Deckard's System Scanner v20071014.68
Run by Beck on 2008-05-31 18:37:33
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
39: 2008-05-31 23:37:39 UTC - RP39 - Deckard's System Scanner Restore Point
38: 2008-05-31 02:09:29 UTC - RP38 - System Checkpoint
37: 2008-05-29 23:14:14 UTC - RP37 - System Checkpoint
36: 2008-05-28 19:40:47 UTC - RP36 - Software Distribution Service 3.0
35: 2008-05-28 04:56:14 UTC - RP35 - System Checkpoint
-- First Restore Point --
1: 2008-05-23 02:48:22 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Beck.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:39:32 PM, on 5/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\Beck\Desktop\dss.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Beck.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [IDTSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell....iler/SysPro.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1211557618953
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\WINDOWS\system32\STacSV.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 8666 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 cercsr6 - c:\windows\system32\drivers\cercsr6.sys <Not Verified; Adaptec, Inc.; Dell RAID Controller>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E96C-E325-11CE-BFC1-08002BE10318}
Description: IDT High Definition Audio CODEC
Device ID: HDAUDIO\FUNC_01&VEN_8384&DEV_7690&SUBSYS_102801BD&REV_1022\4&2973568E&0&0001
Manufacturer: IDT
Name: IDT High Definition Audio CODEC
PNP Device ID: HDAUDIO\FUNC_01&VEN_8384&DEV_7690&SUBSYS_102801BD&REV_1022\4&2973568E&0&0001
Service: STHDA
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Base System Device
Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_01BD1028&REV_01\4&2FE911E8&0&0AF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV_0843&SUBSYS_01BD1028&REV_01\4&2FE911E8&0&0AF0
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Base System Device
Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_01BD1028&REV_0A\4&2FE911E8&0&0BF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV_0592&SUBSYS_01BD1028&REV_0A\4&2FE911E8&0&0BF0
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Base System Device
Device ID: PCI\VEN_1180&DEV_0852&SUBSYS_01BD1028&REV_05\4&2FE911E8&0&0CF0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_1180&DEV_0852&SUBSYS_01BD1028&REV_05\4&2FE911E8&0&0CF0
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_01BD1028&REV_01\3&61AAA01&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_01BD1028&REV_01\3&61AAA01&0&FB
Service:
-- Scheduled Tasks -------------------------------------------------------------
2008-05-31 17:01:47 436 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2008-05-25 22:40:04 370 --a------ C:\WINDOWS\Tasks\RegCure.job
-- Files created between 2008-04-30 and 2008-05-31 -----------------------------
2008-05-31 17:57:38 0 d-------- C:\Documents and Settings\Beck\Application Data\Malwarebytes
2008-05-31 17:57:30 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-31 17:57:28 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-26 20:04:20 0 d-------- C:\Program Files\Alwil Software
2008-05-25 22:38:11 0 d-------- C:\Program Files\RegCure
2008-05-25 22:12:51 0 d-------- C:\Program Files\Trend Micro
2008-05-25 22:00:21 0 d-------- C:\Documents and Settings\Beck\Application Data\Uniblue
2008-05-25 21:38:24 0 d--h----- C:\$AVG8.VAULT$
2008-05-24 07:50:44 0 d-------- C:\Documents and Settings\Beck\Application Data\Yahoo!
2008-05-24 07:50:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-23 22:37:23 0 d-------- C:\Logs
2008-05-23 20:40:31 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-05-23 19:31:18 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-05-23 19:27:26 0 d-------- C:\Program Files\Yahoo!
2008-05-23 19:05:48 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-23 19:05:44 0 d-------- C:\Program Files\AVG
2008-05-23 19:05:43 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-23 18:43:07 0 d-------- C:\Documents and Settings\Beck\Application Data\HP
2008-05-23 18:41:07 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-05-23 18:36:33 0 d-------- C:\Documents and Settings\Beck\Application Data\Macromedia
2008-05-23 18:33:11 0 d-------- C:\bin
2008-05-23 18:31:36 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-05-23 18:31:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-05-23 18:27:39 0 d-------- C:\WINDOWS\system32\URTTemp
2008-05-23 18:27:06 0 d-------- C:\Program Files\Common Files\HP
2008-05-23 18:24:27 0 d-------- C:\Program Files\Hewlett-Packard
2008-05-23 18:23:43 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-05-23 18:17:28 117092 --a------ C:\WINDOWS\hpoins11.dat
2008-05-23 18:03:50 0 d-------- C:\TEMP
2008-05-23 18:03:19 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-05-23 18:02:30 0 d-------- C:\Program Files\HP
2008-05-23 17:38:36 0 d-------- C:\Documents and Settings\Beck\Application Data\Adobe
2008-05-23 13:40:28 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-23 13:40:15 0 d-------- C:\Program Files\Spyware Doctor
2008-05-23 13:40:15 0 d-------- C:\Documents and Settings\administrator\Application Data\PC Tools
2008-05-23 13:30:58 0 d-------- C:\Documents and Settings\administrator\Application Data\Adobe
2008-05-23 13:27:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-23 13:27:22 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-23 13:25:35 0 d-------- C:\Documents and Settings\administrator\Application Data\Identities
2008-05-23 13:25:30 0 d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-23 13:25:26 0 d--h----- C:\Documents and Settings\administrator\Templates
2008-05-23 13:25:26 0 dr------- C:\Documents and Settings\administrator\Start Menu
2008-05-23 13:25:26 0 dr-h----- C:\Documents and Settings\administrator\SendTo
2008-05-23 13:25:26 0 dr-h----- C:\Documents and Settings\administrator\Recent
2008-05-23 13:25:26 0 d--h----- C:\Documents and Settings\administrator\PrintHood
2008-05-23 13:25:26 0 d--h----- C:\Documents and Settings\administrator\NetHood
2008-05-23 13:25:26 0 dr------- C:\Documents and Settings\administrator\My Documents
2008-05-23 13:25:26 0 d--h----- C:\Documents and Settings\administrator\Local Settings
2008-05-23 13:25:26 0 dr------- C:\Documents and Settings\administrator\Favorites
2008-05-23 13:25:26 0 d-------- C:\Documents and Settings\administrator\Desktop
2008-05-23 13:25:26 0 d--hs---- C:\Documents and Settings\administrator\Cookies
2008-05-23 13:25:26 0 dr-h----- C:\Documents and Settings\administrator\Application Data
2008-05-23 13:25:26 0 d---s---- C:\Documents and Settings\administrator\Application Data\Microsoft
2008-05-23 13:25:25 774144 --a------ C:\Documents and Settings\administrator\NTUSER.DAT
2008-05-23 13:24:48 0 d--hs---- C:\WINDOWS\CSC
2008-05-23 13:02:55 0 d-------- C:\Program Files\Microsoft Works
2008-05-23 13:02:46 0 d-------- C:\Program Files\MSBuild
2008-05-23 12:58:50 0 d-------- C:\WINDOWS\SHELLNEW
2008-05-23 12:58:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-23 12:57:59 0 dr-h----- C:\MSOCache
2008-05-23 12:56:01 0 d-------- C:\Program Files\Java
2008-05-23 12:56:00 0 d-------- C:\Program Files\Common Files\Java
2008-05-23 12:00:54 0 d-------- C:\WINDOWS\system32\Dell
2008-05-23 11:11:52 0 d-------- C:\Program Files\Creative
2008-05-23 11:03:23 0 d-------- C:\Program Files\IDT
2008-05-23 10:31:10 0 d-------- C:\Program Files\CONEXANT
2008-05-23 10:26:59 0 d-------- C:\WINDOWS\Prefetch
2008-05-23 10:17:34 0 d-------- C:\WINDOWS\system32\scripting
2008-05-23 10:17:34 0 d-------- C:\WINDOWS\system32\en
2008-05-23 10:17:34 0 d-------- C:\WINDOWS\system32\bits
2008-05-23 10:17:34 0 d-------- C:\WINDOWS\l2schemas
2008-05-23 10:16:03 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-23 10:13:53 0 d-------- C:\WINDOWS\network diagnostic
2008-05-23 09:22:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-23 09:21:00 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-23 09:20:06 0 d--hs---- C:\Documents and Settings\Beck\UserData
2008-05-23 09:19:00 0 d-------- C:\WINDOWS\pss
2008-05-23 09:16:39 666 --a------ C:\WINDOWS\speed.reg
2008-05-23 09:09:56 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-23 09:09:40 0 d-------- C:\Program Files\ATI Technologies
2008-05-23 09:09:34 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-23 09:08:41 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-23 09:08:40 0 d-------- C:\Program Files\Broadcom
2008-05-23 09:07:47 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-22 21:49:35 770048 --a------ C:\WINDOWS\system32\BCMLogon.dll <Not Verified; Dell Inc.; Wireless Network Logon Provider>
2008-05-22 21:49:34 33664 --a------ C:\WINDOWS\system32\drivers\BCMWLNPF.SYS <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
2008-05-22 21:49:33 86016 --a------ C:\WINDOWS\system32\preflib.dll
2008-05-22 21:49:33 253952 --a------ C:\WINDOWS\system32\bcmwlu00.exe <Not Verified; Dell Inc.; Dell Wireless WLAN Card Uninstaller>
2008-05-22 21:49:32 20480 --a------ C:\WINDOWS\system32\WLTRYSVC.EXE
2008-05-22 21:49:32 1392640 --a------ C:\WINDOWS\system32\WLTRAY.EXE <Not Verified; Dell Inc.; Dell Wireless WLAN Card Wireless Network Tray Applet>
2008-05-22 21:49:32 2129920 --a------ C:\WINDOWS\system32\WLBCGCBPRO731.DLL <Not Verified; BCGSoft Ltd; BCGControlBar Professional Dynamic Link Library>
2008-05-22 21:49:32 1253376 --a------ C:\WINDOWS\system32\BCMWLTRY.EXE <Not Verified; Dell Inc.; Dell Wireless WLAN Card Wireless Network Controller>
2008-05-22 21:49:32 69632 --a------ C:\WINDOWS\system32\bcmwlpkt.dll <Not Verified; CACE Technologies; WinPcap low level packet library>
2008-05-22 21:49:32 757760 --a------ C:\WINDOWS\system32\bcm1xsup.dll
2008-05-22 21:49:32 0 d-------- C:\Program Files\Dell
2008-05-22 21:49:27 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-22 21:48:06 0 d-------- C:\Documents and Settings\Beck\Application Data\Identities
2008-05-22 21:47:57 0 dr------- C:\Documents and Settings\Beck\Favorites
2008-05-22 21:47:57 0 d-------- C:\Documents and Settings\Beck\Desktop
2008-05-22 21:47:57 0 d--hs---- C:\Documents and Settings\Beck\Cookies
2008-05-22 21:47:57 0 dr-h----- C:\Documents and Settings\Beck\Application Data
2008-05-22 21:47:56 0 d--h----- C:\Documents and Settings\Beck\Templates
2008-05-22 21:47:56 0 dr------- C:\Documents and Settings\Beck\Start Menu
2008-05-22 21:47:56 0 dr-h----- C:\Documents and Settings\Beck\SendTo
2008-05-22 21:47:56 0 dr-h----- C:\Documents and Settings\Beck\Recent
2008-05-22 21:47:56 0 d--h----- C:\Documents and Settings\Beck\PrintHood
2008-05-22 21:47:56 1572864 --ah----- C:\Documents and Settings\Beck\NTUSER.DAT
2008-05-22 21:47:56 0 d--h----- C:\Documents and Settings\Beck\NetHood
2008-05-22 21:47:56 0 dr------- C:\Documents and Settings\Beck\My Documents
2008-05-22 21:47:56 0 d--h----- C:\Documents and Settings\Beck\Local Settings
2008-05-22 21:47:03 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-22 21:47:01 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-22 21:46:59 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-05-22 21:46:59 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-05-22 21:46:59 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-05-22 21:46:59 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-05-22 21:46:59 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-05-22 21:46:42 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-05-22 21:46:42 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-05-22 21:46:42 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-05-22 21:46:42 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-05-22 21:46:41 225280 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-05-22 21:43:07 0 d-------- C:\WINDOWS\system32\xircom
2008-05-22 21:43:07 0 d-------- C:\Program Files\microsoft frontpage
2008-05-22 21:42:55 262144 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-05-22 21:42:55 0 d-------- C:\DELL
2008-05-22 21:42:43 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-22 21:42:23 0 -rahs---- C:\MSDOS.SYS
2008-05-22 21:42:23 0 -rahs---- C:\IO.SYS
2008-05-22 21:42:23 0 --a------ C:\CONFIG.SYS
2008-05-22 21:42:23 0 --a------ C:\AUTOEXEC.BAT
2008-05-22 21:41:21 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-05-22 21:41:12 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-22 21:41:11 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-22 21:41:02 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-22 21:40:39 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-22 21:40:00 0 d---s---- C:\WINDOWS\Tasks
2008-05-22 21:39:59 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-22 21:39:54 0 d-------- C:\WINDOWS\srchasst
2008-05-22 21:39:53 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-22 21:39:42 0 d-------- C:\Program Files\Movie Maker
2008-05-22 21:39:33 0 d-------- C:\WINDOWS\system32\Restore
2008-05-22 21:38:46 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-22 21:38:25 0 d-------- C:\WINDOWS\Registration
2008-05-22 21:38:16 0 d-------- C:\Program Files\Online Services
2008-05-22 21:38:08 0 d-------- C:\Program Files\Messenger
2008-05-22 21:38:04 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-22 21:37:16 0 d-------- C:\Program Files\Windows NT
2008-05-22 21:37:12 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-22 21:37:10 0 d-------- C:\WINDOWS\system32\Com
2008-05-22 16:15:36 0 d--hs---- C:\WINDOWS\Installer
2008-05-22 16:15:35 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-22 16:15:31 0 dr------- C:\Program Files
2008-05-22 16:15:31 0 d-------- C:\Program Files\Common Files
2008-05-22 16:15:31 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-22 16:15:03 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-05-22 16:15:03 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-05-22 16:15:03 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-22 16:15:03 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-05-22 16:15:03 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-05-22 16:15:03 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-05-22 16:15:03 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-05-22 16:15:03 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-05-22 16:15:03 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-05-22 16:15:03 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-05-22 16:15:03 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-05-22 16:15:03 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-05-22 16:15:03 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-05-22 16:15:03 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-05-22 16:15:03 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-22 16:15:03 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-05-22 16:14:49 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-22 16:14:49 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-22 16:14:44 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-05-22 16:14:44 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-05-22 16:14:43 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-05-22 16:14:43 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-05-22 16:14:14 0 d--hs---- C:\System Volume Information
2008-05-22 16:14:14 0 d-------- C:\Documents and Settings
2008-05-22 16:05:00 0 d-------- C:\WINDOWS
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\WinSxS
2008-05-22 16:05:00 0 dr------- C:\WINDOWS\Web
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\twain_32
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\wins
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\wbem
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\usmt
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\spool
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\Setup
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\ras
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\oobe
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\npp
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\mui
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\IME
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\ias
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\export
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\drivers
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-22 16:05:00 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\config
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\3076
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\2052
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1054
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1042
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1041
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1037
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1033
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1031
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1028
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system32\1025
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\system
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\security
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Resources
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\repair
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Provisioning
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\PeerNet
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\pchealth
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\mui
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\msapps
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\msagent
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Media
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\java
2008-05-22 16:05:00 0 d--h----- C:\WINDOWS\inf
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\ime
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Help
2008-05-22 16:05:00 0 dr--s---- C:\WINDOWS\Fonts
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\ehome
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Driver Cache
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\dell
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Debug
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Cursors
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\Config
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\AppPatch
2008-05-22 16:05:00 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-05-22 16:15:03 62 --ahs---- C:\Documents and Settings\Beck\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [03/16/2007 06:10 PM]
"IDTSysTrayApp"="sttray.exe" [09/05/2007 09:24 PM C:\WINDOWS\sttray.exe]
"CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [02/23/2005 03:57 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [04/10/2008 03:14 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [05/23/2008 07:05 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/15/2008 06:19 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:12 PM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [10/23/2006 1:48:20 AM]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [10/23/2006 12:01:50 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2/19/2006 4:21:22 AM]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2/10/2006 7:56:20 AM]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [5/23/2008 12:56:51 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1715567821-796845957-725345543-500\Scripts\Logon\0\0]
"Script"=Pushprinterconnections.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
-- End of Deckard's System Scanner: finished at 2008-05-31 18:42:57 ------------