MAIN
Deckard's System Scanner v20071014.68
Run by Owner on 2008-07-18 12:00:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; System Restore is disabled (service is not running).
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:02:17, on 7/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\igfxtray.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
G:\Owner.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C34E990-5488-47F2-9313-E355BED3EFED} - c:\windows\system32\acluif.dll
O2 - BHO: (no name) - {FF2F5D95-F03C-4476-AA7F-1778A0957A68} - C:\WINDOWS\system32\atmlibe.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06BA04B9-8C93-4D84-8759-D68DEA6BC870}: NameServer = 10.10.251.246,209.166.161.120
O20 - Winlogon Notify: qffspoux - C:\WINDOWS\SYSTEM32\acluif.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
--
End of file - 6441 bytes
-- HijackThis Fixed Entries (G:\\backups\) -------------------------------------
backup-20080718-093010-963 O2 - BHO: QXK Olive - {21461821-DED9-4D67-BE47-C9800C50B7FE} - C:\WINDOWS\wbxdpgfeovl.dll (file missing)
backup-20080718-093011-391 O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
backup-20080718-093012-310 O2 - BHO: (no name) - {5C34E990-5488-47F2-9313-E355BED3EFED} - c:\windows\system32\acluif.dll
backup-20080718-093015-866 O2 - BHO: (no name) - {B4DE7115-2664-4275-9BEF-72A9B618584D} - C:\WINDOWS\system32\ssqRHXOg.dll (file missing)
backup-20080718-093016-329 O2 - BHO: (no name) - {F8AC36D7-F602-4B69-99B5-2A812E05779F} - C:\WINDOWS\system32\ddcDvwur.dll (file missing)
backup-20080718-093017-168 O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
backup-20080718-093018-382 O2 - BHO: (no name) - {FF2F5D95-F03C-4476-AA7F-1778A0957A68} - C:\WINDOWS\system32\atmlibe.dll
backup-20080718-093021-148 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
backup-20080718-093022-156 O3 - Toolbar: sqvgnrpx - {6144ED4B-6800-4B95-8CB4-23ED98CB84B0} - C:\WINDOWS\sqvgnrpx.dll
backup-20080718-093023-483 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
backup-20080718-093025-988 O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
backup-20080718-093028-425 O16 - DPF: {708C978C-BBF5-4038-8DC1-64FF22BCFFB6} (AXScan Control) - http://10.10.251.244:8000/cleanup/tool/BarracudaSpyRemoval.cab
backup-20080718-093039-422 O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/cpbrkpie.cab
backup-20080718-093043-525 O20 - Winlogon Notify: ddcDvwur - ddcDvwur.dll (file missing)
backup-20080718-093045-690 O20 - Winlogon Notify: qffspoux - C:\WINDOWS\SYSTEM32\acluif.dll
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.reg - regfile - shell\open\command - regedit.exe "%1" %*
.scr - scrfile - shell\open\command - "%1" %*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 ammeihtw - c:\windows\system32\drivers\ammeihtw.sys
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys
R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys
S0 viaagp1 (VIA AGP Filter) - c:\windows\system32\drivers\viaagp1.sys (file missing)
S3 hamachi_oem (PlayLinc Adapter) - c:\windows\system32\drivers\gan_adapter.sys
S3 JL2005C (Dual Mode Camera) - c:\windows\system32\drivers\jl2005c.sys
S3 MREMPR5 (MREMPR5 NDIS Protocol Driver) - c:\program files\common files\motive\mrempr5.sys
S3 MRENDIS5 (MRENDIS5 NDIS Protocol Driver) - c:\program files\common files\motive\mrendis5.sys
S3 TIEHDUSB - c:\windows\system32\drivers\tiehdusb.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe"
S2 AOL ACS (AOL Connectivity Service) - "c:\program files\common files\aol\acs\aolacsd.exe" (file missing)
S4 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe"
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: PlayLinc Adapter
Device ID: ROOT\NET\0000
Manufacturer: Super Computer Inc.
Name: PlayLinc Adapter
PNP Device ID: ROOT\NET\0000
Service: hamachi_oem
-- Scheduled Tasks -------------------------------------------------------------
2008-07-18 12:00:00 412 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-07-18 11:57:10 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job
2008-06-30 15:18:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2006-09-23 16:12:37 246 --a------ C:\WINDOWS\Tasks\WebReg psc C3100 series.job
-- Files created between 2008-06-18 and 2008-07-18 -----------------------------
2008-07-18 11:53:58 0 d-------- C:\WINDOWS\Prefetch
2008-07-18 11:50:45 0 d-------- C:\WINDOWS\LastGood.Tmp
2008-07-18 11:45:01 0 d-------- C:\WINDOWS\system32\scripting
2008-07-18 11:44:58 0 d-------- C:\WINDOWS\system32\en
2008-07-18 11:44:58 0 d-------- C:\WINDOWS\l2schemas
2008-07-18 11:39:51 0 d-------- C:\WINDOWS\network diagnostic
2008-07-18 09:35:39 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-07-18 09:35:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-18 09:35:32 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 09:23:39 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-18 09:23:39 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-18 09:23:39 86528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-18 09:23:39 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-18 09:23:39 82944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-18 09:23:39 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-18 09:23:39 81920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-18 09:23:38 53248 --a------ C:\WINDOWS\system32\Process.exe http://www.beyondlogic.org; Command Line Process Utility>
2008-07-18 08:49:48 1478367 --a------ C:\SmitfraudFix.exe
2008-07-17 15:03:10 0 d-------- C:\Program Files\Lavasoft
2008-07-17 15:03:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-16 14:54:12 0 d-------- C:\Program Files\Windows Defender
2008-07-16 13:27:26 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-16 13:27:25 0 d-------- C:\Program Files\Symantec_Client_Security
2008-07-15 15:37:54 0 d-------- C:\Documents and Settings\Alex\Application Data\PC Tools
2008-07-15 15:20:30 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-07-15 15:00:09 81 --a------ C:\Documents and Settings\All Users\Application Data\ustore.dat
2008-07-15 14:53:33 0 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools
2008-07-15 13:51:06 0 d-------- C:\VundoFix Backups
2008-07-13 09:54:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-07-13 09:54:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Real
2008-07-13 09:54:52 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-13 09:54:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-07-13 09:54:51 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-07-13 09:54:51 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-13 09:54:51 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-13 09:54:51 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-13 09:54:51 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-07-13 09:54:51 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-13 09:54:51 1048576 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-13 09:54:51 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-13 09:54:51 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-07-13 09:54:51 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-13 09:54:51 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-07-13 09:54:51 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-13 09:54:51 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-13 09:54:51 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-13 09:54:51 0 d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-07-13 09:54:51 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-07-13 00:30:31 289507 --ahs---- C:\WINDOWS\system32\gOXHRqss.ini2
2008-07-13 00:25:51 14121 --a------ C:\WINDOWS\system32\clbinit.dll
2008-07-02 20:06:57 0 d-------- C:\Program Files\Take2 Interactive
2008-07-02 17:38:52 0 d-------- C:\Documents and Settings\Owner\Application Data\Snapfish
2008-06-29 19:43:56 1324 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-25 18:14:56 0 d-------- C:\Program Files\Maxis
-- Find3M Report ---------------------------------------------------------------
2008-07-18 11:45:21 0 d-------- C:\Program Files\Messenger
2008-07-18 11:44:57 0 d-------- C:\Program Files\Movie Maker
2008-07-18 11:41:56 0 d-------- C:\Program Files\Windows NT
2008-07-18 09:23:57 1568 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-17 15:02:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-17 10:53:48 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-07-16 13:28:30 0 d-------- C:\Program Files\Symantec
2008-07-16 13:27:26 0 d-------- C:\Program Files\Common Files
2008-07-15 15:02:31 101632 --a------ C:\WINDOWS\system32\atmlibe.dll
2008-07-15 14:15:37 4123 --a------ C:\WINDOWS\viassary-hp.reg
2008-07-02 19:25:16 0 d-------- C:\Documents and Settings\Owner\Application Data\U3
2008-06-09 13:57:30 0 d-------- C:\Program Files\LimeWire
2008-06-09 13:53:43 0 d-------- C:\Program Files\QuickTime
2008-06-05 13:27:07 0 --a------ C:\s33c
2008-06-03 00:10:06 0 --a------ C:\s2uo
2008-05-20 01:17:43 0 d-------- C:\Documents and Settings\Owner\Application Data\mqapfimp
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C34E990-5488-47F2-9313-E355BED3EFED}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF2F5D95-F03C-4476-AA7F-1778A0957A68}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [08/20/2004 15:51]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [08/20/2004 15:55]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [05/21/2003 01:21]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/03/2006 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 20:12]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"=" "
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qffspoux]
acluif.dll 08/12/2004 10:02 103936 C:\WINDOWS\system32\acluif.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ssqRHXOg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys]
@="driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CreataCard Gold 2 Forget Me Not Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 2 Forget Me Not Reminders.lnk
backup=C:\WINDOWS\pss\CreataCard Gold 2 Forget Me Not Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^HP Organize.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\HP Organize.lnk
backup=C:\WINDOWS\pss\HP Organize.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^IMStart.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\IMStart.lnk
backup=C:\WINDOWS\pss\IMStart.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1i3l138p]
C:\WINDOWS\system32\1i3l138p.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\40408b53]
rundll32.exe "C:\WINDOWS\system32\lmmlnice.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupNotify]
c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup]
C:\DOCUME~1\Owner\LOCALS~1\Temp\200871613153_mcappins.exe /v=3 /cleanup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
"C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\System32\hphmon05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
C:\HP\KBD\KBD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci]
C:\DOCUME~1\Owner\LOCALS~1\Temp\2008716131459_mcinfo.exe /insfin
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero PhotoShow Media Manager]
C:\PROGRA~1\Nero\NERO7~1\NEROPH~2\data\xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
"C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
uwpcyzcf
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ee48a58-5432-11dd-913f-001109169727}]
AutoRun\command- F:\wdsync.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cea8e6f8-9df8-11db-908d-001109169727}]
AutoRun\command- H:\LaunchU3.exe -a
-- End of Deckard's System Scanner: finished at 2008-07-18 12:03:48 ------------