Ried,
I hope this is what you need. thanks a lot.
Ed
Deckard's System Scanner v20070426.43
Run by Owner on 2007-05-02 at 15:26:44
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2007-05-02 21:27:20 UTC - RP301 - Deckard's System Scanner Restore Point
3: 2007-05-02 20:43:48 UTC - RP300 - Software Distribution Service 2.0
2: 2007-05-01 23:24:55 UTC - RP299 - System Checkpoint
1: 2007-04-30 18:16:12 UTC - RP298 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 3:32:33 PM, on 5/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\S3tray2.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\HP Wireless Keyboard\KMaestro.exe
C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe
C:\program files\waxoe\waxoe.exe
C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\CRMDQDMX\dss[1].exe
C:\PROGRA~1\HIJACK~1\Owner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [BtcMaestro] "C:\Program Files\HP Wireless Keyboard\KMaestro.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [AppWaxOE] c:\program files\waxoe\waxoe.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.5] "C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" /nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1172281759656
O16 - DPF: {6B78B13A-6E99-4588-8EAB-C2399B202022} (iVocalize Web Conference 4 Setup) -
http://banjolounge.ivocalize.net/iv4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R2 FreeTdi (Freedom Filter) - c:\windows\system32\drivers\freetdi.sys <Not Verified; Zero-Knowledge Systems Inc.; Freedom>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing)
S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing)
S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Scheduled Tasks -------------------------------------------------------------
2007-05-01 10:53:17 266 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
2007-04-18 11:36:02 384 --a------ C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
2007-02-02 17:12:37 412 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
-- Files created between 2007-04-02 and 2007-05-02 -----------------------------
2007-05-02 14:58:40 0 d-------- C:\WINDOWS\network diagnostic
2007-05-02 12:38:30 0 d-------- C:\Program Files\SpywareBlaster
2007-05-02 12:23:56 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-05-02 11:46:48 2560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-04-28 03:01:31 0 dr-h----- C:\Documents and Settings\Owner\Recent
2007-04-27 06:53:10 40960 --a------ C:\WINDOWS\PANICNT.dll
2007-04-27 06:53:10 45056 --a------ C:\WINDOWS\PANIC32.dll
2007-04-27 06:53:09 0 d-------- C:\Program Files\Panicware
2007-04-21 09:49:13 0 d-------- C:\Documents and Settings\Owner\Application Data\System Tweaker
2007-04-21 07:45:02 57344 --a------ C:\WINDOWS\system32\Wnaspint.dll <Not Verified; NexiTech, Inc.; NexiTech ASPI for Win32>
2007-04-21 07:43:43 0 d-------- C:\Program Files\Common Files\Download Manager
2007-04-21 06:27:45 0 d---s---- C:\Documents and Settings\LocalService\UserData
2007-04-21 06:27:22 0 d-------- C:\Documents and Settings\LocalService\Application Data\Google
2007-04-21 06:27:19 0 dr------- C:\Documents and Settings\LocalService\Favorites
2007-04-20 06:04:46 737280 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-04-20 06:04:19 0 d-------- C:\Program Files\Tweak-XP Pro 4
2007-04-20 05:08:06 0 d-------- C:\WINDOWS\system32\EWS
2007-04-20 05:08:05 0 d-------- C:\Program Files\WaxOE
2007-04-18 21:54:06 0 d-------- C:\Program Files\BestPractice
2007-04-18 11:36:10 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2007-04-18 11:35:29 0 d-------- C:\Program Files\Uniblue
2007-04-17 18:13:31 0 d-------- C:\spool_cd
2007-04-17 18:13:05 0 d-------- C:\temp
2007-04-17 18:12:54 254976 --a------ C:\WINDOWS\system32\MSEXCL35.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet>
2007-04-17 18:12:53 415504 --a------ C:\WINDOWS\system32\MSREPL35.DLL <Not Verified; Microsoft Corporation; Microsoft® Access>
2007-04-17 18:12:53 252176 --a------ C:\WINDOWS\system32\MSRD2X35.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet>
2007-04-17 18:12:52 368912 --a------ C:\WINDOWS\system32\VBAR332.DLL <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2007-04-17 18:12:52 24848 --a------ C:\WINDOWS\system32\MSJTER35.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet>
2007-04-17 18:12:52 123664 --a------ C:\WINDOWS\system32\MSJINT35.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet>
2007-04-17 18:12:52 1046288 --a------ C:\WINDOWS\system32\MSJET35.DLL <Not Verified; Microsoft Corporation; Microsoft® Jet>
2007-04-17 18:12:51 0 d-------- C:\spool
2007-04-17 18:12:51 0 d-------- C:\Brit View CD
2007-04-17 09:20:29 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-04-17 09:19:07 0 d-------- C:\Program Files\Spyware Doctor
2007-04-17 09:19:07 0 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools
2007-04-17 09:17:10 0 d-------- C:\WINDOWS\system32\runtime
2007-04-17 09:15:07 0 d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-04-17 08

12 0 d-------- C:\Program Files\Wise Registry Cleaner
2007-04-15 07:31:10 23600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>
2007-04-06 16:26:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-04-06 16:20:20 233472 --a------ C:\WINDOWS\system32\LXCRinst.dll
2007-04-06 16:20:20 0 d-------- C:\Program Files\Lexmark 2400 Series
-- Find3M Report ---------------------------------------------------------------
2007-05-02 15:20:11 0 d-------- C:\Program Files\lx_cats
2007-04-21 11:19:19 0 d-------- C:\Program Files\HP Wireless Keyboard
2007-04-20 13:53:26 0 d-------- C:\Program Files\Google
2007-04-17 09:18:05 0 d-------- C:\Program Files\Picasa2
2007-04-10 20:41:17 0 d-------- C:\Program Files\Transkriber 2.x
2007-04-10 08:20:36 0 d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-04-06 16:05:04 0 d-------- C:\Program Files\Lexmark Toolbar
2007-03-30 14:51:58 0 d-------- C:\Documents and Settings\Owner\Application Data\Google
2007-03-30 14:50:53 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-03-28 17:30:37 0 d-------- C:\Program Files\Presentersoft PowerVideoMaker
2007-03-11 12:32:05 0 d-------- C:\Program Files\AltoMP3 Gold
2007-03-11 12:21:24 0 d-------- C:\Program Files\Setup
2007-03-11 12:08:41 161300 --a------ C:\WINDOWS\Wave@MP3 Uninstaller.exe
2007-03-11 12:08:40 0 d-------- C:\Program Files\Common Files\River Past
2007-03-11 12:08:40 0 d-------- C:\Documents and Settings\Owner\Application Data\River Past G5
2007-03-11 12:08:39 0 d-------- C:\Program Files\River Past
2007-03-10 15:38:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Leadertech
2007-03-10 14:55:46 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2007-03-10 14:54:58 0 d-------- C:\Program Files\Common Files\Adobe
2007-03-07 17

01 0 d-------- C:\Program Files\Simple Backup for My Pictures
2007-03-07 16:50:26 0 d-------- C:\Documents and Settings\Owner\Application Data\Freedom
2007-03-07 16:47:04 0 d-------- C:\Program Files\Security Task Manager
2007-03-06 20:34:16 0 d-------- C:\Program Files\Common Files\Ankiro
2007-03-06 20:33:51 0 d-------- C:\Program Files\Common Files\Application
2007-03-06 20:33:36 0 d-------- C:\Documents and Settings\Owner\Application Data\SPAMfighter
2007-02-19 17:22:44 45056 --a------ C:\WINDOWS\NCUNINST.EXE <Not Verified; Northern Codeworks; Uninstall>
2007-02-19 10:46:07 73216 --a------ C:\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2007-02-11 16:51:00 1093632 --a------ C:\WINDOWS\system32\FreeImage.dll <Not Verified; FreeImage; FreeImage>
2007-02-09 21:21:03 444 --a------ C:\WINDOWS\setuplog
2007-02-08 14:12:38 155 --a------ C:\CONFIG.SYS
2007-02-08 14:12:38 118 --a------ C:\AUTOEXEC.BAT
2007-02-07 16:43:51 61678 --a------ C:\Documents and Settings\Owner\Application Data\PFP100JPR.{PB
2007-02-07 16:43:51 12358 --a------ C:\Documents and Settings\Owner\Application Data\PFP100JCM.{PB
-- Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{3C060EA2-E6A9-4E49-A530-D4657B8C449A} C:\Program Files\Zero Knowledge\Freedom\pkR.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{56071E0D-C61B-11D3-B41C-00E02927A304} C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
{AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar2.dll
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"S3TRAY2"="S3tray2.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"SDTray"="\"C:\\Program Files\\Spyware Doctor\\SDTrayApp.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"LXCRCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCRtime.dll,_RunDLLEntry@16"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"P17Helper"="Rundll32 P17.dll,P17Helper"
"OM_Monitor"="C:\\Program Files\\OLYMPUS\\OLYMPUS Master\\FirstStart.exe"
"NWEReboot"=""
"NeroFilterCheck"="C:\\WINDOWS\\System32\\NeroCheck.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r"
"BtcMaestro"="\"C:\\Program Files\\HP Wireless Keyboard\\KMaestro.exe\""
"AlcxMonitor"="ALCXMNTR.EXE"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Uniblue SpeedUpMyPC"="C:\\Program Files\\Uniblue\\SpeedUpMyPC\\SpeedUpMyPC.exe -s"
"AppWaxOE"="c:\\program files\\waxoe\\waxoe.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Creative MediaSource Go"="\"C:\\Program Files\\Creative\\MediaSource\\Go\\CTCMSGo.exe\" /SCB"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"OM_Monitor"="C:\\Program Files\\OLYMPUS\\OLYMPUS Master\\Monitor.exe -NoStart"
"Gadwin PrintScreen 3.5"="\"C:\\Program Files\\Gadwin Systems\\PrintScreen\\PrintScreen.exe\" /nosplash"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\BtcMaestro]
"ModelName"="MI-5219URF(February)"
"Version"="1.7 (2.0.W-127AU MUL)"
"Language"=dword:00000000
"KeyboardID"=dword:00000000
"MouseID"=dword:00000000
"KeyboardSID"=dword:00000000
"MouseSID"=dword:00000000
"RxSecret"=dword:00000000
"RMenuSel"=dword:00000000
"AddMouse"=dword:00000001
"JumpPickLevel"=dword:00000000
"KeyboardBat"=dword:00000000
"MouseBat"=dword:00000000
"KeyboardCh"=dword:00000000
"MouseCh"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\BtcMaestro\Config]
"DisplayLabel"=dword:00000001
"TaskbarIcon"=dword:00000001
"Autoplay"=dword:00000000
"F091"="0Q;my music"
"L091"="My Music"
"F090"="0P;my pictures"
"L090"="My Pictures"
"F089"="0J;joystick on"
"L089"="Joy Stick ON"
"F088"="0J;joystick off"
"L088"="Joy Stick OFF"
"F087"="F;next track"
"L087"="Next Track"
"F086"="G;previous track"
"L086"="Previous Track"
"F085"="E;stop"
"L085"="Stop"
"F084"="0H;mouse fifth button"
"L084"="Mouse 5th Button"
"F083"="C;volume down"
"L083"="Volume Down"
"F082"="B;volume up"
"L082"="Volume Up"
"F081"="D;play"
"L081"="Play/Pause"
"F080"="0G;mouse fourth button"
"L080"="Mouse 4th Button"
"F079"="0F;scroll right"
"L079"="Middle + Wheel Down"
"F078"="0E;scroll left"
"L078"="Middle + Wheel Up"
"F077"="J;www(AC)"
"L077"="www"
"F076"="0I;quick jump"
"L076"="Mouse Middle Button"
"F075"="0F;scroll right"
"L075"="Middle + Right"
"F074"="0E;scroll left"
"L074"="Middle + Left"
"F073"="m;scroll down"
"L073"="Scroll Down"
"F072"="l;scroll up"
"L072"="Scroll Up"
"F071"="0I;quick jump"
"L071"="Quick Jump"
"F070"="0F;scroll right"
"L070"="Scroll Right"
"F069"="0E;scroll left"
"L069"="Scroll Left"
"F068"="0D:set SID final"
"L068"="Set SID Final"
"F067"="0C:paint"
"L067"="Paint"
"F066"="0B;mouse middle button"
"L066"="Mouse Middle Button"
"F065"="0A;europe dollar(OF)"
"L065"="Europe Dollar"
"F064"="0-;reply all(OF)"
"L064"="Reply All"
"F063"="09;eject 2"
"L063"="Eject/Close 2"
"F062"="08:help(OF)"
"L062"="Help"
"F061"="07;redo(OF)"
"L061"="Redo"
"F060"="06;undo(OF)"
"L060"="Undo"
"F059"="05;task pane(OF)"
"L059"="Task pane"
"F058"="04;send(OF)"
"L058"="Send"
"F057"="03;f'ward(OF)"
"L057"="Forward"
"F056"="02;reply(OF)"
"L056"="Reply"
"F055"="01;bullets(OF)"
"L055"="Bullets"
"F054"="00;spell(OF)"
"L054"="Spell"
"F053"="z;bold(OF)"
"L053"="Bold"
"F052"="y;replace(OF)"
"L052"="Replace"
"F051"="x;save(OF)"
"L051"="Save"
"F050"="w;open(OF)"
"L050"="Open"
"F049"="v;new(OF)"
"L049"="New"
"F048"="u;copy(OF)"
"L048"="Copy"
"F047"="t;cut(OF)"
"L047"="Cut"
"F046"="s;mark(OF)"
"L046"="Mark"
"F045"="r;paste(OF)"
"L045"="Paste"
"F044"="q;calendar(OF)"
"L044"="Calendar"
"F043"="p;power point(OF)"
"L043"="Power Point"
"F042"="o;excel(OF)"
"L042"="Excel"
"F041"="n;word(OF)"
"L041"="Word"
"F040"="m;scroll down"
"L040"="Scroll Down"
"F039"="l;scroll up"
"L039"="Scroll Up"
"F038"="k;Configure"
"L038"="Configure"
"F037"="j;keyboard and mouse battery low"
"L037"="Keyboard and Mouse Battery Low"
"F036"="i;mouse battery low"
"L036"="Mouse Battery Low"
"F035"="h;keyboard battery low"
"L035"="Keyboard Battery Low"
"F034"="g;keyboard and mouse battery OK"
"L034"=""
"F033"="f:wake up"
"L033"="Wake Up"
"F032"="e:sleep"
"L032"="Sleep"
"F031"="d;power off"
"L031"="Power Off"
"F030"="c;mf"
"L030"="F-Lock"
"F029"="b;app. close"
"L029"="App. Close"
"F028"="a;app. switch"
"L028"="App. Switch"
"F027"="Z;log off"
"L027"="Log Off"
"F026"="Y;my computer"
"L026"="My Computer"
"F025"="X;refresh(AC)"
"L025"="www Refresh"
"F024"="W;print(OF)"
"L024"="Print"
"F023"="V;notepad"
"L023"="Notepad"
"F022"="U;explorer"
"L022"="Explorer"
"F021"="T;mediaplayer"
"L021"="Mediaplayer"
"F020"="S;my documents"
"L020"="My Documents"
"F019"="R;calculator"
"L019"="Calculator"
"F018"="Q;help(manual)"
"L018"="HP Wireless Keyboard Help"
"F017"="P;help(OS)"
"L017"="OS Help"
"F016"="O;favorite(AC)"
"L016"="www Favorite"
"F015"="N;search(AC)"
"L015"="www Search"
"F014"="M;forward(AC)"
"L014"="www Forward"
"F013"="L;back(AC)"
"L013"="www Back"
"F012"="K;stop(AC)"
"L012"="www Stop"
"F011"="J;www(AC)"
"L011"="www"
"F010"="I;email(AL)"
"L010"="Email"
"F009"="H;eject"
"L009"="Eject/Close"
"F008"="G;previous track"
"L008"="Previous Track"
"F007"="F;next track"
"L007"="Next Track"
"F006"="E;stop"
"L006"="Stop"
"F005"="D;play"
"L005"="Play/Pause"
"F004"="C;volume down"
"L004"="Volume Down"
"F003"="B;volume up"
"L003"="Volume Up"
"F002"="A;mute"
"L002"="Mute"
"F001"="-;none"
"L001"="None"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMFUprogramsList"=dword:00000000
"NoNetHood"=dword:00000001
"NoRecentDocsMenu"=dword:00000000
"NoRun"=dword:00000000
"NoClose"=dword:00000000
"NoFind"=dword:00000000
"NoSMHelp"=dword:00000000
"StartMenuLogoff"=dword:00000000
"NoFavoritesMenu"=dword:00000000
"NoSetTaskbar"=dword:00000000
"NoStartMenuMorePrograms"=dword:00000000
"NoSetFolders"=dword:00000000
"NoSimpleStartMenu"=dword:00000000
"NoTrayContextMenu"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ
http://mfrost.typepad.com/.shared/th.../banner-bg.gif
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcrmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lxcrmon"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command D:\Info.exe folder.htt 480 480
-- End of Deckard's System Scanner: finished at 2007-05-02 at 15:34:06 ---------