– File Associations -----------------------------------------------------------
All associations okay.
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 Spssys (Toshiba SPS Service) - c:\windows\system32\drivers\spssys.sys <Not Verified; Toshiba Corporation; spssys>
S3 BW2NDIS5 - c:\windows\system32\drivers\bw2ndis5.sys (file missing)
S3 SQTECH905C (DaulCamera) - c:\windows\system32\drivers\capt905c.sys <Not Verified; Service & Quality Technology.; SQ905c>
– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Viewpoint Manager Service - “c:\program files\viewpoint\common\viewpointservice.exe” <Not Verified; Viewpoint Corporation; Viewpoint Manager>
S3 hpqwmi (HP WMI Interface) - c:\program files\hpq\shared\hpqwmi.exe <Not Verified; Hewlett-Packard Development Company, L.P.; hpqwmi Module>
– Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
– Scheduled Tasks -------------------------------------------------------------
2008-03-22 17:44:11 258 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
– Files created between 2008-02-22 and 2008-03-22 -----------------------------
2008-03-22 16:10:54 0 d-------- C:\Program Files\Trend Micro
– Find3M Report ---------------------------------------------------------------
2008-03-22 16:18:27 0 d-------- C:\Program Files\ICQToolbar
2008-03-19 23:25:51 0 d-------- C:\Documents and Settings\Ritalee\Application Data\U3
2008-03-11 01:26:17 20030 --a----c- C:\Documents and Settings\Ritalee\Application Data\wklnhst.dat
2008-02-25 22:26:14 21840 --a----ct C:\WINDOWS\system32\SIntfNT.dll
2008-02-25 22:26:14 17212 --a----ct C:\WINDOWS\system32\SIntf32.dll
2008-02-25 22:26:14 12067 --a----ct C:\WINDOWS\system32\SIntf16.dll
2008-02-25 01:35:12 0 d-------- C:\Program Files\Diablo II
2008-02-12 21:49:29 3064 --a------ C:\WINDOWS\mozver.dat
2008-02-11 10:28:27 3446 --a------ C:\WINDOWS\unins000.dat
2008-02-11 10:24:08 691545 --a------ C:\WINDOWS\unins000.exe
2008-02-11 00:12:17 0 d-------- C:\Program Files\music_now
– Registry Dump ---------------------------------------------------------------
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
12/18/2007 09:10 AM 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}”= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [12/18/2007 09:10 AM 262144]
[-HKEY_CLASSES_ROOT\CLSID{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [02/02/2005 05:12 AM]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [06/08/2007 12:47 AM]
“hpWirelessAssistant”=“C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe” [11/16/2005 09:30 AM]
“HP Software Update”=“C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe” [02/17/2005 12:11 AM]
“QPService”=“C:\Program Files\HP\QuickPlay\QPService.exe” [12/12/2005 12:39 PM]
“eabconfg.cpl”=“C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe” [12/07/2005 11:56 AM]
“Cpqset”=“C:\Program Files\HPQ\Default Settings\cpqset.exe” [02/17/2005 03:01 PM]
“RecGuard”=“C:\Windows\SMINST\RecGuard.exe” [10/11/2005 11:23 AM]
“TosGbWatcher”=“C:\Program Files\TOSHIBA\gigabeat room 2.0.2\TosGbWatcher.exe” [04/26/2005 02:02 AM]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [12/04/2007 06:00 AM]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [07/27/2004 05:50 PM]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [08/09/2004 07:03 AM]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [08/21/2006 10:39 PM]
“zzz_ImInstaller_IncrediMail”=“C:\Documents and Settings\Ritalee\Local Settings\Temp\ImInstaller\IncrediMail\incredimail_install.exe”
“ZoneAlarm Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [11/14/2007 05:05 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [08/04/2004 01:00 AM]
“AIM”=“C:\Program Files\AIM\aim.exe” [08/05/2005 03:08 PM]
“msnmsgr”=“C:\Program Files\MSN Messenger\MsnMsgr.exe” [01/19/2007 12:54 PM]
“SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [01/28/2008 12:43 PM]
C:\Documents and Settings\Ritalee\Start Menu\Programs\Startup
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [11/17/1996]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [11/17/1996]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [9/24/2005 2:39:30 AM]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\Ritalee\Desktop\tipi inside.jpg
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
“C:\Program Files\ICQLite\ICQLite.exe” -minimize
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
“C:\Program Files\MSN Messenger\msnmsgr.exe” /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
“C:\Program Files\QuickTime\qttask.exe” -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
“C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewpointPhotosDeviceConnect]
C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
“C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe” -quiet
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a
– End of Deckard’s System Scanner: finished at 2008-03-22 17:48:17 ------------