[font=\"Arial Black\"]
[color=\"#006400\"] THIS IS WHAT I HAD OF THE main.txt : [/color][/font]
Deckard's System Scanner v20070905.67
Run by Monty on 2007-09-08 22:48:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
66: 2007-09-08 21:48:50 UTC - RP66 - Deckard's System Scanner Restore Point
65: 2007-09-06 12:25:51 UTC - RP65 - Installed Macromedia Contribute 3.11
64: 2007-09-05 22:21:58 UTC - RP64 - Installed QuickTime
63: 2007-09-05 22:15:34 UTC - RP63 - Removed QuickTime
62: 2007-09-05 18:12:17 UTC - RP62 - Installed Macromedia Flash 8
-- First Restore Point --
1: 2007-08-10 19:45:23 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-09-08 22:50:34
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.5730.11)
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Documents and Settings\Monty\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKEY_LOCAL_MACHINE\..\Run: [nwiz] nwiz.exe /install
O4 - HKEY_LOCAL_MACHINE\..\Run: [SkyTel] SkyTel.EXE
O4 - HKEY_LOCAL_MACHINE\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKEY_LOCAL_MACHINE\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKEY_LOCAL_MACHINE\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKEY_LOCAL_MACHINE\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: C:\Program Files\Bonjour\mdnsNSP.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineS...er.cab56986.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - "C:\Program Files\Bonjour\mDNSResponder.exe"
O23 - Service: ColdFusion MX 7 Application Server - Macromedia Inc. - "C:\CFusionMX7\runtime\bin\jrunsvc.exe"
O23 - Service: ColdFusion MX 7 Search Server - Verity, Inc. - "C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe" -cfg "C:\CFusionMX7\verity\k2\common\verity.cfg" -ntstart 1
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\Mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\McTskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - "C:\Program Files\NetLimiter 2 Pro\nlsvc.exe"
O23 - Service: StyleXPService - Unknown owner - "C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"
-- File Associations -----------------------------------------------------------
[color=\"red\"].chm - chm.file - DefaultIcon - %systemroot%\hh.exe,0[/color]
[color=\"red\"].hlp - hlpfile - DefaultIcon - %systemroot%\hh.exe,0[/color]
[color=\"red\"].ini - inifile - DefaultIcon - C:\Program Files\TGTSoft\StyleXP\Icons\Current.Monty\Documents & Settings Folder.ico[/color]
[color=\"red\"].js - jsfile - DefaultIcon - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe",7[/color]
[color=\"red\"].js - jsfile - shell\open\command - "C:\Program Files\Adobe\Adobe Dreamweaver CS3\Dreamweaver.exe","%1"[/color]
[color=\"red\"].txt - txtfile - DefaultIcon - C:\Program Files\TGTSoft\StyleXP\Icons\Current.Monty\Document.ico[/color]
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 prohlp02 (StarForce Protection Helper Driver v2) - c:\windows\system32\drivers\prohlp02.sys <Not Verified; StarForce Technologies, Inc.; StarForce Protection System>
R0 prosync1 (StarForce Protection Synchronization Driver v1) - c:\windows\system32\drivers\prosync1.sys <Not Verified; StarForce Technologies, Inc.; StarForce Protection System>
R0 sfhlp01 (StarForce Protection Helper Driver) - c:\windows\system32\drivers\sfhlp01.sys <Not Verified; StarForce Technologies, Inc.; StarForce Protection System>
R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>
R1 prodrv06 (StarForce Protection Environment Driver v6) - c:\windows\system32\drivers\prodrv06.sys <Not Verified; StarForce Technologies, Inc.; StarForce Protection System>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R1 StyleXPHelper - c:\program files\tgtsoft\stylexp\stylexphelper.exe <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
S4 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
S4 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
S4 ColdFusion MX 7 Application Server - "c:\cfusionmx7\runtime\bin\jrunsvc.exe" <Not Verified; Macromedia Inc.; Macromedia JRun Application Server>
S4 ColdFusion MX 7 Search Server - "c:\cfusionmx7\verity\k2\_nti40\bin\k2admin.exe" -cfg "c:\cfusionmx7\verity\k2\common\verity.cfg" -ntstart 1 <Not Verified; Verity, Inc.; Verity K2 Toolkit>
S4 nlsvc (NetLimiter) - "c:\program files\netlimiter 2 pro\nlsvc.exe" <Not Verified; Locktime Software; NetLimiter 2 Pro>
S4 StyleXPService - "c:\program files\tgtsoft\stylexp\stylexpservice.exe" <Not Verified; ; StyleXPService Module>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_81681849&REV_01\4&257B4EB9&0&001A
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_81681849&REV_01\4&257B4EB9&0&001A
Service: RTL8023xp
Class GUID:
Description:
Device ID: ACPI\AWY0001\2&DABA3FF&0
Manufacturer:
Name:
PNP Device ID: ACPI\AWY0001\2&DABA3FF&0
Service:
-- Scheduled Tasks -------------------------------------------------------------
2007-09-23 02:00:00 350 --a------ C:\WINDOWS\Tasks\At3.job
2007-09-23 01:00:00 350 --a------ C:\WINDOWS\Tasks\At2.job
2007-09-08 22:00:00 350 --a------ C:\WINDOWS\Tasks\At23.job
2007-09-08 21:00:00 350 --a------ C:\WINDOWS\Tasks\At22.job
2007-09-08 20:00:00 350 --a------ C:\WINDOWS\Tasks\At21.job
2007-09-08 18:00:00 350 --a------ C:\WINDOWS\Tasks\At19.job
2007-09-08 17:00:00 350 --a------ C:\WINDOWS\Tasks\At18.job
2007-09-08 14:00:00 350 --a------ C:\WINDOWS\Tasks\At15.job
2007-09-08 13:00:00 350 --a------ C:\WINDOWS\Tasks\At14.job
2007-09-08 12:00:00 350 --a------ C:\WINDOWS\Tasks\At13.job
2007-09-08 00:00:00 350 --a------ C:\WINDOWS\Tasks\At1.job
2007-09-07 23:00:00 350 --a------ C:\WINDOWS\Tasks\At24.job
2007-09-07 20:51:57 530 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Monty.job
2007-09-07 19:00:00 350 --a------ C:\WINDOWS\Tasks\At20.job
2007-09-06 16:00:00 350 --a------ C:\WINDOWS\Tasks\At17.job
2007-09-06 15:00:00 350 --a------ C:\WINDOWS\Tasks\At16.job
2007-09-06 04:00:00 350 --a------ C:\WINDOWS\Tasks\At5.job
2007-09-06 03:00:00 350 --a------ C:\WINDOWS\Tasks\At4.job
2007-09-05 19:26:17 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-09-05 11:45:18 350 --a------ C:\WINDOWS\Tasks\At12.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At9.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At8.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At7.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At6.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At11.job
2007-09-01 23:15:34 350 --a------ C:\WINDOWS\Tasks\At10.job
-- Files created between 2007-08-08 and 2007-09-08 -----------------------------
2007-09-22 16:09:43 0 d-------- C:\Program Files\TGTSoft
2007-09-07 16:40:16 0 d-------- C:\Program Files\Trend Micro
2007-09-06 14:43:58 0 --a------ C:\Documents and Settings\Monty\FlashPaper2PrinterPort
2007-09-06 13:26:17 0 d-------- C:\Program Files\Common Files\Macromedia Shared
2007-09-06 01:13:21 0 d-------- C:\Program Files\Bonjour
2007-09-05 23:21:59 0 d-------- C:\Program Files\QuickTime
2007-09-05 21:42:20 1755 --a------ C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
2007-09-05 19:19:05 21 --ah----- C:\qpmd8378.bin
2007-09-05 19:18:48 49152 --a------ C:\WINDOWS\system32\cfperfmon_mx.dll <Not Verified; Macromedia Inc.; ColdFusion>
2007-09-05 19:17:33 0 d-------- C:\CFusionMX7
2007-09-05 19:17:29 0 d--h----- C:\Program Files\Zero G Registry
2007-09-05 19:14:05 0 d--h----- C:\Documents and Settings\Monty\InstallAnywhere
2007-09-05 19:04:30 0 d-------- C:\Program Files\Common Files\Macromedia
2007-09-05 19:04:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Macromedia
2007-09-05 19:04:20 0 d-------- C:\Program Files\Macromedia
2007-09-05 17:12:44 0 d-------- C:\Documents and Settings\Monty\My Games
2007-09-05 17:12:41 0 d-------- C:\Documents and Settings\All Users\Microsoft
2007-09-04 23:55:29 0 d-------- C:\Documents and Settings\Monty\web page 1_files
2007-09-04 23:41:07 0 d-------- C:\Documents and Settings\Monty\new_page_1_files
2007-09-04 13:20:46 0 d-------- C:\Program Files\Windows Media Connect 2
2007-09-03 23:54:46 0 d-------- C:\WINDOWS\system32\NtmsData
2007-09-03 16:21:40 0 d--h----- C:\WINDOWS\$hf_mig$
2007-09-03 16:16:14 0 d-------- C:\WINDOWS\%DownloadedProgramFiles%
2007-09-02 20:50:55 0 d-------- C:\Program Files\Common Files\L&H
2007-09-02 20:50:41 0 d-------- C:\Program Files\Microsoft ActiveSync
2007-09-02 12:29:13 0 d-------- C:\Documents and Settings\Monty\Application Data\Help
2007-09-02 12:25:10 0 d-------- C:\WINDOWS\system32\LogFiles
2007-09-02 12:25:10 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2007-09-02 12:22:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2007-09-02 00:13:16 0 d-------- C:\Program Files\Ontrack
2007-09-01 23:51:44 0 d-------- C:\Program Files\Microsoft Works
2007-09-01 23:51:37 0 d-------- C:\Program Files\MSBuild
2007-09-01 23:47:53 0 d-------- C:\WINDOWS\SHELLNEW
2007-09-01 23:47:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-01 23:47:14 0 dr-h----- C:\MSOCache
2007-09-01 18:29:41 0 d-------- C:\Program Files\PowerQuest
2007-09-01 03:16:18 0 d-------- C:\Program Files\DC++
2007-09-01 02:32:52 0 d-------- C:\Program Files\Veoh Networks
2007-08-30 00:50:51 0 d-------- C:\Program Files\SystemRequirementsLab
2007-08-30 00:50:25 0 d-------- C:\Documents and Settings\Monty\Application Data\SystemRequirementsLab
2007-08-29 23:20:23 0 d-------- C:\Program Files\LCSI
2007-08-29 12:16:57 0 d-------- C:\Documents and Settings\Monty\Application Data\CyberLink
2007-08-28 23:54:56 0 d-------- C:\Program Files\Keep I.T. Easy
2007-08-28 16:51:09 0 d-------- C:\Program Files\VideoAccessCodec
2007-08-28 16:44:38 0 d-------- C:\Program Files\directx
2007-08-28 15:58:46 299008 --a------ C:\WINDOWS\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2007-08-28 15:58:45 0 d-------- C:\Documents and Settings\Monty\WINDOWS
2007-08-25 03:15:22 20480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2007-08-23 20:08:59 0 d-------- C:\Program Files\Freewire
2007-08-23 20:08:43 0 d-------- C:\Program Files\Common Files\Intel
2007-08-23 20:08:42 0 d-------- C:\Program Files\Freewire Telephone
2007-08-22 21:06:42 0 d-------- C:\WINDOWS\system32\appmgmt
2007-08-22 21:05:06 0 d-------- C:\Documents and Settings\Monty\Application Data\Diskeeper Corporation
2007-08-22 21:04:01 20 --a------ C:\WINDOWS\undRseg.dat
2007-08-22 20:50:06 0 d--hs---- C:\RecoveryBin
2007-08-22 20:49:55 0 d-------- C:\WINDOWS\Downloaded Installations
2007-08-22 20:49:49 0 d-------- C:\Program Files\Diskeeper Corporation
2007-08-22 19:54:02 0 d-------- C:\Program Files\iPod
2007-08-22 19:54:00 0 d-------- C:\Program Files\iTunes
2007-08-22 19:53:48 0 d-------- C:\Program Files\Common Files\Apple
2007-08-22 14:25:42 0 d-------- C:\TEMP
2007-08-22 14:23:11 0 d-------- C:\Program Files\Kelloggs Art Attack
2007-08-20 17:04:17 0 d-------- C:\Documents and Settings\Monty\Application Data\Locktime
2007-08-20 17:03:53 0 d-------- C:\Program Files\GetData
2007-08-20 17:03:43 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-08-20 17:03:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Locktime
2007-08-20 17:03:18 0 d-------- C:\Program Files\NetLimiter 2 Pro
2007-08-19 22:01:19 0 d-------- C:\Documents and Settings\Monty\Application Data\Real
2007-08-19 01:31:23 0 d-------- C:\Program Files\BinaryBiz
2007-08-19 01:31:11 0 d-------- C:\Program Files\AusLogics Disk Defrag
2007-08-17 11:27:34 0 d-------- C:\Program Files\Common Files\xing shared
2007-08-17 02:23:10 0 d-------- C:\Program Files\Common Files\Real
2007-08-17 02:23:06 0 d-------- C:\Program Files\Real
2007-08-17 00:32:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-08-17 00:31:57 0 d-------- C:\Program Files\Google
2007-08-16 23:39:46 0 d-------- C:\Program Files\Windows Live
2007-08-16 23:39:45 0 d-------- C:\Program Files\Messenger Plus! Live
2007-08-16 20:45:51 0 d-------- C:\WINDOWS\Sun
2007-08-16 20:45:51 0 d-------- C:\Documents and Settings\Monty\Application Data\Sun
2007-08-16 11:44:13 0 d-------- C:\Documents and Settings\All Users\Application Data\ashampoo
2007-08-14 23:48:00 0 d-------- C:\Program Files\Minefield
2007-08-12 15:23:40 0 d--hs---- C:\Documents and Settings\Monty\UserData
2007-08-12 03:18:40 0 d-------- C:\Documents and Settings\Monty\Application Data\Apple Computer
2007-08-12 03:16:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-08-12 03:16:29 0 d-------- C:\Program Files\Apple Software Update
2007-08-12 03:16:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-08-12 03:03:22 0 d-------- C:\Documents and Settings\Monty\Application Data\Adobe
2007-08-12 03:03:02 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-08-12 03:02:56 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2007-08-12 02:59:50 0 d-------- C:\Documents and Settings\Monty\Shared
2007-08-12 02:59:48 0 d-------- C:\Documents and Settings\Monty\Incomplete
2007-08-12 02:59:17 0 d-------- C:\Documents and Settings\Monty\Application Data\LimeWire
2007-08-12 02:59:14 0 d-------- C:\Program Files\Common Files\Adobe
2007-08-12 02:59:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2007-08-12 02:55:05 0 d-------- C:\Program Files\Java
2007-08-12 02:52:34 0 d-------- C:\Program Files\Common Files\Java
2007-08-12 02:52:10 0 d-------- C:\Program Files\LimeWire
2007-08-11 03:06:22 0 d-------- C:\Documents and Settings\Monty\Application Data\COWON
2007-08-11 03:02:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-08-11 03:01:52 0 d-------- C:\Documents and Settings\Monty\Contacts
2007-08-11 03:01:09 0 d-------- C:\Program Files\JetAudio
2007-08-11 03:01:09 0 d-------- C:\Program Files\Common Files\COWON
2007-08-11 03:00:21 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-08-11 03:00:16 0 d-------- C:\Program Files\Yahoo!
2007-08-11 03:00:16 0 d-------- C:\Program Files\MSN Messenger
2007-08-11 01:32:42 0 d-------- C:\Program Files\EA GAMES
2007-08-11 01:02:06 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-08-11 00:59:53 0 d-------- C:\Program Files\CyberLink
2007-08-11 00:58:41 0 d-------- C:\Program Files\Common Files\NSV
2007-08-11 00:42:54 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2007-08-11 00:41:22 0 d-------- C:\WINDOWS\SoftwareDistribution
2007-08-11 00:41:12 0 d-------- C:\WINDOWS\Prefetch
2007-08-11 00:39:11 0 d-------- C:\Documents and Settings\Monty\Application Data\DivX
2007-08-11 00:30:05 0 d-------- C:\Program Files\Winamp
2007-08-11 00:27:50 0 d-------- C:\Program Files\DivX
2007-08-11 00:23:16 0 d-------- C:\WINDOWS\peernet
2007-08-11 00:23:15 0 d-------- C:\WINDOWS\provisioning
2007-08-11 00:21:50 0 d-------- C:\WINDOWS\ServicePackFiles
2007-08-11 00:19:52 0 d-------- C:\WINDOWS\NV22683144.TMP
2007-08-11 00:17:08 0 d-------- C:\NVIDIA
2007-08-11 00:16:46 0 d-------- C:\WINDOWS\EHome
2007-08-10 23:18:53 0 d-------- C:\Documents and Settings\Monty\Application Data\Macromedia
2007-08-10 23:18:45 1335 --a------ C:\WINDOWS\mozver.dat
2007-08-10 23:12:20 0 d-------- C:\WINDOWS\LogFiles
2007-08-10 22:52:58 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-10 22:52:56 0 d-------- C:\Documents and Settings\Monty\Application Data\Mozilla
2007-08-10 22:52:50 0 d-------- C:\Program Files\Norton AntiVirus
2007-08-10 22:52:32 0 d-------- C:\Program Files\Symantec
2007-08-10 22:52:31 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-08-10 22:52:09 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-10 22:48:18 0 d-------- C:\Program Files\MagicISO
2007-08-10 22:06:34 0 d-------- C:\Program Files\PowerISO
2007-08-10 22:05:46 0 d-------- C:\Documents and Settings\Monty\Application Data\WinRAR
2007-08-10 21:40:33 0 d-------- C:\Program Files\uTorrent
2007-08-10 21:40:03 0 d-------- C:\Documents and Settings\Monty\Application Data\uTorrent
2007-08-10 21:32:12 0 d-------- C:\Program Files\Common Files\ODBC
2007-08-10 21:32:09 0 d-------- C:\Program Files
2007-08-10 21:32:09 0 d-------- C:\Program Files\Common Files
2007-08-10 21:32:09 0 d-------- C:\Program Files\Common Files\SpeechEngines
2007-08-10 21:31:55 0 d--h----- C:\Documents and Settings\Default User\Templates
2007-08-10 21:31:55 0 dr------- C:\Documents and Settings\Default User\Start Menu
2007-08-10 21:31:55 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2007-08-10 21:31:55 0 d--h----- C:\Documents and Settings\Default User\Recent
2007-08-10 21:31:55 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2007-08-10 21:31:55 0 d--h----- C:\Documents and Settings\Default User\NetHood
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\Default User\My Documents
2007-08-10 21:31:55 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\Default User\Favorites
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\Default User\Desktop
2007-08-10 21:31:55 0 d---s---- C:\Documents and Settings\Default User\Cookies
2007-08-10 21:31:55 0 d--h----- C:\Documents and Settings\All Users\Templates
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\All Users\Start Menu
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\All Users\Favorites
2007-08-10 21:31:55 0 dr------- C:\Documents and Settings\All Users\Documents
2007-08-10 21:31:55 0 d-------- C:\Documents and Settings\All Users\Desktop
2007-08-10 21:31:17 0 d-------- C:\WINDOWS\system32\CatRoot2
2007-08-10 21:31:17 0 d-------- C:\WINDOWS\system32\CatRoot
2007-08-10 21:31:12 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2007-08-10 21:31:12 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2007-08-10 21:31:12 0 d--h----- C:\Documents and Settings\All Users\Application Data
2007-08-10 21:31:12 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2007-08-10 21:30:57 0 d-------- C:\Documents and Settings
2007-08-10 21:28:44 0 d-------- C:\Program Files\NETGEAR WG311v2 Adapter
2007-08-10 21:28:19 0 d-------- C:\Documents and Settings\All Users\Application Data\{70FE9869-8D38-4EB3-8541-A735C2285CF7}
2007-08-10 21:26:36 0 d-------- C:\WINDOWS
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\WinSxS
2007-08-10 21:26:36 0 dr------- C:\WINDOWS\Web
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\twain_32
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\wins
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\wbem
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\usmt
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\spool
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\ShellExt
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\Setup
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\ras
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\oobe
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\npp
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\mui
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\inetsrv
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\IME
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\icsxml
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\ias
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\export
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\drivers
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-08-10 21:26:36 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\dhcp
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\config
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\3076
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\2052
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1054
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1042
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1041
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1037
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1033
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1031
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1028
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system32\1025
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\system
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\security
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Resources
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\repair
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\mui
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\msapps
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\msagent
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Media
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\java
2007-08-10 21:26:36 0 d--h----- C:\WINDOWS\inf
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\ime
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Help
2007-08-10 21:26:36 0 dr--s---- C:\WINDOWS\Fonts
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Driver Cache
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Debug
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Cursors
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Connection Wizard
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\Config
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\AppPatch
2007-08-10 21:26:36 0 d-------- C:\WINDOWS\addins
2007-08-10 21:12:17 0 d-------- C:\WINDOWS\system32\Lang
2007-08-10 21:09:22 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-08-10 21:09:12 0 d-------- C:\Program Files\McAfee.com
2007-08-10 21:07:57 0 d-------- C:\WINDOWS\OPTIONS
2007-08-10 21:07:03 40960 -r------- C:\WINDOWS\system32\ChCfg.exe
2007-08-10 21:06:40 0 d-------- C:\WINDOWS\system32\RTCOM
2007-08-10 21:05:29 0 d-------- C:\Program Files\Realtek
2007-08-10 21:05:28 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-08-10 21:05:26 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-08-10 21:05:20 487424 -r------- C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2007-08-10 21:05:13 0 d-------- C:\Program Files\VIA
2007-08-10 21:04:45 5824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2007-08-10 21:00:33 0 d---s---- C:\WINDOWS\system32\Microsoft
2007-08-10 20:57:21 0 d-------- C:\WINDOWS\RegisteredPackages
2007-08-10 20:56:17 0 d-------- C:\WINDOWS\pss
2007-08-10 20:56:01 0 d-------- C:\WINDOWS\nview
2007-08-10 20:55:28 0 d-------- C:\Program Files\Common Files\InstallShield
2007-08-10 20:45:19 0 d--hs---- C:\WINDOWS\Installer
2007-08-10 20:45:17 0 d-------- C:\Documents and Settings\Monty\Application Data\Identities
2007-08-10 20:45:07 0 d--h----- C:\Documents and Settings\Monty\Templates
2007-08-10 20:45:07 0 d-------- C:\Documents and Settings\Monty\Start Menu
2007-08-10 20:45:07 0 dr-h----- C:\Documents and Settings\Monty\SendTo
2007-08-10 20:45:07 0 dr-h----- C:\Documents and Settings\Monty\Recent
2007-08-10 20:45:07 0 d--h----- C:\Documents and Settings\Monty\PrintHood
2007-08-10 20:45:07 4980736 --ah----- C:\Documents and Settings\Monty\NTUSER.DAT
2007-08-10 20:45:07 0 d--h----- C:\Documents and Settings\Monty\NetHood
2007-08-10 20:45:07 0 dr------- C:\Documents and Settings\Monty\My Documents
2007-08-10 20:45:07 0 d--h----- C:\Documents and Settings\Monty\Local Settings
2007-08-10 20:45:07 0 dr------- C:\Documents and Settings\Monty\Favorites
2007-08-10 20:45:07 0 d-------- C:\Documents and Settings\Monty\Desktop
2007-08-10 20:45:07 0 d--hs---- C:\Documents and Settings\Monty\Cookies
2007-08-10 20:45:07 0 d--h----- C:\Documents and Settings\Monty\Application Data
2007-08-10 20:44:16 0 d--hs---- C:\System Volume Information
2007-08-10 20:44:15 229376 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2007-08-10 20:44:15 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2007-08-10 20:44:15 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2007-08-10 20:44:15 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2007-08-10 20:44:15 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2007-08-10 20:44:15 229376 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2007-08-10 20:44:15 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2007-08-10 20:44:15 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2007-08-10 20:44:15 0 d-------- C:\Documents and Settings\LocalService\Application Data
2007-08-10 20:44:15 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2007-08-10 20:41:23 0 d-------- C:\WINDOWS\system32\xircom
2007-08-10 20:41:23 0 d-------- C:\Program Files\microsoft frontpage
2007-08-10 20:41:17 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2007-08-10 20:41:11 0 -r-hs---- C:\MSDOS.SYS
2007-08-10 20:41:11 0 -r-hs---- C:\IO.SYS
2007-08-10 20:41:11 0 -----n--- C:\CONFIG.SYS
2007-08-10 20:41:11 0 -----n--- C:\AUTOEXEC.BAT
2007-08-10 20:40:44 0 d--hs---- C:\Documents and Settings\All Users\DRM
2007-08-10 20:40:39 0 dr------- C:\WINDOWS\Offline Web Pages
2007-08-10 20:40:39 0 d---s---- C:\WINDOWS\Downloaded Program Files
2007-08-10 20:40:22 0 d-------- C:\WINDOWS\system32\DirectX
2007-08-10 20:39:46 0 d---s---- C:\WINDOWS\Tasks
2007-08-10 20:39:43 0 d-------- C:\Program Files\Common Files\MSSoap
2007-08-10 20:39:39 0 d-------- C:\WINDOWS\system32\Macromed
2007-08-10 20:39:39 0 d-------- C:\WINDOWS\srchasst
2007-08-10 20:39:37 0 d-------- C:\Program Files\Movie Maker
2007-08-10 20:39:33 0 d-------- C:\WINDOWS\system32\Restore
2007-08-10 20:39:33 0 d-------- C:\WINDOWS\PCHealth
2007-08-10 20:39:13 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-10 20:39:12 0 d-------- C:\WINDOWS\Registration
2007-08-10 20:39:10 0 d--h----- C:\Program Files\WindowsUpdate
2007-08-10 20:39:10 0 d-------- C:\Program Files\Online Services
2007-08-10 20:39:06 0 d-------- C:\Program Files\Messenger
2007-08-10 20:39:02 0 d-------- C:\Program Files\MSN Gaming Zone
2007-08-10 20:38:31 0 d-------- C:\Program Files\Windows NT
2007-08-10 20:38:29 0 d-------- C:\WINDOWS\system32\MsDtc
2007-08-10 20:38:28 0 d-------- C:\WINDOWS\system32\Com
-- Find3M Report ---------------------------------------------------------------
2007-09-22 16:13:46 76 --ah----- C:\Program Files\Desktop.ini
2007-08-10 21:31:55 62 --ahs---- C:\Documents and Settings\Monty\Application Data\desktop.ini
2007-07-27 00:06:22 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-27 00:03:48 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2007-07-27 00:03:48 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2007-07-27 00:03:38 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2007-07-27 00:03:38 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2007-07-27 00:03:38 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2007-07-27 00:03:38 740442 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2007-07-27 00:03:02 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-06-29 00:43:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe
2007-06-29 00:43:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2007-06-29 00:43:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-29 00:43:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43:00 1474560 --a------ C:\WINDOWS\system32\nview.dll
2007-06-29 00:43:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2007-06-29 00:43:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2007-06-29 00:43:00 425984 --a------ C:\WINDOWS\system32\keystone.exe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [29/06/2007 00:43]
"nwiz"="nwiz.exe" [29/06/2007 00:43 C:\WINDOWS\system32\nwiz.exe]
"SkyTel"="SkyTel.EXE" [16/05/2006 11:04 C:\WINDOWS\SkyTel.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [09/01/2007 22:59]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [05/09/2006 22:22]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [12/03/2007 18:30]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [29/06/2007 00:43]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [17/08/2007 11:27]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 00:56]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [07/09/2007 00:35]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v2 Smart Configuration.lnk - C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe [14/10/2004 12:32:18]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Monty^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Monty\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Monty^Start Menu^Programs^Startup^uTorrent.lnk]
path=C:\Documents and Settings\Monty\Start Menu\Programs\Startup\uTorrent.lnk
backup=C:\WINDOWS\pss\uTorrent.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Program Files\Google\Google Talk\googletalk.exe /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
C:\Program Files\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
"C:\Program Files\uTorrent\uTorrent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"RichVideo"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McDetect.exe"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"nlsvc"=2 (0x2)
"StyleXPService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"iPod Service"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"ColdFusion MX 7 Search Server"=2 (0x2)
"ColdFusion MX 7 Application Server"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Bonjour Service"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2007-09-08 22:51:56 ------------
[font=\"Arial Black\"][color=\"#006400\"]THIS IS WHAT I HAD OF THE extra.txt :
[/color][/font][/b]
Deckard's System Scanner v20070905.67
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: AMD Athlonâ„¢ 64 X2 Dual Core Processor 6000+
CPU 1: AMD Athlonâ„¢ 64 X2 Dual Core Processor 6000+
Percentage of Memory in Use: 32%
Physical Memory (total/avail): 1023.23 MiB / 685.93 MiB
Pagefile Memory (total/avail): 2461.39 MiB / 2210.04 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1957.28 MiB
C: is Fixed (NTFS) - 58.17 GiB total, 36.93 GiB free.
D: is CDROM (No Media)
F: is Fixed (NTFS) - 174.72 GiB total, 147.55 GiB free.
\\.\PHYSICALDRIVE0 - SATA WD C WD2500 SCSI Disk Device - 232.88 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 58.17 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 174.72 GiB - F:
-- Security Center -------------------------------------------------------------
AUOptions is disabled.
AUState says computer has updates disabled.
Windows Internal Firewall is enabled.
AntiVirusDisableNotify is set.
FirewallDisableNotify is set.
FW: Norton AntiVirus v2007 (Symantec Corporation)
AV: Norton AntiVirus v2007 (Symantec Corporation)
AV: McAfee VirusScan v (McAfee) [color=\"RED\"]Disabled[/color]
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Documents and Settings\\Monty\\Start Menu\\Programs\\uTorrent\\uTorrent.exe"="C:\\Documents and Settings\\Monty\\Start Menu\\Programs\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\DC++\\DCPlusPlus.exe"="C:\\Program Files\\DC++\\DCPlusPlus.exe:*:Enabled:DC++"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Documents and Settings\\Monty\\Start Menu\\Programs\\N E T\\uTorrent\\uTorrent.exe"="C:\\Documents and Settings\\Monty\\Start Menu\\Programs\\N E T\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\EA GAMES\\Need for Speed Most Wanted\\speed.exe"="C:\\Program Files\\EA GAMES\\Need for Speed Most Wanted\\speed.exe:*:Enabled:speed"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Monty\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=DOOMSDAY
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Monty
LOGONSERVER=\\DOOMSDAY
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\CFusionMX7\verity\k2\_nti40\bin;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 67 Stepping 3, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=4303
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Monty\LOCALS~1\Temp
TMP=C:\DOCUME~1\Monty\LOCALS~1\Temp
USERDOMAIN=DOOMSDAY
USERNAME=Monty
USERPROFILE=C:\Documents and Settings\Monty
VERITY_CFG=C:\CFusionMX7\verity\k2\common\verity.cfg
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Monty
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Adobe Acrobat 8 Professional - English, Français, Deutsch --> msiexec /I {AC76BA86-1033-F400-7760-000000000003}
Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3 --> MsiExec.exe /I{8BC84ECC-EA87-49C0-93C0-2B5DF62745CD}
Adobe Bridge CS3 --> MsiExec.exe /I{68CF6DD2-8BA3-4A70-81D8-7CC5F24C9BA2}
Adobe Bridge Start Meeting --> MsiExec.exe /I{7F3A2319-79CF-4701-95FB-034E99281808}
Adobe Camera Raw 4.0 --> MsiExec.exe /I{183B7569-90FB-4C56-9761-0EEB002CAB83}
Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3 --> MsiExec.exe /I{20B83B31-09C4-4F0E-9774-EF8A12A0A527}
Adobe Dreamweaver CS3 --> C:\Program Files\Common Files\Adobe\Installers\435a6af7459cb02a9c1138113a26e93\Setup.exe
Adobe Dreamweaver CS3 --> MsiExec.exe /I{F01D5ED5-D53A-4468-B428-149DC2CB3110}
Adobe ExtendScript Toolkit 2 --> MsiExec.exe /I{4DF98D0B-637E-42B4-B9D6-EB7693D2FBF8}
Adobe Extension Manager CS3 --> MsiExec.exe /I{2A539CD9-0F75-4875-9A32-E06DD93C4114}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
Adobe Help Viewer CS3 --> MsiExec.exe /I{733D84D6-AAFD-4368-A1D0-F2734F6B9082}
Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Setup --> MsiExec.exe /I{3A12C952-61D5-4C3B-B68B-8CFBE