-- Files created between 2007-12-23 and 2008-01-23 -----------------------------
2008-01-21 15:32:37 0 d-------- C:\Program Files\Trend Micro
2008-01-21 07:27:20 0 d--h----- C:\Windows\PIF
2008-01-21 04:06:33 0 d-------- C:\Windows\system32\Kaspersky Lab
2008-01-21 00:56:50 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-01-18 23:19:24 0 d-------- C:\Users\All Users\Apple
2008-01-18 23:19:24 0 d-------- C:\Program Files\Apple Software Update
2008-01-13 04:17:09 0 d-------- C:\Users\All Users\Lavasoft
2008-01-13 04:17:09 0 d-------- C:\Program Files\Lavasoft
2008-01-13 04:04:02 0 d-------- C:\Program Files\Windows Live Safety Center
2008-01-07 00:27:14 77 --a------ C:\Windows\system32\7092.bat
2008-01-06 22:30:23 77 --a------ C:\Windows\system32\1657.bat
2008-01-05 01:08:38 0 d-------- C:\Program Files\SoundSpectrum
2008-01-03 20:07:39 77 --a------ C:\Windows\system32\1317.bat
2008-01-03 01:56:45 0 d-------- C:\Program Files\RadioXpi
2008-01-02 20:16:45 77 --a------ C:\Windows\system32\6345.bat
2008-01-01 15:50:29 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-01 07:39:53 0 d-------- C:\Program Files\JL2004C
2008-01-01 06:50:06 77 --a------ C:\Windows\system32\2715.bat
2007-12-30 22:40:28 77 --a------ C:\Windows\system32\2058.bat
2007-12-30 21:57:11 77 --a------ C:\Windows\system32\2481.bat
2007-12-30 20:56:52 77 --a------ C:\Windows\system32\4304.bat
2007-12-30 17:48:54 680571 --a------ C:\xace26.exe <Not Verified; e-merge GmbH; XAce Plus>
2007-12-30 14:12:57 77 --a------ C:\Windows\system32\4022.bat
2007-12-30 02:08:00 12095 --a------ C:\logfile
2007-12-30 01:32:50 0 d-------- C:\Program Files\Kodak
2007-12-30 01:17:32 77 --a------ C:\Windows\system32\1302.bat
2007-12-30 00:55:57 77 --a------ C:\Windows\system32\2720.bat
2007-12-29 23:52:56 0 d-------- C:\Program Files\Common Files\Ahead
2007-12-29 21:08:35 217088 --a------ C:\Windows\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2007-12-29 21:08:34 282624 --a------ C:\Windows\system32\xvidvfw.dll
2007-12-29 21:08:34 1559040 --a------ C:\Windows\system32\xvidcore.dll
2007-12-29 21:08:33 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2007-12-29 21:08:33 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2007-12-29 21:08:33 682496 --a------ C:\Windows\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2007-12-29 21:08:31 7680 --a------ C:\Windows\system32\ff_vfw.dll
2007-12-29 21:08:28 0 d-------- C:\Users\All Users\Real
2007-12-29 20:52:43 77 --a------ C:\Windows\system32\1174.bat
2007-12-29 20:11:07 77 --a------ C:\Windows\system32\3701.bat
2007-12-29 19:08:40 77 --a------ C:\Windows\system32\6627.bat
2007-12-29 02:56:27 0 d-------- C:\Program Files\Common Files\Intel
2007-12-29 01:59:46 77 --a------ C:\Windows\system32\1718.bat
2007-12-28 21:55:28 77 --a------ C:\Windows\system32\6066.bat
2007-12-28 21:49:59 77 --a------ C:\Windows\system32\3444.bat
2007-12-27 22:23:02 77 --a------ C:\Windows\system32\4442.bat
2007-12-27 22:20:00 77 --a------ C:\Windows\system32\6490.bat
2007-12-25 03:21:46 0 d-------- C:\Program Files\FinalBurner(37)
2007-12-24 16:41:12 77 --a------ C:\Windows\system32\9445.bat
2007-12-23 02:44:19 77 --a------ C:\Windows\system32\9261.bat
-- Find3M Report ---------------------------------------------------------------
2008-01-18 00:52:31 130885 --a------ C:\Windows\hpoins18.dat
2008-01-14 21:57:56 0 d-------- C:\Program Files\AdorageI-GfxDatas
2008-01-09 01:33:48 0 d-------- C:\Program Files\Windows Mail
2008-01-09 01:33:47 0 d-------- C:\Program Files\Windows Sidebar
2008-01-06 22:35:47 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\DVDFab
2008-01-05 01:16:59 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\SoundSpectrum
2008-01-03 02:15:32 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Real
2008-01-03 01:57:10 1767 --a------ C:\Windows\mozver.dat
2008-01-01 15:50:29 0 d-------- C:\Program Files\Common Files
2007-12-30 01:22:49 0 d-a------ C:\Program Files\Common Files\LightScribe
2007-12-30 00:38:12 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Ahead
2007-12-29 21:16:41 0 d-------- C:\Program Files\DVD Shrink
2007-12-29 21:08:32 0 d-------- C:\Program Files\K-Lite Codec Pack
2007-12-29 03:22:27 0 d--h----- C:\Users\Alan Chapin\AppData\Roaming\GTek
2007-12-29 02:27:57 0 d-------- C:\Program Files\DivX
2007-12-27 22:16:57 0 d-------- C:\Program Files\FinalBurner
2007-12-27 22:15:06 0 d-------- C:\Program Files\Common Files\Scanner
2007-12-27 21:23:02 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Vso
2007-12-27 21:23:02 33 --a------ C:\Users\Alan Chapin\AppData\Roaming\pcouffin.log
2007-12-27 01:53:14 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Real(282)
2007-12-23 01:20:04 0 d-------- C:\Program Files\HP
2007-12-21 19:10:23 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Zeon
2007-12-21 19:07:51 77 --a------ C:\Windows\system32\5860.bat
2007-12-20 21:48:33 0 d-------- C:\Program Files\Microsoft Silverlight
2007-12-18 06:56:27 77 --a------ C:\Windows\system32\3811.bat
2007-12-15 19:51:03 77 --a------ C:\Windows\system32\7271.bat
2007-12-15 19:11:54 77 --a------ C:\Windows\system32\5327.bat
2007-12-15 18:06:46 77 --a------ C:\Windows\system32\7965.bat
2007-12-15 17:59:04 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\blstoolbar
2007-12-13 20:44:24 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Backup MyPC
2007-12-13 01:45:43 0 d-------- C:\Program Files\Roxio
2007-12-11 21:11:04 0 d--h----- C:\Program Files\InstallShield Installation Information
2007-12-11 21:10:49 0 d-------- C:\Program Files\Amazon
2007-12-07 19:33:34 77 --a------ C:\Windows\system32\1889.bat
2007-12-06 23:22:20 0 d-------- C:\Program Files\Memorex exPressit Label Design Studio
2007-12-06 23:22:11 0 d-------- C:\Program Files\Common Files\SureThing Shared
2007-12-04 20:48:05 0 d-------- C:\Program Files\DVDFab HD Decrypter 4
2007-12-04 19:42:08 77 --a------ C:\Windows\system32\3111.bat
2007-12-04 19:05:26 77 --a------ C:\Windows\system32\8354.bat
2007-12-02 04:01:17 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Help
2007-11-30 20:23:20 0 d-------- C:\Program Files\Runtime Software
2007-11-30 20:19:23 77 --a------ C:\Windows\system32\8058.bat
2007-11-30 00:52:17 77 --a------ C:\Windows\system32\9020.bat
2007-11-30 00:24:08 0 d-------- C:\Users\Alan Chapin\AppData\Roaming\Lavasoft
2007-11-29 01:50:36 77 --a------ C:\Windows\system32\5217.bat
2007-11-29 01:33:26 147456 --a------ C:\Windows\system32\vbzip10.dll <Not Verified; Info-ZIP; Info-ZIP's WiZ>
2007-11-28 22:15:00 40737 --a------ C:\Windows\system32\rightonadz-uninst.exe
2007-11-27 21:55:10 7887 --a------ C:\Users\Alan Chapin\AppData\Roaming\pcouffin.cat
2007-11-20 04:16:35 169 --a------ C:\AUTOEXEC.BAT
2007-11-12 22:01:00 5642 --ahs---- C:\Windows\system32\KGyGaAvL.sys
2007-11-03 01:13:49 8 -r-hs---- C:\Windows\system32\154C54369E.sys
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [09/28/2006 08:42 AM]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [11/20/2006 06:34 AM]
"RtHDVCpl"="RtHDVCpl.exe" [10/25/2007 05:52 AM C:\WINDOWS\RtHDVCpl.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 03:24 PM]
"HelpCenter4.1"="C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [06/28/2007 06:02 PM]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [06/15/2007 06:15 PM]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [06/05/2007 08:12 AM]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [04/19/2007 05:11 PM]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [06/14/2007 03:44 PM]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [06/14/2007 03:57 PM]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [06/14/2007 03:48 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 03:00 AM]
"DT HPW"="C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe" [04/25/2007 11:36 AM]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [08/28/2007 12:59 AM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [08/28/2007 12:59 AM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [08/28/2007 12:59 AM]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [02/20/2007 02:07 AM]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [05/03/2007 12:12 PM]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe" [06/28/2007 03:09 PM]
"KBD"="C:\HP\KBD\KbdStub.EXE" [12/08/2006 10:16 AM]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [02/20/2007 02:07 AM]
"USB2Check"="C:\Windows\system32\PCLECoInst.dll" [12/21/2005 10:14 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [11/20/2007 02:39 AM]
"NMSSupport"="C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [06/27/2007 10:14 AM]
"CCUTRAYICON"="C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [06/27/2007 10:18 AM]
"-FreedomNeedsReboot"="C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [06/28/2007 03:09 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/09/2008 01:28 AM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/14/2007 12:38 AM]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [11/02/2006 07:35 AM]
"Iconoid"="C:\Program Files\Iconoid\iconoid.exe" [02/03/2007 05:38 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:36 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [08/31/2007 04:46 PM]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 9:05:26 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [1/2/2007 8:40:10 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
rsmsvcs ntmssvc
HPZ12 Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\ialaunch.exe id= ver=1.0.0.0
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
AutoRun\command- L:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{872afd91-34c8-11dc-b9be-001bfc073bbe}]
AutoRun\command- G:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-01-23 20:42:28 ------------