cool...heres the winpfind3u log:
WinPFind3 logfile created on: 11/15/2007 12:33:17 PM
WinPFind3U by OldTimer - Version 1.0.42 Folder = C:\Documents and Settings\scott\Desktop\winpfind3u\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.11)
511.53 Mb Total Physical Memory | 136.70 Mb Available Physical Memory | 26.72% Memory free
1.22 Gb Paging File | 0.89 Gb Available in Paging File | 72.83% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 21.59 Gb Free Space | 28.97% Space Free
Drive D: | 28.62 Gb Total Space | 1.37 Gb Free Space | 4.78% Space Free
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Computer Name: CARLOS
Current User Name: scott
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 6.0\Distillr\acrotray.exe -> Adobe Systems Inc. [Ver = 6.0.0.2003051500 | Size = 217193 bytes | Modified Date = 5/15/2003 1:19:50 AM | Attr = ]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 1:28:18 PM | Attr = ]
cdantsrv.exe -> %System32%\drivers\CDANTSRV.EXE -> C-Dilla Ltd [Ver = 3.27.000 | Size = 46080 bytes | Modified Date = 1/7/2003 5:28:44 PM | Attr = ]
ctnotify.exe -> %ProgramFiles%\Creative\ShareDLL\CTNotify.exe -> Creative Technology Ltd. [Ver = 2.00.02.0 | Size = 191488 bytes | Modified Date = 8/1/2001 2:00:00 AM | Attr = ]
ctsvccda.exe -> %System32%\CTSVCCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 1:01:00 AM | Attr = ]
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 1.8.1.9: 2007102514 | Size = 7649128 bytes | Modified Date = 11/4/2007 3:27:18 PM | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 6:31:10 AM | Attr = ]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 503608 bytes | Modified Date = 9/26/2007 2:41:56 PM | Attr = ]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 267064 bytes | Modified Date = 9/26/2007 2:42:04 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 3/14/2007 2:43:44 AM | Attr = ]
lexbces.exe -> %System32%\LexBceS.exe -> Lexmark International, Inc. [Ver = 5,11,00,00 | Size = 278016 bytes | Modified Date = 8/16/2000 1:13:54 PM | Attr = ]
lexpps.exe -> %System32%\Lexpps.exe -> Lexmark International, Inc. [Ver = 5,11,00,00 | Size = 169984 bytes | Modified Date = 8/16/2000 1:10:26 PM | Attr = ]
mediadet.exe -> %ProgramFiles%\Creative\ShareDLL\Mediadet.exe -> Creative Technology Ltd. [Ver = 2.00.02.0 | Size = 166912 bytes | Modified Date = 8/1/2001 2:00:00 AM | Attr = ]
nintendowfcreg.exe -> %ProgramFiles%\WiFiConnector\NintendoWFCReg.exe -> [Ver = 1, 0, 0, 33 | Size = 1073152 bytes | Modified Date = 4/20/2006 11:45:34 AM | Attr = ]
nvsvc32.exe -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.4523 | Size = 77824 bytes | Modified Date = 7/28/2003 2:19:00 PM | Attr = ]
printray.exe -> %System32%\spool\drivers\w32x86\2\printray.exe -> Lexmark [Ver = 1, 0, 0, 5 | Size = 36864 bytes | Modified Date = 8/16/2000 1:08:16 PM | Attr = ]
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3760 | Size = 185896 bytes | Modified Date = 10/22/2006 11:12:02 AM | Attr = ]
samjlpcv.exe -> %System32%\samjlpcv.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Modified Date = 11/14/2007 11:57:30 AM | Attr = ]
shell.exe -> %SystemRoot%\shell.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/12/2005 11:17:44 PM | Attr = ]
viewmgr.exe -> %ProgramFiles%\Viewpoint\Viewpoint Manager\ViewMgr.exe -> Viewpoint Corporation [Ver = 2, 0, 0, 54 | Size = 112336 bytes | Modified Date = 1/4/2007 3:38:20 PM | Attr = ]
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> Viewpoint Corporation [Ver = 2, 0, 0, 54 | Size = 24652 bytes | Modified Date = 1/4/2007 3:38:10 PM | Attr = ]
vundofix.exe -> %UserDocuments%\downloads\VundoFix.exe -> Atribune.org [Ver = 6.06.0001 | Size = 117248 bytes | Modified Date = 11/15/2007 11:28:02 AM | Attr = ]
winpfind3u.exe -> %UserDesktop%\winpfind3u\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.42.0 | Size = 322560 bytes | Modified Date = 9/4/2007 10:47:26 AM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 1:28:18 PM | Attr = ]
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -> [Ver = | Size = 32768 bytes | Modified Date = 7/15/2004 1:49:26 AM | Attr = ]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 6:31:10 AM | Attr = ]
(C-DillaSrv) C-DillaSrv [Win32_Own | Auto | Running] -> %System32%\drivers\CDANTSRV.EXE -> C-Dilla Ltd [Ver = 3.27.000 | Size = 46080 bytes | Modified Date = 1/7/2003 5:28:44 PM | Attr = ]
(Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %System32%\CTSVCCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/13/1999 1:01:00 AM | Attr = ]
(DefWatch) DefWatch [Win32_Own | Auto | Stopped] -> %ProgramFiles%\NavNT\defwatch.exe -> File not found
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 1:56:48 AM | Attr = ]
(DomainService) DomainService [Win32_Own | Auto | Running] -> %System32%\samjlpcv.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Modified Date = 11/14/2007 11:57:30 AM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 503608 bytes | Modified Date = 9/26/2007 2:41:56 PM | Attr = ]
(LexBceS) LexBce Server [Win32_Own | Auto | Running] -> %System32%\LexBceS.exe -> Lexmark International, Inc. [Ver = 5,11,00,00 | Size = 278016 bytes | Modified Date = 8/16/2000 1:13:54 PM | Attr = ]
(Macromedia Licensing Service) Macromedia Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macromedia Shared\Service\Macromedia Licensing.exe -> [Ver = 2.42.000 | Size = 68096 bytes | Modified Date = 2/11/2005 1:19:00 PM | Attr = ]
(Norton AntiVirus Server) Norton AntiVirus Client [Win32_Own | Auto | Stopped] -> %ProgramFiles%\NavNT\rtvscan.exe -> File not found
(NVSvc) NVIDIA Driver Helper Service [Win32_Own | Auto | Running] -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.4523 | Size = 77824 bytes | Modified Date = 7/28/2003 2:19:00 PM | Attr = ]
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> Viewpoint Corporation [Ver = 2, 0, 0, 54 | Size = 24652 bytes | Modified Date = 1/4/2007 3:38:10 PM | Attr = ]
(wscsvc) Security Center [Win32_Shared | Auto | Stopped] -> C:\WINDOWS\%System32%\svchost.exe -> File not found
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
24941ad8 -> %System32%\yhyqsbje.dll [rundll32.exe "C:\WINDOWS\system32\yhyqsbje.dll",b] -> [Ver = | Size = 85056 bytes | Modified Date = 11/15/2007 12:29:38 PM | Attr = ]
avp -> %SystemRoot%\TEMP\win187.exe -> File not found
CTStartup -> %ProgramFiles%\Creative\Splash Screen\CTEaxSpl.exe -> Creative Technology Ltd. [Ver = 1, 1, 0, 0 | Size = 28672 bytes | Modified Date = 9/14/2001 11:10:00 AM | Attr = ]
Disc Detector -> %ProgramFiles%\Creative\ShareDLL\CTNotify.exe -> Creative Technology Ltd. [Ver = 2.00.02.0 | Size = 191488 bytes | Modified Date = 8/1/2001 2:00:00 AM | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 267064 bytes | Modified Date = 9/26/2007 2:42:04 PM | Attr = ]
Jet Detection -> %ProgramFiles%\Creative\SBAudigy\Program\ADGJDet.exe -> [Ver = 1, 0, 0, 0 | Size = 28672 bytes | Modified Date = 4/20/2001 2:52:40 PM | Attr = ]
nwiz -> %System32%\nwiz.exe -> NVIDIA Corporation [Ver = 6.14.10.4523 | Size = 323584 bytes | Modified Date = 7/28/2003 2:19:00 PM | Attr = ]
POINTER -> point32.exe -> File not found
Printer -> %System32%\printer.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/20/2005 10:34:02 AM | Attr = ]
PrinTray -> %System32%\spool\drivers\w32x86\2\printray.exe -> Lexmark [Ver = 1, 0, 0, 5 | Size = 36864 bytes | Modified Date = 8/16/2000 1:08:16 PM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 6/29/2007 6:24:52 AM | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_01\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 83608 bytes | Modified Date = 3/14/2007 2:43:44 AM | Attr = ]
TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3760 | Size = 185896 bytes | Modified Date = 10/22/2006 11:12:02 AM | Attr = ]
UpdReg -> %SystemRoot%\Updreg.exe -> Creative Technology Ltd. [Ver = 1.0.2 | Size = 90112 bytes | Modified Date = 5/11/2000 1:00:00 AM | Attr = ]
vptray -> %ProgramFiles%\NavNT\vptray.exe -> File not found
wpqpmnaj -> Files\wpqpmnaj\cnazyjwd.DLL [rundll32.exe "%ProgramFiles%\wpqpmnaj\cnazyjwd.dll",Init] -> File not found
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Aim6 -> %ProgramFiles%\AIM6\aim6.exe -> AOL LLC [Ver = 1.4.9.1 | Size = 50528 bytes | Modified Date = 10/4/2007 9:20:56 AM | Attr = ]
Spoolsv -> %System32%\spoolvs.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/20/2005 10:34:02 AM | Attr = ]
Steam -> %ProgramFiles%\Steam\Steam.exe -> Valve Corporation [Ver = 1.0.0.0 | Size = 1271032 bytes | Modified Date = 11/14/2007 8:39:08 PM | Attr = ]
Taen -> %SystemRoot%\MBOLS~1\dllhost.exe -> File not found
Windows update loader -> %SystemRoot%\xpupdate.exe -> File not found
< Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersStartup%\Acrobat Assistant.lnk -> %ProgramFiles%\Adobe\Acrobat 6.0\Distillr\acrotray.exe -> Adobe Systems Inc. [Ver = 6.0.0.2003051500 | Size = 217193 bytes | Modified Date = 5/15/2003 1:19:50 AM | Attr = ]
%AllUsersStartup%\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Modified Date = 9/23/2005 10:05:26 PM | Attr = ]
-> %AllUsersStartup%\autorun.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/20/2005 10:34:02 AM | Attr = ]
%AllUsersStartup%\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk -> %ProgramFiles%\WiFiConnector\NintendoWFCReg.exe -> [Ver = 1, 0, 0, 33 | Size = 1073152 bytes | Modified Date = 4/20/2006 11:45:34 AM | Attr = ]
< User Startup > -> C:\Documents and Settings\scott\Start Menu\Programs\Startup ->
-> %UserStartup%\findfast.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/20/2005 10:34:02 AM | Attr = ]
< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
wbsys.dll -> %System32%\wbsys.dll -> Stardock.Net, Inc [Ver = 4, 0, 0, 0 | Size = 36864 bytes | Modified Date = 2/26/2003 9:27:44 PM | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 6:29:58 AM | Attr = ]
{837B45D6-BF85-457D-AABF-6D2E7815F791} [HKLM] -> Reg Data - Key not found [] -> File not found
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
xlibgfl254.dll -> xlibgfl254.dll -> File not found
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
C:\WINDOWS\shell.exe -> %SystemRoot%\shell.exe -> [Ver = | Size = 9728 bytes | Modified Date = 3/12/2005 11:17:44 PM | Attr = ]
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
NavLogon -> %System32%\NavLogon.dll -> [Ver = | Size = 45056 bytes | Modified Date = 9/24/2001 7:59:00 AM | Attr = ]
WBSrv -> %ProgramFiles%\Stardock\Object Desktop\WindowBlinds\WbSrv.dll -> Stardock [Ver = 5, 0, 0, 1 | Size = 176128 bytes | Modified Date = 12/6/2005 9:16:30 PM | Attr = ]
winrge32 -> %System32%\winrge32.dll -> [Ver = | Size = 20480 bytes | Modified Date = 11/11/2007 8:30:40 PM | Attr = ]
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableTaskMgr -> 1 ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> _
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoControlPanel -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
< HOSTS File > -> ->
-> Hosts file not found ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL ->
http://www.microsoft...p...&ar=msnhome ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> C:\windows\system32\blank.htm ->
HKLM: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Start Page ->
http://www.microsoft...p...ER}&ar=home ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: Search\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Local Page -> C:\windows\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page ->
http://www.microsoft...p...&ar=msnhome ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 59032 bytes | Modified Date = 12/18/2006 4:16:42 AM | Attr = ]
{200D0AAD-71B1-51C9-DDB0-092BA4662A54} [HKLM] -> %ProgramFiles%\Rqdetcoa\fkywyibl.dll [Reg Data - Value does not exist] -> [Ver = | Size = 114688 bytes | Modified Date = 11/13/2007 1:22:14 AM | Attr = ]
{261C35B4-9283-6344-C5C0-005CF873D624} [HKLM] -> %ProgramFiles%\Gkclneuw\fxucqnrd.dll [Reg Data - Value does not exist] -> [Ver = | Size = 114688 bytes | Modified Date = 11/11/2007 8:30:54 PM | Attr = ]
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 3, 0, 12 | Size = 744960 bytes | Modified Date = 5/12/2004 12:03:00 AM | Attr = ]
{7432bac8-7048-4f5b-9c42-51fd3a2dff40} [HKLM] -> %System32%\nowcgfih.dll [Reg Data - Value does not exist] -> [Ver = | Size = 79936 bytes | Modified Date = 11/15/2007 12:29:44 PM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 2:43:40 AM | Attr = ]
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{A7327C09-B521-4EDB-8509-7D2660C9EC98} [HKLM] -> %ProgramFiles%\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll [Viewpoint Toolbar BHO] -> Viewpoint Corporation [Ver = 3, 8, 0, 29 | Size = 38584 bytes | Modified Date = 2/24/2007 1:33:52 PM | Attr = ]
{AE7CD045-E861-484f-8273-0445EE161910} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [AcroIEToolbarHelper Class] -> [Ver = | Size = 147456 bytes | Modified Date = 5/15/2003 1:03:46 AM | Attr = ]
{CBF5B0F7-FDD2-4C06-8A77-53BC1B7EB69B} [HKLM] -> %System32%\awtss.dll [Reg Data - Value does not exist] -> [Ver = | Size = 319584 bytes | Modified Date = 11/11/2007 8:36:16 PM | Attr = ]
{F10587E9-0E47-4CBE-84AE-7DD20B8684BB} [HKLM] -> %ProgramFiles%\E404 Helper\e404.v4.dll [e404mgr Class] -> [Ver = 1, 0, 0, 1 | Size = 17920 bytes | Modified Date = 11/12/2007 7:33:22 AM | Attr = ]
< Internet Explorer Bars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{182EC0BE-5110-49C8-A062-BEB1D02A220B} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 5/15/2003 1:03:46 AM | Attr = ]
< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{11A69AE4-FBED-4832-A2BF-45AF82825583} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 5/15/2003 1:03:46 AM | Attr = ]
{F8AD5AA5-D966-4667-9DAF-2561D68B2012} [HKLM] -> %CommonProgramFiles%\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll [Viewpoint Toolbar] -> Viewpoint Corporation [Ver = 3, 8, 0, 29 | Size = 333472 bytes | Modified Date = 2/24/2007 1:33:40 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 5/15/2003 1:03:46 AM | Attr = ]
WebBrowser\\{11A69AE4-FBED-4832-A2BF-45AF82825583} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [Ver = | Size = 147456 bytes | Modified Date = 5/15/2003 1:03:46 AM | Attr = ]
WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 3/14/2007 2:43:42 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 2:43:40 AM | Attr = ]
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -> %ProgramFiles%\AIM\aim.exe [ButtonText: AIM] -> America Online, Inc. [Ver = 5.9.6089 | Size = 67112 bytes | Modified Date = 8/1/2006 2:35:36 PM | Attr = ]
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
{F4430FE8-2638-42e5-B849-800749B94EED} -> %ProgramFiles%\PartyPoker.net\partypokernet.exe [ButtonText: PartyPoker.net] -> File not found
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{19350190-B42D-4436-A09D-CCD6EBCBA02E} -> (1394 Net Adapter) ->
{2CC22759-1140-44F9-AB80-3B2BC8FBEC32} -> (Nintendo Wi-Fi USB Connector) ->
{8572293F-E8D6-4225-99D0-A1E9AD4E7518} -> (HP NetServer 10/100TX PCI LAN Adapter) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{01010E00-5E80-11D8-9E86-0007E96C65AE} -> SupportSoft SmartIssue - CodeBase =
http://www.symantec....trl/tgctlsi.cab ->
{01012101-5E80-11D8-9E86-0007E96C65AE} -> SupportSoft Script Runner Class - CodeBase =
http://www.symantec....trl/tgctlsr.cab ->
{14B87622-7E19-4EA8-93B3-97215F77A6BC} -> MessengerStatsClient Class - CodeBase =
http://messenger.zon...nt.cab31267.cab ->
{1F2F4C9E-6F09-47BC-970D-3C54734667FE} -> - CodeBase =
http://www.symantec....rl/LSSupCtl.cab ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} -> MSN Photo Upload Tool - CodeBase =
http://gfx2.mail.liv...es/MSNPUpld.cab ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase =
http://update.micros...b?1122278741803 ->
{7B297BFD-85E4-4092-B2AF-16A91B2EA103} -> WScanCtl Class - CodeBase =
http://www3.ca.com/s...nfo/webscan.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -> MessengerStatsClient Class - CodeBase =
http://messenger.zon...nt.cab31267.cab ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -> ActiveScan Installer Class - CodeBase =
http://acs.pandasoft...free/asinst.cab ->
{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} -> Java Plug-in 1.5.0 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_02 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_09 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_10 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_11 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -> - CodeBase =
http://www.symantec....rl/SymAData.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase =
http://download.macr...ash/swflash.cab ->
[Registry - Additional Scans - Non-Microsoft Only]
[Files/Folders - Created Within 30 days]
!KillBox -> %SystemDrive%\!KillBox -> [Folder | Created Date = 11/11/2007 10:59:05 PM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 536449024 bytes | Created Date = 1/1/1601 6:00:00 AM | Attr = HS]
VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Created Date = 11/15/2007 11:28:31 AM | Attr = ]
$NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Created Date = 11/15/2007 11:27:33 AM | Attr = H ]
Casino.ico -> %SystemRoot%\Casino.ico -> [Ver = | Size = 2238 bytes | Created Date = 11/14/2007 12:04:22 PM | Attr = ]
cookies.ini -> %SystemRoot%\cookies.ini -> [Ver = | Size = 366 bytes | Created Date = 11/12/2007 12:43:54 PM | Attr = ]
Free Online Dating.ico -> %SystemRoot%\Free Online Dating.ico -> [Ver = | Size = 1150 bytes | Created Date = 11/14/2007 12:04:21 PM | Attr = ]
mgrs.exe -> %SystemRoot%\mgrs.exe -> [Ver = | Size = 11776 bytes | Created Date = 11/14/2007 12:05:16 PM | Attr = ]
nview -> %SystemRoot%\nview -> [Folder | Created Date = 10/18/2007 4:02:10 AM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 11/4/2007 1:46:38 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 11/4/2007 1:46:38 PM | Attr = H ]
shell.exe -> %SystemRoot%\shell.exe -> [Ver = | Size = 9728 bytes | Created Date = 11/15/2007 12:33:41 AM | Attr = ]
Spyware Remover.ico -> %SystemRoot%\Spyware Remover.ico -> [Ver = | Size = 4846 bytes | Created Date = 11/14/2007 12:04:20 PM | Attr = ]
wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 104 bytes | Created Date = 11/12/2007 8:00:29 AM | Attr = ]
??mbols -> %SystemRoot%\??mbols -> [Folder | Created Date = 7/5/1763 4:33:13 PM | Attr = ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Created Date = 11/15/2007 12:44:35 AM | Attr = ]
agkrdsde.dll -> %System32%\agkrdsde.dll -> [Ver = | Size = 85056 bytes | Created Date = 11/14/2007 12:02:59 PM | Attr = ]
asuninst.exe -> %System32%\asuninst.exe -> Panda Software [Ver = 1, 0, 0, 2 | Size = 73728 bytes | Created Date = 11/15/2007 12:45:16 AM | Attr = ]
awtss.dll -> %System32%\awtss.dll -> [Ver = | Size = 319584 bytes | Created Date = 11/11/2007 8:36:14 PM | Attr = ]
bfeguufo -> %System32%\bfeguufo -> [Folder | Created Date = 11/11/2007 8:30:58 PM | Attr = ]
dumphive.exe -> %System32%\dumphive.exe -> [Ver = | Size = 51200 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
edsdrkga.ini -> %System32%\edsdrkga.ini -> [Ver = | Size = 669330 bytes | Created Date = 11/14/2007 12:03:11 PM | Attr = HS]
ejbsqyhy.ini -> %System32%\ejbsqyhy.ini -> [Ver = | Size = 669390 bytes | Created Date = 11/15/2007 12:29:38 PM | Attr = HS]
fcijytnp.ini -> %System32%\fcijytnp.ini -> [Ver = | Size = 590425 bytes | Created Date = 11/12/2007 12:35:13 PM | Attr = HS]
fibagbia -> %System32%\fibagbia -> [Folder | Created Date = 11/12/2007 12:23:43 PM | Attr = ]
gtmxrine.dll -> %System32%\gtmxrine.dll -> [Ver = | Size = 79424 bytes | Created Date = 11/14/2007 12:03:06 PM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Created Date = 11/15/2007 12:44:44 AM | Attr = ]
jogljkxy.dllbox -> %System32%\jogljkxy.dllbox -> [Ver = | Size = 20768 bytes | Created Date = 11/12/2007 12:24:22 PM | Attr = HS]
kohifqdl.exe -> %System32%\kohifqdl.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Created Date = 11/15/2007 12:24:03 PM | Attr = ]
nowcgfih.dll -> %System32%\nowcgfih.dll -> [Ver = | Size = 79936 bytes | Created Date = 11/15/2007 12:29:41 PM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Created Date = 11/15/2007 12:44:41 AM | Attr = ]
pntyjicf.dll -> %System32%\pntyjicf.dll -> [Ver = | Size = 89664 bytes | Created Date = 11/12/2007 12:35:02 PM | Attr = ]
printer.exe -> %System32%\printer.exe -> [Ver = | Size = 9728 bytes | Created Date = 11/14/2007 12:11:02 PM | Attr = ]
Process.exe -> %System32%\Process.exe ->
http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
samjlpcv.exe -> %System32%\samjlpcv.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Created Date = 11/14/2007 11:57:29 AM | Attr = ]
skwhaofo.exe -> %System32%\skwhaofo.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Created Date = 11/12/2007 12:26:02 PM | Attr = ]
spoolvs.exe -> %System32%\spoolvs.exe -> [Ver = | Size = 9728 bytes | Created Date = 11/14/2007 12:11:03 PM | Attr = ]
SrchSTS.exe -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
sstwa.bak1 -> %System32%\sstwa.bak1 -> [Ver = | Size = 6465 bytes | Created Date = 11/11/2007 8:40:55 PM | Attr = HS]
sstwa.bak2 -> %System32%\sstwa.bak2 -> [Ver = | Size = 441114 bytes | Created Date = 11/11/2007 10:43:10 PM | Attr = HS]
sstwa.ini -> %System32%\sstwa.ini -> [Ver = | Size = 437905 bytes | Created Date = 11/11/2007 8:36:33 PM | Attr = HS]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 3168 bytes | Created Date = 11/12/2007 12:41:42 PM | Attr = ]
ttvwa.ini -> %System32%\ttvwa.ini -> [Ver = | Size = 353 bytes | Created Date = 11/11/2007 8:36:44 PM | Attr = HS]
twepokio.dll -> %System32%\twepokio.dll -> [Ver = | Size = 81472 bytes | Created Date = 11/12/2007 12:38:02 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Created Date = 11/15/2007 12:44:44 AM | Attr = ]
VCCLSID.exe -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
winrge32.dll -> %System32%\winrge32.dll -> [Ver = | Size = 20480 bytes | Created Date = 11/11/2007 8:30:38 PM | Attr = ]
WS2Fix.exe -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Created Date = 11/13/2007 1:06:03 AM | Attr = ]
yhyqsbje.dll -> %System32%\yhyqsbje.dll -> [Ver = | Size = 85056 bytes | Created Date = 11/15/2007 12:29:37 PM | Attr = ]
ZPORT4AS.dll -> %System32%\ZPORT4AS.dll -> [Ver = | Size = 11776 bytes | Created Date = 11/15/2007 12:45:16 AM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Created Date = 11/13/2007 1:37:08 AM | Attr = ]
[Files/Folders - Modified Within 30 days]
!KillBox -> %SystemDrive%\!KillBox -> [Folder | Modified Date = 11/11/2007 10:59:06 PM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 11/4/2007 3:31:16 PM | Attr = HS]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 536449024 bytes | Modified Date = 11/15/2007 12:13:08 PM | Attr = HS]
IPH.PH -> %SystemDrive%\IPH.PH -> [Ver = | Size = 1973 bytes | Modified Date = 11/2/2007 2:24:02 AM | Attr = H ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 11/15/2007 1:17:04 AM | Attr = ]
VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Modified Date = 11/15/2007 11:51:58 AM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 11/15/2007 12:23:30 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 11/15/2007 11:26:40 AM | Attr = H ]
$NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Modified Date = 11/15/2007 11:27:36 AM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 11/15/2007 12:13:10 PM | Attr = S]
Casino.ico -> %SystemRoot%\Casino.ico -> [Ver = | Size = 2238 bytes | Modified Date = 11/14/2007 12:04:24 PM | Attr = ]
cookies.ini -> %SystemRoot%\cookies.ini -> [Ver = | Size = 366 bytes | Modified Date = 11/14/2007 12:06:52 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 11/15/2007 12:44:40 AM | Attr = S]
Free Online Dating.ico -> %SystemRoot%\Free Online Dating.ico -> [Ver = | Size = 1150 bytes | Modified Date = 11/14/2007 12:04:22 PM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 10/18/2007 4:02:12 AM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 11/15/2007 11:27:48 AM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 11/4/2007 3:27:58 PM | Attr = HS]
mgrs.exe -> %SystemRoot%\mgrs.exe -> [Ver = | Size = 11776 bytes | Modified Date = 11/14/2007 12:05:18 PM | Attr = ]
nview -> %SystemRoot%\nview -> [Folder | Modified Date = 10/18/2007 4:02:12 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 11/15/2007 12:30:28 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 11/4/2007 1:46:40 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 11/15/2007 12:24:08 PM | Attr = H ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 11/11/2007 10:40:30 PM | Attr = ]
Spyware Remover.ico -> %SystemRoot%\Spyware Remover.ico -> [Ver = | Size = 4846 bytes | Modified Date = 11/14/2007 12:04:22 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 11/15/2007 12:33:28 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 11/4/2007 1:38:10 PM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 11/15/2007 12:26:04 PM | Attr = ]
wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 104 bytes | Modified Date = 11/12/2007 8:00:30 AM | Attr = ]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 11/4/2007 1:40:34 PM | Attr = ]
??mbols -> %SystemRoot%\??mbols -> [Folder | Modified Date = 11/14/2007 8:35:52 PM | Attr = ]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 11/7/2007 5:14:02 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 11/15/2007 12:13:20 PM | Attr = H ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Modified Date = 11/15/2007 12:45:48 AM | Attr = ]
agkrdsde.dll -> %System32%\agkrdsde.dll -> [Ver = | Size = 85056 bytes | Modified Date = 11/14/2007 12:03:00 PM | Attr = ]
awtss.dll -> %System32%\awtss.dll -> [Ver = | Size = 319584 bytes | Modified Date = 11/11/2007 8:36:16 PM | Attr = ]
bfeguufo -> %System32%\bfeguufo -> [Folder | Modified Date = 11/11/2007 10:40:16 PM | Attr = ]
BMXBkpCtrlState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> %System32%\BMXBkpCtrlState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> [Ver = | Size = 23196 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
BMXCtrlState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> %System32%\BMXCtrlState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> [Ver = | Size = 23196 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
BMXState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> %System32%\BMXState-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> [Ver = | Size = 18560 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
BMXStateBkp-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> %System32%\BMXStateBkp-{00000000-00000000-0000000B-00001102-00000004-00531102}.rfx -> [Ver = | Size = 18560 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 11/15/2007 11:26:34 AM | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 11/11/2007 10:40:46 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 11/15/2007 11:49:36 AM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 11/13/2007 1:37:10 AM | Attr = ]
DRVSTORE -> %System32%\DRVSTORE -> [Folder | Modified Date = 11/4/2007 1:40:52 PM | Attr = ]
DVCState-{00000000-00000000-0000000B-00001102-00000004-00531102}.dat -> %System32%\DVCState-{00000000-00000000-0000000B-00001102-00000004-00531102}.dat -> [Ver = | Size = 24 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-00531102}.dat -> %System32%\DVCStateBkp-{00000000-00000000-0000000B-00001102-00000004-00531102}.dat -> [Ver = | Size = 24 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
edsdrkga.ini -> %System32%\edsdrkga.ini -> [Ver = | Size = 669330 bytes | Modified Date = 11/15/2007 12:24:24 PM | Attr = HS]
ejbsqyhy.ini -> %System32%\ejbsqyhy.ini -> [Ver = | Size = 669390 bytes | Modified Date = 11/15/2007 12:29:56 PM | Attr = HS]
fcijytnp.ini -> %System32%\fcijytnp.ini -> [Ver = | Size = 590425 bytes | Modified Date = 11/12/2007 1:01:10 PM | Attr = HS]
fibagbia -> %System32%\fibagbia -> [Folder | Modified Date = 11/12/2007 12:23:52 PM | Attr = ]
gtmxrine.dll -> %System32%\gtmxrine.dll -> [Ver = | Size = 79424 bytes | Modified Date = 11/14/2007 12:03:08 PM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 11/15/2007 12:44:46 AM | Attr = ]
jogljkxy.dllbox -> %System32%\jogljkxy.dllbox -> [Ver = | Size = 20768 bytes | Modified Date = 11/15/2007 11:48:28 AM | Attr = HS]
kohifqdl.exe -> %System32%\kohifqdl.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Modified Date = 11/15/2007 12:24:04 PM | Attr = ]
nowcgfih.dll -> %System32%\nowcgfih.dll -> [Ver = | Size = 79936 bytes | Modified Date = 11/15/2007 12:29:44 PM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 11/15/2007 12:44:46 AM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 52968 bytes | Modified Date = 11/4/2007 3:32:46 PM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 380680 bytes | Modified Date = 11/4/2007 3:32:46 PM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 439552 bytes | Modified Date = 11/4/2007 3:32:46 PM | Attr = ]
pntyjicf.dll -> %System32%\pntyjicf.dll -> [Ver = | Size = 89664 bytes | Modified Date = 11/12/2007 12:35:04 PM | Attr = ]
samjlpcv.exe -> %System32%\samjlpcv.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Modified Date = 11/14/2007 11:57:30 AM | Attr = ]
settings.sfm -> %System32%\settings.sfm -> [Ver = | Size = 1072 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
settingsbkup.sfm -> %System32%\settingsbkup.sfm -> [Ver = | Size = 1072 bytes | Modified Date = 11/15/2007 11:49:08 AM | Attr = ]
skwhaofo.exe -> %System32%\skwhaofo.exe -> [Ver = 1, 0, 0, 1 | Size = 71232 bytes | Modified Date = 11/12/2007 12:26:06 PM | Attr = ]
sstwa.bak1 -> %System32%\sstwa.bak1 -> [Ver = | Size = 6465 bytes | Modified Date = 11/11/2007 8:40:56 PM | Attr = HS]
sstwa.bak2 -> %System32%\sstwa.bak2 -> [Ver = | Size = 441114 bytes | Modified Date = 11/15/2007 12:24:02 PM | Attr = HS]
sstwa.ini -> %System32%\sstwa.ini -> [Ver = | Size = 437905 bytes | Modified Date = 11/15/2007 12:33:28 PM | Attr = HS]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 3168 bytes | Modified Date = 11/13/2007 1:08:14 AM | Attr = ]
ttvwa.ini -> %System32%\ttvwa.ini -> [Ver = | Size = 353 bytes | Modified Date = 11/11/2007 8:36:46 PM | Attr = HS]
twepokio.dll -> %System32%\twepokio.dll -> [Ver = | Size = 81472 bytes | Modified Date = 11/12/2007 12:38:04 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 11/15/2007 12:44:46 AM | Attr = ]
wbem -> %System32%\wbem -> [Folder | Modified Date = 11/11/2007 10:40:30 PM | Attr = ]
winrge32.dll -> %System32%\winrge32.dll -> [Ver = | Size = 20480 bytes | Modified Date = 11/11/2007 8:30:40 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 11/15/2007 12:23:44 PM | Attr = ]
yhyqsbje.dll -> %System32%\yhyqsbje.dll -> [Ver = | Size = 85056 bytes | Modified Date = 11/15/2007 12:29:38 PM | Attr = ]
_PersonalityVert1.WB4 -> %System32%\_PersonalityVert1.WB4 -> [Ver = | Size = 274 bytes | Modified Date = 10/23/2007 5:35:18 PM | Attr = ]
_PersonalityVert2.WB4 -> %System32%\_PersonalityVert2.WB4 -> [Ver = | Size = 274 bytes | Modified Date = 10/23/2007 5:35:18 PM | Attr = ]
hosts.ics -> %System32%\drivers\etc\hosts.ics -> [Ver = | Size = 430 bytes | Modified Date = 11/15/2007 12:13:46 PM | Attr = ]
[File String Scan - Non-Microsoft Only]
PEC2 , PECompact2 , -> %SystemRoot%\mgrs.exe -> [Ver = | Size = 11776 bytes | Modified Date = 11/14/2007 12:05:18 PM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 12/31/2002 6:00:00 AM | Attr = ]
PEC2 , PECompact2 , -> %System32%\DivX.dll -> DivX, Inc. [Ver = 6.6.1.4 | Size = 740442 bytes | Modified Date = 5/31/2007 12:44:56 AM | Attr = ]
Thawte Consulting , -> %System32%\rmoc3260.dll -> RealNetworks, Inc. [Ver = 6.0.9.2568 | Size = 185952 bytes | Modified Date = 10/22/2006 11:12:08 AM | Attr = ]
Thawte Consulting , -> %System32%\SmartUI2.ocx -> Xceed Software Inc (450) 442-2626
[email protected] www.xceedsoft.com [Ver = 2.00.6553 | Size = 870152 bytes | Modified Date = 3/15/2007 11:22:38 AM | Attr = ]
UPX! , UPX0 , -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Modified Date = 4/27/2006 4:49:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Modified Date = 8/29/2006 6:43:54 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 1/9/2006 9:36:06 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Modified Date = 12/1/2006 5:20:34 AM | Attr = ]
UPX! , UPX0 , -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Modified Date = 9/5/2007 11:22:24 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 12/31/2002 6:00:00 AM | Attr = ]
PEC2 , -> %System32%\winrge32.dll -> [Ver = | Size = 20480 bytes | Modified Date = 11/11/2007 8:30:40 PM | Attr = ]
UPX! , UPX0 , -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Modified Date = 10/3/2007 11:36:46 PM | Attr = ]
Thawte Consulting , -> %System32%\XceedCry.dll -> Xceed Software Inc (450) 442-2626
[email protected] www.xceedsoft.com [Ver = 1.1.6461.0 | Size = 526184 bytes | Modified Date = 3/15/2007 11:19:58 AM | Attr = ]
Thawte Consulting , -> %System32%\XceedZip.dll -> Xceed Software Inc (450) 442-2626
[email protected] www.xceedsoft.com [Ver = 6.0.6621.0 | Size = 497496 bytes | Modified Date = 3/15/2007 11:23:16 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 12/31/2002 6:00:00 AM | Attr = ]
PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 11:41:38 PM | Attr = ]
< End of report >
Edited by karl_hungus, 15 November 2007 - 12:47 PM.