"Owner" - 07-01-15 22:09:21 Service Pack 2
ComboFix 07-01-15 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\INSTALL.LOG
C:\WINDOWS\system32\drivers\fad.sys
C:\Program Files\Common Files\{6C6EB~1
C:\Program Files\PrintView
((((((((((((((((((((((((((((((( Files Created from 2006-12-15 to 2007-01-15 ))))))))))))))))))))))))))))))))))
2007-01-15 16:54 d-------- C:\Program Files\Security Task Manager
2007-01-15 16:54 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\SecTaskMan
2007-01-13 23:13 d-------- C:\avenger
2007-01-13 10:38 d-------- C:\Program Files\jv16 PowerTools 2006
2007-01-13 10:34 929,844 --a------ C:\WINDOWS\system32\MFC42D.DLL
2007-01-13 10:34 8 -r-hs---- C:\WINDOWS\system32\30954A8E6B.sys
2007-01-13 10:34 3,350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-01-11 14:45 d-------- C:\Program Files\Hijackthis
2007-01-09 18:34 d-------- C:\fixwareout
2007-01-08 21:06 d-------- C:\Sierra
2007-01-08 13:03 dr--s---- C:\WINDOWS\assembly
2007-01-08 13:02 d-------- C:\WINDOWS\Microsoft.NET
2007-01-04 11:51 d-------- C:\DOCUME~1\Owner\Application Data\InstallShield
2007-01-04 11:45 d-------- C:\DirectX9
2007-01-03 19:34 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-02 15:43 d-------- C:\Program Files\Windows Defender
2007-01-01 20:21 d-------- C:\Program Files\Common Files\Java
2006-12-30 12:46 d-------- C:\Program Files\Windows Media Connect 2
2006-12-30 12:44 d-------- C:\WINDOWS\system32\LogFiles
2006-12-30 12:44 d-------- C:\WINDOWS\system32\drivers\UMDF
2006-12-28 01:49 d-------- C:\DOCUME~1\Owner\Application Data\Uniblue
2006-12-27 14:12 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\nView_Profiles
2006-12-27 13:10 86,016 -ra------ C:\WINDOWS\system32\nvrszht.dll
2006-12-27 13:10 294,912 -ra------ C:\WINDOWS\system32\nvwrses.dll
2006-12-27 13:10 294,912 -ra------ C:\WINDOWS\system32\nvwrsel.dll
2006-12-27 13:10 286,720 -ra------ C:\WINDOWS\system32\nvwrsesm.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrspt.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrsit.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrsfr.dll
2006-12-27 13:10 278,528 -ra------ C:\WINDOWS\system32\nvwrsptb.dll
2006-12-27 13:10 278,528 -ra------ C:\WINDOWS\system32\nvwrsnl.dll
2006-12-27 13:10 274,432 -ra------ C:\WINDOWS\system32\nvwrsru.dll
2006-12-27 13:10 274,432 -ra------ C:\WINDOWS\system32\nvwrshu.dll
2006-12-27 13:10 266,240 -ra------ C:\WINDOWS\system32\nvwrstr.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrssl.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrsno.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrsfi.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrssv.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrssk.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrspl.dll
2006-12-27 13:10 249,856 -ra------ C:\WINDOWS\system32\nvwrseng.dll
2006-12-27 13:10 241,664 -ra------ C:\WINDOWS\system32\nvwrshe.dll
2006-12-27 13:10 233,472 -ra------ C:\WINDOWS\system32\nvrshe.dll
2006-12-27 13:10 200,704 -ra------ C:\WINDOWS\system32\nvrsko.dll
2006-12-27 13:10 200,704 -ra------ C:\WINDOWS\system32\nvrsja.dll
2006-12-27 13:10 196,608 -ra------ C:\WINDOWS\system32\nvrsit.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrsfr.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrses.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrsel.dll
2006-12-27 13:10 188,416 -ra------ C:\WINDOWS\system32\nvrsnl.dll
2006-12-27 13:10 188,416 -ra------ C:\WINDOWS\system32\nvrsesm.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvwrsja.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrsru.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrsptb.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrspt.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrstr.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrspl.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrsno.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrshu.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvwrsko.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrszhc.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssv.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssl.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssk.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrseng.dll
2006-12-27 13:10 167,936 -ra------ C:\WINDOWS\system32\nvrsfi.dll
2006-12-27 13:10 147,456 -ra------ C:\WINDOWS\system32\nvwrszht.dll
2006-12-27 13:10 143,360 -ra------ C:\WINDOWS\system32\nvwrszhc.dll
2006-12-27 13:09 843,776 -ra------ C:\WINDOWS\system32\nwiz.exe
2006-12-27 13:09 81,920 -ra------ C:\WINDOWS\system32\nvwddi.dll
2006-12-27 13:09 81,920 -ra------ C:\WINDOWS\system32\nvmctray.dll
2006-12-27 13:09 5,222,400 -ra------ C:\WINDOWS\system32\nvoglnt.dll
2006-12-27 13:09 454,656 -ra------ C:\WINDOWS\system32\nvshell.dll
2006-12-27 13:09 438,272 -ra------ C:\WINDOWS\system32\nvappbar.exe
2006-12-27 13:09 4,112,384 -ra------ C:\WINDOWS\system32\nvcpl.dll
2006-12-27 13:09 352,256 -ra------ C:\WINDOWS\system32\keystone.exe
2006-12-27 13:09 32,256 -ra------ C:\WINDOWS\system32\nvcodins.dll
2006-12-27 13:09 32,256 --a------ C:\WINDOWS\system32\nvcod.dll
2006-12-27 13:09 266,240 -ra------ C:\WINDOWS\system32\nvwrsde.dll
2006-12-27 13:09 258,048 -ra------ C:\WINDOWS\system32\nvwrsda.dll
2006-12-27 13:09 249,856 -ra------ C:\WINDOWS\system32\nvwrscs.dll
2006-12-27 13:09 245,760 -ra------ C:\WINDOWS\system32\nvwrsar.dll
2006-12-27 13:09 241,664 -ra------ C:\WINDOWS\system32\nvnt4cpl.dll
2006-12-27 13:09 237,568 -ra------ C:\WINDOWS\system32\nvrsar.dll
2006-12-27 13:09 192,512 -ra------ C:\WINDOWS\system32\nvrsde.dll
2006-12-27 13:09 176,128 -ra------ C:\WINDOWS\system32\nvrsda.dll
2006-12-27 13:09 172,032 --a------ C:\WINDOWS\system32\nvudisp.exe
2006-12-27 13:09 167,936 -ra------ C:\WINDOWS\system32\nvrscs.dll
2006-12-27 13:09 114,755 -ra------ C:\WINDOWS\system32\nvsvc32.exe
2006-12-27 13:09 1,642,496 -ra------ C:\WINDOWS\system32\nvwdmcpl.dll
2006-12-27 13:09 1,363,968 -ra------ C:\WINDOWS\system32\nview.dll
2006-12-27 13:09 1,110,016 -ra------ C:\WINDOWS\system32\nvdspsch.exe
2006-12-27 13:09 1,019,904 -ra------ C:\WINDOWS\system32\nvwimg.dll
2006-12-27 13:09 d-------- C:\WINDOWS\nview
2006-12-27 11:13 d-------- C:\Program Files\INAC
2006-12-27 11:08 d-------- C:\Program Files\NoAdware5.0
2006-12-27 10:48 d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2006-12-26 23:43 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\ParetoLogic Anti-Spyware
2006-12-25 21:38 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\VideoEgg
2006-12-25 11:38 d-------- C:\Program Files\GameShadow
2006-12-25 09:28 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-12-24 16:42 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll
2006-12-24 16:42 d-------- C:\Program Files\TuneUp Utilities 2007
2006-12-24 12:48 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-12-24 12:48 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-12-24 12:32 15,360 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-12-24 12:31 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-12-24 12:31 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-12-24 12:29 57,344 --a------ C:\WINDOWS\Unwash6.exe
2006-12-24 12:29 486,400 --a------ C:\WINDOWS\system32\wwSecure.exe
2006-12-24 12:29 d-------- C:\Program Files\Lavasoft
2006-12-24 12:28 5 --ahs---- C:\WINDOWS\system32\afeedbe5_s.dll
2006-12-19 17:55 d-------- C:\WINDOWS\NV17761524.TMP
2006-12-15 17:09 d-------- C:\Program Files\The Creative Assembly
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-14 12:03 -------- d-------- C:\Program Files\limewire
2007-01-14 12:03 -------- d-------- C:\Program Files\incomplete
2007-01-14 10:36 -------- d-------- C:\Program Files\msn messenger
2007-01-13 21:58 -------- d-------- C:\Program Files\google
2007-01-13 21:57 -------- d--h----- C:\Program Files\installshield installation information
2007-01-13 09:54 -------- d-------- C:\Program Files\itunes
2007-01-12 16:45 21840 --a----t- C:\WINDOWS\system32\sintfnt.dll
2007-01-12 16:45 17212 --a----t- C:\WINDOWS\system32\sintf32.dll
2007-01-12 16:45 12067 --a----t- C:\WINDOWS\system32\sintf16.dll
2007-01-11 16:41 -------- d-------- C:\Program Files\mozilla firefox
2007-01-11 15:53 -------- d---s---- C:\DOCUME~1\Owner\Application Data\microsoft
2007-01-07 17:42 43520 --a------ C:\WINDOWS\system32\cmdlineext03.dll
2007-01-05 03:26 -------- d-------- C:\Program Files\thq
2007-01-04 13:21 -------- d-------- C:\Program Files\Common Files\wise installation wizard
2007-01-03 20:01 -------- d-------- C:\Program Files\cant be deleted
2007-01-03 19:34 -------- d-------- C:\Program Files\grisoft
2007-01-03 17:53 -------- d-------- C:\DOCUME~1\Owner\Application Data\xfire
2007-01-01 21:14 -------- d---s---- C:\Program Files\xfire
2007-01-01 20:23 -------- d-------- C:\Program Files\java
2007-01-01 11:30 -------- d-------- C:\Program Files\webroot
2007-01-01 11:30 -------- d-------- C:\DOCUME~1\Owner\Application Data\webroot
2006-12-28 21:53 -------- d-------- C:\DOCUME~1\Owner\Application Data\avg7
2006-12-25 09:26 -------- d-------- C:\DOCUME~1\Owner\Application Data\macromedia
2006-12-24 12:48 816288 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-12-24 12:48 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-12-24 12:48 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-24 12:48 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-24 12:35 -------- d-------- C:\DOCUME~1\Owner\Application Data\lavasoft
2006-12-24 12:30 -------- d-------- C:\Program Files\Common Files\webroot shared
2006-12-24 10:33 -------- d-------- C:\Program Files\nokia
2006-12-24 10:33 -------- d-------- C:\Program Files\Common Files\symantec shared
2006-12-15 19:43 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-12-09 17:31 62 --a------ C:\WINDOWS\trwinupd.dll
2006-11-16 15:38 -------- d-------- C:\Program Files\msxml 4.0
2006-11-08 05:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-25 15:24 0 --a------ C:\Program Files\_iberr.txt
2006-10-19 13:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"Index Washer"="C:\\Program Files\\Webroot\\Washer\\WashIdx.exe \"Owner\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TalkTalk"="\"C:\\Program Files\\TalkTalk\\bin\\sprtcmd.exe\" /P TalkTalk"
"snpstd"="C:\\WINDOWS\\vsnpstd.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Alcatel\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"Windows Registry Repair Pro"="C:\\Program Files\\3B Software\\Windows Registry Repair Pro\\Windows Registry Repair Pro.exe -X"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
"backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
"location"="Common Startup"
"item"="Kodak EasyShare software"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"location"="Common Startup"
"item"="Kodak software updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
"location"="Common Startup"
"item"="MyWebSearch Email Plugin"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
"backup"="C:\\WINDOWS\\pss\\NkvMon.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Nikon\\NkView6\\NkvMon.exe "
"item"="NkvMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Delta Force-Black Hawk Down Team Sabre Registration.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Delta Force-Black Hawk Down Team Sabre Registration.lnk"
"backup"="C:\\WINDOWS\\pss\\Delta Force-Black Hawk Down Team Sabre Registration.lnkStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\{00BDC6D7-8461-4048-B0CF-4D3886C91571}\\{6164D2E7-986B-42F5-B3A6-64D5E53FB889}\\NOVG.EXE /remind /language=ENG /PRNM=\"Delta Force-Black Hawk Down Team Sabre\""
"item"="Delta Force-Black Hawk Down Team Sabre Registration"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Morpheus.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Morpheus.lnk"
"backup"="C:\\WINDOWS\\pss\\Morpheus.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Morpheus\\Morpheus.exe -min"
"item"="Morpheus"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
"location"="Startup"
"item"="MyWebSearch Email Plugin"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"item"="PowerReg Scheduler"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Webshots.lnk]
"backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Webshots\\WEBSHO~1.EXE "
"item"="Webshots"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1fork]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Curb Phone Amen"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Points Manager"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Virus Update Scheduler V1.39.12R]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msvc"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_EMC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgemc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DATALA~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Evidence Eliminator]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ee"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lxbbbmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Lexmark X74-X75\\lxbbbmgr.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Inet Xp..]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="teekids"
"hkey"="HKLM"
"command"="teekids.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TRAYAP~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperFreeEdition]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PSFree"
"hkey"="HKCU"
"command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"inimapping"="0"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vsnpstd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\vsnpstd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="spykiller"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpySweeperUI"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\styleerrorgplhelp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="math obj"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updmgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="updmgr"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="wwDisp"
"hkey"="HKCU"
"command"="C:\\Program Files\\Webroot\\Washer\\wwDisp.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="run"
"hkey"="HKLM"
"command"="run.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LexBceS"=dword:00000002
"iPodService"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MSN Update"="dllconfg.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"MSN Update"="dllconfg.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://images.google.co.uk/images?q...gator.ru/pub/savers/screensaverdfbhd2.exe.jpg
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
UxTuneUp
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42771541-ca29-11d8-9bce-806d6172696f}]
Shell\AutoRun\command D:\autoplay.exe
Completion time: 07-01-15 22:13:18
ComboFix 07-01-15 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\INSTALL.LOG
C:\WINDOWS\system32\drivers\fad.sys
C:\Program Files\Common Files\{6C6EB~1
C:\Program Files\PrintView
((((((((((((((((((((((((((((((( Files Created from 2006-12-15 to 2007-01-15 ))))))))))))))))))))))))))))))))))
2007-01-15 16:54 d-------- C:\Program Files\Security Task Manager
2007-01-15 16:54 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\SecTaskMan
2007-01-13 23:13 d-------- C:\avenger
2007-01-13 10:38 d-------- C:\Program Files\jv16 PowerTools 2006
2007-01-13 10:34 929,844 --a------ C:\WINDOWS\system32\MFC42D.DLL
2007-01-13 10:34 8 -r-hs---- C:\WINDOWS\system32\30954A8E6B.sys
2007-01-13 10:34 3,350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-01-11 14:45 d-------- C:\Program Files\Hijackthis
2007-01-09 18:34 d-------- C:\fixwareout
2007-01-08 21:06 d-------- C:\Sierra
2007-01-08 13:03 dr--s---- C:\WINDOWS\assembly
2007-01-08 13:02 d-------- C:\WINDOWS\Microsoft.NET
2007-01-04 11:51 d-------- C:\DOCUME~1\Owner\Application Data\InstallShield
2007-01-04 11:45 d-------- C:\DirectX9
2007-01-03 19:34 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-02 15:43 d-------- C:\Program Files\Windows Defender
2007-01-01 20:21 d-------- C:\Program Files\Common Files\Java
2006-12-30 12:46 d-------- C:\Program Files\Windows Media Connect 2
2006-12-30 12:44 d-------- C:\WINDOWS\system32\LogFiles
2006-12-30 12:44 d-------- C:\WINDOWS\system32\drivers\UMDF
2006-12-28 01:49 d-------- C:\DOCUME~1\Owner\Application Data\Uniblue
2006-12-27 14:12 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\nView_Profiles
2006-12-27 13:10 86,016 -ra------ C:\WINDOWS\system32\nvrszht.dll
2006-12-27 13:10 294,912 -ra------ C:\WINDOWS\system32\nvwrses.dll
2006-12-27 13:10 294,912 -ra------ C:\WINDOWS\system32\nvwrsel.dll
2006-12-27 13:10 286,720 -ra------ C:\WINDOWS\system32\nvwrsesm.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrspt.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrsit.dll
2006-12-27 13:10 282,624 -ra------ C:\WINDOWS\system32\nvwrsfr.dll
2006-12-27 13:10 278,528 -ra------ C:\WINDOWS\system32\nvwrsptb.dll
2006-12-27 13:10 278,528 -ra------ C:\WINDOWS\system32\nvwrsnl.dll
2006-12-27 13:10 274,432 -ra------ C:\WINDOWS\system32\nvwrsru.dll
2006-12-27 13:10 274,432 -ra------ C:\WINDOWS\system32\nvwrshu.dll
2006-12-27 13:10 266,240 -ra------ C:\WINDOWS\system32\nvwrstr.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrssl.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrsno.dll
2006-12-27 13:10 262,144 -ra------ C:\WINDOWS\system32\nvwrsfi.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrssv.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrssk.dll
2006-12-27 13:10 258,048 -ra------ C:\WINDOWS\system32\nvwrspl.dll
2006-12-27 13:10 249,856 -ra------ C:\WINDOWS\system32\nvwrseng.dll
2006-12-27 13:10 241,664 -ra------ C:\WINDOWS\system32\nvwrshe.dll
2006-12-27 13:10 233,472 -ra------ C:\WINDOWS\system32\nvrshe.dll
2006-12-27 13:10 200,704 -ra------ C:\WINDOWS\system32\nvrsko.dll
2006-12-27 13:10 200,704 -ra------ C:\WINDOWS\system32\nvrsja.dll
2006-12-27 13:10 196,608 -ra------ C:\WINDOWS\system32\nvrsit.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrsfr.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrses.dll
2006-12-27 13:10 192,512 -ra------ C:\WINDOWS\system32\nvrsel.dll
2006-12-27 13:10 188,416 -ra------ C:\WINDOWS\system32\nvrsnl.dll
2006-12-27 13:10 188,416 -ra------ C:\WINDOWS\system32\nvrsesm.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvwrsja.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrsru.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrsptb.dll
2006-12-27 13:10 184,320 -ra------ C:\WINDOWS\system32\nvrspt.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrstr.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrspl.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrsno.dll
2006-12-27 13:10 176,128 -ra------ C:\WINDOWS\system32\nvrshu.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvwrsko.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrszhc.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssv.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssl.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrssk.dll
2006-12-27 13:10 172,032 -ra------ C:\WINDOWS\system32\nvrseng.dll
2006-12-27 13:10 167,936 -ra------ C:\WINDOWS\system32\nvrsfi.dll
2006-12-27 13:10 147,456 -ra------ C:\WINDOWS\system32\nvwrszht.dll
2006-12-27 13:10 143,360 -ra------ C:\WINDOWS\system32\nvwrszhc.dll
2006-12-27 13:09 843,776 -ra------ C:\WINDOWS\system32\nwiz.exe
2006-12-27 13:09 81,920 -ra------ C:\WINDOWS\system32\nvwddi.dll
2006-12-27 13:09 81,920 -ra------ C:\WINDOWS\system32\nvmctray.dll
2006-12-27 13:09 5,222,400 -ra------ C:\WINDOWS\system32\nvoglnt.dll
2006-12-27 13:09 454,656 -ra------ C:\WINDOWS\system32\nvshell.dll
2006-12-27 13:09 438,272 -ra------ C:\WINDOWS\system32\nvappbar.exe
2006-12-27 13:09 4,112,384 -ra------ C:\WINDOWS\system32\nvcpl.dll
2006-12-27 13:09 352,256 -ra------ C:\WINDOWS\system32\keystone.exe
2006-12-27 13:09 32,256 -ra------ C:\WINDOWS\system32\nvcodins.dll
2006-12-27 13:09 32,256 --a------ C:\WINDOWS\system32\nvcod.dll
2006-12-27 13:09 266,240 -ra------ C:\WINDOWS\system32\nvwrsde.dll
2006-12-27 13:09 258,048 -ra------ C:\WINDOWS\system32\nvwrsda.dll
2006-12-27 13:09 249,856 -ra------ C:\WINDOWS\system32\nvwrscs.dll
2006-12-27 13:09 245,760 -ra------ C:\WINDOWS\system32\nvwrsar.dll
2006-12-27 13:09 241,664 -ra------ C:\WINDOWS\system32\nvnt4cpl.dll
2006-12-27 13:09 237,568 -ra------ C:\WINDOWS\system32\nvrsar.dll
2006-12-27 13:09 192,512 -ra------ C:\WINDOWS\system32\nvrsde.dll
2006-12-27 13:09 176,128 -ra------ C:\WINDOWS\system32\nvrsda.dll
2006-12-27 13:09 172,032 --a------ C:\WINDOWS\system32\nvudisp.exe
2006-12-27 13:09 167,936 -ra------ C:\WINDOWS\system32\nvrscs.dll
2006-12-27 13:09 114,755 -ra------ C:\WINDOWS\system32\nvsvc32.exe
2006-12-27 13:09 1,642,496 -ra------ C:\WINDOWS\system32\nvwdmcpl.dll
2006-12-27 13:09 1,363,968 -ra------ C:\WINDOWS\system32\nview.dll
2006-12-27 13:09 1,110,016 -ra------ C:\WINDOWS\system32\nvdspsch.exe
2006-12-27 13:09 1,019,904 -ra------ C:\WINDOWS\system32\nvwimg.dll
2006-12-27 13:09 d-------- C:\WINDOWS\nview
2006-12-27 11:13 d-------- C:\Program Files\INAC
2006-12-27 11:08 d-------- C:\Program Files\NoAdware5.0
2006-12-27 10:48 d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2006-12-26 23:43 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\ParetoLogic Anti-Spyware
2006-12-25 21:38 d-------- C:\DOCUME~1\ALLUSE~1\Application Data\VideoEgg
2006-12-25 11:38 d-------- C:\Program Files\GameShadow
2006-12-25 09:28 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-12-24 16:42 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll
2006-12-24 16:42 d-------- C:\Program Files\TuneUp Utilities 2007
2006-12-24 12:48 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-12-24 12:48 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-12-24 12:32 15,360 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-12-24 12:31 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-12-24 12:31 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-12-24 12:29 57,344 --a------ C:\WINDOWS\Unwash6.exe
2006-12-24 12:29 486,400 --a------ C:\WINDOWS\system32\wwSecure.exe
2006-12-24 12:29 d-------- C:\Program Files\Lavasoft
2006-12-24 12:28 5 --ahs---- C:\WINDOWS\system32\afeedbe5_s.dll
2006-12-19 17:55 d-------- C:\WINDOWS\NV17761524.TMP
2006-12-15 17:09 d-------- C:\Program Files\The Creative Assembly
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-14 12:03 -------- d-------- C:\Program Files\limewire
2007-01-14 12:03 -------- d-------- C:\Program Files\incomplete
2007-01-14 10:36 -------- d-------- C:\Program Files\msn messenger
2007-01-13 21:58 -------- d-------- C:\Program Files\google
2007-01-13 21:57 -------- d--h----- C:\Program Files\installshield installation information
2007-01-13 09:54 -------- d-------- C:\Program Files\itunes
2007-01-12 16:45 21840 --a----t- C:\WINDOWS\system32\sintfnt.dll
2007-01-12 16:45 17212 --a----t- C:\WINDOWS\system32\sintf32.dll
2007-01-12 16:45 12067 --a----t- C:\WINDOWS\system32\sintf16.dll
2007-01-11 16:41 -------- d-------- C:\Program Files\mozilla firefox
2007-01-11 15:53 -------- d---s---- C:\DOCUME~1\Owner\Application Data\microsoft
2007-01-07 17:42 43520 --a------ C:\WINDOWS\system32\cmdlineext03.dll
2007-01-05 03:26 -------- d-------- C:\Program Files\thq
2007-01-04 13:21 -------- d-------- C:\Program Files\Common Files\wise installation wizard
2007-01-03 20:01 -------- d-------- C:\Program Files\cant be deleted
2007-01-03 19:34 -------- d-------- C:\Program Files\grisoft
2007-01-03 17:53 -------- d-------- C:\DOCUME~1\Owner\Application Data\xfire
2007-01-01 21:14 -------- d---s---- C:\Program Files\xfire
2007-01-01 20:23 -------- d-------- C:\Program Files\java
2007-01-01 11:30 -------- d-------- C:\Program Files\webroot
2007-01-01 11:30 -------- d-------- C:\DOCUME~1\Owner\Application Data\webroot
2006-12-28 21:53 -------- d-------- C:\DOCUME~1\Owner\Application Data\avg7
2006-12-25 09:26 -------- d-------- C:\DOCUME~1\Owner\Application Data\macromedia
2006-12-24 12:48 816288 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-12-24 12:48 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-12-24 12:48 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-24 12:48 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-24 12:35 -------- d-------- C:\DOCUME~1\Owner\Application Data\lavasoft
2006-12-24 12:30 -------- d-------- C:\Program Files\Common Files\webroot shared
2006-12-24 10:33 -------- d-------- C:\Program Files\nokia
2006-12-24 10:33 -------- d-------- C:\Program Files\Common Files\symantec shared
2006-12-15 19:43 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-12-09 17:31 62 --a------ C:\WINDOWS\trwinupd.dll
2006-11-16 15:38 -------- d-------- C:\Program Files\msxml 4.0
2006-11-08 05:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-25 15:24 0 --a------ C:\Program Files\_iberr.txt
2006-10-19 13:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --------- C:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"Index Washer"="C:\\Program Files\\Webroot\\Washer\\WashIdx.exe \"Owner\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TalkTalk"="\"C:\\Program Files\\TalkTalk\\bin\\sprtcmd.exe\" /P TalkTalk"
"snpstd"="C:\\WINDOWS\\vsnpstd.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Alcatel\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"Windows Registry Repair Pro"="C:\\Program Files\\3B Software\\Windows Registry Repair Pro\\Windows Registry Repair Pro.exe -X"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
"backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
"location"="Common Startup"
"item"="Kodak EasyShare software"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
"location"="Common Startup"
"item"="Kodak software updater"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
"location"="Common Startup"
"item"="MyWebSearch Email Plugin"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
"backup"="C:\\WINDOWS\\pss\\NkvMon.exe.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Nikon\\NkView6\\NkvMon.exe "
"item"="NkvMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Delta Force-Black Hawk Down Team Sabre Registration.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Delta Force-Black Hawk Down Team Sabre Registration.lnk"
"backup"="C:\\WINDOWS\\pss\\Delta Force-Black Hawk Down Team Sabre Registration.lnkStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Owner\\Local Settings\\Temp\\{00BDC6D7-8461-4048-B0CF-4D3886C91571}\\{6164D2E7-986B-42F5-B3A6-64D5E53FB889}\\NOVG.EXE /remind /language=ENG /PRNM=\"Delta Force-Black Hawk Down Team Sabre\""
"item"="Delta Force-Black Hawk Down Team Sabre Registration"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Morpheus.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Morpheus.lnk"
"backup"="C:\\WINDOWS\\pss\\Morpheus.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Morpheus\\Morpheus.exe -min"
"item"="Morpheus"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
"location"="Startup"
"item"="MyWebSearch Email Plugin"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"item"="PowerReg Scheduler"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Webshots.lnk]
"backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Webshots\\WEBSHO~1.EXE "
"item"="Webshots"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1fork]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Curb Phone Amen"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Points Manager"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Virus Update Scheduler V1.39.12R]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msvc"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_EMC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgemc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DATALA~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Evidence Eliminator]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ee"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lxbbbmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Lexmark X74-X75\\lxbbbmgr.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Inet Xp..]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="teekids"
"hkey"="HKLM"
"command"="teekids.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TRAYAP~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperFreeEdition]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PSFree"
"hkey"="HKCU"
"command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"inimapping"="0"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vsnpstd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\vsnpstd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="spykiller"
"hkey"="HKCU"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpySweeperUI"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\styleerrorgplhelp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="math obj"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updmgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="updmgr"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="wwDisp"
"hkey"="HKCU"
"command"="C:\\Program Files\\Webroot\\Washer\\wwDisp.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="run"
"hkey"="HKLM"
"command"="run.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LexBceS"=dword:00000002
"iPodService"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MSN Update"="dllconfg.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"MSN Update"="dllconfg.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://images.google.co.uk/images?q...gator.ru/pub/savers/screensaverdfbhd2.exe.jpg
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
UxTuneUp
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{42771541-ca29-11d8-9bce-806d6172696f}]
Shell\AutoRun\command D:\autoplay.exe
Completion time: 07-01-15 22:13:18