– Find3M Report ---------------------------------------------------------------
2007-11-19 03:16:13 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-18 03:31:10 0 d-------- C:\Program Files\Warcraft III
2007-11-18 03:20:50 0 d-------- C:\Documents and Settings\angela\Application Data\Hamachi
2007-11-15 01:36:52 0 d-------- C:\Program Files\eMule
2007-11-09 17:23:51 0 d-------- C:\Documents and Settings\angela\Application Data\Adobe
2007-10-28 11:59:36 0 d-------- C:\Program Files\Online Services
2007-10-28 11:58:09 0 d-------- C:\Program Files\Common Files
2007-10-26 11:07:07 0 d-------- C:\Documents and Settings\angela\Application Data\ppstream
2007-10-25 02:53:31 0 d-------- C:\Program Files\MSN Messenger
2007-10-21 23:32:20 0 d-------- C:\Documents and Settings\angela\Application Data\AdobeUM
2007-10-09 18:31:41 0 d-------- C:\Program Files\Maxthon2
2007-10-08 22:50:42 19 --a------ C:\WINDOWS\popcinfo.dat
2007-09-29 01:16:28 0 d-------- C:\Documents and Settings\angela\Application Data\Sun
– Registry Dump ---------------------------------------------------------------
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“LaunchApp”=“launchapp”
“igfxtray”=“C:\WINDOWS\system32\igfxtray.exe” [11/28/2005 10:55 PM]
“igfxhkcmd”=“C:\WINDOWS\system32\hkcmd.exe” [11/28/2005 10:52 PM]
“igfxpers”=“C:\WINDOWS\system32\igfxpers.exe” [11/28/2005 10:55 PM]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [12/17/2005 01:32 AM]
“NDSTray.exe”=“NDSTray.exe”
“Toshiba Hotkey Utility”=“C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe” [01/28/2006 06:13 AM]
“TPSMain”=“TPSMain.exe” [06/01/2005 01:00 PM C:\WINDOWS\system32\TPSMain.exe]
“IntelZeroConfig”=“C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe” [12/05/2005 12:37 PM]
“IntelWireless”=“C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe” [11/28/2005 11:41 AM]
“IMJPMIG8.1”=“C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe” [08/04/2004 01:00 PM]
“MSPY2002”=“C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe” [08/04/2004 01:00 PM]
“PHIME2002ASync”=“C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe” [08/04/2004 01:00 PM]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [09/06/2007 06:06 PM]
“snpstd”=“C:\WINDOWS\vsnpstd.exe” [06/10/2004 01:48 PM]
“SmoothView”=“C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe” [04/27/2005 08:13 AM]
“BluetoothAuthenticationAgent”=“bthprops.cpl” [08/04/2004 12:56 AM C:\WINDOWS\system32\bthprops.cpl]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [08/04/2004 01:00 PM]
“msnmsgr”=“C:\Program Files\MSN Messenger\msnmsgr.exe” [01/19/2007 12:54 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2/7/2006 5:33:52 AM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
CHDAudPropShortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“BlueSoleil Hid Service”=2 (0x2)
“Spooler”=2 (0x2)
“O&O Defrag”=2 (0x2)
“MSSQL$SQLEXPRESS”=2 (0x2)
“helpsvc”=2 (0x2)
“avast! Mail Scanner”=3 (0x3)
“StarWindService”=2 (0x2)
“Macromedia Licensing Service”=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{0366f18e-2d45-11dc-9c34-0019d286ed86}]
Auto\command- I:\auto.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3298cd0a-850a-11dc-9cb5-00163696e195}]
AutoRun\command- F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3298cd0b-850a-11dc-9cb5-00163696e195}]
Auto\command- infrom.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3338c07d-337a-11dc-9c40-0019d286ed86}]
AutoRun\command- G:\ntde1ect.com
explore\Command- G:\ntde1ect.com
open\Command- G:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{6a079145-4bb8-11dc-9c75-0019d286ed86}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{9c8171e8-40d1-11dc-9c5d-00116712dd0b}]
Auto\command- F:\auto.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{9c8171e9-40d1-11dc-9c5d-00116712dd0b}]
Auto\command- auto.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{b97d4e17-23a6-11dc-9c23-0019d286ed86}]
AutoRun\command- H:\oxfordec.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{e63a7aec-3a7d-11dc-9c4c-0019d286ed86}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{e6669414-7b42-11dc-9ca3-00163696e195}]
Auto\command- F:\RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
– End of Deckard’s System Scanner: finished at 2007-11-19 03:22:15 ------------