Logfile created on: 07/10/2006 21:12
WinPFind2 - PreRelease 1.3.1 Folder = C:\WinPFind\
Microsoft Windows XP (Version = Service Pack 2)
Internet Explorer (Version - 6.0.2900.2180)
Files
Full Path Details
%SystemDrive%
%ProgramFilesDir%
%WinDir%
C:\WINDOWS\whCC-GIANT.exe UPX! [Ver = / Size = 226536 bytes] 10/17/2005 22:44
%System%
C:\WINDOWS\SYSTEM32\dfrg.msc AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213 [Ver = / Size = 41397 bytes] 07/16/2003 16:26
C:\WINDOWS\SYSTEM32\divx.dll PEC2 DivX, Inc. [Ver = 6.2.2.3 / Size = 619156 bytes] 04/19/2006 22:09
C:\WINDOWS\SYSTEM32\divx.dll PECompact2 DivX, Inc. [Ver = 6.2.2.3 / Size = 619156 bytes] 04/19/2006 22:09
C:\WINDOWS\SYSTEM32\LegitCheckControl.dll RIMAPPTECHNOLOGIES Microsoft Corporation [Ver = 1.5.0540.0 / Size = 571184 bytes] 06/19/2006 16:19
C:\WINDOWS\SYSTEM32\MRT.exe (PeCompact2) Microsoft Corporation [Ver = 1.17.1478.0 / Size = 5967776 bytes] 06/08/2006 21:19
C:\WINDOWS\SYSTEM32\MRT.exe (ASPack) Microsoft Corporation [Ver = 1.17.1478.0 / Size = 5967776 bytes] 06/08/2006 21:19
C:\WINDOWS\SYSTEM32\ntdll.dll .aspack Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 708096 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\rasdlg.dll \DuMonitor SendMessage(WM_RASEVENT) doneMicrosoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 657920 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\wbdbase.deu msubjsuchsullsupeswinsyncszens [Ver = / Size = 1309184 bytes] 07/16/2003 16:50
C:\WINDOWS\SYSTEM32\WgaTray.exe RIMAPPTECHNOLOGIES Microsoft Corporation [Ver = 1.5.0540.0 / Size = 304944 bytes] 06/19/2006 16:19
%System%\Drivers folder and sub-folders
C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys V90NEC, --------ERROR--------- occured in adaptechoSmart Link [Ver = 3.80.01MC15 / Size = 1309184 bytes] 08/04/2004 01:41
%windir% + sub-dirs for System or Hidden files less than 60 days old
C:\WINDOWS\bootstat.dat [Ver = / Size = 2048 bytes] 07/10/2006 20:05 S
C:\WINDOWS\QTFont.qfn [Ver = / Size = 54156 bytes] 07/05/2006 12:45 H
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Docklets\Animation\Thumbs.db [Ver = / Size = 3584 bytes] 07/03/2006 22:58 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Docklets\gfd\Thumbs.db [Ver = / Size = 182784 bytes] 07/03/2006 23:39 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Docklets\gfd\icons\Thumbs.db [Ver = / Size = 153088 bytes] 07/03/2006 23:39 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Docklets\Search\Thumbs.db [Ver = / Size = 28672 bytes] 07/03/2006 22:58 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Labelled\Thumbs.db [Ver = / Size = 56320 bytes] 06/27/2006 21:29 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Labelled\ico\Thumbs.db [Ver = / Size = 64512 bytes] 06/27/2006 23:10 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Labelled\png\Thumbs.db [Ver = / Size = 273408 bytes] 06/27/2006 23:11 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Unlabelled\Thumbs.db [Ver = / Size = 47104 bytes] 06/27/2006 21:22 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Unlabelled\ico\Thumbs.db [Ver = / Size = 52736 bytes] 06/27/2006 23:10 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\Icons\Blaqua Applications\Unlabelled\png\Thumbs.db [Ver = / Size = 252416 bytes] 06/27/2006 23:11 HS
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\Themes\Vista Inspirat\Thumbs.db [Ver = / Size = 4096 bytes] 07/03/2006 22:57 HS
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB911280.cat [Ver = / Size = 13309 bytes] 05/14/2006 06:21 S
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB916281.cat [Ver = / Size = 23751 bytes] 05/29/2006 12:16 S
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB917344.cat [Ver = / Size = 10925 bytes] 05/18/2006 03:15 S
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB918439.cat [Ver = / Size = 11043 bytes] 06/01/2006 16:28 S
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WgaNotify.cat [Ver = / Size = 7160 bytes] 06/19/2006 16:20 S
C:\WINDOWS\system32\config\default.LOG [Ver = / Size = 8192 bytes] 07/10/2006 20:05 H
C:\WINDOWS\system32\config\SAM.LOG [Ver = / Size = 1024 bytes] 07/10/2006 20:05 H
C:\WINDOWS\system32\config\SECURITY.LOG [Ver = / Size = 16384 bytes] 07/10/2006 20:05 H
C:\WINDOWS\system32\config\software.LOG [Ver = / Size = 73728 bytes] 07/10/2006 20:07 H
C:\WINDOWS\system32\config\system.LOG [Ver = / Size = 950272 bytes] 07/10/2006 20:05 H
C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG [Ver = / Size = 1024 bytes] 06/15/2006 03:05 H
C:\WINDOWS\system32\drivers\umdf\MsftWdf_user_01_00_00.Wdf [Ver = / Size = 0 bytes] 06/29/2006 19:48 H
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\a6b09ca3-d53e-4854-8319-4745bd2a87ca [Ver = / Size = 388 bytes] 05/14/2006 19:35 HS
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\Preferred [Ver = / Size = 24 bytes] 05/14/2006 19:35 HS
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\5c0cf735-f181-42b5-a2a5-39de7e24790b [Ver = / Size = 388 bytes] 05/14/2006 19:25 HS
C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred [Ver = / Size = 24 bytes] 05/14/2006 19:25 HS
C:\WINDOWS\Tasks\SA.DAT [Ver = / Size = 6 bytes] 07/10/2006 20:04 H
CPL files
C:\WINDOWS\SYSTEM32\access.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 68608 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\appwiz.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 549888 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\bdeadmin.cpl Borland Software Corporation [Ver = 5.2.0.2 / Size = 184320 bytes] 10/07/2003 13:39
C:\WINDOWS\SYSTEM32\bthprops.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 110592 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\desk.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 135168 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\firewall.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 80384 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\hdwwiz.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 155136 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\inetcpl.cpl Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) / Size = 358400 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\intl.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 129536 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\irprops.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 380416 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\joy.cpl Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 68608 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\jpicpl32.cpl Sun Microsystems, Inc. [Ver = 5.0.40.5 / Size = 49265 bytes] 06/03/2005 03:52
C:\WINDOWS\SYSTEM32\main.cpl Microsoft Corporation [Ver = 5.1.2403.1 / Size = 187904 bytes] 07/16/2003 16:32
C:\WINDOWS\SYSTEM32\mmsys.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 618496 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\ncpa.cpl Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) / Size = 35840 bytes] 07/16/2003 16:37
C:\WINDOWS\SYSTEM32\netsetup.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 25600 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\nusrmgr.cpl Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) / Size = 257024 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\nvtuicpl.cpl NVIDIA Corporation [Ver = 6.14.10.4586 / Size = 143360 bytes] 01/08/2004 15:26
C:\WINDOWS\SYSTEM32\odbccp32.cpl Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) / Size = 32768 bytes] 08/04/2004 03:56
C:\WINDOWS\SYSTEM32\powercfg.cpl Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) / Size = 114688 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\stac97.cpl SigmaTel Inc. [Ver = 1, 0, 0, 12 / Size = 102481 bytes] 04/06/2004 11:13
C:\WINDOWS\SYSTEM32\sysdm.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 298496 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\telephon.cpl Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) / Size = 28160 bytes] 07/16/2003 16:47
C:\WINDOWS\SYSTEM32\timedate.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 94208 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\wscui.cpl Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) / Size = 148480 bytes]08/04/2004 03:56
C:\WINDOWS\SYSTEM32\wuaucpl.cpl Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) / Size = 174360 bytes] 05/26/2005 04:16
C:\WINDOWS\SYSTEM32\dllcache\main.cpl Microsoft Corporation [Ver = 5.1.2403.1 / Size = 629248 bytes] 07/16/2003 16:32
C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) / Size = 167936 bytes] 07/16/2003 16:37
C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) / Size = 166400 bytes] 07/16/2003 16:47
AllUsers Startup Folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk [Ver = / Size = 1757 bytes] 09/03/2005 16:16
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini [Ver = / Size = 84 bytes] 07/22/2005 22:48 HS
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless-G Notebook Adapter with SpeedBooster Utility.lnk [Ver = / Size = 1046 bytes] 07/23/2005 00:04
AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini [Ver = / Size = 62 bytes] 07/22/2005 18:33 HS
CurrentUser Startup Folder
C:\Documents and Settings\Garrett Keating\Start Menu\Programs\Startup\Adobe Gamma.lnk [Ver = / Size = 988 bytes] 09/09/2005 22:23
C:\Documents and Settings\Garrett Keating\Start Menu\Programs\Startup\desktop.ini [Ver = / Size = 84 bytes] 07/22/2005 22:48 HS
C:\Documents and Settings\Garrett Keating\Start Menu\Programs\Startup\Stardock ObjectDock.lnk [Ver = / Size = 1685 bytes] 07/10/2006 12:31
CurrentUser ApplicationData Folder
C:\Documents and Settings\Garrett Keating\Application Data\AdobeDLM.log [Ver = / Size = 871 bytes] 09/03/2005 16:12
C:\Documents and Settings\Garrett Keating\Application Data\desktop.ini [Ver = / Size = 62 bytes] 07/22/2005 18:33 HS
C:\Documents and Settings\Garrett Keating\Application Data\dm.ini [Ver = / Size = 0 bytes] 09/03/2005 16:12
C:\Documents and Settings\Garrett Keating\Application Data\PFP120JCM.{PB [Ver = / Size = 12358 bytes] 08/11/2005 09:55
C:\Documents and Settings\Garrett Keating\Application Data\PFP120JPR.{PB [Ver = / Size = 61678 bytes] 08/11/2005 09:55
DPF files
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} QuickTime Object - CodeBase =
http://www.apple.com...ex/qtplugin.cab{166B1BCA-3F9C-11CF-8075-444553540000} Shockwave ActiveX Control - CodeBase =
http://download.macr...director/sw.cab{17492023-C23A-453E-A040-C7C580BBF700} Windows Genuine Advantage Validation Tool - CodeBase =
http://go.microsoft....k/?linkid=39204{29D73455-3ADA-49BB-9067-44822F6728F5} - CodeBase =
http://www.joga.com/.../uploadactx.cab{3334504D-9980-0010-8000-00AA00389B71} - CodeBase =
http://download.micr...C4D/mp43dmo.CAB{5F8469B4-B055-49DD-83F7-62B522420ECC} Facebook Photo Uploader Control - CodeBase =
http://upload.facebo...otoUploader.cab{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} MUWebControl Class - CodeBase =
http://update.micros...b?1128013305187{8AD9C840-044E-11D1-B3E9-00805F499D93} Java Plug-in 1.5.0_04 - CodeBase =
http://java.sun.com/...indows-i586.cab{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} Java Plug-in 1.5.0_04 - CodeBase =
http://java.sun.com/...indows-i586.cab{D27CDB6E-AE6D-11CF-96B8-444553540000} Shockwave Flash Object - CodeBase =
http://fpdownload.ma...ash/swflash.cabHosts file = 734 bytes. Reading all entries.
# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
Scanning Report
Monday, July 10, 2006 21:28:35 - 23:21:06
Computer name: GARRETT
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 6 malware found
Tracking Cookie (spyware)
* System (Disinfected)
* System
* System
* System
* System
WebHancer (spyware)
* System (Disinfected)
Statistics
Scanned:
* Files: 31175
* System: 4233
* Not scanned: 4
Actions:
* Disinfected: 2
* Renamed: 0
* Deleted: 0
* None: 4
* Submitted: 0
Files not scanned:
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{E38D93EE-988E-423A-B43B-175F29B8692B}.BIN
* C:\DOCUMENTS AND SETTINGS\GARRETT KEATING\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\7LGLHM81\FRONT[3].ASP
Options
Scanning engines:
* F-Secure AVP: 6.0.171, 2006-07-10
* F-Secure Libra: 2.4.1, 2006-07-08
* F-Secure Orion: 1.2.37, 2006-07-10
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Pegasus: 1.19.0, 2006-06-04
* F-Secure Draco: 1.0.35, 0259-24-212
Scanning options:
* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
* Use Advanced heuristics