– File Associations -----------------------------------------------------------
.scr - unable to read key
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 rttmntr (R-TT Backup Archive Explorer) - c:\windows\system32\drivers\rttmntr.sys <Not Verified; Acronis; >
R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync02 (StarForce Protection Synchronization Driver (version 2.x)) - c:\windows\system32\drivers\sfsync02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfsync03 (StarForce Protection Synchronization Driver (version 3.x)) - c:\windows\system32\drivers\sfsync03.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System>
R0 snaprtt (Acronis Snapshots Manager (R-TT)) - c:\windows\system32\drivers\snaprtt.sys <Not Verified; Acronis; Acronis Snapshot API>
R1 papycpu2 - c:\windows\system32\drivers\papycpu2.sys
R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys
R2 rttfsfilt (R-TT FS Filter) - c:\windows\system32\drivers\rttfsfilt.sys <Not Verified; Acronis; >
R3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S0 ElbyVCD - c:\windows\system32\drivers\elbyvcd.sys (file missing)
S0 viaagp1 (VIA AGP Filter) - c:\windows\system32\drivers\viaagp1.sys (file missing)
S2 BTXBAR (ATI TV Wonder WDM Video Crossbar) - c:\windows\system32\drivers\btxbar.sys <Not Verified; ATI Technologies; ATI TV Wonder PCI>
S2 IAIVMOUSERVICE (IAIVMOU Service) - c:\windows\system32\drivers\iaivmou.sys <Not Verified; InterAct Accessories Incorporation; InterAct Gaming Device>
S2 PPSCAN - c:\windows\system32\drivers\ppscan.sys <Not Verified; Hewlett-Packard Co.; >
S3 Agamejoy (A4Tech Game Port Input Device) - c:\windows\system32\drivers\agamejoy.sys <Not Verified; A4Tech Co., Ltd.; A4Tech Game Device Driver>
S3 ALCXWDM (Service for Realtek AC97 Audio (WDM)) - c:\windows\system32\drivers\alcxwdm.sys (file missing)
S3 ezplay (VSO Software ezplay) - c:\windows\system32\drivers\ezplay.sys <Not Verified; VSO Software; autoplay Application>
S3 giveio - c:\windows\system32\giveio.sys
S3 GMSIPCI - f:\install\gmsipci.sys (file missing)
S3 IAIGD150FilterService (IAIGD150 Filter Service) - c:\windows\system32\drivers\iaigd150.sys <Not Verified; InterAct Accessories Incorporation; InterAct Gaming Device>
S3 IAIUpperFilterService (IAIUPPER Filter Service) - c:\windows\system32\drivers\iaiupper.sys <Not Verified; InterAct Accessories Incorporation; InterAct Gaming Device>
S3 kxwdmdrv (kX WDM Driver Service) - c:\windows\system32\drivers\kx.sys (file missing)
S3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys (file missing)
S3 ossrv (Creative OS Services Driver) - c:\windows\system32\drivers\ctoss2k.sys (file missing)
S3 rtl8139 (Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver) - c:\windows\system32\drivers\rtl8139.sys (file missing)
S3 RushTopDevice - c:\program files\msi\core center\rushtop.sys (file missing)
S3 sfcure01 (StarForce Cure Driver (version 1.x)) - c:\windows\system32\drivers\sfcure01.sys
S3 SPCP825K (Sunplus Serial port driver) - c:\windows\system32\drivers\spcp825k.sys (file missing)
– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 EpsonBidirectionalService - c:\program files\epson\esm2\eebsvc.exe
R2 Routing (Routing Service) - c:\windows\system32\routing.exe
S2 perfmons (perfmons Service) - c:\windows\system32\perfs.exe (file missing)
S2 RoxLiveShare9 (LiveShare P2P Server 9) - “c:\program files\common files\roxio shared\9.0\sharedcom\roxliveshare9.exe” (file missing)
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
S3 stllssvr - “c:\program files\common files\surething shared\stllssvr.exe” <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>
– Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer: ATK
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
Description:
Device ID: ROOT\IMAGE\0002
Manufacturer: Hewlett-Packard
Name:
PNP Device ID: ROOT\IMAGE\0002
Service:
Class GUID: {D45B1C18-C8FA-11D1-9F77-0000F805F530}
Description: NT Apm/Legacy Interface Node
Device ID: ROOT\NTAPM\0000
Manufacturer: Microsoft
Name: NT Apm/Legacy Interface Node
PNP Device ID: ROOT\NTAPM\0000
Service: NtApm
Class GUID: {4D36Å97D-Å325-11ÑÅ-ÂFÑ1-08002ÂÅ10318}
Description: Plug and Play BIOS Extension
Device ID: ROOT\SYSTEM\0003
Manufacturer: (Standard system devices)
Name: Plug and Play BIOS Extension
PNP Device ID: ROOT\SYSTEM\0003
Service: vax347b
Class GUID: {4D36Å97D-Å325-11ÑÅ-ÂFÑ1-08002ÂÅ10318}
Description: PnP BIOS Extension
Device ID: ROOT\SYSTEM\0004
Manufacturer: (Standard system devices)
Name: PnP BIOS Extension
PNP Device ID: ROOT\SYSTEM\0004
Service: d347bus
– Scheduled Tasks -------------------------------------------------------------
2008-01-24 06:44:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-12-08 00:04:01 344 --a------ C:\WINDOWS\Tasks\At6.job
2007-09-06 23:04:00 352 --a------ C:\WINDOWS\Tasks\At7.job
2007-06-08 23:04:00 350 --a------ C:\WINDOWS\Tasks\At4.job
2007-04-14 23:04:00 352 --a------ C:\WINDOWS\Tasks\At8.job
2004-01-02 23:30:30 474 --a------ C:\WINDOWS\Tasks\Event 1.job
– Files created between 2007-12-24 and 2008-01-24 -----------------------------
2008-01-24 12:01:48 250368 --a------ C:\WINDOWS\system32\andt.sys
2008-01-23 22:37:19 0 d-------- C:\Documents and Settings\Le Survenant !.housecall6.6
2008-01-23 21:55:49 45056 --a------ C:\WINDOWS\system32\Indt2.sys <Not Verified; a; Microsoft Internet Explorer1>
2008-01-23 03:08:34 0 dr-h----- C:\Documents and Settings\Le Survenant !\Recent
2008-01-22 20:18:54 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-01-21 18:03:58 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\SolSuite
2008-01-19 10:13:06 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-19 10:13:00 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-01-19 10:12:59 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\SUPERAntiSpyware.com
2008-01-19 10:12:40 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-17 16:48:34 0 d-------- C:\Documents and Settings\LocalService\My Documents
– Find3M Report ---------------------------------------------------------------
2008-01-21 21:56:12 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\Azureus
2008-01-19 14:59:57 59 --a------ C:\WINDOWS\popcinfo.dat
2008-01-19 10:18:54 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\funkitron
2008-01-19 10:12:40 0 d-------- C:\Program Files\Common Files
2008-01-12 23:31:49 0 d-------- C:\Program Files\winamp
2007-12-25 22:28:11 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\ATI MMC
2007-12-18 14:10:40 32256 --a------ C:\WINDOWS\system32\routing.exe
2007-12-08 23:08:45 0 d-------- C:\Program Files\SlySoft
2007-12-02 10:34:26 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\Vso
2007-12-01 10:11:14 0 d-------- C:\Program Files\Java
2007-11-26 20:34:26 0 d-------- C:\Program Files\eMule
2007-11-26 18:38:45 0 d-------- C:\Documents and Settings\Le Survenant !\Application Data\Media Player Classic
2007-11-25 23:31:58 0 d-------- C:\Program Files\XP Codec Pack
2007-11-18 11:39:32 13474 --a------ C:\WINDOWS\mozver.dat
2007-11-18 10:08:35 34 --a------ C:\Documents and Settings\Le Survenant !\Application Data\pcouffin.log
2007-11-18 10:08:29 47360 --a------ C:\Documents and Settings\Le Survenant !\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2007-11-18 10:08:29 1144 --a------ C:\Documents and Settings\Le Survenant !\Application Data\pcouffin.inf
2007-11-18 10:08:29 7887 --a------ C:\Documents and Settings\Le Survenant !\Application Data\pcouffin.cat
2007-11-18 09:42:36 12288 --a------ C:\WINDOWS\impborl.dll
2007-11-18 09:42:36 606848 --a------ C:\WINDOWS\flashax.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(R) Operating System>
2007-11-14 22:14:55 724992 --a------ C:\WINDOWS\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>
2007-10-29 11:07:13 251712 -rahs---- C:\ntldr