It seems like things have come to a grinding halt on my XP desktop. Everything is running very slow. Many thanks for your help. Below are the results of my DSS scan. I've also attached my Panda active scan report and the extra.txt DSS report. Kevin
Deckard's System Scanner v20071014.68
Run by Kevin Pope on 2007-11-11 16:26:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 224 MiB (512 MiB recommended).
System Drive C: has 0.01 GiB (less than 15%) free.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-11 16:30:48
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Common Files\AOL\1156385735\ee\aolsoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\rje\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r2.attbi.com:8000
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - D:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1156385735\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Kevin Pope\Start Menu\Programs\IMVU\Run IMVU.lnk
O15 - Trusted Zone: *.www.pandasecurity.com (HKCU)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37948.8168981482
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462...img/operations/symbizpr/xcontrol/SymDlBrg.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{8C1989A1-B559-402E-B9CD-422855CC5F60}: NameServer = 192.168.1.1
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\CCPWDSVC.EXE
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
O23 - Service: COM Host (comHost) - Symantec Corporation - D:\Program Files\Norton Internet Security\COMHOST.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
--
End of file - 9206 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 HPPECP00 - c:\windows\system32\drivers\hppecp00.sys
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S2 tmpreflt - c:\windows\system32\drivers\tmpreflt.sys (file missing)
S2 vsapint - c:\windows\system32\drivers\vsapint.sys (file missing)
S3 CV2K1 (CommView Network Monitor) - c:\windows\system32\drivers\cv2k1.sys <Not Verified; TamoSoft, Inc.; CommView Driver>
S3 hwi4857 (Duo Digital Media Player) - c:\windows\system32\drivers\hwi4857.sys <Not Verified; Cowon Systems, Inc.; USB Falsh Memory Controller>
S3 PalmUSBD - c:\windows\system32\drivers\palmusbd.sys (file missing)
S3 PortRst - c:\windows\system32\drivers\portrst.sys <Not Verified; Barom Technologies Co., Ltd.; PortRST.sys>
S3 RioS10 (RioS10 driver) - c:\windows\system32\drivers\rios10.sys <Not Verified; SonicBlue Inc.; RioS10.sys>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Parallel Device
Device ID: ROOT\LEGACY_HPPECP00\0000
Manufacturer:
Name: Parallel Device
PNP Device ID: ROOT\LEGACY_HPPECP00\0000
Service: Hppecp00
Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
Description: Photosmart C6200 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C6200 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
-- Scheduled Tasks -------------------------------------------------------------
2007-11-10 02:02:27 558 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Kevin Pope.job
-- Files created between 2007-10-11 and 2007-11-11 -----------------------------
2007-11-11 16:06:13 0 d-------- C:\Program Files\SpywareBlaster
2007-11-11 11:39:36 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-11-11 11:39:24 0 d-------- C:\WINDOWS\LastGood
2007-11-10 21:53:59 5157 --a------ C:\hijackthis111007b
2007-11-10 17:35:47 23 --ahs---- C:\WINDOWS\system32\fffcbcffeb_g.dll
2007-11-04 22:31:50 0 d-------- C:\Program Files\sisagp
2007-11-04 22:31:42 110592 -----n--- C:\WINDOWS\system32\TVMode.dll <Not Verified; Silicon Integrated Systems Corporation; TVModeLib Dynamic Link Library>
2007-11-04 22:31:42 65536 -----n--- C:\WINDOWS\system32\SiSHook.dll <Not Verified; Silicon Integrated Systems Corporation; SiSHook Dynamic Link Library>
2007-11-04 22:31:25 0 d-------- C:\WINDOWS\SiS
2007-11-04 22:31:11 258048 --a------ C:\WINDOWS\system32\SiSParse.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA Script Parser Dynamic Link Library>
2007-11-04 22:31:11 49152 --a------ C:\WINDOWS\system32\SiSBase.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA SiSBase Dynamic Link Library>
2007-11-04 22:31:09 49152 --a------ C:\WINDOWS\system32\SiSPower.dll <Not Verified; Silicon Integrated Systems Corporation; SiS Power Scheme Library>
2007-11-04 22:31:08 36864 --a------ C:\WINDOWS\InstFunc.exe
2007-11-04 22:31:07 7168 --a------ C:\WINDOWS\InstFunc.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA InstFunc Dynamic Link Library>
2007-11-04 22:29:38 0 d-------- C:\WINDOWS\system32\trayres
2007-11-04 22:29:13 1 --a------ C:\WINDOWS\~sisRslt
2007-11-03 20:12:49 94208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2007-11-03 20:12:48 15872 --a------ C:\WINDOWS\system32\GTNDIS5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2007-11-03 20:12:32 32768 --a------ C:\WINDOWS\system32\GTGina.dll <Not Verified; Gemtek; GTGina Dynamic Link Library>
2007-11-03 20:11:49 0 d-------- C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2007-10-31 15:41:30 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-31 15:38:25 0 d-------- C:\Program Files\AIM6
2007-10-28 02:01:39 0 d-------- C:\Program Files\MSXML 4.0
2007-10-27 18:02:24 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\HP
2007-10-27 17:56:33 0 d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2007-10-27 17:52:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2007-10-27 17:30:03 0 d-------- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2007-10-27 17:29:29 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\HPAppData
2007-10-27 17:23:53 0 d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2007-10-27 17:23:51 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2007-10-27 17:22:44 0 d-------- C:\Program Files\Common Files\HP
2007-10-27 17:21:22 0 d-------- C:\Program Files\Hewlett-Packard
2007-10-27 17:20:48 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2007-10-27 17:18:29 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-10-27 17:17:43 0 d-------- C:\Program Files\HP
2007-10-27 17:11:09 8138 -----n--- C:\WINDOWS\hpomdl21.dat
2007-10-27 17:11:09 147616 --a------ C:\WINDOWS\hpoins21.dat
2007-10-27 16:24:42 0 d-------- C:\WINDOWS\system32\LogFiles
2007-10-27 16:19:16 1244 --a------ C:\WINDOWS\checkip.dat
-- Find3M Report ---------------------------------------------------------------
2007-11-11 16:05:11 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-11 13:37:57 0 d-------- C:\Program Files\Symantec
2007-11-11 13:33:02 0 d-------- C:\Program Files\QuickTime
2007-11-11 13:12:56 0 d-------- C:\Program Files\iTunes
2007-11-11 12:48:08 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\Symantec
2007-11-10 15:45:57 0 d-------- C:\Program Files\Google
2007-11-10 15:22:40 0 d-------- C:\Program Files\Panicware
2007-11-10 15:21:15 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-10 15:18:24 0 d--h----- C:\Documents and Settings\Kevin Pope\Application Data\Move Networks
2007-11-10 15:09:30 0 d-------- C:\Program Files\Canon
2007-11-05 00:19:33 0 d-a------ C:\Program Files\Common Files
2007-11-04 22:56:59 0 d-------- C:\Program Files\AIM95
2007-11-04 22:56:56 0 d-------- C:\Program Files\411Ferret
2007-11-04 22:27:11 184320 --a------ C:\WINDOWS\system32\SiSInst.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA SiSInst Dynamic Link Library>
2007-11-04 22:27:02 135168 -----n--- C:\WINDOWS\system32\SiSApCom.dll <Not Verified; Silicon Integrated Systems Corporation; SiSApCom Dynamic Link Library>
2007-10-30 18:55:24 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-18 18:49:01 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\IMVU
2007-09-28 19:53:04 0 d-------- C:\Program Files\Common Files\Adobe
2007-09-04 20:44:59 61678 --a------ C:\Documents and Settings\Kevin Pope\Application Data\PFP100JPR.{PB
2007-09-04 20:44:59 12358 --a------ C:\Documents and Settings\Kevin Pope\Application Data\PFP100JCM.{PB
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
03/02/2007 03:52 PM 1298024 -ra------ D:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
03/02/2007 03:52 PM 177768 -ra------ D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1156385735\ee\AOLSoftware.exe" [05/09/2006 04:24 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/2006 06:58 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [02/17/2006 08:59 AM]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 06:51 PM]
"HP Software Update"="D:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 08:34 PM]
"SiSPower"="SiSPower.dll" [11/04/2007 10:27 PM C:\WINDOWS\system32\SiSPower.dll]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/22/2007 10:19 PM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [03/12/2007 06:30 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [3/11/2007 8:26:24 PM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
c:\WINDOWS\System32\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt hpqcxs08 hpqddsvc
HPService HPSLPSVC
*Newly Created Service* - COMHOST
*Newly Created Service* - GTNDIS5
-- End of Deckard's System Scanner: finished at 2007-11-11 16:34:17 ------------
Deckard's System Scanner v20071014.68
Run by Kevin Pope on 2007-11-11 16:26:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 224 MiB (512 MiB recommended).
System Drive C: has 0.01 GiB (less than 15%) free.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-11-11 16:30:48
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Common Files\AOL\1156385735\ee\aolsoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE
D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\rje\dss.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r2.attbi.com:8000
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - D:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVSHEXT.DLL
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1156385735\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - D:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Kevin Pope\Start Menu\Programs\IMVU\Run IMVU.lnk
O15 - Trusted Zone: *.www.pandasecurity.com (HKCU)
O16 - DPF: {33564D57-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37948.8168981482
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462...img/operations/symbizpr/xcontrol/SymDlBrg.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{8C1989A1-B559-402E-B9CD-422855CC5F60}: NameServer = 192.168.1.1
O18 - Protocol: lid - {5C135180-9973-46D9-ABF4-148267CBB8BF} - C:\WINDOWS\system32\msvidctl.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\CCPWDSVC.EXE
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
O23 - Service: COM Host (comHost) - Symantec Corporation - D:\Program Files\Norton Internet Security\COMHOST.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
--
End of file - 9206 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R2 HPPECP00 - c:\windows\system32\drivers\hppecp00.sys
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S2 tmpreflt - c:\windows\system32\drivers\tmpreflt.sys (file missing)
S2 vsapint - c:\windows\system32\drivers\vsapint.sys (file missing)
S3 CV2K1 (CommView Network Monitor) - c:\windows\system32\drivers\cv2k1.sys <Not Verified; TamoSoft, Inc.; CommView Driver>
S3 hwi4857 (Duo Digital Media Player) - c:\windows\system32\drivers\hwi4857.sys <Not Verified; Cowon Systems, Inc.; USB Falsh Memory Controller>
S3 PalmUSBD - c:\windows\system32\drivers\palmusbd.sys (file missing)
S3 PortRst - c:\windows\system32\drivers\portrst.sys <Not Verified; Barom Technologies Co., Ltd.; PortRST.sys>
S3 RioS10 (RioS10 driver) - c:\windows\system32\drivers\rios10.sys <Not Verified; SonicBlue Inc.; RioS10.sys>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Parallel Device
Device ID: ROOT\LEGACY_HPPECP00\0000
Manufacturer:
Name: Parallel Device
PNP Device ID: ROOT\LEGACY_HPPECP00\0000
Service: Hppecp00
Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318}
Description: Photosmart C6200 series
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Photosmart C6200 series
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
-- Scheduled Tasks -------------------------------------------------------------
2007-11-10 02:02:27 558 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Kevin Pope.job
-- Files created between 2007-10-11 and 2007-11-11 -----------------------------
2007-11-11 16:06:13 0 d-------- C:\Program Files\SpywareBlaster
2007-11-11 11:39:36 0 d-------- C:\WINDOWS\system32\ActiveScan
2007-11-11 11:39:24 0 d-------- C:\WINDOWS\LastGood
2007-11-10 21:53:59 5157 --a------ C:\hijackthis111007b
2007-11-10 17:35:47 23 --ahs---- C:\WINDOWS\system32\fffcbcffeb_g.dll
2007-11-04 22:31:50 0 d-------- C:\Program Files\sisagp
2007-11-04 22:31:42 110592 -----n--- C:\WINDOWS\system32\TVMode.dll <Not Verified; Silicon Integrated Systems Corporation; TVModeLib Dynamic Link Library>
2007-11-04 22:31:42 65536 -----n--- C:\WINDOWS\system32\SiSHook.dll <Not Verified; Silicon Integrated Systems Corporation; SiSHook Dynamic Link Library>
2007-11-04 22:31:25 0 d-------- C:\WINDOWS\SiS
2007-11-04 22:31:11 258048 --a------ C:\WINDOWS\system32\SiSParse.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA Script Parser Dynamic Link Library>
2007-11-04 22:31:11 49152 --a------ C:\WINDOWS\system32\SiSBase.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA SiSBase Dynamic Link Library>
2007-11-04 22:31:09 49152 --a------ C:\WINDOWS\system32\SiSPower.dll <Not Verified; Silicon Integrated Systems Corporation; SiS Power Scheme Library>
2007-11-04 22:31:08 36864 --a------ C:\WINDOWS\InstFunc.exe
2007-11-04 22:31:07 7168 --a------ C:\WINDOWS\InstFunc.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA InstFunc Dynamic Link Library>
2007-11-04 22:29:38 0 d-------- C:\WINDOWS\system32\trayres
2007-11-04 22:29:13 1 --a------ C:\WINDOWS\~sisRslt
2007-11-03 20:12:49 94208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2007-11-03 20:12:48 15872 --a------ C:\WINDOWS\system32\GTNDIS5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2007-11-03 20:12:32 32768 --a------ C:\WINDOWS\system32\GTGina.dll <Not Verified; Gemtek; GTGina Dynamic Link Library>
2007-11-03 20:11:49 0 d-------- C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2007-10-31 15:41:30 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-31 15:38:25 0 d-------- C:\Program Files\AIM6
2007-10-28 02:01:39 0 d-------- C:\Program Files\MSXML 4.0
2007-10-27 18:02:24 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\HP
2007-10-27 17:56:33 0 d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2007-10-27 17:52:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2007-10-27 17:30:03 0 d-------- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2007-10-27 17:29:29 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\HPAppData
2007-10-27 17:23:53 0 d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2007-10-27 17:23:51 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2007-10-27 17:22:44 0 d-------- C:\Program Files\Common Files\HP
2007-10-27 17:21:22 0 d-------- C:\Program Files\Hewlett-Packard
2007-10-27 17:20:48 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2007-10-27 17:18:29 0 d------c- C:\WINDOWS\system32\DRVSTORE
2007-10-27 17:17:43 0 d-------- C:\Program Files\HP
2007-10-27 17:11:09 8138 -----n--- C:\WINDOWS\hpomdl21.dat
2007-10-27 17:11:09 147616 --a------ C:\WINDOWS\hpoins21.dat
2007-10-27 16:24:42 0 d-------- C:\WINDOWS\system32\LogFiles
2007-10-27 16:19:16 1244 --a------ C:\WINDOWS\checkip.dat
-- Find3M Report ---------------------------------------------------------------
2007-11-11 16:05:11 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-11 13:37:57 0 d-------- C:\Program Files\Symantec
2007-11-11 13:33:02 0 d-------- C:\Program Files\QuickTime
2007-11-11 13:12:56 0 d-------- C:\Program Files\iTunes
2007-11-11 12:48:08 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\Symantec
2007-11-10 15:45:57 0 d-------- C:\Program Files\Google
2007-11-10 15:22:40 0 d-------- C:\Program Files\Panicware
2007-11-10 15:21:15 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-11-10 15:18:24 0 d--h----- C:\Documents and Settings\Kevin Pope\Application Data\Move Networks
2007-11-10 15:09:30 0 d-------- C:\Program Files\Canon
2007-11-05 00:19:33 0 d-a------ C:\Program Files\Common Files
2007-11-04 22:56:59 0 d-------- C:\Program Files\AIM95
2007-11-04 22:56:56 0 d-------- C:\Program Files\411Ferret
2007-11-04 22:27:11 184320 --a------ C:\WINDOWS\system32\SiSInst.dll <Not Verified; Silicon Integrated Systems Corporation; SiS (R) Compatible Super VGA SiSInst Dynamic Link Library>
2007-11-04 22:27:02 135168 -----n--- C:\WINDOWS\system32\SiSApCom.dll <Not Verified; Silicon Integrated Systems Corporation; SiSApCom Dynamic Link Library>
2007-10-30 18:55:24 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-18 18:49:01 0 d-------- C:\Documents and Settings\Kevin Pope\Application Data\IMVU
2007-09-28 19:53:04 0 d-------- C:\Program Files\Common Files\Adobe
2007-09-04 20:44:59 61678 --a------ C:\Documents and Settings\Kevin Pope\Application Data\PFP100JPR.{PB
2007-09-04 20:44:59 12358 --a------ C:\Documents and Settings\Kevin Pope\Application Data\PFP100JCM.{PB
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
03/02/2007 03:52 PM 1298024 -ra------ D:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
03/02/2007 03:52 PM 177768 -ra------ D:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1156385735\ee\AOLSoftware.exe" [05/09/2006 04:24 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/2006 06:58 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [02/17/2006 08:59 AM]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 06:51 PM]
"HP Software Update"="D:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 08:34 PM]
"SiSPower"="SiSPower.dll" [11/04/2007 10:27 PM C:\WINDOWS\system32\SiSPower.dll]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/22/2007 10:19 PM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [03/12/2007 06:30 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [3/11/2007 8:26:24 PM]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
c:\WINDOWS\System32\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt hpqcxs08 hpqddsvc
HPService HPSLPSVC
*Newly Created Service* - COMHOST
*Newly Created Service* - GTNDIS5
-- End of Deckard's System Scanner: finished at 2007-11-11 16:34:17 ------------
Attachments
-
21.6 KB Views: 40
-
35.2 KB Views: 45