Hey Dan12,
Oh couple quick inquiries: I discovered (pretty sure I installed it and forgot about it

) RegCleaner 4.3 by Jouni Vuorio. Is this a trusted program? Because it lists 3 McAfee items in my registry and I am just itching to delete them! Thanks for the new download it actually worked!
Here is the WinPFind2 log as requested.
Logfile created on: 08/17/2006 19:27
WinPFind2 by OldTimer - Version 1.0.3 Folder = C:\WinPFind2\
Microsoft Windows XP (Version = Service Pack 2)
Internet Explorer (Version - 6.0.2900.2180)
alg.exe - c:\windows\system32\alg.exe - (Microsoft Corporation )
avgamsvr.exe - c:\progra~1\grisoft\avgfre~1\avgamsvr.exe - (GRISOFT, s.r.o. )
avgcc.exe - c:\progra~1\grisoft\avgfre~1\avgcc.exe - (GRISOFT, s.r.o. )
avgemc.exe - c:\progra~1\grisoft\avgfre~1\avgemc.exe - (GRISOFT, s.r.o. )
avgupsvc.exe - c:\progra~1\grisoft\avgfre~1\avgupsvc.exe - (GRISOFT, s.r.o. )
bcmwltry.exe - c:\windows\system32\bcmwltry.exe - (Dell Inc. )
csrss.exe - \??\c:\windows\system32\csrss.exe - (Microsoft Corporation )
dllhost.exe - c:\windows\system32\dllhost.exe - (Microsoft Corporation )
ehrecvr.exe - c:\windows\ehome\ehrecvr.exe - (Microsoft Corporation )
ehsched.exe - c:\windows\ehome\ehsched.exe - (Microsoft Corporation )
explorer.exe - c:\windows\explorer.exe - (Microsoft Corporation )
firefox.exe - c:\progra~1\mozill~1\firefox.exe - (Mozilla Corporation )
hkcmd.exe - c:\windows\system32\hkcmd.exe - (Intel Corporation )
hpzipm12.exe - c:\windows\system32\hpzipm12.exe - (HP )
igfxpers.exe - c:\windows\system32\igfxpers.exe - (Intel Corporation )
igfxsrvc.exe - c:\windows\system32\igfxsrvc.exe - (Intel Corporation )
ipodservice.exe - c:\program files\ipod\bin\ipodservice.exe - (Apple Computer, Inc. )
ituneshelper.exe - c:\program files\itunes\ituneshelper.exe - (Apple Computer, Inc. )
jusched.exe - c:\program files\java\jre1.5.0_08\bin\jusched.exe - (Sun Microsystems, Inc. )
lsass.exe - c:\windows\system32\lsass.exe - (Microsoft Corporation )
mcrdsvc.exe - c:\windows\ehome\mcrdsvc.exe - (Microsoft Corporation )
nicconfigsvc.exe - c:\program files\dell\quickset\nicconfigsvc.exe - (Dell Inc. )
realsched.exe - c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
services.exe - c:\windows\system32\services.exe - (Microsoft Corporation )
smss.exe - \systemroot\system32\smss.exe - (Microsoft Corporation )
spoolsv.exe - c:\windows\system32\spoolsv.exe - (Microsoft Corporation )
stsystra.exe - c:\windows\stsystra.exe - (SigmaTel, Inc. )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
svchost.exe - c:\windows\system32\svchost.exe - (Microsoft Corporation )
syntpenh.exe - c:\program files\synaptics\syntp\syntpenh.exe - (Synaptics, Inc. )
trillian.exe - c:\program files\trillian\trillian.exe - (Cerulean Studios )
vsmon.exe - c:\windows\system32\zonelabs\vsmon.exe - (Zone Labs, LLC )
winlogon.exe - \??\c:\windows\system32\winlogon.exe - (Microsoft Corporation )
winpatrol.exe - c:\program files\billp studios\winpatrol\winpatrol.exe - (BillP Studios )
winpfind2.exe - c:\winpfind2\winpfind2.exe - (OldTimer Tools )
wltray.exe - c:\windows\system32\wltray.exe - (Dell Inc. )
wltrysvc.exe - c:\windows\system32\wltrysvc.exe - ( )
wmiprvse.exe - c:\windows\system32\wbem\wmiprvse.exe - (Microsoft Corporation )
zlclient.exe - c:\program files\zone labs\zonealarm\zlclient.exe - (Zone Labs, LLC )
Version Info
WinPFind2 by OldTimer - Version 1.0.3 -
Microsoft Windows XP Version = Service Pack 2 -
Internet Explorer Version = 6.0.2900.2180 -
Internet Explorer Settings
HKLM->Main\\Start Page -
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
HKLM->Main\\Search Page -
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Default Page - http://www.dell.com
HKLM->Main\\Default Search -
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page -
http://www.spu.edu/
HKCU->Main\\Search Page -
http://www.google.com
HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm
HKCU->Internet Settings\\ProxyEnable - 0
HKCU->Internet Settings\\ProxyOverride -
BHO's
HKLM->Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated )
HKLM->Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions )
HKLM->Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a} - = C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems )
HKLM->Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll (Sun Microsystems, Inc. )
Internet Explorer Bars, Toolbars and Extensions
HKCU->Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} - File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
HKCU->Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E} - Explorer Band = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
HKLM->Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
HKLM->Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - Real.com = C:\WINDOWS\system32\Shdocvw.dll (Microsoft Corporation )
HKCU->Toolbar\ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
HKCU->Toolbar\ShellBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} - &RoboForm = C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems )
HKCU->Toolbar\WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
HKCU->Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
HKCU->Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Data missing or invalid = Reg Data missing or invalid (File not found))
HKCU->Toolbar\WebBrowser\\{724D43A0-0D85-11D4-9908-00400523E39A} - &RoboForm = C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems )
HKLM->ToolBar\\{724d43a0-0d85-11d4-9908-00400523e39a} - &RoboForm = C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems )
HKCU->Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8192 - Sun Java Console
HKCU->Extensions\CmdMapping\\{320AF880-6646-11D3-ABEE-C5DBF3571F46} - 8199 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{320AF880-6646-11D3-ABEE-C5DBF3571F49} - 8200 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - 8195 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{724d43aa-0d85-11d4-9908-00400523e39a} - 8201 - RoboForm Toolbar
HKCU->Extensions\CmdMapping\\{85d1f590-48f4-11d9-9669-0800200c9a66} - 8202 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 8197 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{CB9CDC2D-0AB4-4031-A1F7-E9B4070CE521} - 8198 - Reg Data missing or invalid
HKCU->Extensions\CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - 8193 -
HKCU->Extensions\CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8194 - Windows Messenger
HKCU->Extensions\CmdMapping\\NextId - 8203
HKLM->Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll (Sun Microsystems, Inc. )
HKLM->Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = Reg Data missing or invalid (File not found))
HKLM->Extensions\{724d43aa-0d85-11d4-9908-00400523e39a} - ButtonText: RoboForm = file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (File not found))
HKLM->Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - ButtonText: Real.com = (File not found))
HKLM->Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation )
HKCU->MenuExt\&Google Search - (File not found))
HKCU->MenuExt\&Translate English Word - (File not found))
HKCU->MenuExt\Backward Links - (File not found))
HKCU->MenuExt\Cached Snapshot of Page - (File not found))
HKCU->MenuExt\Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html (File not found))
HKCU->MenuExt\Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm (File not found))
HKCU->MenuExt\Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm (File not found))
HKCU->MenuExt\Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm (File not found))
HKCU->MenuExt\Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm (File not found))
HKCU->MenuExt\Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html (File not found))
HKCU->MenuExt\Lookup on CD - c:\AHD4withThesaurus\ahd.htm ( )
HKCU->MenuExt\RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html (File not found))
HKCU->MenuExt\Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html (File not found))
HKCU->MenuExt\Similar Pages - (File not found))
HKCU->MenuExt\Translate Page into English - (File not found))
Approved Shell Extensions (Non-Microsoft only)
HKLM->Shell Extensions\Approved\{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} - Autoplay for SlideShow = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{2F603045-309F-11CF-9774-0020AFD0CFF6} - Synaptics Control Panel = C:\Program Files\Synaptics\SynTP\SynTPCpl.dll (Synaptics, Inc. )
HKLM->Shell Extensions\Approved\{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{5CA3D70E-1895-11CF-8E15-001234567890} - DriveLetterAccess = C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions )
HKLM->Shell Extensions\Approved\{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data missing or invalid (File not found))
HKLM->Shell Extensions\Approved\{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\system32\hticons.dll (Hilgraeve, Inc. )
HKLM->Shell Extensions\Approved\{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - AVG7 Shell Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
HKLM->Shell Extensions\Approved\{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} - AVG7 Find Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
HKLM->Shell Extensions\Approved\{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - iTunes = C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. )
HKLM->Shell Extensions\Approved\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc. )
ContextMenuHandlers (Non-Microsoft only)
HKLM->* - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
HKLM->Directory\Background - igfxcui - {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} = C:\WINDOWS\system32\igfxpph.dll (Intel Corporation )
HKLM->Folder - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
ColumnHandlers (Non-Microsoft only)
HKLM->Folder - {F9DB5320-233E-11D1-9F84-707F02C10627} - PDF Shell Extension = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc. )
Registry Run Keys
HKLM->Run\\AVG7_CC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o. )
HKLM->Run\\Broadcom Wireless Manager UI - C:\WINDOWS\system32\WLTRAY.exe (Dell Inc. )
HKLM->Run\\igfxhkcmd - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation )
HKLM->Run\\igfxpers - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation )
HKLM->Run\\igfxtray - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation )
HKLM->Run\\iTunesHelper - "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc. )
HKLM->Run\\SigmatelSysTrayApp - stsystra.exe (SigmaTel, Inc. )
HKLM->Run\\SunJavaUpdateSched - "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" (Sun Microsystems, Inc. )
HKLM->Run\\SynTPEnh - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc. )
HKLM->Run\\TkBellExe - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. )
HKLM->Run\\WinPatrol - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios )
HKLM->Run\\Zone Labs Client - "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Zone Labs, LLC )
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
Startup Lnks
HKLM->Common Startup - desktop.ini - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ( )
HKLM->Common Startup - Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation )
HKCU->Startup - desktop.ini - C:\Documents and Settings\Kevin Binz\Start Menu\Programs\Startup\desktop.ini ( )
Disabled MSConfig Items
User Agent Post Platform
HKLM->Post Platform\\SV1 -
AppInit DLLs
HKLM->Windows\\AppInit_DLLs - (File not found))
Image File Execution Options
HKLM->Image File Execution Options\Your Image File Name Here without a path - Debugger = ntsd -d
Shell Service Object Delay Load
HKLM->ShellServiceObjectDelayLoad\\CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
HKLM->ShellServiceObjectDelayLoad\\PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
HKLM->ShellServiceObjectDelayLoad\\SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll (Microsoft Corporation )
HKLM->ShellServiceObjectDelayLoad\\WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation )
Shell Execute Hooks
HKLM->ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )
Shared Task Scheduler
HKLM->SharedTaskScheduler\\{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
HKLM->SharedTaskScheduler\\{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
Winlogon
HKLM->Winlogon\\UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation )
HKLM->Winlogon\\Shell - Explorer.exe (Microsoft Corporation )
HKLM->Winlogon\\System - (File not found))
HKLM->Winlogon\Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\cscdll - cscdll.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\igfxcui - igfxdev.dll (Intel Corporation )
HKLM->Winlogon\Notify\ScCertProp - wlnotify.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\Schedule - wlnotify.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\termsrv - wlnotify.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\WgaLogon - WgaLogon.dll (Microsoft Corporation )
HKLM->Winlogon\Notify\wlballoon - wlnotify.dll (Microsoft Corporation )
DNS Name Servers
HKLM->Interfaces\{5871B05F-FDE8-464C-BA97-C7D8334A46B8} - (Dell Wireless 1390 WLAN Mini-Card)
HKLM->Interfaces\{61BD785F-51BF-44FF-B817-CAABAD1DC997} - (Broadcom 440x 10/100 Integrated Controller)
HKLM->Interfaces\{88FD9676-86DC-473F-A278-A0D993DBC79A} - (1394 Net Adapter)
Winsock2 Catalogs (Non-Microsoft only)
Protocol Handlers (Non-Microsoft only)
HKLM->PROTOCOLS\Handler\ipp - (File not found))
HKLM->PROTOCOLS\Handler\msdaipp - (File not found))
Protocol Filters (Non-Microsoft only)
Application Layer Gateway Service - ALG - On Demand - Running - Win32, running in it's own process - C:\WINDOWS\System32\alg.exe (Microsoft Corporation )
Windows Audio - AudioSrv - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
AVG7 Alert Manager Server - Avg7Alrt - Automatic - Running - Win32, running in it's own process - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. )
AVG7 Update Service - Avg7UpdSvc - Automatic - Running - Win32, running in it's own process - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. )
AVG E-mail Scanner - AVGEMS - Automatic - Running - Win32, running in it's own process - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (GRISOFT, s.r.o. )
Background Intelligent Transfer Service - BITS - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Computer Browser - Browser - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
COM+ System Application - COMSysApp - On Demand - Running - Win32, running in it's own process - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (Microsoft Corporation )
Cryptographic Services - CryptSvc - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
DCOM Server Process Launcher - DcomLaunch - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation )
DHCP Client - Dhcp - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
DNS Client - Dnscache - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k NetworkService (Microsoft Corporation )
Media Center Receiver Service - ehRecvr - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\eHome\ehRecvr.exe (Microsoft Corporation )
Media Center Scheduler Service - ehSched - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\eHome\ehSched.exe (Microsoft Corporation )
Error Reporting Service - ERSvc - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Event Log - Eventlog - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\services.exe (Microsoft Corporation )
COM+ Event System - EventSystem - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Help and Support - helpsvc - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
HID Input Service - HidServ - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
iPodService - iPodService - On Demand - Running - Win32, running in it's own process - C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc. )
Server - lanmanserver - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Workstation - lanmanworkstation - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
TCP/IP NetBIOS Helper - LmHosts - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation )
Media Center Extender Service - McrdSvc - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\ehome\mcrdsvc.exe (Microsoft Corporation )
Network Connections - Netman - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
NICCONFIGSVC - NICCONFIGSVC - Automatic - Running - Win32, running in it's own process - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe (Dell Inc. )
Network Location Awareness (NLA) - Nla - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Plug and Play - PlugPlay - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\services.exe (Microsoft Corporation )
Pml Driver HPZ12 - Pml Driver HPZ12 - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\system32\HPZipm12.exe (HP )
IPSEC Services - PolicyAgent - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation )
Protected Storage - ProtectedStorage - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation )
Remote Access Connection Manager - RasMan - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Remote Registry - RemoteRegistry - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation )
Remote Procedure Call (RPC) - RpcSs - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost -k rpcss (Microsoft Corporation )
Security Accounts Manager - SamSs - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\lsass.exe (Microsoft Corporation )
Task Scheduler - Schedule - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Secondary Logon - seclogon - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
System Event Notification - SENS - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Windows Firewall/Internet Connection Sharing (ICS) - SharedAccess - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Shell Hardware Detection - ShellHWDetection - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Print Spooler - Spooler - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation )
System Restore Service - srservice - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
SSDP Discovery Service - SSDPSRV - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation )
Windows Image Acquisition (WIA) - stisvc - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k imgsvc (Microsoft Corporation )
Telephony - TapiSrv - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Terminal Services - TermService - On Demand - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost -k DComLaunch (Microsoft Corporation )
Themes - Themes - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Distributed Link Tracking Client - TrkWks - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
TrueVector Internet Monitor - vsmon - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (Zone Labs, LLC )
Windows Time - w32time - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
WebClient - WebClient - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k LocalService (Microsoft Corporation )
Windows Management Instrumentation - winmgmt - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
Dell Wireless WLAN Tray Service - wltrysvc - Automatic - Running - Win32, running in it's own process - C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe (File not found))
Security Center - wscsvc - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation )
Automatic Updates - wuauserv - Automatic - Running - Win32, running in a shared process - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation )
%SystemDrive%
%ProgramFilesDir%
%WinDir%
%System%
C:\WINDOWS\SYSTEM32\dfrg.msc - AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213( [Ver = | Size = 41397 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\LegitCheckControl.dll - RIMAPPTECHNOLOGIES (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 571184 bytes | Date = 06/19/2006 16:19 | Attr = ])
C:\WINDOWS\SYSTEM32\MRT.exe - (PeCompact2) (Microsoft Corporation [Ver = 1.19.1565.0 | Size = 8255912 bytes | Date = 08/02/2006 18:22 | Attr = ])
C:\WINDOWS\SYSTEM32\MRT.exe - (ASPack) (Microsoft Corporation [Ver = 1.19.1565.0 | Size = 8255912 bytes | Date = 08/02/2006 18:22 | Attr = ])
C:\WINDOWS\SYSTEM32\ntbackup.exe - VWSuD (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 1200128 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ntdll.dll - .aspack (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 708096 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - Pln``pmlidb_[ZYWSUdxa\^`^Tsfbeffhjol(Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\rasdlg.dll - \DuMonitor SendMessage(WM_RASEVENT) done(Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 657920 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wbdbase.deu - msubjsuchsullsupeswinsyncszens( [Ver = | Size = 1309184 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\WgaTray.exe - RIMAPPTECHNOLOGIES (Microsoft Corporation [Ver = 1.5.0540.0 | Size = 304944 bytes | Date = 06/19/2006 16:19 | Attr = ])
%System%\Drivers folder and sub-folders
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - error finding UPX! header(GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/11/2006 21:05 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - FSG!u.h (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/11/2006 21:05 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - pec2-ext.exe (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/11/2006 21:05 | Attr = ])
C:\WINDOWS\SYSTEM32\drivers\avg7core.sys - ;PE_ASPACK (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/11/2006 21:05 | Attr = ])
%windir% + sub-dirs for System or Hidden files less than 60 days old
C:\WINDOWS\bootstat.dat - ( [Ver = | Size = 2048 bytes | Date = 08/17/2006 18:41 | Attr = S])
C:\WINDOWS\$regcmp$\DEFAULT.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-19-NTUSER.DAT.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-19_Classes-UsrClass.dat.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-20-NTUSER.DAT.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-20_Classes-UsrClass.dat.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-21-3185575301-2876196551-2769801379-1005-NTUSER.DAT.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\S-1-5-21-3185575301-2876196551-2769801379-1005_Classes-UsrClass.dat.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\SAM.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\SECURITY.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\SOFTWARE.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\$regcmp$\SYSTEM.LOG - ( [Ver = | Size = 0 bytes | Date = 07/25/2006 21:31 | Attr = H ])
C:\WINDOWS\assembly\PublisherPolicy.tme - ( [Ver = | Size = 0 bytes | Date = 07/06/2006 12:34 | Attr = RH ])
C:\WINDOWS\assembly\pubpol1.dat - ( [Ver = | Size = 0 bytes | Date = 07/06/2006 12:34 | Attr = RH ])
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\index1c.dat - ( [Ver = | Size = 0 bytes | Date = 07/06/2006 14:04 | Attr = RH ])
C:\WINDOWS\CSC\00000001 - ( [Ver = | Size = 64 bytes | Date = 07/10/2006 15:40 | Attr = S])
C:\WINDOWS\CSC\00000002 - ( [Ver = | Size = 64 bytes | Date = 06/19/2006 23:32 | Attr = S])
C:\WINDOWS\inf\oem31.inf - ( [Ver = | Size = 0 bytes | Date = 08/05/2006 16:48 | Attr = H ])
C:\WINDOWS\system32\AuxDrv32ds_k.ods - ( [Ver = | Size = 5 bytes | Date = 07/20/2006 22:39 | Attr = HS])
C:\WINDOWS\system32\vsconfig.xml - ( [Ver = | Size = 48883 bytes | Date = 08/17/2006 18:41 | Attr = H ])
C:\WINDOWS\system32\zllictbl.dat - ( [Ver = | Size = 4212 bytes | Date = 08/04/2006 07:07 | Attr = H ])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB917422.cat - ( [Ver = | Size = 10925 bytes | Date = 07/05/2006 05:21 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB918899.cat - ( [Ver = | Size = 23751 bytes | Date = 07/28/2006 05:16 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB919803.cat - ( [Ver = | Size = 11963 bytes | Date = 06/29/2006 16:40 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920214.cat - ( [Ver = | Size = 10337 bytes | Date = 07/27/2006 07:00 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920670.cat - ( [Ver = | Size = 10925 bytes | Date = 07/21/2006 02:03 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB920683.cat - ( [Ver = | Size = 11929 bytes | Date = 06/26/2006 12:47 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB921398.cat - ( [Ver = | Size = 13050 bytes | Date = 07/13/2006 07:24 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB921883.cat - ( [Ver = | Size = 10925 bytes | Date = 07/14/2006 09:13 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB922616.cat - ( [Ver = | Size = 10925 bytes | Date = 07/14/2006 08:53 | Attr = S])
C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WgaNotify.cat - ( [Ver = | Size = 7160 bytes | Date = 06/19/2006 16:20 | Attr = S])
C:\WINDOWS\system32\config\default.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/17/2006 18:41 | Attr = H ])
C:\WINDOWS\system32\config\SAM.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/17/2006 18:41 | Attr = H ])
C:\WINDOWS\system32\config\SECURITY.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/17/2006 18:51 | Attr = H ])
C:\WINDOWS\system32\config\software.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/17/2006 19:11 | Attr = H ])
C:\WINDOWS\system32\config\system.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/17/2006 18:42 | Attr = H ])
C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG - ( [Ver = | Size = 1024 bytes | Date = 08/11/2006 17:27 | Attr = H ])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8 - ( [Ver = | Size = 341 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165 - ( [Ver = | Size = 413 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\904590238400AD963F77FAAAADC9BAB5 - ( [Ver = | Size = 574 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8 - ( [Ver = | Size = 126 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165 - ( [Ver = | Size = 98 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\904590238400AD963F77FAAAADC9BAB5 - ( [Ver = | Size = 136 bytes | Date = 06/30/2006 21:01 | Attr = S])
C:\WINDOWS\Tasks\SA.DAT - ( [Ver = | Size = 6 bytes | Date = 08/17/2006 18:41 | Attr = H ])
CPL files -
C:\WINDOWS\SYSTEM32\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\appwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 549888 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\BACSCPL.cpl - ( [Ver = 8, 2, 4, 0 | Size = 24576 bytes | Date = 07/13/2005 14:55 | Attr = ])
C:\WINDOWS\SYSTEM32\BCMWLCPL.CPL - (Dell Inc. [Ver = 4.10.47.3 | Size = 3096576 bytes | Date = 12/19/2005 06:08 | Attr = ])
C:\WINDOWS\SYSTEM32\bthprops.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 110592 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\desk.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 135168 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\firewall.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 80384 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 155136 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\igfxcpl.cpl - (Intel Corporation [Ver = 3.0.0.4446 | Size = 77824 bytes | Date = 12/13/2005 14:43 | Attr = ])
C:\WINDOWS\SYSTEM32\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 358400 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\intl.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\irprops.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 380416 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ISUSPM.cpl - (InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 73728 bytes | Date = 07/27/2004 14:50 | Attr = ])
C:\WINDOWS\SYSTEM32\joy.cpl - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\jpicpl32.cpl - (Sun Microsystems, Inc. [Ver = 5.0.80.3 | Size = 49265 bytes | Date = 07/26/2006 03:03 | Attr = ])
C:\WINDOWS\SYSTEM32\main.cpl - (Microsoft Corporation [Ver = 5.1.2403.1 | Size = 187904 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\mmsys.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 618496 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\ncpa.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 35840 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\NicConfigSvc.cpl - (Dell Inc. [Ver = 1, 0, 0, 1 | Size = 172032 bytes | Date = 04/06/2006 12:57 | Attr = ])
C:\WINDOWS\SYSTEM32\nusrmgr.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 257024 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\nwc.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 36864 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\odbccp32.cpl - (Microsoft Corporation [Ver = 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) | Size = 32768 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\powercfg.cpl - (Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 114688 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\stacgui.cpl - (SigmaTel, Inc. [Ver = 1.0.4823.0 nd322 cp1 | Size = 7405568 bytes | Date = 11/16/2005 12:35 | Attr = ])
C:\WINDOWS\SYSTEM32\sysdm.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\telephon.cpl - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 28160 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\timedate.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 94208 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wscui.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 148480 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\access.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 68608 bytes | Date = 08/10/2004 03:00 | Attr = ])
C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
AllUsers Startup Folder
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 08/16/2005 02:43 | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk - ( [Ver = | Size = 1730 bytes | Date = 05/30/2006 11:44 | Attr = ])
AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 08/16/2005 02:33 | Attr = HS])
C:\Documents and Settings\All Users\Application Data\hpzinstall.log - ( [Ver = | Size = 738 bytes | Date = 07/04/2006 18:45 | Attr = ])
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare - ( [Ver = | Size = 4 bytes | Date = 05/30/2006 11:36 | Attr = H ])
C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache - ( [Ver = | Size = 3714 bytes | Date = 08/12/2006 22:35 | Attr = ])
CurrentUser Startup Folder
C:\Documents and Settings\Kevin Binz\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 08/16/2005 02:43 | Attr = HS])
CurrentUser ApplicationData Folder
C:\Documents and Settings\Kevin Binz\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 08/16/2005 02:33 | Attr = HS])
C:\Documents and Settings\Kevin Binz\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log - ( [Ver = | Size = 10563 bytes | Date = 07/06/2006 11:47 | Attr = ])
C:\Documents and Settings\Kevin Binz\Application Data\wklnhst.dat - ( [Ver = | Size = 1806 bytes | Date = 08/17/2006 11:59 | Attr = ])
DPF files
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.5.0_08 - CodeBase =
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - Java Plug-in 1.5.0_08 - CodeBase =
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.5.0_08 - CodeBase =
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab
Hosts file = 734 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
# Copyright © 1993-1999 Microsoft Corp. -
# -
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. -
# -
# This file contains the mappings of IP addresses to host names. Each -
# entry should be kept on an individual line. The IP address should -
# be placed in the first column followed by the corresponding host name. -
# The IP address and the host name should be separated by at least one -
# space. -
# -
# Additionally, comments (such as these) may be inserted on individual -
# lines or following the machine name denoted by a '#' symbol. -
# -
# For example: -
# -
# 102.54.94.97 rhino.acme.com # source server -
# 38.25.63.10 x.acme.com # x client host -
-
127.0.0.1 localhost -