I finally finished copy and pasting the the first log scan. Yikes
Starting on the second one.
WinPFind3 logfile created on: 12/9/2007 8:31:47 AM
WinPFind3U by OldTimer - Version 1.0.44 Folder = C:\Documents and Settings\Charmi Keranen\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 7.0.5730.11)
1014.37 Mb Total Physical Memory | 499.13 Mb Available Physical Memory | 49.21% Memory free
2.38 Gb Paging File | 1.92 Gb Available in Paging File | 80.49% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 67.83 Gb Total Space | 15.35 Gb Free Space | 22.64% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Computer Name: CHARMILAPTOP
Current User Name: Charmi Keranen
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
aluschedulersvc.exe -> %ProgramFiles%\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
andreavc.exe -> %ProgramFiles%\Creative\VoiceCenter\AndreaVC.exe -> Andrea Electronics Corporation [Ver = 2, 1, 6, 0 | Size = 1118208 bytes | Modified Date = 2/16/2006 10:20:20 AM | Attr = ]
aolacsd.exe -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> America Online, Inc. [Ver = 2.0.20.1.US.1 | Size = 1135728 bytes | Modified Date = 4/7/2004 1:07:32 PM | Attr = ]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 12, 0, 0 | Size = 106496 bytes | Modified Date = 7/9/2007 5:46:50 PM | Attr = ]
aupdate.exe -> %ProgramFiles%\Symantec\LiveUpdate\AUPDATE.EXE -> Symantec Corporation [Ver = 3.0.0.154 | Size = 149184 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 4:25:42 AM | Attr = ]
bcmwltry.exe -> %System32%\BCMWLTRY.EXE -> Dell Inc. [Ver = 4.10.47.3 | Size = 1200128 bytes | Modified Date = 12/19/2005 4:08:40 PM | Attr = ]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\CCAPP.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 52840 bytes | Modified Date = 1/22/2007 9:19:26 PM | Attr = ]
ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\CCEVTMGR.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 192104 bytes | Modified Date = 1/22/2007 9:19:28 PM | Attr = ]
ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\CCSETMGR.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 169576 bytes | Modified Date = 1/22/2007 9:19:34 PM | Attr = ]
creativelicensing.exe -> %CommonProgramFiles%\Creative Labs Shared\Service\CreativeLicensing.exe -> Creative Labs [Ver = 2.65.010 | Size = 69632 bytes | Modified Date = 11/24/2006 8:10:38 PM | Attr = ]
crypserv.exe -> %System32%\Crypserv.exe -> CrypKey (Canada) Ltd. [Ver = 6.0 | Size = 61440 bytes | Modified Date = 7/18/2003 2:31:22 AM | Attr = ]
ctsvccda.exe -> %System32%\CTSVCCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/12/1999 6:01:00 PM | Attr = ]
ctsysvol.exe -> %ProgramFiles%\Creative\SBAudigy\Surround Mixer\CTSysVol.exe -> Creative Technology Ltd [Ver = 1.4.8.0 | Size = 57344 bytes | Modified Date = 10/31/2005 11:51:52 AM | Attr = ]
dsagnt.exe -> %ProgramFiles%\Dell Support\DSAgnt.exe -> Gteko Ltd. [Ver = 2, 1, 3, 176 | Size = 395776 bytes | Modified Date = 8/28/2006 10:57:12 PM | Attr = ]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 7:31:10 AM | Attr = ]
lucallbackproxy.exe -> %ProgramFiles%\Symantec\LiveUpdate\LuCallbackProxy.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
lucallbackproxy.exe -> %ProgramFiles%\Symantec\LiveUpdate\LuCallbackProxy.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
lucallbackproxy.exe -> %ProgramFiles%\Symantec\LiveUpdate\LuCallbackProxy.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
lucallbackproxy.exe -> %ProgramFiles%\Symantec\LiveUpdate\LuCallbackProxy.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
lucoms~1.exe -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_0.EXE -> Symantec Corporation [Ver = 3.0.0.154 | Size = 2041536 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
navapsvc.exe -> %ProgramFiles%\Norton AntiVirus\NAVAPSVC.EXE -> Symantec Corporation [Ver = 12.8.0.4 | Size = 139888 bytes | Modified Date = 5/23/2007 11:13:38 AM | Attr = ]
npfmntor.exe -> %ProgramFiles%\Norton AntiVirus\IWP\NPFMNTOR.EXE -> Symantec Corporation [Ver = 12.8.0.4 | Size = 46704 bytes | Modified Date = 5/23/2007 11:13:40 AM | Attr = ]
nscsrvce.exe -> %CommonProgramFiles%\Symantec Shared\Security Console\NSCSRVCE.EXE -> Symantec Corporation [Ver = 2006.1.8.2 | Size = 750720 bytes | Modified Date = 12/15/2006 1:36:28 PM | Attr = ]
pifsvc.exe -> %CommonProgramFiles%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -> Symantec Corporation [Ver = 1.2.0.18 | Size = 517768 bytes | Modified Date = 3/12/2007 5:30:16 PM | Attr = ]
sndsrvc.exe -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.8.804 | Size = 214408 bytes | Modified Date = 10/1/2007 2:50:08 PM | Attr = ]
spbbcsvc.exe -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.1.0.4 | Size = 1160848 bytes | Modified Date = 11/3/2005 8:06:22 PM | Attr = ]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 6, 0, 1000 | Size = 1310720 bytes | Modified Date = 2/27/2007 11:39:26 AM | Attr = ]
symlcsvc.exe -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> Symantec Corporation [Ver = 1.9.1.1080 | Size = 1174152 bytes | Modified Date = 7/14/2007 7:43:18 AM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.44.0 | Size = 371200 bytes | Modified Date = 11/21/2007 9:19:46 AM | Attr = ]
wltrysvc.exe -> %System32%\WLTRYSVC.EXE -> [Ver = | Size = 18944 bytes | Modified Date = 12/19/2005 4:08:42 PM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> America Online, Inc. [Ver = 2.0.20.1.US.1 | Size = 1135728 bytes | Modified Date = 4/7/2004 1:07:32 PM | Attr = ]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 12, 0, 0 | Size = 106496 bytes | Modified Date = 7/9/2007 5:46:50 PM | Attr = ]
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> Symantec Corporation [Ver = 3.0.0.154 | Size = 100032 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 7:31:10 AM | Attr = ]
(ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCEVTMGR.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 192104 bytes | Modified Date = 1/22/2007 9:19:28 PM | Attr = ]
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCSETMGR.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 169576 bytes | Modified Date = 1/22/2007 9:19:34 PM | Attr = ]
(Creative Labs Licensing Service) Creative Labs Licensing Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Creative Labs Shared\Service\CreativeLicensing.exe -> Creative Labs [Ver = 2.65.010 | Size = 69632 bytes | Modified Date = 11/24/2006 8:10:38 PM | Attr = ]
(Creative Service for CDROM Access) Creative Service for CDROM Access [Win32_Own | Auto | Running] -> %System32%\CTSVCCDA.EXE -> Creative Technology Ltd [Ver = 1.0.1.0 | Size = 44032 bytes | Modified Date = 12/12/1999 6:01:00 PM | Attr = ]
(Crypkey License) Crypkey License [Win32_Own | Auto | Running] -> %System32%\Crypserv.exe -> CrypKey (Canada) Ltd. [Ver = 6.0 | Size = 61440 bytes | Modified Date = 7/18/2003 2:31:22 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/10/2004 6:00:00 AM | Attr = ]
(DMService) Whale Component Manager [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Downloaded Program Files\DMService.exe -> [Ver = | Size = 423576 bytes | Modified Date = 10/15/2007 7:50:18 AM | Attr = ]
(GoogleDesktopManager) GoogleDesktopManager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopManager.exe -> Google [Ver = 5.0.610.1586 | Size = 86528 bytes | Modified Date = 11/24/2006 8:21:24 PM | Attr = ]
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 2/1/2007 6:51:38 PM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.3.1.3 | Size = 501048 bytes | Modified Date = 7/10/2007 8:18:14 AM | Attr = ]
(LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_0.EXE -> Symantec Corporation [Ver = 3.0.0.154 | Size = 2041536 bytes | Modified Date = 1/19/2006 11:29:54 AM | Attr = ]
(LiveUpdate Notice Service) LiveUpdate Notice Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -> Symantec Corporation [Ver = 1.2.0.18 | Size = 517768 bytes | Modified Date = 3/12/2007 5:30:16 PM | Attr = ]
(navapsvc) Norton AntiVirus Auto-Protect Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Norton AntiVirus\NAVAPSVC.EXE -> Symantec Corporation [Ver = 12.8.0.4 | Size = 139888 bytes | Modified Date = 5/23/2007 11:13:38 AM | Attr = ]
(NPFMntor) Norton AntiVirus Firewall Monitor Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Norton AntiVirus\IWP\NPFMNTOR.EXE -> Symantec Corporation [Ver = 12.8.0.4 | Size = 46704 bytes | Modified Date = 5/23/2007 11:13:40 AM | Attr = ]
(NSCService) Norton Protection Center Service [Win32_Own | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\Security Console\NSCSRVCE.EXE -> Symantec Corporation [Ver = 2006.1.8.2 | Size = 750720 bytes | Modified Date = 12/15/2006 1:36:28 PM | Attr = ]
(SAVScan) Symantec AVScan [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Norton AntiVirus\SAVScan.exe -> Symantec Corporation [Ver = 9.7.1.4 | Size = 198416 bytes | Modified Date = 12/19/2005 8:41:56 PM | Attr = ]
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.8.804 | Size = 214408 bytes | Modified Date = 10/1/2007 2:50:08 PM | Attr = ]
(SPBBCSvc) SPBBCSvc [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.1.0.4 | Size = 1160848 bytes | Modified Date = 11/3/2005 8:06:22 PM | Attr = ]
(SwiWiFiComm) SwiWiFiComm [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Sierra Wireless\AirCard 580\Verizon\Components\swiwificomm.exe -> File not found
(Symantec Core LC) Symantec Core LC [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> Symantec Corporation [Ver = 1.9.1.1080 | Size = 1174152 bytes | Modified Date = 7/14/2007 7:43:18 AM | Attr = ]
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %System32%\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe -> File not found
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 4:25:42 AM | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\CCAPP.EXE -> Symantec Corporation [Ver = 104.0.14.2 | Size = 52840 bytes | Modified Date = 1/22/2007 9:19:26 PM | Attr = ]
CTSysVol -> %ProgramFiles%\Creative\SBAudigy\Surround Mixer\CTSysVol.exe -> Creative Technology Ltd [Ver = 1.4.8.0 | Size = 57344 bytes | Modified Date = 10/31/2005 11:51:52 AM | Attr = ]
MSKDetectorExe -> %ProgramFiles%\McAfee\SpamKiller\MSKDetct.exe -> McAfee, Inc. [Ver = 7.0.1.3 | Size = 1117184 bytes | Modified Date = 7/12/2005 8:05:30 PM | Attr = ]
VoiceCenter -> %ProgramFiles%\Creative\VoiceCenter\AndreaVC.exe -> Andrea Electronics Corporation [Ver = 2, 1, 6, 0 | Size = 1118208 bytes | Modified Date = 2/16/2006 10:20:20 AM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
DellSupport -> %ProgramFiles%\Dell Support\DSAgnt.exe -> Gteko Ltd. [Ver = 2, 1, 3, 176 | Size = 395776 bytes | Modified Date = 8/28/2006 10:57:12 PM | Attr = ]
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 6, 0, 1000 | Size = 1310720 bytes | Modified Date = 2/27/2007 11:39:26 AM | Attr = ]
< AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> Google [Ver = 5.0.610.1586 | Size = 164864 bytes | Modified Date = 11/24/2006 8:21:24 PM | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 7:29:58 AM | Attr = ]
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKLM] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 12/20/2006 12:55:48 PM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
!SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 282624 bytes | Modified Date = 2/27/2007 11:39:26 AM | Attr = ]
igfxcui -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4446 | Size = 139264 bytes | Modified Date = 12/13/2005 10:40:12 AM | Attr = ]
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\LinkResolveIgnoreLinkInfo -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoResolveSearch -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallVisualStyle -> C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallTheme -> C:\WINDOWS\Resources\Themes\Royale.theme ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\\NoResolveTrack -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\LinkResolveIgnoreLinkInfo -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\Shell\ -> ->
< HOSTS File > (213799 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL ->
http://www.microsoft...p...&ar=msnhome ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> C:\windows\system32\blank.htm ->
HKLM: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Start Page ->
http://www.microsoft...p...ER}&ar=home ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: Search\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Local Page -> C:\windows\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page ->
http://www.microsoft...p...&ar=msnhome ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.7.2006011200 | Size = 63128 bytes | Modified Date = 1/12/2006 9:38:22 PM | Attr = ]
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 5, 0, 8 | Size = 1122128 bytes | Modified Date = 8/31/2007 4:46:14 PM | Attr = ]
{5CA3D70E-1895-11CF-8E15-001234567890} [HKLM] -> %System32%\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.08a | Size = 118842 bytes | Modified Date = 12/6/2004 2:05:00 AM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 11/10/2005 2:22:12 PM | Attr = ]
{7E745F86-6B67-45D3-922A-878167A9D258} [HKLM] -> %SystemRoot%\werbetnor.dll [MSVPS System] -> File not found
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} [HKLM] -> %ProgramFiles%\Norton AntiVirus\NAVSHEXT.DLL [CNavExtBho Class] -> Symantec Corporation [Ver = 12.8.0.4 | Size = 140912 bytes | Modified Date = 5/23/2007 11:13:40 AM | Attr = ]
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 2/1/2007 6:51:38 PM | Attr = R ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 2/1/2007 6:51:38 PM | Attr = R ]
{C4069E3A-68F1-403E-B40E-20066696354B} [HKLM] -> %ProgramFiles%\Norton AntiVirus\NAVSHEXT.DLL [Norton AntiVirus] -> Symantec Corporation [Ver = 12.8.0.4 | Size = 140912 bytes | Modified Date = 5/23/2007 11:13:40 AM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar2.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 2/1/2007 6:51:38 PM | Attr = R ]
WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKLM] -> %ProgramFiles%\Norton AntiVirus\NAVSHEXT.DLL [Norton AntiVirus] -> Symantec Corporation [Ver = 12.8.0.4 | Size = 140912 bytes | Modified Date = 5/23/2007 11:13:40 AM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Modified Date = 11/10/2005 2:22:12 PM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 11/10/2005 2:22:12 PM | Attr = ]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> Reg Data - Value does not exist [ButtonText: Research] -> File not found
{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -> Reg Data - Value does not exist [ButtonText: Real.com] -> File not found
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [MenuText: Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 8 | Size = 1122128 bytes | Modified Date = 8/31/2007 4:46:14 PM | Attr = ]
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> -> File not found
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{0D8CE5C9-37FE-474C-9147-EA9431BE4AB5} -> (Broadcom 440x 10/100 Integrated Controller) ->
{60387882-7971-4D15-9D9B-B7869C42937D} -> (Dell Wireless 1390 WLAN Mini-Card) ->
{650BC190-77E2-447B-B175-F0CDDA1045F4} -> () ->
{6729C033-A820-4D17-84B1-0E84D0492AE2} -> (1394 Net Adapter) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase =
http://download.macr...director/sw.cab ->
{5F8469B4-B055-49DD-83F7-62B522420ECC} -> Facebook Photo Uploader Control - CodeBase =
http://upload.facebo...otoUploader.cab ->
{6A344D34-5231-452A-8A57-D064AC9B7862} -> Symantec Download Manager - CodeBase =
https://webdl.symant...ex/symdlmgr.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{8D9563A9-8D5F-459B-87F2-BA842255CB9A} -> Whale Client Components - CodeBase =
https://mymail.ul.co.../WhlCompMgr.cab ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -> - CodeBase =
http://fpdownload.ma...t/ultrashim.cab ->
{917623D1-D8E5-11D2-BE8B-00104B06BDE3} -> CamImage Class - CodeBase =
http://webcams.mtu.e...sCamControl.ocx ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
[Registry - Additional Scans - Non-Microsoft Only]
[Files/Folders - Created Within 30 days]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1063714816 bytes | Created Date = 1/1/1601 5:00:00 AM | Attr = HS]
$NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Created Date = 11/15/2007 7:16:35 AM | Attr = H ]
mozver.dat -> %SystemRoot%\mozver.dat -> [Ver = | Size = 1156 bytes | Created Date = 12/1/2007 11:29:18 AM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 11/29/2007 8:48:29 PM | Attr = ]
unvise32.exe -> %SystemRoot%\unvise32.exe -> MindVision Software [Ver = 3.1.1 | Size = 86016 bytes | Created Date = 11/25/2007 12:50:37 PM | Attr = ]
WMPrfAra.prx -> %SystemRoot%\WMPrfAra.prx -> [Ver = | Size = 33336 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
WMPrfCHS.prx -> %SystemRoot%\WMPrfCHS.prx -> [Ver = | Size = 19492 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
WMPrfCHT.prx -> %SystemRoot%\WMPrfCHT.prx -> [Ver = | Size = 18804 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfcsy.prx -> %SystemRoot%\wmprfcsy.prx -> [Ver = | Size = 35474 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfdan.prx -> %SystemRoot%\wmprfdan.prx -> [Ver = | Size = 31712 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
WMPrfDeu.prx -> %SystemRoot%\WMPrfDeu.prx -> [Ver = | Size = 33820 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfell.prx -> %SystemRoot%\wmprfell.prx -> [Ver = | Size = 36594 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfesp.prx -> %SystemRoot%\wmprfesp.prx -> [Ver = | Size = 35590 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprffin.prx -> %SystemRoot%\wmprffin.prx -> [Ver = | Size = 31764 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprffra.prx -> %SystemRoot%\wmprffra.prx -> [Ver = | Size = 37916 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfheb.prx -> %SystemRoot%\wmprfheb.prx -> [Ver = | Size = 28718 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfhun.prx -> %SystemRoot%\wmprfhun.prx -> [Ver = | Size = 37014 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
wmprfita.prx -> %SystemRoot%\wmprfita.prx -> [Ver = | Size = 35680 bytes | Created Date = 11/25/2007 12:46:38 PM | Attr = ]
WMPrfJpn.prx -> %SystemRoot%\WMPrfJpn.prx -> [Ver = | Size = 23304 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
WMPrfKor.prx -> %SystemRoot%\WMPrfKor.prx -> [Ver = | Size = 22338 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfnld.prx -> %SystemRoot%\wmprfnld.prx -> [Ver = | Size = 32964 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfnor.prx -> %SystemRoot%\wmprfnor.prx -> [Ver = | Size = 32852 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfplk.prx -> %SystemRoot%\wmprfplk.prx -> [Ver = | Size = 35822 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfptb.prx -> %SystemRoot%\wmprfptb.prx -> [Ver = | Size = 33694 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfptg.prx -> %SystemRoot%\wmprfptg.prx -> [Ver = | Size = 35916 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfrus.prx -> %SystemRoot%\wmprfrus.prx -> [Ver = | Size = 35306 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfsky.prx -> %SystemRoot%\wmprfsky.prx -> [Ver = | Size = 38232 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfslv.prx -> %SystemRoot%\wmprfslv.prx -> [Ver = | Size = 33580 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprfsve.prx -> %SystemRoot%\wmprfsve.prx -> [Ver = | Size = 33314 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
wmprftrk.prx -> %SystemRoot%\wmprftrk.prx -> [Ver = | Size = 32022 bytes | Created Date = 11/25/2007 12:46:39 PM | Attr = ]
Aviprax.dll -> %System32%\Aviprax.dll -> Pinnacle Systems GmbH [Ver = 4.3.133 | Size = 114759 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
Cachex.dll -> %System32%\Cachex.dll -> Pinnacle Systems GmbH [Ver = 4.3.195 | Size = 32838 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
DiskIO.dll -> %System32%\DiskIO.dll -> Pinnacle Systems GmbH [Ver = 6.0.299 | Size = 204881 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
dumphive.exe -> %System32%\dumphive.exe -> [Ver = | Size = 51200 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
langserv.dll -> %System32%\langserv.dll -> Pinnacle Systems GmbH [Ver = 2.3.198 | Size = 40960 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lfbmp13s.dll -> %System32%\lfbmp13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 70144 bytes | Created Date = 11/25/2007 12:52:52 PM | Attr = ]
LFCMP13s.DLL -> %System32%\LFCMP13s.DLL -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 409600 bytes | Created Date = 11/25/2007 12:52:52 PM | Attr = ]
lffax13n.dll -> %System32%\lffax13n.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 73216 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lffax13s.dll -> %System32%\lffax13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 116224 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
LFJ2K13s.dll -> %System32%\LFJ2K13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 283648 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lfpct13s.dll -> %System32%\lfpct13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 105984 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lftga13s.dll -> %System32%\lftga13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 64512 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lftif13s.dll -> %System32%\lftif13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 167936 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
lfwmf13s.dll -> %System32%\lfwmf13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 80896 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
LTCLR13n.dll -> %System32%\LTCLR13n.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.047 | Size = 1684992 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
LTCLR13s.dll -> %System32%\LTCLR13s.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.038 | Size = 2079232 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
ltkrn13n.dll -> %System32%\ltkrn13n.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 445952 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
Ltr13n.dll -> %System32%\Ltr13n.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 930992 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
Ltrio13n.dll -> %System32%\Ltrio13n.dll -> LEAD Technologies, Inc. [Ver = 13.0.0.053 | Size = 306352 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
miroDV2Bmp.dll -> %System32%\miroDV2Bmp.dll -> Pinnacle System GmbH [Ver = 1, 0, 0, 0 | Size = 60416 bytes | Created Date = 11/25/2007 12:52:52 PM | Attr = ]
MLPagAx.dll -> %System32%\MLPagAx.dll -> Pinnacle Systems GmbH [Ver = 1.2.113 | Size = 32768 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
MMAviAx.dll -> %System32%\MMAviAx.dll -> Pinnacle Systems GmbH [Ver = 4.3.83 | Size = 73728 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
PCLEGetGuid.dll -> %System32%\PCLEGetGuid.dll -> Pinnacle Systems [Ver = 2, 0, 0, 2 | Size = 49152 bytes | Created Date = 11/25/2007 12:52:52 PM | Attr = ]
pclepim1.dll -> %System32%\pclepim1.dll -> Pinnacle Systems [Ver = 2.00 | Size = 61440 bytes | Created Date = 11/25/2007 12:52:53 PM | Attr = ]
Process.exe -> %System32%\Process.exe ->
http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
pvmjpg21.dll -> %System32%\pvmjpg21.dll -> Pegasus Imaging Corporation [Ver = 2.10.0.25 | Size = 294912 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
RALMain.dll -> %System32%\RALMain.dll -> Pinnacle Systems GmbH [Ver = 1.3.160 | Size = 155721 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
SrchSTS.exe -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 1938 bytes | Created Date = 12/9/2007 8:18:46 AM | Attr = ]
VCCLSID.exe -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
vdrcodec.dll -> %System32%\vdrcodec.dll -> Pinnacle Systems [Ver = 1.00 | Size = 46592 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
vdrmux.dll -> %System32%\vdrmux.dll -> Pinnacle Systems [Ver = 1, 0, 0, 0 | Size = 81920 bytes | Created Date = 11/25/2007 12:52:54 PM | Attr = ]
WS2Fix.exe -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Created Date = 12/9/2007 8:16:14 AM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Created Date = 12/8/2007 7:57:46 PM | Attr = ]
Pclepci.sys -> %System32%\drivers\Pclepci.sys -> Pinnacle Systems GmbH [Ver = 1.06 | Size = 14165 bytes | Created Date = 11/25/2007 11:11:09 AM | Attr = ]
pfc.sys -> %System32%\drivers\pfc.sys -> Padus, Inc. [Ver = 2, 5, 0, 200 | Size = 14604 bytes | Created Date = 11/25/2007 12:47:38 PM | Attr = ]
hosts.20071129-191345.backup -> %System32%\drivers\etc\hosts.20071129-191345.backup -> [Ver = | Size = 734 bytes | Created Date = 11/29/2007 7:13:45 PM | Attr = ]
[Files/Folders - Modified Within 30 days]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1063714816 bytes | Modified Date = 12/9/2007 8:26:20 AM | Attr = HS]
MDT -> %SystemDrive%\MDT -> [Folder | Modified Date = 12/1/2007 10:30:38 AM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 12/9/2007 8:18:48 AM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 12/6/2007 9:33:08 PM | Attr = HS]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 12/9/2007 8:26:42 AM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 11/15/2007 7:16:06 AM | Attr = H ]
$NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Modified Date = 11/15/2007 7:16:38 AM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 12/9/2007 8:26:22 AM | Attr = S]
CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 11/25/2007 2:34:36 PM | Attr = HS]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 11/19/2007 4:05:38 PM | Attr = S]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 11/25/2007 12:52:54 PM | Attr = R S]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 11/29/2007 12:47:36 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 11/25/2007 12:58:36 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 12/8/2007 10:04:28 PM | Attr = HS]
mozver.dat -> %SystemRoot%\mozver.dat -> [Ver = | Size = 1156 bytes | Modified Date = 12/1/2007 11:29:20 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 12/9/2007 8:30:02 AM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 11/29/2007 8:48:30 PM | Attr = ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 12/9/2007 8:26:42 AM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 12/9/2007 8:18:48 AM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 11/27/2007 8:17:54 PM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 12/9/2007 8:26:58 AM | Attr = ]
wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 343 bytes | Modified Date = 11/27/2007 8:42:02 PM | Attr = ]
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 11/25/2007 12:47:14 PM | Attr = ]
AdwareAlert Scheduled Scan.job -> %SystemRoot%\tasks\AdwareAlert Scheduled Scan.job -> [Ver = | Size = 514 bytes | Modified Date = 11/22/2007 3:00:02 AM | Attr = ]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 11/23/2007 12:04:02 PM | Attr = ]
Norton AntiVirus - Run Full System Scan - Charmi Keranen.job -> %SystemRoot%\tasks\Norton AntiVirus - Run Full System Scan - Charmi Keranen.job -> [Ver = | Size = 548 bytes | Modified Date = 11/23/2007 8:00:02 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 12/9/2007 8:26:30 AM | Attr = H ]
User_Feed_Synchronization-{0870BE56-A051-4E7E-95EC-ABCB21430483}.job -> %SystemRoot%\tasks\User_Feed_Synchronization-{0870BE56-A051-4E7E-95EC-ABCB21430483}.job -> [Ver = | Size = 440 bytes | Modified Date = 12/9/2007 8:30:02 AM | Attr = H ]
CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 11/25/2007 12:47:08 PM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 12/8/2007 11:38:16 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 11/25/2007 1:05:26 PM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 12/8/2007 7:57:48 PM | Attr = ]
DRVSTORE -> %System32%\DRVSTORE -> [Folder | Modified Date = 11/27/2007 8:17:54 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 280536 bytes | Modified Date = 11/25/2007 12:55:42 PM | Attr = ]
FxsTmp -> %System32%\FxsTmp -> [Folder | Modified Date = 11/30/2007 7:48:06 AM | Attr = ]
ias -> %System32%\ias -> [Folder | Modified Date = 12/9/2007 8:26:58 AM | Attr = ]
Macromed -> %System32%\Macromed -> [Folder | Modified Date = 11/20/2007 6:34:38 AM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 12/6/2007 9:33:08 PM | Attr = ]
S32EVNT1.DLL -> %System32%\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.5.2.2 | Size = 60800 bytes | Modified Date = 11/29/2007 7:04:28 PM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 1938 bytes | Modified Date = 12/9/2007 8:18:48 AM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 12/9/2007 8:26:58 AM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 11/29/2007 7:13:46 PM | Attr = ]
SYMEVENT.CAT -> %System32%\drivers\SYMEVENT.CAT -> [Ver = | Size = 10740 bytes | Modified Date = 11/29/2007 7:04:28 PM | Attr = ]
SYMEVENT.INF -> %System32%\drivers\SYMEVENT.INF -> [Ver = | Size = 805 bytes | Modified Date = 11/29/2007 7:04:28 PM | Attr = ]
SYMEVENT.SYS -> %System32%\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.5.2.1 | Size = 123952 bytes | Modified Date = 11/29/2007 7:04:28 PM | Attr = ]
[File String Scan - Non-Microsoft Only]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %SystemDrive%\rapport.txt -> [Ver = | Size = 215515 bytes | Modified Date = 12/9/2007 8:22:16 AM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/10/2004 6:00:00 AM | Attr = ]
Thawte Consulting , -> %System32%\Px.dll -> Sonic Solutions [Ver = 3.0.88.500 | Size = 452264 bytes | Modified Date = 8/24/2006 1:33:36 PM | Attr = ]
Thawte Consulting , -> %System32%\pxcpya64.exe -> Sonic Solutions [Ver = 1.00.35a | Size = 63144 bytes | Modified Date = 8/24/2006 1:33:36 PM | Attr = ]
Thawte Consulting , -> %System32%\pxcpyi64.exe -> Sonic Solutions [Ver = 1.00.35a | Size = 114856 bytes | Modified Date = 8/24/2006 1:33:36 PM | Attr = ]
Thawte Consulting , -> %System32%\pxdrv.dll -> Sonic Solutions [Ver = 1.01.88a | Size = 472744 bytes | Modified Date = 8/24/2006 1:33:36 PM | Attr = ]
Thawte Consulting , -> %System32%\pxhpinst.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 67240 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
Thawte Consulting , -> %System32%\pxinsa64.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 62632 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
Thawte Consulting , -> %System32%\pxinsi64.exe -> Sonic Solutions [Ver = 3.00.33a | Size = 115880 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
Thawte Consulting , -> %System32%\PxMas.dll -> Sonic Solutions [Ver = 3.0.88.500 | Size = 181928 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
Thawte Consulting , -> %System32%\PxSFS.DLL -> Sonic Solutions [Ver = 3.0.88.500 | Size = 1279656 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
Thawte Consulting , -> %System32%\PxWave.dll -> Sonic Solutions [Ver = 3.0.88.500 | Size = 345768 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
UPX! , UPX0 , -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Modified Date = 4/27/2006 4:49:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Modified Date = 8/29/2006 6:43:54 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 1/9/2006 9:36:06 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Modified Date = 12/1/2006 5:20:34 AM | Attr = ]
UPX! , UPX0 , -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Modified Date = 9/5/2007 11:22:24 PM | Attr = ]
Thawte Consulting , -> %System32%\VXBLOCK.dll -> Sonic Solutions [Ver = 1.00.69a | Size = 38568 bytes | Modified Date = 8/24/2006 1:33:38 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/10/2004 6:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Modified Date = 10/3/2007 11:36:46 PM | Attr = ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts -> [Ver = | Size = 213799 bytes | Modified Date = 12/9/2007 8:18:44 AM | Attr = ]
< End of report >