....Continued from above
-- Files created between 2008-02-05 and 2008-03-05 -----------------------------
2008-03-05 10:06:00 0 d-------- C:\Program Files\Trend Micro
2008-03-04 19:35:27 352 --ah----- C:\Windows\nod32fixtemdono.reg
2008-03-03 20:34:42 0 d-------- C:\Users\Expert\temp
2008-03-03 20:24:16 0 d-------- C:\Program Files\Common Files\Steam
2008-03-03 20:24:12 0 d-------- C:\Program Files\Steam
2008-03-03 14:37:09 0 d-------- C:\Program Files\backups
2008-03-03 12:04:57 0 d-------- C:\Users\All Users\Malwarebytes
2008-02-25 18:52:48 0 d-------- C:\Program Files\Ventrilo
2008-02-24 12:33:57 0 d-------- C:\Program Files\WarRock
2008-02-24 11:27:21 0 d-------- C:\Users\All Users\InstallShield
2008-02-23 12:16:18 0 d-------- C:\Program Files\CCleaner
2008-02-23 11:47:20 135473184 --ahs---- C:\Windows\system32\drivers\fidbox.dat
2008-02-23 10:42:47 91492 --a------ C:\Windows\system32\drivers\klin.dat
2008-02-23 10:42:47 85860 --a------ C:\Windows\system32\drivers\klick.dat
2008-02-22 22:55:32 0 d-------- C:\c46bbcf4673eca1b725ec7b363
2008-02-21 17:09:56 0 d-------- C:\Users\All Users\Apple Computer
2008-02-21 17:09:10 0 d-------- C:\Program Files\Apple Software Update
2008-02-21 17:07:59 0 d-------- C:\Program Files\Common Files\Apple
2008-02-21 17:07:58 0 d-------- C:\Users\All Users\Apple
2008-02-20 23:32:36 0 d-------- C:\Programas
2008-02-20 23:18:21 0 d-------- C:\Users\All Users\ESET
2008-02-20 21:13:38 68096 --a------ C:\Windows\system32\zip.exe
2008-02-20 21:13:38 98816 --a------ C:\Windows\system32\sed.exe
2008-02-20 21:13:38 80412 --a------ C:\Windows\system32\grep.exe
2008-02-20 21:13:38 73728 --a------ C:\Windows\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-20 00:01:59 0 d-a------ C:\Users\All Users\TEMP
2008-02-19 23:30:24 0 d-------- C:\VundoFix Backups
2008-02-19 23:30:16 696 --a------ C:\Windows\system32\tmp.reg
2008-02-19 23:23:20 0 d-------- C:\Users\All Users\Simply Super Software
2008-02-19 23:02:50 85504 --a------ C:\Windows\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-02-19 22:47:13 0 d-------- C:\Program Files\Yahoo!
2008-02-19 22:43:33 25600 --a------ C:\Windows\system32\WS2Fix.exe
2008-02-19 22:43:33 289144 --a------ C:\Windows\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-02-19 22:43:33 288417 --a------ C:\Windows\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-02-19 22:43:33 53248 --a------ C:\Windows\system32\Process.exe <Not Verified;
http://www.beyondlogic.org; Command Line Process Utility>
2008-02-19 22:43:33 77824 --a------ C:\Windows\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-02-19 22:43:33 51200 --a------ C:\Windows\system32\dumphive.exe
2008-02-18 17:45:19 0 d-------- C:\GTK
2008-02-18 00:22:29 0 d-------- C:\Program Files\VentSrv
2008-02-17 23:00:41 0 d-------- C:\Users\Expert\.unlimitedftp
2008-02-10 10:29:36 0 d-------- C:\Program Files\GTASAConsole
2008-02-09 18:57:52 0 d-------- C:\Users\All Users\Kaspersky Lab Setup Files
2008-02-09 17:23:55 0 d-------- C:\Users\All Users\Grisoft
2008-02-08 23:15:59 0 d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-02-08 18:22:42 0 d-------- C:\AVG
2008-02-07 23:03:19 40 --a------ C:\Windows\system32\drmgs.sys
-- Find3M Report ---------------------------------------------------------------
2008-03-04 07:22:36 0 d--h----- C:\Users\Expert\AppData\Roaming\drivers4
2008-03-03 20:37:05 0 d-------- C:\Users\Expert\AppData\Roaming\TeamViewer
2008-03-03 20:24:16 0 d-------- C:\Program Files\Common Files
2008-03-03 13:40:45 0 d-------- C:\Users\Expert\AppData\Roaming\Xfire
2008-03-03 12:05:04 0 d-------- C:\Users\Expert\AppData\Roaming\Malwarebytes
2008-02-25 18:52:19 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 18:35:29 0 d-------- C:\Program Files\Xfire
2008-02-25 14:23:02 127426 --a------ C:\Users\Expert\AppData\Roaming\czr8lry.exe
2008-02-24 12:33:51 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-02-24 00:38:33 0 d-------- C:\Users\Expert\AppData\Roaming\InstallShield
2008-02-23 14:53:38 0 d-------- C:\Program Files\EA GAMES
2008-02-23 01:40:13 0 d-------- C:\Users\Expert\AppData\Roaming\Ventrilo
2008-02-21 19:36:57 0 d-------- C:\Program Files\Winamp
2008-02-21 17:32:42 0 d-------- C:\Users\Expert\AppData\Roaming\Opera
2008-02-21 17:12:12 0 d-------- C:\Users\Expert\AppData\Roaming\Apple Computer
2008-02-20 23:27:03 0 d-------- C:\Users\Expert\AppData\Roaming\ESET
2008-02-19 16:16:57 0 d-------- C:\Users\Expert\AppData\Roaming\SystemRequirements Lab
2008-02-17 16:22:26 0 d-------- C:\Program Files\Microsoft Games
2008-02-16 16:25:03 0 d-------- C:\Program Files\Teamspeak2_RC2
2008-02-16 16:10:23 0 d-------- C:\Program Files\VideoLAN
2008-02-16 15:40:31 0 d-------- C:\Users\Expert\AppData\Roaming\GlobalSCAPE
2008-02-16 15:15:50 0 d-------- C:\Users\Expert\AppData\Roaming\teamspeak2
2008-02-11 16:36:25 0 d-------- C:\Program Files\Common Files\Adobe
2008-02-10 23:42:15 0 d-------- C:\Users\Expert\AppData\Roaming\Screaming Bee
2008-02-09 17:37:39 0 d-------- C:\Users\Expert\AppData\Roaming\Adobe
2008-02-07 10:07:48 98304 --a------ C:\Windows\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2008-02-04 16:35:23 0 d-------- C:\Program Files\Electronic Arts
2008-02-04 16:09:38 0 d-------- C:\Users\Expert\AppData\Roaming\Atari
2008-02-03 11:18:28 0 d-------- C:\Users\Expert\AppData\Roaming\Winamp
2008-02-02 12:46:12 0 d-------- C:\Program Files\Grand Theft Auto
2008-02-02 12:17:13 0 d-------- C:\Program Files\Asprate
2008-01-27 10:46:51 0 d-------- C:\Program Files\Microsoft Works
2008-01-27 10:46:03 0 d-------- C:\Program Files\MSBuild
2008-01-27 10:36:32 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-01-26 19:43:16 25575 --a------ C:\Users\Expert\AppData\Roaming\UserTile.png
2008-01-26 19:43:14 0 d-------- C:\Users\Expert\AppData\Roaming\PeerNetworking
2008-01-25 23:14:01 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-25 23:06:09 0 d-------- C:\Program Files\Windows Live
2008-01-24 23:46:58 174 --ahs---- C:\Program Files\desktop.ini
2008-01-24 23:44:25 0 d-------- C:\Program Files\Windows Calendar
2008-01-24 23:44:24 0 d-------- C:\Program Files\Windows Mail
2008-01-24 23:44:23 0 d-------- C:\Program Files\Windows Defender
2008-01-24 23:41:55 24194 ---h----- C:\Users\Expert\AppData\Roaming\addon.dat
2008-01-24 23:11:39 0 d-------- C:\Program Files\Windows Sidebar
2008-01-24 22:39:33 22668 --a------ C:\Windows\system32\emptyregdb.dat
2008-01-24 22:29:05 0 d-------- C:\Users\Expert\AppData\Roaming\Xfire Plus
2008-01-24 22:29:02 0 d-------- C:\Users\Expert\AppData\Roaming\Sun
2008-01-24 22:29:02 0 d-------- C:\Users\Expert\AppData\Roaming\SmartFTP
2008-01-24 22:29:02 0 dr-h----- C:\Users\Expert\AppData\Roaming\SecuROM
2008-01-24 22:29:02 0 d-------- C:\Users\Expert\AppData\Roaming\NCH Swift Sound
2008-01-24 22:29:01 0 d-------- C:\Users\Expert\AppData\Roaming\Mozilla
2008-01-24 22:28:57 0 d-------- C:\Users\Expert\AppData\Roaming\Macromedia
2008-01-24 22:28:57 0 d-------- C:\Users\Expert\AppData\Roaming\Leadertech
2008-01-24 22:28:57 0 d-------- C:\Users\Expert\AppData\Roaming\Identities
2008-01-24 22:28:57 0 d-------- C:\Users\Expert\AppData\Roaming\Google
2008-01-24 22:28:53 0 d-------- C:\Users\Expert\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2008-01-24 22:28:24 0 d-------- C:\Users\Expert\AppData\Roaming\ATI
2008-01-24 22:22:00 0 d-------- C:\Program Files\Windows Live Safety Center
2008-01-24 22:21:58 0 d-------- C:\Program Files\Winamp Remote
2008-01-24 22:21:37 0 d-------- C:\Program Files\VIAudioi
2008-01-24 22:21:36 0 d-------- C:\Program Files\VIA
2008-01-24 22:21:33 0 d-------- C:\Program Files\TheWeatherNetwork
2008-01-24 22:21:29 0 d-------- C:\Program Files\Silkroad
2008-01-24 22:21:26 0 d-------- C:\Program Files\PowerISO
2008-01-24 22:21:25 0 d-------- C:\Program Files\MSXML 6.0
2008-01-24 22:21:25 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-24 22:21:21 0 d-------- C:\Program Files\Microsoft.NET
2008-01-24 22:10:36 0 d-------- C:\Program Files\Messenger Plus! Live
2008-01-24 22:10:35 0 d-------- C:\Program Files\Logitech
2008-01-24 22:10:26 0 d-------- C:\Program Files\Java
2008-01-24 22:10:09 0 d-------- C:\Program Files\Google
2008-01-24 22:10:08 0 d-------- C:\Program Files\FinalAlert 2 Yuri's Revenge
2008-01-24 22:08:21 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-24 22:08:21 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-24 22:08:16 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-01-24 22:08:16 0 d-------- C:\Program Files\Common Files\Logitech
2008-01-24 22:08:16 0 d-------- C:\Program Files\Common Files\Java
2008-01-24 22:08:15 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-24 22:00:51 0 d-------- C:\Program Files\ATI Technologies
2008-01-24 21:55:30 0 d-------- C:\Program Files\Ares
2008-01-24 21:55:29 0 d-------- C:\Program Files\AGEIA Technologies
2008-01-22 19:50:34 4096 --a------ C:\Windows\system32\crash
2008-01-03 03:35:09 3314 --a------ C:\Windows\system32\adobeupdate
2007-12-30 13:21:01 1324 --a------ C:\Windows\system32\d3d9caps.dat
2007-12-30 13:20:59 1100 --a------ C:\Windows\system32\d3d8caps.dat
2007-12-20 22:12:50 1749 --a------ C:\Windows\mozver.dat
2007-12-08 11:29:28 0 --a------ C:\Windows\nsreg.dat
2007-12-06 21:15:45 0 -rahs---- C:\MSDOS.SYS
2007-12-06 21:15:45 0 -rahs---- C:\IO.SYS
2007-12-05 14:17:00 593920 --a------ C:\Windows\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"WxEx"="" []
"MSConfig"="C:\Windows\system32\msconfig.exe" [11/02/2006 04:45 AM]
"RegistryMechanic"="" []
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [12/21/2007 08:21 AM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:34 AM]
"Steam"="c:\program files\steam\steam.exe" [03/03/2008 08:24 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\r3h ook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dl l,
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\AppInfo]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\KeyIso]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\NTDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\ProfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\SWPRV]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TabletInputService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TBS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\TrustedInstaller]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\VDS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\volmgr.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\volmgrx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"ATI Smart"=2 (0x2)
"idsvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc
WudfServiceGroup WUDFSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
-- End of Deckard's System Scanner: finished at 2008-03-05 10:08:36 ------------