Hopefully last bit!
2007-04-21 03:12:54 0 d—s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2007-04-21 03:12:34 0 d-------- C:\Documents and Settings
2007-04-21 03:12:33 0 d–hs---- C:\System Volume Information
2007-04-21 03:04:32 0 d-------- C:\WINDOWS
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\WinSxS
2007-04-21 03:04:32 0 dr------- C:\WINDOWS\Web
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\twain_32
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\wins
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\wbem
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\usmt
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\spool
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\ShellExt
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\Setup
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\ras
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\oobe
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\npp
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\mui
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\inetsrv
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\IME
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\icsxml
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\ias
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\export
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\drivers
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\drivers\etc
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\drivers\disdn
2007-04-21 03:04:32 0 dr-hs–c- C:\WINDOWS\system32\dllcache
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\dhcp
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\config
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\3com_dmi
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\3076
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\2052
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1054
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1042
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1041
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1037
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1033
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1031
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1028
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system32\1025
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\system
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\security
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Resources
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\repair
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Provisioning
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\PeerNet
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\pchealth
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\mui
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\msapps
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\msagent
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Media
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\java
2007-04-21 03:04:32 0 d–h----- C:\WINDOWS\inf
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\ime
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Help
2007-04-21 03:04:32 0 dr–s---- C:\WINDOWS\Fonts
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\ehome
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Driver Cache
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\dell
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Debug
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Cursors
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Connection Wizard
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\Config
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\AppPatch
2007-04-21 03:04:32 0 d-------- C:\WINDOWS\addins
– Find3M Report ---------------------------------------------------------------
2007-04-21 20:44:10 40 —hs---- C:\Documents and Settings\GE\Application Data.zreglib
2007-04-21 03:13:15 62 --ahs---- C:\Documents and Settings\GE\Application Data\desktop.ini
– Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
{089FD14D-132B-48FC-8861-0048AE113215} C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
“adiras”=“adiras.exe”
“ZoneAlarm Client”=“"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"”
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe”
“SBCSTray”=“C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe”
“WinPatrol”=“C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe”
“AWMON”=“"C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"”
“NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup”
“NvMediaCenter”=“RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit”
“nwiz”=“nwiz.exe /install”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe”
“TClockEx”=“C:\Documents and Settings\GE\My Documents\Unzipped\tclockex\TCLOCKEX.EXE”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegistryTools”=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoActiveDesktop”=hex:00,00,00,00
“NoSaveSettings”=hex:00,00,00,00
“ClearRecentDocsOnExit”=hex:00,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“AVG Anti-Spyware 7.5”
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”=“”
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify!SASWinLogon
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
@=“”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“CloneCDTray”=“"C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s”
“HPDJ Taskbar Utility”=“C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe”
“NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe”
“RemoteControl”=“"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"”
“SunJavaUpdateSched”=“"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"”
“UpdReg”=“C:\WINDOWS\UpdReg.EXE”
“iTunesHelper”=“"C:\Program Files\iTunes\iTunesHelper.exe"”
“QuickTime Task”=“"C:\Program Files\QuickTime\qttask.exe" -atboottime”
“TkBellExe”=“"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot”
“NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup”
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
newlycreated - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_SBAPIFS
– End of Deckard’s System Scanner: finished at 2007-05-17 at 03:15:14 ---------