Here are the results of the WinPFind.txt
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600
Internet Explorer Version: 6.0.2800.1106
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
UPX! 4/26/2004 1:45:52 PM 6656 C:\WINDOWS\services.exe
Checking %System% folder...
FSG! 9/1/2005 10:42:32 PM 8833 C:\WINDOWS\SYSTEM32\1010781.exe
FSG! 9/4/2005 2:54:38 AM 8833 C:\WINDOWS\SYSTEM32\32101625.exe
UPX! 4/26/2004 1:28:28 PM 3072 C:\WINDOWS\SYSTEM32\arpa.exe
UPX! 7/23/2004 1:32:52 PM 9728 C:\WINDOWS\SYSTEM32\authz.exe
PEC2 8/29/2002 6:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 4/29/2004 2:35:00 AM H 3066522 C:\WINDOWS\SYSTEM32\kyf.dat
UPX! 8/22/2001 6:00:00 PM 86030 C:\WINDOWS\SYSTEM32\msdjgk.dll
UPX! 8/22/2001 6:00:00 PM 218624 C:\WINDOWS\SYSTEM32\mseggo.gif
Umonitor 8/29/2002 6:00:00 AM 631808 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 8/29/2002 6:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
Checking %System%\Drivers folder and sub-folders...
UPX! 4/26/2004 2:04:54 AM 6656 C:\WINDOWS\SYSTEM32\drivers\csrss.exe
aspack 12/10/2004 10:30:48 AM R 707176 C:\WINDOWS\SYSTEM32\drivers\css-dvp.sys
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/5/2005 12:34:16 PM S 2048 C:\WINDOWS\bootstat.dat
8/4/2005 11:24:20 AM H 30202 C:\WINDOWS\fiz2
7/17/2005 8:25:22 AM H 15515 C:\WINDOWS\log0.txt
8/8/2005 11:38:06 AM H 10277 C:\WINDOWS\log1.txt
8/6/2005 8:22:38 AM H 10363 C:\WINDOWS\log2.txt
8/4/2005 11:24:22 AM H 65680 C:\WINDOWS\MEMORY.DMP
9/1/2005 1:11:56 AM H 54156 C:\WINDOWS\QTFont.qfn
8/25/2005 8:33:52 AM HS 48680 C:\WINDOWS\winnt.bmp
8/5/2005 5:27:00 AM HS 48680 C:\WINDOWS\winnt256.bmp
9/5/2005 12:34:18 PM H 6 C:\WINDOWS\Tasks\SA.DAT
Checking for CPL files...
Microsoft Corporation 8/29/2002 6:00:00 AM 66048 C:\WINDOWS\SYSTEM32\access.cpl
Realtek Semiconductor Corp. 2/17/2004 5:49:14 AM 14193152 C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL
Microsoft Corporation 8/29/2002 6:00:00 AM 578560 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 129024 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 150016 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation 4/7/2003 8:14:30 AM 94208 C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Ahead Software AG 5/26/2003 4:12:14 AM 57344 C:\WINDOWS\SYSTEM32\ImageDrive.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 292352 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 121856 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 65536 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 10/11/2003 4:52:00 AM 53352 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 559616 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 256000 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
NVIDIA Corporation 8/19/2003 3:56:00 AM 143360 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 109056 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 9/23/2004 6:57:40 PM 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 268288 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 90112 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 8/3/2004 2:03:24 PM 167704 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 66048 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 578560 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 129024 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 150016 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 292352 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 121856 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 65536 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 559616 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 256000 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 109056 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 147456 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 268288 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 90112 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Realtek Semiconductor Corp. 2/17/2004 5:49:14 AM 14193152 C:\WINDOWS\SYSTEM32\DRVSTORE\Alcxwdm_cfb7d3fc0ab7f7a3133a6c25509eaf3479108975\ALSNDMGR.CPL
Intel Corporation 4/7/2003 8:14:30 AM 94208 C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\igfxcpl.cpl
Realtek Semiconductor Corp. 9/12/2003 8:24:20 PM 10435584 C:\WINDOWS\SYSTEM32\ReinstallBackups\0014\DriverFiles\ALSNDMGR.CPL
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
9/17/2004 10:28:00 PM 1562 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dataviz Messenger.lnk
10/11/2003 4:16:08 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
Checking files in %ALLUSERSPROFILE%\Application Data folder...
10/10/2003 9:10:12 PM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
10/11/2003 5:35:18 AM 534 C:\Documents and Settings\All Users\Application Data\hpzinstall.log
Checking files in %USERPROFILE%\Startup folder...
10/11/2003 4:16:08 AM HS 84 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini
9/17/2004 11:14:26 PM 1315 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\HotSync Manager.lnk
11/7/2004 1:13:28 PM 0 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\WindowsUpdate23452[1].exe
UPX! 3/4/2005 3:24:56 AM 9216 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\winupdate07503810[1].exe
UPX! 2/18/2005 8:59:22 PM 8704 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\winupdate19698025[1].exe
6/17/2004 12:21:22 AM 938 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\WKCALREM.LNK
Checking files in %USERPROFILE%\Application Data folder...
10/10/2003 9:10:12 PM HS 62 C:\Documents and Settings\Owner\Application Data\desktop.ini
9/21/2004 9:27:20 PM 0 C:\Documents and Settings\Owner\Application Data\dm.ini
6/16/2004 9:33:44 PM 37 C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
4/26/2005 11:02:10 PM 284 C:\Documents and Settings\Owner\Application Data\ViewerApp.dat
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD9CF1BA-C149-7FD6-0BF4-CE2A97CF0E4F}
Class = C:\WINDOWS\sdklz32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = &Yahoo! Companion : C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINDOWS\System32\msdxm.ocx
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\WINDOWS\System32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
ButtonText = Messenger :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ButtonText = Research :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D7811076-5F96-4C6C-B50E-1403311C1D3A}
ButtonText = Microsoft AntiSpyware helper :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F4430FE8-2638-42e5-B849-800749B94EED}
ButtonText = PartyPoker.net : C:\Program Files\PartyPoker.net\partypokernet.exe
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}
&Research = C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = &Yahoo! Companion : C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
NeroCheck C:\WINDOWS\system32\NeroCheck.exe
SSC_UserPrompt C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
WildTangent CDA RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
iTunesHelper C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
ViewMgr C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
InstaFinderK C:\Program Files\INSTAFINK\InstaFinderK_inst.exe
explorer.exe C:\WINDOWS\explorer.exe
d3ty32.exe C:\WINDOWS\system32\d3ty32.exe
ntrd.exe C:\WINDOWS\ntrd.exe
mfcya32.exe C:\WINDOWS\mfcya32.exe
netkg32.exe C:\WINDOWS\system32\netkg32.exe
mfcgo32.exe C:\WINDOWS\system32\mfcgo32.exe
ieui32.exe C:\WINDOWS\ieui32.exe
d3hq32.exe C:\WINDOWS\d3hq32.exe
ipbf32.exe C:\WINDOWS\system32\ipbf32.exe
appwg32.exe C:\WINDOWS\appwg32.exe
cruu.exe C:\WINDOWS\system32\cruu.exe
d3ne.exe C:\WINDOWS\system32\d3ne.exe
sdkqp.exe C:\WINDOWS\system32\sdkqp.exe
d3mr32.exe C:\WINDOWS\system32\d3mr32.exe
atltm32.exe C:\WINDOWS\atltm32.exe
crfq32.exe C:\WINDOWS\system32\crfq32.exe
sdkzd32.exe C:\WINDOWS\sdkzd32.exe
sdksi.exe C:\WINDOWS\sdksi.exe
HostManager C:\Program Files\Common Files\AOL\1124573388\ee\AOLHostManager.exe
atlxm32.exe C:\WINDOWS\atlxm32.exe
apida.exe C:\WINDOWS\apida.exe
javajm32.exe C:\WINDOWS\system32\javajm32.exe
winpl.exe C:\WINDOWS\system32\winpl.exe
systf32.exe C:\WINDOWS\system32\systf32.exe
sdkpm.exe C:\WINDOWS\system32\sdkpm.exe
appws32.exe C:\WINDOWS\system32\appws32.exe
AuthConsoleStart
Upp C:\WINDOWS\Qab.exe
Shell open32.exe
Systemos Restart Rundll32.exe pifn.dll, DllRegisterServer
Mbg C:\WINDOWS\System32\Ohg.exe
Tgv C:\WINDOWS\System32\Ted.exe
Etc C:\WINDOWS\Sea.exe
Noh C:\WINDOWS\Cri.exe
Nlq C:\WINDOWS\Hft.exe
Dfl C:\WINDOWS\System32\Uuj.exe
Epm C:\WINDOWS\Uni.exe
Gai C:\WINDOWS\System32\Sgf.exe
Nbh C:\WINDOWS\Hpr.exe
Dig C:\WINDOWS\Rer.exe
Hrp C:\WINDOWS\System32\Cci.exe
Vic C:\WINDOWS\System32\Poo.exe
Mit C:\WINDOWS\Ljt.exe
Jji C:\WINDOWS\Ilc.exe
Thd C:\WINDOWS\Rkm.exe
Cfn C:\WINDOWS\System32\Ecc.exe
Qpt C:\WINDOWS\System32\Nqr.exe
Qob C:\WINDOWS\Eom.exe
Duc C:\WINDOWS\Elr.exe
Alp C:\WINDOWS\Dre.exe
Mog C:\WINDOWS\System32\Alk.exe
Nmp C:\WINDOWS\Nnl.exe
Dmg C:\WINDOWS\System32\Srs.exe
Hoi C:\WINDOWS\System32\Fuh.exe
Ruk C:\WINDOWS\Hvq.exe
Pad C:\WINDOWS\System32\Bun.exe
Tti C:\WINDOWS\Lua.exe
Mvk C:\WINDOWS\Udn.exe
Hcr C:\WINDOWS\System32\Uel.exe
Dsi C:\WINDOWS\Sha.exe
Cnr C:\WINDOWS\System32\Erc.exe
Gcs C:\WINDOWS\System32\Utn.exe
Mom C:\WINDOWS\System32\Bah.exe
Vou C:\WINDOWS\System32\Svn.exe
Ifa C:\WINDOWS\System32\Jea.exe
Imu C:\WINDOWS\System32\Ama.exe
Bgm C:\WINDOWS\System32\Ppu.exe
Lfr C:\WINDOWS\System32\Tnl.exe
Jcc C:\WINDOWS\System32\Ega.exe
Ebg C:\WINDOWS\Dai.exe
Ctj C:\WINDOWS\System32\Nll.exe
Buu C:\WINDOWS\Abv.exe
Dgg C:\WINDOWS\Rmf.exe
Blb C:\WINDOWS\System32\Lci.exe
Qme C:\WINDOWS\System32\Dku.exe
Cqk C:\WINDOWS\System32\Nvb.exe
Kig C:\WINDOWS\System32\Tom.exe
Lor C:\WINDOWS\System32\Cuj.exe
Bds C:\WINDOWS\System32\Eij.exe
Vmk C:\WINDOWS\Vaf.exe
Bvr C:\WINDOWS\Cof.exe
Ufb C:\WINDOWS\System32\Vni.exe
Gtn C:\WINDOWS\Ibu.exe
Jsv C:\WINDOWS\System32\Ovf.exe
Rhv C:\WINDOWS\Qko.exe
Alq C:\WINDOWS\Maj.exe
Vor C:\WINDOWS\System32\Bes.exe
Pcd C:\WINDOWS\Ijs.exe
Cfb C:\WINDOWS\Pkm.exe
Ugm C:\WINDOWS\System32\Upp.exe
Fbk C:\WINDOWS\Use.exe
Gom C:\WINDOWS\Ncn.exe
Uci C:\WINDOWS\System32\Tca.exe
Rnq C:\WINDOWS\System32\Jpe.exe
Api C:\WINDOWS\Jlr.exe
Qov C:\WINDOWS\Tqi.exe
Iin C:\WINDOWS\System32\Ncm.exe
Tjj C:\WINDOWS\System32\Ppe.exe
Ahe C:\WINDOWS\System32\Plc.exe
Nhn C:\WINDOWS\Fdh.exe
Rln C:\WINDOWS\System32\Irp.exe
Cqr C:\WINDOWS\Onl.exe
Cni C:\WINDOWS\Sgc.exe
Rmt C:\WINDOWS\Bfe.exe
Aua C:\WINDOWS\System32\Ljg.exe
Gba C:\WINDOWS\System32\Dql.exe
Qok C:\WINDOWS\System32\Rrj.exe
Iuu C:\WINDOWS\Tjm.exe
Lfo C:\WINDOWS\Qsl.exe
Kdm C:\WINDOWS\Chf.exe
Qjb C:\WINDOWS\System32\Eap.exe
Hnp C:\WINDOWS\Cks.exe
Ucm C:\WINDOWS\System32\Tug.exe
Vek C:\WINDOWS\Rpt.exe
Qvn C:\WINDOWS\System32\Pgf.exe
Shh C:\WINDOWS\Hnb.exe
Qsh C:\WINDOWS\Gmv.exe
Hul C:\WINDOWS\System32\Oma.exe
Pih C:\WINDOWS\System32\Ace.exe
mfcuc.exe C:\WINDOWS\mfcuc.exe
Nle C:\WINDOWS\Ofo.exe
Acj C:\WINDOWS\System32\Dps.exe
Jlj C:\WINDOWS\Sft.exe
Sdv C:\WINDOWS\Ikg.exe
Pbq C:\WINDOWS\System32\Mev.exe
Rjr C:\WINDOWS\System32\Vgn.exe
Jns C:\WINDOWS\Dvn.exe
Meq C:\WINDOWS\Nsm.exe
Qiv C:\WINDOWS\System32\Sdk.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
atldi32.exe C:\WINDOWS\atldi32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background
MoneyAgent "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
AIM C:\Program Files\AIM\aim.exe -cnetwait.odl
Weather C:\Program Files\AWS\WeatherBug\Weather.exe 1
Yahoo! Pager C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
Upp C:\WINDOWS\Qab.exe
xservice C:\DOCUME~1\Owner\LOCALS~1\Temp\temp25.exe
Mbg C:\WINDOWS\System32\Ohg.exe
Tgv C:\WINDOWS\System32\Ted.exe
Etc C:\WINDOWS\Sea.exe
Noh C:\WINDOWS\Cri.exe
Nlq C:\WINDOWS\Hft.exe
Dfl C:\WINDOWS\System32\Uuj.exe
Epm C:\WINDOWS\Uni.exe
Gai C:\WINDOWS\System32\Sgf.exe
Nbh C:\WINDOWS\Hpr.exe
Dig C:\WINDOWS\Rer.exe
Hrp C:\WINDOWS\System32\Cci.exe
Vic C:\WINDOWS\System32\Poo.exe
Mit C:\WINDOWS\Ljt.exe
winservice C:\WINDOWS\services\svchost.exe
Jji C:\WINDOWS\Ilc.exe
Thd C:\WINDOWS\Rkm.exe
Cfn C:\WINDOWS\System32\Ecc.exe
Qpt C:\WINDOWS\System32\Nqr.exe
Qob C:\WINDOWS\Eom.exe
Duc C:\WINDOWS\Elr.exe
Alp C:\WINDOWS\Dre.exe
Mog C:\WINDOWS\System32\Alk.exe
Nmp C:\WINDOWS\Nnl.exe
Dmg C:\WINDOWS\System32\Srs.exe
Hoi C:\WINDOWS\System32\Fuh.exe
Ruk C:\WINDOWS\Hvq.exe
Pad C:\WINDOWS\System32\Bun.exe
Tti C:\WINDOWS\Lua.exe
Mvk C:\WINDOWS\Udn.exe
Hcr C:\WINDOWS\System32\Uel.exe
Dsi C:\WINDOWS\Sha.exe
Cnr C:\WINDOWS\System32\Erc.exe
Gcs C:\WINDOWS\System32\Utn.exe
Mom C:\WINDOWS\System32\Bah.exe
Vou C:\WINDOWS\System32\Svn.exe
Ifa C:\WINDOWS\System32\Jea.exe
Imu C:\WINDOWS\System32\Ama.exe
Bgm C:\WINDOWS\System32\Ppu.exe
Lfr C:\WINDOWS\System32\Tnl.exe
Jcc C:\WINDOWS\System32\Ega.exe
Ebg C:\WINDOWS\Dai.exe
Ctj C:\WINDOWS\System32\Nll.exe
Buu C:\WINDOWS\Abv.exe
Dgg C:\WINDOWS\Rmf.exe
Blb C:\WINDOWS\System32\Lci.exe
Qme C:\WINDOWS\System32\Dku.exe
Cqk C:\WINDOWS\System32\Nvb.exe
Kig C:\WINDOWS\System32\Tom.exe
Lor C:\WINDOWS\System32\Cuj.exe
Bds C:\WINDOWS\System32\Eij.exe
Vmk C:\WINDOWS\Vaf.exe
Bvr C:\WINDOWS\Cof.exe
Ufb C:\WINDOWS\System32\Vni.exe
Gtn C:\WINDOWS\Ibu.exe
Jsv C:\WINDOWS\System32\Ovf.exe
Rhv C:\WINDOWS\Qko.exe
Alq C:\WINDOWS\Maj.exe
Vor C:\WINDOWS\System32\Bes.exe
Pcd C:\WINDOWS\Ijs.exe
Cfb C:\WINDOWS\Pkm.exe
Ugm C:\WINDOWS\System32\Upp.exe
Fbk C:\WINDOWS\Use.exe
Gom C:\WINDOWS\Ncn.exe
Uci C:\WINDOWS\System32\Tca.exe
Rnq C:\WINDOWS\System32\Jpe.exe
Api C:\WINDOWS\Jlr.exe
Qov C:\WINDOWS\Tqi.exe
Iin C:\WINDOWS\System32\Ncm.exe
Tjj C:\WINDOWS\System32\Ppe.exe
Ahe C:\WINDOWS\System32\Plc.exe
Nhn C:\WINDOWS\Fdh.exe
Rln C:\WINDOWS\System32\Irp.exe
Cqr C:\WINDOWS\Onl.exe
Cni C:\WINDOWS\Sgc.exe
Rmt C:\WINDOWS\Bfe.exe
Aua C:\WINDOWS\System32\Ljg.exe
Gba C:\WINDOWS\System32\Dql.exe
Qok C:\WINDOWS\System32\Rrj.exe
Iuu C:\WINDOWS\Tjm.exe
Lfo C:\WINDOWS\Qsl.exe
Kdm C:\WINDOWS\Chf.exe
Qjb C:\WINDOWS\System32\Eap.exe
Hnp C:\WINDOWS\Cks.exe
Ucm C:\WINDOWS\System32\Tug.exe
Vek C:\WINDOWS\Rpt.exe
Qvn C:\WINDOWS\System32\Pgf.exe
Shh C:\WINDOWS\Hnb.exe
Qsh C:\WINDOWS\Gmv.exe
Hul C:\WINDOWS\System32\Oma.exe
Pih C:\WINDOWS\System32\Ace.exe
Nle C:\WINDOWS\Ofo.exe
Acj C:\WINDOWS\System32\Dps.exe
Jlj C:\WINDOWS\Sft.exe
Sdv C:\WINDOWS\Ikg.exe
Pbq C:\WINDOWS\System32\Mev.exe
Rjr C:\WINDOWS\System32\Vgn.exe
Jns C:\WINDOWS\Dvn.exe
Meq C:\WINDOWS\Nsm.exe
Qiv C:\WINDOWS\System32\Sdk.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoViewContextMenu 2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
Key KY/Pkx,Rå·cÎ
Hint rats
FileName0 C:\WINDOWS\System32\RSACi.rat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default
Allow_Unknowns 0
PleaseMom 1
Enabled 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default\
http://www.rsac.org/ratingsv01.html l 0
n 0
s 0
v 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules\.Default
NumSys 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 255
_NoDriveTypeAutoRun 0
NoActiveDesktop 0
ClassicShell 0
ForceActiveDesktopOn 1
NoViewContextMenu 2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
Wallpaper C:\WINDOWS\desktop.html
disableregistrytools 0
disabletaskmgr 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\System32\AUserInit.exe
Shell = Explorer.exe
System =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
= igfxsrvc.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.5 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/5/2005 2:32:05 PM