<?xml version = "1.0"?>
<Session START = "12 Nov 05 20:39:36" END = "12 Nov 05 20:39:36">
<Information Version = "4.17" DatabaseVersion = "127" DataBaseDate = "8 Nov 2005"/>
<Information OS = "Win XP"/>
<Information ServicePack = "Service Pack 2"/>
<Information WorkingDirectory = "C:\Program Files\XoftSpy\"/>
<Information Option = "AdvSpyware Scan" State = "ON"/>
<Information Option = "Scan IE Favorites" State = "ON"/>
<Information Option = "Scan Host Files" State = "ON"/>
<Information Option = "Scan Drives" State = "ON"/>
<Information Option = "Do Not Scan Executables" State = "OFF"/>
<Information Option = "Scan Registry" State = "ON"/>
<Information Option = "Scan Active Processes" State = "ON"/>
<Information Option = "Automatic Database Update" State = "ON"/>
<Information Option = "Automatic Program Update" State = "ON"/>
<Information Option = "Automatic Removal" State = "OFF"/>
<Information Option = "Exit When Finished" State = "OFF"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Run"/>
<Information Value = "SpybotSD TeaTimer" Data = "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" MD5 = "58f7e6434d285f4c98ad3621e0bd8c8d" Path = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Run"/>
<Information Value = "AVG7_CC" Data = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" MD5 = "6492815fc67068a11420740637946b0e" Path = ""/>
<Information Value = "LXCGCATS" Data = "rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16"/>
<Information Value = "lxcgmon.exe" Data = "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" MD5 = "69b04046b521ac8fd7c8ca34ff6800aa" Path = ""/>
<Information Value = "FaxCenterServer" Data = "C:\Program Files\Lexmark Fax Solutions\fm3032.exe /s" MD5 = "050e681e81e068cd5ab35fbd948df8b5" Path = ""/>
<Information Value = "EzPrint" Data = "C:\Program Files\Lexmark 2300 Series\ezprint.exe" MD5 = "7dd0cb43c8e3be094910369313693643" Path = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Winlogon"/>
<Information Value = "Userinit" Data = "C:\WINDOWS\system32\userinit.exe,"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Winlogon"/>
<Information Value = "Shell" Data = "Explorer.exe"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Windows"/>
<Information Value = "load" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows NT\CurrentVersion\Windows"/>
<Information Value = "AppInit_DLLs" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad"/>
<Information Value = "PostBootReminder" Data = "{7849596a-48ea-486e-8937-a2a3009f31a9}"/>
<Information Value = "CDBurn" Data = "{fbeb8a05-beee-4442-804e-409d6c4515e9}"/>
<Information Value = "WebCheck" Data = "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"/>
<Information Value = "SysTray" Data = "{35CEC8A3-2BE6-11D2-8773-92E220524153}"/>
<Information Value = "UPnPMonitor" Data = "{e57ce738-33e8-4c51-8354-bb4de9d215d1}"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler"/>
<Information Value = "{438755C2-A8BA-11D1-B96B-00A0C90312E1}" Data = "Browseui preloader"/>
<Information Value = "{8C7461EF-2B13-11d2-BE35-3078302C2030}" Data = "Component Categories cache daemon"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\OLE"/>
<Information Value = "DefaultLaunchPermission" Data = ""/>
<Information Value = "MachineLaunchRestriction" Data = ""/>
<Information Value = "MachineAccessRestriction" Data = ""/>
<Information Value = "EnableDCOM" Data = "Y"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\Main"/>
<Information Value = "NoUpdateCheck" Data = "(DWORD) 0 0 0 0"/>
<Information Value = "NoJITSetup" Data = "(DWORD) 0 0 0 0"/>
<Information Value = "Anchor Underline" Data = "hover"/>
<Information Value = "Cache_Update_Frequency" Data = "Once_Per_Session"/>
<Information Value = "Do404Search" Data = ""/>
<Information Value = "Local Page" Data = "http://www.google.com/"/>
<Information Value = "Start Page" Data = "http://www.google.com/"/>
<Information Value = "Search Page" Data = "http://www.google.com"/>
<Information Value = "Default_Page_URL" Data = "http://www.dell4me.c...com/mywaybiz"/>
<Information Value = "UseHR" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "Use Custom Search URL" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "Window_Placement" Data = ""/>
<Information Value = "AddToFavoritesExpanded" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "HistoryViewType" Data = ""/>
<Information Value = "NscSingleExpand" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "NoWebJITSetup" Data = "(DWORD) 0 0 0 0"/>
<Information Value = "Page_Transitions" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "UseThemes" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "Force Offscreen Composition" Data = "(DWORD) 0 0 0 0"/>
<Information Value = "AllowWindowReuse" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "SmoothScroll" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "Show image placeholders" Data = "(DWORD) 0 0 0 0"/>
<Information Value = "AutoSearch" Data = "(DWORD) 0x5 0 0 0"/>
<Information Value = "HistoryTopNSitesView" Data = "(DWORD) 0x14 0 0 0"/>
<Information Value = "StatusBarWeb" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "Search Bar" Data = "http://www.google.com/ie"/>
<Information Value = "LastCheckedHi" Data = "(DWORD) 0x2f f2 c5 1"/>
<Information Value = "First Home Page" Data = "http://www.microsoft...update&O1=b1"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Internet Explorer\Main"/>
<Information Value = "Default_Page_URL" Data = "http://www.microsoft...6&ar=msnhome"/>
<Information Value = "Default_Search_URL" Data = "http://www.microsoft...&ar=iesearch"/>
<Information Value = "Search Page" Data = "http://www.google.com"/>
<Information Value = "Cache_Percent_of_Disk" Data = ""/>
<Information Value = "Local Page" Data = "http://www.google.com/"/>
<Information Value = "Anchor_Visitation_Horizon" Data = ""/>
<Information Value = "Placeholder_Width" Data = ""/>
<Information Value = "Placeholder_Height" Data = ""/>
<Information Value = "Start Page" Data = "http://www.google.com/"/>
<Information Value = "CompanyName" Data = "Microsoft Corporation"/>
<Information Value = "Custom_Key" Data = "MICROSO"/>
<Information Value = "Wizard_Version" Data = "6.0.2600.0000"/>
<Information Value = "Search Bar" Data = "http://red.clientapp.../search.html"/>
<Information Value = "Window Title" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Internet Explorer\Search"/>
<Information Value = "SearchAssistant" Data = "http://www.google.com/ie"/>
<Information Value = "CustomizeSearch" Data = "http://ie.search.msn...srchcust.htm"/>
<Information Value = "CustomSearch" Data = "http://red.clientapp.../search.html"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\SearchURL"/>
<Information Value = "provider" Data = "gogl"/>
<Information Value = "" Data = "http://www.google.co...m/keyword/%s"/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\URLSearchHooks"/>
<Information Value = "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "Software\Microsoft\Internet Explorer\Toolbar"/>
<Information Value = "{BA52B914-B692-46c4-B683-905236F6F655}" Data = "McAfee VirusScan"/>
<Information Value = "{4982D40A-C53B-4615-B15B-B5B5E98D167C}" Data = ""/>
<Information Value = "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" Data = ""/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Internet Explorer\Toolbar"/>
<Information Value = "LinksFolderName" Data = "Links"/>
<Information Value = "Locked" Data = "(DWORD) 0x1 0 0 0"/>
<Information Value = "{1E796980-9CC5-11D1-A83F-00C04FC99D61}" Data = ""/>
<Information Value = "Theater" Data = ""/>
<Information Value = "{710EB7A1-45ED-11D0-924A-0020AFC7AC4D}" Data = ""/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\exefile\shell\open\command"/>
<Information Value = "" Data = "%1 %*"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\comfile\shell\open\command"/>
<Information Value = "" Data = "%1 %*"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\batfile\shell\open\command"/>
<Information Value = "" Data = "%1 %*"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\piffile\shell\open\command"/>
<Information Value = "" Data = "%1 %*"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\scrfile\shell\open\command"/>
<Information Value = "" Data = "%1 /S"/>
<Information RootKey = "HKEY_LOCAL_MACHINE" KeyPath = "SOFTWARE\Classes\htafile\shell\open\command"/>
<Information Value = "" Data = "C:\WINDOWS\system32\mshta.exe %1 %*" MD5 = "c4445bd306656ade30900e6197fabed1" Path = ""/>
<Information RootKey = "HKEY_CURRENT_USER" KeyPath = "Software\Microsoft\Windows\CurrentVersion\Internet Settings"/>
<Information Value = "ProxyEnable" Data = "(DWORD) 0 0 0 0"/>
<Information Directory = "C:\Documents and Settings\Yvonne Smith\Start Menu\Programs\Startup\*" Program = "DESKTOP.INI" MD5 = "d6a6856702e3f0953e7246a9b4a9fe35" />
<Information Directory = "C:\Documents and Settings\Yvonne Smith\Start Menu\Programs\Startup\*" Program = "Stick.lnk.disabled" LinkFile = "C:\Program Files\Stick\Stick.exe" MD5 = "(null)"/>
<Information Directory = "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\*" Program = "DESKTOP.INI" MD5 = "d6a6856702e3f0953e7246a9b4a9fe35" />
<Scanning TIME = "12 Nov 05 20:39:36">
<PROCESS NAME = "C:\WINDOWS\system32\services.exe" MD5 = "c6ce6eec82f187615d1002bb3bb50ed4"/>
<PROCESS NAME = "C:\WINDOWS\system32\lsass.exe" MD5 = "84885f9b82f4d55c6146ebf6065d75d2"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\System32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\Explorer.EXE" MD5 = "a0732187050030ae399b241436565e64"/>
<PROCESS NAME = "C:\WINDOWS\system32\spoolsv.exe" MD5 = "da81ec57acd4cdc3d4c51cf3d409af9f"/>
<PROCESS NAME = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" MD5 = "71599f550d4d892671dba3f05efafb71"/>
<PROCESS NAME = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" MD5 = "66093610fa61142f6bcfd83afb7e8a29"/>
<PROCESS NAME = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" MD5 = "cb3b430807aa5ee7e840e3d3a12ce6de"/>
<PROCESS NAME = "C:\WINDOWS\System32\snmp.exe" MD5 = "d923bf27723e28e3c121b77f52db4bce"/>
<PROCESS NAME = "C:\WINDOWS\system32\svchost.exe" MD5 = "8f078ae4ed187aaabc0a305146de6716"/>
<PROCESS NAME = "C:\WINDOWS\system32\wdfmgr.exe" MD5 = "c81b8635dee0d3ef5f64b3dd643023a5"/>
<PROCESS NAME = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" MD5 = "6492815fc67068a11420740637946b0e"/>
<PROCESS NAME = "C:\Program Files\Lexmark 2300 Series\ezprint.exe" MD5 = "7dd0cb43c8e3be094910369313693643"/>
<PROCESS NAME = "C:\WINDOWS\System32\alg.exe" MD5 = "f1958fbf86d5c004cf19a5951a9514b7"/>
<PROCESS NAME = "C:\Program Files\XoftSpy\XoftSpy.exe" MD5 = "8107deb204f560cd5e8326d6364f56db"/>
<ScanningRegKeys>
</SW>
<SW NAME = "ISTBar">
<REGKEYFOUND NAME = "software\microsoft\code store database\distribution units\{7c559105-9ecf-42b8-b3f7-832e75edd959}"/>
<REGKEY NAME = "ISTBar software\microsoft\code store database\distribution units\{7c559105-9ecf-42b8-b3f7-832e75edd959}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{52889e01-cb46-11d2-96bc-00104b242e64}"/>
<REGKEY NAME = "OrbitExplorer interface\{52889e01-cb46-11d2-96bc-00104b242e64}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{5c49cbd2-8ed7-439b-8668-32149f84a235}"/>
<REGKEY NAME = "OrbitExplorer interface\{5c49cbd2-8ed7-439b-8668-32149f84a235}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{6e6cf8e5-d795-11d2-a566-444553540000}"/>
<REGKEY NAME = "OrbitExplorer interface\{6e6cf8e5-d795-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{79884200-3ade-11d3-ac39-00105a2057fa}"/>
<REGKEY NAME = "OrbitExplorer interface\{79884200-3ade-11d3-ac39-00105a2057fa}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{810e95c2-f908-4e02-9b28-b92c3a778d0d}"/>
<REGKEY NAME = "OrbitExplorer interface\{810e95c2-f908-4e02-9b28-b92c3a778d0d}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{aa0c96f9-a994-42d7-9543-842cf85e1ba7}"/>
<REGKEY NAME = "OrbitExplorer interface\{aa0c96f9-a994-42d7-9543-842cf85e1ba7}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{b57613b6-ef02-4d96-99c6-70c9a2014a14}"/>
<REGKEY NAME = "OrbitExplorer interface\{b57613b6-ef02-4d96-99c6-70c9a2014a14}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{bdb9b021-caff-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{bdb9b021-caff-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{bdb9b022-caff-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{bdb9b022-caff-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{c1da7ab8-54fc-4971-9afb-1bcb9afc3aa2}"/>
<REGKEY NAME = "OrbitExplorer interface\{c1da7ab8-54fc-4971-9afb-1bcb9afc3aa2}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{c3a156d4-503f-4779-a673-657308d94faf}"/>
<REGKEY NAME = "OrbitExplorer interface\{c3a156d4-503f-4779-a673-657308d94faf}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{d72ac8e7-f41d-11d2-a566-444553540000}"/>
<REGKEY NAME = "OrbitExplorer interface\{d72ac8e7-f41d-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{de3e540a-f0f2-4761-99be-afc6dc427e30}"/>
<REGKEY NAME = "OrbitExplorer interface\{de3e540a-f0f2-4761-99be-afc6dc427e30}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{ea6f254d-1a8c-4518-8fe0-e9b94fd134ed}"/>
<REGKEY NAME = "OrbitExplorer interface\{ea6f254d-1a8c-4518-8fe0-e9b94fd134ed}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{ec914a5c-7c4b-4ac8-8c86-c10ff5c0d23d}"/>
<REGKEY NAME = "OrbitExplorer interface\{ec914a5c-7c4b-4ac8-8c86-c10ff5c0d23d}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{f10493c1-d0b6-11d2-a566-444553540000}"/>
<REGKEY NAME = "OrbitExplorer interface\{f10493c1-d0b6-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa3a-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa3a-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa3e-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa3e-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa40-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa40-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa44-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa44-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa46-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa46-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aa50-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aa50-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{fa13aafa-ca9b-11d2-9780-00104b242ea3}"/>
<REGKEY NAME = "OrbitExplorer interface\{fa13aafa-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "OrbitExplorer">
<REGKEYFOUND NAME = "interface\{feca7cfa-1083-4073-a98a-cf3389fcaf6a}"/>
<REGKEY NAME = "OrbitExplorer interface\{feca7cfa-1083-4073-a98a-cf3389fcaf6a}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ecfbe6e0-1ac8-11d4-8501-00a0cc5d1f63}"/>
<REGKEY NAME = "WildTangent clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ecfbe6e0-1ac8-11d4-8501-00a0cc5d1f63}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{05ef74a5-e109-11d2-a566-444553540000}"/>
<REGKEY NAME = "WildTangent interface\{05ef74a5-e109-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{0e7ae465-ee8d-11d2-a566-444553540000}"/>
<REGKEY NAME = "WildTangent interface\{0e7ae465-ee8d-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{1113c0b6-5300-4d5d-b2d7-35c14b28341b}"/>
<REGKEY NAME = "WildTangent interface\{1113c0b6-5300-4d5d-b2d7-35c14b28341b}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{111d8b01-96c5-46dd-94d1-c6e8b1f69f44}"/>
<REGKEY NAME = "WildTangent interface\{111d8b01-96c5-46dd-94d1-c6e8b1f69f44}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{16410859-886f-4579-bc1f-330a139d0f0f}"/>
<REGKEY NAME = "WildTangent interface\{16410859-886f-4579-bc1f-330a139d0f0f}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{35ed7dfb-a8ed-4216-a4bb-bc08c326ef08}"/>
<REGKEY NAME = "WildTangent interface\{35ed7dfb-a8ed-4216-a4bb-bc08c326ef08}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME =
"interface\{399a8818-2000-436c-9a55-0016e5e3d227}"/>
<REGKEY NAME = "WildTangent interface\{399a8818-2000-436c-9a55-0016e5e3d227}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{52889e01-cb46-11d2-96bc-00104b242e64}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{5c49cbd2-8ed7-439b-8668-32149f84a235}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{6e6cf8e5-d795-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{79884200-3ade-11d3-ac39-00105a2057fa}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{810e95c2-f908-4e02-9b28-b92c3a778d0d}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{aa0c96f9-a994-42d7-9543-842cf85e1ba7}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{b57613b6-ef02-4d96-99c6-70c9a2014a14}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{bdb9b021-caff-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{bdb9b022-caff-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{c1da7ab8-54fc-4971-9afb-1bcb9afc3aa2}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{c1da7ab8-54fc-4971-9afb-1bcb9afc3aa2}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{c3a156d4-503f-4779-a673-657308d94faf}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{d72ac8e7-f41d-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{de3e540a-f0f2-4761-99be-afc6dc427e30}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{ea6f254d-1a8c-4518-8fe0-e9b94fd134ed}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{ec914a5c-7c4b-4ac8-8c86-c10ff5c0d23d}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{f10493c1-d0b6-11d2-a566-444553540000}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa3a-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa3e-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa40-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa44-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa46-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aa50-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{fa13aafa-ca9b-11d2-9780-00104b242ea3}"/>
</SW>
<SW NAME = "WildTangent">
<REGKEYFOUND NAME = "interface\{feca7cfa-1083-4073-a98a-cf3389fcaf6a}"/>
</SW>
<SW NAME = "YourSiteBar">
<REGKEYFOUND NAME = "software\microsoft\code store database\distribution units\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}"/>
<REGKEY NAME = "YourSiteBar software\microsoft\code store database\distribution units\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}"/>
</ScanningRegKeys>
<ScanningRegValues>
</ScanningRegValues>
<ScanningRegValuesChanged>
</SW>
<SW NAME = "Default Windows Settings">
<REGVALUE NAME = "Default Windows Settings software\microsoft\windows\currentversion\thememanager\themeactive\0:@:0"/>
<REGVALUECHANGEDFOUND NAME =
"software\microsoft\windows\currentversion\thememanager\themeactive\0:@:0"/>
</ScanningRegValuesChanged>
</Scanning>
I was kinda happy that I did find out what the eero message was (I think)
It's a Hijack helper bar Yahoo anti-spy found
ISTbar is an IE toolbar, homepage- and search-hijacker provided by Integrated Search Technologies/CDT Inc.Installed by ActiveX drive-by download on affiliate sites, typically porn adverts, from April 2003. At least ISTbar/AUpdate is known to install using aggressive JavaScript (opening an error and re-trying if you refuse the ActiveX download).
I cant seem to get to go away...
I sure do thank anyone that can help.... I'm so lost... I could just cry.............Thank You