OK that was weird. My firewall I installed shut down my internet access. So I had to uninstall it and reboot. But I did get the logs you requested first. Am I doing something wrong? Did I miss a step or something? I don't know, there is so much to learn about a computer as well as the WWW. OK here are the logs.
Deckard's System Scanner v20071014.68
Run by Customer on 2008-07-28 12:05:59
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
5: 2008-07-28 17:06:12 UTC - RP6 - Deckard's System Scanner Restore Point
4: 2008-07-28 16:52:15 UTC - RP5 - Software Distribution Service 3.0
3: 2008-07-28 15:59:08 UTC - RP4 - Installed Ad-Aware
2: 2008-07-28 14:44:41 UTC - RP3 - Software Distribution Service 3.0
1: 2008-07-28 14:40:22 UTC - RP2 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
Total Physical Memory: 256 MiB (512 MiB recommended).
-- HijackThis (run as Customer.exe) --------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:28 PM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\R-TT\R-Firewall\R-Firewall.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Program Files\Virtual Assistant\bin\mpbtn.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\R-TT\R-Firewall\Service\RTT_CRC_Service.exe
C:\Documents and Settings\Customer\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Customer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.myembarq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.searchsave.com/index.php?req=search&source=1term=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: Embarq Toolbar - {4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C} - C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
O3 - Toolbar: EFOToolbar - {AB26BF6C-BB04-4F00-8F98-BDE786CDE97D} - C:\WINDOWS\system32\EFOToolbar.dll
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [R-Firewall] C:\Program Files\R-TT\R-Firewall\R-Firewall.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EMBARQ Help.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O8 - Extra context menu item: &3D Satellite Search - res://C:\WINDOWS\system32\EFOToolbar.dll/GoSatteliteSearch.dll.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: S&earchSave Web Search - res://C:\WINDOWS\system32\EFOToolbar.dll/GoWebSearch.dll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O15 - Trusted Zone:
http://sckesc.owotw.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {38A5F6F0-0B64-421B-A553-3D49A76ECDCD} (CPlayFirstMythicMarblesControl Object) -
http://download.playfirst.com/play/game/mythicmarbles/MythicMarbles.1.0.0.3.cab
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) -
http://www.gamehouse.com/realarcade-webgames/piratepoppers/PiratePoppers.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
http://catalog.update.microsoft.com.../en/x86/MuCatalogWebControl.cab?1216430943179
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) -
http://download.playfirst.com/play/game/dinerdash2/DinerDash2.1.0.0.67.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) -
http://www.gamehouse.com/realarcade-webgames/burgershop/GoBitGamesPlayer.cab
O16 - DPF: {BAC761D3-DFFD-4DB4-A01D-173346E090A7} (CPlayFirstzenerchiControl Object) -
http://download.playfirst.com/play/game/zenerchi/ZenerchiWeb.1.0.0.10.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) -
http://www.gamehouse.com/realarcade-webgames/dinerdashfloonthego/DinerDashFloGo.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://www.gamehouse.com/realarcade-webgames/zylom/zylomplayer.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: RTT CRC Service (RTT_CRC_Service) - Unknown owner - C:\Program Files\R-TT\R-Firewall\Service\RTT_CRC_Service.exe
O24 - Desktop Component 1: How to Make a Website on SiteRightNow.com -
http://www.siteritenow.com/
--
End of file - 9467 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080727-111804-155 O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\rcntntdm.exe
backup-20080727-111805-345 O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\rrwnw64r.exe
backup-20080727-111805-395 O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZBzeb032YYUS
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 RFW (R-Firewall Kernel Driver) - c:\windows\system32\rfwnt.sys <Not Verified; R-TT; R-Firewall>
R1 SbcpHid - c:\windows\system32\drivers\sbcphid.sys
R3 ADBLOCK.DLL (R-Firewall Plugin(ADBLOCK.DLL)) - c:\program files\r-tt\r-firewall\kernel\adblock.dll <Not Verified; R-TT; R-Firewall>
R3 CONTENT.DLL (R-Firewall Plugin(CONTENT.DLL)) - c:\program files\r-tt\r-firewall\kernel\content.dll <Not Verified; R-TT; R-Firewall>
R3 DNSCACHE.DLL (R-Firewall Plugin(DNSCACHE.DLL)) - c:\program files\r-tt\r-firewall\kernel\dnscache.dll <Not Verified; R-TT; R-Firewall>
R3 FTPFILT.DLL (R-Firewall Plugin(FTPFILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\ftpfilt.dll <Not Verified; R-TT; R-Firewall>
R3 HTMLFILT.DLL (R-Firewall Plugin(HTMLFILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\htmlfilt.dll <Not Verified; R-TT; R-Firewall>
R3 httpfilt.dll (R-Firewall Plugin(httpfilt.dll)) - c:\program files\r-tt\r-firewall\kernel\httpfilt.dll <Not Verified; R-TT; R-Firewall>
R3 IMAPFILT.DLL (R-Firewall Plugin(IMAPFILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\imapfilt.dll <Not Verified; R-TT; R-Firewall>
R3 MAILFILT.DLL (R-Firewall Plugin(MAILFILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\mailfilt.dll <Not Verified; R-TT; R-Firewall>
R3 NNTPFILT.DLL (R-Firewall Plugin(NNTPFILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\nntpfilt.dll <Not Verified; R-TT; R-Firewall>
R3 POP3FILT.DLL (R-Firewall Plugin(POP3FILT.DLL)) - c:\program files\r-tt\r-firewall\kernel\pop3filt.dll <Not Verified; R-TT; R-Firewall>
R3 PROTECT.DLL (R-Firewall Plugin(PROTECT.DLL)) - c:\program files\r-tt\r-firewall\kernel\protect.dll <Not Verified; R-TT; R-Firewall>
S3 ATWPKT2 - c:\program files\america online 8.0a\atwpkt2.sys (file missing)
S3 MREMP50 (MREMP50 NDIS Protocol Driver) - c:\program files\common files\motive\mremp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 MREMP50a64 (MREMP50a64 NDIS Protocol Driver) - c:\progra~1\common~1\motive\mremp50a64.sys (file missing)
S3 MRESP50 (MRESP50 NDIS Protocol Driver) - c:\program files\common files\motive\mresp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
S3 MRESP50a64 (MRESP50a64 NDIS Protocol Driver) - c:\progra~1\common~1\motive\mresp50a64.sys (file missing)
S3 SQTECH9080 (MegaCam(PID_9080_00)) - c:\windows\system32\drivers\capt9080.sys <Not Verified; Service & Quality Technology.; SQ908>
S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 AntiVirScheduler (Avira AntiVir Personal - Free Antivirus Scheduler) - "c:\program files\avira\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation>
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 McciCMService - "c:\program files\common files\motive\mccicmservice.exe" <Not Verified; Motive Communications, Inc.; >
R3 RTT_CRC_Service (RTT CRC Service) - c:\program files\r-tt\r-firewall\service\rtt_crc_service.exe
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-07-25 23:44:05 414 --ah----- C:\WINDOWS\Tasks\{5237129E-AB10-445E-B37F-02814D2F34BD}_KCRC-75F6A08A51_Customer.job
2008-07-21 23:12:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-06-28 and 2008-07-28 -----------------------------
2008-07-28 11:14:56 0 d-------- C:\Program Files\R-TT
2008-07-28 11:09:26 0 d-------- C:\Program Files\SpywareBlaster
2008-07-28 10:59:17 0 d-------- C:\Program Files\Lavasoft
2008-07-28 10:59:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-27 12:03:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-27 12:03:42 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-26 09:11:59 0 d-------- C:\Program Files\Avira
2008-07-26 09:11:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-21 16:25:48 0 d-------- C:\Program Files\Trend Micro
2008-07-20 17:32:08 0 d-------- C:\Program Files\MozyHome
2008-07-19 17:04:08 0 d-------- C:\WINDOWS\Prefetch
2008-07-19 16:11:29 0 d-------- C:\WINDOWS\system32\scripting
2008-07-19 16:11:23 0 d-------- C:\WINDOWS\l2schemas
2008-07-19 16:11:21 0 d-------- C:\WINDOWS\system32\en
2008-07-19 15:45:35 409600 --a------ C:\WINDOWS\system32\qmgr.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 15:41:12 1845248 --a------ C:\WINDOWS\system32\win32k.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-19 15:40:56 15360 --a------ C:\WINDOWS\system32\asfsipc.dll <Not Verified; Microsoft Corporation; Microsoft (R) DRM>
2008-07-19 15:39:27 0 d-------- C:\WINDOWS\EHome
2008-07-19 09:50:36 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-07-18 21:38:38 0 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-18 20:55:49 0 d-------- C:\Program Files\Windows Media Connect 2
2008-07-18 20:46:11 0 d-------- C:\WINDOWS\system32\LogFiles
2008-07-18 20:46:11 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-07-16 11:36:04 0 d-------- C:\Program Files\Cat Computer
2008-07-16 11:07:18 0 d-------- C:\Program Files\Quick Heal
2008-07-14 15:58:54 0 d-------- C:\WINDOWS\system32\bits
2008-07-14 15:57:59 7168 --a------ C:\WINDOWS\system32\bitsprx4.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-07-13 20:53:49 0 d-------- C:\WINDOWS\system32\NtmsData
2008-07-13 19:25:15 13893632 --a------ C:\Documents and Settings\Customer\ntuser.dat
2008-07-13 19:23:34 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-07-13 19:23:17 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-07-13 19:20:56 0 d-------- C:\Documents and Settings\LocalService\Application Data\EMBARQTOOLBAR
2008-07-13 19:20:42 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-07-09 10:26:22 0 d-------- C:\Program Files\iPod
2008-07-09 10:25:55 0 d-------- C:\Program Files\iTunes
2008-07-09 10:24:01 0 d-------- C:\Program Files\Bonjour
2008-07-09 10:21:37 0 d-------- C:\Program Files\QuickTime
2008-07-09 10:20:19 0 d-------- C:\Program Files\Apple Software Update
2008-07-09 10:19:13 0 d-------- C:\Program Files\Common Files\Apple
2008-07-09 10:18:49 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-09 00:15:11 0 d-------- C:\Program Files\Common Files\xing shared
2008-07-07 11:58:11 0 d-------- C:\Documents and Settings\Customer\Application Data\Meridian93
2008-07-07 11:12:02 0 d-------- C:\Documents and Settings\All Users\Application Data\HipSoft
2008-07-07 11:08:42 0 d-------- C:\Documents and Settings\Customer\Application Data\Gamelab
2008-07-06 18:01:21 0 d-------- C:\Program Files\sisagp
2008-07-06 14:58:22 0 d-------- C:\Documents and Settings\Customer\Application Data\Legends of pirates
2008-07-06 13:06:13 0 d-------- C:\Documents and Settings\Customer\Application Data\TheScruffs
2008-07-06 13:01:35 0 d-------- C:\Documents and Settings\All Users\Application Data\PlayPond
2008-07-06 12:57:51 0 d-------- C:\Documents and Settings\Customer\Application Data\Super-Cow
2008-07-06 12:32:37 0 d-------- C:\Documents and Settings\All Users\Application Data\3 Blokes Studios
2008-07-06 11:37:49 0 d-------- C:\Documents and Settings\Customer\Application Data\Twilight Games
2008-07-06 10:26:08 0 d-------- C:\Documents and Settings\All Users\Application Data\JollyBear
2008-07-06 10:25:07 0 d-------- C:\Documents and Settings\All Users\Application Data\MonteCristo
2008-07-04 11:38:23 0 d-------- C:\Documents and Settings\Customer\Application Data\Eyeblaster
2008-07-04 11:23:45 0 d-------- C:\users
2008-07-04 11:21:33 0 d-------- C:\Program Files\RealArcade
2008-07-02 22:30:16 691545 --a------ C:\WINDOWS\unins001.exe
2008-07-02 22:30:15 2553 --a------ C:\WINDOWS\unins001.dat
2008-07-02 21:12:45 0 --a------ C:\Documents and Settings\Customer\jagex_runescape_preferences.dat
2008-07-02 21:12:26 0 d-------- C:\WINDOWS\.jagex_cache_32
2008-07-01 11:34:52 278528 --a------ C:\WINDOWS\system32\EFOToolbar.dll <Not Verified; ; EFOToolbar Module>
2008-07-01 11:34:35 691545 --a------ C:\WINDOWS\unins000.exe
2008-07-01 11:34:35 8294 --a------ C:\WINDOWS\unins000.dat
2008-06-29 16:43:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-29 16:11:43 0 d-------- C:\Program Files\WOMGames
2008-06-28 15:16:34 0 d-------- C:\WINDOWS\system32\Adobe
2008-06-28 08:35:25 0 d-------- C:\Documents and Settings\All Users\Application Data\GoBit Games
2008-06-28 08:19:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Zylom
-- Find3M Report ---------------------------------------------------------------
2008-07-28 11:46:25 0 d-------- C:\Documents and Settings\Customer\Application Data\EMBARQTOOLBAR
2008-07-28 10:57:11 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-27 21:48:01 0 d-------- C:\Program Files\iWin.com
2008-07-27 11:29:08 0 d-------- C:\Program Files\Common Files
2008-07-27 11:00:27 0 d-------- C:\Program Files\Java
2008-07-26 16:39:52 0 d-------- C:\Program Files\SearchAssistant6
2008-07-26 15:54:57 0 d-------- C:\Program Files\Desktop
2008-07-25 22:35:07 1524 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-20 23:04:29 0 d-------- C:\Program Files\AMS
2008-07-19 18:57:24 0 d-------- C:\Program Files\Yahoo!
2008-07-19 16:50:22 0 d-------- C:\Program Files\Messenger
2008-07-19 16:36:18 0 d-------- C:\Program Files\Windows NT
2008-07-19 16:36:09 0 d-------- C:\Program Files\Movie Maker
2008-07-19 09:28:37 1636 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-07-16 18:55:33 0 d-------- C:\Program Files\MSN Messenger
2008-07-16 17:47:12 0 d-------- C:\Program Files\Symantec
2008-07-16 17:37:18 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-16 17:05:45 0 d-------- C:\Program Files\XoftSpy
2008-07-16 16:50:13 0 d-------- C:\Program Files\Norton SystemWorks
2008-07-16 12:26:42 0 d-------- C:\Program Files\iWin Games
2008-07-12 00:34:14 0 d-------- C:\Documents and Settings\Customer\Application Data\PlayFirst
2008-07-10 19:08:04 0 d-------- C:\Documents and Settings\Customer\Application Data\Apple Computer
2008-07-10 11:31:26 0 d-------- C:\Program Files\PopCap Games
2008-07-09 00:14:19 0 d-------- C:\Program Files\Common Files\Real
2008-07-07 12:57:15 0 d-------- C:\Documents and Settings\Customer\Application Data\iWin
2008-07-06 18:01:40 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-07-04 22:54:29 101 --a----c- C:\WINDOWS\popcinfo.dat
2008-07-04 14:57:36 0 d-------- C:\Documents and Settings\Customer\Application Data\Lavasoft
2008-07-01 12:53:18 0 d-------- C:\Program Files\iConferenceCL
2008-07-01 11:39:32 0 d-------- C:\Documents and Settings\Customer\Application Data\Mozilla
2008-06-29 17:02:10 0 d-------- C:\Documents and Settings\Customer\Application Data\Yahoo!
2008-06-28 15:18:51 0 d-------- C:\Documents and Settings\Customer\Application Data\Adobe
2008-06-27 21:14:21 0 d-------- C:\Documents and Settings\Customer\Application Data\iWinArcade
2008-06-27 18:18:35 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-27 13:02:26 0 d-------- C:\Program Files\Virtual Assistant
2008-06-27 13:01:04 0 d-------- C:\Program Files\Motive
2008-06-27 12:57:44 0 d-------- C:\Program Files\embarqtoolbar
2008-06-27 12:56:46 0 d-------- C:\Program Files\EMBARQ
2008-06-27 12:54:09 0 d-------- C:\Program Files\Common Files\Motive
2008-06-16 08:13:45 0 d-------- C:\Program Files\Atlantis Adventure
2008-06-02 10:44:01 0 d-------- C:\Program Files\Crystalize
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C}]
06/08/2007 06:13 PM 1897472 --a------ C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C}"= C:\PROGRA~1\EMBARQ~1\EMBARQ~1.DLL [06/08/2007 06:13 PM 1897472]
"{AB26BF6C-BB04-4F00-8F98-BDE786CDE97D}"= C:\WINDOWS\system32\EFOToolbar.dll [03/31/2008 12:16 AM 278528]
[-HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-92BE-BF2DFE9AAE2C}]
[HKEY_CLASSES_ROOT\embarqtoolbar.EMBARQTOOLBAR]
[-HKEY_CLASSES_ROOT\CLSID\{AB26BF6C-BB04-4F00-8F98-BDE786CDE97D}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{668611E3-7EC2-44EF-BF11-2D814E19FAA3}]
[HKEY_CLASSES_ROOT\EFOToolbar.EFOObj]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [04/21/2006 03:41 PM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/09/2008 12:11 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [05/27/2008 10:50 AM]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [06/12/2008 02:28 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"R-Firewall"="C:\Program Files\R-TT\R-Firewall\R-Firewall.exe" [03/02/2005 09:49 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 07:00 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07/07/2008 09:42 AM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/24/2005 1:05:26 AM]
EMBARQ Help.lnk - C:\Program Files\Virtual Assistant\bin\matcli.exe [6/27/2008 1:00:24 PM]
MozyHome Status.lnk - C:\Program Files\MozyHome\mozystat.exe [7/20/2008 5:32:22 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
"disableregistrytools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax DllCmd 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax DllCmd 4.0.lnk
backup=C:\WINDOWS\pss\eFax DllCmd 4.0.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 4.0.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax Tray Menu 4.0.lnk
backup=C:\WINDOWS\pss\eFax Tray Menu 4.0.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Customer^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Customer\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Customer^Start Menu^Programs^Startup^TypeItIn.lnk]
path=C:\Documents and Settings\Customer\Start Menu\Programs\Startup\TypeItIn.lnk
backup=C:\WINDOWS\pss\TypeItIn.lnkStartup
*Newly Created Service* - ADBLOCK.DLL
*Newly Created Service* - CONTENT.DLL
*Newly Created Service* - DNSCACHE.DLL
*Newly Created Service* - FTPFILT.DLL
*Newly Created Service* - HTMLFILT.DLL
*Newly Created Service* - HTTPFILT.DLL
*Newly Created Service* - IMAPFILT.DLL
*Newly Created Service* - MAILFILT.DLL
*Newly Created Service* - NNTPFILT.DLL
*Newly Created Service* - POP3FILT.DLL
*Newly Created Service* - PROTECT.DLL
*Newly Created Service* - RFW
*Newly Created Service* - RTT_CRC_SERVICE
-- End of Deckard's System Scanner: finished at 2008-07-28 12:13:36 ------------