Main DSS log
Deckard's System Scanner v20071014.68
Run by Ryan Gartner on 2008-07-24 10:32:36
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
30: 2008-07-24 08:32:40 UTC - RP145 - Deckard's System Scanner Restore Point
29: 2008-07-24 07:52:56 UTC - RP144 - ComboFix created restore point
28: 2008-07-24 06:48:34 UTC - RP143 - System Checkpoint
27: 2008-07-23 00:52:26 UTC - RP142 - Installed AVG 8.0
26: 2008-07-23 00:50:00 UTC - RP141 - Installed AVG 7.5
-- First Restore Point --
1: 2008-07-07 21:53:11 UTC - RP116 - Installed AVG 7.5
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Ryan Gartner.exe) ----------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:34 AM, on 7/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\MHotkey.exe
C:\WINDOWS\CleGameKey\driver\ZClevoGKY.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\StkCSrv.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Ryan Gartner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ryan Gartner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LchGKey] C:\WINDOWS\LchGKey.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Hook] C:\Program Files\VideoView\StkHK.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/wind...?1196826068891
O17 - HKLM\System\CCS\Services\Tcpip\..\{797AB5AC-E12D-48D0-A954-55EE70D653F0}: NameServer = 217.237.148.102 217.237.151.115
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkCSrv.exe
--
End of file - 8404 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys <Not Verified; IVT Corporation; BlueSoleil(c)>
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 VClone - c:\windows\system32\drivers\vclone.sys <Not Verified; Elaborate Bytes AG; Virtual CloneDrive>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.6.0.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.6.0.0>
R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys <Not Verified; Elaborate Bytes AG; CDRTools>
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys <Not Verified; IVT Corporation; Windows (R) 2000 DDK driver>
R3 BlueletSCOAudio (Bluetooth SCO Audio Service) - c:\windows\system32\drivers\blueletscoaudio.sys <Not Verified; IVT Corporation; Windows (R) 2000 DDK driver>
R3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys <Not Verified; IVT Corporation; BlueSoleil>
R3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys <Not Verified; IVT Corporation; Bluetooth USB Device Driver>
R3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys
R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes AG; CDRTools>
R3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys <Not Verified; IVT Corporation; BlueSoleil>
R3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys <Not Verified; IVT Corporation; BlueSoleil>
S2 cdralw (NVIDIA Compatible Windows Miniport Driver) - c:\windows\system32\drivers\nvmini.sys (file missing)
S3 ENTECH - c:\windows\system32\drivers\entech.sys <Not Verified; EnTech Taiwan; PowerStrip>
S3 GoProto (GoProto Protocol Driver) - c:\windows\system32\drivers\goprot51.sys <Not Verified; Gteko Ltd.; Gteko Diagnostics Network Module>
S3 SDDMI2 - c:\windows\system32\ddmi2.sys <Not Verified; Gteko Ltd.; DDMI>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 RegSrvc (Intel(R) PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel(R) PROSet/Wireless Registry Service>
R2 RichVideo (Cyberlink RichVideo Service(CRVS)) - "c:\program files\cyberlink\shared files\richvideo.exe" <Not Verified; ; RichVideo Module>
R3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" <Not Verified; Nero AG; Nero Home>
S2 McShield (McAfee Real-time Scanner) - c:\progra~1\mcafee\viruss~1\mcshield.exe (file missing)
S2 McSysmon (McAfee SystemGuards) - c:\progra~1\mcafee\viruss~1\mcsysmon.exe (file missing)
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-07-22 07:28:47 354 --a------ C:\WINDOWS\Tasks\McDefragTask.job
2008-07-22 07:28:45 346 --a------ C:\WINDOWS\Tasks\McQcTask.job
-- Files created between 2008-06-24 and 2008-07-24 -----------------------------
2008-07-24 10:03:03 0 d-------- C:\WINDOWS\LastGood
2008-07-23 03:44:34 0 d--h----- C:\$AVG8.VAULT$
2008-07-23 02:52:49 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-23 02:52:49 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\AVGTOOLBAR
2008-07-23 02:52:26 0 d-------- C:\Program Files\AVG
2008-07-23 02:52:26 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-22 22:35:08 0 d-------- C:\cmdcons
2008-07-22 22:34:52 68096 --a------ C:\WINDOWS\zip.exe
2008-07-22 22:34:52 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-22 22:34:52 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-22 22:34:52 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-22 22:34:52 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-22 22:34:52 98816 --a------ C:\WINDOWS\sed.exe
2008-07-22 22:34:52 80412 --a------ C:\WINDOWS\grep.exe
2008-07-22 22:34:52 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-22 22:34:44 24576 --a------ C:\WINDOWS\system32\tennfs.dll
2008-07-22 22:34:28 24576 --a------ C:\WINDOWS\system32\comrsdo.dll
2008-07-22 11:46:57 0 d-------- C:\Program Files\EsetOnlineScanner
2008-07-22 10:44:43 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\Malwarebytes
2008-07-22 10:44:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-22 10:44:41 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-22 07:37:10 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-07-22 07:30:33 0 d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-07-22 07:30:29 0 d-------- C:\Program Files\SiteAdvisor
2008-07-22 07:30:29 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\SiteAdvisor
2008-07-22 07:30:05 143360 --a------ C:\WINDOWS\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-07-22 07:28:36 0 d-------- C:\Program Files\Common Files\McAfee
2008-07-22 03:11:18 0 d-------- C:\WINDOWS\system32\appmgmt
2008-07-22 03:02:57 0 d-------- C:\Program Files\Trend Micro
2008-07-22 02:30:24 0 d-------- C:\WINDOWS\pss
2008-07-22 01:46:14 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-07-21 18:03:36 0 d-------- C:\Program Files\Codemasters
2008-07-20 13:55:02 0 d-------- C:\Program Files\Zune
2008-07-16 16:58:13 0 d-------- C:\Program Files\Sierra On-Line
2008-07-16 16:42:01 0 d-------- C:\Program Files\Sierra
2008-07-11 23:06:17 8 --a------ C:\WINDOWS\system32\Update.dat
2008-07-06 17:00:12 0 d-------- C:\Program Files\Stardock Games
2008-07-06 12:52:26 0 d-------- C:\Documents and Settings\LocalService\Desktop
2008-07-06 12:52:19 0 d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-07-06 12:45:14 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-06 12:45:13 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-07-06 12:44:02 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-06 01:01:45 0 d-------- C:\Program Files\EGOSOFT
2008-07-04 15:08:27 0 d-------- C:\WINDOWS\system32\NtmsData
2008-07-03 20:48:31 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-07-03 20:47:18 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-03 20:47:18 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-03 20:47:18 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-03 20:47:18 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-03 20:47:18 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-03 20:47:18 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-03 20:47:18 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-03 20:47:18 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-03 20:47:18 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-03 20:47:18 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-03 20:47:18 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-03 20:47:18 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-03 20:47:18 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-03 20:47:18 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-03 20:47:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-07-03 20:47:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-07-03 20:18:40 0 d-------- C:\WINDOWS\system32\vi
2008-07-03 20:18:40 0 d-------- C:\WINDOWS\system32\gI5
2008-07-03 01:44:30 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-07-03 01:40:56 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-03 01:40:37 0 d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-07-02 21:21:56 0 d-------- C:\Documents and Settings\NetworkService\Desktop
2008-07-02 21:16:58 0 d--h----- C:\WINDOWS\PIF
2008-07-02 20:20:27 9936 --a------ C:\WINDOWS\system32\awtsRKAt.dll
2008-07-02 20:10:59 0 d-------- C:\Temp
2008-07-01 23:04:18 5746688 --a------ C:\Documents and Settings\Ryan Gartner\ntuser.dat
2008-07-01 23:04:18 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat
-- Find3M Report ---------------------------------------------------------------
2008-07-24 09:53:45 0 d-------- C:\Program Files\Common Files
2008-07-21 04:08:22 0 d-------- C:\Program Files\Steam
2008-07-17 06:21:05 0 d-------- C:\Program Files\DAP
2008-07-09 01:58:51 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\Adobe
2008-07-07 21:20:35 0 d-------- C:\Program Files\Linksys EasyLink Advisor
2008-07-02 14:00:00 0 d-------- C:\Program Files\Starcraft
2008-07-02 11:54:12 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-01 23:04:29 0 d-------- C:\Program Files\Sierra Entertainment
2008-06-22 11:18:53 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\Help
2008-06-22 11:15:35 0 d-------- C:\Program Files\TRABULANCE
2008-06-15 19:35:40 0 d-------- C:\Program Files\Diablo II
2008-06-15 19:32:16 21840 --a-----t C:\WINDOWS\system32\SIntfNT.dll
2008-06-15 19:32:16 17212 --a-----t C:\WINDOWS\system32\SIntf32.dll
2008-06-15 19:32:16 12067 --a-----t C:\WINDOWS\system32\SIntf16.dll
2008-06-15 13:51:41 34562 --a------ C:\WINDOWS\DIIUnin.dat
2008-06-15 10:37:58 2829 --a------ C:\WINDOWS\DIIUnin.pif
2008-06-15 10:37:58 94208 --a------ C:\WINDOWS\DIIUnin.exe <Not Verified; Blizzard Entertainment; Diablo II Uninstaller>
2008-06-15 09:50:14 0 d-------- C:\Program Files\OpenAL
2008-06-13 14:26:00 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\Sierra Entertainment
2008-06-13 14:15:33 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-09 14:47:05 0 d-------- C:\Documents and Settings\Ryan Gartner\Application Data\vlc
2008-06-07 18:53:00 0 d-------- C:\Program Files\Activision
2008-06-07 18:04:48 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-03 00:42:16 967 --a------ C:\WINDOWS\ScUnin.pif
2008-06-03 00:42:16 94208 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2008-06-03 00:42:16 35382 --a------ C:\WINDOWS\scunin.dat
2008-06-02 15:24:27 0 d-------- C:\Program Files\Elaborate Bytes
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
07/23/2008 02:52 AM 2055960 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [07/23/2008 02:52 AM 2055960]
[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [07/27/2007 02:00 PM C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [08/23/2007 05:45 PM]
"nwiz"="nwiz.exe" [08/23/2007 05:45 PM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [08/23/2007 05:45 PM]
"RTHDCPL"="RTHDCPL.EXE" [02/26/2007 09:03 AM C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 12:04 PM C:\WINDOWS\SkyTel.exe]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [11/23/2006 01:31 AM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [09/08/2006 06:34 PM]
"LchGKey"="C:\WINDOWS\LchGKey.exe" [04/10/2007 02:44 AM]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [02/21/2007 09:19 PM]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [02/21/2007 09:17 PM]
"Hook"="C:\Program Files\VideoView\StkHK.exe" [07/30/2007 11:31 PM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/24/2006 01:10 AM]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [12/06/2006 08:55 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/13/2006 01:40 AM]
"VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [04/29/2006 03:21 PM]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [04/29/2008 07:56 PM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [07/23/2008 02:52 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [12/24/2006 04:05 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [07/27/2007 02:00 PM]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [10/18/2007 09:34 PM]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [04/03/2006 05:07 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/24/2005 7:05:26 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
*Newly Created Service* - CATCHME
-- End of Deckard's System Scanner: finished at 2008-07-24 10:33:57 ------------