[code] WinPFind35 logfile created on: 3/12/2008 10:22:31 PM WinPFind35U Version 1.0.5.0 Folder = C:\Documents and Settings\LuanneRowland\Desktop\WinPFind35u Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 1014.05 Mb Total Physical Memory | 402.23 Mb Available Physical Memory | 39.67% Memory free 2.38 Gb Paging File | 1.85 Gb Available in Paging File | 77.67% Paging File free Paging file location(s): C:\pagefile.sys 1524 3048; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 55.88 Gb Total Space | 31.21 Gb Free Space | 55.85% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: CAES-LROWLAND2 Current User Name: LuanneRowland Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users [Processes - Non-Microsoft Only] xtagent.exe -> %SystemRoot%\system32\novell\xtagent.exe -> Novell, Inc. [Ver = 1.2.3.1 | Size = 61440 bytes | Modified Date = 5/2/2006 10:17:16 AM | Attr = ] evteng.exe -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 10.5.1.21 | Size = 434176 bytes | Modified Date = 10/18/2006 6:05:18 PM | Attr = ] s24evmon.exe -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 10.5.1.3 | Size = 946176 bytes | Modified Date = 10/18/2006 5:56:52 PM | Attr = ] wlkeeper.exe -> %ProgramFiles%\Intel\Wireless\Bin\WLKEEPER.exe -> Intel(R) Corporation [Ver = 10.5.1.5 | Size = 290816 bytes | Modified Date = 10/18/2006 6:01:34 PM | Attr = ] ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 169632 bytes | Modified Date = 3/24/2006 6:14:58 PM | Attr = ] ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 192160 bytes | Modified Date = 3/24/2006 6:14:52 PM | Attr = ] spbbcsvc.exe -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.2.0.7 | Size = 1160848 bytes | Modified Date = 4/11/2006 6:13:38 PM | Attr = ] aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/14/2008 11:44:35 PM | Attr = ] aolacsd.exe -> %CommonProgramFiles%\aol\acs\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 8:50:35 AM | Attr = R ] applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 12, 0, 0 | Size = 106496 bytes | Modified Date = 7/31/2007 6:11:06 PM | Attr = ] defwatch.exe -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 31472 bytes | Modified Date = 6/15/2006 2:40:16 AM | Attr = ] nalntsrv.exe -> %ProgramFiles%\Novell\ZENworks\NALNTSRV.EXE -> Novell, Inc. [Ver = 7.0.1.0 | Size = 113152 bytes | Modified Date = 6/13/2006 8:52:18 AM | Attr = ] netaloader.exe -> %SystemRoot%\NetALoader.exe -> SurfControl [Ver = 3.5.1.2 | Size = 282624 bytes | Modified Date = 6/12/2006 11:44:02 AM | Attr = ] regsrvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 10.5.1.5 | Size = 327680 bytes | Modified Date = 10/18/2006 5:49:52 PM | Attr = ] zenrem32.exe -> %ProgramFiles%\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe -> Novell, Inc. [Ver = 7,0,0,1 | Size = 167936 bytes | Modified Date = 5/9/2006 11:59:00 AM | Attr = ] savroam.exe -> %ProgramFiles%\Symantec AntiVirus\SavRoam.exe -> symantec [Ver = 10.1.4.4000 | Size = 115952 bytes | Modified Date = 6/15/2006 2:40:28 AM | Attr = ] rtvscan.exe -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 1805552 bytes | Modified Date = 6/15/2006 2:40:24 AM | Attr = ] viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> Viewpoint Corporation [Ver = 2, 0, 0, 54 | Size = 24652 bytes | Modified Date = 1/4/2007 5:38:08 PM | Attr = ] wm.exe -> %ProgramFiles%\Novell\ZENworks\WM.EXE -> Novell, Inc. [Ver = v7.0.1 (20060510) | Size = 151104 bytes | Modified Date = 6/13/2006 8:57:32 AM | Attr = ] wmrundll.exe -> %ProgramFiles%\Novell\ZENworks\WMRUNDLL.EXE -> Novell, Inc. [Ver = v7.0.1 (20060510) | Size = 12224 bytes | Modified Date = 6/13/2006 8:57:30 AM | Attr = ] dpmw32.exe -> %SystemRoot%\system32\dpmw32.exe -> Novell, Inc. [Ver = v3.0.1 | Size = 32859 bytes | Modified Date = 5/17/2004 2:27:28 PM | Attr = ] nwtray.exe -> %SystemRoot%\system32\nwtray.exe -> Novell, Inc. [Ver = v4.90 | Size = 28672 bytes | Modified Date = 3/12/2002 10:37:28 AM | Attr = ] ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 53408 bytes | Modified Date = 3/24/2006 6:14:48 PM | Attr = ] vptray.exe -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 124656 bytes | Modified Date = 6/15/2006 2:40:34 AM | Attr = ] iprntctl.exe -> %SystemRoot%\system32\iprntctl.exe -> Novell, Inc. [Ver = 4,2,6,0 | Size = 40960 bytes | Modified Date = 10/18/2006 3:14:18 PM | Attr = ] hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 77824 bytes | Modified Date = 1/24/2007 3:35:28 PM | Attr = ] igfxpers.exe -> %SystemRoot%\system32\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 118784 bytes | Modified Date = 1/24/2007 3:35:29 PM | Attr = ] igfxsrvc.exe -> %SystemRoot%\system32\igfxsrvc.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 159744 bytes | Modified Date = 1/24/2007 3:35:30 PM | Attr = ] stsystra.exe -> %SystemRoot%\stsystra.exe -> SigmaTel, Inc. [Ver = 1.0.4995.1 nd446 cp1 | Size = 282624 bytes | Modified Date = 3/24/2006 5:30:44 PM | Attr = ] zcfgsvc.exe -> %ProgramFiles%\Intel\Wireless\Bin\ZCfgSvc.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 802816 bytes | Modified Date = 10/18/2006 6:04:28 PM | Attr = ] ifrmewrk.exe -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 10.5.1.18 | Size = 696320 bytes | Modified Date = 10/18/2006 5:58:16 PM | Attr = ] dlactrlw.exe -> %SystemRoot%\system32\DLA\DLACTRLW.EXE -> Sonic Solutions [Ver = 5.20.08a | Size = 122940 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] issch.exe -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 81920 bytes | Modified Date = 7/27/2004 4:50:18 PM | Attr = ] dvdlauncher.exe -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 49152 bytes | Modified Date = 12/9/2005 8:29:52 PM | Attr = ] iprntlgn.exe -> %SystemRoot%\system32\iprntlgn.exe -> Novell, Inc. [Ver = 4,2,6,0 | Size = 45056 bytes | Modified Date = 10/18/2006 3:14:28 PM | Attr = ] aolsoftware.exe -> %CommonProgramFiles%\aol\1185832750\ee\aolsoftware.exe -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 1:16:08 PM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.3.2.6 | Size = 271672 bytes | Modified Date = 7/31/2007 6:44:42 PM | Attr = ] napster.exe -> %ProgramFiles%\Napster\napster.exe -> Napster [Ver = 4.0.4.7 | Size = 323216 bytes | Modified Date = 10/29/2007 6:14:04 PM | Attr = ] sprtcmd.exe -> %ProgramFiles%\Bellsouth\HelpCenter40b\bin\sprtcmd.exe -> SupportSoft, Inc. [Ver = 6,9,2018,0 | Size = 198184 bytes | Modified Date = 6/28/2007 7:02:08 PM | Attr = ] teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 0, 9 | Size = 1460312 bytes | Modified Date = 6/18/2007 3:58:02 PM | Attr = ] nkbmonitor.exe -> %ProgramFiles%\Nikon\PictureProject\NkbMonitor.exe -> Nikon Corporation [Ver = 1, 7, 5, 3000 | Size = 118784 bytes | Modified Date = 11/29/2006 5:48:22 PM | Attr = ] memonitor.exe -> %ProgramFiles%\Verizon Wireless\V CAST Music Manager\MEMonitor.exe -> Smith Micro Software, Inc. [Ver = 1.1.0 | Size = 947544 bytes | Modified Date = 7/4/2007 4:25:16 AM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.3.2.6 | Size = 501048 bytes | Modified Date = 7/31/2007 6:44:34 PM | Attr = ] waol.exe -> %ProgramFiles%\AOL 9.1\waol.exe -> AOL, LLC. [Ver = 9.05.001 | Size = 39264 bytes | Modified Date = 10/27/2007 1:45:07 PM | Attr = ] shellmon.exe -> %ProgramFiles%\AOL 9.1\shellmon.exe -> AOL, LLC. [Ver = 9.05.001 | Size = 54624 bytes | Modified Date = 10/27/2007 1:45:05 PM | Attr = ] dot1xcfg.exe -> %ProgramFiles%\Intel\Wireless\Bin\Dot1XCfg.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 479232 bytes | Modified Date = 10/18/2006 5:53:24 PM | Attr = ] isuspm.exe -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe -> InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 221184 bytes | Modified Date = 7/27/2004 4:50:42 PM | Attr = ] agent.exe -> %CommonProgramFiles%\InstallShield\UpdateService\agent.exe -> InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 503808 bytes | Modified Date = 7/27/2004 4:50:04 PM | Attr = ] realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.4081 | Size = 185632 bytes | Modified Date = 9/9/2007 4:02:32 PM | Attr = ] firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe -> Mozilla Corporation [Ver = 1.8.1.12: 2008020121 | Size = 7655024 bytes | Modified Date = 2/9/2008 9:24:40 AM | Attr = ] winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.5.0 | Size = 310272 bytes | Modified Date = 3/10/2008 2:34:14 AM | Attr = ] [Win32 Services - Non-Microsoft Only] (aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/14/2008 11:44:35 PM | Attr = ] (AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\aol\acs\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 8:50:35 AM | Attr = R ] (Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 12, 0, 0 | Size = 106496 bytes | Modified Date = 7/31/2007 6:11:06 PM | Attr = ] (ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 192160 bytes | Modified Date = 3/24/2006 6:14:52 PM | Attr = ] (ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 169632 bytes | Modified Date = 3/24/2006 6:14:58 PM | Attr = ] (cusrvc) Client Update Service for Novell [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\system32\cusrvc.exe -> Novell, Inc. [Ver = v4.91 | Size = 28672 bytes | Modified Date = 8/11/2006 3:51:04 PM | Attr = ] (DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 31472 bytes | Modified Date = 6/15/2006 2:40:16 AM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (EvtEng) Intel(R) PROSet/Wireless Event Log [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\EvtEng.exe -> Intel Corporation [Ver = 10.5.1.21 | Size = 434176 bytes | Modified Date = 10/18/2006 6:05:18 PM | Attr = ] (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.3.2.6 | Size = 501048 bytes | Modified Date = 7/31/2007 6:44:34 PM | Attr = ] (LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_0.EXE -> Symantec Corporation [Ver = 3.0.0.160 | Size = 2045632 bytes | Modified Date = 2/23/2006 12:41:02 PM | Attr = ] (NALNTSERVICE) Novell Application Launcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Novell\ZENworks\NALNTSRV.EXE -> Novell, Inc. [Ver = 7.0.1.0 | Size = 113152 bytes | Modified Date = 6/13/2006 8:52:18 AM | Attr = ] (NetALoader) NetALoader [Win32_Own | Auto | Running] -> %SystemRoot%\NetALoader.exe -> SurfControl [Ver = 3.5.1.2 | Size = 282624 bytes | Modified Date = 6/12/2006 11:44:02 AM | Attr = ] (RegSrvc) Intel(R) PROSet/Wireless Registry Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\RegSrvc.exe -> Intel Corporation [Ver = 10.5.1.5 | Size = 327680 bytes | Modified Date = 10/18/2006 5:49:52 PM | Attr = ] (Remote Management Agent) Novell ZENworks Remote Management Agent [Win32_Own | Auto | Running] -> %ProgramFiles%\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe -> Novell, Inc. [Ver = 7,0,0,1 | Size = 167936 bytes | Modified Date = 5/9/2006 11:59:00 AM | Attr = ] (S24EventMonitor) Intel(R) PROSet/Wireless Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\S24EvMon.exe -> Intel Corporation [Ver = 10.5.1.3 | Size = 946176 bytes | Modified Date = 10/18/2006 5:56:52 PM | Attr = ] (SavRoam) SavRoam [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\SavRoam.exe -> symantec [Ver = 10.1.4.4000 | Size = 115952 bytes | Modified Date = 6/15/2006 2:40:28 AM | Attr = ] (SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.2.211 | Size = 214720 bytes | Modified Date = 1/24/2006 9:06:58 PM | Attr = ] (SPBBCSvc) Symantec SPBBCSvc [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.2.0.7 | Size = 1160848 bytes | Modified Date = 4/11/2006 6:13:38 PM | Attr = ] (Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 1805552 bytes | Modified Date = 6/15/2006 2:40:24 AM | Attr = ] (Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> Viewpoint Corporation [Ver = 2, 0, 0, 54 | Size = 24652 bytes | Modified Date = 1/4/2007 5:38:08 PM | Attr = ] (WLANKEEPER) Intel(R) PROSet/Wireless SSO Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Intel\Wireless\Bin\WLKEEPER.exe -> Intel(R) Corporation [Ver = 10.5.1.5 | Size = 290816 bytes | Modified Date = 10/18/2006 6:01:34 PM | Attr = ] (XTAgent) Novell XTier Agent Services [Win32_Own | Auto | Running] -> %SystemRoot%\system32\novell\xtagent.exe -> Novell, Inc. [Ver = 1.2.3.1 | Size = 61440 bytes | Modified Date = 5/2/2006 10:17:16 AM | Attr = ] (ZFDWM) Workstation Manager [Win32_Own | Auto | Running] -> %ProgramFiles%\Novell\ZENworks\WM.EXE -> Novell, Inc. [Ver = v7.0.1 (20060510) | Size = 151104 bytes | Modified Date = 6/13/2006 8:57:32 AM | Attr = ] [Driver Services - Non-Microsoft Only] (Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] -> -> File not found (abp480n5) abp480n5 [Kernel | Disabled | Stopped] -> -> File not found (ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ac97intc.sys -> Intel Corporation [Ver = 5.10.3523 built by: WinDDK | Size = 96256 bytes | Modified Date = 8/17/2001 8:20:04 AM | Attr = ] (adpu160m) adpu160m [Kernel | Disabled | Stopped] -> -> File not found (AegisP) AEGIS Protocol (IEEE 802.1x) v3.6.0.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\AegisP.sys -> Meetinghouse Data Communications [Ver = 3.6.0.0 | Size = 21425 bytes | Modified Date = 7/30/2007 8:24:32 AM | Attr = ] (Aha154x) Aha154x [Kernel | Disabled | Stopped] -> -> File not found (aic78u2) aic78u2 [Kernel | Disabled | Stopped] -> -> File not found (aic78xx) aic78xx [Kernel | Disabled | Stopped] -> -> File not found (AliIde) AliIde [Kernel | Disabled | Stopped] -> -> File not found (amsint) amsint [Kernel | Disabled | Stopped] -> -> File not found (ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Apfiltr.sys -> Alps Electric Co., Ltd. [Ver = 5.5.1.297 | Size = 113847 bytes | Modified Date = 9/28/2005 8:57:18 PM | Attr = R ] (asc) asc [Kernel | Disabled | Stopped] -> -> File not found (asc3350p) asc3350p [Kernel | Disabled | Stopped] -> -> File not found (asc3550) asc3550 [Kernel | Disabled | Stopped] -> -> File not found (Atdisk) Atdisk [Kernel | Disabled | Stopped] -> -> File not found (atiide) ATI SATA Controller IDE mode [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\atiide.sys -> ATI Technologies Inc. [Ver = 1.00.0000.0 built by: WinDDK | Size = 3456 bytes | Modified Date = 1/24/2007 3:25:46 PM | Attr = ] (b57w2k) Broadcom NetXtreme Gigabit Ethernet [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\b57xp32.sys -> Broadcom Corporation [Ver = 9.52.0.0 built by: WinDDK | Size = 156160 bytes | Modified Date = 1/24/2007 3:35:22 PM | Attr = ] (BlankScr) HBDevice [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\blankscr.sys -> Novell Inc. [Ver = 7, 0, 0, 0 | Size = 6899 bytes | Modified Date = 5/23/2005 3:47:18 PM | Attr = ] (cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] -> -> File not found (Changer) Changer [Kernel | System | Stopped] -> -> File not found (CmdIde) CmdIde [Kernel | Disabled | Stopped] -> -> File not found (Cpqarray) Cpqarray [Kernel | Disabled | Stopped] -> -> File not found (dac960nt) dac960nt [Kernel | Disabled | Stopped] -> -> File not found (Darpan) Darpan [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\Darpan.sys -> Novell, Inc. [Ver = 7.0.0.0 | Size = 2773 bytes | Modified Date = 5/23/2005 3:11:14 PM | Attr = ] (DLABOIOM) DLABOIOM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLABOIOM.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 25628 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLACDBHM) DLACDBHM [File_System | System | Running] -> %SystemRoot%\system32\drivers\DLACDBHM.SYS -> Sonic Solutions [Ver = 5.20.01a | Size = 5628 bytes | Modified Date = 8/25/2005 12:16:52 PM | Attr = ] (DLADResN) DLADResN [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLADResN.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 2496 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLAIFS_M) DLAIFS_M [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAIFS_M.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 86524 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLAOPIOM) DLAOPIOM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAOPIOM.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 14684 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLAPoolM) DLAPoolM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAPoolM.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 6364 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLARTL_N) DLARTL_N [File_System | System | Running] -> %SystemRoot%\system32\drivers\DLARTL_N.SYS -> Sonic Solutions [Ver = 5.20.01a | Size = 22684 bytes | Modified Date = 8/25/2005 12:16:16 PM | Attr = ] (DLAUDFAM) DLAUDFAM [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAUDFAM.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 94332 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (DLAUDF_M) DLAUDF_M [File_System | Auto | Running] -> %SystemRoot%\system32\DLA\DLAUDF_M.SYS -> Sonic Solutions [Ver = 5.20.08a | Size = 87036 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (dpti2o) dpti2o [Kernel | Disabled | Stopped] -> -> File not found (DRVMCDB) DRVMCDB [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\DRVMCDB.SYS -> Sonic Solutions [Ver = 3.30.04a | Size = 89264 bytes | Modified Date = 9/12/2005 3:30:00 AM | Attr = ] (DRVNDDM) DRVNDDM [File_System | Auto | Running] -> %SystemRoot%\system32\drivers\DRVNDDM.SYS -> Sonic Solutions [Ver = 5.20.00a | Size = 40544 bytes | Modified Date = 8/12/2005 5:20:00 AM | Attr = ] (eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\eengine\eectrl.sys -> Symantec Corporation [Ver = 107.2.0.100 | Size = 389432 bytes | Modified Date = 7/30/2007 8:15:05 AM | Attr = ] (EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\el90xbc5.sys -> 3Com Corporation [Ver = 4.05.00.0000 | Size = 66591 bytes | Modified Date = 8/17/2001 8:11:06 AM | Attr = ] (EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\eengine\EraserUtilRebootDrv.sys -> Symantec Corporation [Ver = 107.2.0.100 | Size = 106808 bytes | Modified Date = 7/30/2007 8:15:05 AM | Attr = ] (GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 2:44:04 PM | Attr = ] (HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Hdaudbus.sys -> Windows (R) Server 2003 DDK provider [Ver = 5.10.01.5013 built by: WinDDK | Size = 138752 bytes | Modified Date = 1/7/2005 6:07:18 PM | Attr = ] (hpn) hpn [Kernel | Disabled | Stopped] -> -> File not found (HSF_DPV) HSF_DPV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSX_DPV.sys -> Conexant Systems, Inc. [Ver = 7.38.00 built by: WinDDK | Size = 936960 bytes | Modified Date = 1/24/2007 3:33:37 PM | Attr = ] (HSXHWAZL) HSXHWAZL [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSXHWAZL.sys -> Conexant Systems, Inc. [Ver = 7.38.00 built by: WinDDK | Size = 192512 bytes | Modified Date = 1/24/2007 3:33:37 PM | Attr = ] (i2omgmt) i2omgmt [Kernel | System | Stopped] -> -> File not found (i2omp) i2omp [Kernel | Disabled | Stopped] -> -> File not found (i81x) i81x [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\i81xnt5.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 161020 bytes | Modified Date = 8/3/2004 6:29:38 PM | Attr = ] (iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12415 bytes | Modified Date = 8/3/2004 6:29:38 PM | Attr = ] (iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV02NT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12127 bytes | Modified Date = 8/3/2004 6:29:38 PM | Attr = ] (iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV05NT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 11775 bytes | Modified Date = 8/3/2004 6:29:38 PM | Attr = ] (iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wSiINTxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12063 bytes | Modified Date = 8/3/2004 6:29:48 PM | Attr = ] (iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wVchNTxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 19455 bytes | Modified Date = 8/3/2004 6:29:50 PM | Attr = ] (iAimFP5) iAimFP5 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV07nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 11807 bytes | Modified Date = 8/3/2004 6:29:40 PM | Attr = ] (iAimFP6) iAimFP6 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV08NT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 11295 bytes | Modified Date = 8/3/2004 6:29:40 PM | Attr = ] (iAimFP7) iAimFP7 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wADV09NT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 11871 bytes | Modified Date = 8/3/2004 6:29:42 PM | Attr = ] (iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 29311 bytes | Modified Date = 8/3/2004 6:29:42 PM | Attr = ] (iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV02NT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 19551 bytes | Modified Date = 8/3/2004 6:29:44 PM | Attr = ] (iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV04nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 33599 bytes | Modified Date = 8/3/2004 6:29:44 PM | Attr = ] (iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wCh7xxNT.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 23615 bytes | Modified Date = 8/3/2004 6:29:46 PM | Attr = ] (iAimTV5) iAimTV5 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV10nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 25471 bytes | Modified Date = 8/3/2004 6:29:46 PM | Attr = ] (iAimTV6) iAimTV6 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wATV06nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 22271 bytes | Modified Date = 8/3/2004 6:29:46 PM | Attr = ] (ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.4446 | Size = 1364574 bytes | Modified Date = 1/24/2007 3:35:28 PM | Attr = ] (iastor) Intel AHCI/IASTOR Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\iaStor.sys -> Intel Corporation [Ver = 6.2.0.2002 | Size = 250368 bytes | Modified Date = 1/24/2007 3:25:47 PM | Attr = ] (ini910u) ini910u [Kernel | Disabled | Stopped] -> -> File not found (lbrtfdc) lbrtfdc [Kernel | System | Stopped] -> -> File not found (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\mdmxsdk.sys -> Conexant [Ver = 1.0.2.010 | Size = 12544 bytes | Modified Date = 1/24/2007 3:33:37 PM | Attr = ] (mraid35x) mraid35x [Kernel | Disabled | Stopped] -> -> File not found (NAVENG) NAVENG [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20070717.016\NAVENG.SYS -> Symantec Corporation [Ver = 20071.3.0.24 | Size = 81232 bytes | Modified Date = 7/30/2007 8:15:05 AM | Attr = ] (NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20070717.016\NAVEX15.SYS -> Symantec Corporation [Ver = 20071.3.0.24 | Size = 865904 bytes | Modified Date = 7/30/2007 8:15:06 AM | Attr = ] (NETw3x32) Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows XP 32 Bit [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\NETw3x32.sys -> Intel® Corporation [Ver = 10, 5, 1, 72 | Size = 1711104 bytes | Modified Date = 10/17/2006 11:55:28 AM | Attr = ] (NetwareWorkstation) Novell Client for Windows [File_System | Auto | Running] -> %SystemRoot%\system32\NetWare\nwfs.sys -> Novell, Inc. [Ver = 4.91.3.1 | Size = 506159 bytes | Modified Date = 11/9/2006 10:38:22 AM | Attr = ] (NICM) Novell InterService Communication Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\nicm.sys -> Novell, Inc. [Ver = 3.0.0.4 | Size = 38416 bytes | Modified Date = 3/3/2006 5:50:48 PM | Attr = ] (nipplpt2) Novell iCapture Lpt Redirector 2 [Kernel | System | Running] -> %SystemRoot%\system32\drivers\nipplpt.sys -> [Ver = | Size = 34671 bytes | Modified Date = 10/18/2006 3:37:56 PM | Attr = ] (NWDHCP) Novell DHCP Inform Client [File_System | Auto | Running] -> %SystemRoot%\system32\NetWare\nwdhcp.sys -> Novell, Inc. [Ver = 4.91.3.0 | Size = 18353 bytes | Modified Date = 11/22/2005 10:51:22 AM | Attr = ] (NWDNS) Novell DNS Name Space Service Provider [File_System | On_Demand | Running] -> %SystemRoot%\system32\NetWare\nwdns.sys -> Novell, Inc. [Ver = 4.91.3.1 | Size = 43280 bytes | Modified Date = 9/25/2006 12:44:52 PM | Attr = ] (NWFILTER) Novell UNC Path Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\NetWare\nwfilter.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 15891 bytes | Modified Date = 5/26/2005 6:14:00 PM | Attr = ] (NWHOST) Novell Host File Name Space Service Provider [File_System | On_Demand | Running] -> %SystemRoot%\system32\NetWare\nwhost.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 9297 bytes | Modified Date = 10/12/2005 1:12:18 PM | Attr = ] (NWSAP) Novell SAP Name Space Provider [File_System | On_Demand | Stopped] -> %SystemRoot%\system32\NetWare\nwsap.sys -> [Ver = | Size = 23232 bytes | Modified Date = 2/26/2003 2:51:18 PM | Attr = ] (NWSIPX32) Novell NetWare IPX/SPX Transport Interface [File_System | Auto | Stopped] -> %SystemRoot%\system32\NetWare\nwsipx32.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 39731 bytes | Modified Date = 10/27/2005 4:15:14 PM | Attr = ] (NWSLP) Novell SLP Name Space Service Provider [File_System | On_Demand | Running] -> %SystemRoot%\system32\NetWare\nwslp.sys -> Novell, Inc. [Ver = 4.91.0.1 | Size = 20332 bytes | Modified Date = 1/3/2005 2:51:38 PM | Attr = ] (NWSNS) Novell Simple Naming Services [File_System | On_Demand | Running] -> %SystemRoot%\system32\NetWare\nwsns.sys -> Novell, Inc. [Ver = 4.91.1.1 | Size = 6128 bytes | Modified Date = 10/12/2005 1:11:32 PM | Attr = ] (PCIDump) PCIDump [Kernel | System | Stopped] -> -> File not found (PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] -> -> File not found (PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] -> -> File not found (PDRELI) PDRELI [Kernel | On_Demand | Stopped] -> -> File not found (PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] -> -> File not found (perc2) perc2 [Kernel | Disabled | Stopped] -> -> File not found (perc2hib) perc2hib [Kernel | Disabled | Stopped] -> -> File not found (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 3.00.67a | Size = 43872 bytes | Modified Date = 7/26/2007 4:00:00 AM | Attr = ] (ql1080) ql1080 [Kernel | Disabled | Stopped] -> -> File not found (Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] -> -> File not found (ql12160) ql12160 [Kernel | Disabled | Stopped] -> -> File not found (ql1240) ql1240 [Kernel | Disabled | Stopped] -> -> File not found (ql1280) ql1280 [Kernel | Disabled | Stopped] -> -> File not found (RESMGR) Novell NetWare Resource Manager [Kernel | Auto | Running] -> %SystemRoot%\system32\NetWare\resmgr.sys -> Novell, Inc. [Ver = 4.90 | Size = 27249 bytes | Modified Date = 6/1/2004 6:19:34 PM | Attr = ] (s24trans) WLAN Transport [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\s24trans.sys -> Intel Corporation [Ver = 10.5.1.0 | Size = 12544 bytes | Modified Date = 10/19/2006 9:29:22 AM | Attr = ] (SAVRT) SAVRT [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\savrt.sys -> Symantec Corporation [Ver = 9.7.1.4 | Size = 337592 bytes | Modified Date = 12/19/2005 9:41:56 PM | Attr = ] (SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\Savrtpel.sys -> Symantec Corporation [Ver = 9.7.1.4 | Size = 54968 bytes | Modified Date = 12/19/2005 9:41:58 PM | Attr = ] (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> [Ver = | Size = 27440 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] (Simbad) Simbad [Kernel | Disabled | Stopped] -> -> File not found (Sparrow) Sparrow [Kernel | Disabled | Stopped] -> -> File not found (SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCDrv.sys -> Symantec Corporation [Ver = 2.2.0.7 | Size = 389776 bytes | Modified Date = 4/11/2006 6:13:34 PM | Attr = ] (SRVLOC) Novell Service Location [File_System | Auto | Running] -> %SystemRoot%\system32\NetWare\srvloc.sys -> Novell, Inc. [Ver = 4.91.3.0 | Size = 160209 bytes | Modified Date = 9/25/2006 9:54:54 AM | Attr = ] (STHDA) SigmaTel High Definition Audio CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\sthda.sys -> SigmaTel, Inc. [Ver = 5.10.4995.1 nd446 cp1 | Size = 1156648 bytes | Modified Date = 3/24/2006 5:34:30 PM | Attr = ] (symc810) symc810 [Kernel | Disabled | Stopped] -> -> File not found (symc8xx) symc8xx [Kernel | Disabled | Stopped] -> -> File not found (SymEvent) SymEvent [Kernel | On_Demand | Running] -> %ProgramFiles%\Symantec\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.0.3.1 | Size = 107696 bytes | Modified Date = 5/5/2006 5:19:50 PM | Attr = ] (SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symredrv.sys -> Symantec Corporation [Ver = 6.0.2.211 | Size = 24768 bytes | Modified Date = 1/24/2006 9:06:32 PM | Attr = ] (SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> Symantec Corporation [Ver = 6.0.2.211 | Size = 195776 bytes | Modified Date = 1/24/2006 9:06:36 PM | Attr = ] (sym_hi) sym_hi [Kernel | Disabled | Stopped] -> -> File not found (sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> -> File not found (TosIde) TosIde [Kernel | Disabled | Stopped] -> -> File not found (ultra) ultra [Kernel | Disabled | Stopped] -> -> File not found (usbbus) LGE CDMA Composite USB Device [Kernel | On_Demand | Stopped] -> -> File not found (UsbDiag) LGE CDMA USB Serial Port [Kernel | On_Demand | Stopped] -> -> File not found (USBModem) LGE CDMA USB Modem [Kernel | On_Demand | Stopped] -> -> File not found (ViaIde) ViaIde [Kernel | Disabled | Stopped] -> -> File not found (w39n51) Intel(R) PRO/Wireless 3945ABG Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\w39n51.sys -> Intel® Corporation [Ver = 10010-15 Driver | Size = 1428480 bytes | Modified Date = 1/24/2007 3:33:11 PM | Attr = ] (wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 1/10/2003 5:13:04 PM | Attr = R ] (WDICA) WDICA [Kernel | On_Demand | Stopped] -> -> File not found (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSX_CNXT.sys -> Conexant Systems, Inc. [Ver = 7.38.00 built by: WinDDK | Size = 669696 bytes | Modified Date = 1/24/2007 3:33:36 PM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> BGInfo -> %SystemRoot%\BGInfo.exe c:\Windows\ACSD5.bgi -> File not found ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 104.0.8.3 | Size = 53408 bytes | Modified Date = 3/24/2006 6:14:48 PM | Attr = ] DLA -> %SystemRoot%\system32\DLA\DLACTRLW.EXE -> Sonic Solutions [Ver = 5.20.08a | Size = 122940 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] DVDLauncher -> %ProgramFiles%\CyberLink\PowerDVD\DVDLauncher.exe -> CyberLink Corp. [Ver = 3.00.0000 | Size = 49152 bytes | Modified Date = 12/9/2005 8:29:52 PM | Attr = ] HelpCenter4.1 -> %ProgramFiles%\Bellsouth\HelpCenter40b\bin\sprtcmd.exe -> SupportSoft, Inc. [Ver = 6,9,2018,0 | Size = 198184 bytes | Modified Date = 6/28/2007 7:02:08 PM | Attr = ] HostManager -> %CommonProgramFiles%\aol\1185832750\ee\aolsoftware.exe -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 1:16:08 PM | Attr = ] igfxhkcmd -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 77824 bytes | Modified Date = 1/24/2007 3:35:28 PM | Attr = ] igfxpers -> %SystemRoot%\system32\igfxpers.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 118784 bytes | Modified Date = 1/24/2007 3:35:29 PM | Attr = ] igfxtray -> %SystemRoot%\system32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.4446 | Size = 98304 bytes | Modified Date = 1/24/2007 3:35:30 PM | Attr = ] IntelWireless -> %ProgramFiles%\Intel\Wireless\Bin\iFrmewrk.exe -> Intel Corporation [Ver = 10.5.1.18 | Size = 696320 bytes | Modified Date = 10/18/2006 5:58:16 PM | Attr = ] IntelZeroConfig -> %ProgramFiles%\Intel\Wireless\Bin\ZCfgSvc.exe -> Intel Corporation [Ver = 10.5.1.9 | Size = 802816 bytes | Modified Date = 10/18/2006 6:04:28 PM | Attr = ] iPrint Event Monitor -> %SystemRoot%\system32\iprntlgn.exe -> Novell, Inc. [Ver = 4,2,6,0 | Size = 45056 bytes | Modified Date = 10/18/2006 3:14:28 PM | Attr = ] iPrint Tray -> %SystemRoot%\system32\iprntctl.exe -> Novell, Inc. [Ver = 4,2,6,0 | Size = 40960 bytes | Modified Date = 10/18/2006 3:14:18 PM | Attr = ] ISUSPM Startup -> %CommonProgramFiles%\InstallShield\UpdateService\ISUSPM.exe -> InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 221184 bytes | Modified Date = 7/27/2004 4:50:42 PM | Attr = ] ISUSScheduler -> %CommonProgramFiles%\InstallShield\UpdateService\issch.exe -> InstallShield Software Corporation [Ver = 3, 10, 100, 1155 | Size = 81920 bytes | Modified Date = 7/27/2004 4:50:18 PM | Attr = ] iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.3.2.6 | Size = 271672 bytes | Modified Date = 7/31/2007 6:44:42 PM | Attr = ] NapsterShell -> %ProgramFiles%\Napster\napster.exe -> Napster [Ver = 4.0.4.7 | Size = 323216 bytes | Modified Date = 10/29/2007 6:14:04 PM | Attr = ] NDPS -> %SystemRoot%\system32\dpmw32.exe -> Novell, Inc. [Ver = v3.0.1 | Size = 32859 bytes | Modified Date = 5/17/2004 2:27:28 PM | Attr = ] NWTRAY -> %SystemRoot%\system32\nwtray.exe -> Novell, Inc. [Ver = v4.90 | Size = 28672 bytes | Modified Date = 3/12/2002 10:37:28 AM | Attr = ] QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.2 | Size = 286720 bytes | Modified Date = 6/29/2007 6:24:52 AM | Attr = ] SigmatelSysTrayApp -> %SystemRoot%\stsystra.exe -> SigmaTel, Inc. [Ver = 1.0.4995.1 nd446 cp1 | Size = 282624 bytes | Modified Date = 3/24/2006 5:30:44 PM | Attr = ] TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.4081 | Size = 185632 bytes | Modified Date = 9/9/2007 4:02:32 PM | Attr = ] vptray -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 124656 bytes | Modified Date = 6/15/2006 2:40:34 AM | Attr = ] ZENRC Tray Icon -> %SystemRoot%\system32\zentray.exe -> Novell, Inc. [Ver = 7, 0, 0, 0 | Size = 40960 bytes | Modified Date = 5/18/2005 6:04:00 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AOL Fast Start -> %ProgramFiles%\AOL 9.1\aol.exe -> AOL, LLC. [Ver = 9.05.001 | Size = 50528 bytes | Modified Date = 10/27/2007 1:44:58 PM | Attr = ] SpybotSD TeaTimer -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 0, 9 | Size = 1460312 bytes | Modified Date = 6/18/2007 3:58:02 PM | Attr = ] updateMgr -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe -> Adobe Systems Incorporated [Ver = 3.1.0.10 | Size = 313472 bytes | Modified Date = 3/30/2006 4:45:08 PM | Attr = R ] < Run [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AOL Fast Start -> %ProgramFiles%\AOL 9.1\aol.exe -> AOL, LLC. [Ver = 9.05.001 | Size = 50528 bytes | Modified Date = 10/27/2007 1:44:58 PM | Attr = ] SpybotSD TeaTimer -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 0, 9 | Size = 1460312 bytes | Modified Date = 6/18/2007 3:58:02 PM | Attr = ] updateMgr -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe -> Adobe Systems Incorporated [Ver = 3.1.0.10 | Size = 313472 bytes | Modified Date = 3/30/2006 4:45:08 PM | Attr = R ] < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Modified Date = 9/23/2005 10:05:26 PM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\Application Window.lnk -> %ProgramFiles%\Novell\ZENworks\NalWin.exe -> Novell, Inc [Ver = 7.0.1.0 | Size = 365568 bytes | Modified Date = 6/13/2006 8:51:50 AM | Attr = ] %AllUsersProfile%\Start Menu\Programs\Startup\NkbMonitor.exe.lnk -> %ProgramFiles%\Nikon\PictureProject\NkbMonitor.exe -> Nikon Corporation [Ver = 1, 7, 5, 3000 | Size = 118784 bytes | Modified Date = 11/29/2006 5:48:22 PM | Attr = ] < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < LuanneRowland Startup Folder > -> C:\Documents and Settings\LuanneRowland\Start Menu\Programs\Startup -> %UserProfile%\Start Menu\Programs\Startup\MEMonitor.lnk -> %ProgramFiles%\Verizon Wireless\V CAST Music Manager\MEMonitor.exe -> Smith Micro Software, Inc. [Ver = 1.1.0 | Size = 947544 bytes | Modified Date = 7/4/2007 4:25:16 AM | Attr = ] < tech Startup Folder > -> C:\Documents and Settings\tech\Start Menu\Programs\Startup -> < ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> {763370C4-268E-4308-A60C-D8DA0342BE32} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Novell\ZENworks\NalShell.dll [] -> Novell, Inc [Ver = 7.0.1.0 | Size = 446464 bytes | Modified Date = 6/28/2006 3:00:56 PM | Attr = ] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *System* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\System -> ziswin.exe -> %SystemRoot%\system32\ZISWIN.EXE -> Novell [Ver = 7, 0, 1, 0 | Size = 192512 bytes | Modified Date = 6/27/2006 2:30:22 PM | Attr = ] *MultiFile Done* -> -> *GinaDLL* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\GinaDLL -> NWGina.DLL -> %SystemRoot%\system32\nwgina.dll -> Novell, Inc. [Ver = v6.5.1 (20061106) | Size = 372817 bytes | Modified Date = 10/6/2006 10:33:50 AM | Attr = ] *MultiFile Done* -> -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> igfxcui -> %SystemRoot%\system32\igfxdev.dll -> Intel Corporation [Ver = 3.0.0.4446 | Size = 139264 bytes | Modified Date = 1/24/2007 3:35:28 PM | Attr = ] NavLogon -> %SystemRoot%\system32\NavLogon.dll -> Symantec Corporation [Ver = 10.1.4.4000 | Size = 43760 bytes | Modified Date = 6/15/2006 2:40:42 AM | Attr = ] NetIdentity Notification -> %SystemRoot%\system32\novell\xtnotify.dll -> Novell, Inc. [Ver = 1.2.3 | Size = 24576 bytes | Modified Date = 5/2/2006 10:17:20 AM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ClassicShell -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoInternetIcon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSharedDocuments -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoWelcomeScreen -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D} -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\CompatibleRUPSecurity -> 1 -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoChangingWallpaper -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoComponents -> 2 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoAddingComponents -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoDeletingComponents -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoEditingComponents -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoHTMLWallPaper -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoManageMyComputerVerb -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ForceClassicControlPanel -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\Locked -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoWelcomeScreen -> 1 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ForceActiveDesktopOn -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop -> 2 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ClassicShell -> 2 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\Wallpaper -> 2‘| -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoChangingWallpaper -> 0 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoComponents -> 2 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoAddingComponents -> 0 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoDeletingComponents -> 0 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoEditingComponents -> 0 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\\NoHTMLWallPaper -> 1 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoManageMyComputerVerb -> 1 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ForceClassicControlPanel -> 1 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\Locked -> 1 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoWelcomeScreen -> 1 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ForceActiveDesktopOn -> 0 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop -> 2 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\ClassicShell -> 2 -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\Wallpaper -> 2‘| -> < HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 10.10.50.1 zenwsimport -> -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.aol.com/ -> HKEY_CURRENT_USER\: URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOLTBSearch Class] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] HKEY_CURRENT_USER\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\: Main\\Start Page -> http://www.aol.com/ -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\: URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOLTBSearch Class] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\: ProxyEnable -> 0 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4263 domain(s) found. -> 34 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6365 domain(s) found. -> objects_aol.com [*] -> Out of zone range - ( 5 ) -> 41 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4262 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4262 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4262 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4262 domain(s) found. -> 33 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 6365 domain(s) found. -> objects_aol.com [*] -> Out of zone range - ( 5 ) -> 41 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 7.0.9.2006121800 | Size = 59032 bytes | Modified Date = 12/18/2006 4:16:42 AM | Attr = ] {3049C3E9-B461-4BC5-8870-4C09146192CA} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Real\RealPlayer\rpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> RealPlayer [Ver = 1.0.0.334 | Size = 296312 bytes | Modified Date = 9/9/2007 4:03:05 PM | Attr = ] {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\blstoolbar\blstoolbar.dll [BellSouth Toolbar] -> [Ver = 4.0.2.144 | Size = 1369088 bytes | Modified Date = 2/16/2006 4:57:20 PM | Attr = ] {53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 5, 0, 6 | Size = 1098840 bytes | Modified Date = 6/18/2007 3:57:46 PM | Attr = ] {5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\DLA\DLASHX_W.DLL [DriveLetterAccess] -> Sonic Solutions [Ver = 5.20.08a | Size = 110652 bytes | Modified Date = 9/8/2005 5:20:00 AM | Attr = ] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_10\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 5.0.100.3 | Size = 440056 bytes | Modified Date = 11/9/2006 4:21:52 PM | Attr = ] {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar Launcher] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {327C2873-E90D-4c37-AA9D-10AC9BABA46C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Canon\Easy-WebPrint\Toolband.dll [Easy-WebPrint] -> [Ver = 2, 5, 0, 25 | Size = 405504 bytes | Modified Date = 4/16/2004 7:43:12 PM | Attr = ] {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\blstoolbar\blstoolbar.dll [BellSouth Toolbar] -> [Ver = 4.0.2.144 | Size = 1369088 bytes | Modified Date = 2/16/2006 4:57:20 PM | Attr = ] {DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\blstoolbar\blstoolbar.dll [BellSouth Toolbar] -> [Ver = 4.0.2.144 | Size = 1369088 bytes | Modified Date = 2/16/2006 4:57:20 PM | Attr = ] WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\blstoolbar\blstoolbar.dll [BellSouth Toolbar] -> [Ver = 4.0.2.144 | Size = 1369088 bytes | Modified Date = 2/16/2006 4:57:20 PM | Attr = ] WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.100.3 | Size = 75528 bytes | Modified Date = 11/9/2006 4:21:53 PM | Attr = ] {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.5.0_10\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.100.3 | Size = 440056 bytes | Modified Date = 11/9/2006 4:21:52 PM | Attr = ] {3369AF0D-62E9-4bda-8103-B4C75499B578}:{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] {C1994287-422F-47aa-8E5E-6323E210A125}:{4B5F7606-8666-4D5A-9780-DB92A9D8812B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Novell\ZENworks\AxNalServer.dll [Novell delivered applications] -> Novell, Inc [Ver = 7.0.1.0 | Size = 516096 bytes | Modified Date = 6/13/2006 8:53:36 AM | Attr = ] {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 6 | Size = 1098840 bytes | Modified Date = 6/18/2007 3:57:46 PM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.100.3 | Size = 75528 bytes | Modified Date = 11/9/2006 4:21:53 PM | Attr = ] CmdMapping\\{3369AF0D-62E9-4bda-8103-B4C75499B578} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] CmdMapping\\{C1994287-422F-47aa-8E5E-6323E210A125} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Novell\ZENworks\AxNalServer.dll [Novell delivered applications] -> Novell, Inc [Ver = 7.0.1.0 | Size = 516096 bytes | Modified Date = 6/13/2006 8:53:36 AM | Attr = ] CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 6 | Size = 1098840 bytes | Modified Date = 6/18/2007 3:57:46 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &AOL Toolbar Search -> %ProgramFiles%\aol\aol toolbar 5.0\resources\en-US\local\search.htm -> File not found Easy-WebPrint Add To Print List -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint High Speed Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint Preview -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\ -> Add to AMV Converter... -> %ProgramFiles%\MP3 Player Utilities 4.05\AMVConverter\grab.htm -> File not found Add to Media Manager... -> %ProgramFiles%\MP3 Player Utilities 4.05\MediaManager\grab.htm -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\ -> Add to AMV Converter... -> %ProgramFiles%\MP3 Player Utilities 4.05\AMVConverter\grab.htm -> File not found Add to Media Manager... -> %ProgramFiles%\MP3 Player Utilities 4.05\MediaManager\grab.htm -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.5.0_10\bin\NPJPI150_10.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 5.0.100.3 | Size = 75528 bytes | Modified Date = 11/9/2006 4:21:53 PM | Attr = ] CmdMapping\\{3369AF0D-62E9-4bda-8103-B4C75499B578} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> AOL LLC [Ver = 5.0.17.1 | Size = 1025584 bytes | Modified Date = 3/23/2007 4:35:30 PM | Attr = ] CmdMapping\\{C1994287-422F-47aa-8E5E-6323E210A125} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Novell\ZENworks\AxNalServer.dll [Novell delivered applications] -> Novell, Inc [Ver = 7.0.1.0 | Size = 516096 bytes | Modified Date = 6/13/2006 8:53:36 AM | Attr = ] CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 6 | Size = 1098840 bytes | Modified Date = 6/18/2007 3:57:46 PM | Attr = ] < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\] > -> HKEY_USERS\S-1-5-21-247937475-255354955-1307212239-1020\Software\Microsoft\Internet Explorer\MenuExt\ -> &AOL Toolbar Search -> %ProgramFiles%\aol\aol toolbar 5.0\resources\en-US\local\search.htm -> File not found Easy-WebPrint Add To Print List -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint High Speed Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint Preview -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] Easy-WebPrint Print -> %ProgramFiles%\Canon\Easy-WebPrint\Resource.dll -> [Ver = 2, 5, 0, 25 | Size = 200704 bytes | Modified Date = 4/16/2004 7:42:08 PM | Attr = ] < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> SV1 -> -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {918DD1A2-4CBE-4064-A3AB-3011FA930F51} -> (Intel(R) PRO/Wireless 3945ABG Network Connection) -> {E1C6A872-A0AA-4055-A34D-E8DB972A3902} -> (Broadcom NetXtreme 57xx Gigabit Controller) -> < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> NameSpace_Catalog5\Catalog_Entries\000000000004 [Novell Directory Services Name Provider] -> %SystemRoot%\system32\NetWare\nwws2nds.dll -> Novell, Inc. [Ver = 4.91 | Size = 36947 bytes | Modified Date = 1/30/2006 4:40:26 PM | Attr = ] NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell IPX/SPX SAP Name Provider] -> %SystemRoot%\system32\NetWare\nwws2sap.dll -> Novell, Inc. [Ver = 4.91 | Size = 32851 bytes | Modified Date = 10/27/2005 4:24:08 PM | Attr = ] NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell SLP Provider] -> %SystemRoot%\system32\NetWare\nwws2slp.dll -> Novell, Inc. [Ver = 4.91 | Size = 49235 bytes | Modified Date = 1/30/2006 4:40:28 PM | Attr = ] < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.] -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab[CKAVWebScan Object] -> {17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185799394241[WUWebControl Class] -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}[HKEY_LOCAL_MACHINE] -> http://office.microsoft.com/officeupdate/content/opuc4.cab[Office Update Installation Engine] -> {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab[Java Plug-in 1.5.0_05] -> {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab[Java Plug-in 1.5.0_09] -> {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab[Java Plug-in 1.5.0_10] -> {D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> (binary data) -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\\EnableFirewall -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] nwv1_0 -> %SystemRoot%\system32\nwv1_0.dll -> Novell, Inc. [Ver = v4.71 (000217) | Size = 8480 bytes | Modified Date = 2/17/2000 6:54:28 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 1:49:30 PM | Attr = ] msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 10:21:15 AM | Attr = ] wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49152 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 944 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\\MachineSid -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\Auth132 -> C:\WINDOWS\system32\iissuba.dll [IISSUBA] -> Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 9216 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 671 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3753:TCP -> 3753:TCP:*:Enabled:SETS -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\3751:TCP -> 3751:TCP:*:Enabled:SETS -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\dpmw32.exe -> C:\WINDOWS\system32\dpmw32.exe [C:\WINDOWS\system32\dpmw32.exe:*:Enabled:NDPS RPM & Notification Listener] -> Novell, Inc. [Ver = v3.0.1 | Size = 32859 bytes | Modified Date = 5/17/2004 2:27:28 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\acs\AOLDial.exe -> C:\Program Files\Common Files\aol\acs\AOLDial.exe [C:\Program Files\Common Files\aol\acs\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer] -> AOL LLC [Ver = 4.6.1.2 | Size = 71216 bytes | Modified Date = 10/23/2006 8:50:37 AM | Attr = R ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\acs\AOLacsd.exe -> C:\Program Files\Common Files\aol\acs\AOLacsd.exe [C:\Program Files\Common Files\aol\acs\AOLacsd.exe:*:Enabled:AOL Connectivity Service] -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 8:50:35 AM | Attr = R ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\1185832750\ee\aolsoftware.exe -> C:\Program Files\Common Files\aol\1185832750\ee\aolsoftware.exe [C:\Program Files\Common Files\aol\1185832750\ee\aolsoftware.exe:*:Enabled:AOL Shared Components] -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 1:16:08 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AOL 9.0\waol.exe -> C:\Program Files\AOL 9.0\waol.exe [C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL] -> AOL, LLC. [Ver = 9.05.001 | Size = 39472 bytes | Modified Date = 4/18/2007 2:49:07 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe -> C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe [C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed] -> AOL LLC [Ver = 3, 0, 0, 4 | Size = 63120 bytes | Modified Date = 4/2/2007 8:33:32 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\Loader\aolload.exe -> C:\Program Files\Common Files\aol\Loader\aolload.exe [C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Loader] -> AOL LLC [Ver = 9.3.2.2 | Size = 10800 bytes | Modified Date = 11/3/2006 3:17:27 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\aol\System Information\sinf.exe -> C:\Program Files\Common Files\aol\System Information\sinf.exe [C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL System Information] -> AOL LLC [Ver = 2, 4, 6, 2 | Size = 206176 bytes | Modified Date = 9/17/2007 9:02:47 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\iTunes\iTunes.exe -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> Apple Inc. [Ver = 7.3.2.6 | Size = 15333688 bytes | Modified Date = 7/31/2007 6:44:34 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AIM6\aim6.exe -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> AOL LLC [Ver = 1.4.9.1 | Size = 50528 bytes | Modified Date = 10/4/2007 11:20:54 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AOL 9.1\waol.exe -> C:\Program Files\AOL 9.1\waol.exe [C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL] -> AOL, LLC. [Ver = 9.05.001 | Size = 39264 bytes | Modified Date = 10/27/2007 1:45:07 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Maxis\SimCity 3000 Unlimited\Apps\Updater\UPDATER.EXE -> C:\Program Files\Maxis\SimCity 3000 Unlimited\Apps\Updater\UPDATER.EXE [C:\Program Files\Maxis\SimCity 3000 Unlimited\Apps\Updater\UPDATER.EXE:*:Disabled:SC3UpdaterMFC] -> [Ver = 1, 0, 0, 1 | Size = 888832 bytes | Modified Date = 4/15/2000 2:47:10 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\3753:TCP -> 3753:TCP:*:Enabled:SETS -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\3751:TCP -> 3751:TCP:*:Enabled:SETS -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Description -> Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DependOnService -> RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 12:39:49 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DisplayName -> Remote Registry -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ImagePath -> C:\WINDOWS\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k LocalService] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ObjectName -> NT AUTHORITY\LocalService -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Group -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\FailureActions -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\\ServiceDll -> C:\WINDOWS\system32\regsvc.dll [%SystemRoot%\system32\regsvc.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 59904 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\\Security -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\0 -> Root\LEGACY_REMOTEREGISTRY\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Type -> 16 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Start -> 4 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ImagePath -> C:\WINDOWS\system32\tlntsvr.exe [C:\WINDOWS\system32\tlntsvr.exe] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 73216 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DisplayName -> Telnet -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnService -> RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 12:39:49 AM | Attr = ] TCPIP -> -> File not found NTLMSSP -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Description -> Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\\Security -> (binary data) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\EnableAutodial -> 0 -> [Files/Folders - Created Within 90 days] 8 -> %SystemDrive%\8 -> [Ver = | Size = 87 bytes | Created Date = 3/3/2008 11:43:41 PM | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Created Date = 2/5/2008 10:35:57 PM | Attr = HS] Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 3/11/2008 4:05:45 PM | Attr = ] s -> %SystemDrive%\s -> [Ver = | Size = 87 bytes | Created Date = 3/4/2008 11:31:03 PM | Attr = ] vvvÿ{{{Ì{{{Ì___s___s -> %SystemDrive%\vvvÿ{{{Ì{{{Ì___s___s -> [Ver = | Size = 91 bytes | Created Date = 12/19/2007 3:23:26 PM | Attr = ] ~MSSETUP.T -> %SystemDrive%\~MSSETUP.T -> [Folder | Created Date = 2/17/2008 2:01:42 PM | Attr = ] ° -> %SystemDrive%\° -> [Ver = | Size = 91 bytes | Created Date = 12/29/2007 6:42:48 PM | Attr = ] history.aaw -> %SystemRoot%\System32\history.aaw -> [Ver = | Size = 1088 bytes | Created Date = 2/16/2008 1:40:21 PM | Attr = ] Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Created Date = 3/11/2008 7:30:01 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> NtmsData -> %SystemRoot%\System32\NtmsData -> [Folder | Created Date = 1/18/2008 1:54:07 PM | Attr = ] settings.aaw -> %SystemRoot%\System32\settings.aaw -> [Ver = | Size = 2608 bytes | Created Date = 2/16/2008 1:40:21 PM | Attr = ] aolshare -> %SystemRoot%\aolshare -> [Folder | Created Date = 12/19/2007 7:41:57 AM | Attr = ] 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 3/11/2008 4:06:00 PM | Attr = ] eReg.dat -> %SystemRoot%\eReg.dat -> [Ver = | Size = 599 bytes | Created Date = 2/17/2008 2:07:49 PM | Attr = ] LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 3/11/2008 7:30:00 PM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Created Date = 3/11/2008 7:30:02 PM | Attr = ] TEMP -> %AllUsersProfile%\Application Data\TEMP -> [Folder | Created Date = 3/3/2008 10:59:03 PM | Attr = ] @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:5C321E34 MicroVision Applications -> %UserProfile%\Local Settings\Application Data\MicroVision Applications -> [Folder | Created Date = 1/18/2008 2:05:45 PM | Attr = ] BeneteauCushions.jpg -> %UserProfile%\My Documents\BeneteauCushions.jpg -> [Ver = | Size = 39274 bytes | Created Date = 2/5/2008 5:24:50 PM | Attr = ] FACILITY_MAP_OVERVIEW.pdf -> %UserProfile%\My Documents\FACILITY_MAP_OVERVIEW.pdf -> [Ver = | Size = 4616620 bytes | Created Date = 1/27/2008 3:20:12 PM | Attr = ] February 6 to Barbados.doc -> %UserProfile%\My Documents\February 6 to Barbados.doc -> [Ver = | Size = 24064 bytes | Created Date = 2/6/2008 6:44:11 PM | Attr = ] JustinFederal2007.pdf -> %UserProfile%\My Documents\JustinFederal2007.pdf -> [Ver = | Size = 53578 bytes | Created Date = 2/2/2008 11:50:56 AM | Attr = ] Justinstate2007.pdf -> %UserProfile%\My Documents\Justinstate2007.pdf -> [Ver = | Size = 70974 bytes | Created Date = 2/2/2008 11:51:42 AM | Attr = ] minicraft2006catalog.pdf -> %UserProfile%\My Documents\minicraft2006catalog.pdf -> [Ver = | Size = 21598365 bytes | Created Date = 2/3/2008 9:48:00 AM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\minicraft2006catalog.pdf:Zone.Identifier Newman Scholarship 100wds.doc -> %UserProfile%\My Documents\Newman Scholarship 100wds.doc -> [Ver = | Size = 24576 bytes | Created Date = 3/5/2008 4:56:13 PM | Attr = ] physics bake sale.doc -> %UserProfile%\My Documents\physics bake sale.doc -> [Ver = | Size = 24064 bytes | Created Date = 12/17/2007 11:52:21 PM | Attr = ] Resume UPGRADED.doc -> %UserProfile%\My Documents\Resume UPGRADED.doc -> [Ver = | Size = 38400 bytes | Created Date = 2/1/2008 7:34:00 PM | Attr = ] SC State Fair.doc -> %UserProfile%\My Documents\SC State Fair.doc -> [Ver = | Size = 26624 bytes | Created Date = 3/5/2008 5:10:25 PM | Attr = ] SpecialDTSMeeting.pdf -> %UserProfile%\My Documents\SpecialDTSMeeting.pdf -> [Ver = | Size = 51131 bytes | Created Date = 1/12/2008 11:16:17 AM | Attr = ] Thorne Schloarship 1000 words.doc -> %UserProfile%\My Documents\Thorne Schloarship 1000 words.doc -> [Ver = | Size = 27648 bytes | Created Date = 3/5/2008 5:07:02 PM | Attr = ] USD Wire, Rowland F.WD 2800.doc -> %UserProfile%\My Documents\USD Wire, Rowland F.WD 2800.doc -> [Ver = | Size = 30720 bytes | Created Date = 12/20/2007 9:52:30 AM | Attr = ] 165.JPG -> %UserProfile%\Desktop\165.JPG -> [Ver = | Size = 1084403 bytes | Created Date = 2/14/2008 1:02:55 PM | Attr = ] Captain-Chris-Long-Point-Ligh.jpg -> %UserProfile%\Desktop\Captain-Chris-Long-Point-Ligh.jpg -> [Ver = | Size = 104529 bytes | Created Date = 2/16/2008 11:27:01 AM | Attr = ] dss.exe -> %UserProfile%\Desktop\dss.exe -> [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Created Date = 3/11/2008 8:18:13 PM | Attr = ] FTF1201967698294.pdf -> %UserProfile%\Desktop\FTF1201967698294.pdf -> [Ver = | Size = 112690 bytes | Created Date = 2/2/2008 11:57:10 AM | Attr = ] Pi Day Flyer.doc -> %UserProfile%\Desktop\Pi Day Flyer.doc -> [Ver = | Size = 31232 bytes | Created Date = 3/11/2008 10:09:53 PM | Attr = ] pi.doc -> %UserProfile%\Desktop\pi.doc -> [Ver = | Size = 24576 bytes | Created Date = 2/25/2008 7:49:03 PM | Attr = ] Resume most recent.doc -> %UserProfile%\Desktop\Resume most recent.doc -> [Ver = | Size = 34304 bytes | Created Date = 2/24/2008 11:17:10 PM | Attr = ] Scholarships January 14 2008.pdf -> %UserProfile%\Desktop\Scholarships January 14 2008.pdf -> [Ver = | Size = 59540 bytes | Created Date = 1/18/2008 1:41:24 PM | Attr = ] Shortcut to System Tools.lnk -> %UserProfile%\Desktop\Shortcut to System Tools.lnk -> [Ver = | Size = 956 bytes | Created Date = 1/18/2008 1:56:23 PM | Attr = ] SSF1201967739458.pdf -> %UserProfile%\Desktop\SSF1201967739458.pdf -> [Ver = | Size = 20820 bytes | Created Date = 2/2/2008 11:57:50 AM | Attr = ] STF1201967724356.pdf -> %UserProfile%\Desktop\STF1201967724356.pdf -> [Ver = | Size = 130191 bytes | Created Date = 2/2/2008 11:57:34 AM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Created Date = 3/12/2008 10:19:28 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 481244 bytes | Created Date = 3/12/2008 10:18:52 PM | Attr = ] Blizzard Entertainment -> %CommonProgramFiles%\Blizzard Entertainment -> [Folder | Created Date = 12/26/2007 7:19:55 PM | Attr = ] [Files/Folders - Modified Within 90 days] 8 -> %SystemDrive%\8 -> [Ver = | Size = 87 bytes | Modified Date = 3/3/2008 11:43:41 PM | Attr = ] a -> %SystemDrive%\a -> [Ver = | Size = 271 bytes | Modified Date = 2/20/2008 11:57:18 AM | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 3/11/2008 7:35:53 PM | Attr = HS] Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 3/11/2008 4:05:45 PM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1063378944 bytes | Modified Date = 3/9/2008 1:10:25 PM | Attr = HS] NALCache -> %SystemDrive%\NALCache -> [Folder | Modified Date = 3/12/2008 1:11:14 PM | Attr = H ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 2/17/2008 2:01:17 PM | Attr = R ] s -> %SystemDrive%\s -> [Ver = | Size = 87 bytes | Modified Date = 3/4/2008 11:31:03 PM | Attr = ] vvvÿ{{{Ì{{{Ì___s___s -> %SystemDrive%\vvvÿ{{{Ì{{{Ì___s___s -> [Ver = | Size = 91 bytes | Modified Date = 12/19/2007 3:23:26 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 3/12/2008 10:19:29 PM | Attr = ] ~MSSETUP.T -> %SystemDrive%\~MSSETUP.T -> [Folder | Modified Date = 2/17/2008 2:01:42 PM | Attr = ] ° -> %SystemDrive%\° -> [Ver = | Size = 91 bytes | Modified Date = 12/29/2007 6:42:48 PM | Attr = ] CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 3/11/2008 4:06:36 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 279744 bytes | Modified Date = 2/17/2008 8:30:18 PM | Attr = ] history.aaw -> %SystemRoot%\System32\history.aaw -> [Ver = | Size = 1088 bytes | Modified Date = 2/16/2008 1:40:21 PM | Attr = ] Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Modified Date = 3/11/2008 7:30:01 PM | Attr = ] lsdelete.exe -> %SystemRoot%\System32\lsdelete.exe -> [Ver = | Size = 12632 bytes | Modified Date = 1/14/2008 11:45:55 PM | Attr = ] NtmsData -> %SystemRoot%\System32\NtmsData -> [Folder | Modified Date = 1/18/2008 1:54:08 PM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 59842 bytes | Modified Date = 3/9/2008 1:14:54 PM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 395768 bytes | Modified Date = 3/9/2008 1:14:54 PM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 462168 bytes | Modified Date = 3/9/2008 1:14:54 PM | Attr = ] settings.aaw -> %SystemRoot%\System32\settings.aaw -> [Ver = | Size = 2608 bytes | Modified Date = 2/16/2008 1:40:21 PM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 3/9/2008 1:10:30 PM | Attr = ] aolshare -> %SystemRoot%\aolshare -> [Folder | Modified Date = 12/19/2007 7:41:57 AM | Attr = ] 4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 3/9/2008 1:10:28 PM | Attr = S] CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 3/1/2008 10:42:56 AM | Attr = HS] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 3/11/2008 7:30:02 PM | Attr = S] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Modified Date = 3/11/2008 4:06:00 PM | Attr = ] eReg.dat -> %SystemRoot%\eReg.dat -> [Ver = | Size = 599 bytes | Modified Date = 2/17/2008 2:07:49 PM | Attr = ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 2/17/2008 2:07:44 PM | Attr = R S] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 3/11/2008 7:30:01 PM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 3/11/2008 7:35:54 PM | Attr = HS] LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 3/11/2008 7:30:00 PM | Attr = ] MEDB.mdb -> %SystemRoot%\MEDB.mdb -> [Ver = | Size = 1609728 bytes | Modified Date = 1/17/2008 7:26:14 PM | Attr = ] NetWare.INI -> %SystemRoot%\NetWare.INI -> [Ver = | Size = 11 bytes | Modified Date = 2/17/2008 2:01:34 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 3/12/2008 10:19:46 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 3/9/2008 2:19:01 PM | Attr = H ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 3/11/2008 7:30:01 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 1/18/2008 1:57:33 PM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 3/10/2008 10:01:01 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 923 bytes | Modified Date = 3/9/2008 9:42:05 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 3/9/2008 1:10:35 PM | Attr = H ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 4232 bytes | Modified Date = 11/25/2007 12:51:12 AM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 5360 bytes | Modified Date = 8/26/2007 4:20:54 PM | Attr = ] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 8206 bytes | Modified Date = 12/4/2006 11:21:32 AM | Attr = ] md5deep.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~dkidefw.tmp\md5deep.exe -> [Ver = | Size = 21504 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] sed.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~dkidefw.tmp\sed.exe -> [Ver = | Size = 37376 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] swreg.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~dkidefw.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] md5deep.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~mlctznn.tmp\md5deep.exe -> [Ver = | Size = 21504 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] sed.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~mlctznn.tmp\sed.exe -> [Ver = | Size = 37376 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] swreg.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~mlctznn.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] md5deep.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~pbllswd.tmp\md5deep.exe -> [Ver = | Size = 21504 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] sed.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~pbllswd.tmp\sed.exe -> [Ver = | Size = 37376 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] swreg.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~pbllswd.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] md5deep.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~vukbuhx.tmp\md5deep.exe -> [Ver = | Size = 21504 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] sed.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~vukbuhx.tmp\sed.exe -> [Ver = | Size = 37376 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] swreg.exe -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~vukbuhx.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 10:23:07 PM | Attr = ] dss.dll -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~dkidefw.tmp\dss.dll -> [Ver = | Size = 37888 bytes | Modified Date = 10/14/2007 2:42:28 AM | Attr = ] dss.dll -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~mlctznn.tmp\dss.dll -> [Ver = | Size = 37888 bytes | Modified Date = 10/14/2007 2:42:28 AM | Attr = ] dss.dll -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~pbllswd.tmp\dss.dll -> [Ver = | Size = 37888 bytes | Modified Date = 10/14/2007 2:42:28 AM | Attr = ] dss.dll -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\~vukbuhx.tmp\dss.dll -> [Ver = | Size = 37888 bytes | Modified Date = 10/14/2007 2:42:28 AM | Attr = ] setup.ini -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\setup.ini -> [Ver = | Size = 4585 bytes | Modified Date = 2/26/2008 10:39:22 PM | Attr = ] 5 C:\Documents and Settings\LuanneRowland\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\LuanneRowland\Local Settings\Temp\*.tmp -> Perflib_Perfdata_16bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_16bc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/4/2008 11:54:07 PM | Attr = ] 1 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> [Files Modified - Additional Folder Scans - Non-Microsoft Only] AOL -> %AllUsersProfile%\Application Data\AOL -> [Folder | Modified Date = 12/19/2007 7:41:43 AM | Attr = ] AOL Downloads -> %AllUsersProfile%\Application Data\AOL Downloads -> [Folder | Modified Date = 2/26/2008 10:39:18 PM | Attr = ] Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Modified Date = 3/11/2008 7:30:02 PM | Attr = ] Lavasoft -> %AllUsersProfile%\Application Data\Lavasoft -> [Folder | Modified Date = 1/14/2008 11:47:03 PM | Attr = ] PKP_DLds.DAT -> %AllUsersProfile%\Application Data\PKP_DLds.DAT -> [Ver = | Size = 20 bytes | Modified Date = 3/7/2008 4:32:32 PM | Attr = H ] PKP_DLec.DAT -> %AllUsersProfile%\Application Data\PKP_DLec.DAT -> [Ver = | Size = 20 bytes | Modified Date = 3/7/2008 4:32:32 PM | Attr = H ] TEMP -> %AllUsersProfile%\Application Data\TEMP -> [Folder | Modified Date = 3/8/2008 12:23:22 PM | Attr = ] @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:5C321E34 AOL -> %AppData%\AOL -> [Folder | Modified Date = 12/19/2007 7:44:43 AM | Attr = ] Roxio -> %AppData%\Roxio -> [Folder | Modified Date = 1/17/2008 7:16:26 PM | Attr = ] U3 -> %AppData%\U3 -> [Folder | Modified Date = 12/26/2007 9:53:57 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 2643154 bytes | Modified Date = 3/9/2008 1:08:13 PM | Attr = H ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 1/18/2008 1:54:06 PM | Attr = ] MicroVision Applications -> %UserProfile%\Local Settings\Application Data\MicroVision Applications -> [Folder | Modified Date = 1/18/2008 2:05:45 PM | Attr = ] BeneteauCushions.jpg -> %UserProfile%\My Documents\BeneteauCushions.jpg -> [Ver = | Size = 39274 bytes | Modified Date = 2/5/2008 5:24:53 PM | Attr = ] Calculus BC -> %UserProfile%\My Documents\Calculus BC -> [Folder | Modified Date = 2/25/2008 8:07:24 PM | Attr = ] Chemistry AP -> %UserProfile%\My Documents\Chemistry AP -> [Folder | Modified Date = 3/11/2008 10:34:23 PM | Attr = ] FACILITY_MAP_OVERVIEW.pdf -> %UserProfile%\My Documents\FACILITY_MAP_OVERVIEW.pdf -> [Ver = | Size = 4616620 bytes | Modified Date = 1/27/2008 3:20:12 PM | Attr = ] February 6 to Barbados.doc -> %UserProfile%\My Documents\February 6 to Barbados.doc -> [Ver = | Size = 24064 bytes | Modified Date = 2/6/2008 6:44:11 PM | Attr = ] JustinFederal2007.pdf -> %UserProfile%\My Documents\JustinFederal2007.pdf -> [Ver = | Size = 53578 bytes | Modified Date = 2/2/2008 11:50:56 AM | Attr = ] Justinstate2007.pdf -> %UserProfile%\My Documents\Justinstate2007.pdf -> [Ver = | Size = 70974 bytes | Modified Date = 2/2/2008 11:51:42 AM | Attr = ] minicraft2006catalog.pdf -> %UserProfile%\My Documents\minicraft2006catalog.pdf -> [Ver = | Size = 21598365 bytes | Modified Date = 2/3/2008 9:51:46 AM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\minicraft2006catalog.pdf:Zone.Identifier My Music -> %UserProfile%\My Documents\My Music -> [Folder | Modified Date = 1/5/2008 2:47:48 PM | Attr = R ] My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 1/17/2008 6:34:47 PM | Attr = R ] Newman Scholarship 100wds.doc -> %UserProfile%\My Documents\Newman Scholarship 100wds.doc -> [Ver = | Size = 24576 bytes | Modified Date = 3/9/2008 11:48:18 AM | Attr = ] physics bake sale.doc -> %UserProfile%\My Documents\physics bake sale.doc -> [Ver = | Size = 24064 bytes | Modified Date = 12/17/2007 11:52:22 PM | Attr = ] Resume UPGRADED.doc -> %UserProfile%\My Documents\Resume UPGRADED.doc -> [Ver = | Size = 38400 bytes | Modified Date = 2/24/2008 11:10:08 PM | Attr = ] Resume.doc -> %UserProfile%\My Documents\Resume.doc -> [Ver = | Size = 34816 bytes | Modified Date = 2/15/2008 5:35:44 PM | Attr = ] SC State Fair.doc -> %UserProfile%\My Documents\SC State Fair.doc -> [Ver = | Size = 26624 bytes | Modified Date = 3/9/2008 12:28:54 PM | Attr = ] Spanish III (IV) -> %UserProfile%\My Documents\Spanish III (IV) -> [Folder | Modified Date = 2/15/2008 12:24:46 AM | Attr = ] SpecialDTSMeeting.pdf -> %UserProfile%\My Documents\SpecialDTSMeeting.pdf -> [Ver = | Size = 51131 bytes | Modified Date = 1/12/2008 11:16:19 AM | Attr = ] Thorne Schloarship 1000 words.doc -> %UserProfile%\My Documents\Thorne Schloarship 1000 words.doc -> [Ver = | Size = 27648 bytes | Modified Date = 3/9/2008 12:08:35 PM | Attr = ] USD Wire, Rowland F.WD 2800.doc -> %UserProfile%\My Documents\USD Wire, Rowland F.WD 2800.doc -> [Ver = | Size = 30720 bytes | Modified Date = 12/20/2007 9:52:31 AM | Attr = ] AOL 9.1.lnk -> %AllUsersProfile%\Desktop\AOL 9.1.lnk -> [Ver = | Size = 612 bytes | Modified Date = 12/19/2007 7:44:24 AM | Attr = ] iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 2137 bytes | Modified Date = 2/2/2008 11:23:17 PM | Attr = ] 165.JPG -> %UserProfile%\Desktop\165.JPG -> [Ver = | Size = 1084403 bytes | Modified Date = 2/14/2008 1:02:43 PM | Attr = ] Captain-Chris-Long-Point-Ligh.jpg -> %UserProfile%\Desktop\Captain-Chris-Long-Point-Ligh.jpg -> [Ver = | Size = 104529 bytes | Modified Date = 2/16/2008 11:26:03 AM | Attr = ] dss.exe -> %UserProfile%\Desktop\dss.exe -> [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Modified Date = 3/11/2008 8:18:11 PM | Attr = ] Duke -> %UserProfile%\Desktop\Duke -> [Folder | Modified Date = 3/9/2008 12:28:48 PM | Attr = ] FTF1201967698294.pdf -> %UserProfile%\Desktop\FTF1201967698294.pdf -> [Ver = | Size = 112690 bytes | Modified Date = 2/2/2008 11:57:04 AM | Attr = ] Georgia Tech -> %UserProfile%\Desktop\Georgia Tech -> [Folder | Modified Date = 3/6/2008 4:52:22 PM | Attr = ] Pi Day Flyer.doc -> %UserProfile%\Desktop\Pi Day Flyer.doc -> [Ver = | Size = 31232 bytes | Modified Date = 3/11/2008 10:28:08 PM | Attr = ] pi.doc -> %UserProfile%\Desktop\pi.doc -> [Ver = | Size = 24576 bytes | Modified Date = 2/25/2008 7:49:00 PM | Attr = ] Resume most recent.doc -> %UserProfile%\Desktop\Resume most recent.doc -> [Ver = | Size = 34304 bytes | Modified Date = 3/8/2008 12:21:33 PM | Attr = ] Scholarships January 14 2008.pdf -> %UserProfile%\Desktop\Scholarships January 14 2008.pdf -> [Ver = | Size = 59540 bytes | Modified Date = 1/18/2008 1:41:24 PM | Attr = ] Setups -> %UserProfile%\Desktop\Setups -> [Folder | Modified Date = 3/3/2008 11:03:06 PM | Attr = ] Shortcut to System Tools.lnk -> %UserProfile%\Desktop\Shortcut to System Tools.lnk -> [Ver = | Size = 956 bytes | Modified Date = 1/18/2008 1:56:23 PM | Attr = ] SSF1201967739458.pdf -> %UserProfile%\Desktop\SSF1201967739458.pdf -> [Ver = | Size = 20820 bytes | Modified Date = 2/2/2008 11:57:45 AM | Attr = ] STF1201967724356.pdf -> %UserProfile%\Desktop\STF1201967724356.pdf -> [Ver = | Size = 130191 bytes | Modified Date = 2/2/2008 11:57:31 AM | Attr = ] WinPFind35u -> %UserProfile%\Desktop\WinPFind35u -> [Folder | Modified Date = 3/12/2008 10:19:28 PM | Attr = ] WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe -> [Ver = | Size = 481244 bytes | Modified Date = 3/12/2008 10:18:39 PM | Attr = ] aol -> %CommonProgramFiles%\aol -> [Folder | Modified Date = 12/19/2007 7:43:34 AM | Attr = ] aolshare -> %CommonProgramFiles%\aolshare -> [Folder | Modified Date = 12/19/2007 7:41:57 AM | Attr = ] Blizzard Entertainment -> %CommonProgramFiles%\Blizzard Entertainment -> [Folder | Modified Date = 12/26/2007 7:19:55 PM | Attr = ] [File - Lop Check: Additional Folder Scans - Non-Microsoft Only] C:\Documents and Settings\All Users\Application Data\ -> C:\Documents and Settings\All Users\Application Data -> [Folder | Modified Date = 3/11/2008 7:30:02 PM | Attr = RH ] Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [Folder | Modified Date = 7/31/2007 12:24:41 AM | Attr = ] AOL -> C:\Documents and Settings\All Users\Application Data\AOL -> [Folder | Modified Date = 12/19/2007 7:41:43 AM | Attr = ] AOL Downloads -> C:\Documents and Settings\All Users\Application Data\AOL Downloads -> [Folder | Modified Date = 2/26/2008 10:39:18 PM | Attr = ] AOL OCP -> C:\Documents and Settings\All Users\Application Data\AOL OCP -> [Folder | Modified Date = 8/14/2007 8:41:29 PM | Attr = ] Apple -> C:\Documents and Settings\All Users\Application Data\Apple -> [Folder | Modified Date = 7/31/2007 12:21:59 AM | Attr = ] Apple Computer -> C:\Documents and Settings\All Users\Application Data\Apple Computer -> [Folder | Modified Date = 8/16/2007 5:26:29 PM | Attr = ] EnterNHelp -> C:\Documents and Settings\All Users\Application Data\EnterNHelp -> [Folder | Modified Date = 8/15/2007 4:52:49 PM | Attr = ] Google -> C:\Documents and Settings\All Users\Application Data\Google -> [Folder | Modified Date = 7/30/2007 6:31:39 PM | Attr = ] InstallShield -> C:\Documents and Settings\All Users\Application Data\InstallShield -> [Folder | Modified Date = 7/30/2007 8:41:37 AM | Attr = ] Intel -> C:\Documents and Settings\All Users\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:11 AM | Attr = ] Kaspersky Lab -> C:\Documents and Settings\All Users\Application Data\Kaspersky Lab -> [Folder | Modified Date = 3/11/2008 7:30:02 PM | Attr = ] Lavasoft -> C:\Documents and Settings\All Users\Application Data\Lavasoft -> [Folder | Modified Date = 1/14/2008 11:47:03 PM | Attr = ] Macromedia -> C:\Documents and Settings\All Users\Application Data\Macromedia -> [Folder | Modified Date = 7/30/2007 6:00:51 PM | Attr = ] Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [Folder | Modified Date = 8/17/2007 2:09:00 PM | Attr = S] Motive -> C:\Documents and Settings\All Users\Application Data\Motive -> [Folder | Modified Date = 7/30/2007 5:26:02 PM | Attr = ] MotiveSysIDs -> C:\Documents and Settings\All Users\Application Data\MotiveSysIDs -> [Folder | Modified Date = 7/30/2007 5:45:46 PM | Attr = ] Musicnotes -> C:\Documents and Settings\All Users\Application Data\Musicnotes -> [Folder | Modified Date = 10/27/2007 5:38:45 PM | Attr = ] Napster -> C:\Documents and Settings\All Users\Application Data\Napster -> [Folder | Modified Date = 8/17/2007 2:03:34 PM | Attr = ] Nikon -> C:\Documents and Settings\All Users\Application Data\Nikon -> [Folder | Modified Date = 8/15/2007 2:12:56 PM | Attr = ] Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [Folder | Modified Date = 7/31/2007 12:13:52 AM | Attr = ] Symantec -> C:\Documents and Settings\All Users\Application Data\Symantec -> [Folder | Modified Date = 12/4/2006 11:43:48 AM | Attr = ] TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [Folder | Modified Date = 3/8/2008 12:23:22 PM | Attr = ] @Alternate Data Stream - 115 bytes -> %AllUsersProfile%\Application Data\TEMP:5C321E34 Ultima_T15 -> C:\Documents and Settings\All Users\Application Data\Ultima_T15 -> [Folder | Modified Date = 8/15/2007 4:52:49 PM | Attr = ] Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [Folder | Modified Date = 8/16/2007 11:17:57 AM | Attr = ] Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [Folder | Modified Date = 12/4/2006 12:46:21 PM | Attr = ] C:\Documents and Settings\Default User\Application Data\ -> C:\Documents and Settings\Default User\Application Data -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Adobe -> C:\Documents and Settings\Default User\Application Data\Adobe -> [Folder | Modified Date = 12/8/2006 10:54:15 AM | Attr = ] Identities -> C:\Documents and Settings\Default User\Application Data\Identities -> [Folder | Modified Date = 12/8/2006 10:13:42 AM | Attr = ] Intel -> C:\Documents and Settings\Default User\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Macromedia -> C:\Documents and Settings\Default User\Application Data\Macromedia -> [Folder | Modified Date = 12/8/2006 10:21:56 AM | Attr = ] Microsoft -> C:\Documents and Settings\Default User\Application Data\Microsoft -> [Folder | Modified Date = 1/23/2007 11:42:54 AM | Attr = ] Sun -> C:\Documents and Settings\Default User\Application Data\Sun -> [Folder | Modified Date = 12/8/2006 10:30:06 AM | Attr = ] C:\Documents and Settings\LocalService\Application Data\ -> C:\Documents and Settings\LocalService\Application Data -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Intel -> C:\Documents and Settings\LocalService\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Microsoft -> C:\Documents and Settings\LocalService\Application Data\Microsoft -> [Folder | Modified Date = 12/4/2006 10:43:59 AM | Attr = S] C:\Documents and Settings\LuanneRowland\Application Data\ -> C:\Documents and Settings\LuanneRowland\Application Data -> [Folder | Modified Date = 11/16/2007 7:34:55 PM | Attr = ] acccore -> C:\Documents and Settings\LuanneRowland\Application Data\acccore -> [Folder | Modified Date = 8/14/2007 8:41:55 PM | Attr = ] Adobe -> C:\Documents and Settings\LuanneRowland\Application Data\Adobe -> [Folder | Modified Date = 9/16/2007 9:21:23 PM | Attr = ] AdobeUM -> C:\Documents and Settings\LuanneRowland\Application Data\AdobeUM -> [Folder | Modified Date = 8/15/2007 6:21:21 PM | Attr = ] AOL -> C:\Documents and Settings\LuanneRowland\Application Data\AOL -> [Folder | Modified Date = 12/19/2007 7:44:43 AM | Attr = ] Apple Computer -> C:\Documents and Settings\LuanneRowland\Application Data\Apple Computer -> [Folder | Modified Date = 8/16/2007 5:26:49 PM | Attr = ] CyberLink -> C:\Documents and Settings\LuanneRowland\Application Data\CyberLink -> [Folder | Modified Date = 8/15/2007 1:09:49 AM | Attr = ] Help -> C:\Documents and Settings\LuanneRowland\Application Data\Help -> [Folder | Modified Date = 9/4/2007 5:54:34 PM | Attr = ] Identities -> C:\Documents and Settings\LuanneRowland\Application Data\Identities -> [Folder | Modified Date = 12/8/2006 10:13:42 AM | Attr = ] InstallShield -> C:\Documents and Settings\LuanneRowland\Application Data\InstallShield -> [Folder | Modified Date = 11/6/2007 11:46:16 PM | Attr = ] Intel -> C:\Documents and Settings\LuanneRowland\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Leadertech -> C:\Documents and Settings\LuanneRowland\Application Data\Leadertech -> [Folder | Modified Date = 7/30/2007 9:01:32 AM | Attr = ] Macromedia -> C:\Documents and Settings\LuanneRowland\Application Data\Macromedia -> [Folder | Modified Date = 9/10/2007 5:41:13 PM | Attr = ] Microsoft -> C:\Documents and Settings\LuanneRowland\Application Data\Microsoft -> [Folder | Modified Date = 8/15/2007 5:36:30 AM | Attr = ] Mozilla -> C:\Documents and Settings\LuanneRowland\Application Data\Mozilla -> [Folder | Modified Date = 8/14/2007 8:24:44 PM | Attr = ] Nikon -> C:\Documents and Settings\LuanneRowland\Application Data\Nikon -> [Folder | Modified Date = 8/15/2007 4:48:10 PM | Attr = ] Real -> C:\Documents and Settings\LuanneRowland\Application Data\Real -> [Folder | Modified Date = 9/9/2007 4:00:23 PM | Attr = ] Roxio -> C:\Documents and Settings\LuanneRowland\Application Data\Roxio -> [Folder | Modified Date = 1/17/2008 7:16:26 PM | Attr = ] Sibelius Software -> C:\Documents and Settings\LuanneRowland\Application Data\Sibelius Software -> [Folder | Modified Date = 11/16/2007 7:34:55 PM | Attr = ] Smith Micro -> C:\Documents and Settings\LuanneRowland\Application Data\Smith Micro -> [Folder | Modified Date = 8/19/2007 12:32:26 PM | Attr = ] Sonic -> C:\Documents and Settings\LuanneRowland\Application Data\Sonic -> [Folder | Modified Date = 7/30/2007 9:01:38 AM | Attr = ] Sun -> C:\Documents and Settings\LuanneRowland\Application Data\Sun -> [Folder | Modified Date = 12/8/2006 10:30:06 AM | Attr = ] Talkback -> C:\Documents and Settings\LuanneRowland\Application Data\Talkback -> [Folder | Modified Date = 7/31/2007 12:10:10 AM | Attr = ] U3 -> C:\Documents and Settings\LuanneRowland\Application Data\U3 -> [Folder | Modified Date = 12/26/2007 9:53:57 PM | Attr = ] Viewpoint -> C:\Documents and Settings\LuanneRowland\Application Data\Viewpoint -> [Folder | Modified Date = 8/16/2007 11:17:58 AM | Attr = ] C:\Documents and Settings\NetworkService\Application Data\ -> C:\Documents and Settings\NetworkService\Application Data -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Intel -> C:\Documents and Settings\NetworkService\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Microsoft -> C:\Documents and Settings\NetworkService\Application Data\Microsoft -> [Folder | Modified Date = 12/4/2006 10:43:51 AM | Attr = S] C:\Documents and Settings\tech\Application Data\ -> C:\Documents and Settings\tech\Application Data -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Adobe -> C:\Documents and Settings\tech\Application Data\Adobe -> [Folder | Modified Date = 12/8/2006 10:54:15 AM | Attr = ] Identities -> C:\Documents and Settings\tech\Application Data\Identities -> [Folder | Modified Date = 12/8/2006 10:13:42 AM | Attr = ] Intel -> C:\Documents and Settings\tech\Application Data\Intel -> [Folder | Modified Date = 7/30/2007 8:24:38 AM | Attr = ] Macromedia -> C:\Documents and Settings\tech\Application Data\Macromedia -> [Folder | Modified Date = 12/8/2006 10:21:56 AM | Attr = ] Microsoft -> C:\Documents and Settings\tech\Application Data\Microsoft -> [Folder | Modified Date = 7/30/2007 8:22:21 AM | Attr = ] Sun -> C:\Documents and Settings\tech\Application Data\Sun -> [Folder | Modified Date = 12/8/2006 10:30:06 AM | Attr = ] C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [Folder | Modified Date = 1/18/2008 1:57:33 PM | Attr = S] desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [Ver = | Size = 65 bytes | Modified Date = 8/4/2004 8:00:00 AM | Attr = RH ] SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 3/9/2008 1:10:35 PM | Attr = H ] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] < End of report > [/code]