– File Associations -----------------------------------------------------------
All associations okay.
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.10.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.10.0>
R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver>
R2 s24trans (WLAN Transport) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
S3 catchme - c:\docume~1\sandyr~1\locals~1\temp\catchme.sys (file missing)
S3 DSproct - c:\program files\dell support\gtaction\triggers\dsproct.sys <Not Verified; GTek Technologies Ltd.; processt>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 RegSrvc (Intel(R) PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel(R) PROSet/Wireless Registry Service>
R2 WLANKEEPER (Intel(R) PROSet/Wireless SSO Service) - c:\program files\intel\wireless\bin\wlkeeper.exe <Not Verified; Intel(R) Corporation; SSO Service>
– Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
– Files created between 2007-12-08 and 2008-01-08 -----------------------------
2008-01-07 22:08:05 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-01-07 19:07:03 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-01 18:59:41 0 d-------- C:!KillBox
2008-01-01 16:29:32 0 d-------- C:\VundoFix Backups
2007-12-28 20:53:27 356352 --a------ C:\Documents and Settings\Sandy Rudy\cwshredder.dll <Not Verified; Trend Micro Incorporated; Anti-Spyware Engine>
2007-12-26 20:22:56 147456 -ra------ C:\WINDOWS\system32\mcs_vfw.dll
2007-12-26 20:22:56 249856 -ra------ C:\WINDOWS\system32\mcs_cor2.dll
2007-12-26 20:22:56 700416 -ra------ C:\WINDOWS\system32\mcs_cor1.dll
2007-12-26 20:22:40 282624 -ra------ C:\WINDOWS\Uninstall.exe <Not Verified; ; Uninstall ?? ???>
2007-12-26 20:22:40 11648 -ra------ C:\WINDOWS\system32\drivers\CamFlt.sys <Not Verified; Samsung electronics, Inc; Samsung electronics, Inc>
2007-12-26 20:22:40 72832 -ra------ C:\WINDOWS\system32\drivers\CamAvb.sys <Not Verified; Samsung Inc.; Samsung Digial Video Camera>
2007-12-26 20:22:40 58624 -ra------ C:\WINDOWS\system32\drivers\CamAv.sys <Not Verified; Samsung electronics, Inc; Samsung electronics, Inc>
2007-12-26 20:22:40 57344 -ra------ C:\WINDOWS\HAJEInstall.dll
2007-12-23 17:32:03 0 d-------- C:\Program Files\InterMute
2007-12-08 11:44:47 0 d-------- C:\WINDOWS\pss
– Find3M Report ---------------------------------------------------------------
2008-01-08 19:17:21 0 d-------- C:\Program Files\Trend Micro
2008-01-08 17:57:00 1466864 --a------ C:\Documents and Settings\Sandy Rudy\Application Data\CleanUp!.log
2007-12-26 20:24:33 0 d-------- C:\Program Files\QuickTime
2007-11-29 21:42:07 0 d-------- C:\Documents and Settings\Sandy Rudy\Application Data\MySpace
2007-11-29 21:42:03 0 d-------- C:\Program Files\MySpace
2007-11-12 20:35:10 0 d-------- C:\Program Files\Dl_cats
– Registry Dump ---------------------------------------------------------------
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [09/29/2005 01:01 PM]
“igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [12/13/2005 10:44 PM]
“igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [12/13/2005 10:41 PM]
“igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [12/13/2005 10:45 PM]
“IntelZeroConfig”=“C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [05/01/2006 08:28 AM]
“IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [05/01/2006 08:28 AM]
“SigmatelSysTrayApp”=“stsystra.exe” [03/24/2006 10:30 PM C:\WINDOWS\stsystra.exe]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [03/08/2006 05:48 PM]
“dla”=“C:\WINDOWS\system32\dla\tfswctrl.exe” [12/06/2004 12:05 AM]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [07/27/2004 03:50 PM]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [07/27/2004 03:50 PM]
“Google Desktop Search”=“C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” [01/01/2007 08:05 AM]
“PCMService”=“C:\Program Files\Dell\MediaDirect\PCMService.exe” [08/22/2006 02:32 PM]
“Device Detector”=“DevDetect.exe”
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [01/01/2007 08:03 AM]
“dlcimon.exe”=“C:\Program Files\Dell AIO Printer 946\dlcimon.exe” [02/14/2006 02:26 AM]
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe” [07/09/2001 10:50 AM]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [12/04/2007 06:00 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ModemOnHold”=“C:\Program Files\NetWaiting\netWaiting.exe” [09/10/2003 01:24 AM]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [08/10/2004 04:00 AM]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [10/13/2004 09:24 AM]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [08/14/2007 03:31 PM]
“SpybotSD TeaTimer”=“C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe” [08/31/2007 04:46 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 9:05:26 PM]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [5/3/2005 9:07:32 PM]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\SpySub.exe [12/23/2007 5:32:04 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
“{FA010552-4A27-4cb1-A1BB-3E2D697F1639}”= c:\Program Files\InterMute\SpySubtract\sshook.dll [12/23/2007 05:32 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“appinit_dlls”=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
– End of Deckard’s System Scanner: finished at 2008-01-08 19:18:04 ------------