the next log
\
WinPFind3 logfile created on: 10/23/2007 6:54:04 PM
WinPFind3U by OldTimer - Version 1.0.42 Folder = C:\Documents and Settings\Owner\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.11)
501.98 Mb Total Physical Memory | 179.30 Mb Available Physical Memory | 35.72% Memory free
1.20 Gb Paging File | 0.85 Gb Available in Paging File | 71.28% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 61.83 Gb Total Space | 47.84 Gb Free Space | 77.37% Space Free
Drive D: | 11.67 Gb Total Space | 1.36 Gb Free Space | 11.68% Space Free
Drive E: | 420.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free
F: Drive not present or media not loaded
Computer Name: LAPTOP
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 9/3/2007 10:15:22 PM | Attr = ]
avgcc.exe -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.487 | Size = 421888 bytes | Modified Date = 9/13/2007 10:59:20 AM | Attr = ]
avgemc.exe -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.482 | Size = 353280 bytes | Modified Date = 9/3/2007 10:15:22 PM | Attr = ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 9/3/2007 10:15:24 PM | Attr = ]
cfd.exe -> %ProgramFiles%\BroadJump\Client Foundation\CFD.exe -> [Ver = | Size = 368706 bytes | Modified Date = 9/10/2002 9:26:26 PM | Attr = ]
hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 77824 bytes | Modified Date = 3/22/2006 10:13:40 PM | Attr = ]
hp wireless assistant.exe -> %ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe -> Hewlett-Packard Development Company, L.P. [Ver = 2, 0, 7, 2 | Size = 458752 bytes | Modified Date = 5/4/2006 7:58:26 AM | Attr = ]
hpqwmiex.exe -> %ProgramFiles%\Hewlett-Packard\Shared\hpqwmiex.exe -> Hewlett-Packard Development Company, L.P. [Ver = 2, 0, 1, 9 | Size = 135168 bytes | Modified Date = 5/2/2006 5:41:28 PM | Attr = ]
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 AM | Attr = ]
hpzipm12.exe -> %System32%\HPZipm12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 69632 bytes | Modified Date = 9/29/2004 12:14:36 PM | Attr = ]
igfxpers.exe -> %System32%\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 118784 bytes | Modified Date = 3/22/2006 10:17:50 PM | Attr = ]
igfxtray.exe -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 94208 bytes | Modified Date = 3/22/2006 10:17:04 PM | Attr = ]
issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> Macrovision Corporation [Ver = 4, 60, 100, 37068 | Size = 81920 bytes | Modified Date = 8/11/2005 6:30:30 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 11/11/2005 6:03:52 AM | Attr = ]
lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.97.1 | Size = 49152 bytes | Modified Date = 5/18/2006 6:52:06 PM | Attr = ]
motivesb.exe -> %ProgramFiles%\SBC Self Support Tool\SmartBridge\MotiveSB.exe -> Motive, Inc. [Ver = 5.8.18.asst_classic.smartbridge.20050824_144000 | Size = 442455 bytes | Modified Date = 8/24/2005 7:51:18 AM | Attr = ]
movielink user.exe -> %ProgramFiles%\Movielink\MovielinkManager\Movielink User.exe -> Movielink LLC [Ver = 4, 0, 0, 413 | Size = 124248 bytes | Modified Date = 9/10/2007 5:14:00 PM | Attr = ]
moviel~2.exe -> %ProgramFiles%\Movielink\MovielinkManager\MovielinkCore.exe -> Movielink LLC [Ver = 4, 0, 0, 413 | Size = 1328472 bytes | Modified Date = 9/10/2007 5:13:48 PM | Attr = ]
mpbtn.exe -> %ProgramFiles%\SBC Self Support Tool\bin\mpbtn.exe -> [Ver = | Size = 192512 bytes | Modified Date = 10/10/2003 9:06:10 AM | Attr = ]
qlbctrl.exe -> %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe -> Hewlett-Packard Development Company, L.P. [Ver = 6, 1, 1, 2 | Size = 163840 bytes | Modified Date = 6/19/2006 1:33:12 PM | Attr = ]
qpservice.exe -> %ProgramFiles%\HP\QuickPlay\QPService.exe -> CyberLink Corp. [Ver = 4.5.0.0000 | Size = 102400 bytes | Modified Date = 7/19/2006 5:14:20 PM | Attr = ]
syntpenh.exe -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 8.3.8 16Jun06 | Size = 794713 bytes | Modified Date = 6/17/2006 7:22:46 AM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.42.0 | Size = 322560 bytes | Modified Date = 9/4/2007 10:47:26 AM | Attr = ]
ybrwicon.exe -> %ProgramFiles%\Yahoo!\browser\ybrwicon.exe -> Yahoo! Inc. [Ver = 2006, 7, 21, 1 | Size = 129536 bytes | Modified Date = 7/21/2006 4:19:46 PM | Attr = ]
ycommon.exe -> %ProgramFiles%\Yahoo!\browser\ycommon.exe -> Yahoo!, Inc. [Ver = 2006, 3, 2, 1 | Size = 200704 bytes | Modified Date = 3/3/2006 1:18:10 PM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(AddFiltr) AddFiltr [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe -> Hewlett-Packard Development Company, L.P. [Ver = 1.0.0.1 | Size = 126976 bytes | Modified Date = 6/12/2006 3:27:28 PM | Attr = ]
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 9/3/2007 10:15:22 PM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 9/3/2007 10:15:24 PM | Attr = ]
(AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG7\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.482 | Size = 353280 bytes | Modified Date = 9/3/2007 10:15:22 PM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 3/16/2006 6:00:00 AM | Attr = ]
(hpqwmiex) hpqwmiex [Win32_Own | Auto | Running] -> %ProgramFiles%\Hewlett-Packard\Shared\hpqwmiex.exe -> Hewlett-Packard Development Company, L.P. [Ver = 2, 0, 1, 9 | Size = 135168 bytes | Modified Date = 5/2/2006 5:41:28 PM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 2:41:10 AM | Attr = ]
(LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.97.1 | Size = 49152 bytes | Modified Date = 5/18/2006 6:52:06 PM | Attr = ]
(Movielink Core Service) Movielink Core Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Movielink\MovielinkManager\MovielinkCore.exe -> Movielink LLC [Ver = 4, 0, 0, 413 | Size = 1328472 bytes | Modified Date = 9/10/2007 5:13:48 PM | Attr = ]
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> %System32%\HPZipm12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 69632 bytes | Modified Date = 9/29/2004 12:14:36 PM | Attr = ]
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AVG7_CC -> %ProgramFiles%\Grisoft\AVG7\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.487 | Size = 421888 bytes | Modified Date = 9/13/2007 10:59:20 AM | Attr = ]
BJCFD -> %ProgramFiles%\BroadJump\Client Foundation\CFD.exe -> [Ver = | Size = 368706 bytes | Modified Date = 9/10/2002 9:26:26 PM | Attr = ]
Cpqset -> %ProgramFiles%\Hewlett-Packard\Default Settings\Cpqset.exe -> [Ver = | Size = 40960 bytes | Modified Date = 6/19/2006 12:50:40 PM | Attr = ]
High Definition Audio Property Page Shortcut -> %System32%\CHDAudPropShortcut.exe -> Windows ® Server 2003 DDK provider [Ver = 5.10.00.5010 built by: WinDDK | Size = 61952 bytes | Modified Date = 6/2/2006 5:02:50 PM | Attr = ]
HP Software Update -> %ProgramFiles%\HP\HP Software Update\HPWuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 AM | Attr = ]
hpWirelessAssistant -> %ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe -> Hewlett-Packard Development Company, L.P. [Ver = 2, 0, 7, 2 | Size = 458752 bytes | Modified Date = 5/4/2006 7:58:26 AM | Attr = ]
igfxhkcmd -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 77824 bytes | Modified Date = 3/22/2006 10:13:40 PM | Attr = ]
igfxpers -> %System32%\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 118784 bytes | Modified Date = 3/22/2006 10:17:50 PM | Attr = ]
igfxtray -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4543 | Size = 94208 bytes | Modified Date = 3/22/2006 10:17:04 PM | Attr = ]
ISUSPM Startup -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe -> Macrovision Corporation [Ver = 4, 60, 100, 37068 | Size = 249856 bytes | Modified Date = 8/11/2005 6:30:30 PM | Attr = ]
ISUSScheduler -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> Macrovision Corporation [Ver = 4, 60, 100, 37068 | Size = 81920 bytes | Modified Date = 8/11/2005 6:30:30 PM | Attr = ]
LoadMSvcmm -> %ProgramFiles%\Movielink\MovielinkManager\Movielink User.exe -> Movielink LLC [Ver = 4, 0, 0, 413 | Size = 124248 bytes | Modified Date = 9/10/2007 5:14:00 PM | Attr = ]
Motive SmartBridge -> %ProgramFiles%\SBC Self Support Tool\SmartBridge\MotiveSB.exe -> Motive, Inc. [Ver = 5.8.18.asst_classic.smartbridge.20050824_144000 | Size = 442455 bytes | Modified Date = 8/24/2005 7:51:18 AM | Attr = ]
QlbCtrl -> HP Quick Launch Buttons\QlbCtrl.exe -> File not found
QPService -> %ProgramFiles%\HP\QuickPlay\QPService.exe -> CyberLink Corp. [Ver = 4.5.0.0000 | Size = 102400 bytes | Modified Date = 7/19/2006 5:14:20 PM | Attr = ]
RecGuard -> %SystemRoot%\SMINST\Recguard.exe -> [Ver = 6, 0, 66, 5 | Size = 1187840 bytes | Modified Date = 10/11/2005 12:23:50 PM | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 11/11/2005 6:03:52 AM | Attr = ]
SynTPEnh -> %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe -> Synaptics, Inc. [Ver = 8.3.8 16Jun06 | Size = 794713 bytes | Modified Date = 6/17/2006 7:22:46 AM | Attr = ]
YBrowser -> %ProgramFiles%\Yahoo!\browser\ybrwicon.exe -> Yahoo! Inc. [Ver = 2006, 7, 21, 1 | Size = 129536 bytes | Modified Date = 7/21/2006 4:19:46 PM | Attr = ]
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Yahoo! Pager -> -> File not found
< Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersStartup%\SBC Self Support Tool.lnk -> %ProgramFiles%\SBC Self Support Tool\bin\matcli.exe -> Motive Communications, Inc. [Ver = 5.6.1.asst_classic.asst_matcli.20031010_085000 | Size = 217088 bytes | Modified Date = 10/10/2003 9:06:10 AM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4543 | Size = 139264 bytes | Modified Date = 3/22/2006 10:12:42 PM | Attr = ]
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{17492023-C23A-453E-A040-C7C580BBF700} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallVisualStyle -> C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallTheme -> C:\WINDOWS\Resources\Themes\Royale.theme ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
< HOSTS File > (3066 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
192.168.200.3 ad.doubleclick.net -> ->
192.168.200.3 ad.fastclick.net -> ->
192.168.200.3 ads.fastclick.net -> ->
192.168.200.3 ar.atwola.com -> ->
192.168.200.3 atdmt.com -> ->
192.168.200.3 avp.ch -> ->
192.168.200.3 avp.com -> ->
192.168.200.3 avp.ru -> ->
192.168.200.3 awaps.net -> ->
192.168.200.3 banner.fastclick.net -> ->
192.168.200.3 banners.fastclick.net -> ->
192.168.200.3 ca.com -> ->
192.168.200.3 click.atdmt.com -> ->
192.168.200.3 clicks.atdmt.com -> ->
192.168.200.3 customer.symantec.com -> ->
192.168.200.3 dispatch.mcafee.com -> ->
192.168.200.3 download.mcafee.com -> ->
192.168.200.3 downloads-us1.kaspersky-labs.com -> ->
192.168.200.3 downloads-us2.kaspersky-labs.com -> ->
192.168.200.3 downloads-us3.kaspersky-labs.com -> ->
192.168.200.3 downloads1.kaspersky-labs.com -> ->
192.168.200.3 downloads2.kaspersky-labs.com -> ->
192.168.200.3 downloads3.kaspersky-labs.com -> ->
192.168.200.3 downloads4.kaspersky-labs.com -> ->
192.168.200.3 engine.awaps.net -> ->
192.168.200.3 f-secure.com -> ->
192.168.200.3 fastclick.net -> ->
192.168.200.3 ftp.avp.ch -> ->
192.168.200.3 ftp.downloads1.kaspersky-labs.com -> ->
192.168.200.3 ftp.downloads2.kaspersky-labs.com -> ->
192.168.200.3 ftp.downloads3.kaspersky-labs.com -> ->
192.168.200.3 ftp.f-secure.com -> ->
192.168.200.3 ftp.kasperskylab.ru -> ->
192.168.200.3 ftp.sophos.com -> ->
192.168.200.3 ids.kaspersky-labs.com -> ->
192.168.200.3 kaspersky-labs.com -> ->
192.168.200.3 kaspersky.com -> ->
192.168.200.3 liveupdate.symantec.com -> ->
192.168.200.3 liveupdate.symantecliveupdate.com -> ->
192.168.200.3 mast.mcafee.com -> ->
192.168.200.3 mcafee.com -> ->
192.168.200.3 media.fastclick.net -> ->
192.168.200.3 my-etrust.com -> ->
192.168.200.3 nai.com -> ->
192.168.200.3 networkassociates.com -> ->
192.168.200.3 norton.com -> ->
192.168.200.3 phx.corporate-ir.net -> ->
192.168.200.3 rads.mcafee.com -> ->
192.168.200.3 secure.nai.com -> ->
192.168.200.3 securityresponse.symantec.com -> ->
192.168.200.3 service1.symantec.com -> ->
192.168.200.3 sophos.com -> ->
192.168.200.3 spd.atdmt.com -> ->
192.168.200.3 symantec.com -> ->
192.168.200.3 trendmicro.com -> ->
192.168.200.3 update.symantec.com -> ->
192.168.200.3 updates.symantec.com -> ->
192.168.200.3 updates1.kaspersky-labs.com -> ->
192.168.200.3 updates2.kaspersky-labs.com -> ->
192.168.200.3 updates3.kaspersky-labs.com -> ->
192.168.200.3 updates4.kaspersky-labs.com -> ->
192.168.200.3 updates5.kaspersky-labs.com -> ->
192.168.200.3 us.mcafee.com -> ->
192.168.200.3 vil.nai.com -> ->
192.168.200.3 viruslist.com -> ->
192.168.200.3 viruslist.ru -> ->
192.168.200.3 virusscan.jotti.org -> ->
192.168.200.3 virustotal.com -> ->
192.168.200.3 www.avp.ch -> ->
192.168.200.3 www.avp.com -> ->
192.168.200.3 www.avp.ru -> ->
192.168.200.3 www.awaps.net -> ->
192.168.200.3 www.ca.com -> ->
192.168.200.3 www.f-secure.com -> ->
192.168.200.3 www.fastclick.net -> ->
192.168.200.3 www.grisoft.com -> ->
192.168.200.3 www.kaspersky-labs.com -> ->
192.168.200.3 www.kaspersky.com -> ->
192.168.200.3 www.kaspersky.ru -> ->
192.168.200.3 www.mcafee.com -> ->
192.168.200.3 www.my-etrust.com -> ->
192.168.200.3 www.nai.com -> ->
192.168.200.3 www.networkassociates.com -> ->
192.168.200.3 www.sophos.com -> ->
192.168.200.3 www.symantec.com -> ->
192.168.200.3 www.symantec.com -> ->
192.168.200.3 www.trendmicro.com -> ->
192.168.200.3 www.viruslist.com -> ->
192.168.200.3 www.viruslist.ru -> ->
192.168.200.3 www.virustotal.com -> ->
192.168.200.3 www3.ca.com -> ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL ->
http://www.microsoft...p...&ar=msnhome ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> C:\windows\system32\blank.htm ->
HKLM: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Start Page ->
http://www.microsoft...p...ER}&ar=home ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: Search\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Local Page -> C:\windows\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page ->
http://www.microsoft...p...&ar=msnhome ->
HKCU: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
HKCU: ProxyEnable -> 0 ->
HKCU: ProxyOverride -> 127.0.0.1 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< Trusted Sites > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
att.net [http] -> ->
att.net [https] -> ->
sbcglobal.net [https] -> ->
clientapps_yahoo.com [http] -> ->
clientapps_yahoo.com [https] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [&Yahoo! Toolbar Helper] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Modified Date = 11/11/2005 6:22:10 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 11/11/2005 6:22:10 AM | Attr = ]
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> -> File not found
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{15BD0110-E061-47F5-BB56-43137AB4EB9B} -> (Intel® PRO/Wireless 3945ABG Network Connection) ->
{2CF2FB2C-F0B5-4B56-B78E-68D17EB4B517} -> (Intel® PRO/100 VE Network Connection) ->
{5AC8631C-D5DB-4A24-AD7B-A05975D24A79} -> (1394 Net Adapter) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -> YInstStarter Class - CodeBase = C:\Program Files\Yahoo!\common\yinsthelper.dll ->
{49232000-16E4-426C-A231-62846947304B} -> SysData Class - CodeBase =
http://ipgweb.cce.hp...ads/sysinfo.cab ->
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B} -> OnlineScanner Control - CodeBase =
http://www.eset.eu/b...lineScanner.cab ->
{5F8469B4-B055-49DD-83F7-62B522420ECC} -> Facebook Photo Uploader Control - CodeBase =
http://upload.facebo...otoUploader.cab ->
{6B75345B-AA36-438A-BBE6-4078B4C6984D} -> HpProductDetection Class - CodeBase =
http://h20270.www2.h...ctDetection.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -> Get_ActiveX Control - CodeBase =
https://h17000.www1....loadManager.ocx ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase =
http://fpdownload.ma...ash/swflash.cab ->
Microsoft XML Parser for Java -> - CodeBase = file:///C:/WINDOWS/Java/classes/xmldso.cab ->
[Registry - Additional Scans - Non-Microsoft Only]
[Files/Folders - Created Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Created Date = 10/19/2007 9:18:16 PM | Attr = RH ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 9/27/2007 6:58:23 PM | Attr = H ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 526438400 bytes | Created Date = 1/1/1601 6:00:00 AM | Attr = HS]
qoobox -> %SystemDrive%\qoobox -> [Folder | Created Date = 10/22/2007 5:45:06 PM | Attr = ]
Temp -> %SystemDrive%\Temp -> [Folder | Created Date = 9/27/2007 6:57:01 PM | Attr = ]
$NtUninstallKB926239$ -> %SystemRoot%\$NtUninstallKB926239$ -> [Folder | Created Date = 10/10/2007 8:17:15 PM | Attr = H ]
$NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Created Date = 10/11/2007 9:28:30 PM | Attr = H ]
$NtUninstallKB933729$ -> %SystemRoot%\$NtUninstallKB933729$ -> [Folder | Created Date = 10/10/2007 9:38:42 AM | Attr = H ]
$NtUninstallKB941202$ -> %SystemRoot%\$NtUninstallKB941202$ -> [Folder | Created Date = 10/10/2007 9:38:05 AM | Attr = H ]
$NtUninstallWMFDist11$ -> %SystemRoot%\$NtUninstallWMFDist11$ -> [Folder | Created Date = 10/10/2007 8:16:38 PM | Attr = H ]
$NtUninstallWudf01000$ -> %SystemRoot%\$NtUninstallWudf01000$ -> [Folder | Created Date = 10/10/2007 8:15:45 PM | Attr = H ]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 136192 bytes | Created Date = 10/22/2007 5:44:21 PM | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 10/23/2007 5:47:28 PM | Attr = ]
hpoins05.dat -> %SystemRoot%\hpoins05.dat -> [Ver = | Size = 102262 bytes | Created Date = 9/27/2007 6:58:06 PM | Attr = ]
hpomdl07.dat -> %SystemRoot%\hpomdl07.dat -> [Ver = | Size = 17505 bytes | Created Date = 9/27/2007 6:58:06 PM | Attr = ]
MegaMud.INI -> %SystemRoot%\MegaMud.INI -> [Ver = | Size = 422 bytes | Created Date = 10/19/2007 8:45:44 PM | Attr = ]
NirCmd.exe -> %SystemRoot%\NirCmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 10/22/2007 5:44:21 PM | Attr = ]
TEMP -> %SystemRoot%\TEMP -> [Folder | Created Date = 10/23/2007 5:48:19 PM | Attr = ]
xlavba3.exe -> %SystemRoot%\xlavba3.exe -> [Ver = | Size = 16384 bytes | Created Date = 10/22/2007 3:13:21 PM | Attr = ]
d3d9caps.dat -> %System32%\d3d9caps.dat -> [Ver = | Size = 664 bytes | Created Date = 10/16/2007 6:43:57 PM | Attr = ]
Delete_Me_Dummy_sulimo.dat -> %System32%\Delete_Me_Dummy_sulimo.dat -> [Ver = | Size = 1536 bytes | Created Date = 10/19/2007 9:08:19 PM | Attr = ]
dumphive.exe -> %System32%\dumphive.exe -> [Ver = | Size = 51200 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
hpgwiamd.dll -> %System32%\hpgwiamd.dll -> Hewlett-Packard [Ver = 3.2.2.905 | Size = 278528 bytes | Created Date = 9/27/2007 6:57:22 PM | Attr = ]
hpotscl.dll -> %System32%\hpotscl.dll -> Hewlett-Packard Co. [Ver = 50.0.174.000 | Size = 606208 bytes | Created Date = 9/27/2007 6:57:22 PM | Attr = ]
hpovst08.dll -> %System32%\hpovst08.dll -> Hewlett-Packard Co. [Ver = 50.0.174.000 | Size = 258122 bytes | Created Date = 9/27/2007 6:57:22 PM | Attr = ]
HPZc3212.dll -> %System32%\HPZc3212.dll -> Hewlett-Packard Co. [Ver = 9, 0, 0, 0 | Size = 274432 bytes | Created Date = 9/27/2007 6:57:22 PM | Attr = ]
hpzcoi12.dll -> %System32%\hpzcoi12.dll -> HP [Ver = 2.335.5.0 | Size = 196608 bytes | Created Date = 9/27/2007 6:57:13 PM | Attr = ]
hpzcon12.dll -> %System32%\hpzcon12.dll -> Hewlett-Packard Company [Ver = 2.335.5.0 | Size = 393216 bytes | Created Date = 9/27/2007 6:57:13 PM | Attr = ]
HPZidr12.dll -> %System32%\HPZidr12.dll -> HP [Ver = 9, 0, 0, 0 | Size = 278584 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
HPZinw12.exe -> %System32%\HPZinw12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 61440 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
HPZipm12.exe -> %System32%\HPZipm12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 69632 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
HPZipr12.dll -> %System32%\HPZipr12.dll -> HP [Ver = 9, 0, 0, 0 | Size = 204800 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
HPZipt12.dll -> %System32%\HPZipt12.dll -> HP [Ver = 9, 0, 0, 0 | Size = 94208 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
HPZisn12.dll -> %System32%\HPZisn12.dll -> HP [Ver = 9, 0, 0, 0 | Size = 57344 bytes | Created Date = 9/27/2007 6:58:59 PM | Attr = ]
hpzjsn01.dll -> %System32%\hpzjsn01.dll -> Hewlett Packard Company [Ver = 1, 0, 0, 3 | Size = 98304 bytes | Created Date = 9/27/2007 6:57:18 PM | Attr = ]
hpzsnt12.dll -> %System32%\hpzsnt12.dll -> HP [Ver = 14.00.00.41711 | Size = 180315 bytes | Created Date = 9/27/2007 6:57:13 PM | Attr = ]
msvcmm32.exe -> %System32%\msvcmm32.exe -> [Ver = | Size = 0 bytes | Created Date = 10/10/2007 8:13:08 PM | Attr = ]
Process.exe -> %System32%\Process.exe ->
http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
SrchSTS.exe -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.6 | Size = 139776 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 3958 bytes | Created Date = 10/22/2007 5:37:19 PM | Attr = ]
VCCLSID.exe -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
VFind.exe -> %System32%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 10/22/2007 5:44:21 PM | Attr = ]
WS2Fix.exe -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Created Date = 10/22/2007 5:36:41 PM | Attr = ]
apphelp.sdb -> %System32%\dllcache\apphelp.sdb -> [Ver = | Size = 217118 bytes | Created Date = 10/10/2007 8:17:06 PM | Attr = ]
apph_sp.sdb -> %System32%\dllcache\apph_sp.sdb -> [Ver = | Size = 764868 bytes | Created Date = 10/10/2007 8:17:06 PM | Attr = ]
sysmain.sdb -> %System32%\dllcache\sysmain.sdb -> [Ver = | Size = 1197294 bytes | Created Date = 10/10/2007 8:17:06 PM | Attr = ]
HPZid412.sys -> %System32%\drivers\HPZid412.sys -> HP [Ver = 9, 0, 0, 0 | Size = 51120 bytes | Created Date = 9/27/2007 6:58:03 PM | Attr = ]
HPZipr12.sys -> %System32%\drivers\HPZipr12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 16496 bytes | Created Date = 9/27/2007 6:58:03 PM | Attr = ]
HPZius12.sys -> %System32%\drivers\HPZius12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 21744 bytes | Created Date = 9/27/2007 6:58:03 PM | Attr = ]
UMDF -> %System32%\drivers\UMDF -> [Folder | Created Date = 10/10/2007 8:15:52 PM | Attr = ]
MsftWdf_user_01_00_00.Wdf -> %System32%\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Created Date = 10/10/2007 8:15:57 PM | Attr = H ]
[Files/Folders - Modified Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 10/23/2007 6:51:48 PM | Attr = RH ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 9/27/2007 8:01:02 PM | Attr = H ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 526438400 bytes | Modified Date = 10/22/2007 6:40:20 PM | Attr = HS]
hpqp.ini -> %SystemDrive%\hpqp.ini -> [Ver = | Size = 898 bytes | Modified Date = 10/22/2007 6:40:56 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 10/22/2007 4:28:38 PM | Attr = ]
qoobox -> %SystemDrive%\qoobox -> [Folder | Modified Date = 10/23/2007 6:48:10 PM | Attr = ]
Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 9/27/2007 7:57:02 PM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 10/23/2007 6:51:48 PM | Attr = ]
XP_TV.ini -> %SystemDrive%\XP_TV.ini -> [Ver = | Size = 39 bytes | Modified Date = 10/22/2007 6:40:32 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 10/10/2007 10:38:42 AM | Attr = H ]
$NtUninstallKB926239$ -> %SystemRoot%\$NtUninstallKB926239$ -> [Folder | Modified Date = 10/10/2007 9:17:18 PM | Attr = H ]
$NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Modified Date = 10/11/2007 10:28:32 PM | Attr = H ]
$NtUninstallKB933729$ -> %SystemRoot%\$NtUninstallKB933729$ -> [Folder | Modified Date = 10/10/2007 10:38:44 AM | Attr = H ]
$NtUninstallKB941202$ -> %SystemRoot%\$NtUninstallKB941202$ -> [Folder | Modified Date = 10/10/2007 10:38:08 AM | Attr = H ]
$NtUninstallWMFDist11$ -> %SystemRoot%\$NtUninstallWMFDist11$ -> [Folder | Modified Date = 10/10/2007 9:16:42 PM | Attr = H ]
$NtUninstallWudf01000$ -> %SystemRoot%\$NtUninstallWudf01000$ -> [Folder | Modified Date = 10/10/2007 9:15:46 PM | Attr = H ]
AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 10/10/2007 9:19:12 PM | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 10/22/2007 6:40:24 PM | Attr = S]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 136192 bytes | Modified Date = 10/20/2007 6:03:32 AM | Attr = ]
Downloaded Installations -> %SystemRoot%\Downloaded Installations -> [Folder | Modified Date = 9/27/2007 7:51:38 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 10/22/2007 4:23:32 PM | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 10/23/2007 6:47:30 PM | Attr = ]
hpoins05.dat -> %SystemRoot%\hpoins05.dat -> [Ver = | Size = 102262 bytes | Modified Date = 9/27/2007 8:01:12 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1393 bytes | Modified Date = 10/10/2007 9:17:24 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 10/11/2007 10:28:40 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 9/27/2007 8:01:02 PM | Attr = HS]
MegaMud.INI -> %SystemRoot%\MegaMud.INI -> [Ver = | Size = 422 bytes | Modified Date = 10/21/2007 8:43:02 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 10/23/2007 6:53:50 PM | Attr = ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 10/22/2007 6:40:54 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 10/22/2007 6:44:22 PM | Attr = ]
TEMP -> %SystemRoot%\TEMP -> [Folder | Modified Date = 10/23/2007 6:48:20 PM | Attr = ]
twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 9/27/2007 8:01:02 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 751 bytes | Modified Date = 10/21/2007 8:28:12 PM | Attr = ]
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 10/10/2007 9:16:56 PM | Attr = ]
xlavba3.exe -> %SystemRoot%\xlavba3.exe -> [Ver = | Size = 16384 bytes | Modified Date = 10/22/2007 4:13:22 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 10/22/2007 6:40:26 PM | Attr = H ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 10/23/2007 6:45:56 PM | Attr = ]
d3d9caps.dat -> %System32%\d3d9caps.dat -> [Ver = | Size = 664 bytes | Modified Date = 10/16/2007 7:44:04 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 10/10/2007 9:17:22 PM | Attr = RH ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 10/23/2007 6:45:26 PM | Attr = ]
LogFiles -> %System32%\LogFiles -> [Folder | Modified Date = 10/10/2007 9:15:54 PM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 3958 bytes | Modified Date = 10/22/2007 6:37:20 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 10/21/2007 2:49:08 PM | Attr = ]
WS2Fix.exe -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Modified Date = 10/4/2007 12:36:46 AM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 10/22/2007 4:28:56 PM | Attr = ]
UMDF -> %System32%\drivers\UMDF -> [Folder | Modified Date = 10/10/2007 9:16:50 PM | Attr = ]
MsftWdf_user_01_00_00.Wdf -> %System32%\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Modified Date = 10/10/2007 9:15:58 PM | Attr = H ]
[File String Scan - Non-Microsoft Only]
UPX! , UPX0 , -> %SystemRoot%\browser.exe -> [Ver = 2, 64, 0, 0 | Size = 43387 bytes | Modified Date = 6/22/2006 3:40:18 PM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 3/16/2006 6:00:00 AM | Attr = ]
PEC2 , PECompact2 , -> %System32%\DivX.dll -> DivXNetworks, Inc. [Ver = 5.2.1.1338 | Size = 716800 bytes | Modified Date = 9/21/2004 7:26:40 PM | Attr = ]
PTech , -> %System32%\LegitCheckControl.dll -> Microsoft Corp. [Ver = 1.5.0512.0 | Size = 550120 bytes | Modified Date = 2/14/2006 11:20:14 AM | Attr = ]
UPX! , UPX0 , -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Modified Date = 4/27/2006 5:49:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.6 | Size = 139776 bytes | Modified Date = 4/2/2007 2:21:28 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 1/9/2006 10:36:06 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Modified Date = 12/1/2006 6:20:34 AM | Attr = ]
UPX! , UPX0 , -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Modified Date = 9/6/2007 12:22:24 AM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 3/16/2006 6:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Modified Date = 10/4/2007 12:36:46 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.488 | Size = 821728 bytes | Modified Date = 9/21/2007 9:48:16 AM | Attr = ]
< End of report >