second part of logs - ddr
Deckard's System Scanner v20071014.68
Run by jacek on 2008-03-07 19:25:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------
System Drive E: has 1.58 GiB (less than 15%) free.
-- HijackThis (run as jacek.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:20 PM, on 3/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\nfsclnt.exe
F:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
E:\Program Files\Common Files\LightScribe\LSSrvc.exe
F:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\TVersity\Media Server\MediaServer.exe
E:\WINDOWS\System32\dmadmin.exe
E:\SFU\Mapper\mapsvc.exe
E:\WINDOWS\system32\nfssvc.exe
E:\WINDOWS\system32\pcnfsd.exe
F:\Program Files\PeerGuardian2\pg2.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
E:\WINDOWS\SOUNDMAN.EXE
E:\WINDOWS\system32\S3trayp.exe
F:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
E:\WINDOWS\system32\LVCOMSX.EXE
E:\Program Files\Canon\MyPrinter\BJMyPrt.exe
E:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\PROGRA~1\Yahoo!\YOP\yop.exe
E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
E:\WINDOWS\system32\VTTimer.exe
E:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
F:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
F:\program files\ActiveSync\WCESCOMM.EXE
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
E:\Program Files\Messenger\msmsgs.exe
E:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
E:\Documents and Settings\jacek\Desktop\WinPFind35u\WinPFind35U.exe
E:\WINDOWS\notepad.exe
E:\Program Files\Norton Security Scan\Nss.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\WINDOWS\system32\NOTEPAD.EXE
E:\Documents and Settings\jacek\Desktop\dss.exe
C:\PLIKIZ~1\jacek.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - E:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - F:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - E:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - F:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [Windows Media Connect 2] "E:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "E:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [OpwareSE4] "F:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] E:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CanonMyPrinter] E:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [AudioDeck] E:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [Zone Labs Client] "E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [YOP] E:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [A8GSdsApp] E:\A8GSds\AGSeiApp.exe
O4 - HKLM\..\Run: [WinPatrol] E:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "E:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [WMPNSCFG] E:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] F:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\program files\ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Yahoo! Pager] "E:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PeerGuardian] F:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-117609710-1085031214-725345543-1004\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe (User 'internet')
O4 - HKUS\S-1-5-21-117609710-1085031214-725345543-1004\..\Run: [WMPNSCFG] E:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'internet')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-21-117609710-1085031214-725345543-1004 Startup: eMule.lnk = F:\Program Files\e.47c\emule.exe (User 'internet')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = F:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Otlook2000\Office\OSA9.EXE
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://F:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://F:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://F:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://F:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - f:\PROGRA~1\ACTIVE~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - f:\PROGRA~1\ACTIVE~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - f:\PROGRA~1\ACTIVE~1\INetRepl.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - E:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (Software Center) -
http://us.dl1.yimg.com/download.yahoo.com/dl/controls/ysftcntr/ysftcntr_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127678961638
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AFA411E-8DC4-4A1E-A58A-67B25AE56063}: NameServer = 10.0.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - E:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - F:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - E:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Unknown owner - E:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: LVSrvLauncher - Logitech Inc. - E:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton Ghost - Symantec Corporation - F:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TVersityMediaServer - Unknown owner - E:\Program Files\TVersity\Media Server\MediaServer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 11376 bytes
-- Files created between 2008-02-07 and 2008-03-07 -----------------------------
2008-02-20 21:48:44 0 d-------- E:\Documents and Settings\internet\Application Data\Media Player Classic
2008-02-18 20:21:24 0 d-------- E:\Documents and Settings\jacek\Application Data\WinPatrol
2008-02-18 20:21:08 0 d-------- E:\Program Files\BillP Studios
2008-02-18 20:19:08 0 d-------- E:\WINDOWS\system32\drivers\down
2008-02-18 15:02:57 0 d-------- E:\WINDOWS\system32\ZoneLabs
2008-02-18 15:02:22 0 d-------- E:\WINDOWS\Internet Logs
2008-02-18 13:50:49 0 d-------- E:\cmdcons
2008-02-17 16:09:28 0 d-------- E:\WINDOWS\system32\NtmsData
2008-02-16 18:34:19 701247 --a------ E:\Documents and Settings\internet\SOUNDMAN.EXE
2008-02-16 17:32:03 0 d-------- E:\Documents and Settings\jacek\Application Data\Seven Zip
2008-02-16 15:27:50 0 d-------- E:\SDM_ALLzSansy
2008-02-16 12:47:19 0 d-------- E:\SDM
2008-02-10 16:26:21 0 d-------- E:\Program Files\TVersity
2008-02-07 21:44:56 0 d-------- E:\Program Files\Omron Healthcare
-- Find3M Report ---------------------------------------------------------------
2008-03-07 18:00:01 0 d-------- E:\Program Files\Norton Security Scan
2008-02-23 17:59:33 0 d-------- E:\Documents and Settings\jacek\Application Data\OpenOffice.org2
2008-02-20 09:31:49 0 d-------- E:\Program Files\Common Files\Symantec Shared
2008-02-18 17:18:33 0 d-------- E:\Program Files\Symantec
2008-02-18 17:17:06 0 d-------- E:\Program Files\Common Files
2008-02-18 16:00:21 0 d-------- E:\Documents and Settings\jacek\Application Data\Yahoo!
2008-02-18 15:35:29 0 d-------- E:\Program Files\Yahoo!
2008-02-18 15:03:59 4212 ---h----- E:\WINDOWS\system32\zllictbl.dat
2008-01-20 16:47:48 0 d-------- E:\Program Files\Apple Software Update
2008-01-19 19:42:13 0 d-------- E:\Documents and Settings\jacek\Application Data\Media Player Classic
2008-01-19 19:36:22 0 d-------- E:\Program Files\K-Lite Codec Pack
2008-01-19 19:36:17 0 d-------- E:\Documents and Settings\jacek\Application Data\Real
2007-12-24 13:49:52 7680 --a------ E:\WINDOWS\system32\ff_vfw.dll
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Media Connect 2"="E:\Program Files\Windows Media Connect 2\WMCCFG.exe" [10/18/2006 09:58 PM]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 12:11 AM]
"SSBkgdUpdate"="E:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [09/30/2003 12:14 AM]
"SoundMan"="SOUNDMAN.EXE" [03/01/2006 12:22 AM E:\WINDOWS\SOUNDMAN.EXE]
"S3Trayp"="S3trayp.exe" [10/31/2005 12:15 PM E:\WINDOWS\system32\S3Trayp.exe]
"OpwareSE4"="F:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [03/21/2006 01:19 PM]
"NeroFilterCheck"="E:\WINDOWS\system32\NeroCheck.exe" [07/09/2001 10:50 AM]
"LVCOMSX"="E:\WINDOWS\system32\LVCOMSX.EXE" [10/08/2004 10:52 AM]
"CanonMyPrinter"="E:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [03/21/2006 05:30 PM]
"AudioDeck"="E:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [11/02/2006 03:57 PM]
"Zone Labs Client"="E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [08/23/2006 11:38 PM]
"YOP"="E:\PROGRA~1\Yahoo!\YOP\yop.exe" [10/26/2007 03:42 PM]
"YBrowser"="E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [12/09/2003 01:02 PM]
"VTTimer"="VTTimer.exe" [03/07/2005 03:33 AM E:\WINDOWS\system32\VTTimer.exe]
"A8GSdsApp"="E:\A8GSds\AGSeiApp.exe" [05/05/2007 12:15 AM]
"WinPatrol"="E:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [01/26/2008 09:38 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="E:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/27/2004 03:08 AM]
"PhotoShow Deluxe Media Manager"="F:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe" [02/25/2005 04:28 PM]
"MsnMsgr"="E:\Program Files\MSN Messenger\MsnMsgr.exe" []
"H/PC Connection Agent"="F:\program files\ActiveSync\WCESCOMM.EXE" [08/09/2000 09:41 PM]
"Yahoo! Pager"="E:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" []
"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]
"PeerGuardian"="F:\Program Files\PeerGuardian2\pg2.exe" [09/18/2005 06:40 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"Spybot - Search & Destroy"="E:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
path=E:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk
backup=E:\WINDOWS\pss\NkvMon.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"F:\Program Files\Adobe\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"E:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DynDNS Updater]
"F:\Program Files\DynDNS Updater\DynDNS.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
F:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
"E:\PROGRA~1\Symantec\osCheck.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ymetray]
"E:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"YPCService"=3 (0x3)
*Newly Created Service* - PGFILTER
-- End of Deckard's System Scanner: finished at 2008-03-07 19:25:39 ------------