Thanks for the reply, Oldtimer. I am running your program now and I will post a log once it's done running.
Well it finished! here ya go!
WinPFind3 logfile created on: 07-01-12 21:37:13
WinPFind3U by OldTimer - Version 1.0.10 Folder = C:\Documents and Settings\HP_Owner.BUNDOCK\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)
523760 Kb Total Physical Memory | 226712 Kb Available Physical Memory | 43.29% Memory free
1279236 Kb Paging File | 943188 Kb Available in Paging File | 73.73% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 150194516 Kb Total Space | 64446356 Kb Free Space | 42.91% Space Free
Drive D: | 6073888 Kb Total Space | 794496 Kb Free Space | 13.08% Space Free
Unable to calculate disk information.
Drive F: | 271404 Kb Total Space | 0 Kb Free Space | 0.00% Space Free
[Processes - Non-Microsoft Only]
aim.exe -> %ProgramFiles%\AIM\aim.exe -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 05-08-05 14:08:26 | Attr = ]
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 05-06-06 23:46:24 | Attr = ]
ashserv.exe -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> [Ver = 4, 7, 844, 0 | Size = 108160 bytes | Modified Date = 06-08-05 01:23:06 | Attr = ]
aswupdsv.exe -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> [Ver = | Size = 59008 bytes | Modified Date = 06-08-05 10:10:10 | Attr = ]
bandwidth monitor pro.exe -> %SystemDrive%\Documents and Settings\All Users\Start Menu\Programs\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe -> Pro²soft [Ver = 1.30 | Size = 224768 bytes | Modified Date = 07-01-11 22:49:48 | Attr = ]
hijackthis.exe -> %ProgramFiles%\HijackThis.exe -> Soeperman Enterprises Ltd. [Ver = 1.99.0001 | Size = 218112 bytes | Modified Date = 05-02-16 10:06:16 | Attr = ]
iftpsvc.exe -> %SystemDrive%\iFtpSvc\iFtpSvc.exe -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. [Ver = 2006, 4, 17, 0 | Size = 565248 bytes | Modified Date = 06-04-21 10:34:32 | Attr = ]
intfysvc.exe -> %SystemDrive%\iNtfySvc\intfysvc.exe -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. [Ver = 2004, 6, 21, 0 | Size = 131072 bytes | Modified Date = 04-06-28 10:56:58 | Attr = ]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 492608 bytes | Modified Date = 06-10-30 09:36:32 | Attr = ]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 256576 bytes | Modified Date = 06-10-30 09:36:36 | Attr = ]
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 229376 bytes | Modified Date = 06-02-28 12:42:38 | Attr = R ]
nvsvc32.exe -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 143436 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
services.exe -> %SystemRoot%\services.exe -> [Ver = | Size = 350764 bytes | Modified Date = 07-01-11 22:58:54 | Attr = HS]
spysweeper.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,2,3,2125 | Size = 3297792 bytes | Modified Date = 06-11-01 17:17:20 | Attr = ]
spysweeperui.exe -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,2,3,2125 | Size = 4806144 bytes | Modified Date = 06-11-01 17:17:34 | Attr = ]
ssu.exe -> %ProgramFiles%\Webroot\Spy Sweeper\ssu.exe -> [Ver = | Size = 164352 bytes | Modified Date = 06-11-01 17:17:26 | Attr = ]
starwindservice.exe -> %ProgramFiles%\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -> Rocket Division Software [Ver = 2.6.1 Build 0x20050401 | Size = 217600 bytes | Modified Date = 05-04-01 12:51:48 | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> Oldtimer Tools [Ver = 1.0.10.0 | Size = 306176 bytes | Modified Date = 07-01-12 16:20:26 | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Abel) Abel [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Cain\Abel.exe -> oxid.it [Ver = 2.9 | Size = 27136 bytes | Modified Date = 06-05-22 22:13:12 | Attr = ]
(Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> Adobe Systems [Ver = 2.67.010 | Size = 72704 bytes | Modified Date = 06-07-19 20:41:46 | Attr = ]
(aswUpdSv) avast! iAVS4 Control Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> [Ver = | Size = 59008 bytes | Modified Date = 06-08-05 10:10:10 | Attr = ]
(avast! Antivirus) avast! Antivirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> [Ver = 4, 7, 844, 0 | Size = 108160 bytes | Modified Date = 06-08-05 01:23:06 | Attr = ]
(avast! Mail Scanner) avast! Mail Scanner [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Alwil Software\Avast4\ashMaiSv.exe -> ALWIL Software [Ver = 4, 7, 869, 0 | Size = 251520 bytes | Modified Date = 06-08-05 01:22:48 | Attr = ]
(avast! Web Scanner) avast! Web Scanner [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Alwil Software\Avast4\ashWebSv.exe -> ALWIL Software [Ver = 4, 7, 844, 0 | Size = 370304 bytes | Modified Date = 06-08-05 01:22:38 | Attr = ]
(Bonjour Service) ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> Apple Computer, Inc. [Ver = 1,0,3,1 | Size = 229376 bytes | Modified Date = 06-02-28 12:42:38 | Attr = R ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 04-08-04 14:00:00 | Attr = ]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 07-01-12 06:59:54 | Attr = ]
(iFtpSvc) Ipswitch WS_FTP Service [Win32_Own | Auto | Running] -> %SystemDrive%\iFtpSvc\iFtpSvc.exe -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. [Ver = 2006, 4, 17, 0 | Size = 565248 bytes | Modified Date = 06-04-21 10:34:32 | Attr = ]
(inotifysvr) Ipswitch Notification Server [Win32_Own | Auto | Running] -> %SystemDrive%\iNtfySvc\intfysvc.exe -> Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. [Ver = 2004, 6, 21, 0 | Size = 131072 bytes | Modified Date = 04-06-28 10:56:58 | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 492608 bytes | Modified Date = 06-10-30 09:36:32 | Attr = ]
(NBService) NBService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBService.exe -> Nero AG [Ver = 2, 6, 6, 0 | Size = 724992 bytes | Modified Date = 06-10-09 21:11:08 | Attr = ]
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 143436 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
(StarWindService) StarWind iSCSI Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -> Rocket Division Software [Ver = 2.6.1 Build 0x20050401 | Size = 217600 bytes | Modified Date = 05-04-01 12:51:48 | Attr = ]
(WebrootDesktopFirewallDataService) Webroot Desktop Firewall Data Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Webroot\Desktop Firewall\WDFDataService.exe -> Webroot Software, Inc. [Ver = 2.0.0.419 | Size = 665600 bytes | Modified Date = 05-09-29 21:46:50 | Attr = ]
(WebrootFirewall) Webroot Desktop Firewall [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Webroot\Desktop Firewall\FirewallNTService.exe -> [Ver = | Size = 192512 bytes | Modified Date = 05-05-18 13:10:56 | Attr = ]
(WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Auto | Running] -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> Webroot Software, Inc. [Ver = 3,2,3,2125 | Size = 3297792 bytes | Modified Date = 06-11-01 17:17:20 | Attr = ]
(wscsvc) Security Center [Win32_Shared | Disabled | Stopped] -> C:\WINDOWS\%System32%\svchost.exe -> File not found
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adobe Photo Downloader -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 05-06-06 23:46:24 | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 256576 bytes | Modified Date = 06-10-30 09:36:36 | Attr = ]
MSPY2002 -> %System32%\IME\PINTLGNT\IMSCINST.EXE -> [Ver = | Size = 59392 bytes | Modified Date = 04-08-04 07:00:00 | Attr = ]
NvCplDaemon -> %System32%\nvcpl.dll ["RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
SpySweeper -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeperUI.exe -> Webroot Software, Inc. [Ver = 5,2,3,2125 | Size = 4806144 bytes | Modified Date = 06-11-01 17:17:34 | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Bandwidth Monitor Pro -> %SystemDrive%\Documents and Settings\All Users\Start Menu\Programs\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe -> Pro²soft [Ver = 1.30 | Size = 224768 bytes | Modified Date = 07-01-11 22:49:48 | Attr = ]
< Disabled MSConfig Folder Items[HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk -> Reg Data - Value does not exist -> File not found
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk -> Reg Data - Value does not exist -> File not found
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk -> %ProgramFiles%\Updates from HP\309731\Program\Updates from HP.exe -> [Ver = | Size = 16423 bytes | Modified Date = 04-08-07 16:33:32 | Attr = ]
C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk -> %ProgramFiles%\WinZip\WZQKPICK.EXE -> WinZip Computing, Inc. [Ver = 1.0 (32-bit) | Size = 106560 bytes | Modified Date = 01-11-27 07:10:00 | Attr = ]
C:^Documents and Settings^HP_Owner.BUNDOCK^Start Menu^Programs^Startup^Adobe Gamma.lnk -> %CommonProgramFiles%\Adobe\Calibration\Adobe Gamma Loader.exe -> Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Modified Date = 99-11-04 14:06:48 | Attr = ]
C:^Documents and Settings^HP_Owner.BUNDOCK^Start Menu^Programs^Startup^HP Organize.lnk -> Reg Data - Value does not exist -> File not found
C:^Documents and Settings^HP_Owner.BUNDOCK^Start Menu^Programs^Startup^SpamSubtract.lnk -> Reg Data - Value does not exist -> File not found
C:^Documents and Settings^HP_Owner.BUNDOCK^Start Menu^Programs^Startup^UMAX VistaAccess.lnk -> %ProgramFiles%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 1. 02 | Size = 159232 bytes | Modified Date = 00-01-06 07:26:36 | Attr = ]
< Disabled MSConfig Registry Items [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\
AGRSMMSG -> %SystemRoot%\AGRSMMSG.exe -> Agere Systems [Ver = 2.1.41.10 2.1.41.10 06/29/2004 09:06:35 | Size = 88363 bytes | Modified Date = 04-06-29 19:06:38 | Attr = ]
avast! -> %ProgramFiles%\Alwil Software\Avast4\ashDisp.exe -> [Ver = 5, 0, 0, 0 | Size = 108160 bytes | Modified Date = 06-08-05 01:23:12 | Attr = ]
BearShare -> %ProgramFiles%\BearShare\BearShare.exe -> File not found
CTFMon -> %System32%\CTF\ctfmon.exe -> File not found
DAEMON Tools -> %ProgramFiles%\DAEMON Tools\daemon.exe -> DT Soft Ltd. [Ver = 4.03.0.0 | Size = 133016 bytes | Modified Date = 05-12-10 09:57:20 | Attr = ]
HPHmon06 -> %System32%\hphmon06.exe -> Hewlett-Packard [Ver = 6,0,72 | Size = 659456 bytes | Modified Date = 04-06-07 20:42:30 | Attr = ]
HPHUPD06 -> %ProgramFiles%\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe -> Hewlett-Packard [Ver = 6,0,72 | Size = 49152 bytes | Modified Date = 04-06-07 20:53:26 | Attr = ]
hpsysdrv -> %SystemRoot%\system\hpsysdrv.exe -> Hewlett-Packard Company [Ver = 1, 7, 0, 0 | Size = 52736 bytes | Modified Date = 98-05-07 18:04:38 | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 256576 bytes | Modified Date = 06-10-30 09:36:36 | Attr = ]
KBD -> %SystemDrive%\hp\KBD\kbd.exe -> Hewlett-Packard Company [Ver = 1.0.2.0 | Size = 61440 bytes | Modified Date = 03-02-11 22:02:48 | Attr = ]
Microsoft Works Update Detection -> %CommonProgramFiles%\Microsoft Shared\Works Shared\WkUFind.exe -> Microsoft® Corporation [Ver = 9.00.0912.0 | Size = 50688 bytes | Modified Date = 03-09-13 21:36:52 | Attr = ]
NvCplDaemon -> %System32%\nvcpl.dll -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
NvMediaCenter -> %System32%\nvmctray.dll -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 86016 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
nwiz -> %System32%\nwiz.exe -> [Ver = | Size = 1519616 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
PS2 -> %System32%\ps2.EXE -> Hewlett-Packard Company [Ver = 1.0.2.1 | Size = 81920 bytes | Modified Date = 02-10-16 18:57:10 | Attr = ]
PWRISOVM.EXE -> %ProgramFiles%\PowerISO\PWRISOVM.EXE -> File not found
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.5a38 | Size = 282624 bytes | Modified Date = 06-12-05 21:00:28 | Attr = ]
Recguard -> %SystemRoot%\SMINST\Recguard.exe -> [Ver = 5, 0, 44, 2 | Size = 233472 bytes | Modified Date = 04-04-14 22:43:46 | Attr = ]
SSC_UserPrompt -> %CommonProgramFiles%\Symantec Shared\Security Center\UsrPrmpt.exe -> File not found
Steam -> -> File not found
SunJavaUpdateSched -> %ProgramFiles%\Java\j2re1.4.2_03\bin\jusched.exe -> [Ver = | Size = 32881 bytes | Modified Date = 04-08-07 14:37:00 | Attr = ]
VTTimer -> VTTimer.exe -> File not found
< SSODL [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} [HKLM] -> %CommonProgramFiles%\stardock\MCPCore.dll [0aMCPClient] -> Stardock [Ver = 0, 0, 5, 4 | Size = 86016 bytes | Modified Date = 05-05-10 13:31:20 | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
C:\WINDOWS\system32\fservice.exe -> %System32%\fservice.exe -> [Ver = | Size = 350764 bytes | Modified Date = 07-01-11 22:58:54 | Attr = HS]
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
Control_RunDLL -> -> File not found
< Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\DirectX For Microsoft® Windows -> C:\WINDOWS\system32\fservice.exe ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
< Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\{B4FE4312-0833-1033-0606-050923040001} -> "C:\Program Files\Common Files\{B4FE4312-0833-1033-0606-050923040001}\Update.exe" te-110-12-0000073 ->
-> HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer not found. ->
< Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\
0 -> [Key] ->
0 -> FriendlyName = My Current Home Page ->
0 -> Source = About:Home ->
0 -> SubscribedURL = About:Home ->
< HOSTS File > -> C:\WINDOWS\System32\drivers\etc\Hosts
< Internet Explorer Settings > ->
HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->
HKLM: Start Page -> about:blank ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Start Page ->
http://www.google.com/ ->
HKCU: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 6.0.1.2003110300 | Size = 54248 bytes | Modified Date = 03-11-03 23:17:44 | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
ShellBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> Reg Data - Key not found [&Yahoo! Toolbar] -> File not found
< Internet Explorer CmdMapping [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -> 8192 - Reg Data - Key not found ->
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> 8193 - Reg Data - Key not found ->
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -> 8195 - Reg Data - Value does not exist ->
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -> 8196 - Reg Data - Key not found ->
{FB5F1910-F110-11d2-BB9E-00C04F795683} -> 8194 - Reg Data - Key not found ->
NextId -> 8197 ->
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -> %ProgramFiles%\AIM\aim.exe [ButtonText: AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 05-08-05 14:08:26 | Attr = ]
< Approved Shell Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} [HKLM] -> Reg Data - Key not found [Autoplay for SlideShow] -> File not found
{0DF44EAA-FF21-4412-828E-260A8728E7F1} [HKLM] -> Reg Data - Key not found [Taskbar and Start Menu] -> File not found
{1CDB2949-8F65-4355-8456-263E7C208A5D} [HKLM] -> %System32%\nvshell.dll [Desktop Explorer] -> [Ver = | Size = 466944 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{1E9B04FB-F9E5-4718-997B-B8DA88302A47} [HKLM] -> %System32%\nvshell.dll [Desktop Explorer Menu] -> [Ver = | Size = 466944 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} [HKLM] -> %System32%\nvshell.dll [nView Desktop Context Menu] -> [Ver = | Size = 466944 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{2B3453E4-49DF-11D3-8229-0080BE509050} [HKLM] -> %System32%\ShellExt\GMailFS.dll [GMail Drive] -> Bjarke Viksoe [Ver = 1, 0, 0, 10 | Size = 289280 bytes | Modified Date = 06-04-18 17:49:18 | Attr = ]
{2B3453E4-49DF-11D3-8229-0080BE509052} [HKLM] -> %System32%\ShellExt\GMailFS.dll [GMailFS Property Sheet] -> Bjarke Viksoe [Ver = 1, 0, 0, 10 | Size = 289280 bytes | Modified Date = 06-04-18 17:49:18 | Attr = ]
{2B3453E4-49DF-11D3-8229-0080BE509054} [HKLM] -> %System32%\ShellExt\GMailFS.dll [GMailFS Drop Handler] -> Bjarke Viksoe [Ver = 1, 0, 0, 10 | Size = 289280 bytes | Modified Date = 06-04-18 17:49:18 | Attr = ]
{2B3453E4-49DF-11D3-8229-0080BE509056} [HKLM] -> %System32%\ShellExt\GMailFS.dll [GMailFS Context Menu] -> Bjarke Viksoe [Ver = 1, 0, 0, 10 | Size = 289280 bytes | Modified Date = 06-04-18 17:49:18 | Attr = ]
{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} [HKLM] -> %ProgramFiles%\Illustrate\dBpowerAMP\dMCShell.dll [dBpowerAMP Music Converter] -> [Ver = 6, 4, 0, 0 | Size = 118784 bytes | Modified Date = 06-07-31 13:45:38 | Attr = ]
{32020A01-506E-484D-A2A8-BE3CF17601C3} [HKLM] -> %ProgramFiles%\Alcohol Soft\Alcohol 120\AXShlEx.dll [AlcoholShellEx] -> Alcohol Soft Development Team [Ver = 1.9.5.3718 | Size = 715648 bytes | Modified Date = 06-10-08 09:04:56 | Attr = ]
{42071714-76d4-11d1-8b24-00a0c9068ff3} [HKLM] -> Reg Data - Key not found [Display Panning CPL Extension] -> File not found
{472083B0-C522-11CF-8763-00608CC02F24} [HKLM] -> %ProgramFiles%\Alwil Software\Avast4\ashShell.dll [avast] -> ALWIL Software [Ver = 4, 7, 869, 0 | Size = 13824 bytes | Modified Date = 06-08-05 01:17:58 | Attr = ]
{6DEA92E9-8682-4b6a-97DE-354772FE5727} [HKLM] -> %CommonProgramFiles%\Autodesk Shared\AcDwfThmbPrxy16.dll [Autodesk DWF Preview] -> Autodesk [Ver = 16.2.54.0 | Size = 39032 bytes | Modified Date = 05-03-05 03:14:24 | Attr = ]
{764BF0E1-F219-11ce-972D-00AA00A14F56} [HKLM] -> Reg Data - Key not found [Shell extensions for file compression] -> File not found
{7A9D77BD-5403-11d2-8785-2E0420524153} [HKLM] -> Reg Data - Key not found [User Accounts] -> File not found
{7C9D5882-CB4A-4090-96C8-430BFE8B795B} [HKLM] -> %ProgramFiles%\Webroot\Spy Sweeper\SSCtxMnu.dll [Webroot Spy Sweeper Context Menu Integration] -> Webroot Software, Inc. [Ver = 5,2,3,2125 | Size = 219136 bytes | Modified Date = 06-11-01 17:17:38 | Attr = ]
{7F1CF152-04F8-453A-B34C-E609530A9DC8} [HKLM] -> %CommonProgramFiles%\Ahead\Lib\NeroDigitalExt.dll [NeroDigitalPropSheetHandler] -> Nero AG [Ver = 2, 0, 0, 8 | Size = 1802240 bytes | Modified Date = 05-11-15 11:07:16 | Attr = ]
{7F67036B-66F1-411A-AD85-759FB9C5B0DB} [HKLM] -> %System32%\ShellvRTF.dll [SampleView] -> XSS [Ver = 1, 0, 0, 1 | Size = 122880 bytes | Modified Date = 02-09-20 23:42:28 | Attr = ]
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} [HKLM] -> Reg Data - Key not found [Encryption Context Menu] -> File not found
{88895560-9AA2-1069-930E-00AA0030EBC8} [HKLM] -> %System32%\hticons.dll [HyperTerminal Icon Ext] -> Hilgraeve, Inc. [Ver = 5.1.2600.0 | Size = 44544 bytes | Modified Date = 04-08-04 07:00:00 | Attr = ]
{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} [HKLM] -> Reg Data - Key not found [PowerISO] -> File not found
{A70C977A-BF00-412C-90B7-034C51DA2439} [HKLM] -> %System32%\nvcpl.dll [NvCpl DesktopContext Class] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{B327765E-D724-4347-8B16-78AE18552FC3} [HKLM] -> %CommonProgramFiles%\Ahead\Lib\NeroDigitalExt.dll [NeroDigitalIconHandler] -> Nero AG [Ver = 2, 0, 0, 8 | Size = 1802240 bytes | Modified Date = 05-11-15 11:07:16 | Attr = ]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} [HKLM] -> %ProgramFiles%\WinRAR\RarExt.dll [WinRAR shell extension] -> [Ver = | Size = 121344 bytes | Modified Date = 04-12-27 10:56:08 | Attr = ]
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} [HKLM] -> %ProgramFiles%\iTunes\iTunesMiniPlayer.dll [iTunes] -> Apple Computer, Inc. [Ver = 7.0.2.16 | Size = 132672 bytes | Modified Date = 06-10-30 09:36:36 | Attr = ]
{DEE12703-6333-4D4E-8F34-738C4DCC2E04} [HKLM] -> %ProgramFiles%\Sonic RecordNow!\shlext.dll [RecordNow! SendToExt] -> [Ver = 7.0.0.0 | Size = 73728 bytes | Modified Date = 04-06-07 16:02:00 | Attr = ]
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} [HKLM] -> Reg Data - Key not found [Shell Extensions for RealOne Player] -> File not found
{FED7043D-346A-414D-ACD7-550D052499A7} [HKLM] -> %ProgramFiles%\Illustrate\dBpowerAMP\dBShell.dll [dBpowerAMP Music Converter 1] -> [Ver = 6, 4, 0, 1 | Size = 110592 bytes | Modified Date = 06-07-31 13:45:36 | Attr = ]
{FFB699E0-306A-11d3-8BD1-00104B6F7516} [HKLM] -> %System32%\nvcpl.dll [Play on my TV helper] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
< ContextMenuHandlers - * [HKLM] > -> HKEY_LOCAL_MACHINE\Software\Classes\*\shellex\ContextMenuHandlers\
{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} [HKLM] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBShell.dll [NBShellHook Class] -> Nero AG [Ver = 2, 6, 6, 0 | Size = 73728 bytes | Modified Date = 06-10-09 21:11:32 | Attr = ]
{472083B0-C522-11CF-8763-00608CC02F24} [HKLM] -> %ProgramFiles%\Alwil Software\Avast4\ashShell.dll [avast] -> ALWIL Software [Ver = 4, 7, 869, 0 | Size = 13824 bytes | Modified Date = 06-08-05 01:17:58 | Attr = ]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} [HKLM] -> %ProgramFiles%\WinRAR\RarExt.dll [WinRAR] -> [Ver = | Size = 121344 bytes | Modified Date = 04-12-27 10:56:08 | Attr = ]
< ContextMenuHandlers - AllFilesystemObjects [HKLM] > -> HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
{7C9D5882-CB4A-4090-96C8-430BFE8B795B} [HKLM] -> %ProgramFiles%\Webroot\Spy Sweeper\SSCtxMnu.dll [SpySweeper] -> Webroot Software, Inc. [Ver = 5,2,3,2125 | Size = 219136 bytes | Modified Date = 06-11-01 17:17:38 | Attr = ]
< ContextMenuHandlers - Directory [HKLM] > -> HKEY_LOCAL_MACHINE\Software\Classes\Directory\shellex\ContextMenuHandlers\
{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} [HKLM] -> Reg Data - Key not found [PowerISO] -> File not found
{B41DB860-8EE4-11D2-9906-E49FADC173CA} [HKLM] -> %ProgramFiles%\WinRAR\RarExt.dll [WinRAR] -> [Ver = | Size = 121344 bytes | Modified Date = 04-12-27 10:56:08 | Attr = ]
< ContextMenuHandlers - Directory\Background [HKLM] > -> HKEY_LOCAL_MACHINE\Software\Classes\Directory\Background\shellex\ContextMenuHandlers\
{1E9B04FB-F9E5-4718-997B-B8DA88302A48} [HKLM] -> %System32%\nvshell.dll [00nView] -> [Ver = | Size = 466944 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} [HKLM] -> %System32%\igfxpph.dll [igfxcui] -> Intel Corporation [Ver = 3.0.0.3882 | Size = 225280 bytes | Modified Date = 04-08-03 20:47:00 | Attr = ]
{A70C977A-BF00-412C-90B7-034C51DA2439} [HKLM] -> %System32%\nvcpl.dll [NvCplDesktopContext] -> NVIDIA Corporation [Ver = 6.14.10.8421 | Size = 7561216 bytes | Modified Date = 06-03-09 14:29:00 | Attr = ]
{23F2DE6C-2C3F-4F95-B16A-56714C6FAAF4} [HKLM] -> Reg Data - Key not found [XPTools] -> File not found
< ContextMenuHandlers - Folder [HKLM] > -> HKEY_LOCAL_MACHINE\Software\Classes\Folder\shellex\ContextMenuHandlers\
{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} [HKLM] -> %ProgramFiles%\Nero\Nero 7\Nero BackItUp\NBShell.dll [NBShellHook Class] -> Nero AG [Ver = 2, 6, 6, 0 | Size = 73728 bytes | Modified Date = 06-10-09 21:11:32 | Attr = ]
{472083B0-C522-11CF-8763-00608CC02F24} [HKLM] -> %ProgramFiles%\Alwil Software\Avast4\ashShell.dll [avast] -> ALWIL Software [Ver = 4, 7, 869, 0 | Size = 13824 bytes | Modified Date = 06-08-05 01:17:58 | Attr = ]
{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} [HKLM] -> Reg Data - Key not found [PowerISO] -> File not found
{7C9D5882-CB4A-4090-96C8-430BFE8B795B} [HKLM] -> %ProgramFiles%\Webroot\Spy Sweeper\SSCtxMnu.dll [SpySweeper] -> Webroot Software, Inc. [Ver = 5,2,3,2125 | Size = 219136 bytes | Modified Date = 06-11-01 17:17:38 | Attr = ]
{B41DB860-8EE4-11D2-9906-E49FADC173CA} [HKLM] -> %ProgramFiles%\WinRAR\RarExt.dll [WinRAR] -> [Ver = | Size = 121344 bytes | Modified Date = 04-12-27 10:56:08 | Attr = ]
< ColumnHandlers - Folder [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{7D4D6379-F301-4311-BEBA-E26EB0561882} [HKLM] -> %CommonProgramFiles%\Ahead\Lib\NeroDigitalExt.dll [NeroDigitalColumnHandler Class] -> Nero AG [Ver = 2, 0, 0, 8 | Size = 1802240 bytes | Modified Date = 05-11-15 11:07:16 | Attr = ]
{FED7043D-346A-414D-ACD7-550D052499A7} [HKLM] -> %ProgramFiles%\Illustrate\dBpowerAMP\dBShell.dll [dBpShell Class] -> [Ver = 6, 4, 0, 1 | Size = 110592 bytes | Modified Date = 06-07-31 13:45:36 | Attr = ]
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
{C302D863-4E76-4BA1-BE82-93EFAEA842D4} -> (1394 Net Adapter) ->
{D8C10C11-EFCF-40E9-8540-A1A45C4A0852} -> (VIA Rhine II Fast Ethernet Adapter) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -> QuickTime Object - CodeBase =
http://www.apple.com...ex/qtplugin.cab ->
{166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase =
http://download.macr...director/sw.cab ->
{48884C41-EFAC-433D-958A-9FADAC41408E} -> EGamesPlugin Class - CodeBase =
https://www.e-games....GamesPlugin.cab ->
{5F8469B4-B055-49DD-83F7-62B522420ECC} -> Facebook Photo Uploader Control - CodeBase =
http://upload.facebo...otoUploader.cab ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} -> WUWebControl Class - CodeBase =
http://update.micros...b?1155341631876 ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.4.2_03 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} -> Java Plug-in 1.4.2_03 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
[Files - Created Wihin 30 days]
pcd.db -> %CommonProgramFiles%\Adobe\Adobe PCD\pcd.db -> [Ver = | Size = 45056 bytes | Created Date = 07-01-12 06:58:42 | Attr = ]
caps.db -> %CommonProgramFiles%\Adobe\caps\caps.db -> [Ver = | Size = 278528 bytes | Created Date = 07-01-12 06:53:20 | Attr = ]
FNPLicensingService.exe -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Created Date = 07-01-12 06:59:52 | Attr = ]
fnp_registrations.xml -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\fnp_registrations.xml -> [Ver = | Size = 327 bytes | Created Date = 07-01-12 06:59:54 | Attr = ]
cache.db -> %CommonProgramFiles%\Adobe\Adobe PCD\cache\cache.db -> [Ver = | Size = 15360 bytes | Created Date = 07-01-12 06:58:42 | Attr = ]
bridge.lnk -> %CommonProgramFiles%\Adobe\Launch\bridge\2.0\bridge.lnk -> [Ver = | Size = 1744 bytes | Created Date = 07-01-12 07:09:55 | Attr = ]
DeviceCentral.lnk -> %CommonProgramFiles%\Adobe\Launch\devicecentral\1.0\DeviceCentral.lnk -> [Ver = | Size = 889 bytes | Created Date = 07-01-12 07:11:30 | Attr = ]
ExtendScript Toolkit 2.lnk -> %CommonProgramFiles%\Adobe\Launch\estoolkit\2.0\ExtendScript Toolkit 2.lnk -> [Ver = | Size = 1078 bytes | Created Date = 07-01-12 07:08:10 | Attr = ]
Adobe Photoshop CS3.lnk -> %CommonProgramFiles%\Adobe\Launch\photoshop\10.0\en_US\Adobe Photoshop CS3.lnk -> [Ver = | Size = 840 bytes | Created Date = 07-01-12 07:02:09 | Attr = ]
ktd32.atm -> %SystemRoot%\ktd32.atm -> [Ver = | Size = 3783 bytes | Created Date = 07-01-12 06:51:13 | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 07-01-10 23:59:31 | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 07-01-10 23:59:30 | Attr = H ]
services.exe -> %SystemRoot%\services.exe -> [Ver = | Size = 350764 bytes | Created Date = 07-01-11 22:59:04 | Attr = HS]
unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 668 bytes | Created Date = 06-12-24 01:59:26 | Attr = ]
unvise32.exe -> %SystemRoot%\unvise32.exe -> MindVision Software [Ver = 3.6.1 | Size = 90112 bytes | Created Date = 06-12-29 12:46:32 | Attr = ]
winzipme.ini -> %SystemRoot%\winzipme.ini -> [Ver = | Size = 96 bytes | Created Date = 07-01-09 19:50:04 | Attr = ]
CmdLineExt03.dll -> %System32%\CmdLineExt03.dll -> [Ver = | Size = 43520 bytes | Created Date = 06-12-27 12:37:54 | Attr = ]
fservice.exe -> %System32%\fservice.exe -> [Ver = | Size = 350764 bytes | Created Date = 07-01-11 22:59:04 | Attr = HS]
fservice.exe.bat -> %System32%\fservice.exe.bat -> [Ver = | Size = 105 bytes | Created Date = 07-01-12 16:37:41 | Attr = ]
reginv.dll -> %System32%\reginv.dll -> [Ver = | Size = 36864 bytes | Created Date = 07-01-12 16:37:38 | Attr = ]
reginv.dll_tobedeleted -> %System32%\reginv.dll_tobedeleted -> [Ver = | Size = 36864 bytes | Created Date = 07-01-11 22:59:08 | Attr = ]
Winhp32.exe -> %System32%\Winhp32.exe -> [Ver = | Size = 1355784 bytes | Created Date = 07-01-09 19:42:13 | Attr = ]
winkey.dll -> %System32%\winkey.dll -> [Ver = | Size = 13312 bytes | Created Date = 07-01-12 16:37:35 | Attr = ]
winkey.dll_tobedeleted -> %System32%\winkey.dll_tobedeleted -> [Ver = | Size = 13312 bytes | Created Date = 07-01-11 22:59:05 | Attr = ]
xvid.ax -> %System32%\xvid.ax -> [Ver = | Size = 77824 bytes | Created Date = 06-12-22 20:53:25 | Attr = ]
xvidcore.dll -> %System32%\xvidcore.dll -> [Ver = | Size = 765952 bytes | Created Date = 06-12-22 20:53:25 | Attr = ]
xvidvfw.dll -> %System32%\xvidvfw.dll -> [Ver = | Size = 180224 bytes | Created Date = 06-12-22 20:53:24 | Attr = ]
[Files - Modified Wihin 30 days]
pcd.db -> %CommonProgramFiles%\Adobe\Adobe PCD\pcd.db -> [Ver = | Size = 45056 bytes | Modified Date = 07-01-12 07:13:10 | Attr = ]
caps.db -> %CommonProgramFiles%\Adobe\caps\caps.db -> [Ver = | Size = 278528 bytes | Modified Date = 07-01-12 07:13:12 | Attr = ]
FNPLicensingService.exe -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 07-01-12 06:59:54 | Attr = ]
fnp_registrations.xml -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\fnp_registrations.xml -> [Ver = | Size = 327 bytes | Modified Date = 07-01-12 14:41:48 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\Adobe Anchor Service\AMT\component.xml -> [Ver = | Size = 534 bytes | Modified Date = 07-01-12 06:59:58 | Attr = ]
cache.db -> %CommonProgramFiles%\Adobe\Adobe PCD\cache\cache.db -> [Ver = | Size = 15360 bytes | Modified Date = 07-01-12 14:42:28 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\DefaultLanguage\AMT\component.xml -> [Ver = | Size = 548 bytes | Modified Date = 07-01-12 07:04:46 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\TypeSupport\AMT\component.xml -> [Ver = | Size = 548 bytes | Modified Date = 07-01-12 07:06:28 | Attr = ]
bridge.lnk -> %CommonProgramFiles%\Adobe\Launch\bridge\2.0\bridge.lnk -> [Ver = | Size = 1744 bytes | Modified Date = 07-01-12 07:09:56 | Attr = ]
DeviceCentral.lnk -> %CommonProgramFiles%\Adobe\Launch\devicecentral\1.0\DeviceCentral.lnk -> [Ver = | Size = 889 bytes | Modified Date = 07-01-12 07:11:32 | Attr = ]
ExtendScript Toolkit 2.lnk -> %CommonProgramFiles%\Adobe\Launch\estoolkit\2.0\ExtendScript Toolkit 2.lnk -> [Ver = | Size = 1078 bytes | Modified Date = 07-01-12 07:08:12 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\PDFL\8.0\AMT\component.xml -> [Ver = | Size = 528 bytes | Modified Date = 07-01-12 07:12:20 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\TypeSupport\CMaps\AMT\component.xml -> [Ver = | Size = 532 bytes | Modified Date = 07-01-12 07:04:22 | Attr = ]
Adobe Photoshop CS3.lnk -> %CommonProgramFiles%\Adobe\Launch\photoshop\10.0\en_US\Adobe Photoshop CS3.lnk -> [Ver = | Size = 840 bytes | Modified Date = 07-01-12 07:02:10 | Attr = ]
component.xml -> %CommonProgramFiles%\Adobe\Linguistics\Providers\WinSoft\WRLiloPlugin1.0\AMT\component.xml -> [Ver = | Size = 545 bytes | Modified Date = 07-01-12 07:06:50 | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 07-01-12 16:40:38 | Attr = S]
IF40LE.INI -> %SystemRoot%\IF40LE.INI -> [Ver = | Size = 4816 bytes | Modified Date = 06-12-21 19:23:00 | Attr = ]
ktd32.atm -> %SystemRoot%\ktd32.atm -> [Ver = | Size = 3783 bytes | Modified Date = 07-01-12 21:35:08 | Attr = ]
NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 07-01-10 14:52:28 | Attr = ]
ppdrv.ini -> %SystemRoot%\ppdrv.ini -> [Ver = | Size = 114 bytes | Modified Date = 07-01-08 07:59:32 | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 07-01-10 23:59:32 | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 07-01-10 23:59:32 | Attr = H ]
services.exe -> %SystemRoot%\services.exe -> [Ver = | Size = 350764 bytes | Modified Date = 07-01-11 22:58:54 | Attr = HS]
unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 668 bytes | Modified Date = 06-12-24 01:59:28 | Attr = ]
unins000.exe -> %SystemRoot%\unins000.exe -> Jordan Russell [Ver = 51.5.0.0 | Size = 72748 bytes | Modified Date = 06-12-24 01:59:28 | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 1015 bytes | Modified Date = 07-01-10 03:03:26 | Attr = ]
wincmd.ini -> %SystemRoot%\wincmd.ini -> [Ver = | Size = 642 bytes | Modified Date = 07-01-12 15:57:58 | Attr = ]
winzipme.ini -> %SystemRoot%\winzipme.ini -> [Ver = | Size = 96 bytes | Modified Date = 07-01-09 19:50:06 | Attr = ]
WMSysPr9.prx -> %SystemRoot%\WMSysPr9.prx -> [Ver = | Size = 316640 bytes | Modified Date = 06-12-27 12:35:24 | Attr = ]
CmdLineExt03.dll -> %System32%\CmdLineExt03.dll -> [Ver = | Size = 43520 bytes | Modified Date = 06-12-28 12:46:06 | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 227208 bytes | Modified Date = 06-12-26 16:05:46 | Attr = ]
fservice.exe -> %System32%\fservice.exe -> [Ver = | Size = 350764 bytes | Modified Date = 07-01-11 22:58:54 | Attr = HS]
fservice.exe.bat -> %System32%\fservice.exe.bat -> [Ver = | Size = 105 bytes | Modified Date = 07-01-12 16:37:42 | Attr = ]
nvapps.xml -> %System32%\nvapps.xml -> [Ver = | Size = 50257 bytes | Modified Date = 07-01-12 16:42:32 | Attr = ]
reginv.dll -> %System32%\reginv.dll -> [Ver = | Size = 36864 bytes | Modified Date = 07-01-12 16:41:14 | Attr = ]
reginv.dll_tobedeleted -> %System32%\reginv.dll_tobedeleted -> [Ver = | Size = 36864 bytes | Modified Date = 07-01-12 15:21:10 | Attr = ]
Winhp32.exe -> %System32%\Winhp32.exe -> [Ver = | Size = 1355784 bytes | Modified Date = 07-01-09 19:42:10 | Attr = ]
winkey.dll -> %System32%\winkey.dll -> [Ver = | Size = 13312 bytes | Modified Date = 07-01-12 16:40:52 | Attr = ]
winkey.dll_tobedeleted -> %System32%\winkey.dll_tobedeleted -> [Ver = | Size = 13312 bytes | Modified Date = 07-01-12 15:21:08 | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 07-01-12 15:21:12 | Attr = ]
[File String Scan - Non-Microsoft Only]
PTech , -> %CommonProgramFiles%\Adobe\Adobe Asset Services CS3\Plug-Ins\Dicom.8bi -> Adobe Systems Incorporated [Ver = 1.0 | Size = 3399680 bytes | Modified Date = 06-11-28 19:10:26 | Attr = ]
WSUD , -> %CommonProgramFiles%\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\payloads\AdobeBridge2All\AdobeBridge2All.proxy.xml -> [Ver = | Size = 4139685 bytes | Modified Date = 06-12-05 17:02:50 | Attr = ]
WSUD , -> %CommonProgramFiles%\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\payloads\AdobeDeviceCentralAll\AdobeDeviceCentralAll.proxy.xml -> [Ver = | Size = 3978960 bytes | Modified Date = 06-12-01 17:50:28 | Attr = ]
CNNIC , -> %CommonProgramFiles%\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\payloads\AdobeExtendScriptToolKitAll\AdobeExtendScriptToolKitAll.proxy.xml -> [Ver = | Size = 1298334 bytes | Modified Date = 06-12-01 21:02:48 | Attr = ]
WSUD , -> %CommonProgramFiles%\Adobe\Installers\8d0dc9390f2c596455e1446b5918a40\payloads\AdobePhotoshop10en_US\AdobePhotoshop10en_US.proxy.xml -> [Ver = | Size = 6009509 bytes | Modified Date = 06-12-08 08:03:06 | Attr = ]
PTech , -> %CommonProgramFiles%\Adobe\Linguistics\Providers\Proximity\cze108.lex -> [Ver = | Size = 3916800 bytes | Modified Date = 05-03-16 18:15:32 | Attr = ]
PTech , -> %CommonProgramFiles%\Adobe\Linguistics\Providers\Proximity\11.00\cze108.lex -> [Ver = | Size = 7915520 bytes | Modified Date = 06-12-01 16:37:40 | Attr = ]
PEC2 , PECompact2 , -> %CommonProgramFiles%\Adobe\Updater\AdobeUpdaterApp.dll -> Adobe Systems Incorporated [Ver = 4, 0, 3, 26 | Size = 745984 bytes | Modified Date = 05-09-19 10:49:16 | Attr = ]
Umonitor , -> %CommonProgramFiles%\Ahead\Lib\ROLLBACK.DB -> [Ver = | Size = 508928 bytes | Modified Date = 06-10-22 17:27:44 | Attr = ]
UPX0 , -> %CommonProgramFiles%\Autodesk Shared\AcGradient16.dll -> Autodesk [Ver = 16.2.54.0 | Size = 12408 bytes | Modified Date = 05-03-05 04:18:10 | Attr = ]
PEC2 , -> %CommonProgramFiles%\GTK\2.0\bin\libglib-2.0-0.dll -> The GLib developer community [Ver = 2.6.6.0 | Size = 663547 bytes | Modified Date = 05-08-01 20:57:20 | Attr = ]
Thawte Consulting , -> %CommonProgramFiles%\Java\Update\Base Images\j2re1.4.2-b28\core3.zip -> [Ver = | Size = 4648893 bytes | Modified Date = 04-09-29 11:36:24 | Attr = ]
Thawte Consulting , -> %CommonProgramFiles%\Java\Update\Base Images\j2re1.4.2_03-b02\core3.zip -> [Ver = | Size = 4622375 bytes | Modified Date = 03-11-20 08:38:14 | Attr = ]
Thawte Consulting , -> %CommonProgramFiles%\Java\Update\Base Images\jre1.5.0.b64\core3.zip -> [Ver = | Size = 3290841 bytes | Modified Date = 05-03-04 03:09:40 | Attr = ]
WSUD , -> %CommonProgramFiles%\Microsoft Shared\SpeechEngines\TTS\female.vce -> [Ver = | Size = 2053632 bytes | Modified Date = 99-01-12 10:29:28 | Attr = ]
PTech , -> %CommonProgramFiles%\Microsoft Shared\Works Shared\1033\WkCalLng.dll -> Microsoft® Corporation [Ver = 7.02.0710.1 | Size = 196608 bytes | Modified Date = 02-07-11 06:22:04 | Attr = ]
PEC2 , WSUD , -> %CommonProgramFiles%\SpeechEngines\Microsoft\SR61\1033\AF031033.AM -> [Ver = | Size = 7048576 bytes | Modified Date = 02-11-22 10:27:36 | Attr = ]
PECompact2 , qoologic , SAHAgent , -> %SystemRoot%\LPT$VPN.516 -> [Ver = | Size = 13910687 bytes | Modified Date = 05-03-25 12:28:04 | Attr = ]
UPX! , UPX0 , -> %SystemRoot%\tsc.exe -> Trend Micro Inc. [Ver = 3.9.0.1020 | Size = 170053 bytes | Modified Date = 05-03-25 12:28:04 | Attr = ]
PECompact2 , qoologic , SAHAgent , -> %SystemRoot%\VPTNFILE.516 -> [Ver = | Size = 13910687 bytes | Modified Date = 05-03-25 12:28:04 | Attr = ]
UPX! , aspack , -> %SystemRoot%\vsapi32.dll -> Trend Micro Inc. [Ver = 7.510-1002 | Size = 1044560 bytes | Modified Date = 05-03-25 12:28:04 | Attr = ]
WSUD , -> %System32%\ALSNDMGR.CPL -> Realtek Semiconductor Corp. [Ver = 2.2.0.34 | Size = 16121856 bytes | Modified Date = 04-09-20 14:20:44 | Attr = ]
UPX! , UPX0 , -> %System32%\aswBoot.exe -> [Ver = 4, 7, 869, 0 | Size = 635520 bytes | Modified Date = 06-08-08 11:53:28 | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 04-08-04 07:00:00 | Attr = ]
PEC2 , PECompact2 , -> %System32%\DivX.dll -> DivX, Inc. [Ver = 6.4.0.51 | Size = 635486 bytes | Modified Date = 06-12-12 11:25:20 | Attr = ]
UPX! , UPX0 , -> %System32%\fservice.exe -> [Ver = | Size = 350764 bytes | Modified Date = 07-01-11 22:58:54 | Attr = HS]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 04-08-04 07:00:00 | Attr = ]
aspack , -> %System32%\winkey.dll -> [Ver = | Size = 13312 bytes | Modified Date = 07-01-12 16:40:52 | Attr = ]
aspack , -> %System32%\winkey.dll_tobedeleted -> [Ver = | Size = 13312 bytes | Modified Date = 07-01-12 15:21:08 | Attr = ]
< End of report >
Edited by heyyy, 12 January 2007 - 08:52 PM.