Part 2
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{B8A7839C-51E8-4067-ADA3-CA74BABC1976} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} [HKLM] -> %ProgramFiles%\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [ZoneAlarm Spy Blocker BHO] -> ZoneAlarm [Ver = 2, 3, 0, 11 | Size = 262144 bytes | Modified Date = 2/16/2008 4:08:02 PM | Attr = ]
< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> Yahoo! Inc. [Ver = 2007, 3, 20, 1 | Size = 803864 bytes | Modified Date = 3/20/2007 4:39:26 PM | Attr = ]
{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} [HKLM] -> %ProgramFiles%\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [ZoneAlarm Spy Blocker] -> ZoneAlarm [Ver = 2, 3, 0, 11 | Size = 262144 bytes | Modified Date = 2/16/2008 4:08:02 PM | Attr = ]
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} [HKLM] -> %ProgramFiles%\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [ZoneAlarm Spy Blocker] -> ZoneAlarm [Ver = 2, 3, 0, 11 | Size = 262144 bytes | Modified Date = 2/16/2008 4:08:02 PM | Attr = ]
< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr = ]
{7F9DB11C-E358-4ca6-A83D-ACC663939424} -> Reg Data - Value does not exist [ButtonText: Bonjour] -> File not found
{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> Reg Data - Key not found [MenuText: @xpsp3res.dll,-20001] -> File not found
< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> -> File not found
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->
YPC 3.2.0 -> Yahoo! Parental Controls ->
< Winsock2 Catalogs [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ ->
NameSpace_Catalog5\Catalog_Entries\000000000001 [mdnsNSP] -> %ProgramFiles%\Bonjour\mdnsNSP.dll -> Apple Inc. [Ver = 1,0,4,12 | Size = 147456 bytes | Modified Date = 7/24/2007 3:17:08 PM | Attr = ]
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{0B79F48A-E8D6-11DB-9283-E25056D89593} -> F-Secure Online Scanner 3.1 - CodeBase =
http://support.f-secure.com/ols/fscax.cab ->
{166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase =
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab ->
{17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase =
http://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -> Installation Support - CodeBase = C:\Program Files\Yahoo!\Common\Yinsthelper.dll ->
{5ED80217-570B-4DA9-BF44-BE107C0EC166} -> Windows Live Safety Center Base Module - CodeBase =
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab ->
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} -> DivXBrowserPlugin Object - CodeBase =
http://download.divx.com/player/DivXBrowserPlugin.cab ->
{8167C273-DF59-4416-B647-C8BB2C7EE83E} -> WebSDev Control - CodeBase =
http://liveupdate.msi.com.tw/autobios/LOnline/install.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_03 - CodeBase =
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -> - CodeBase =
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab ->
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_02 - CodeBase =
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_03 - CodeBase =
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_03 - CodeBase =
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> Shockwave Flash Object - CodeBase =
http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab ->
{D4323BF2-006A-4440-A2F5-27E3E7AB25F8} -> Virtools WebPlayer Class - CodeBase =
http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe ->
[Files/Folders - Created Within 30 days]
aidualc3 -> %SystemDrive%\aidualc3 -> [Folder | Created Date = 1/20/2008 5:41:56 PM | Attr = ]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 2/9/2008 9:10:06 AM | Attr = RHS]
Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 2/8/2008 5:29:18 PM | Attr = ]
QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 2/8/2008 5:40:49 PM | Attr = ]
rollback.ini -> %SystemDrive%\rollback.ini -> [Ver = | Size = 2544 bytes | Created Date = 1/30/2008 4:04:11 PM | Attr = ]
SICKO -> %SystemDrive%\SICKO -> [Folder | Created Date = 1/31/2008 8:21:22 PM | Attr = ]
$NtUninstallKB943055$ -> %SystemRoot%\$NtUninstallKB943055$ -> [Folder | Created Date = 2/13/2008 5:00:54 PM | Attr = H ]
$NtUninstallKB946026$ -> %SystemRoot%\$NtUninstallKB946026$ -> [Folder | Created Date = 2/13/2008 5:02:17 PM | Attr = H ]
$NtUninstallWudf01000$ -> %SystemRoot%\$NtUninstallWudf01000$ -> [Folder | Created Date = 2/7/2008 8:20:55 AM | Attr = H ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 2/8/2008 5:41:23 PM | Attr = ]
gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 14, 14116 | Size = 819200 bytes | Created Date = 2/11/2008 1:06:47 PM | Attr = ]
gmer.exe -> %SystemRoot%\gmer.exe -> [Ver = 1, 0, 14, 14116 | Size = 757760 bytes | Created Date = 2/11/2008 1:06:47 PM | Attr = ]
gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 250 bytes | Created Date = 2/11/2008 1:06:49 PM | Attr = ]
gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Created Date = 2/11/2008 1:06:47 PM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 2/18/2008 9:26:16 AM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 2/3/2008 9:51:13 AM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 2/3/2008 9:51:13 AM | Attr = H ]
setup.pss -> %SystemRoot%\setup.pss -> [Folder | Created Date = 2/9/2008 9:10:02 AM | Attr = ]
setupupd -> %SystemRoot%\setupupd -> [Folder | Created Date = 2/9/2008 9:09:44 AM | Attr = ]
WMSysPr8.prx -> %SystemRoot%\WMSysPr8.prx -> [Ver = | Size = 156910 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
zllsputility.exe -> %SystemRoot%\zllsputility.exe -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 75248 bytes | Created Date = 2/16/2008 4:07:03 PM | Attr = ]
AC3ACM.acm -> %System32%\AC3ACM.acm -> fccHandler [Ver = 0, 7, 0, 0 | Size = 81920 bytes | Created Date = 2/3/2008 11:03:19 AM | Attr = ]
alf2cd.acm -> %System32%\alf2cd.acm -> NCT Company [Ver = 2.03 | Size = 38912 bytes | Created Date = 2/3/2008 11:03:19 AM | Attr = ]
camcodec.dll -> %System32%\camcodec.dll -> RenderSoft Software. [Ver = 1.0.0 | Size = 51200 bytes | Created Date = 2/7/2008 10:58:17 AM | Attr = ]
ControlSubX.ocx -> %System32%\ControlSubX.ocx -> [Ver = 1.00.0007 | Size = 24576 bytes | Created Date = 1/31/2008 10:35:31 PM | Attr = ]
divx.dll -> %System32%\divx.dll -> DivXNetworks, Inc. [Ver = 5.0.5.830 | Size = 638976 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
divxdec.ax -> %System32%\divxdec.ax -> DivXNetworks, Inc. [Ver = 5.0.5.830 | Size = 221215 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
fdsv.exe -> %System32%\fdsv.exe -> Smallfrogs Studio [Ver = 1.0.0.10 | Size = 73728 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
grep.exe -> %System32%\grep.exe -> [Ver = | Size = 80412 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
libeay32_0.9.6l.dll -> %System32%\libeay32_0.9.6l.dll -> [Ver = | Size = 796048 bytes | Created Date = 2/16/2008 4:06:37 PM | Attr = ]
mcdvd_32.dll -> %System32%\mcdvd_32.dll -> MainConcept [Ver = 2.0.4 | Size = 261632 bytes | Created Date = 2/3/2008 11:03:19 AM | Attr = ]
PropertyGrid.ocx -> %System32%\PropertyGrid.ocx -> [Ver = 1.00 | Size = 364544 bytes | Created Date = 1/31/2008 10:35:34 PM | Attr = ]
ReyXpBasics.tlb -> %System32%\ReyXpBasics.tlb -> [Ver = | Size = 208500 bytes | Created Date = 1/31/2008 10:35:34 PM | Attr = ]
rrMon.sys -> %System32%\rrMon.sys -> Resplendence Software Projects Sp [Ver = 2.02 built by: WinDDK | Size = 31280 bytes | Created Date = 2/12/2008 5:15:35 PM | Attr = ]
rrsec.dll -> %System32%\rrsec.dll -> [Ver = | Size = 119728 bytes | Created Date = 2/12/2008 3:37:12 PM | Attr = ]
rrsec2k.exe -> %System32%\rrsec2k.exe -> [Ver = | Size = 97240 bytes | Created Date = 2/12/2008 3:37:12 PM | Attr = ]
Scg726.acm -> %System32%\Scg726.acm -> SHARP Corporation [Ver = 1, 0, 0, 3 | Size = 13239 bytes | Created Date = 2/3/2008 11:03:19 AM | Attr = ]
sed.exe -> %System32%\sed.exe -> [Ver = | Size = 98816 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 2/8/2008 5:40:39 PM | Attr = ]
swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
vct3216.acm -> %System32%\vct3216.acm -> Voxware, Inc. [Ver = 1.6.0.17 | Size = 82944 bytes | Created Date = 2/3/2008 11:03:19 AM | Attr = ]
VFind.exe -> %System32%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 2/8/2008 5:40:38 PM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 353366 bytes | Created Date = 2/16/2008 4:06:23 PM | Attr = ]
vsdata.dll -> %System32%\vsdata.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 83432 bytes | Created Date = 2/16/2008 4:05:09 PM | Attr = ]
vsdatant.sys -> %System32%\vsdatant.sys -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 394952 bytes | Created Date = 2/16/2008 4:06:23 PM | Attr = ]
vsinit.dll -> %System32%\vsinit.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 157160 bytes | Created Date = 2/16/2008 4:05:09 PM | Attr = ]
vsmonapi.dll -> %System32%\vsmonapi.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 103912 bytes | Created Date = 2/16/2008 4:06:24 PM | Attr = ]
vspubapi.dll -> %System32%\vspubapi.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 275944 bytes | Created Date = 2/16/2008 4:06:24 PM | Attr = ]
vsregexp.dll -> %System32%\vsregexp.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 71144 bytes | Created Date = 2/16/2008 4:06:37 PM | Attr = ]
vsutil.dll -> %System32%\vsutil.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 472552 bytes | Created Date = 2/16/2008 4:05:09 PM | Attr = ]
vswmi.dll -> %System32%\vswmi.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 46568 bytes | Created Date = 2/16/2008 4:06:26 PM | Attr = ]
vsxml.dll -> %System32%\vsxml.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 99816 bytes | Created Date = 2/16/2008 4:06:25 PM | Attr = ]
xvid.ax -> %System32%\xvid.ax -> [Ver = | Size = 53248 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
xvidcore.dll -> %System32%\xvidcore.dll -> [Ver = | Size = 524288 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
xvidvfw.dll -> %System32%\xvidvfw.dll -> [Ver = | Size = 139264 bytes | Created Date = 2/3/2008 11:03:20 AM | Attr = ]
zip.exe -> %System32%\zip.exe -> [Ver = | Size = 68096 bytes | Created Date = 2/8/2008 5:40:39 PM | Attr = ]
zlcomm.dll -> %System32%\zlcomm.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 83432 bytes | Created Date = 2/16/2008 4:06:34 PM | Attr = ]
zlcommdb.dll -> %System32%\zlcommdb.dll -> Zone Labs, LLC [Ver = 7.0.462.000 | Size = 71144 bytes | Created Date = 2/16/2008 4:06:34 PM | Attr = ]
ZoneLabs -> %System32%\ZoneLabs -> [Folder | Created Date = 1/29/2008 7:35:55 PM | Attr = ]
zpeng24.dll -> %System32%\zpeng24.dll -> Python Software Foundation [Ver = 2.4.2 | Size = 1086952 bytes | Created Date = 2/16/2008 4:06:25 PM | Attr = ]
AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Created Date = 2/14/2008 7:10:26 PM | Attr = ]
avgntdd.sys -> %System32%\drivers\avgntdd.sys -> Avira GmbH [Ver = 6.39.00.02 | Size = 40768 bytes | Created Date = 2/12/2008 3:40:26 PM | Attr = ]
avgntmgr.sys -> %System32%\drivers\avgntmgr.sys -> Avira GmbH [Ver = 6.37.01.01 | Size = 21312 bytes | Created Date = 2/12/2008 3:40:26 PM | Attr = ]
avipbb.sys -> %System32%\drivers\avipbb.sys -> AVIRA GmbH [Ver = 1.00.02.13 | Size = 61632 bytes | Created Date = 2/12/2008 3:40:22 PM | Attr = ]
camcodec.inf -> %System32%\drivers\camcodec.inf -> [Ver = | Size = 1461 bytes | Created Date = 2/7/2008 10:58:18 AM | Attr = ]
fidbox.dat -> %System32%\drivers\fidbox.dat -> [Ver = | Size = 15743008 bytes | Created Date = 2/16/2008 4:10:12 PM | Attr = HS]
fidbox.idx -> %System32%\drivers\fidbox.idx -> [Ver = | Size = 142124 bytes | Created Date = 2/16/2008 4:10:12 PM | Attr = HS]
gmer.sys -> %System32%\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4316 | Size = 85713 bytes | Created Date = 2/11/2008 1:06:47 PM | Attr = ]
klif.sys -> %System32%\drivers\klif.sys -> Kaspersky Lab [Ver = 7.0.0.122 | Size = 127768 bytes | Created Date = 2/16/2008 4:06:56 PM | Attr = ]
pcouffin.sys -> %System32%\drivers\pcouffin.sys -> VSO Software [Ver = 1.37 | Size = 47360 bytes | Created Date = 1/28/2008 5:53:57 PM | Attr = ]
ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 2/12/2008 3:40:25 PM | Attr = ]
hosts.20080120-200533.backup -> %System32%\drivers\etc\hosts.20080120-200533.backup -> [Ver = | Size = 223027 bytes | Created Date = 1/20/2008 8:05:33 PM | Attr = R ]
hosts.20080129-190002.backup -> %System32%\drivers\etc\hosts.20080129-190002.backup -> [Ver = | Size = 223027 bytes | Created Date = 1/29/2008 7:00:02 PM | Attr = R ]
hosts.20080129-190010.backup -> %System32%\drivers\etc\hosts.20080129-190010.backup -> [Ver = | Size = 223955 bytes | Created Date = 1/29/2008 7:00:10 PM | Attr = R ]
hosts.20080129-190014.backup -> %System32%\drivers\etc\hosts.20080129-190014.backup -> [Ver = | Size = 223955 bytes | Created Date = 1/29/2008 7:00:14 PM | Attr = R ]
hosts.20080129-190019.backup -> %System32%\drivers\etc\hosts.20080129-190019.backup -> [Ver = | Size = 223955 bytes | Created Date = 1/29/2008 7:00:19 PM | Attr = R ]
hosts.20080129-190025.backup -> %System32%\drivers\etc\hosts.20080129-190025.backup -> [Ver = | Size = 223955 bytes | Created Date = 1/29/2008 7:00:25 PM | Attr = R ]
hosts.20080204-204653.backup -> %System32%\drivers\etc\hosts.20080204-204653.backup -> [Ver = | Size = 223955 bytes | Created Date = 2/4/2008 8:46:53 PM | Attr = R ]
[Files/Folders - Modified Within 30 days]
$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 2/10/2008 6:58:30 PM | Attr = RH ]
aidualc3 -> %SystemDrive%\aidualc3 -> [Folder | Modified Date = 1/21/2008 8:19:40 PM | Attr = ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 282 bytes | Modified Date = 2/10/2008 8:30:08 PM | Attr = RHS]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 2/9/2008 9:10:50 AM | Attr = RHS]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 2/4/2008 7:26:02 PM | Attr = H ]
Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 2/8/2008 5:29:20 PM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 2/18/2008 1:27:42 PM | Attr = S]
QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 2/15/2008 3:52:26 PM | Attr = ]
rollback.ini -> %SystemDrive%\rollback.ini -> [Ver = | Size = 2544 bytes | Modified Date = 2/14/2008 6:50:10 PM | Attr = ]
SICKO -> %SystemDrive%\SICKO -> [Folder | Modified Date = 1/31/2008 8:21:24 PM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 2/17/2008 11:57:14 PM | Attr = HS]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 2/18/2008 9:26:18 AM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 2/13/2008 4:33:38 PM | Attr = H ]
$NtUninstallKB943055$ -> %SystemRoot%\$NtUninstallKB943055$ -> [Folder | Modified Date = 2/13/2008 5:00:56 PM | Attr = H ]
$NtUninstallKB946026$ -> %SystemRoot%\$NtUninstallKB946026$ -> [Folder | Modified Date = 2/13/2008 5:02:20 PM | Attr = H ]
$NtUninstallWudf01000$ -> %SystemRoot%\$NtUninstallWudf01000$ -> [Folder | Modified Date = 2/7/2008 8:20:56 AM | Attr = H ]
ALCFDRTM.VER -> %SystemRoot%\ALCFDRTM.VER -> Realtek Semiconductor Corp. [Ver = 1.01 | Size = 60416 bytes | Modified Date = 1/27/2008 10:30:38 AM | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 2/18/2008 8:35:46 AM | Attr = S]
cdplayer.ini -> %SystemRoot%\cdplayer.ini -> [Ver = | Size = 4934 bytes | Modified Date = 1/22/2008 4:33:02 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 2/18/2008 11:44:04 AM | Attr = S]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 2/11/2008 8:42:44 AM | Attr = ]
Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 2/3/2008 11:03:34 AM | Attr = R S]
gmer.dll -> %SystemRoot%\gmer.dll -> [Ver = 1, 0, 14, 14116 | Size = 819200 bytes | Modified Date = 2/11/2008 1:06:48 PM | Attr = ]
gmer.ini -> %SystemRoot%\gmer.ini -> [Ver = | Size = 250 bytes | Modified Date = 2/11/2008 3:13:16 PM | Attr = ]
gmer_uninstall.cmd -> %SystemRoot%\gmer_uninstall.cmd -> [Ver = | Size = 80 bytes | Modified Date = 2/11/2008 1:06:48 PM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 2/17/2008 8:52:38 PM | Attr = ]
ie7updates -> %SystemRoot%\ie7updates -> [Folder | Modified Date = 2/13/2008 5:01:34 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 2/13/2008 5:01:54 PM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 2/17/2008 8:52:22 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 2/5/2008 3:42:22 PM | Attr = HS]
Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 2/18/2008 1:24:58 PM | Attr = ]
LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 2/18/2008 9:26:18 AM | Attr = ]
MEMORY.DMP -> %SystemRoot%\MEMORY.DMP -> [Ver = | Size = 1073299456 bytes | Modified Date = 2/8/2008 7:13:38 PM | Attr = ]
Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 2/8/2008 7:13:44 PM | Attr = ]
nview -> %SystemRoot%\nview -> [Folder | Modified Date = 2/17/2008 10:21:26 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 2/18/2008 1:27:20 PM | Attr = ]
pss -> %SystemRoot%\pss -> [Folder | Modified Date = 2/9/2008 9:01:16 AM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 2/3/2008 9:51:14 AM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 2/18/2008 1:16:32 PM | Attr = H ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 1/31/2008 3:46:06 PM | Attr = ]
security -> %SystemRoot%\security -> [Folder | Modified Date = 2/10/2008 11:25:50 PM | Attr = ]
setup.pss -> %SystemRoot%\setup.pss -> [Folder | Modified Date = 2/9/2008 9:10:04 AM | Attr = ]
setupupd -> %SystemRoot%\setupupd -> [Folder | Modified Date = 2/9/2008 9:09:58 AM | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 327 bytes | Modified Date = 2/15/2008 3:52:42 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 2/17/2008 10:21:28 PM | Attr = ]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 2/18/2008 8:38:52 AM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 2/18/2008 1:27:56 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 1225 bytes | Modified Date = 2/10/2008 8:30:08 PM | Attr = ]
Ad-Aware SE Personal.job -> %SystemRoot%\tasks\Ad-Aware SE Personal.job -> [Ver = | Size = 348 bytes | Modified Date = 2/16/2008 8:00:02 PM | Attr = ]
MP Scheduled Scan.job -> %SystemRoot%\tasks\MP Scheduled Scan.job -> [Ver = | Size = 330 bytes | Modified Date = 2/18/2008 8:38:52 AM | Attr = H ]
Norton Security Online - Run Full System Scan - Wyatt.job -> %SystemRoot%\tasks\Norton Security Online - Run Full System Scan - Wyatt.job -> [Ver = | Size = 576 bytes | Modified Date = 2/4/2008 8:00:02 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 2/18/2008 8:35:58 AM | Attr = H ]
Spybot - Search & Destroy - Scheduled Task.job -> %SystemRoot%\tasks\Spybot - Search & Destroy - Scheduled Task.job -> [Ver = | Size = 440 bytes | Modified Date = 2/15/2008 5:30:02 PM | Attr = ]
SpywareBlaster.job -> %SystemRoot%\tasks\SpywareBlaster.job -> [Ver = | Size = 264 bytes | Modified Date = 2/16/2008 8:00:02 PM | Attr = ]
amcompat.tlb -> %System32%\amcompat.tlb -> [Ver = | Size = 16832 bytes | Modified Date = 2/7/2008 8:27:44 AM | Attr = ]
CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 2/16/2008 4:07:02 PM | Attr = ]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 2/18/2008 8:38:56 AM | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 2/11/2008 8:43:04 AM | Attr = ]
CONFIG.NT -> %System32%\CONFIG.NT -> [Ver = | Size = 2577 bytes | Modified Date = 2/15/2008 6:46:18 PM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 2/17/2008 8:52:36 PM | Attr = RHS]
drivers -> %System32%\drivers -> [Folder | Modified Date = 2/17/2008 8:52:28 PM | Attr = ]
FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 1449256 bytes | Modified Date = 2/3/2008 1:37:58 PM | Attr = ]
mlfcache.dat -> %System32%\mlfcache.dat -> [Ver = | Size = 28608 bytes | Modified Date = 2/8/2008 8:40:26 PM | Attr = H ]
nscompat.tlb -> %System32%\nscompat.tlb -> [Ver = | Size = 23392 bytes | Modified Date = 2/7/2008 8:27:44 AM | Attr = ]
nvapps.xml -> %System32%\nvapps.xml -> [Ver = | Size = 161432 bytes | Modified Date = 2/17/2008 8:52:54 PM | Attr = ]
pncrt.dll -> %System32%\pncrt.dll -> Real Networks, Inc [Ver = 6.0.0.0 | Size = 278528 bytes | Modified Date = 2/1/2008 9:47:14 AM | Attr = ]
pndx5016.dll -> %System32%\pndx5016.dll -> RealNetworks, Inc. [Ver = 5.0.0.0 | Size = 6656 bytes | Modified Date = 2/1/2008 9:47:20 AM | Attr = ]
pndx5032.dll -> %System32%\pndx5032.dll -> RealNetworks, Inc. [Ver = 5.0.0.0 | Size = 5632 bytes | Modified Date = 2/1/2008 9:47:20 AM | Attr = ]
ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 2/17/2008 8:52:38 PM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 2/17/2008 11:57:14 PM | Attr = ]
rmoc3260.dll -> %System32%\rmoc3260.dll -> RealNetworks, Inc. [Ver = 6.0.10.45 | Size = 185944 bytes | Modified Date = 2/1/2008 9:48:16 AM | Attr = ]
rrMon.sys -> %System32%\rrMon.sys -> Resplendence Software Projects Sp [Ver = 2.02 built by: WinDDK | Size = 31280 bytes | Modified Date = 2/9/2008 11:20:04 AM | Attr = ]
rrsec.dll -> %System32%\rrsec.dll -> [Ver = | Size = 119728 bytes | Modified Date = 2/9/2008 11:20:08 AM | Attr = ]
rrsec2k.exe -> %System32%\rrsec2k.exe -> [Ver = | Size = 97240 bytes | Modified Date = 2/9/2008 11:19:50 AM | Attr = ]
vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 353366 bytes | Modified Date = 2/18/2008 8:36:34 AM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 13646 bytes | Modified Date = 2/18/2008 1:16:18 PM | Attr = ]
zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 2/17/2008 10:30:18 PM | Attr = H ]
ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 2/16/2008 4:07:08 PM | Attr = ]
avipbb.sys -> %System32%\drivers\avipbb.sys -> AVIRA GmbH [Ver = 1.00.02.13 | Size = 61632 bytes | Modified Date = 2/12/2008 3:42:26 PM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 2/11/2008 8:45:44 AM | Attr = ]
fidbox.dat -> %System32%\drivers\fidbox.dat -> [Ver = | Size = 15743008 bytes | Modified Date = 2/18/2008 1:22:32 PM | Attr = HS]
fidbox.idx -> %System32%\drivers\fidbox.idx -> [Ver = | Size = 142124 bytes | Modified Date = 2/18/2008 12:01:02 AM | Attr = HS]
gmer.sys -> %System32%\drivers\gmer.sys -> GMER [Ver = 1, 0, 14, 4316 | Size = 85713 bytes | Modified Date = 2/11/2008 1:06:48 PM | Attr = ]
pcouffin.sys -> %System32%\drivers\pcouffin.sys -> VSO Software [Ver = 1.37 | Size = 47360 bytes | Modified Date = 1/28/2008 5:53:58 PM | Attr = ]
hosts.20080129-190002.backup -> %System32%\drivers\etc\hosts.20080129-190002.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/20/2008 8:05:34 PM | Attr = R ]
hosts.20080129-190010.backup -> %System32%\drivers\etc\hosts.20080129-190010.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:04 PM | Attr = R ]
hosts.20080129-190014.backup -> %System32%\drivers\etc\hosts.20080129-190014.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:12 PM | Attr = R ]
hosts.20080129-190019.backup -> %System32%\drivers\etc\hosts.20080129-190019.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:16 PM | Attr = R ]
hosts.20080129-190025.backup -> %System32%\drivers\etc\hosts.20080129-190025.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:20 PM | Attr = R ]
hosts.20080204-204653.backup -> %System32%\drivers\etc\hosts.20080204-204653.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:26 PM | Attr = R ]
[File String Scan - Non-Microsoft Only]
File scan skipped for file %SystemRoot%\MEMORY.DMP -> File size too big (1073299456 bytes) ->
UPX! , UPX0 , -> %SystemRoot%\screengenie.scr -> XMLAuthor Inc. [Ver = 6.1.55.0 | Size = 1559056 bytes | Modified Date = 10/31/2006 9:32:30 PM | Attr = ]
@Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable ->
WSUD , -> %System32%\ALSNDMGR.CPL -> Realtek Semiconductor Corp. [Ver = 2.2.0.37 | Size = 16166912 bytes | Modified Date = 12/1/2004 2:53:44 AM | Attr = R ]
@Alternate Data Stream - 26 bytes -> %System32%\bdco1.dll:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\bdco1ins.dll:Zone.Identifier ->
aspack , -> %System32%\ControlSubX.ocx -> [Ver = 1.00.0007 | Size = 24576 bytes | Modified Date = 9/28/2005 1:31:50 AM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %System32%\fdco1.dll:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\fdco1ins.dll:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\idecoi.dll:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\idecoins.dll:Zone.Identifier ->
UPX! , UPX0 , -> %System32%\npmirage.dll -> XMLAuthor Inc. [Ver = 6, 1, 55, 0 | Size = 35344 bytes | Modified Date = 10/31/2006 9:32:40 PM | Attr = ]
@Alternate Data Stream - 26 bytes -> %System32%\NVCOI.DLL:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\nvconrm.dll:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\nvide.nvu:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\nvnrm.nvu:Zone.Identifier ->
PEC2 , -> %System32%\ReyXpBasics.tlb -> [Ver = | Size = 208500 bytes | Modified Date = 10/13/2005 1:42:22 PM | Attr = ]
Thawte Consulting , -> %System32%\rmoc3260.dll -> RealNetworks, Inc. [Ver = 6.0.10.45 | Size = 185944 bytes | Modified Date = 2/1/2008 9:48:16 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Modified Date = 8/31/2000 8:00:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\Uharc.exe -> [Ver = | Size = 111104 bytes | Modified Date = 12/3/2006 4:15:34 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
Thawte Consulting , -> %System32%\wbsys.dll -> Stardock.Net, Inc [Ver = 5, 5, 0, 0 | Size = 42672 bytes | Modified Date = 5/26/2007 11:34:34 AM | Attr = ]
UPX! , UPX0 , -> %System32%\xmforgert.exe -> XMLAuthor Inc. [Ver = 6.1.55.0 | Size = 1559056 bytes | Modified Date = 10/31/2006 9:32:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\xmirage.ocx -> XMLAuthor Inc. [Ver = 6.1.55.0 | Size = 300560 bytes | Modified Date = 10/31/2006 9:32:36 PM | Attr = ]
UPX! , UPX0 , -> %System32%\xmirageu.ocx -> XMLAuthor Inc.
www.mediaforge.com [Ver = 1, 0, 0, 3 | Size = 136208 bytes | Modified Date = 3/4/2006 5:19:58 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 8/4/2004 7:00:00 AM | Attr = ]
UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.498 | Size = 821856 bytes | Modified Date = 1/3/2008 8:56:48 PM | Attr = ]
@Alternate Data Stream - 26 bytes -> %System32%\drivers\nvata.sys:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\drivers\NVENETFD.sys:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\drivers\nvnetbus.sys:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\drivers\nvnrm.sys:Zone.Identifier ->
@Alternate Data Stream - 26 bytes -> %System32%\drivers\nvsnpu.sys:Zone.Identifier ->
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080113-174037.backup -> [Ver = | Size = 222475 bytes | Modified Date = 1/4/2008 7:45:36 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080113-174044.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/13/2008 5:40:40 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080114-180837.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/13/2008 5:40:46 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080116-155044.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/14/2008 6:08:40 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080116-155453.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/16/2008 3:50:46 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080116-155459.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/16/2008 3:54:54 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080116-155506.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/16/2008 3:55:00 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080120-200533.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/16/2008 3:55:08 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080129-190002.backup -> [Ver = | Size = 223027 bytes | Modified Date = 1/20/2008 8:05:34 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080129-190010.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:04 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080129-190014.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:12 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080129-190019.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:16 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080129-190025.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:20 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\hosts.20080204-204653.backup -> [Ver = | Size = 223955 bytes | Modified Date = 1/29/2008 7:00:26 PM | Attr = R ]
abetterinternet.com , web-nex , ad-w-a-r-e.com , -> %System32%\drivers\etc\Hosts.bak -> [Ver = | Size = 210837 bytes | Modified Date = 11/10/2007 8:51:44 PM | Attr = RH ]
< End of report >