thanks Silver! Here are the three logfiles...
WinPFind3U:
WinPFind3 logfile created on: 3/29/2007 6:37:30 AM
WinPFind3U by OldTimer - Version 1.0.31 Folder = C:\Documents and Settings\Avram Peters\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)
509 Mb Total Physical Memory | 301 Mb Available Physical Memory | 59.05% Memory free
1 Gb Paging File | 0 Gb Available in Paging File | 75.90% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74 Gb Total Space | 52 Gb Free Space | 70.80% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232 Gb Total Space | 228 Gb Free Space | 98.22% Space Free
Computer Name: DELL-HOME
Current User Name: Avram Peters
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 6/7/2005 12:46:24 AM | Attr = ]
avgamsvr.exe -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.445 | Size = 353792 bytes | Modified Date = 2/25/2007 4:51:38 AM | Attr = ]
avgas.exe -> %UserDesktop%\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 10/7/2006 7:20:00 AM | Attr = ]
avgcc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.438 | Size = 411648 bytes | Modified Date = 2/9/2007 9:10:52 AM | Attr = ]
avgupsvc.exe -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 11/24/2006 11:41:28 PM | Attr = ]
dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 6/23/2005 4:31:48 PM | Attr = ]
guard.exe -> %UserDesktop%\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 9:13:20 AM | Attr = ]
hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4396 | Size = 77824 bytes | Modified Date = 9/20/2005 3:32:24 PM | Attr = ]
iap.exe -> %ProgramFiles%\Dell\OpenManage\Client\Iap.exe -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 155648 bytes | Modified Date = 2/13/2004 10:47:02 AM | Attr = ]
igfxpers.exe -> %System32%\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4396 | Size = 114688 bytes | Modified Date = 9/20/2005 3:36:20 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.5.0_11\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 75520 bytes | Modified Date = 12/15/2006 4:23:28 AM | Attr = ]
pptd40nt.exe -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 4/14/2004 2:46:50 PM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1 | Size = 282624 bytes | Modified Date = 9/10/2006 8:08:00 AM | Attr = ]
spyeraser.exe -> %ProgramFiles%\Uniblue\SpyEraser\SpyEraser.exe -> Uniblue Software [Ver = 1.2.1.1151 | Size = 1331712 bytes | Modified Date = 1/30/2007 11:12:40 AM | Attr = ]
tfswctrl.exe -> %System32%\dla\tfswctrl.exe -> Sonic Solutions [Ver = 1.04.08a | Size = 127035 bytes | Modified Date = 12/6/2004 1:05:00 AM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.31.0 | Size = 318464 bytes | Modified Date = 3/26/2007 8:04:38 PM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %UserDesktop%\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 9/28/2006 9:13:20 AM | Attr = ]
(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.445 | Size = 353792 bytes | Modified Date = 2/25/2007 4:51:38 AM | Attr = ]
(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Free\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 11/24/2006 11:41:28 PM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 5:00:00 AM | Attr = ]
(Iap) Iap [Win32_Own | Auto | Running] -> %ProgramFiles%\Dell\OpenManage\Client\Iap.exe -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 155648 bytes | Modified Date = 2/13/2004 10:47:02 AM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1150\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.50.42618 | Size = 69632 bytes | Modified Date = 11/14/2005 2:06:04 AM | Attr = ]
(NetSvc) Intel NCS NetService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Intel\NCS\Sync\NetSvc.exe -> Intel® Corporation [Ver = 1.2.26.0 | Size = 143360 bytes | Modified Date = 3/3/2003 1:33:40 PM | Attr = ]
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
!AVG Anti-Spyware -> %UserDesktop%\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 10/7/2006 7:20:00 AM | Attr = ]
Adobe Photo Downloader -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 6/7/2005 12:46:24 AM | Attr = ]
AVG7_CC -> %ProgramFiles%\Grisoft\AVG Free\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.438 | Size = 411648 bytes | Modified Date = 2/9/2007 9:10:52 AM | Attr = ]
ControlCenter2.0 -> %ProgramFiles%\Brother\ControlCenter2\brctrcen.exe -> Brother Industries, Ltd. [Ver = 2, 0, 12, 4 | Size = 864256 bytes | Modified Date = 11/11/2004 10:00:04 PM | Attr = ]
dla -> %System32%\dla\tfswctrl.exe -> Sonic Solutions [Ver = 1.04.08a | Size = 127035 bytes | Modified Date = 12/6/2004 1:05:00 AM | Attr = ]
DVDLauncher -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 53248 bytes | Modified Date = 6/23/2005 4:31:48 PM | Attr = ]
igfxhkcmd -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4396 | Size = 77824 bytes | Modified Date = 9/20/2005 3:32:24 PM | Attr = ]
igfxpers -> %System32%\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4396 | Size = 114688 bytes | Modified Date = 9/20/2005 3:36:20 PM | Attr = ]
igfxtray -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4396 | Size = 94208 bytes | Modified Date = 9/20/2005 3:35:40 PM | Attr = ]
IndexSearch -> %ProgramFiles%\ScanSoft\PaperPort\IndexSearch.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 40960 bytes | Modified Date = 4/14/2004 3:04:12 PM | Attr = ]
PaperPort PTD -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 4/14/2004 2:46:50 PM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1 | Size = 282624 bytes | Modified Date = 9/10/2006 8:08:00 AM | Attr = ]
SSBkgdUpdate -> %CommonProgramFiles%\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -> Scansoft, Inc. [Ver = 1, 0, 0, 6 | Size = 155648 bytes | Modified Date = 10/14/2003 10:22:30 AM | Attr = R ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.5.0_11\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 75520 bytes | Modified Date = 12/15/2006 4:23:28 AM | Attr = ]
UpdateManager -> %CommonProgramFiles%\Sonic\Update Manager\sgtray.exe -> Sonic Solutions [Ver = 1.01.33b | Size = 110592 bytes | Modified Date = 1/7/2004 1:01:00 AM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Uniblue SpyEraser -> %ProgramFiles%\Uniblue\SpyEraser\SpyEraser.exe -> Uniblue Software [Ver = 1.2.1.1151 | Size = 1331712 bytes | Modified Date = 1/30/2007 11:12:40 AM | Attr = ]
updateMgr -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe -> Adobe Systems Incorporated [Ver = 3.1.0.10 | Size = 313472 bytes | Modified Date = 3/30/2006 4:45:08 PM | Attr = R ]
< Common Startup > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup
%AllUsersStartup%\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Modified Date = 9/23/2005 10:05:26 PM | Attr = ]
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> %UserDesktop%\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 9/28/2006 9:13:28 AM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
*VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet ->
Control_RunDLL -> -> File not found
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
igfxcui -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4396 | Size = 135168 bytes | Modified Date = 9/20/2005 3:31:28 PM | Attr = ]
< HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts
127.0.0.1 localhost -> ->
< Internet Explorer Settings > ->
HKLM: Default_Page_URL ->
http://www.dell.com ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->
HKLM: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Start Page ->
http://www.dell.com ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page ->
http://www.yahoo.com/ ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.7.2006011200 | Size = 63128 bytes | Modified Date = 1/12/2006 8:38:22 PM | Attr = ]
{0A87E45F-537A-40B4-B812-E2544C21A09F} [HKLM] -> %ProgramFiles%\SpyCatcher 2006\SCActiveBlock.dll [SpywareBlock Class] -> File not found
{5CA3D70E-1895-11CF-8E15-001234567890} [HKLM] -> %System32%\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.08a | Size = 118842 bytes | Modified Date = 12/6/2004 1:05:00 AM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_11\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 440056 bytes | Modified Date = 12/15/2006 4:23:24 AM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_11\bin\npjpi150_11.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 75528 bytes | Modified Date = 12/15/2006 4:23:26 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_11\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 440056 bytes | Modified Date = 12/15/2006 4:23:24 AM | Attr = ]
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -> Reg Data - Value does not exist [ButtonText: Create Mobile Favorite] -> File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -> Reg Data - Value does not exist [ButtonText: Research] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\
E&xport to Microsoft Excel -> -> File not found
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
{3126B78D-C56E-45C0-B9D0-D561FF68B84B} -> (Windows Mobile-based Device) ->
{77E199C5-4077-4012-88D9-9B732D6608A0} -> (Intel® PRO/100 VE Network Connection) ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
{00000055-9980-0010-8000-00AA00389B71} -> - CodeBase =
http://codecs.micros...cs/i386/fhg.CAB ->
{01A88BB1-1174-41EC-ACCB-963509EAE56B} -> SysProWmi Class - CodeBase =
http://support.dell....iler/SysPro.CAB ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -> QuickTime Object - CodeBase =
http://www.apple.com...ex/qtplugin.cab ->
{2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} -> DownloadManager Control - CodeBase =
http://dlm.tools.aka...vex-2.2.0.5.cab ->
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -> Office Update Installation Engine - CodeBase =
http://office.micros...ntent/opuc3.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_11 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} -> Java Plug-in 1.4.2_03 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_09 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_10 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_11 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_11 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase =
http://fpdownload.ma...ash/swflash.cab ->
{EF791A6B-FC12-4C68-99EF-FB9E207A39E6} -> McFreeScan Class - CodeBase =
http://download.mcaf...876/mcfscan.cab ->
[Files/Folders - Created Within 30 days]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 534827008 bytes | Created Date = 1/1/1601 6:00:00 AM | Attr = HS]
HJT -> %SystemDrive%\HJT -> [Folder | Created Date = 3/28/2007 8:58:08 AM | Attr = ]
VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Created Date = 3/28/2007 6:33:24 AM | Attr = ]
$NtUninstallKB929338$ -> %SystemRoot%\$NtUninstallKB929338$ -> [Folder | Created Date = 3/18/2007 7:33:27 PM | Attr = H ]
$NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Created Date = 3/18/2007 7:35:47 PM | Attr = H ]
brmx2001.ini -> %SystemRoot%\brmx2001.ini -> [Ver = | Size = 51 bytes | Created Date = 3/28/2007 9:53:15 AM | Attr = ]
Intuit -> %SystemRoot%\Intuit -> [Folder | Created Date = 3/23/2007 6:47:11 AM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 3/28/2007 10:28:42 AM | Attr = ]
opt_2460.ini -> %SystemRoot%\opt_2460.ini -> [Ver = | Size = 40 bytes | Created Date = 3/28/2007 9:53:15 AM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Created Date = 3/4/2007 8:22:43 PM | Attr = ]
Microsoft_Hardware_Launch_IType_exe.job -> %SystemRoot%\tasks\Microsoft_Hardware_Launch_IType_exe.job -> [Ver = | Size = 314 bytes | Created Date = 3/4/2007 4:38:33 PM | Attr = H ]
Uniblue SpyEraser.job -> %SystemRoot%\tasks\Uniblue SpyEraser.job -> [Ver = | Size = 352 bytes | Created Date = 3/21/2007 8:18:07 PM | Attr = ]
appmgmt -> %System32%\appmgmt -> [Folder | Created Date = 3/23/2007 6:41:26 AM | Attr = ]
archlib.dll -> %System32%\archlib.dll -> Tenebril Incorporated [Ver = 0, 0, 2, 2 | Size = 180224 bytes | Created Date = 3/21/2007 6:30:28 AM | Attr = S]
java.exe -> %System32%\java.exe -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 49248 bytes | Created Date = 2/28/2007 9:19:59 PM | Attr = ]
javaw.exe -> %System32%\javaw.exe -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 53346 bytes | Created Date = 2/28/2007 9:19:59 PM | Attr = ]
javaws.exe -> %System32%\javaws.exe -> Sun Microsystems, Inc. [Ver = 5.0.110.3 | Size = 127078 bytes | Created Date = 2/28/2007 9:20:00 PM | Attr = ]
locate.com -> %System32%\locate.com -> [Ver = | Size = 11254 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
NtmsData -> %System32%\NtmsData -> [Folder | Created Date = 3/23/2007 11:42:51 AM | Attr = ]
Ntrights.exe -> %System32%\Ntrights.exe -> [Ver = | Size = 39184 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
Process.exe -> %System32%\Process.exe ->
http://www.beyondlogic.org [Ver = 2, 0, 0, 0 | Size = 53248 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
restart.exe -> %System32%\restart.exe -> WareSoft Software [Ver = 1.00 | Size = 16384 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
strings.exe -> %System32%\strings.exe -> [Ver = | Size = 175616 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
tenarchlib -> %System32%\tenarchlib -> [Folder | Created Date = 3/21/2007 6:30:29 AM | Attr = ]
zip.exe -> %System32%\zip.exe -> [Ver = | Size = 126976 bytes | Created Date = 3/24/2007 12:45:29 PM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 3/28/2007 7:17:12 AM | Attr = ]
[Files/Folders - Modified Within 30 days]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 534827008 bytes | Modified Date = 3/28/2007 11:25:42 AM | Attr = HS]
HJT -> %SystemDrive%\HJT -> [Folder | Modified Date = 3/28/2007 1:44:42 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 3/23/2007 8:20:54 AM | Attr = R ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 3/23/2007 12:45:12 PM | Attr = HS]
VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Modified Date = 3/28/2007 7:33:26 AM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 3/28/2007 11:28:44 AM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 3/18/2007 8:32:18 PM | Attr = H ]
$NtUninstallKB929338$ -> %SystemRoot%\$NtUninstallKB929338$ -> [Folder | Modified Date = 3/18/2007 8:33:30 PM | Attr = H ]
$NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Modified Date = 3/18/2007 8:35:48 PM | Attr = H ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 3/28/2007 11:25:44 AM | Attr = S]
brdfxspd.dat -> %SystemRoot%\brdfxspd.dat -> [Ver = | Size = 0 bytes | Modified Date = 3/28/2007 10:54:24 AM | Attr = ]
brmx2001.ini -> %SystemRoot%\brmx2001.ini -> [Ver = | Size = 51 bytes | Modified Date = 3/28/2007 10:53:16 AM | Attr = ]
brpcfx.ini -> %SystemRoot%\brpcfx.ini -> [Ver = | Size = 152 bytes | Modified Date = 3/28/2007 10:53:30 AM | Attr = ]
Brpfx04a.ini -> %SystemRoot%\Brpfx04a.ini -> [Ver = | Size = 1137 bytes | Modified Date = 3/28/2007 10:54:40 AM | Attr = ]
brwmark.ini -> %SystemRoot%\brwmark.ini -> [Ver = | Size = 743 bytes | Modified Date = 3/28/2007 10:30:12 AM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 3/21/2007 7:13:34 AM | Attr = S]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 3/23/2007 8:20:54 AM | Attr = R S]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 3/18/2007 8:33:44 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 3/28/2007 11:29:02 AM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 3/23/2007 7:47:14 AM | Attr = HS]
Intuit -> %SystemRoot%\Intuit -> [Folder | Modified Date = 3/23/2007 7:47:12 AM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 3/28/2007 11:28:44 AM | Attr = ]
opt_2460.ini -> %SystemRoot%\opt_2460.ini -> [Ver = | Size = 40 bytes | Modified Date = 3/28/2007 10:53:16 AM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 3/29/2007 6:37:06 AM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 3/4/2007 9:22:44 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 3/26/2007 11:15:16 PM | Attr = H ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 3/23/2007 12:45:10 PM | Attr = ]
repair -> %SystemRoot%\repair -> [Folder | Modified Date = 3/23/2007 12:45:16 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 3/28/2007 11:24:14 AM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 3/21/2007 9:18:08 PM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 3/28/2007 1:42:36 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 634 bytes | Modified Date = 3/22/2007 3:29:58 PM | Attr = ]
Microsoft_Hardware_Launch_IType_exe.job -> %SystemRoot%\tasks\Microsoft_Hardware_Launch_IType_exe.job -> [Ver = | Size = 314 bytes | Modified Date = 3/5/2007 4:13:46 PM | Attr = H ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 3/28/2007 11:25:46 AM | Attr = H ]
Uniblue SpyEraser.job -> %SystemRoot%\tasks\Uniblue SpyEraser.job -> [Ver = | Size = 352 bytes | Modified Date = 3/21/2007 9:18:08 PM | Attr = ]
appmgmt -> %System32%\appmgmt -> [Folder | Modified Date = 3/23/2007 7:41:28 AM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 3/28/2007 11:28:22 AM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 3/18/2007 8:35:50 PM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 3/28/2007 8:17:14 AM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 192184 bytes | Modified Date = 3/23/2007 8:20:56 AM | Attr = ]
NtmsData -> %System32%\NtmsData -> [Folder | Modified Date = 3/23/2007 11:08:02 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 54280 bytes | Modified Date = 3/17/2007 4:44:20 PM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 384596 bytes | Modified Date = 3/17/2007 4:44:20 PM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 445630 bytes | Modified Date = 3/17/2007 4:44:20 PM | Attr = ]
ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 3/4/2007 5:38:06 PM | Attr = ]
tenarchlib -> %System32%\tenarchlib -> [Folder | Modified Date = 3/21/2007 7:30:30 AM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 3/28/2007 11:26:22 AM | Attr = ]
[File String Scan - Non-Microsoft Only]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/4/2004 5:00:00 AM | Attr = ]
UPX! , -> %System32%\locate.com -> [Ver = | Size = 11254 bytes | Modified Date = 1/13/2005 9:41:48 PM | Attr = ]
UPX! , UPX0 , -> %System32%\pncrt.dll -> Real Networks, Inc [Ver = 6.0.0.0 | Size = 123392 bytes | Modified Date = 11/25/2003 5:32:02 PM | Attr = ]
UPX! , WSUD , UPX0 , -> %System32%\strings.exe -> [Ver = | Size = 175616 bytes | Modified Date = 1/20/2005 1:47:50 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/4/2004 5:00:00 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.444 | Size = 775680 bytes | Modified Date = 2/25/2007 4:51:34 AM | Attr = ]
< End of report >