– Files created between 2007-11-29 and 2007-12-29 -----------------------------
2007-12-29 16:33:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-12-29 15:28:38 0 dr-h----- C:\Documents and Settings\Owner\Recent
2007-12-29 14:19:11 1158 --a------ C:\WINDOWS\mozver.dat
2007-12-29 13:51:40 0 d-------- C:\Documents and Settings\Owner\Application Data\BitTorrent
2007-12-29 12:56:31 0 d-------- C:\WINDOWS\network diagnostic
2007-12-28 17:49:42 44928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS <Not Verified; Panda Software; Panda® Antivirus>
2007-12-28 14:34:15 0 d-------- C:\Program Files\MSXML 4.0
2007-12-27 20:34:14 0 d-------- C:\Program Files\STOPzilla!
2007-12-27 20:34:13 0 d-------- C:\Program Files\Common Files\iS3
2007-12-27 20:34:11 0 d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-12-27 19:55:56 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2007-12-27 19:53:05 0 d-------- C:\WINDOWS\Prefetch
2007-12-27 19:19:29 0 d-------- C:\WINDOWS\peernet
2007-12-27 19:19:26 0 d-------- C:\WINDOWS\provisioning
2007-12-27 19:15:22 0 d-------- C:\WINDOWS\ServicePackFiles
2007-12-27 19:03:54 0 d-------- C:\WINDOWS\EHome
2007-12-27 17:39:12 0 d-------- C:\Program Files\Trend Micro
2007-12-27 17:19:06 0 d-------- C:\Documents and Settings\Owner\Application Data\WinPatrol
2007-12-27 17:18:43 0 d-------- C:\Program Files\BillP Studios
2007-12-26 18:56:10 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2007-12-26 17:40:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
– Find3M Report ---------------------------------------------------------------
2007-12-29 16:30:49 0 d-------- C:\Program Files\Common Files
2007-12-29 16:26:28 0 d-------- C:\Program Files\Easy Internet signup
2007-12-29 16:06:56 0 d-------- C:\Program Files\Java
2007-12-29 14:19:20 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
2007-12-29 13:57:37 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-12-28 20:15:10 0 d-------- C:\Program Files\Messenger
2007-12-28 18:43:56 0 d-------- C:\Program Files\Symantec
2007-12-28 18:40:52 0 d-------- C:\Program Files\NetZero DSL
2007-12-28 18:37:32 0 d-------- C:\Program Files\Multimedia Card Reader
2007-12-28 18:32:06 0 d-------- C:\Program Files\iTunes
2007-12-28 18:27:22 0 d-------- C:\Program Files\Google
2007-12-28 17:59:07 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2007-12-27 19:19:29 0 d-------- C:\Program Files\Movie Maker
2007-12-27 19:14:36 0 d-------- C:\Program Files\Windows NT
2007-12-26 17:01:26 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2007-11-23 20:03:56 0 d-------- C:\Program Files\Compaq Instant Support
2007-11-04 16:37:56 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2007-10-05 10:11:08 225280 -ra------ C:\WINDOWS\system32\SZBase5.dll <Not Verified; iS3, Inc.; STOPzilla>
– Registry Dump ---------------------------------------------------------------
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{4224FF33-C2EB-4039-B8C8-6EED565B9D96}]
03/06/2007 10:27 AM 225240 --a------ C:\Program Files\NetZero DSL\PopupBlocker.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{8E613EAF-E16E-415C-BD39-F71D6A3B5518}”= C:\Program Files\NetZero DSL\Toolbar.dll [09/13/2007 01:34 PM 264688]
[-HKEY_CLASSES_ROOT\CLSID{8E613EAF-E16E-415C-BD39-F71D6A3B5518}]
[HKEY_CLASSES_ROOT\DSLToolbar.NetZero DSL.1]
[HKEY_CLASSES_ROOT\TypeLib{98C469F7-8C27-489D-B107-44FD6A54C554}]
[HKEY_CLASSES_ROOT\DSLToolbar.NetZero DSL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [09/25/2007 01:11 AM]
“hpsysdrv”=“c:\windows\system\hpsysdrv.exe” [05/07/1998 04:04 PM]
“HPHUPD05”=“c:\Program Files\HP{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe” [08/21/2003 03:23 AM]
“HPHmon05”=“C:\WINDOWS\System32\hphmon05.exe” [08/21/2003 03:15 AM]
“Sunkist2k”=“C:\Program Files\Multimedia Card Reader\shwicon2k.exe” [10/29/2003 10:17 AM]
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [01/16/2004 11:16 AM]
“HPDJ Taskbar Utility”=“C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe” [03/12/2003 04:23 AM]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [05/19/2004 07:35 PM]
“NetZeroDSL”=“C:\Program Files\NetZero DSL\ConnectionCenter.exe” [09/17/2007 03:48 PM]
“ccApp”=“C:\Program Files\Common Files\Symantec Shared\ccApp.exe” [01/22/2007 10:19 PM]
“C:\DOCUME~1\Owner\LOCALS~1\Temp\update.exe”=“C:\DOCUME~1\Owner\LOCALS~1\Temp\update.exe”
“VTTimer”=“VTTimer.exe” [10/22/2004 11:53 AM C:\WINDOWS\system32\VTTimer.exe]
“UpdateManager”=“C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe” [08/19/2003 08:01 AM]
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” [09/11/2007 05:48 PM]
“Recguard”=“C:\WINDOWS\SMINST\RECGUARD.EXE” [11/03/2003 04:50 PM]
“KBD”=“C:\HP\KBD\KBD.EXE” [02/11/2003 07:02 PM]
“AlcxMonitor”=“ALCXMNTR.EXE” [09/07/2004 01:47 PM C:\WINDOWS\ALCXMNTR.EXE]
“AGRSMMSG”=“AGRSMMSG.exe” [06/29/2004 09:06 AM C:\WINDOWS\AGRSMMSG.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [09/06/2007 11:19 AM]
“RecordNow!”=“”
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [08/03/2004 11:56 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
“DJSNetCN”=C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“NoColorChoice”=0 (0x0)
“NoSizeChoice”=0 (0x0)
“NoDispScrSavPage”=0 (0x0)
“NoDispCPL”=0 (0x0)
“NoVisualStyleChoice”=0 (0x0)
“NoDispSettingsPage”=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoActiveDesktop”=0 (0x0)
“NoSaveSettings”=0 (0x0)
“NoThemesTab”=0 (0x0)
“ForceActiveDesktopOn”=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=“Service”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=“Volume shadow copy”
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\Info.exe folder.htt 480 480
– End of Deckard’s System Scanner: finished at 2007-12-29 17:31:00 ------------