 03:50 AM]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 01:50 PM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [10/31/2003 09:42 PM]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [10/18/2004 04:05 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [10/25/2007 07:23 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 12:11 AM]
"Lexmark 5200 series"="C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe" [06/04/2004 05:58 AM]
"602PC SUITE PDF Saver"="C:\Program Files\Common Files\soft602\pdfSaver.exe" [08/31/2005 04:00 PM]
"m2tray"="C:\Program Files\GiPo@Utilities\DesktopUtilities.3\m2tray.exe" [04/17/2005 05:01 PM]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [06/03/2004 10:51 PM]
"music SUBST"="C:\sub.bat" [06/28/2007 03:35 PM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [09/06/2007 03:14 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PegtopPStart"="C:\Program Files\Pegtop\PStart\PStart.exe" [02/04/2007 02:09 AM]
"LeechGet"="C:\Program Files\LeechGet 2006\LeechGet.exe" [04/25/2006 02:25 PM]
"pdfSaver3"="C:\Program Files\PDF\pdfSaver\pdfSaver3.exe" [05/19/2004 02:29 PM]
"SlickRun"="C:\Program Files\SlickRun\sr.exe" [03/21/2007 01:59 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 01:00 PM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 03:45 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 9:05:26 PM]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [10/9/2005 1:16:54 AM]
run_startmenu.cmd [10/11/2004 10:20:38 PM]
StayAlive.lnk - C:\Program Files\Software by Design\StayLive.exe [5/23/2007 1:23:35 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"=1 (0x1)
"NoDispScrSavPage"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispScrSavPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuPinnedList"=1 (0x1)
"StartMenuFavorites"=0 (0x0)
"Start_ShowHelp"=0 (0x0)
"Start_ShowMyComputer"=1 (0x1)
"Start_ShowMyDocs"=1 (0x1)
"Start_ShowMyMusic"=0 (0x0)
"Start_ShowMyPics"=0 (0x0)
"Start_ShowNetConn"=0 (0x0)
"Start_ShowPrinters"=1 (0x1)
"Start_ShowRun"=1 (0x1)
"Start_ShowSearch"=1 (0x1)
"NoStartMenuMFUprogramsList"=1 (0x1)
"NoUserNameInStartMenu"=1 (0x1)
"NoRemoteRecursiveEvents"=1 (0x1)
"MemCheckBoxInRunDlg"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
"NoSMMyDocs"=01000000
"NoSMMyPictures"=01000000
"NoNetworkConnections"=01000000
"NoSMConfigurePrograms"=1 (0x1)
"NoStartMenuMFUprogramsList"=1 (0x1)
"NoUserNameInStartMenu"=1 (0x1)
"StartMenuLogoff"=0 (0x0)
"MemCheckBoxInRunDlg"=1 (0x1)
"NoSharedDocuments"=1 (0x1)
"NoActiveDesktop"=1 (0x1)
"ForceClassicControlPanel"=1 (0x1)
"NoStrCmpLogical"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TaskMgr.exe]
Debugger=C:\WINDOWS\system32\dtaskmanager.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 setuid
-- End of Deckard's System Scanner: finished at 2007-12-14 16:14:02 ------------