Page 22 of 36 FirstFirst ... 12202122232432 ... LastLast
Results 211 to 220 of 353

Thread: Help - trying to remove BraveSentry etc

  1. #211
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Holy Crap! sorry...now what the heck is going on? Hey, we are now up to 211 posts with this one...what the heck, let's go for 300!

  2. #212
    Join Date
    May 2007
    Posts
    194
    The drives are back again, at least.

  3. #213
    Join Date
    May 2007
    Posts
    194
    Haha... what comes after "Senior Member"?

  4. #214
    Join Date
    May 2007
    Posts
    194
    Internet's working again, too! I'm ashamed to admit what happened out of fear you'll think I don't know anything after all...

    I have two ethernet cords behind my tower, one of which goes to the network, one of which goes to nothing. Guess which one I plugged in first :-X

    But I've re-unplugged now, just in case.

  5. #215
    Join Date
    May 2007
    Posts
    194
    So, it looks like we can discount the last lump of posts about the disk drives, and we can go back to the fact that WPFind is giving me the error. Reminder: The error says "Access violation at address 00402849 in module Winpfind.exe. Read of address 013BFFFF" and then the scanner hangs on the task "Scanning ShellExecuteHooks key"

  6. #216
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Try this...
    ISeeYouXP
    Run in normal mode.


    Possible Error Messages

    -- If your ISeeYouXP.txt log appear to be empty or semi-empty or if you get an error message similar to the below
    when running ISeeYouXP.bat and you are running Windows XP or Windows 2000, follow the steps further down that relate
    to your OS

    C:\WINDOWS\SYSTEM32\AUTOEXEC.NT.
    The system file is not suitable for running MS-DOS and Microsoft Window applications.


    To fix the above error message, choose the download below which is appropriate for your system
    O For Windows XP Pro: download and run: XPproFix
    O For Windows XP Home: download and run: XPHomeFix
    O For Windows 2000: download and run: W2KFix

    Then run ISeeYouXP.bat again and attach the log.

    -- A possible second type of error message may occur as shown below! If you get either of these two messages,
    perform the Resolution steps given in this: Virtual Device Driver Error Message in 16-Bit MS-DOS Subsystem

    16 bit MS-DOS Subsystem

    drive:\program path

    XXXX. An installable Virtual Device Driver failed DLL initialization. Choose 'Close' to terminate the application.


    -or-

    16 bit MS-DOS Subsystem

    drive:\program path

    SYSTEM\CurrentControlSet\Control\VirtualDeviceDriv ers. VDD. Virtual Device Driver format in the registry is invalid.
    Choose 'Close' to terminate the application.


    After attempting to fix the above errors, run ISeeYouXP.bat again and attach the log.

  7. #217
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Quote Originally Posted by StckFigure View Post
    Internet's working again, too! I'm ashamed to admit what happened out of fear you'll think I don't know anything after all...

    I have two ethernet cords behind my tower, one of which goes to the network, one of which goes to nothing. Guess which one I plugged in first :-X

    But I've re-unplugged now, just in case.


    Haha... what comes after "Senior Member"?
    Old Timer's Disease

  8. #218
    Join Date
    May 2007
    Posts
    194
    This'll take three posts, it looks like. I see lots of NOT FOUNDs, which is nice! I also see
    **** PPTP Haxdoor FOUND by this tool! ****
    CAREFULL HERE THIS WILL ALSO FIND WinLanMiniport

    I don't know what the second part is.

    Beyond that, my untrained eye isn't really sure what I'm looking for anyway, so here's the whole thing!

    ************************************************** **********************************
    ISeeYouXP v2.0 Beta6

    ISeeYouXP v1.3.0-v2.0 Beta6 Copyright - ShadowPuterDude
    ISeeYouXP v1.2.9 and earlier Copyright - PhilliePhan
    ------------------------------------------------------------------------------------
    **** PLEASE NOTE THAT MOST (if not ALL) OF THE ITEMS BELOW ARE NOT BADDIES! ****
    **** PLEASE CONSULT A KNOWLEDGEABLE PERSON BEFORE TAKING ANY ACTION. ****
    ************************************************** **********************************

    Windows OS is:

    Microsoft Windows XP [Version 5.1.2600]
    It's Thu May 17, 2007 05:05:33 PM

    ------------------------------------------------------------------------------------

    ISeeYouXP installation folder and files

    "C:\ISeeYouXP\"
    change.log Apr 4 2007 3690 "change.log"
    chodefix.bat Feb 21 2007 5214 "chodefix.bat"
    egrep Dec 24 2004 35 "egrep"
    fgrep Dec 24 2004 35 "fgrep"
    fixexp~1.bat Feb 24 2007 487 "FixExplorerPolicies.bat"
    getunk~1.bat Aug 12 2006 1478 "GetUnKeys.bat"
    grep.exe Dec 24 2004 160768 "grep.exe"
    hideit.bat Mar 31 2007 1114 "HideIT.bat"
    iseeyo~1.bat Apr 7 2007 177450 "ISeeYouXP.bat"
    libico~1.dll Mar 16 2004 898048 "libiconv2.dll"
    libintl3.dll Oct 9 2004 101888 "libintl3.dll"
    locate.com Jan 14 2005 11254 "locate.com"
    ltime.exe Oct 28 1986 13184 "ltime.exe"
    msconf~1.bat Feb 24 2007 578 "MSConfigFix.bat"
    pcbutts.txt Mar 25 2007 5167 "PCBUTTS.TXT"
    pcre.dll Nov 14 2004 183313 "pcre.dll"
    regedi~1.bat Mar 30 2007 650 "RegEditFix.bat"
    showit.bat Mar 31 2007 1055 "ShowIT.bat"
    swreg.exe Apr 5 2007 139776 "swreg.exe"
    system~1.bat Feb 28 2007 369 "SystemRestoreFix.bat"
    taskmg~1.bat Feb 24 2007 288 "TaskMgrFix.bat"

    21 items found: 21 files, 0 directories.
    Total of file sizes: 1,705,841 bytes 1.63 M
    3 Dir(s) 56,363,982,848 bytes free

    ------------------------------------------------------------------------------------

    System Environment Variables

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Owner\Application Data
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
    CLIENTNAME=Console
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=EDDIE
    ComSpec=C:\WINDOWS\system32\cmd.exe
    errcode=0
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Owner
    LOGONSERVER=\\EDDIE
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\Sys tem32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\Common Files\Ulead Systems\Mpeg;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WS F;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL=15
    PROCESSOR_REVISION=2f02
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip
    RoxioCentral=C:\Program Files\Common Files\Roxio Shared\Roxio Central\
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
    TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp
    USERDOMAIN=EDDIE
    USERNAME=Owner
    USERPROFILE=C:\Documents and Settings\Owner
    windir=C:\WINDOWS
    __COMPAT_LAYER=EnableNXShowUI

    ------------------------------------------------------------------------------------

    Showing any Pocket Killbox backup files

    No matches found.

    ------------------------------------------------------------------------------------

    SYSTEM.INI:

    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    [mci]
    [driver32]
    [386enh]
    woafont=dosapp.FON
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    [Windows]
    load=

    ------------------------------------------------------------------------------------

    WIN.INI:

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [MCI Extensions.BAK]
    aif=MPEGVideo
    aifc=MPEGVideo
    aiff=MPEGVideo
    asf=MPEGVideo
    asx=MPEGVideo
    au=MPEGVideo
    m1v=MPEGVideo
    m3u=MPEGVideo
    mp2=MPEGVideo
    mp2v=MPEGVideo
    mp3=MPEGVideo
    mpa=MPEGVideo
    mpe=MPEGVideo
    mpeg=MPEGVideo
    mpg=MPEGVideo
    mpv2=MPEGVideo
    snd=MPEGVideo
    wax=MPEGVideo
    wm=MPEGVideo
    wma=MPEGVideo
    wmv=MPEGVideo
    wmx=MPEGVideo
    wpl=MPEGVideo
    wvx=MPEGVideo
    [WAOL]
    Installed=
    AppPath=C:\Program Files\America Online 9.0
    SharedPath=C:\Program Files\Common Files\AOLSHARE
    [Status]
    State=Running
    [ActiveScan]
    ID = {24D13F07-97AD-4E3D-BF12-277AEA90BD0E}
    [netsock]
    netapi.dll-VREKDD26FS-32b2=5505820
    netapi.dll-IZALEN0-312e=5505820
    [FISApp]
    CLSID=462025A221786122ED8F30
    [RAD Video Tools]
    Path=C:\Documents and Settings\Owner\Desktop\2\Digital Book
    BinkComp= /d650000 /m3.0 /l4 /p8
    BinkMix=
    SmackComp= /n250000 /m3.0 /l104 /v8
    SmackMix=/l104
    BinkPlay=
    SmackPlay=
    BinkConv= /n-1
    X=100
    Y=100
    W=526
    H=392
    LastVersionCheckDate=2007-04-12
    [FoxyTunesWMP]
    MessageBoxAnswer=0

    ------------------------------------------------------------------------------------

    LOG for Microsoft Windows Malicious Software Removal Tool:

    ---------------------------------------------------------------------------------------

    Microsoft Windows Malicious Software Removal Tool v1.25, February 2007
    Started On Sat Feb 17 00:24:46 2007

    Results Summary:
    ----------------
    No infection found.

    Return code: 0
    Microsoft Windows Malicious Software Removal Tool Finished On Sat Feb 17 00:25:03 2007


    ---------------------------------------------------------------------------------------

    Microsoft Windows Malicious Software Removal Tool v1.27, March 2007
    Started On Thu Mar 15 00:31:15 2007

    Results Summary:
    ----------------
    No infection found.

    Return code: 0
    Microsoft Windows Malicious Software Removal Tool Finished On Thu Mar 15 00:31:29 2007


    ---------------------------------------------------------------------------------------

    Microsoft Windows Malicious Software Removal Tool v1.28, April 2007
    Started On Thu Apr 12 23:44:02 2007

    Results Summary:
    ----------------
    No infection found.

    Return code: 0
    Microsoft Windows Malicious Software Removal Tool Finished On Thu Apr 12 23:44:18 2007


    ---------------------------------------------------------------------------------------

    Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
    Started On Mon May 14 03:17:42 2007

    Results Summary:
    ----------------
    No infection found.

    Return code: 0
    Microsoft Windows Malicious Software Removal Tool Finished On Mon May 14 03:18:56 2007

    ----------------------------------------------------------------------------
    Listing HKCU Explorer\Advanced//Hidden and SuperHidden Registry Keys
    if Hidden = 0 then Hidden Files and Folders are not shown
    if SuperHidden = 1 is the desired default value.
    if ShowSuperHidden = 0 then System Files are not shown
    if HideFileExt = 1 then File Extension are not shown
    We want their values to be (from top to bottom) 1,1,1,0
    ----------------------------------------------------------------------------

    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\advanced
    Hidden REG_DWORD 2 (0x2)
    SuperHidden REG_DWORD 1 (0x1)
    ShowSuperHidden REG_DWORD 1 (0x1)
    HideFileExt REG_DWORD 1 (0x1)

    ************************************************** **********************************

    Examining Select Windows Registry Keys
    ------------------------------------------------------------------------------------

    --------------------------------------------------------------------------
    Items Found in ZoneMap\Domains:
    --------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\internet settings\zonemap\domains
    <NO NAME> REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\internet settings\zonemap\domains\msn.com

    ----------------------------------------------------------------------------
    Current User ZoneMap ProtocolDefaults
    ----------------------------------------------------------------------------



    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\internet settings\zonemap\protocoldefaults
    <NO NAME> REG_SZ
    http REG_DWORD 3 (0x3)
    https REG_DWORD 3 (0x3)
    ftp REG_DWORD 3 (0x3)
    file REG_DWORD 3 (0x3)
    @ivt REG_DWORD 1 (0x1)
    shell REG_DWORD 0 (0x0)

    ----------------------------------------------------------------------------
    Default URL Prefix Keys
    ----------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\url

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\url\DefaultPrefix
    <NO NAME> REG_SZ http://

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\url\Prefixes
    ftp REG_SZ ftp://
    gopher REG_SZ gopher://
    home REG_SZ http://
    mosaic REG_SZ http://
    www REG_SZ http://

    --------------------------------------------------------------------------
    Startup Items Disabled via MSCONFIG:
    --------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services
    UleadBurningHelper REG_DWORD 2 (0x2)
    svcWRSSSDK REG_DWORD 2 (0x2)
    RoxWatch REG_DWORD 2 (0x2)
    RoxUpnpServer REG_DWORD 2 (0x2)
    RoxUPnPRenderer REG_DWORD 3 (0x3)
    RoxMediaDB REG_DWORD 3 (0x3)
    RoxLiveShare REG_DWORD 2 (0x2)
    AOL TopSpeedMonitor REG_DWORD 2 (0x2)
    AOL ACS REG_DWORD 2 (0x2)
    AFSEGTGF Windows Service REG_DWORD 2 (0x2)

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk
    path REG_SZ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup REG_SZ C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
    location REG_SZ Common Startup
    command REG_SZ C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE
    item REG_SZ Adobe Reader Speed Launch

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk
    path REG_SZ C:\Documents and Settings\All Users\Start Menu\Programs\BigFix\BigFix.lnk
    backup REG_SZ C:\WINDOWS\pss\BigFix.lnkCommon Startup
    location REG_SZ Common Startup
    command REG_SZ C:\PROGRA~1\BigFix\BigFix.exe /atstartup
    item REG_SZ BigFix

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk
    path REG_SZ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
    backup REG_SZ C:\WINDOWS\pss\Cisco Systems VPN Client.lnkCommon Startup
    location REG_SZ Common Startup
    command REG_SZ C:\VPNCLI~1\vpngui.exe "-user_logon"
    item REG_SZ Cisco Systems VPN Client

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^D-link AirPlus G DWL-G120 Wireless USB.lnk
    path REG_SZ C:\Documents and Settings\All Users\Start Menu\Programs\D-link AirPlus G DWL-G120 Wireless USB\D-link AirPlus G DWL-G120 Wireless USB.lnk
    backup REG_SZ C:\WINDOWS\pss\D-link AirPlus G DWL-G120 Wireless USB.lnkCommon Startup
    location REG_SZ Common Startup
    command REG_SZ C:\PROGRA~1\D-LINK~1\120UTIL.exe
    item REG_SZ D-link AirPlus G DWL-G120 Wireless USB

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ
    hkey REG_SZ HKLM
    command REG_SZ
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ
    hkey REG_SZ HKCU
    command REG_SZ
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ AOL
    hkey REG_SZ HKCU
    command REG_SZ "C:\Program Files\America Online 9.0\AOL.EXE" -b
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ AOLSP Scheduler
    hkey REG_SZ HKLM
    command REG_SZ "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ atiptaxx
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ ccApp
    hkey REG_SZ HKLM
    command REG_SZ "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ zHotkey
    hkey REG_SZ HKLM
    command REG_SZ zHotkey.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlPanel
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ cmd32
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\system32\cmd32.exe internat.dll,LoadKeyboardProfile
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ ehtray
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\ehome\ehtray.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Explorer32
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ efsdfgxg
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\system32\efsdfgxg.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ AOLSoftware
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Common Files\AOL\1123358120\ee\AOLSoftware.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ hpztsb07
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 7.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon04
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ hphmon04
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\system32\hphmon04.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD04
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ hphupd04
    hkey REG_SZ HKLM
    command REG_SZ "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ cfgwiz
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ mcagent
    hkey REG_SZ HKLM
    command REG_SZ c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ mcupdate
    hkey REG_SZ HKLM
    command REG_SZ C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ msmsgs
    hkey REG_SZ HKCU
    command REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ NeroCheck
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ PSDrvCheck
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ PlaxoHelper
    hkey REG_SZ HKCU
    command REG_SZ C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ qttask
    hkey REG_SZ HKLM
    command REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ RECGUARD
    hkey REG_SZ HKLM
    command REG_SZ %WINDIR%\SMINST\RECGUARD.EXE
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ Remind_XP
    hkey REG_SZ HKLM
    command REG_SZ %WINDIR%\Creator\Remind_XP.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ PDVDServ
    hkey REG_SZ HKLM
    command REG_SZ "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ DrgToDsc
    hkey REG_SZ HKLM
    command REG_SZ "C:\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ RoxWatchTray
    hkey REG_SZ HKLM
    command REG_SZ "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run
    key REG_SZ SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    item REG_SZ services
    hkey REG_SZ HKCU
    command REG_SZ C:\WINDOWS\inet20099\services.exe
    inimapping REG_SZ 1

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySheriff
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ SpySheriff
    hkey REG_SZ HKCU
    command REG_SZ C:\Program Files\SpySheriff\SpySheriff.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ UsrPrmpt
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StickIt
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ
    hkey REG_SZ HKCU
    command REG_SZ
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StickIt Note Launcher (Required to load StickIt notes on Windows startup)
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ StickItLauncher
    hkey REG_SZ HKCU
    command REG_SZ C:\Stickit\StickItLauncher.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ shwiconem
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Digital Media Reader\shwiconem.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunServer
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ sunserver
    hkey REG_SZ HKLM
    command REG_SZ C:\CounterSpy\Consumer\sunserver.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ UrlLstCk
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\Norton Internet Security\UrlLstCk.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows installer
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ winstall
    hkey REG_SZ HKCU
    command REG_SZ C:\winstall.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xp_system
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ services
    hkey REG_SZ HKLM
    command REG_SZ C:\WINDOWS\inet20099\services.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\_AntiSpyware
    key REG_SZ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    item REG_SZ MssCli
    hkey REG_SZ HKLM
    command REG_SZ C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe
    inimapping REG_SZ 0

    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\state
    system.ini REG_DWORD 0 (0x0)
    win.ini REG_DWORD 0 (0x0)
    bootini REG_DWORD 0 (0x0)
    services REG_DWORD 2 (0x2)
    startup REG_DWORD 2 (0x2)

  9. #219
    Join Date
    May 2007
    Posts
    194
    Part 2

    --------------------------------------------------------------------------
    Select AutoRun Registry Keys:
    --------------------------------------------------------------------------



    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run
    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
    swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe


    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\runonce


    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\runonceex


    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\runservices


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run
    SoundMan REG_SZ SOUNDMAN.EXE
    CTSysVol REG_SZ C:\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
    P17Helper REG_SZ Rundll32 P17.dll,P17Helper
    WinFast Schedule REG_SZ C:\WinFast\WFTVFM\WFWIZ.exe
    <NO NAME> REG_SZ
    ATIMACE REG_SZ MACE.exe
    ccApp REG_SZ "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\OptionalComponents


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runonce


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runonceex
    Flag REG_SZ 
    Windows Update REG_SZ C:\WINDOWS\scvhost.exe


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runservices


    Error: Key: software\microsoft\windows\currentversion\runservi cesonce does not exist!



    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run


    Error: Key: .default\software\microsoft\windows\currentversion \runonce does not exist!



    HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run


    Error: Key: s-1-5-18\software\microsoft\windows\currentversion\runon ce does not exist!



    HKEY_USERS\s-1-5-19\software\microsoft\windows\currentversion\run


    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\runon ce does not exist!



    HKEY_USERS\s-1-5-20\software\microsoft\windows\currentversion\run


    Error: Key: s-1-5-20\software\microsoft\windows\currentversion\runon ce does not exist!



    Error: Key: s-1-5-18\microsoft\windows nt\currentversion\windows\load does not exist!



    Error: Key: software\microsoft\windows nt\currentversion\windows\run does not exist!


    --------------------------------------------------------------------------
    WinLogon Notify Registry Key:
    --------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent
    DLLName REG_SZ Ati2evxx.dll
    Asynchronous REG_DWORD 0 (0x0)
    Impersonate REG_DWORD 1 (0x1)
    Lock REG_SZ AtiLockEvent
    Logoff REG_SZ AtiLogoffEvent
    Logon REG_SZ AtiLogonEvent
    Disconnect REG_SZ AtiDisConnectEvent
    Reconnect REG_SZ AtiReConnectEvent
    Safe REG_DWORD 0 (0x0)
    Shutdown REG_SZ AtiShutdownEvent
    StartScreenSaver REG_SZ AtiStartScreenSaverEvent
    StartShell REG_SZ AtiStartShellEvent
    Startup REG_SZ AtiStartupEvent
    StopScreenSaver REG_SZ AtiStopScreenSaverEvent
    Unlock REG_SZ AtiUnLockEvent

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
    Asynchronous REG_DWORD 0 (0x0)
    Impersonate REG_DWORD 0 (0x0)
    DllName REG_EXPAND_SZ crypt32.dll
    Logoff REG_SZ ChainWlxLogoffEvent

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
    Asynchronous REG_DWORD 0 (0x0)
    Impersonate REG_DWORD 0 (0x0)
    DllName REG_EXPAND_SZ cryptnet.dll
    Logoff REG_SZ CryptnetWlxLogoffEvent

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
    DLLName REG_SZ cscdll.dll
    Logon REG_SZ WinlogonLogonEvent
    Logoff REG_SZ WinlogonLogoffEvent
    ScreenSaver REG_SZ WinlogonScreenSaverEvent
    Startup REG_SZ WinlogonStartupEvent
    Shutdown REG_SZ WinlogonShutdownEvent
    StartShell REG_SZ WinlogonStartShellEvent
    Impersonate REG_DWORD 0 (0x0)
    Asynchronous REG_DWORD 1 (0x1)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
    DLLName REG_SZ wlnotify.dll
    Logon REG_SZ SCardStartCertProp
    Logoff REG_SZ SCardStopCertProp
    Lock REG_SZ SCardSuspendCertProp
    Unlock REG_SZ SCardResumeCertProp
    Enabled REG_DWORD 1 (0x1)
    Impersonate REG_DWORD 1 (0x1)
    Asynchronous REG_DWORD 1 (0x1)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
    Asynchronous REG_DWORD 0 (0x0)
    DllName REG_EXPAND_SZ wlnotify.dll
    Impersonate REG_DWORD 0 (0x0)
    StartShell REG_SZ SchedStartShell
    Logoff REG_SZ SchedEventLogOff

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
    Logoff REG_SZ WLEventLogoff
    Impersonate REG_DWORD 0 (0x0)
    Asynchronous REG_DWORD 1 (0x1)
    DllName REG_EXPAND_SZ sclgntfy.dll

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
    DLLName REG_SZ WlNotify.dll
    Lock REG_SZ SensLockEvent
    Logon REG_SZ SensLogonEvent
    Logoff REG_SZ SensLogoffEvent
    Safe REG_DWORD 1 (0x1)
    MaxWait REG_DWORD 600 (0x258)
    StartScreenSaver REG_SZ SensStartScreenSaverEvent
    StopScreenSaver REG_SZ SensStopScreenSaverEvent
    Startup REG_SZ SensStartupEvent
    Shutdown REG_SZ SensShutdownEvent
    StartShell REG_SZ SensStartShellEvent
    PostShell REG_SZ SensPostShellEvent
    Disconnect REG_SZ SensDisconnectEvent
    Reconnect REG_SZ SensReconnectEvent
    Unlock REG_SZ SensUnlockEvent
    Impersonate REG_DWORD 1 (0x1)
    Asynchronous REG_DWORD 1 (0x1)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
    Asynchronous REG_DWORD 0 (0x0)
    DllName REG_EXPAND_SZ wlnotify.dll
    Impersonate REG_DWORD 0 (0x0)
    Logoff REG_SZ TSEventLogoff
    Logon REG_SZ TSEventLogon
    PostShell REG_SZ TSEventPostShell
    Shutdown REG_SZ TSEventShutdown
    StartShell REG_SZ TSEventStartShell
    Startup REG_SZ TSEventStartup
    MaxWait REG_DWORD 600 (0x258)
    Reconnect REG_SZ TSEventReconnect
    Disconnect REG_SZ TSEventDisconnect

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon
    Logon REG_SZ WLEventLogon
    Logoff REG_SZ WLEventLogoff
    Startup REG_SZ WLEventStartup
    Shutdown REG_SZ WLEventShutdown
    StartScreenSaver REG_SZ WLEventStartScreenSaver
    StopScreenSaver REG_SZ WLEventStopScreenSaver
    Lock REG_SZ WLEventLock
    Unlock REG_SZ WLEventUnlock
    StartShell REG_SZ WLEventStartShell
    PostShell REG_SZ WLEventPostShell
    Disconnect REG_SZ WLEventDisconnect
    Reconnect REG_SZ WLEventReconnect
    Impersonate REG_DWORD 1 (0x1)
    Asynchronous REG_DWORD 0 (0x0)
    SafeMode REG_DWORD 1 (0x1)
    MaxWait REG_DWORD -1 (0xffffffff)
    DllName REG_EXPAND_SZ WgaLogon.dll
    Event REG_DWORD 0 (0x0)
    EulaAccepted REG_DWORD 0 (0x0)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon\Setting s
    Data REG_BINARY 01000000d08c9ddf0115d1118c7a00c04fc297eb010000002a 7e88bac6d2bb489c00c780818e259404000000040000005300 000003660000a8000000100000007a285a36d51418470a1dda e2c92a2d900000000004800000a0000000100000005adf3a0e 19deddc251630e0767049704b00100008111d36050c9c2b007 5df641e7c49ad9438c8dca801c5c6a57e8a8602b801f10294c 5844a79f5fed412b77ff5859e143488effb0b6e5b4d23d5121 f02ad1e3be6ce71eab9d5accf13f98494bbbbe15d36dd9d0aa 0ee2f5d493cfd6200fbe545b0db994e96ee1471ce100fb6f80 80509f4896c8124dbd88a5b87c8acd224b3a155c99f64a275a 8eb814598589ba36342f8177872aee3ff8b1e10a963df4378a 8509c8710ed8c244719489ccebfc7879984adef99aa630380b 4dae1685ec13c47021858a32cc91909aaa0533fa8389013d04 37c88d628cce1347ddf633db3fc00605e19610c4458ee6df52 fd255455c9ae9f96425dad38022667382fba7d076f271fd958 88385d2005b54b750d7e90ebbcf931a718c02b5e8746031c55 e6f531ad686608ca112405666c2798e7e9b051c52b18270181 6a53a6fce3ddc854945cd1d9cfb3afb82999a69b8a3dca506b e149c8f2a3765e0b811670212910c9f8b5308fe9a4a6e96be1 e54c8612740e81f153585e92e8f7ffebdd278f516c16390d09 1cf05d07db71e2cdef89cf78b4609473d4aaf81879b3bdbc4d a925c43b11384630a91475de5f24d97bd6437b6b911b191400 00007d3f8d1ef105e9af98602c5808afc7ca5117141c

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
    DLLName REG_SZ wlnotify.dll
    Logon REG_SZ RegisterTicketExpiredNotificationEvent
    Logoff REG_SZ UnregisterTicketExpiredNotificationEvent
    Impersonate REG_DWORD 1 (0x1)
    Asynchronous REG_DWORD 1 (0x1)

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WRNotifier
    Asynchronous REG_DWORD 0 (0x0)
    DllName REG_SZ WRLogonNTF.dll
    Impersonate REG_DWORD 1 (0x1)
    Lock REG_SZ WRLock
    StartScreenSaver REG_SZ WRStartScreenSaver
    StartShell REG_SZ WRStartShell
    Startup REG_SZ WRStartup
    StopScreenSaver REG_SZ WRStopScreenSaver
    Unlock REG_SZ WRUnlock
    Shutdown REG_SZ WRShutdown
    Logoff REG_SZ WRLogoff
    Logon REG_SZ WRLogon

    --------------------------------------------------------------------------
    Shared Task Scheduler Registry Items:
    --------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\sharedtaskscheduler
    {438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
    {8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon

    --------------------------------------------------------------------------
    Scheduled Tasks:
    --------------------------------------------------------------------------

    Volume in drive C has no label.
    Volume Serial Number is 10D3-D6EE

    Directory of C:\WINDOWS\tasks

    05/16/2007 04:05 PM <DIR> .
    05/16/2007 04:05 PM <DIR> ..
    05/16/2007 02:39 PM 284 AppleSoftwareUpdate.job
    08/10/2004 02:00 PM 65 desktop.ini
    12/11/2005 06:08 PM 258 ISP signup reminder 2.job
    12/11/2005 06:08 PM 258 ISP signup reminder 3.job
    05/04/2007 08:23 PM 548 Norton AntiVirus - Scan my computer - Owner.job
    05/17/2007 03:24 PM 6 SA.DAT
    05/17/2007 04:10 PM 364 Symantec NetDetect.job
    05/17/2007 11:38 AM 422 User_Feed_Synchronization-{0BECA80B-B388-4AE3-AF65-66E87AAB161E}.job
    8 File(s) 2,205 bytes

    Total Files Listed:
    8 File(s) 2,205 bytes
    2 Dir(s) 56,363,909,120 bytes free
    A C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    HR C:\WINDOWS\tasks\desktop.ini
    A C:\WINDOWS\tasks\ISP signup reminder 2.job
    A C:\WINDOWS\tasks\ISP signup reminder 3.job
    A C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Owner.job
    A H C:\WINDOWS\tasks\SA.DAT
    A C:\WINDOWS\tasks\Symantec NetDetect.job
    A H C:\WINDOWS\tasks\User_Feed_Synchronization-{0BECA80B-B388-4AE3-AF65-66E87AAB161E}.job

    ----------------------------------------------------------------------------
    ShellExecuteHooks Registry Keys
    ----------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\shellexecutehooks
    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
    {076394AD-7FDD-44EF-A075-32C68DBAB99B} REG_SZ
    {57B86673-276A-48B2-BAE7-C6DBB3020EB8} REG_SZ AVG Anti-Spyware 7.5

    ----------------------------------------------------------------------------
    ShellServiceObjectDelayLoad Registry Keys
    ----------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\shellserviceobjectdelayload
    PostBootReminder REG_SZ {7849596a-48ea-486e-8937-a2a3009f31a9}
    CDBurn REG_SZ {fbeb8a05-beee-4442-804e-409d6c4515e9}
    WebCheck REG_SZ {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
    SysTray REG_SZ {35CEC8A3-2BE6-11D2-8773-92E220524153}

    ----------------------------------------------------------------------------
    ModuleUsage Registry Keys:
    ----------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/asinst.dll
    .Owner REG_SZ {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
    {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/asquared.ocx
    .Owner REG_SZ {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9}
    {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/CacheManager.ocx
    .Owner REG_SZ {DA80E089-4648-43D5-93B4-7F37917084E6}
    {DA80E089-4648-43D5-93B4-7F37917084E6} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/cpcScan.dll
    .Owner REG_SZ {A90A5822-F108-45AD-8482-9BC8B12DD539}
    {A90A5822-F108-45AD-8482-9BC8B12DD539} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/FacebookPhotoUploader.ocx
    .Owner REG_SZ {5F8469B4-B055-49DD-83F7-62B522420ECC}
    {5F8469B4-B055-49DD-83F7-62B522420ECC} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/hrtbeat.ocx
    .Owner REG_SZ {E5D419D6-A846-4514-9FAD-97E826C84822}
    {E5D419D6-A846-4514-9FAD-97E826C84822} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/ZIntro.ocx
    .Owner REG_SZ {B8BE5E93-A60C-4D26-A2DC-220313175592}
    {B8BE5E93-A60C-4D26-A2DC-220313175592} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/Downloaded Program Files/zsetup.exe
    .Owner REG_SZ {E5D419D6-A846-4514-9FAD-97E826C84822}
    {E5D419D6-A846-4514-9FAD-97E826C84822} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/system32/GWFSPidGen.DLL
    .Owner REG_SZ Unknown Owner
    {17492023-C23A-453E-A040-C7C580BBF700} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/system32/LegitCheckControl.DLL
    .Owner REG_SZ Unknown Owner
    {17492023-C23A-453E-A040-C7C580BBF700} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/system32/msinet.ocx
    .Owner REG_SZ Unknown Owner
    {DA80E089-4648-43D5-93B4-7F37917084E6} REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\moduleusage\C:/WINDOWS/system32/muweb.dll
    .Owner REG_SZ {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} REG_SZ

    ----------------------------------------------------------------------------
    BHO Registry Keys:
    ----------------------------------------------------------------------------



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects
    <NO NAME> REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    <NO NAME> REG_SZ

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}
    <NO NAME> REG_SZ Norton Internet Security

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{BDF3E430-B101-42AD-A544-FADC6B084872}
    <NO NAME> REG_SZ NAV Helper

    --------------------------------------------------------------------------
    Select Policy Keys:
    --------------------------------------------------------------------------



    Error: Key: software\microsoft\windows\currentversion\policies \run does not exist!



    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer
    NoDriveTypeAutoRun REG_DWORD 145 (0x91)
    NoFolderOptions REG_DWORD 0 (0x0)
    NoRun REG_DWORD 0 (0x0)

    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer\run


    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer\run


    HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system
    DisableRegistryTools REG_DWORD 0 (0x0)


    HKEY_CURRENT_USER\software\policies\microsoft\inte rnet explorer

    HKEY_CURRENT_USER\software\policies\microsoft\inte rnet explorer\Control Panel


    Error: Key: software\microsoft\windows\currentversion\policies \run does not exist!



    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer
    NoCDBurning REG_DWORD 0 (0x0)
    NoFolderOptions REG_DWORD 0 (0x0)

    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer\Run


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer\run


    HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system
    dontdisplaylastusername REG_DWORD 0 (0x0)
    legalnoticecaption REG_SZ
    legalnoticetext REG_SZ
    shutdownwithoutlogon REG_DWORD 1 (0x1)
    undockwithoutlogon REG_DWORD 1 (0x1)
    InstallVisualStyle REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    InstallTheme REG_EXPAND_SZ C:\WINDOWS\Resources\Themes\Royale.theme


    Error: Key: software\policies\microsoft\internet explorer\run does not exist!



    Error: Key: .default\software\microsoft\windows\currentversion \policies\run does not exist!



    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer
    NoDriveTypeAutoRun REG_DWORD 145 (0x91)
    CDRAutoRun REG_DWORD 0 (0x0)

    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer\run


    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer\run


    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies

    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\Explorer

    HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\System


    Error: Key: .default\software\policies\microsoft\internet explorer does not exist!



    Error: Key: s-1-5-18\software\microsoft\windows\currentversion\polic ies\run does not exist!



    HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\polic ies\explorer
    NoDriveTypeAutoRun REG_DWORD 145 (0x91)
    CDRAutoRun REG_DWORD 0 (0x0)

    HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\polic ies\explorer\run


    HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\polic ies\explorer\run


    HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\polic ies\system


    Error: Key: s-1-5-18\software\policies\microsoft\internet explorer does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\run does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\explorer\run does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\system does not exist!



    Error: Key: s-1-5-19\software\policies\microsoft\internet explorer does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\run does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\explorer\run does not exist!



    Error: Key: s-1-5-19\software\microsoft\windows\currentversion\polic ies\system does not exist!



    Error: Key: s-1-5-19\software\policies\microsoft\internet explorer does not exist!


    ************************************************** **********************************

    Checking File System for suspicious Files

    --------------------------------------------------------------------------
    Items in the Root Directory:
    --------------------------------------------------------------------------

    Locating all files created in C:\

    "C:\"
    AD-AWA~1 Dec 13 2005 "Ad-Aware SE Personal"
    ADOBEP~1 Dec 12 2005 "Adobe Photoshop CS2"
    AGENTN~1 May 14 2006 "Agent Newsreader"
    ANTIVI~1 Jan 19 2006 "AntiVirPersonal"
    aolcon~1.exe Dec 11 2005 10920 "aolconnfix.exe"
    aolcon~1.txt Dec 11 2005 1039 "aolconnfix.txt"
    AUDACITY Mar 3 2007 "Audacity"
    audio.log Aug 6 2005 193 "audio.log"
    AUSLOG~1 May 16 2007 "AusLogics Disk Defrag"
    autoexec.bat Dec 13 2005 95 "AUTOEXEC.BAT"
    AVGANT~1.5 May 9 2007 "AVG Anti-Spyware 7.5"
    AZUREUS May 16 2006 "Azureus"
    BINARY~1 May 14 2006 "Binary Boy"
    BOGGLE Dec 15 2005 "Boggle"
    boot.ini May 15 2007 209 "boot.ini"
    BUNDLE Apr 13 2005 "Bundle"
    CABS Jan 18 2006 "cabs"
    CCLEANER Dec 2 2006 "CCleaner"
    CMPNENTS Apr 13 2005 "CMPNENTS"
    COLLEC~1 Jul 15 2006 "Collectorz"
    combofix.txt May 15 2007 16111 "ComboFix.txt"
    combof~1.txt May 15 2007 5408 "ComboFix-quarantined-files.txt"
    combof~2.txt May 14 2007 17609 "ComboFix2.txt"
    combof~3.txt May 15 2007 5408 "ComboFix-quarantined-files515.txt"
    config.sys Apr 13 2005 0 "CONFIG.SYS"
    COUNTE~1 Jan 20 2006 "CounterSpy"
    CREATIVE Dec 12 2005 "Creative"
    DARTKA~1 Jul 26 2006 "DART Karaoke Studio CDG"
    debug.log Oct 8 2006 42507 "debug.log"
    DIAMOND May 7 2007 "Diamond"
    DIGITA~1 Dec 11 2005 "Digital Pictures"
    DISCJU~1 Feb 7 2006 "DiscJuggler"
    DOCUME~1 Apr 13 2005 "Documents and Settings"
    DOCUME~2 Dec 12 2005 "Documents"
    DRAMAT~1 Apr 30 2006 "Dramatica Pro"
    DRIVERS Apr 2 2007 "Drivers"
    DVDLAB~1 Feb 7 2006 "DVDlabPro"
    DVDSANTA Oct 8 2006 "dvdSanta"
    DVDSHR~1 Apr 28 2006 "DVDShrink"
    EASYDV~1 Feb 2 2006 "EasyDVDConverter"
    err_log.txt Mar 24 2007 52 "err_log.txt"
    FINALD~1 May 6 2006 "Final Draft 7"
    GADWIN~1 Apr 28 2007 "Gadwin Systems"
    GOOGLE~1 Apr 28 2006 "Google SketchUp"
    graph.txt Dec 5 2006 1001 "graph.txt"
    hiberfil.sys May 17 2007 2145964032 "hiberfil.sys"
    HIJACK~1 May 11 2007 "HijackThis199"
    hpfr5550.xml Jul 28 2006 564 "hpfr5550.xml"
    hph7150.log Jul 28 2006 63890 "hph7150.log"
    io.sys Apr 13 2005 0 "IO.SYS"
    iph.ph Dec 17 2006 877 "IPH.PH"
    ISEEYO~1 May 17 2007 "ISeeYouXP"
    JEOPAR~1 Apr 1 2006 "Jeopardy! 2nd Edition"
    JEOPAR~2 May 17 2006 "Jeopardy! 2003"
    LAST~1.FMP May 23 2006 "Last.fm Player"
    LEXMARK Aug 24 2006 "lexmark"
    LIMEWIRE Jan 18 2007 "LimeWire"
    LINKSY~1 Feb 1 2007 "Linksys EasyLink Advisor"
    lmab.log Mar 12 2007 195 "lmab.log"
    log.dat Jul 27 2006 2 "log.dat"
    MACROM~1 Dec 13 2005 "Macromedia"
    MAGICD~1 Mar 20 2007 "MagicDVDRipper"
    MAGICISO Feb 7 2006 "MagicISO"
    MAGICW~1 Mar 15 2007 "Magic Workstation"
    MAXIS Dec 13 2005 "Maxis"
    MICROP~1 Dec 15 2005 "Microprose"
    MICROS~1 Dec 12 2005 "Microsoft Office"
    MIRC Dec 11 2005 "mIRC"
    MOVIEM~1 Apr 30 2006 "Movie Magic Screenwriter"
    MOVIES Dec 12 2005 "Movies"
    MOZILL~1 May 16 2007 "Mozilla Firefox"
    msdos.sys Apr 13 2005 0 "MSDOS.SYS"
    MSOCACHE Dec 12 2005 "MSOCache"
    MYMUSI~1 Aug 6 2005 "My Music"
    MYDOWN~1 Feb 11 2006 "My Downloads"
    MYSTER~1 Apr 30 2006 "Mystery Case Files Huntsville"
    napster.log Aug 6 2005 160 "napster.log"
    NERO7~1 Nov 12 2006 "Nero 7"
    NESTER Aug 2 2006 "Nester"
    ntdetect.com Aug 10 2004 47564 "NTDETECT.COM"
    ntldr Aug 10 2004 250032 "ntldr"
    ORGANI~1 Jul 27 2006 "Organizers"
    OZUM May 21 2006 "Ozum"
    pagefile.sys May 17 2007 2145894400 "pagefile.sys"
    pcsimo~1.rar Oct 14 2006 202689801 "PC Simon The Sorcerer 2+XP Patch.rar"
    PINNACLE Dec 13 2005 "Pinnacle"
    POPCAP~2 Dec 13 2005 "PopCap Games"
    POWERP~1 Apr 17 2006 "PowerPlugs"
    PROGRA~1 Aug 6 2005 "Program Files"
    RADVIDEO Mar 24 2007 "RADVideo"
    rapport.txt May 9 2007 2409 "rapport.txt"
    RECYCLER Aug 6 2005 "RECYCLER"
    REFLEX~1 May 6 2006 "Reflexive Arcade"
    REGCLE~1 May 16 2007 "RegCleaner"
    REGORG~1 Mar 12 2007 "Reg Organizer"
    ROXIO Feb 7 2006 "Roxio"
    SCRABBLE Dec 15 2005 "Scrabble"
    SETIAT~1 May 16 2006 "SETI At Home"
    SIDMEI~1 Dec 12 2005 "Sid Meier's Civilization 4"
    smitfi~1.txt Jan 19 2006 1441 "smitfiles.txt"
    SNES9X Aug 3 2006 "SNES9x"
    SNOOD Dec 15 2005 "Snood"
    SPSSST~1 Dec 12 2005 "SPSS Student"
    SPYBOT~1 Dec 13 2005 "Spybot - Search & Destroy"
    SPYWAR~1 May 16 2007 "SpywareBlaster"
    sqmdat~1.sqm Feb 23 2007 268 "sqmdata00.sqm"
    sqmdat~2.sqm Mar 18 2007 268 "sqmdata01.sqm"
    sqmdat~3.sqm Apr 7 2007 268 "sqmdata02.sqm"
    sqmnoo~1.sqm Feb 23 2007 244 "sqmnoopt00.sqm"
    sqmnoo~2.sqm Mar 18 2007 244 "sqmnoopt01.sqm"
    sqmnoo~3.sqm Apr 7 2007 244 "sqmnoopt02.sqm"
    STARCR~1 Dec 14 2005 "Starcraft"
    STICKIT Dec 15 2005 "Stickit"
    SURETH~1 Apr 21 2006 "SureThing"
    SYSTEM~1 Aug 6 2005 "System Volume Information"
    TEMP Jan 23 2006 "temp"
    TEMPDVD Nov 11 2006 "TempDVD"
    TEMP_DVD Feb 10 2006 "temp_dvd"
    THEFON~1 Mar 12 2007 "The Font Thing"
    TIGERW~2 Jun 20 2006 "Tiger Woods PGA TOUR 06"
    TRILLIAN Nov 25 2006 "Trillian"
    TROJAN~1.6 May 11 2007 "TrojanHunter 4.6"
    ULEADC~1 Dec 19 2005 "Ulead COOL 3D Studio"
    ULTIMA~1 Apr 9 2006 "Ultima Online Mondain's Legacy"
    USENEXT Mar 24 2007 "UseNeXT"
    VIDEOLAN Feb 19 2006 "VideoLAN"
    VPNCLI~1 Apr 22 2006 "VPN Client"
    WALLPA~1 Dec 12 2005 "wallpaper"
    WEBROOT Dec 13 2005 "Webroot"
    WINAVI~1 Oct 8 2006 "WinAVIVideoConverter"
    WINDOWS Apr 13 2005 "WINDOWS"
    WINFAST Jan 18 2006 "WinFast"
    WINFAS~1 Jan 18 2006 "WinFast WorkArea"
    WINRAR Dec 13 2005 "WinRAR"
    YAHOO! Sep 10 2006 "Yahoo!"
    YDKJ Apr 1 2006 "YDKJ"

    137 items found: 34 files (14 H/S), 103 directories (3 H/S).
    Total of file sizes: 4,495,017,455 bytes 4.18 G

    --------------------------------------------------------------------------
    Locating all Backup files on C:
    --------------------------------------------------------------------------

    Locating all *.BAK* files

    "C:\Magic Workstation\"
    magicw~1.bak Aug 11 2005 3008000 "MagicWorkstation.exe.bak"

    "C:\WINDOWS\"
    imsins.bak May 14 2007 1374 "imsins.BAK"

    "C:\LimeWire\Incomplete\"
    downlo~1.bak Apr 2 2007 275 "downloads.bak"

    "C:\Documents and Settings\All Users\DRM\"
    drmv1.bak Feb 1 2006 4348 "DRMv1.bak"

    "C:\Program Files\Common Files\Symantec Shared\"
    persist.bak May 16 2007 11060 "Persist.BAK"

    "C:\WINDOWS\Debug\UserMode\"
    userenv.bak Apr 12 2007 308884 "userenv.bak"

    "C:\WINDOWS\erdnt\subs\"
    software.bak May 14 2007 35856384 "software.bak"
    system.bak May 14 2007 6897664 "system.bak"

    "C:\WINDOWS\system32\config\"
    default.bak May 14 2007 524288 "default.bak"
    sam.bak May 14 2007 28672 "SAM.bak"
    security.bak May 14 2007 98304 "SECURITY.bak"
    software.bak May 14 2007 35913728 "software.bak"
    system.bak May 14 2007 7077888 "system.bak"

    "C:\WINDOWS\system32\NtmsData\"
    ntmsdata.bak Jan 30 2006 159744 "NTMSDATA.BAK"

    "C:\Documents and Settings\Owner\Application Data\Azureus\"
    azureu~1.bak May 16 2007 251 "azureus.statistics.bak"
    azureu~2.bak May 16 2007 14420 "azureus.config.bak"
    banips~1.bak Apr 29 2007 73 "banips.config.bak"
    downlo~1.bak May 16 2007 690 "downloads.config.bak"
    tracke~1.bak May 16 2007 14 "tracker.config.bak"

    "C:\Documents and Settings\Owner\Application Data\LimeWire\"
    fileurns.bak Mar 4 2007 3507 "fileurns.bak"

    "C:\Documents and Settings\Owner\Application Data\UseNeXT\"
    articl~1.bak Mar 24 2007 11 "articlestatus.dat.bak"
    config~1.bak Mar 24 2007 271 "config.dat.bak"
    downlo~1.bak Mar 24 2007 11 "downloadqueue.dat.bak"
    subscr~1.bak Mar 24 2007 15 "subscribed.dat.bak"
    wizard~1.bak Mar 24 2007 11 "wizard.dat.bak"

    "C:\Program Files\Common Files\Symantec Shared\IDS\"
    idssettg.bak May 16 2007 4372 "IDSSettg.BAK"

    "C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\"
    settings.bak May 17 2007 8699396 "settings.bak"

    "C:\Documents and Settings\Owner\Application Data\Ahead\NeroVision\"
    gchwcfg.bak Dec 16 2006 97 "GCHWCfg.bak"

    "C:\Documents and Settings\Owner\Application Data\Azureus\active\"
    961672~1.bak Mar 24 2007 18477 "9616727FD99803656867B7E09B2B0CB0AAA3840A.dat. bak"

    "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\"
    drmv1key.bak Feb 1 2006 4348 "drmv1key.bak"
    drmv1lic.bak Apr 29 2007 20 "drmv1lic.bak"
    drmv2key.bak Feb 12 2006 488 "drmv2key.bak"
    drmv2lic.bak Apr 29 2007 36864 "drmv2lic.bak"

    "C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\Recording\"
    record~1.bak May 17 2007 520 "Recordings.xml.bak"

    "C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\"
    opa11.bak Oct 17 2002 8200 "OPA11.BAK"

    "C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\9wzhox2s.default\"
    bookma~1.bak May 17 2007 93672 "bookmarks.bak"

    36 items found: 36 files (4 H/S), 0 directories.
    Total of file sizes: 98,776,341 bytes 94.20 M

  10. #220
    Join Date
    May 2007
    Posts
    194
    Part 3

    --------------------------------------------------------------------------
    Items in Document and Settings:
    --------------------------------------------------------------------------

    Listing contents of C:\Documents and Settings

    "C:\Documents and Settings\"
    ADMINI~1 Apr 13 2005 "Administrator"
    ALLUSE~1 Apr 13 2005 "All Users"
    DEFAUL~1 Apr 13 2005 "Default User"
    LOCALS~1 Apr 13 2005 "LocalService"
    NETWOR~1 Apr 13 2005 "NetworkService"
    OWNER Dec 11 2005 "Owner"

    6 items found: 0 files, 6 directories (3 H/S).

    --------------------------------------------------------------------------
    Desktop Items:
    --------------------------------------------------------------------------

    Locating all files created in C:\Documents and Settings\Owner\Desktop within the last 90 days.

    "C:\Documents and Settings\Owner\Desktop\"
    2 Mar 8 2007 "2"
    analyzer.exe May 10 2007 1308216 "Analyzer.exe"
    atf-cl~1.exe May 10 2007 50688 "atf-cleaner.exe"
    auslog~1.lnk May 16 2007 573 "AusLogics Disk Defrag.lnk"
    avgark~1.exe May 11 2007 423736 "avgarkt-setup-1.1.0.42.exe"
    avgas-~1.exe May 10 2007 11470608 "avgas-setup-7.5.0.50.exe"
    avgasr~1.exe May 11 2007 11470608 "avgasroot-setup-7.5.0.50.exe"
    BACKUPS May 13 2007 "backups"
    combined.ppt May 6 2007 1580032 "Combined.ppt"
    combofix.exe May 15 2007 1091621 "ComboFix.exe"
    deafet~1.doc May 3 2007 136704 "DeafEthicalGuidelinesrh[1].doc"
    diskde~1.exe May 17 2007 1510059 "diskdefrag_install.exe"
    DRIVERS May 17 2007 "drivers"
    dvd200~1.zip May 18 2007 674593 "dvd20050506090450171_TS-H552B_TS10.zip"
    firefo~1.exe May 16 2007 6006832 "Firefox Setup 2.0.0.3.exe"
    fixme.reg May 16 2007 549 "fixme.reg"
    fsbl-2~1.log May 13 2007 1150 "fsbl-20070513211745.log"
    fsbl.exe May 14 2007 899952 "fsbl.exe"
    hijack~1.log May 16 2007 9304 "hijackthis.log"
    idea_n~1.doc May 7 2007 53760 "IDEA_NCLB.doc"
    instal~1.exe May 16 2007 1163592 "install_flash_player.exe"
    intern~1.doc May 3 2007 162816 "Internet_Search_Practices-proposal.doc"
    joseph~1.doc May 7 2007 28160 "Joseph_Proposal.doc"
    jre-6u~1.exe May 16 2007 370328 "jre-6u1-windows-i586-p-iftw.exe"
    jre-6u~2.exe May 16 2007 13801120 "jre-6u1-windows-i586-p-s.exe"
    mirc621.exe May 16 2007 1367553 "mirc621.exe"
    propos~1.doc Apr 23 2007 30208 "proposals.doc"
    propos~2.doc May 2 2007 1688576 "Proposal-JeffGoetz-Edited.doc"
    propos~3.doc May 6 2007 1553408 "Proposal-JeffGoetz-FInal.doc"
    RAGTIME May 7 2007 "Ragtime"
    realav~1.txt May 10 2007 39568 "RealavgReport-Scan-20070510-195552.txt"
    regcle~1.exe May 17 2007 553687 "regcleaner.exe"
    regcle~1.lnk May 16 2007 513 "RegCleaner.lnk"
    ROBERT~1 Apr 25 2007 "Robert Wuhl - Assume the Position"
    SMITFR~1 May 8 2007 "SmitfraudFix"
    smitfr~1.exe May 8 2007 875511 "SmitfraudFix.exe"
    spywar~1.exe May 17 2007 2566736 "spywareblastersetup351.exe"
    spywar~1.lnk May 16 2007 558 "SpywareBlaster.lnk"
    SQUEAK~1.9-W Apr 4 2007 "Squeak3.9-win32"
    squeak~1.zip Apr 4 2007 12351408 "Squeak3.9-win32.zip"
    startu~1.zip May 17 2007 58671 "StartupCPL.zip"
    statsf~1.doc May 7 2007 125440 "statsfinal.doc"
    stinger.exe May 13 2007 1893383 "stinger.exe"
    stinger.opt May 13 2007 22 "stinger.opt"
    SYSTEM~1 May 17 2007 "systembkuip"
    thumbs.db Feb 22 2007 83456 "Thumbs.db"
    trojan~1.exe May 11 2007 12594978 "TrojanHunterSetup.exe"
    trojan~1.lnk May 11 2007 560 "TrojanHunter.lnk"
    TUNEUP~1 May 11 2007 "Tuneup_Utilities_2007_+_Keygen"
    uninst~1.txt May 11 2007 8401 "uninstall_list.txt"
    WINPFIND May 16 2007 "WinPFind"
    winpfind.exe May 17 2007 267222 "winpfind.exe"
    WINPFI~1 May 14 2007 "WinPFind3u"
    winpfi~1.exe May 15 2007 353350 "winpfind3u.exe"
    xpprof~1.exe May 18 2007 94208 "XPProfiles.exe"

    55 items found: 44 files (1 H/S), 11 directories.
    Total of file sizes: 88,722,418 bytes 84.61 M

    Locating all files created in C:\Documents and Settings\All Users\Desktop\ within the last 90 days.

    "C:\Documents and Settings\All Users\Desktop\"
    avgant~1.lnk May 9 2007 589 "AVG Anti-Spyware.lnk"
    mozill~1.lnk May 16 2007 1414 "Mozilla Firefox.lnk"

    2 items found: 2 files, 0 directories.
    Total of file sizes: 2,003 bytes 1.95 K

    --------------------------------------------------------------------------
    Start Menu Items:
    --------------------------------------------------------------------------

    Locating all files created inC:\Documents and Settings\Owner\Start Menu within the last 90 days.

    No matches found.

    Locating all files created in C:\Documents and Settings\Owner\Start Menu\Programs\Startup within the last 90 days.

    No matches found.

    Locating all files created in C:\Documents and Settings\All Users\Start Menu within the last 90 days.

    "C:\Documents and Settings\All Users\Start Menu\"
    micros~1.lnk Mar 9 2007 1566 "Microsoft Update.lnk"

    1 item found: 1 file, 0 directories.
    Total of file sizes: 1,566 bytes 1.53 K

    Locating all files created in C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    Application Data Items:
    --------------------------------------------------------------------------

    Locating all files created in C:\Documents and Settings\Owner\Application Data\ within the last 90 days.

    "C:\Documents and Settings\Owner\Application Data\"
    APPLEC~1 Feb 17 2007 "Apple Computer"
    MOVENE~1 Apr 17 2007 "Move Networks"
    MOZILLA May 16 2007 "Mozilla"
    rdr~1.ini May 8 2007 16 ".rdr.ini"
    TALKBACK May 16 2007 "Talkback"
    TROJAN~1 May 11 2007 "TrojanHunter"
    USENEXT Mar 24 2007 "UseNeXT"

    7 items found: 1 file, 6 directories (1 H/S).
    Total of file sizes: 16 bytes 0.02 K

    Locating all files created in C:\Documents and Settings\Owner\Local Settings\Application Data\ within the last 90 days.

    "C:\Documents and Settings\Owner\Local Settings\Application Data\"
    CHEMTA~1 Mar 12 2007 "ChemTable Software"
    dcbc2a~1.ini May 17 2007 13824 "DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini"
    gdipfo~1.dat Mar 17 2007 100176 "GDIPFONTCACHEV1.DAT"
    iconca~1.db May 11 2007 1575460 "IconCache.db"
    MOZILLA May 16 2007 "Mozilla"
    rx_aud~1.cac Mar 8 2007 2108 "rx_audio.Cache"

    6 items found: 4 files (1 H/S), 2 directories.
    Total of file sizes: 1,691,568 bytes 1.61 M

    Locating all files created in C:\Documents and Settings\All Users\Application Data\ within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\Documents and Settings\Owner\Local Settings\TEMP:
    --------------------------------------------------------------------------

    Locating all files created in C:\Documents and Settings\Owner\Local Settings\TEMP within the last 90 days.

    --------------------------------------------------------------------------
    Items in Templates Folder:
    --------------------------------------------------------------------------

    Locating all files created in C:\Documents and Settings\Owner\Templates

    "C:\Documents and Settings\Owner\Templates\"
    amipro.sam Aug 10 2004 4570 "amipro.sam"
    excel.xls Aug 10 2004 5632 "excel.xls"
    excel4.xls Aug 10 2004 1518 "excel4.xls"
    lotus.wk4 Aug 10 2004 2448 "lotus.wk4"
    powerpnt.ppt Aug 10 2004 12288 "powerpnt.ppt"
    presenta.shw Aug 10 2004 461 "presenta.shw"
    quattro.wb2 Aug 10 2004 4017 "quattro.wb2"
    sndrec.wav Aug 10 2004 58 "sndrec.wav"
    winword.doc Aug 10 2004 4608 "winword.doc"
    winword2.doc Aug 10 2004 1769 "winword2.doc"
    wordpfct.wpd Aug 10 2004 30 "wordpfct.wpd"
    wordpfct.wpg Aug 10 2004 57 "wordpfct.wpg"

    12 items found: 12 files, 0 directories.
    Total of file sizes: 37,456 bytes 36.58 K

    --------------------------------------------------------------------------
    Items in Program Files:
    --------------------------------------------------------------------------

    Locating all files created in C:\Program Files\ within the last 90 days.

    "C:\Program Files\"
    MFINST~1 May 7 2007 "MFInstall"
    OFB11 May 8 2007 "Ofb11"
    VIRTOOLS Apr 14 2007 "Virtools"

    3 items found: 0 files, 3 directories.

    Locating all files created in C:\Program Files\Common Files\ within the last 90 days.

    No matches found.

    Locating all files created in C:\Program Files\Common Files\Microsoft Shared\Web Folders within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    Items in the Windows Directory:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\ within the last 90 days.

    "C:\WINDOWS\"
    $N20DA~1 Apr 11 2007 "$NtUninstallKB931261$"
    $N44E0~1 Feb 17 2007 "$NtUninstallKB928255$"
    $N48B0~1 Feb 17 2007 "$NtUninstallKB927802$"
    $N50B4~1 Apr 5 2007 "$NtUninstallKB925902$"
    $N50EE~1 Apr 11 2007 "$NtUninstallKB931784$"
    $N54CA~1 Feb 17 2007 "$NtUninstallKB918118$"
    $N5CC0~1 Feb 17 2007 "$NtUninstallKB926436$"
    $N5CD8~1 Feb 17 2007 "$NtUninstallKB928843$"
    $N64D6~1 Apr 11 2007 "$NtUninstallKB932168$"
    $N64D6~2 Apr 11 2007 "$NtUninstallKB930178$"
    $N68BA~1 Feb 17 2007 "$NtUninstallKB931836$"
    $N68DC~1 Mar 15 2007 "$NtUninstallKB929338$"
    $N6CD0~1 Feb 17 2007 "$NtUninstallKB924667$"
    $N74A6~1 May 14 2007 "$NtUninstallKB930916$"
    $N80F4~1 Feb 17 2007 "$NtUninstallKB927779$"
    0.log May 17 2007 0 "0.log"
    bootstat.dat May 17 2007 2048 "bootstat.dat"
    catchme.exe Apr 21 2007 86528 "catchme.exe"
    comsetup.log May 14 2007 216709 "comsetup.log"
    cs_cache.ini May 8 2007 4317 "cs_cache.ini"
    directx.log May 7 2007 36432 "DirectX.log"
    ehocgen.log May 14 2007 35638 "ehOCGen.log"
    ERDNT May 14 2007 "erdnt"
    faxsetup.log May 14 2007 624178 "FaxSetup.log"
    ie4err~1.txt May 7 2007 1083 "IE4 Error Log.txt"
    iis6.log May 14 2007 709006 "iis6.log"
    ijl11.dll Mar 24 2007 71168 "ijl11.dll"
    imsins.bak May 14 2007 1374 "imsins.BAK"
    imsins.log May 14 2007 1374 "imsins.log"
    iun506.exe Feb 28 2007 286720 "iun506.exe"
    kb918118.log Feb 17 2007 24060 "KB918118.log"
    kb924667.log Feb 17 2007 24287 "KB924667.log"
    kb925902.log Apr 5 2007 12323 "KB925902.log"
    kb926436.log Feb 17 2007 26250 "KB926436.log"
    kb927779.log Feb 17 2007 31026 "KB927779.log"
    kb927802.log Feb 17 2007 28122 "KB927802.log"
    kb9280~1.log Feb 17 2007 22807 "KB928090-IE7.log"
    kb928255.log Feb 17 2007 27786 "KB928255.log"
    kb928843.log Feb 17 2007 24065 "KB928843.log"
    kb929338.log Mar 15 2007 12094 "KB929338.log"
    kb930178.log Apr 11 2007 12597 "KB930178.log"
    kb930916.log May 14 2007 10621 "KB930916.log"
    kb931261.log Apr 11 2007 12290 "KB931261.log"
    kb931784.log Apr 11 2007 14273 "KB931784.log"
    kb9317~1.log May 14 2007 16811 "KB931768-IE7.log"
    kb931836.log Feb 17 2007 36779 "KB931836.log"
    kb932168.log Apr 11 2007 14198 "KB932168.log"
    medctroc.log May 14 2007 71564 "MedCtrOC.log"
    mozver.dat May 16 2007 657 "mozver.dat"
    msgsocm.log May 14 2007 31462 "msgsocm.log"
    msmqinst.log May 14 2007 196276 "msmqinst.log"
    mswinsck.ocx Mar 24 2007 108336 "mswinsck.ocx"
    nerodi~1.ini May 17 2007 116 "NeroDigital.ini"
    netfxocm.log May 14 2007 123049 "netfxocm.log"
    ntbtlog.txt May 17 2007 88220464 "ntbtlog.txt"
    ntdtcs~1.log May 14 2007 129651 "ntdtcsetup.log"
    ocgen.log May 14 2007 303416 "ocgen.log"
    ocmsn.log May 14 2007 34401 "ocmsn.log"
    offlog.txt May 9 2007 2568 "offlog.txt"
    pavsig.txt Mar 24 2007 32 "pavsig.txt"
    PIF Feb 28 2007 "PIF"
    plusoc.log May 14 2007 72249 "plusoc.log"
    popcinfo.dat Feb 27 2007 17 "popcinfo.dat"
    qtfont.for May 7 2007 1409 "QTFont.for"
    qtfont.qfn May 16 2007 54156 "QTFont.qfn"
    schedlgu.txt May 17 2007 32620 "SchedLgU.Txt"
    screen~1.bmp Mar 24 2007 3932214 "screenshot.bmp"
    screen~1.jpg Mar 24 2007 235309 "screenshot.jpg"
    setupact.log May 8 2007 355801 "setupact.log"
    setupapi.log May 17 2007 314023 "setupapi.log"
    system.ini May 15 2007 219 "system.ini"
    tabletoc.log May 14 2007 32083 "tabletoc.log"
    TEMP May 15 2007 "temp"
    thumbs.db May 17 2007 62464 "Thumbs.db"
    tsoc.log May 14 2007 295871 "tsoc.log"
    updspapi.log May 14 2007 69951 "updspapi.log"
    webcam.bmp May 4 2007 230454 "webcam.bmp"
    wganot~1.log Mar 9 2007 18140 "WgaNotify.log"
    wiadebug.log May 17 2007 159 "wiadebug.log"
    wiaservc.log May 17 2007 49 "wiaservc.log"
    win.ini May 16 2007 1094 "win.ini"
    window~1.log May 17 2007 1522951 "WindowsUpdate.log"
    wininit.ini May 8 2007 115 "WININIT.INI"
    wmsetup.log May 16 2007 133134 "wmsetup.log"

    84 items found: 66 files (3 H/S), 18 directories (16 H/S).
    Total of file sizes: 99,013,438 bytes 94.43 M

    --------------------------------------------------------------------------
    C:\WINDOWS\Downloaded Program Files:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\Downloaded Program Files\ within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\WINDOWS\PCHealth\HelpCtr\Binaries:
    --------------------------------------------------------------------------

    Locating all files in C:\WINDOWS\PCHealth\HelpCtr\Binaries

    "C:\WINDOWS\pchealth\helpctr\binaries\"
    brpinfo.dll Aug 10 2004 21504 "brpinfo.dll"
    hcappres.dll Aug 10 2004 6656 "HCAppRes.dll"
    helpctr.exe Aug 10 2004 768512 "HelpCtr.exe"
    helphost.exe Aug 10 2004 99840 "HelpHost.exe"
    helpsvc.exe Aug 10 2004 743936 "HelpSvc.exe"
    hscmui.cab Aug 10 2004 68327 "hscmui.cab"
    hscsp_w3.cab Aug 10 2004 305145 "hscsp_w3.cab"
    hscupd.exe Aug 10 2004 18944 "HscUpd.exe"
    msconfig.exe Aug 10 2004 158208 "msconfig.exe"
    msinfo.dll Aug 10 2004 376320 "msinfo.dll"
    notiflag.exe Aug 10 2004 35328 "notiflag.exe"
    pchdt_w3.cab Aug 10 2004 2737914 "pchdt_w3.cab"
    pchshell.dll Aug 10 2004 102400 "pchshell.dll"
    pchsvc.dll Aug 10 2004 38912 "pchsvc.dll"

    14 items found: 14 files, 0 directories.
    Total of file sizes: 5,481,946 bytes 5.23 M

    --------------------------------------------------------------------------
    C:\WINDOWS\system:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\system within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\WINDOWS\system32:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\system32 within the last 90 days.

    "C:\WINDOWS\system32\"
    advpack.dll Mar 7 2007 124928 "advpack.dll"
    click.exe May 8 2007 177152 "click.exe"
    d3d9caps.dat May 13 2007 664 "d3d9caps.dat"
    extmgr.dll Mar 7 2007 132608 "extmgr.dll"
    flash.exe May 8 2007 179200 "flash.exe"
    fntcache.dat Apr 5 2007 336744 "FNTCACHE.DAT"
    gdi32.dll Mar 8 2007 281600 "gdi32.dll"
    help.ico Mar 24 2007 1406 "Help.ico"
    ie4uinit.exe Mar 7 2007 56832 "ie4uinit.exe"
    ieakeng.dll Mar 7 2007 153088 "ieakeng.dll"
    ieaksie.dll Mar 7 2007 230400 "ieaksie.dll"
    ieakui.dll Feb 21 2007 161792 "ieakui.dll"
    ieapfltr.dat Apr 2 2007 2453952 "ieapfltr.dat"
    ieapfltr.dll Apr 3 2007 383488 "ieapfltr.dll"
    iedkcs32.dll Mar 7 2007 384000 "iedkcs32.dll"
    ieframe.dll Mar 7 2007 6054400 "ieframe.dll"
    iernonce.dll Mar 7 2007 44544 "iernonce.dll"
    iertutil.dll Mar 7 2007 266752 "iertutil.dll"
    ieudinit.exe Feb 27 2007 13824 "ieudinit.exe"
    inetcpl.cpl Mar 7 2007 1823744 "inetcpl.cpl"
    jsproxy.dll Mar 7 2007 27136 "jsproxy.dll"
    keylog.dll May 11 2007 3072 "keylog.dll"
    kr_done1 May 8 2007 1 "kr_done1"
    lexfiles.ulf Mar 12 2007 4466 "LexFiles.ulf"
    mf3216.dll Mar 8 2007 40960 "mf3216.dll"
    mrt.exe Apr 27 2007 14970328 "MRT.exe"
    msfeeds.dll Mar 7 2007 458752 "msfeeds.dll"
    msfeed~1.dll Mar 7 2007 51712 "msfeedsbs.dll"
    mshtml.dll Mar 7 2007 3581952 "mshtml.dll"
    mshtmled.dll Mar 7 2007 477696 "mshtmled.dll"
    msinet.oca Apr 26 2007 29184 "MSINET.oca"
    msrating.dll Mar 7 2007 193024 "msrating.dll"
    mstime.dll Mar 7 2007 670720 "mstime.dll"
    ntkrnlpa.exe Feb 28 2007 2057600 "ntkrnlpa.exe"
    ntoskrnl.exe Feb 28 2007 2180352 "ntoskrnl.exe"
    occache.dll Mar 7 2007 102400 "occache.dll"
    pavas.ico Mar 24 2007 30590 "pavas.ico"
    perfc009.dat May 14 2007 53544 "perfc009.dat"
    perfh009.dat May 14 2007 382594 "perfh009.dat"
    perfst~1.ini May 14 2007 442074 "PerfStringBackup.INI"
    stream~1.dll May 11 2007 59392 "streamhlp.dll"
    swreg.exe Apr 2 2007 428032 "swreg.exe"
    thumbs.db May 17 2007 24064 "Thumbs.db"
    tmp.reg May 9 2007 2624 "tmp.reg"
    tmp.txt May 9 2007 0 "tmp.txt"
    tzlog.log Feb 17 2007 122436 "TZLog.log"
    uninst~1.ico Mar 24 2007 2550 "Uninstall.ico"
    url.dll Mar 7 2007 105984 "url.dll"
    urlmon.dll Mar 7 2007 1150464 "urlmon.dll"
    user32.dll Mar 8 2007 577536 "user32.dll"
    webcheck.dll Mar 7 2007 232960 "webcheck.dll"
    win32k.sys Mar 8 2007 1843584 "win32k.sys"
    wininet.dll Mar 7 2007 822784 "wininet.dll"
    winsrv.dll Mar 17 2007 292864 "winsrv.dll"
    wpa.dbl May 16 2007 1170 "wpa.dbl"
    xpsp3res.dll Mar 9 2007 248320 "xpsp3res.dll"

    56 items found: 56 files (1 H/S), 0 directories.
    Total of file sizes: 44,934,039 bytes 42.85 M

    --------------------------------------------------------------------------
    C:\WINDOWS\system32\com:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\system32\com within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\WINDOWS\system32\components:
    --------------------------------------------------------------------------
    Locating all files created in C:\WINDOWS\system32\components within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\WINDOWS\system32\drivers:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\system32\drivers within the last 90 days.

    No matches found.

    --------------------------------------------------------------------------
    C:\WINDOWS\system32\drivers\etc:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\system32\drivers\etc within the last 90 days.

    "C:\WINDOWS\system32\drivers\etc\"
    hosts May 14 2007 27 "hosts"

    1 item found: 1 file, 0 directories.
    Total of file sizes: 27 bytes 0.02 K

    --------------------------------------------------------------------------
    C:\WINDOWS\TEMP:
    --------------------------------------------------------------------------

    Locating all files created in C:\WINDOWS\TEMP within the last 90 days.

    "C:\WINDOWS\temp\"
    COOKIES May 16 2007 "Cookies"
    HISTORY May 16 2007 "History"
    TEMPOR~1 May 16 2007 "Temporary Internet Files"
    wgaerr~1.txt May 17 2007 255 "WGAErrLog.txt"
    wganot~1.set May 17 2007 409 "WGANotify.settings"

    5 items found: 2 files, 3 directories (3 H/S).
    Total of file sizes: 664 bytes 0.65 K

    ************************************************** **********************************

    Checking for .COM files to Delete. They will only print if deleted!

    Locating .COM files in the C:\WINDOWS\System32 folder

    "C:\WINDOWS\system32\"
    chcp.com Aug 10 2004 7680 "chcp.com"
    command.com Aug 17 2001 50620 "command.com"
    diskcomp.com Aug 10 2004 9216 "diskcomp.com"
    diskcopy.com Aug 10 2004 7168 "diskcopy.com"
    edit.com Aug 10 2004 69886 "edit.com"
    format.com Aug 10 2004 25600 "format.com"
    graftabl.com Aug 10 2004 26112 "graftabl.com"
    graphics.com Aug 10 2004 19694 "graphics.com"
    kb16.com Aug 10 2004 14710 "kb16.com"
    loadfix.com Aug 10 2004 1131 "loadfix.com"
    locate.com Jan 14 2005 11254 "locate.com"
    mode.com Aug 10 2004 19456 "mode.com"
    more.com Aug 10 2004 15872 "more.com"
    tree.com Aug 10 2004 11264 "tree.com"
    win.com Aug 10 2004 18432 "win.com"

    15 items found: 15 files, 0 directories.
    Total of file sizes: 308,095 bytes 300.87 K

    ************************************************** **********************************

    Miscellaneous Malware Detections:
    ------------------------------------------------------------------------------------


    **** Delfin Media {31EE3286-D785-4E3F-95FC-51D00FDABC01} NOT FOUND by this tool! ****

    **** SmitFraud {0BC9BC01-54D4-4CCE-2B7D-955164314CD4} NOT FOUND by this tool! ****

    **** SpywareStrike {C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D} NOT FOUND by this tool! ****

    **** SpywareStrike {C1A2FDA2-2A5B-2C8A-F2A2-BA2DB3A2C31C} NOT FOUND by this tool! ****

    **** SpywareStrike {D81E2FC4-B0A2-11D3-21AC-07C04C21A18A} NOT FOUND by this tool! ****

    **** SpyAxe {A1D9D3F0-8C2A-9A1D-A376-2CACFB10AB72} NOT FOUND by this tool! ****

    **** SpyAxe {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} NOT FOUND by this tool! ****

    **** SpyAxe {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} NOT FOUND by this tool! ****

    **** SpyAxe {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72} NOT FOUND by this tool! ****

    **** SpyAxe {A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} NOT FOUND by this tool! ****

    **** SpyFalcon {A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} NOT FOUND by this tool! ****

    **** SpyFalcon {C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D} NOT FOUND by this tool! ****

    **** SpyFalcon {CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E} NOT FOUND by this tool! ****

    **** SpyFalcon {35a88e51-b53d-43e9-b8a7-75d4c31b4676} NOT FOUND by this tool! ****

    **** SpyFalcon {64ba30a2-811a-4597-b0af-d551128be340} NOT FOUND by this tool! ****

    **** SpyFalcon {89aef01d-d237-49c7-84dc-4e1904c1fd31} NOT FOUND by this tool! ****

    **** SpyFalcon {e04408db-4812-4478-8d4d-e46edcffd3b6} NOT FOUND by this tool! ****

    **** SpyFalcon {336ec37f-54bf-4f13-8237-03f64fa591e7} NOT FOUND by this tool! ****

    **** SpyFalcon {5bc82bdb-bc03-4671-9a78-3ef2b68449de} NOT FOUND by this tool! ****

    **** SpyFalcon {24c60b9b-26b5-4201-9f7a-fb9219356ae9} NOT FOUND by this tool! ****

    **** SpyFalcon {a0c51615-738a-4542-801a-5af61614e182} NOT FOUND by this tool! ****

    **** SpyFalcon {70fbd528-2d3c-4a00-9b8c-bbf441e534be} NOT FOUND by this tool! ****

    **** SpyFalcon {a566f298-05a6-4b3d-b672-da7c27316430} NOT FOUND by this tool! ****

    **** SpyFalcon {f5947202-e9cb-4a72-88e7-22f2cbd2b124} NOT FOUND by this tool! ****

    **** SpyFalcon {5aaf6542-f4ba-4df4-873d-4902ecbe794c} NOT FOUND by this tool! ****

    **** SpyFalcon {3e4155b8-5a4a-4e95-83b2-ab032da9acbc} NOT FOUND by this tool! ****

    **** SpyFalcon {9952355f-fefb-4764-bcd7-a993d03dd7e2} NOT FOUND by this tool! ****

    **** SpyFalcon {55059d4f-a1ac-4837-ae07-4859101f598d} NOT FOUND by this tool! ****

    **** SpyFalcon {c3786a8d-6426-4c29-a23f-f36e47b31e0c} NOT FOUND by this tool! ****

    **** SpywareQuake {0c7416f0-dd23-420f-97f5-aae352ea2bf1} NOT FOUND by this tool! ****

    **** SpywareQuake {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D} NOT FOUND by this tool! ****

    **** SpywareQuake {AC1B4DA2-12FA-31F2-1A7D-CD2B14E6AD4E} NOT FOUND by this tool! ****

    **** SpywareQuake {CD5E2AC9-25CE-A1C5-D1E2-DC6B28A6ED5A} NOT FOUND by this tool! ****

    **** SpywareQuake {EA26CE12-DE64-A1C5-9A4F-FC1A64E6AC2E} NOT FOUND by this tool! ****

    **** SpywareQuake {e5b1e382-817e-4b74-8a96-ec78751e6acf} NOT FOUND by this tool! ****

    **** SpywareQuake {a0aa3e4b-31cb-4ea2-9049-22b7f5b65edb} NOT FOUND by this tool! ****

    **** SpywareQuake {cbb430e6-5b1b-474a-9d7e-160d4fe74bea} NOT FOUND by this tool! ****

    **** SpywareQuake {62eb0924-19d2-4226-b4b9-8ad1f70904c1} NOT FOUND by this tool! ****

    **** SpywareQuake {6c69e319-0d03-47da-997a-36586cbc53b3} NOT FOUND by this tool! ****

    **** SpywareQuake {aea3d2df-2b2c-4d7b-81a0-d975c6dc088e} NOT FOUND by this tool! ****

    **** SpywareSheriff {1C3B31AE-FD16-D2CE-43FF-DC4CD5C1BC5E} NOT FOUND by this tool! ****

    **** TrustCleaner {24E27EA9-FCF3-444F-BD80-20543BA5D946} NOT FOUND by this tool! ****

    **** Troj/Small-ER {4F141CBA-1457-6CCA-03A7-7AA21B61EA0F} NOT FOUND by this tool! ****

    **** Troj/Spabot-E {429F4BB8-7BF7-4152-8011-3C6F9EB7E892} NOT FOUND by this tool! ****

    **** Troj/Dloader-OF {203B1C4D9-BC71-8916-38AD-9DEA5D213614} NOT FOUND by this tool! ****

    **** Troj/Crafted-A {0BC9BC01-54D4-4CCE-2B7D-955164314CD4} NOT FOUND by this tool! ****

    **** Troj/Agent-FG {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} NOT FOUND by this tool! ****

    **** TX 4 BrowserAd adware {8e99f990-b75a-4568-b3c8-24cbc8cbbfc1} NOT FOUND by this tool! ****

    **** Trojan-Proxy.Win32.Small {87A3E824-A726-4CF4-8A66-6314B11BDA0C} NOT FOUND by this tool! ****

    **** Trojan-Downloader.Win32.Delf.ks {786C369D-409A-456f-A13C-971EADA850C6} NOT FOUND by this tool! ****

    **** i386p.* Stealthing Agent NOT FOUND by this tool! ****

    **** msctl32.dll SpamBot NOT FOUND by this tool! ****

    **** KeyLogger NOT FOUND by this tool! ****

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •