WinPFind35 logfile created on: 1/29/2008 9:11:14 PM
WinPFind35U Version Beta40 Folder = C:\Documents and Settings\Original\Desktop\WinPFind35u
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
1015.36 Mb Total Physical Memory | 478.98 Mb Available Physical Memory | 47.17% Memory free
2.39 Gb Paging File | 1.91 Gb Available in Paging File | 79.92% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.81 Gb Total Space | 7.45 Gb Free Space | 13.35% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Computer Name: TREY-HAGINS
Current User Name: Original
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
[Processes - Non-Microsoft Only]
smc.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Smc.exe -> Symantec Corporation [Ver = 11.0.780.980 | Size = 2532736 bytes | Modified Date = 9/7/2007 10:33:32 PM | Attr = ]
ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.3.16 | Size = 108392 bytes | Modified Date = 8/6/2007 3:08:06 AM | Attr = ]
wltrysvc.exe -> %System32%\WLTRYSVC.EXE -> [Ver = | Size = 65536 bytes | Modified Date = 12/6/2004 7:45:14 PM | Attr = ]
bcmwltry.exe -> %System32%\BCMWLTRY.EXE -> Dell Inc [Ver = 3.100.41.0 | Size = 872556 bytes | Modified Date = 12/6/2004 7:45:12 PM | Attr = ]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ]
basfipm.exe -> %System32%\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.4 | Size = 77824 bytes | Modified Date = 4/1/2004 5:05:48 PM | Attr = ]
iap.exe -> %ProgramFiles%\Dell\OpenManage\Client\Iap.exe -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 155648 bytes | Modified Date = 2/13/2004 9:47:02 AM | Attr = ]
nicconfigsvc.exe -> %ProgramFiles%\Dell\NicConfigSvc\NicConfigSvc.exe -> Dell Inc. [Ver = 1, 0, 0, 1 | Size = 356352 bytes | Modified Date = 3/3/2005 10:29:02 PM | Attr = ]
rtvscan.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> Symantec Corporation [Ver = 11.0.777.1008 | Size = 2177464 bytes | Modified Date = 9/6/2007 3:55:38 AM | Attr = ]
spysweeper.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,3,1,2592 | Size = 3376704 bytes | Modified Date = 1/25/2007 9:58:50 PM | Attr = ]
smcgui.exe -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\SmcGui.exe -> Symantec Corporation [Ver = 11.0.780.980 | Size = 1635712 bytes | Modified Date = 9/7/2007 10:33:34 PM | Attr = ]
apoint.exe -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Modified Date = 9/13/2004 3:33:20 PM | Attr = ]
wltray.exe -> %System32%\WLTRAY.EXE -> Dell Inc [Ver = 3.100.41.0 | Size = 696425 bytes | Modified Date = 12/6/2004 7:45:14 PM | Attr = ]
dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 4/26/2004 7:04:14 AM | Attr = ]
tfswctrl.exe -> %System32%\dla\tfswctrl.exe -> Sonic Solutions [Ver = 1.04.08a | Size = 127035 bytes | Modified Date = 12/6/2004 12:05:00 AM | Attr = ]
hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4020 | Size = 126976 bytes | Modified Date = 2/15/2005 8:02:56 AM | Attr = ]
apntex.exe -> %ProgramFiles%\Apoint\ApntEx.exe -> Alps Electric Co., Ltd. [Ver = 5.5.1.19 | Size = 45056 bytes | Modified Date = 8/19/2004 1:40:08 PM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 6/29/2007 5:24:52 AM | Attr = ]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 267064 bytes | Modified Date = 9/26/2007 1:42:04 PM | Attr = ]
motivesb.exe -> %ProgramFiles%\ALLTEL DSL Check-up Center\SmartBridge\MotiveSB.exe -> Motive Communications, Inc. [Ver = 5.8.10.asst_classic.smartbridge.20041013_160000 | Size = 393216 bytes | Modified Date = 11/9/2004 10:32:44 AM | Attr = ]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 106.3.3.16 | Size = 115560 bytes | Modified Date = 8/6/2007 3:08:40 AM | Attr = ]
spysweeperui.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,3,1,2344 | Size = 4865600 bytes | Modified Date = 1/25/2007 9:58:38 PM | Attr = ]
googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 7/28/2007 8:50:24 PM | Attr = ]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr = ]
ymsgr_tray.exe -> %ProgramFiles%\Yahoo!\Messenger\Ymsgr_tray.exe -> Yahoo! Inc. [Ver = 8,1,0,0 | Size = 103664 bytes | Modified Date = 8/30/2007 4:43:18 PM | Attr = ]
reader_sl.exe -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 29696 bytes | Modified Date = 12/14/2004 3:44:06 AM | Attr = ]
tosbtmng1.exe -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe -> [Ver = | Size = 45056 bytes | Modified Date = 12/22/2004 12:42:22 PM | Attr = ]
pnagent.exe -> %ProgramFiles%\Citrix\ICA Client\pnagent.exe -> Citrix Systems, Inc. [Ver = 9.200.44376 | Size = 233744 bytes | Modified Date = 5/2/2006 6:22:30 PM | Attr = ]
mpbtn.exe -> %ProgramFiles%\ALLTEL DSL Check-up Center\bin\mpbtn.exe -> [Ver = | Size = 192512 bytes | Modified Date = 3/16/2004 5:49:50 PM | Attr = ]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 503608 bytes | Modified Date = 9/26/2007 1:41:56 PM | Attr = ]
ssu.exe -> %ProgramFiles%\Webroot\Spy Sweeper\ssu.exe -> [Ver = | Size = 168512 bytes | Modified Date = 1/25/2007 9:58:46 PM | Attr = ]
winpfind35u.exe -> %UserDesktop%\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 307200 bytes | Modified Date = 1/29/2008 11:17:26 AM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ]
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Stopped] -> %System32%\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4107 | Size = 405504 bytes | Modified Date = 12/4/2004 2:32:34 AM | Attr = ]
(BAsfIpM) Broadcom ASF IP monitoring service v6.0.4 [Win32_Own | Auto | Running] -> %System32%\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.4 | Size = 77824 bytes | Modified Date = 4/1/2004 5:05:48 PM | Attr = ]
(ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.3.16 | Size = 108392 bytes | Modified Date = 8/6/2007 3:08:06 AM | Attr = ]
(ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.3.16 | Size = 108392 bytes | Modified Date = 8/6/2007 3:08:06 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 4:00:00 AM | Attr = ]
(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 1/27/2007 2:01:52 PM | Attr = ]
(Iap) Iap [Win32_Own | Auto | Running] -> %ProgramFiles%\Dell\OpenManage\Client\Iap.exe -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 155648 bytes | Modified Date = 2/13/2004 9:47:02 AM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1050\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 10.50.125 | Size = 73728 bytes | Modified Date = 10/22/2004 2:24:18 AM | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 503608 bytes | Modified Date = 9/26/2007 1:41:56 PM | Attr = ]
(LVSrvLauncher) LVSrvLauncher [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Logitech\SrvLnch\SrvLnch.exe -> Logitech Inc. [Ver = 10.4.0.1401 | Size = 101152 bytes | Modified Date = 11/15/2006 10:05:40 PM | Attr = ]
(NICCONFIGSVC) NICCONFIGSVC [Win32_Own | Auto | Running] -> %ProgramFiles%\Dell\NicConfigSvc\NicConfigSvc.exe -> Dell Inc. [Ver = 1, 0, 0, 1 | Size = 356352 bytes | Modified Date = 3/3/2005 10:29:02 PM | Attr = ]
(SmcService) Symantec Management Client [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Smc.exe -> Symantec Corporation [Ver = 11.0.780.980 | Size = 2532736 bytes | Modified Date = 9/7/2007 10:33:32 PM | Attr = ]
(SNAC) Symantec Network Access Control [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\SNAC.EXE -> Symantec Corporation [Ver = 11.0.780.980 | Size = 234888 bytes | Modified Date = 9/7/2007 10:35:04 PM | Attr = ]
(Symantec AntiVirus) Symantec Endpoint Protection [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\Symantec Endpoint Protection\Rtvscan.exe -> Symantec Corporation [Ver = 11.0.777.1008 | Size = 2177464 bytes | Modified Date = 9/6/2007 3:55:38 AM | Attr = ]
(WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Auto | Running] -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,3,1,2592 | Size = 3376704 bytes | Modified Date = 1/25/2007 9:58:50 PM | Attr = ]
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %System32%\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe -> File not found
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
Apoint -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.141 | Size = 155648 bytes | Modified Date = 9/13/2004 3:33:20 PM | Attr = ]
ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.14.10.5125 | Size = 344064 bytes | Modified Date = 12/3/2004 8:00:00 PM | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 106.3.3.16 | Size = 115560 bytes | Modified Date = 8/6/2007 3:08:40 AM | Attr = ]
Dell Wireless Manager UI -> %System32%\WLTRAY.EXE -> Dell Inc [Ver = 3.100.41.0 | Size = 696425 bytes | Modified Date = 12/6/2004 7:45:14 PM | Attr = ]
dla -> %System32%\dla\tfswctrl.exe -> Sonic Solutions [Ver = 1.04.08a | Size = 127035 bytes | Modified Date = 12/6/2004 12:05:00 AM | Attr = ]
DVDLauncher -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 4/26/2004 7:04:14 AM | Attr = ]
HotKeysCmds -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4020 | Size = 126976 bytes | Modified Date = 2/15/2005 8:02:56 AM | Attr = ]
IgfxTray -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4020 | Size = 155648 bytes | Modified Date = 2/15/2005 8:02:58 AM | Attr = ]
ISUSPM Startup -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe -> InstallShield Software Corporation [Ver = 3, 20, 100, 1123 | Size = 221184 bytes | Modified Date = 8/9/2004 5:03:58 AM | Attr = ]
ISUSScheduler -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> InstallShield Software Corporation [Ver = 3, 20, 100, 1123 | Size = 81920 bytes | Modified Date = 8/9/2004 5:03:38 AM | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.4.3.1 | Size = 267064 bytes | Modified Date = 9/26/2007 1:42:04 PM | Attr = ]
Motive SmartBridge -> %ProgramFiles%\ALLTEL DSL Check-up Center\SmartBridge\MotiveSB.exe -> Motive Communications, Inc. [Ver = 5.8.10.asst_classic.smartbridge.20041013_160000 | Size = 393216 bytes | Modified Date = 11/9/2004 10:32:44 AM | Attr = ]
NeroFilterCheck -> %System32%\NeroCheck.exe -> Ahead Software Gmbh [Ver = 1, 0, 0, 2 | Size = 155648 bytes | Modified Date = 7/9/2001 9:50:42 AM | Attr = ]
NoteBurner -> %ProgramFiles%\NoteBurner\VTBurnerGUI.exe -> File not found
PDF4 Registry Controller -> %ProgramFiles%\ScanSoft\PDF Professional 4.0\RegistryController.exe -> Nuance Communications, Inc. [Ver = 4.0.6422.2 | Size = 40960 bytes | Modified Date = 8/22/2006 6:09:54 PM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 6/29/2007 5:24:52 AM | Attr = ]
SpySweeper -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,3,1,2344 | Size = 4865600 bytes | Modified Date = 1/25/2007 9:58:38 PM | Attr = ]
SSBkgdUpdate -> %CommonProgramFiles%\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe -> Scansoft, Inc. [Ver = 1, 0, 0, 6 | Size = 155648 bytes | Modified Date = 9/29/2003 11:14:58 PM | Attr = R ]
UpdateManager -> %CommonProgramFiles%\Sonic\Update Manager\sgtray.exe -> Sonic Solutions [Ver = 1.01.33b | Size = 110592 bytes | Modified Date = 1/7/2004 12:01:00 AM | Attr = ]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL-> Installed = 1 ->
MAPI-> Installed = 1 ->
MSFS-> Installed = 1 ->
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
H/PC Connection Agent -> %ProgramFiles%\Microsoft ActiveSync\WCESCOMM.EXE -> File not found
MySpaceIM -> %ProgramFiles%\MySpace\IM\MySpaceIM.exe -> File not found
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr = ]
swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 7/28/2007 8:50:24 PM | Attr = ]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,421 | Size = 4670704 bytes | Modified Date = 8/30/2007 4:43:18 PM | Attr = ]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersStartup%\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 29696 bytes | Modified Date = 12/14/2004 3:44:06 AM | Attr = ]
%AllUsersStartup%\Bluetooth Manager.lnk -> %ProgramFiles%\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe -> [Ver = | Size = 45056 bytes | Modified Date = 12/22/2004 12:42:22 PM | Attr = ]
%AllUsersStartup%\Program Neighborhood Agent.lnk -> %ProgramFiles%\Citrix\ICA Client\pnagent.exe -> Citrix Systems, Inc. [Ver = 9.200.44376 | Size = 233744 bytes | Modified Date = 5/2/2006 6:22:30 PM | Attr = ]
%AllUsersStartup%\Windstream Broadband Check-up Center.lnk -> %ProgramFiles%\ALLTEL DSL Check-up Center\bin\matcli.exe -> Motive Communications, Inc. [Ver = 5.8.1.asst_classic.asst_matcli.20040316_162000 | Size = 217088 bytes | Modified Date = 3/16/2004 5:49:50 PM | Attr = ]
< Original Startup Folder > -> C:\Documents and Settings\Original\Start Menu\Programs\Startup ->
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
AtiExtEvent -> %System32%\ati2evxx.dll -> ATI Technologies Inc. [Ver = 6.14.10.4107 | Size = 90112 bytes | Modified Date = 12/4/2004 2:32:40 AM | Attr = ]
igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4020 | Size = 348160 bytes | Modified Date = 2/15/2005 8:02:58 AM | Attr = ]
WgaLogon -> -> File not found
WRNotifier -> %System32%\WRLogonNtf.dll -> Webroot Software, Inc. [Ver = 3,3,1,2592 | Size = 233024 bytes | Modified Date = 1/25/2007 9:58:48 PM | Attr = ]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
< HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL ->
http://go.microsoft....k/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL ->
http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Page ->
http://go.microsoft....k/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page ->
http://go.microsoft....k/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL ->
http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant ->
http://www.google.com/ie ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Default_Page_URL ->
http://www.dell.com/ ->
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\Search Bar ->
http://www.google.com/ie ->
HKEY_CURRENT_USER\: Main\\Search Page ->
http://www.google.com ->
HKEY_CURRENT_USER\: Main\\Start Page ->
http://softwarerefer...=...6Ojg5&lid=2 ->
HKEY_CURRENT_USER\: Search\\SearchAssistant ->
http://www.google.com/ie ->
HKEY_CURRENT_USER\: SearchURL\\ ->
http://www.google.com/search?q=%s[Reg Error: Value provider does not exist or could not be read.] ->
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
HKEY_CURRENT_USER\: ProxyOverride -> 127.0.0.1 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
turbotax.com .[https] -> Trusted sites ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 7.0.0.2004121400 | Size = 63136 bytes | Modified Date = 12/14/2004 12:56:50 AM | Attr = ]
{5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %System32%\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.08a | Size = 118842 bytes | Modified Date = 12/6/2004 12:05:00 AM | Attr = ]
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar4.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/19/2007 11:55:32 PM | Attr = R ]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [Google Toolbar Notifier BHO] -> Google Inc. [Ver = 2, 0, 301, 7164 | Size = 325048 bytes | Modified Date = 7/28/2007 8:50:24 PM | Attr = ]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar4.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/19/2007 11:55:32 PM | Attr = R ]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Google\GoogleToolbar4.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2403392 bytes | Modified Date = 1/19/2007 11:55:32 PM | Attr = R ]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_02\bin\NPJPI150_02.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.20.9 | Size = 69746 bytes | Modified Date = 3/4/2005 2:54:17 AM | Attr = ]
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Microsoft ActiveSync\INETREPL.DLL [Create Mobile Favorite] -> File not found
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}:{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Microsoft ActiveSync\INETREPL.DLL [Create Mobile Favorite...] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
Open with ScanSoft PDF Converter 4.0 -> %ProgramFiles%\ScanSoft\PDF Professional 4.0\cnvres_eng.dll -> [Ver = | Size = 2150400 bytes | Modified Date = 8/16/2006 3:51:06 PM | Attr = ]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage ->
http://activex.micro...d...=%s&mime=%s ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{1524D730-4159-4A68-A15A-E8E30FB50642} -> (Dell Wireless 1370 WLAN Mini-PCI Card) ->
{933601B8-66F8-409B-A8D7-EBD6CE6CF4FA} -> (Broadcom NetXtreme 57xx Gigabit Controller) ->
{A4C21C79-A5BC-4F9F-B3EB-CA0367E7618F} -> () ->
{EDB79E45-97F2-4BCB-A61A-16C15ACDD17B} -> () ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
mctp:{d7b95390-b1c5-11d0-b111-0080c712fe82} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Microsoft ActiveSync\aatp.dll[mctp: Asynchronous Pluggable Protocol Handler] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}[HKEY_LOCAL_MACHINE] ->
http://www.apple.com...ex/qtplugin.cab[QuickTime Object] ->
{166B1BCA-3F9C-11CF-8075-444553540000}[HKEY_LOCAL_MACHINE] ->
http://download.macr...director/sw.cab[Shockwave ActiveX Control] ->
{321FB770-1FBE-4BFE-BDC1-6F622D4FA499}[HKEY_LOCAL_MACHINE] ->
https://activation.a...aller_2-0-0.cab[Reg Error: Value does not exist or could not be read.] ->
{406B5949-7190-4245-91A9-30A17DE16AD0}[HKEY_LOCAL_MACHINE] ->
http://photo.walgree...eensActivia.cab[Snapfish Activia] ->
{493ACF15-5CD9-4474-82A6-91670C3DD66E}[HKEY_LOCAL_MACHINE] ->
http://www.linkedin....nderControl.cab[LinkedIn ContactFinderControl] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537}[HKEY_LOCAL_MACHINE] ->
http://gfx1.hotmail....es/MSNPUpld.cab[MSN Photo Upload Tool] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] ->
http://java.sun.com/...indows-i586.cab[Java Plug-in 1.5.0_02] ->
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}[HKEY_LOCAL_MACHINE] ->
http://acs.pandasoft...free/asinst.cab[ActiveScan Installer Class] ->
{AE6C4705-0F11-4ACB-BDD4-37F138BEF289}[HKEY_LOCAL_MACHINE] ->
http://www.hebphoto....PUploader45.cab[Image Uploader Control] ->
{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] ->
http://java.sun.com/...indows-i586.cab[Java Plug-in 1.5.0_02] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] ->
http://download.macr...ash/swflash.cab[Shockwave Flash Object] ->
{F5131C24-E56D-11CF-B78A-444553540000}[HKEY_LOCAL_MACHINE] ->
https://wc.wachovia....ab/ikcntrls.cab[Ikonic Menu Control] ->
Microsoft XML Parser for Java[HKEY_LOCAL_MACHINE] -> file:///C:/WINDOWS/Java/classes/xmldso.cab[Reg Error: Key does not exist or could not be opened.] ->
[Registry - Additional Scans - Non-Microsoft Only]
[Files/Folders - Created Within 30 days]
Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 1/26/2008 8:06:52 PM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1064755200 bytes | Created Date = 1/26/2008 7:51:41 PM | Attr = HS]
install.dat -> %SystemDrive%\install.dat -> [Ver = | Size = 164 bytes | Created Date = 1/19/2008 11:46:19 PM | Attr = ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 1/21/2008 9:24:06 PM | Attr = ]
sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [Ver = | Size = 268 bytes | Created Date = 1/1/2008 8:07:18 PM | Attr = H ]
sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [Ver = | Size = 244 bytes | Created Date = 1/1/2008 8:07:18 PM | Attr = H ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Created Date = 1/27/2008 8:33:40 PM | Attr = ]
enethusb.sys -> %System32%\drivers\enethusb.sys -> Efficient Networks, Inc. [Ver = 2.1.0.60 | Size = 28005 bytes | Created Date = 1/18/2008 11:34:30 PM | Attr = R ]
SSFS0509.sys -> %System32%\drivers\SSFS0509.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.1.2592 | Size = 20544 bytes | Created Date = 1/20/2008 8:24:06 AM | Attr = ]
sshrmd.sys -> %System32%\drivers\sshrmd.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.1.2592 | Size = 22080 bytes | Created Date = 1/20/2008 8:24:05 AM | Attr = ]
ssidrv.sys -> %System32%\drivers\ssidrv.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.1.2592 | Size = 144448 bytes | Created Date = 1/20/2008 8:24:05 AM | Attr = ]
sskbfd.sys -> %System32%\drivers\sskbfd.sys -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.1.2592 | Size = 21056 bytes | Created Date = 1/20/2008 8:24:05 AM | Attr = ]
SYMEVENT.CAT -> %System32%\drivers\SYMEVENT.CAT -> [Ver = | Size = 10652 bytes | Created Date = 1/19/2008 10:03:57 PM | Attr = ]
SYMEVENT.INF -> %System32%\drivers\SYMEVENT.INF -> [Ver = | Size = 806 bytes | Created Date = 1/19/2008 10:03:57 PM | Attr = ]
SYMEVENT.SYS -> %System32%\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.4.0.24 | Size = 136496 bytes | Created Date = 1/19/2008 10:03:57 PM | Attr = ]
SysPlant.sys -> %System32%\drivers\SysPlant.sys -> Symantec Corporation [Ver = 11.0.780.980 | Size = 87424 bytes | Created Date = 1/19/2008 10:04:52 PM | Attr = ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Created Date = 1/25/2008 8:17:59 PM | Attr = ]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
asuninst.exe -> %System32%\asuninst.exe -> Panda Software [Ver = 1, 0, 0, 2 | Size = 73728 bytes | Created Date = 1/25/2008 8:55:56 PM | Attr = ]
DevMngr.vxd -> %System32%\DevMngr.vxd -> [Ver = | Size = 6345 bytes | Created Date = 1/18/2008 11:21:26 PM | Attr = R ]
dumphive.exe -> %System32%\dumphive.exe -> [Ver = | Size = 51200 bytes | Created Date = 1/20/2008 8:22:57 PM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Created Date = 1/25/2008 8:24:18 PM | Attr = ]
IEDFix.exe -> %System32%\IEDFix.exe -> S!Ri.URZ [Ver = | Size = 81920 bytes | Created Date = 1/20/2008 8:23:00 PM | Attr = ]
javasup.vxd -> %System32%\javasup.vxd -> [Ver = | Size = 7315 bytes | Created Date = 1/18/2008 11:15:53 PM | Attr = ]
MCC16.dll -> %System32%\MCC16.dll -> [Ver = | Size = 6048 bytes | Created Date = 1/19/2008 12:04:58 AM | Attr = ]
MCCDevice.dll -> %System32%\MCCDevice.dll -> Motive Communications, Inc. [Ver = 4,10,7,2 | Size = 69632 bytes | Created Date = 1/19/2008 12:04:58 AM | Attr = ]
MCCDNSHLP_1-0-0_DSR.dll -> %System32%\MCCDNSHLP_1-0-0_DSR.dll -> Motive Communications, Inc. [Ver = 1,0,0,3 | Size = 589824 bytes | Created Date = 1/18/2008 11:19:11 PM | Attr = ]
MRT.INI -> %System32%\MRT.INI -> [Ver = | Size = 118 bytes | Created Date = 1/26/2008 7:59:03 PM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Created Date = 1/25/2008 8:19:41 PM | Attr = ]
Process.exe -> %System32%\Process.exe ->
http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 1/20/2008 8:22:51 PM | Attr = ]
S32EVNT1.DLL -> %System32%\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.4.0.25 | Size = 60808 bytes | Created Date = 1/19/2008 10:03:57 PM | Attr = ]
SrchSTS.exe -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Created Date = 1/20/2008 8:22:55 PM | Attr = ]
ssiefr.EXE -> %System32%\ssiefr.EXE -> Webroot Software Inc (www.webroot.com) [Ver = 3.3.1.2592 | Size = 10240 bytes | Created Date = 1/20/2008 8:23:59 AM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.0 | Size = 135168 bytes | Created Date = 1/20/2008 8:22:52 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Created Date = 1/20/2008 8:22:53 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 79360 bytes | Created Date = 1/20/2008 8:22:57 PM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 4780 bytes | Created Date = 1/20/2008 8:26:02 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Created Date = 1/25/2008 8:26:49 PM | Attr = ]
VCCLSID.exe -> %System32%\VCCLSID.exe -> S!Ri [Ver = | Size = 289144 bytes | Created Date = 1/20/2008 8:22:58 PM | Attr = ]
WRLogonNtf.dll -> %System32%\WRLogonNtf.dll -> Webroot Software, Inc. [Ver = 3,3,1,2592 | Size = 233024 bytes | Created Date = 1/20/2008 8:24:04 AM | Attr = ]
wrlzma.dll -> %System32%\wrlzma.dll -> [Ver = | Size = 26688 bytes | Created Date = 1/20/2008 8:24:00 AM | Attr = ]
WS2Fix.exe -> %System32%\WS2Fix.exe -> [Ver = | Size = 25600 bytes | Created Date = 1/20/2008 8:22:59 PM | Attr = ]
zonedoff.reg -> %System32%\zonedoff.reg -> [Ver = | Size = 113 bytes | Created Date = 1/18/2008 11:15:46 PM | Attr = ]
zonedon.reg -> %System32%\zonedon.reg -> [Ver = | Size = 113 bytes | Created Date = 1/18/2008 11:15:46 PM | Attr = ]
ZPORT4AS.dll -> %System32%\ZPORT4AS.dll -> [Ver = | Size = 11776 bytes | Created Date = 1/25/2008 8:55:56 PM | Attr = ]
ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 1/26/2008 8:07:22 PM | Attr = ]
jautoexp.dat -> %SystemRoot%\jautoexp.dat -> [Ver = | Size = 6550 bytes | Created Date = 1/18/2008 11:15:53 PM | Attr = ]
Motive -> %SystemRoot%\Motive -> [Folder | Created Date = 1/19/2008 12:07:16 AM | Attr = ]
WRUninstall.dll -> %SystemRoot%\WRUninstall.dll -> Webroot Software, Inc. [Ver = 5,3,1,2344 | Size = 271936 bytes | Created Date = 1/20/2008 8:23:59 AM | Attr = ]
_detmp.1 -> %SystemRoot%\_detmp.1 -> [Ver = | Size = 1619873 bytes | Created Date = 1/25/2008 11:41:18 PM | Attr = ]
_detmp.2 -> %SystemRoot%\_detmp.2 -> SAS Institute Inc. [Ver = 8.2.0.6 | Size = 72192 bytes | Created Date = 1/25/2008 11:41:35 PM | Attr = ]
_detmp.3 -> %SystemRoot%\_detmp.3 -> [Ver = | Size = 7091 bytes | Created Date = 1/25/2008 11:42:00 PM | Attr = ]
_detmp.4 -> %SystemRoot%\_detmp.4 -> [Ver = | Size = 33280 bytes | Created Date = 1/25/2008 11:43:00 PM | Attr = ]
[Files/Folders - Modified Within 30 days]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 1/28/2008 6:36:09 PM | Attr = HS]
Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 1/26/2008 8:06:52 PM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1064755200 bytes | Modified Date = 1/29/2008 9:04:35 PM | Attr = HS]
install.dat -> %SystemDrive%\install.dat -> [Ver = | Size = 164 bytes | Modified Date = 1/19/2008 11:46:35 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 1/29/2008 8:19:36 PM | Attr = R ]
SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 1/19/2008 7:26:04 AM | Attr = ]
sqmdata09.sqm -> %SystemDrive%\sqmdata09.sqm -> [Ver = | Size = 268 bytes | Modified Date = 1/1/2008 8:07:18 PM | Attr = H ]
sqmnoopt09.sqm -> %SystemDrive%\sqmnoopt09.sqm -> [Ver = | Size = 244 bytes | Modified Date = 1/1/2008 8:07:18 PM | Attr = H ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 1/26/2008 8:07:16 PM | Attr = HS]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 1/29/2008 9:05:38 PM | Attr = ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Modified Date = 1/27/2008 8:33:40 PM | Attr = ]
SYMEVENT.CAT -> %System32%\drivers\SYMEVENT.CAT -> [Ver = | Size = 10652 bytes | Modified Date = 1/19/2008 10:04:07 PM | Attr = ]
SYMEVENT.INF -> %System32%\drivers\SYMEVENT.INF -> [Ver = | Size = 806 bytes | Modified Date = 1/19/2008 10:04:07 PM | Attr = ]
SYMEVENT.SYS -> %System32%\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.4.0.24 | Size = 136496 bytes | Modified Date = 1/19/2008 10:04:07 PM | Attr = ]
WpsHelper.sys -> %System32%\drivers\WpsHelper.sys -> Symantec Corporation [Ver = 11.0.717.804 | Size = 50536 bytes | Modified Date = 1/19/2008 10:08:00 PM | Attr = ]
ActiveScan -> %System32%\ActiveScan -> [Folder | Modified Date = 1/25/2008 8:56:00 PM | Attr = ]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 1/29/2008 9:05:16 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 1/26/2008 8:00:50 PM | Attr = RHS]
drivers -> %System32%\drivers -> [Folder | Modified Date = 1/27/2008 8:58:19 PM | Attr = ]
Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 1/25/2008 8:26:43 PM | Attr = ]
Macromed -> %System32%\Macromed -> [Folder | Modified Date = 1/19/2008 9:04:21 PM | Attr = ]
MRT.INI -> %System32%\MRT.INI -> [Ver = | Size = 118 bytes | Modified Date = 1/26/2008 7:59:03 PM | Attr = ]
pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 1/25/2008 8:24:13 PM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 1/26/2008 8:07:16 PM | Attr = ]
S32EVNT1.DLL -> %System32%\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.4.0.25 | Size = 60808 bytes | Modified Date = 1/19/2008 10:04:07 PM | Attr = ]
tmp.reg -> %System32%\tmp.reg -> [Ver = | Size = 4780 bytes | Modified Date = 1/24/2008 9:15:14 PM | Attr = ]
Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 1/25/2008 8:29:50 PM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 12598 bytes | Modified Date = 1/29/2008 8:15:31 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 1/26/2008 7:59:08 PM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 1/29/2008 9:04:38 PM | Attr = S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 1/26/2008 8:11:21 PM | Attr = S]
ERDNT -> %SystemRoot%\ERDNT -> [Folder | Modified Date = 1/27/2008 8:37:57 PM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 1/20/2008 12:34:52 AM | Attr = ]
ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 1/26/2008 7:55:10 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 1/26/2008 7:56:44 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 1/26/2008 7:59:19 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 1/27/2008 8:58:34 PM | Attr = HS]
java -> %SystemRoot%\java -> [Folder | Modified Date = 1/18/2008 11:15:51 PM | Attr = ]
Motive -> %SystemRoot%\Motive -> [Folder | Modified Date = 1/19/2008 12:07:16 AM | Attr = ]
NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 1/19/2008 12:57:55 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 1/29/2008 8:33:11 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 1/29/2008 9:05:53 PM | Attr = H ]
system32 -> %System32% -> [Folder | Modified Date = 1/26/2008 8:00:50 PM | Attr = ]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 1/29/2008 9:07:17 PM | Attr = ]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 1/19/2008 10:03:45 PM | Attr = ]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 1/28/2008 12:12:02 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 1/29/2008 9:04:49 PM | Attr = H ]
User_Feed_Synchronization-{FCED3B27-FF7D-4D36-8741-FFED57F606A6}.job -> %SystemRoot%\tasks\User_Feed_Synchronization-{FCED3B27-FF7D-4D36-8741-FFED57F606A6}.job -> [Ver = | Size = 428 bytes | Modified Date = 1/29/2008 9:10:25 PM | Attr = H ]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 41372 bytes | Modified Date = 1/25/2008 11:08:54 PM | Attr = ]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 41372 bytes | Modified Date = 1/25/2008 11:08:53 PM | Attr = ]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 12330 bytes | Modified Date = 12/10/2006 10:25:43 PM | Attr = ]
SSUPDATE.EXE -> C:\Documents and Settings\Original\Local Settings\Temp\SSUPDATE.EXE -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 146672 bytes | Modified Date = 6/21/2007 2:07:10 PM | Attr = ]
4 C:\Documents and Settings\Original\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Original\Local Settings\Temp\*.tmp ->
md5deep.exe -> C:\Documents and Settings\Original\Local Settings\Temp\~tamqlrz.tmp\md5deep.exe -> [Ver = | Size = 21504 bytes | Modified Date = 7/29/2007 8:23:07 PM | Attr = ]
sed.exe -> C:\Documents and Settings\Original\Local Settings\Temp\~tamqlrz.tmp\sed.exe -> [Ver = | Size = 37376 bytes | Modified Date = 7/29/2007 8:23:07 PM | Attr = ]
swreg.exe -> C:\Documents and Settings\Original\Local Settings\Temp\~tamqlrz.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 8:23:07 PM | Attr = ]
Resume.exe -> C:\Documents and Settings\Original\Local Settings\Temp\2S771O1K\Resume.exe -> [Ver = 3.3 | Size = 433521 bytes | Modified Date = 1/29/2008 8:32:54 PM | Attr = ]
dss.dll -> C:\Documents and Settings\Original\Local Settings\Temp\~tamqlrz.tmp\dss.dll -> [Ver = | Size = 37888 bytes | Modified Date = 10/14/2007 12:42:28 AM | Attr = ]
unpack.dll -> C:\Documents and Settings\Original\Local Settings\Temp\2S771O1K\unpack.dll -> [Ver = | Size = 35328 bytes | Modified Date = 1/29/2008 8:32:54 PM | Attr = ]
CustomUI.dll -> C:\Documents and Settings\Original\Local Settings\Temp\2S771O1K\Uninstall\plugins\0\CustomUI.dll -> [Ver = | Size = 352768 bytes | Modified Date = 12/19/2006 12:28:12 PM | Attr = ]
Services.dll -> C:\Documents and Settings\Original\Local Settings\Temp\2S771O1K\Uninstall\plugins\1\Services.dll -> [Ver = | Size = 107520 bytes | Modified Date = 11/24/2004 12:53:52 PM | Attr = ]
_shfoldr.dll -> C:\Documents and Settings\Original\Local Settings\Temp\is-78QTU.tmp\_isetup\_shfoldr.dll -> Microsoft Corporation [Ver = 5.50.4807.2300 | Size = 23312 bytes | Modified Date = 1/29/2008 8:20:12 PM | Attr = ]
1 C:\Documents and Settings\Original\Local Settings\Temp\is-78QTU.tmp\_isetup\*.tmp files -> C:\Documents and Settings\Original\Local Settings\Temp\is-78QTU.tmp\_isetup\*.tmp ->
Perflib_Perfdata_48c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_48c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/28/2008 6:37:00 PM | Attr = ]
Perflib_Perfdata_604.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_604.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/29/2008 9:05:07 PM | Attr = ]
Perflib_Perfdata_618.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_618.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/26/2008 8:01:40 PM | Attr = ]
Perflib_Perfdata_648.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_648.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/27/2008 8:44:16 PM | Attr = ]
Perflib_Perfdata_664.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_664.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/27/2008 8:53:49 PM | Attr = ]
Perflib_Perfdata_6a0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6a0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/29/2008 8:24:05 PM | Attr = ]
Perflib_Perfdata_6b8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_6b8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/29/2008 8:16:07 PM | Attr = ]
[CatchMe Rootkit Scan by GMER]
Rootkit scan error - could not find scan log
Rootkit scan error - could not find scan log
< End of report >