this is the main text notepad i will send the second one to you straight after,god bless bro,you should be my neighbour/
Deckard's System Scanner v20071014.68
Run by EDDY on 2008-03-28 09:31:43
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
112: 2008-03-28 09:31:53 UTC - RP112 - Deckard's System Scanner Restore Point
111: 2008-03-28 03:05:56 UTC - RP111 - Software Distribution Service 3.0
110: 2008-03-28 01:39:42 UTC - RP110 - Restore Operation
109: 2008-03-28 01:32:02 UTC - RP109 - Restore Operation
108: 2008-03-28 01:26:11 UTC - RP108 - 12/03/08 AT 1200
-- First Restore Point --
1: 2008-01-30 01:47:21 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
--
HijackThis (run as EDDY.exe) ------------------------------------------------
Logfile of Trend Micro
HijackThis v2.0.2
Scan saved at 09:32:56, on 28/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NetProject\sbmntr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Common Files\WinPCDoctor\strpmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MemInfo\meminfo.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Azureus\Azureus.exe
C:\Documents and Settings\EDDY\Local Settings\Temporary Internet Files\Content.IE5\Z05KFWRG\dss[1].exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\EDDY.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.crawler.com/search/dispatcher...w=%s&tbid=60076
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: 299914 helper - {47DF236B-7D10-4C01-9820-50C0D54E7841} - C:\WINDOWS\system32\299914\299914.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: 375013 helper - {74F7DB6B-86E9-4B91-9D9F-B0D954D7AA5B} - C:\WINDOWS\system32\375013\375013.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [strpmon] "C:\Program Files\Common Files\WinPCDoctor\strpmon.exe" dm=http://winpcdoctor.com ad=http://winpcdoctor.com sd=http://inspaid.winpcdoctor.com
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinPCDoctor\strpmon.exe" dm=http://winpcdoctor.com ad=http://winpcdoctor.com sd=http://inspaid.winpcdoctor.com
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
O4 - HKCU\..\Run: [WinPatrol Helper DLL] C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [SpyShredder] C:\Program Files\SpyShredder\SpyShredder.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: MemInfo.lnk = C:\Program Files\MemInfo\meminfo.exe
O4 - Startup: WordWeb.lnk = C:\Documents and Settings\EDDY\My Documents\WordWeb\wweb32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} -
http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} -
http://www.iefixgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microsof...b?1201727103468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsof...b?1201727078062
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.sun.com/update/1.6.0/j...ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{99525DF8-A407-4756-8479-1E90AA2806D3}: NameServer = 62.30.112.39,194.117.134.19
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: bimaculate - {d70e9b0f-aabc-4066-8176-c6de84d92fa1} - C:\WINDOWS\system32\kknwg.dll
O23 - Service:
Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service:
Apple Mobile Device -
Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service -
Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service -
Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
--
End of file - 7216 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 Pcatip - c:\windows\system32\drivers\pcatip.sys <Not Verified; VSO Software;
Patin-Couffin Autoplay(tm) support driver>
R3 Pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 ZSMC302 (VIMICRO USB PC Camera) - c:\windows\system32\drivers\usbvm31b.sys <Not Verified; VM; >
S3 BDFsDrv - c:\program files\softwin\bitdefender10\bdfsdrv.sys (file missing)
S3 BDRsDrv - c:\program files\softwin\bitdefender10\bdrsdrv.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2
Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified;
Apple, Inc.;
Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified;
Apple Inc.; Bonjour>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-03-27 18:00:00 440 --a------ C:\WINDOWS\Tasks\ParetoLogic Registration.job
2008-03-24 16:02:47 344 --a------ C:\WINDOWS\Tasks\SmartDefrag.job
-- Files created between 2008-02-28 and 2008-03-28 -----------------------------
2008-03-28 07:45:57 0 d-------- C:\UBCD4Win
2008-03-28 04:57:20 0 d-------- C:\Program Files\AntiSpyKit 5.3
2008-03-28 01:46:19 0 d-------- C:\Program Files\Trend Micro
2008-03-28 01:37:46 0 d-------- C:\Program Files\Microsoft Silverlight
2008-03-28 00:57:34 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-27 23:01:14 0 d-------- C:\WINDOWS\system32\299914
2008-03-27 20:40:55 0 d-------- C:\Program Files\Lavasoft
2008-03-27 20:40:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-27 20:40:02 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-27 18:48:55 0 dr-h----- C:\Documents and Settings\EDDY\Recent
2008-03-27 12:00:09 0 d-------- C:\Program Files\CCleaner
2008-03-27 02:29:56 0 d-------- C:\Documents and Settings\All Users\Application Data\YourPrivacyGuard
2008-03-27 00:31:45 0 d-------- C:\Program Files\Common Files\SecurePCCleaner
2008-03-27 00:24:13 0 dr------- C:\Documents and Settings\All Users\Application Data\winpcdoctor
2008-03-27 00:23:40 0 d-------- C:\Program Files\Common Files\WinPCDoctor
2008-03-27 00:21:49 261896 --a------ C:\Documents and Settings\EDDY\Application Data\setup_en[1].exe <Not Verified; Locus Software, Inc.; Locus Installer>
2008-03-26 23:55:19 0 d-------- C:\WINDOWS\system32\375013
2008-03-26 23:54:55 0 d-------- C:\Program Files\NetProject
2008-03-24 11:22:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-03-23 14:11:22 0 d-------- C:\Documents and Settings\EDDY\Application Data\MozillaControl
2008-03-23 10:24:49 0 d-------- C:\Documents and Settings\EDDY\Application Data\Opera
2008-03-22 21:16:04 0 d-------- C:\Documents and Settings\EDDY\AbiSuite
2008-03-22 18:30:41 0 d-------- C:\Program Files\LingvoSoft
2008-03-22 18:13:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Transparent
2008-03-20 12:58:30 0 d-------- C:\Program Files\Mozilla
Firefox 3 Beta 4
2008-03-19 00:32:46 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-03-19 00:27:21 0 d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-03-18 23:36:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-03-18 23:36:12 216576 --a------ C:\WINDOWS\system32\monln.dll <Not Verified; Comodo Inc.; Comodo Anti-Viruspyware>
2008-03-15 19:34:08 0 d-------- C:\Program Files\DivX
2008-03-15 19:28:29 36734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2008-03-15 19:04:51 0 d-------- C:\Program Files\Common Files\xing shared
2008-03-11 12:09:41 0 d-------- C:\Program Files\Kontiki
2008-03-11 12:09:41 0 d-------- C:\logs3
2008-03-11 12:09:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-03-11 12:09:23 0 d-------- C:\WINDOWS\Downloaded Installations
2008-03-06 00:05:37 0 d-------- C:\Documents and Settings\EDDY\Application Data\Real
2008-03-02 06:54:26 56832 --a------ C:\WINDOWS\system32\Iyvu9_32.dll
2008-03-02 06:54:26 27648 --a------ C:\WINDOWS\system32\ir50_lcs.dll <Not Verified;
Intel Corporation.;
Intel Indeo® video 5.0 LC>
2008-03-02 06:54:09 305152 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-03-02 06:51:00 0 d-------- C:\Program Files\LEAD Technologies, Inc
2008-03-02 06:35:04 62464 --a------ C:\WINDOWS\system32\cygz.dll
2008-03-02 06:35:04 1208320 --a------ C:\WINDOWS\system32\cygxml2-2.dll
2008-03-02 06:35:04 1153417 --a------ C:\WINDOWS\system32\cygwin1.dll <Not Verified; Red Hat; Cygwin>
2008-03-02 06:35:04 980992 --a------ C:\WINDOWS\system32\cygiconv-2.dll
2008-03-02 06:33:57 57344 --a------ C:\WINDOWS\system32\WNASPINT.DLL <Not Verified; NexiTech, Inc.; NexiTech ASPI for Win32>
2008-03-01 18:34:45 0 d-------- C:\Program Files\iPod
-- Find3M Report ---------------------------------------------------------------
2008-03-28 09:32:59 0 d-------- C:\Documents and Settings\EDDY\Application Data\Azureus
2008-03-28 09:28:06 0 d-------- C:\Documents and Settings\EDDY\Application Data\Vso
2008-03-28 09:28:05 668 --a------ C:\Documents and Settings\EDDY\Application Data\vso_ts_preview.xml
2008-03-27 20:40:02 0 d-------- C:\Program Files\Common Files
2008-03-27 20:30:25 0 d-------- C:\Program Files\Windows Media Connect 2
2008-03-27 02:40:00 6397 --a------ C:\Documents and Settings\EDDY\Application Data\update.log
2008-03-25 21:39:00 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-25 13:04:56 0 d-------- C:\Program Files\Azureus
2008-03-25 09:57:13 0 d-------- C:\Documents and Settings\EDDY\Application Data\uTorrent
2008-03-24 16:02:39 0 d-------- C:\Program Files\IObit
2008-03-24 15:12:31 13312 --a-s---- C:\WINDOWS\system32\kknwg.dll
2008-03-24 10:35:11 0 d-------- C:\Documents and Settings\EDDY\Application Data\CopyToDvd
2008-03-20 12:58:54 0 d-------- C:\Documents and Settings\EDDY\Application Data\Mozilla
2008-03-19 01:05:13 0 d-------- C:\Program Files\XP Smoker
2008-03-17 22:31:51 0 d-------- C:\Documents and Settings\EDDY\Application Data\BSplayer PRO
2008-03-15 19:10:00 0 d-------- C:\Documents and Settings\EDDY\Application Data\DivX
2008-03-14 22:48:10 0 d-------- C:\Documents and Settings\EDDY\Application Data\DVD Flick
2008-03-02 06:36:17 0 d-------- C:\Program Files\Cucusoft
2008-03-01 18:34:56 0 d-------- C:\Program Files\iTunes
2008-02-21 02:04:16 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified;
DivX, Inc.;
DivX, Inc. dtu100>
2008-02-21 02:04:04 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified;
DivX, Inc.;
DivX?>
2008-02-21 02:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified;
DivX, Inc.; DivX®>
2008-02-21 02:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified;
DivX, Inc.; DivX®>
2008-02-21 02:03:24 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-18 13:13:14 0 d-------- C:\Program Files\NCH Swift Sound
2008-02-15 02:44:08 0 d-------- C:\Program Files\Driver Magician
2008-02-15 01:19:03 0 d-------- C:\Documents and Settings\EDDY\Application Data\Help
2008-02-10 18:29:35 0 d-------- C:\Documents and Settings\EDDY\Application Data\ImgBurn
2008-02-10 18:29:11 0 d-------- C:\Program Files\ImgBurn
2008-02-10 00:00:44 0 d-------- C:\Program Files\Alwil Software
2008-02-09 20:03:52 0 d-------- C:\Documents and Settings\EDDY\Application Data\Any DVD Converter Professional
2008-02-09 20:00:49 0 d-------- C:\Program Files\Any DVD Converter Professional
2008-02-09 19:53:20 0 d-------- C:\Documents and Settings\EDDY\Application Data\Media Player Classic
2008-02-09 19:51:54 680 --a------ C:\Documents and Settings\EDDY\Application Data\coreavc.ini
2008-02-08 22:50:25 0 d-------- C:\Program Files\iSofter
2008-02-06 21:29:10 0 d-------- C:\Documents and Settings\EDDY\Application Data\Nero
2008-02-06 11:11:06 0 d-------- C:\Documents and Settings\EDDY\Application Data\WinSpyControl
2008-02-05 22:05:06 0 d-------- C:\Program Files\VSO
2008-02-05 15:19:29 0 d-------- C:\Documents and Settings\EDDY\Application Data\NCH Swift Sound
2008-02-05 10:43:54 0 d-------- C:\Documents and Settings\EDDY\Application Data\Launchy
2008-02-05 09:30:17 0 d-------- C:\Documents and Settings\EDDY\Application Data\VSO_HWE
2008-02-04 20:51:15 0 d-------- C:\Documents and Settings\EDDY\Application Data\Ahead
2008-02-04 20:18:29 0 d-------- C:\Program Files\MSECache
2008-02-04 19:59:33 0 d-------- C:\Program Files\Microsoft DirectX SDK (November 2007)
2008-02-04 18:04:39 0 d-------- C:\Program Files\Noël Danjou
2008-02-04 07:20:46 0 d-------- C:\Program Files\MemInfo
2008-02-02 19:55:19 0 d-------- C:\Documents and Settings\EDDY\Application Data\IObit
2008-02-02 18:18:36 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-02 17:16:29 0 d-------- C:\Documents and Settings\EDDY\Application Data\SpywareRemover
2008-02-02 17:08:34 0 d-------- C:\Documents and Settings\EDDY\Application Data\Avant Profiles
2008-02-02 17:08:31 0 d-------- C:\Program Files\Avant Browser
2008-02-02 16:59:45 0 d-------- C:\Program Files\Citi-Software
2008-02-02 16:17:06 0 d-------- C:\Program Files\NCH Software
2008-02-01 23:01:14 0 d-------- C:\Program Files\Cool PDF Reader
2008-02-01 22:32:14 0 d-------- C:\Program Files\Machinist2DLL
2008-02-01 21:49:28 0 d-------- C:\Program Files\007DVD
2008-02-01 09:31:39 0 dr------- C:\Documents and Settings\EDDY\Application Data\Brother
2008-02-01 09:17:42 50 --a------ C:\WINDOWS\system32\bridf07a.dat
2008-02-01 09:17:29 0 d-------- C:\Program Files\Brother
2008-02-01 09:15:57 0 d-------- C:\Documents and Settings\EDDY\Application Data\InstallShield
2008-02-01 09:14:56 0 d-------- C:\Program Files\Nuance
2008-02-01 09:13:42 0 d-------- C:\Program Files\Common Files\ScanSoft Shared
2008-02-01 09:13:38 0 d-------- C:\Program Files\Common Files\InstallShield
2008-02-01 09:13:24 0 d-------- C:\Program Files\ScanSoft
2008-02-01 08:05:19 0 d-------- C:\Program Files\uTorrent
2008-02-01 01:00:58 0 d-------- C:\Program Files\Real
2008-02-01 00:42:44 0 d-------- C:\Program Files\AC3Filter
2008-02-01 00:18:46 0 d-------- C:\Program Files\coverXP
2008-02-01 00:07:28 0 d-------- C:\Program Files\DVDFab Gold 4
2008-01-31 23:56:41 34 --a------ C:\Documents and Settings\EDDY\Application Data\pcouffin.log
2008-01-31 23:56:36 47360 --a------ C:\Documents and Settings\EDDY\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2008-01-31 23:56:36 1144 --a------ C:\Documents and Settings\EDDY\Application Data\pcouffin.inf
2008-01-31 23:56:36 7887 --a------ C:\Documents and Settings\EDDY\Application Data\pcouffin.cat
2008-01-31 23:56:35 0 d-------- C:\Program Files\DVDFab Platinum 4
2008-01-31 23:50:08 0 d-------- C:\Documents and Settings\EDDY\Application Data\Apple Computer
2008-01-31 23:49:35 0 d-------- C:\Program Files\Bonjour
2008-01-31 23:48:29 0 d-------- C:\Program Files\Apple Software Update
2008-01-31 23:48:05 0 d-------- C:\Program Files\Common Files\Apple
2008-01-31 23:34:38 0 d-------- C:\Documents and Settings\EDDY\Application Data\WinPatrol
2008-01-31 23:34:30 0 d-------- C:\Program Files\BillP Studios
2008-01-31 23:17:33 0 d-------- C:\Documents and Settings\EDDY\Application Data\Adobe
2008-01-31 22:42:23 0 d-------- C:\Program Files\Windows Live
2008-01-31 22:40:15 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-31 22:20:31 0 d-------- C:\Program Files\Messenger
2008-01-31 21:07:37 0 d-------- C:\Documents and Settings\EDDY\Application Data\LimeWire
2008-01-31 21:04:37 0 d-------- C:\Program Files\LimeWire
2008-01-31 20:35:27 0 d-------- C:\Program Files\Vimicro
2008-01-31 20:32:04 0 d-------- C:\Program Files\Xvid
2008-01-31 02:31:12 0 d-------- C:\Program Files\Microsoft Works
2008-01-31 02:30:57 0 d-------- C:\Program Files\MSBuild
2008-01-31 02:29:23 0 d-------- C:\Program Files\Microsoft.NET
2008-01-31 02:27:38 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-01-30 23:41:23 0 d-------- C:\Program Files\Common Files\Ahead
2008-01-30 23:34:49 0 d-------- C:\Program Files\Nero
2008-01-30 23:31:15 0 d-------- C:\Documents and Settings\EDDY\Application Data\vlc
2008-01-30 23:28:39 0 d-------- C:\Program Files\VideoLAN
2008-01-30 23:26:52 1167 --a------ C:\WINDOWS\mozver.dat
2008-01-30 23:23:17 0 d-------- C:\Documents and Settings\EDDY\Application Data\Macromedia
2008-01-30 23:12:31 0 d-------- C:\Documents and Settings\EDDY\Application Data\Sun
2008-01-30 23:03:20 0 d-------- C:\Program Files\Java
2008-01-30 23:01:58 0 d-------- C:\Program Files\Common Files\Java
2008-01-30 21:20:12 0 d-------- C:\Program Files\MSXML 6.0
2008-01-30 21:20:01 0 d-------- C:\Program Files\MSXML 4.0
2008-01-30 02:48:09 25004 --a------ C:\WINDOWS\system32\tcpipbak.reg
2008-01-30 02:34:19 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-30 01:47:09 0 d-------- C:\Documents and Settings\EDDY\Application Data\Identities
2008-01-30 01:19:05 0 d-------- C:\Program Files\microsoft frontpage
2008-01-30 01:18:49 0 -rahs---- C:\MSDOS.SYS
2008-01-30 01:18:49 0 -rahs---- C:\IO.SYS
2008-01-30 01:18:49 0 --a------ C:\CONFIG.SYS
2008-01-30 01:18:49 0 --a------ C:\AUTOEXEC.BAT
2008-01-30 01:17:32 0 d--h----- C:\Program Files\WindowsUpdate
2008-01-30 01:16:37 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-30 01:16:26 0 d-------- C:\Program Files\Movie Maker
2008-01-30 01:15:33 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-01-30 01:15:12 0 d-------- C:\Program Files\Online Services
2008-01-30 01:14:55 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-30 01:14:47 0 d-------- C:\Program Files\Windows NT
2008-01-30 01:07:55 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-30 01:07:51 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-01-30 01:07:28 62 --ahs---- C:\Documents and Settings\EDDY\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47DF236B-7D10-4C01-9820-50C0D54E7841}]
27/03/2008 23:01 13312 --a------ C:\WINDOWS\system32\299914\299914.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74F7DB6B-86E9-4B91-9D9F-B0D954D7AA5B}]
26/03/2008 23:55 13312 --a------ C:\WINDOWS\system32\375013\375013.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]
28/03/2008 03:14 10240 --a------ C:\Program Files\NetProject\sbmdl.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40}"= C:\Program Files\NetProject\wamdl.dll [26/03/2008 23:55 85504]
[-HKEY_CLASSES_ROOT\CLSID\{DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [19/02/2008 13:10]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [09/06/2004 15:37]
"SmartDefrag"="C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" [07/01/2008 23:29]
"strpmon"="C:\Program Files\Common Files\WinPCDoctor\strpmon.exe" [26/02/2008 09:40]
"Salestart"="C:\Program Files\Common Files\WinPCDoctor\strpmon.exe" [26/02/2008 09:40]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol Helper DLL"="C:\Program Files\BillP Studios\WinPatrol\patrolpro.dll" [27/01/2008 05:38]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [18/10/2007 11:34]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [03/08/2004 23:56]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [27/02/2008 17:56]
"Windows update loader"="C:\Windows\xpupdate.exe" [27/03/2008 23:00]
"SpyShredder"="C:\Program Files\SpyShredder\SpyShredder.exe" []
C:\Documents and Settings\EDDY\Start Menu\Programs\Startup\
MemInfo.lnk - C:\Program Files\MemInfo\meminfo.exe [13/01/2008 17:16:32]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"Wallpaper"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
"NoStartMenuEjectPC"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"some"=C:\Program Files\NetProject\scit.exe
"start"=C:\Program Files\NetProject\sbmntr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceActiveDesktopOn"=1 (0x1)
"NoSetActiveDesktop"=0 (0x0)
"NoActiveDesktopChanges"=0 (0x0)
"NoActiveDesktop"=2 (0x2)
"NoViewContextMenu"=0 (0x0)
"NoDFSTab"=0 (0x0)
"NoSecurityTab"=0 (0x0)
"NoHardwareTab"=0 (0x0)
"NoToolbarCustomize"=1 (0x1)
"NoBandCustomize"=0 (0x0)
"NoFileMenu"=0 (0x0)
"NoFolderOptions"=0 (0x0)
"NoPropertiesMyComputer"=0 (0x0)
"NoFileAssociate"=0 (0x0)
"NoLowDiskSpaceChecks"=1 (0x1)
"NoInstrumentation"=1 (0x1)
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"ClearRecentDocsOnExit"=0 (0x0)
"NoDesktopCleanupWizard"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoRecycleFiles"=1 (0x1)
"NoWelcomeScreen"=1 (0x1)
"NoStartMenuEjectPC"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{d70e9b0f-aabc-4066-8176-c6de84d92fa1}"= C:\WINDOWS\system32\kknwg.dll [24/03/2008 15:12 13312]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\K-Lite
Codec Pack\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
-- End of Deckard's System Scanner: finished at 2008-03-28 09:33:24 ------------