i had problems so bad yesterday that i had lost the use of the mouse
i ended up reformatting the computer
3 times in a row before it seemed to work right.
when i got back online i went thru the steps again and i have had alot better sucess in getting things to work.
here is my css scan that finally worked for me
i still suspect that i have something lurking ,ready to
do this to me all over here is the css scan
Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-31 03:08:43
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 4 Restore Point(s) --
4: 2008-05-31 07:08:50 UTC - RP4 - Deckard's System Scanner Restore Point
3: 2008-05-30 18:29:27 UTC - RP3 - Software Distribution Service 3.0
2: 2008-05-30 14:27:44 UTC - RP2 - Software Distribution Service 3.0
1: 2008-05-31 06:30:38 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 383 MiB (512 MiB recommended).
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-31 03:10:06
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\alg.exe
C:\Program Files\Digital Media Reader\shwiconEM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msscli.exe
C:\Program Files\Common Files\AOL\1212214156\EE\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1212214156\EE\AOLServiceHost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVShExt.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1212214156\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212217990828
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212217920296
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{87963452-40F9-4277-9BF1-4883BDED03DB}: NameServer = 205.188.146.145
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\Program Files\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 9923 bytes
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 SunkFilt (Alcor Micro Corp Reader) - c:\windows\system32\drivers\sunkfilt.sys <Not Verified; Alcor Micro Corp.; SunkFilt>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 McAfeeAntiSpyware (McAfee AntiSpyware Real-Time Scanner) - c:\program files\mcafee\mcafee antispyware\msssrv.exe <Not Verified; Network Associates, Inc.; McAfee AntiSpyware>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-31 04:17:00 476 --a------ C:\WINDOWS\Tasks\McAfee.com Update Check (YOUR-CA66427893-Owner).job
2008-05-31 02:30:28 258 --a------ C:\WINDOWS\Tasks\ISP signup reminder 3.job
2008-05-31 02:30:27 258 --a------ C:\WINDOWS\Tasks\ISP signup reminder 2.job
2008-05-31 02:30:27 258 --a------ C:\WINDOWS\Tasks\ISP signup reminder 1.job
2008-05-31 01:59:16 366 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-05-30 21:00:00 344 --a------ C:\WINDOWS\Tasks\McAfee AntiSpyware.job
-- Files created between 2008-04-30 and 2008-05-31 -----------------------------
2008-05-31 03:27:22 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-31 03:10:22 0 d---s---- C:\Documents and Settings\Owner\UserData
2008-05-31 03:02:20 0 d-------- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-05-31 02:55:47 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-31 02:55:39 0 d-------- C:\Program Files\MetaStream
2008-05-31 02:55:34 0 d-------- C:\Program Files\SpywareBlaster
2008-05-31 02:55:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-31 02:32:21 0 d-------- C:\Documents and Settings\Owner\Application Data\AOL
2008-05-31 02:31:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Help
2008-05-31 02:30:22 0 d-------- C:\Documents and Settings\Default User\WINDOWS
2008-05-31 02:30:22 0 d-------- C:\Documents and Settings\Default User\Application Data\You've Got Pictures Screensaver
2008-05-31 02:30:22 0 d-------- C:\Documents and Settings\Default User\Application Data\SampleView
2008-05-31 02:30:22 0 d-------- C:\Documents and Settings\Default User\Application Data\McAfee
2008-05-31 02:30:22 0 d-------- C:\Documents and Settings\Default User\Application Data\Identities
2008-05-31 02:15:10 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-31 02:14:24 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-31 02:14:23 0 d-------- C:\Program Files\McAfee
2008-05-31 02:14:23 0 d-------- C:\Program Files\Common Files\McAfee
2008-05-31 02:14:23 0 d-------- C:\Documents and Settings\Owner\Application Data\McAfee
2008-05-31 02:14:14 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-05-31 02:14:02 0 d-------- C:\Program Files\McAfee.com
2008-05-31 02:12:57 0 d-------- C:\WINDOWS\RegisteredPackages
2008-05-31 02:12:46 67072 --a------ C:\WINDOWS\POWERCFG.EXE <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-31 02:12:30 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-31 02:12:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-31 02:12:02 0 d-------- C:\Program Files\MSN Encarta Plus
2008-05-31 02:11:10 0 d-------- C:\Program Files\Microsoft Money 2005
2008-05-31 02:10:45 0 d-------- C:\Documents and Settings\Owner\Application Data\You've Got Pictures Screensaver
2008-05-31 02:10:43 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-05-31 02:10:29 86016 --a------ C:\WINDOWS\unvise32qt.exe <Not Verified; MindVision; Installer VISE 2.8.3>
2008-05-31 02:10:22 0 d-------- C:\WINDOWS\system32\QuickTime
2008-05-31 02:10:22 0 d-------- C:\Program Files\QuickTime
2008-05-31 02:10:22 0 d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-05-31 02:10:18 0 d-------- C:\My Music
2008-05-31 02:10:17 8552 --a------ C:\WINDOWS\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
2008-05-31 02:10:14 0 d-------- C:\Program Files\Real
2008-05-31 02:10:14 0 d-------- C:\Program Files\Common Files\Real
2008-05-31 02:10:06 10752 --a------ C:\WINDOWS\system32\aamd532.dll <Not Verified; Almeida & Andrade Ltda; MD5 Maker DLL>
2008-05-31 02:10:05 102400 --a------ C:\WINDOWS\system32\SimpleRegistry.dll <Not Verified; 4Developers LLC; SimpleRegistry Control>
2008-05-31 02:09:59 0 d-------- C:\Program Files\Viewpoint
2008-05-31 02:09:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-05-31 02:09:54 0 d-------- C:\Program Files\Pure Networks
2008-05-31 02:09:44 0 d-------- C:\Program Files\AOL Toolbar
2008-05-31 02:09:35 0 d-------- C:\Program Files\Common Files\AolCoach
2008-05-31 02:09:22 0 d-------- C:\Documents and Settings\Owner\Application Data\SampleView
2008-05-31 02:09:13 0 d-------- C:\Program Files\Common Files\aolshare
2008-05-31 02:09:13 0 d-------- C:\Program Files\America Online 9.0
2008-05-31 02:09:13 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-05-31 02:09:05 335 --a------ C:\WINDOWS\nsreg.dat
2008-05-31 02:09:05 0 d-------- C:\Program Files\Common Files\AOL
2008-05-31 02:08:12 40960 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-05-31 02:08:09 294912 --a------ C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update driver Tool>
2008-05-31 02:08:09 200704 --a------ C:\WINDOWS\alcrmv.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Removing driver Tool>
2008-05-31 02:08:06 192512 --a------ C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-05-31 02:07:53 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-05-31 02:07:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Napster
2008-05-31 02:07:37 0 d-------- C:\Program Files\Napster
2008-05-31 02:07:31 20480 --a------ C:\WINDOWS\system32\Marker32.exe <Not Verified; Gateway; Marker32>
2008-05-31 02:06:50 0 d-------- C:\Program Files\Java
2008-05-31 02:06:49 0 d-------- C:\Program Files\Common Files\Java
2008-05-31 02:06:22 0 d-------- C:\Program Files\CyberLink
2008-05-31 02:06:13 471300 --a------ C:\WINDOWS\wallpe.exe <Not Verified; ; wallpe>
2008-05-31 02:04:15 262144 --a------ C:\Documents and Settings\All Users\NTUSER.DAT
2008-05-31 02:03:36 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-05-31 02:03:15 0 d-------- C:\WINDOWS\SHELLNEW
2008-05-31 02:02:59 0 d-------- C:\Program Files\Microsoft.NET
2008-05-31 02:02:37 0 dr-h----- C:\MSOCache
2008-05-31 02:02:22 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-31 02:01:48 0 d-------- C:\Program Files\ATI Technologies
2008-05-31 01:57:32 0 d-------- C:\Program Files\Norton Internet Security
2008-05-31 01:56:08 0 d-------- C:\Program Files\Google
2008-05-31 01:56:05 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-05-31 01:55:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-31 01:55:57 0 d-------- C:\Program Files\Symantec
2008-05-31 01:55:40 18000 --a------ C:\WINDOWS\BigFixClientOverride.dll <Not Verified; BigFix, Inc.; BigFix>
2008-05-31 01:55:40 0 d-------- C:\Program Files\BigFix
2008-05-31 01:55:25 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-31 01:54:40 0 d-------- C:\Program Files\Digital Media Reader
2008-05-31 01:54:36 0 d-------- C:\WINDOWS\Downloaded Installations
2008-05-31 01:54:35 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-31 01:54:24 76288 -ra------ C:\WINDOWS\system32\PUBOLE32.DLL <Not Verified; Microsoft Corporation; Microsoft Publisher for Windows>
2008-05-31 01:54:24 212480 -ra------ C:\WINDOWS\system32\PCDLIB32.DLL <Not Verified; Eastman Kodak; Kodak Photo CD Access Developer Toolkit>
2008-05-31 01:54:24 37888 -ra------ C:\WINDOWS\system32\ochlp30e.dll <Not Verified; Microsoft Corporation; Microsoft Multimedia Controls>
2008-05-31 01:54:24 82432 --a------ C:\WINDOWS\system32\msxml4r.dll <Not Verified; Microsoft Corporation; Microsoft(R) MSXML 4.0 SP1>
2008-05-31 01:54:24 1233920 --a------ C:\WINDOWS\system32\msxml4.dll <Not Verified; Microsoft Corporation; Microsoft(R) MSXML 4.0 SP 2>
2008-05-31 01:54:24 91136 -ra------ C:\WINDOWS\system32\msls2.dll <Not Verified; Microsoft Corporation; Microsoft® Line Services>
2008-05-31 01:54:23 31744 -ra------ C:\WINDOWS\system32\hlp95en.dll <Not Verified; Microsoft Corporation; Microsoft Office>
2008-05-31 01:54:01 0 d-------- C:\Program Files\Microsoft Works
2008-05-31 01:51:50 2658304 -----n--- C:\WINDOWS\UNNeroBurnRights.exe <Not Verified; Nero AG; Nero WebEngine>
2008-05-31 01:51:50 90184 --a------ C:\WINDOWS\system32\NeroCo.dll <Not Verified; Ahead Software AG
im Stoeckmaedle 18
76307 Karlsbad, Germany
Fax: ++49-7248-911-888
e-mail:
[email protected]; Nero Burning Rom>
2008-05-31 01:51:16 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2008-05-31 01:51:13 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2008-05-31 01:51:13 471040 -----n--- C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-05-31 01:51:13 262144 -----n--- C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-05-31 01:51:13 1568768 -----n--- C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-05-31 01:51:12 0 d-------- C:\Program Files\Common Files\Ahead
2008-05-31 01:51:12 0 d-------- C:\Program Files\Ahead
2008-05-31 01:47:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Prism Deploy
2008-05-31 01:47:04 0 d-------- C:\Program Files\Common Files\New Boundary
2008-05-31 01:44:23 0 d-------- C:\WINDOWS\system32\URTTemp
2008-05-31 01:44:19 2 -r-hs---- C:\USER
2008-05-31 01:43:02 0 d-------- C:\Program Files\CONEXANT
2008-05-31 01:40:29 0 d--hs---- C:\System Volume Information
2008-05-31 01:11:20 60 --a------ C:\WINDOWS\system32\SYSDRV.DAT
2008-05-31 01:11:17 0 d-------- C:\WINDOWS\creator
2008-05-31 01:09:41 0 d-------- C:\WINDOWS\SMINST
2008-05-31 01:09:37 0 d-------- C:\WINDOWS\I386
2008-05-30 21:35:58 0 d-------- C:\Documents and Settings\Owner\Application Data\CyberLink
2008-05-30 21:35:27 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-30 21:32:12 0 d-------- C:\WINDOWS\Prefetch
2008-05-30 21:24:33 0 d-------- C:\WINDOWS\system32\scripting
2008-05-30 21:24:32 0 d-------- C:\WINDOWS\l2schemas
2008-05-30 21:24:31 0 d-------- C:\WINDOWS\system32\en
2008-05-30 21:24:30 0 d-------- C:\WINDOWS\system32\bits
2008-05-30 21:21:29 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-30 21:18:58 0 d-------- C:\WINDOWS\network diagnostic
2008-05-30 21:13:26 0 d-------- C:\WINDOWS\EHome
2008-05-30 10:29:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-30 10:28:26 0 d-------- C:\WINDOWS\system32\PreInstall
-- Find3M Report ---------------------------------------------------------------
2008-05-31 02:14:23 0 d-------- C:\Program Files\Common Files
2008-05-31 01:04:58 0 d-------- C:\Program Files\Online Services
2008-05-31 01:04:58 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-31 01:04:58 0 d-------- C:\Program Files\microsoft frontpage
2008-05-31 01:04:58 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-31 01:04:58 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-31 01:04:58 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-31 01:04:51 0 d-------- C:\Documents and Settings\Owner\Application Data\Identities
2008-05-30 21:31:36 0 d-------- C:\Program Files\Messenger
2008-05-30 21:24:30 0 d-------- C:\Program Files\Movie Maker
2008-05-30 21:21:15 0 d-------- C:\Program Files\Windows NT
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 02:50 PM]
"SunKistEM"="C:\Program Files\Digital Media Reader\shwiconem.exe" [11/15/2004 06:04 PM]
"@"="" []
"SSC_UserPrompt"="C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [08/05/2004 08:23 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/27/2004 07:22 PM]
"IS CfgWiz"="C:\Program Files\Norton Internet Security\cfgwiz.exe" [08/17/2004 06:36 PM]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [08/30/2004 10:29 PM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [03/18/2005 12:05 AM]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [11/02/2004 11:24 PM]
"SoundMan"="SOUNDMAN.EXE" [04/15/2005 02:01 PM C:\WINDOWS\SOUNDMAN.EXE]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
"HostManager"="C:\Program Files\Common Files\AOL\1212214156\EE\AOLHostManager.exe" [11/03/2004 05:03 PM]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [10/18/2004 08:42 PM]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [08/17/2004 09:26 PM]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [10/02/2004 07:34 PM]
"_AntiSpyware"="C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe" [10/19/2004 04:00 AM]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" [04/05/2004 05:33 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [04/13/2008 08:12 PM]
"AOL Fast Start"="C:\Program Files\America Online 9.0\AOL.exe" [06/23/2005 12:24 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 7:44:06 AM]
BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [5/31/2008 1:55:40 AM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{F2A0229A-C4CA-4789-B606-973D24DCDD1C}"= C:\Program Files\McAfee\McAfee AntiSpyware\MssShell.dll [10/19/2004 04:00 AM 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{508aba02-2eda-11dd-9fb6-806d6172696f}]
PlayWithPowerDVD\Command- "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%l"
*Newly Created Service* - UDFS
-- End of Deckard's System Scanner: finished at 2008-05-31 03:12:46 ------------