This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with all this stuff.

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Budapest George.

Those temporary files are a bit worrying. They were there when you ran the Kaspersky scan. They've survived ATF Cleaner and CCleaner and have changed their names. We'll get tough with them, but I want to check a couple of things first. The HijackThis log is still clean. :)

———————————————————–

Run Erunt

We've got one more item to change in the registry, but we must back it up first.
  • Clck on Start > All Programs
  • Go to ERUNT and then select ERUNT from the menu
  • Click OK on the message box
  • Click OK then Yes then OK
  • ERUNT will backup the registry
  • When complete, click OK to close the message box
———————————————————-

Edit the Windows Registry

Select the contents of the Code Box below and copy/paste into Notepad

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"flags"=dword:00000047

  • Make sure that Word Wrap is turned off in Notepad - (click the Format menu and uncheck Word Wrap)
  • Click Save As on the File menu and name the file fix.reg
  • Change the Save as Type to All Files
  • Save the file on your desktop
  • Close Notepad and make sure that all other windows are closed
Important:
  • Make sure there are NO blank lines before REGEDIT4
  • Make sure there is one blank line at the end of the file
  • Make sure that you have copied all of the text (e.g. don't miss the first 'R')
  • Double-click on the fix.reg file
  • When it prompts to merge, click Yes
———————————————————-

Search for Files
  • Download FileFind by Atribune.
  • Double click on FileFind.exe to open the program.
  • Enter ABC123.* into the File: box.
  • Click on the Search button.
  • Let the scan complete
  • If any files appear in the List of Files: box
    • Click on the Export button.
    • This will create a Notepad file named C:\Export.txt.
    • Find the file C:\Export.txt and rename it as ABC.txt
    • Copy and paste ABC.txt in your next post please.
  • If no files appear and it says 0 Files found in n Directories
    • Don't click the Export button, just let me know in the next post
Click on Start then My Computer and check that the following folder is empty:
  • C:\WINDOWS\Temp\
If it's not empty, please delete the contents and let me know what was there.

—————————————————

Delete the Files (hopefully!)

Please download Killbox and save it to your desktop: http://www.killbox.net/downloads/KillBox.exe

Run FileFind again (see above) but, this time, enter the following:
  • Copy/paste C:\Documents and Settings\dave and michelle\Local Settings\Temp\ into the Directory box
  • Type *.* into the File box
  • Run the program as above
  • This will produce a file named C:\Export.txt (which is why renamed the other one!)
  • Select and copy the entire text in C:\Export.txt
This gives us the current names of the files we want to delete using Killbox.
  • Open Killbox
  • Click the option Delete on Reboot
  • Click on the All Files button
  • Go to File and click on Paste from Clipboard
  • If no files appear in the drop-down box, please stop and let me know
  • Click on the red button with the white 'X' on it (Delete File)
  • Wait for the confirmation message that will ask you to Reboot Now
  • Click Yes
  • Exit the program
Reboot your computer

—————————————————-

After the reboot, please check to see whether the files have gone (C:\Documents and Settings\dave and michelle\Local Settings\Temp\). If they're still there, they will probably have changed their names, but they will start with "me_".

Let me know whether the files have gone and post the contents of ABC.txt (or tell me if there were no files).
Hi Beynac- The first FileFind reported "0 Files Found in 5881 Directories." The folder C:\WINDOWS\Temp\ was empty. The second run of Filefind reported back 15 files in C:\Documents and Settings\dave and michelle\Local Settings\Temp\. I ran into trouble running Killbox though. I saved it to my desktop but when I clicked on it, the Windows Installation dialogue box said "Configuring The Print Shop 20" and then said I needed a CD to install the program. When cancelled Killbox opened but after following your instructions the drop-down box remained empty. I am holding off on doing anything else until I hear from you. Thanks. BG
Hi Budapest George.

The first FileFind reported "0 Files Found in 5881 Directories."

Good! :)

I'm don't know what caused your problem with opening Killbox, but I don't think that it was related to the problem entering the file names. I'd like to see what files are in the temp directory please.

Search for Files
  • Double click on FileFind.exe to open the program.
  • Copy/paste C:\Documents and Settings\dave and michelle\Local Settings\Temp\ into the Directory box
  • Enter *.* into the File: box.
  • Click on the Search button.
  • Let the scan complete
  • If any files appear in the List of Files: box
    • Click on the Export button.
    • This will create a Notepad file named C:\Export.txt. Copy and paste it to your next post please.
  • If no files appear and it says 0 Files found in n Directories
    • Don't click the Export button, just let me know in the next post
Please don't reboot your computer until I ask you to do so.
Beynac- FileFind reported "19 Files found in 6 Directories." The exported log is below. I can honestly say that the computer is running much better. :D C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_8S5tXNxkeTVwAwb - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_b1nQ2hO6jYMDVhS - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_ipOUHiS33efi5OA - 2048 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_kLQK6Ae9t2RzwPU - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_LVfbEZymKAtST1E - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\MSIb6198.LOG - 280 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\MSId6047.LOG - 280 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\MSIee560.LOG - 280 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 1 for FileFind.zip - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 2 for FileFind.zip - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 3 for FileFind.zip - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 4 for FileFind.zip - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\VBE - 0 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\~DF3B48.tmp - 32768 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 1 for FileFind.zip\FileFind.exe - 69632 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 2 for FileFind.zip\FileFind.exe - 69632 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 3 for FileFind.zip\FileFind.exe - 69632 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\Temporary Directory 4 for FileFind.zip\FileFind.exe - 69632 Bytes C:\Documents and Settings\dave and michelle\Local Settings\Temp\VBE\MSForms.exd - 147268 Bytes
Hi Budapest George.

It was my fault that Killbox didn't accept the list of files. :oops: It only works if it can find all of the files on the list. FileFind had created temporary files which had been deleted as soon as you closed the program. Therefore Killbox couldn't find them! Let's try again.

Killbox

Select and copy the entire text within the code box below.

C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_8S5tXNxkeTVwAwb
C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_b1nQ2hO6jYMDVhS
C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_ipOUHiS33efi5OA
C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_kLQK6Ae9t2RzwPU
C:\Documents and Settings\dave and michelle\Local Settings\Temp\me_LVfbEZymKAtST1E
  • Open Killbox
  • Click the option Delete on Reboot
  • Click on the All Files button
  • Go to File and click on Paste from Clipboard
  • If no files appear in the drop-down box, please stop and let me know
  • Click on the red button with the white 'X' on it (Delete File)
  • Wait for the confirmation message that will ask you to Reboot Now
  • Click Yes
  • Exit the program
Reboot your computer

Please check whether there are any files in C:\Documents and Settings\dave and michelle\Local Settings\Temp\ which start with me_ and let me know the result.
No dice, Beynac. It seems that the files just changed names or regenerated with new names. There are five me_* files that have creation dates that match the recent reboot. :( What should we do now? BG
Hi Budapest George.

I've been doing some research. I still don't know what these files are but, in the logs where I found them, some respected experts have left them alone. I think that we ought to try and find out what they are before we go any further. Can you confirm that they are files, not folders (they do look like files despite the fact that they have no extensions). If they are folders, please see what's in them.

Submit File to Jotti

In the FileFind list, four of the files had '0 Bytes' and one had '2048 Bytes'. Please find one that is not zero and submit it for a scan.
  • Please click on http://virusscan.jotti.org/
  • Use the "Browse" button and locate the file on your computer:
  • Click the "Submit" button.
  • Please copy and paste the results, as a reply to this thread.
If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
Hi there Beynac-

The suspect files do indeed appear to be files. They are hidden. I checked under C:\Documents and Settings\Sweet Pea\Local Settings\Temp\ and there are five me_* files there as well. They are also hidden and all but one are 0 KB. Strange.

Jotti reported "The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file."

VirusTotal Report
STATUS: FINISHEDComplete scanning result of "me_gTYXvcIdQ9Ujf6b", received in VirusTotal at 02.04.2007, 21:00:17 (CET).

Antivirus Version Update Result
AntiVir 7.3.1.34 02.04.2007 no virus found
Authentium 4.93.8 02.03.2007 no virus found
Avast 4.7.936.0 02.04.2007 no virus found
AVG 386 02.04.2007 no virus found
BitDefender 7.2 02.04.2007 no virus found
CAT-QuickHeal 9.00 02.03.2007 no virus found
ClamAV devel-20060426 02.04.2007 no virus found
DrWeb 4.33 02.04.2007 no virus found
eSafe 7.0.14.0 02.03.2007 no virus found
eTrust-InoculateIT 30.4.3364 02.02.2007 no virus found
eTrust-Vet 30.3.3366 02.03.2007 no virus found
Ewido 4.0 02.04.2007 no virus found
Fortinet 2.85.0.0 02.04.2007 no virus found
F-Prot 4.2.1.29 02.03.2007 no virus found
Ikarus T3.1.0.31 02.04.2007 no virus found
Kaspersky 4.0.2.24 02.04.2007 no virus found
McAfee 4955 02.02.2007 no virus found
Microsoft 1.2101 02.04.2007 no virus found
Norman 5.80.02 02.02.2007 no virus found
Panda 9.0.0.4 02.04.2007 no virus found
Prevx1 V2 02.04.2007 no virus found
Sophos 4.13.0 02.02.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.04.2007 no virus found
TheHacker [removed] 02.02.2007 no virus found
UNA 1.83 02.03.2007 no virus found
VBA32 3.11.2 02.04.2007 no virus found
VirusBuster 4.3.19:9 02.04.2007 no virus found


Aditional Information
File size: 0 bytes
MD5: d41d8cd98f00b204e9800998ecf8427e
SHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709
Thanks Budapest George. That's very interesting! They look as if they are some sort of cache, like temporary internet files. I think I need to do a bit more research on this. I'll get back to you shortly.
Hi Budapest george.

I would like you to login as 'Sweet Pea' and check something for me.

Check Registry Entries

Select the contents of the Code Box below, right-click and copy it, then paste into Notepad.

@echo off
regedit /e mecheck.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
regedit /e zone.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2"
del regcheck.bat
  • Still in Notepad, go to Format (upper menu bar) and untick Word Wrap
  • Go to File (upper menu bar), and select: Save as
  • In the Save as prompt:
    • Save in: Desktop
    • File Name: regcheck.bat
    • Save as Type: All files
    • Click: Save
  • Exit out of Notepad.
On the Desktop, double-click on regcheck.bat. This will open two text files (mecheck.txt and zone.txt) on your desktop. Please post the contents of these as a reply to this post.

Please also post a HijackThis log (logged in as 'Sweet Pea').
Hello Beynac-
Hope you had a good monday, maybe tuesday for you. Here are the logs signed in as "Sweet Pea".

MeCheck:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges]
@=""


Zone:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
@=""
"DisplayName"="Trusted sites"
"Description"="This zone contains Web sites that you trust not to damage your computer or data."
"Icon"="inetcpl.cpl#00004480"
"CurrentLevel"=dword:00010000
"MinLevel"=dword:00010000
"RecommendedLevel"=dword:00010000
"Flags"=dword:00000043
"1001"=dword:00000000
"1004"=dword:00000001
"1200"=dword:00000000
"1201"=dword:00000001
"1400"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000000
"1407"=dword:00000000
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000000
"1608"=dword:00000000
"1609"=dword:00000001
"1800"=dword:00000000
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000000
"1805"=dword:00000000
"1A00"=dword:00000000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000000
"1A05"=dword:00000000
"1A06"=dword:00000000
"1A10"=dword:00000000
"1C00"=dword:00030000
"1E05"=dword:00030000
"2001"=dword:00000000
"2004"=dword:00000000
"1206"=dword:00000000
"1806"=dword:00000000
"1807"=dword:00000000
"1808"=dword:00000000
"1809"=dword:00000003
"2000"=dword:00000000
"2100"=dword:00000000
"2101"=dword:00000001
"2102"=dword:00000000
"2200"=dword:00000000
"2201"=dword:00000000
"2300"=dword:00000001


Logfile of HijackThis v1.99.1
Scan saved at 5:02:52 PM, on 2/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\PcScnSrv.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\KodakEasyShare\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\HJT\NoHide.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KodakEasyShare\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168658939905
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe
Hi Budapest George.

Yes, it's a lovely cold, bright Tuesday morning here!

The log looks clean, but I'm still worried about those temporary files. I'm very reluctant to say that the computer is clean without knowing what they are. If we haven't killed the infection, it looks as if we have at least disabled it. I would like you to run another online scan and also WinPFind2, which we tried to run at the start of this. If these both come back clean, I think that we can safely say that we have done it!

—————————————————————-

WinPFind2

Please delete the copy of WinPFind2 that you downloaded earlier. I want to make sure that we use an up-to-date version and we can't be sure that the previous one didn't get corrupted.

Download WinPFind2.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind2 on your desktop.
  • Open the WinPFind2 folder and double-click on winpfind2.exe to start the program.
  • Keep the standard settings.
  • In the AddOn Options group (on the right-hand side) click the checkboxes for:
    • awf.def
    • HKCU_IEDesktop.def
    • Jobs.def
    • Policies.def
    • SID_Run_Policies.def
    • ZoneMap.def
  • Now click the Run All Scans button on the toolbar.
  • When the scans are complete click the Simple Report button in the lower right-hand corner to create a report file. Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
  • Copy the report and paste it as a reply to this thread.
—————————————————————

Panda ActiveScan

Using Internet Explorer, please go HERE to run Panda ActiveScan.
  • Once you are on the Panda site click the Check your PC Online button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click Send
  • Select Home User
  • Click the big Scan Now button
  • If it wants to install an ActiveX component, allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
———————————————————

Please post:
  • The WinPFind2 report
  • The Panda ActiveScan report
Howdy Beynac-
Sounds like lovely weather. Nothing but fog and rain here, no surprise.
Here are reports (broken into multiple replies). Activescan reported infections but they appear to be simple cookies. I did not delete them yet, I wanted to check with you first.
BG


Logfile created on: 2/6/2007 8:44:53 PM
WinPFind2 by OldTimer - Version 1.0.15 Folder = C:\Documents and Settings\dave and michelle\Desktop\WinPFind2\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)


< Processes (Non-Microsoft Only) >
c:\program files\adobe\acrobat 7.0\distillr\acrotray.exe - (Adobe Systems Inc. )
c:\program files\adobe\acrobat 7.0\distillr\acrotray.exe - (Adobe Systems Inc. )
c:\windows\system32\ati2evxx.exe - ( )
c:\windows\system32\ati2evxx.exe - ( )
c:\windows\system32\ati2evxx.exe - ( )
c:\program files\ati technologies\ati control panel\atiptaxx.exe - (ATI Technologies, Inc. )
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe - (Anti-Malware Development a.s. )
c:\program files\grisoft\avg anti-spyware 7.5\avgas.exe - (Anti-Malware Development a.s. )
c:\program files\kodakeasyshare\kodak easyshare software\bin\easyshare.exe - ( )
c:\program files\kodakeasyshare\kodak easyshare software\bin\easyshare.exe - ( )
c:\program files\google\googletoolbarnotifier\1.2.908.5008\googletoolbarnotifier.exe - (File not found))
c:\program files\google\googletoolbarnotifier\1.2.1128.5462\googletoolbarnotifier.exe - (Google Inc. )
c:\program files\grisoft\avg anti-spyware 7.5\guard.exe - (Anti-Malware Development a.s. )
c:\program files\hewlett-packard\digital imaging\bin\hpoevm08.exe - (Hewlett-Packard Co. )
c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe - (Hewlett-Packard )
c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe - (Hewlett-Packard )
c:\program files\ipod\bin\ipodservice.exe - (Apple Computer, Inc. )
c:\program files\itunes\ituneshelper.exe - (Apple Computer, Inc. )
c:\program files\java\jre1.6.0\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\program files\java\jre1.6.0\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\windows\mixer.exe - (C-Media Electronic Inc. (www.cmedia.com.tw) )
c:\windows\mixer.exe - (C-Media Electronic Inc. (www.cmedia.com.tw) )
c:\program files\trend micro\internet security 2007\pccguide.exe - (Trend Micro Inc. )
c:\program files\trend micro\internet security 2007\pccguide.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\pcctlcom.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\pcscnsrv.exe - (Trend Micro Inc. )
c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. )
c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
c:\program files\common files\real\update_ob\realsched.exe - (RealNetworks, Inc. )
c:\program files\rhapsody\rhaphlpr.exe - (RealNetworks, Inc. )
c:\program files\analog devices\soundmax\smagent.exe - (Analog Devices, Inc. )
c:\program files\analog devices\soundmax\smax4pnp.exe - (Analog Devices, Inc. )
c:\program files\analog devices\soundmax\smax4pnp.exe - (Analog Devices, Inc. )
c:\program files\trend micro\internet security 2007\tmas_oe\tmas_oemon.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmntsrv.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmpfw.exe - (Trend Micro Inc. )
c:\progra~1\trendm~1\intern~3\tmproxy.exe - (Trend Micro Inc. )
c:\documents and settings\dave and michelle\desktop\winpfind2\winpfind2.exe - (OldTimer Tools )

< Registry Entries >

[>> Internet Explorer Settings <<]
HKLM->Main\\Start Page - about:blank
HKLM->Main\\Search Page - http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
HKLM->Main\\Default_Page_URL - http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKLM->Main\\Default_Search_URL - http://www.google.com/ie
HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page - http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
HKCU->Main\\Search Bar - http://www.google.com/ie
HKCU->Main\\Search Page - http://www.google.com
HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm
HKLM->Search\\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM->Search\\SearchAssistant - http://www.google.com/ie
HKCU->Search\\SearchAssistant - http://www.google.com/ie
HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 0

[>> BHO's <<]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - Adobe PDF Reader Link Helper = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated )
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc. )
{AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper = c:\program files\google\googletoolbar4.dll (Google Inc. )
{AE7CD045-E861-484f-8273-0445EE161910} - AcroIEToolbarHelper Class = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )

[>> Internet Explorer Bars, Toolbars and Extensions <<]

[HKLM-> Internet Explorer Bars]
{182EC0BE-5110-49C8-A062-BEB1D02A220B} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )

[HKCU-> Internet Explorer Bars]
{30D02401-6A81-11D0-8274-00C04FD5AE38} - Search Band = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
{32683183-48a0-441b-a342-7c2a440a9478} - Reg Data - Key not found = Reg Data - Key not found (File not found)
{EFA24E61-B078-11D0-89E4-00C04FC9E26E} - Favorites Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )
{EFA24E62-B078-11D0-89E4-00C04FC9E26E} - History Band = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation )

[HKLM-> Internet Explorer ToolBars]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )

[HKCU-> Internet Explorer ToolBars]
ShellBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
ShellBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar4.dll (Google Inc. )
WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF = C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated )

[HKCU-> Internet Explorer CmdMapping]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8194 - Sun Java Console
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 8193 - Reg Data - Key not found
{FB5F1910-F110-11d2-BB9E-00C04F795683} - 8196 - Windows Messenger
NextId - 8197

[HKLM-> Internet Explorer Extensions]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc. )
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc. )
{FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation )

[HKCU-> Internet Explorer Menu Extensions]
Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html (Adobe Systems Incorporated )
Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html (Adobe Systems Incorporated )
Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html (Adobe Systems Incorporated )
Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html (Adobe Systems Incorporated )
E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation )

[>> Approved Shell Extensions (Non-Microsoft only) <<]

[HKLM-> Approved Shell Extensions]
{0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = Reg Data - Key not found (File not found)
{32683183-48a0-441b-a342-7c2a440a9478} - Media Band = Reg Data - Key not found (File not found)
{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = deskpan.dll (File not found)
{48F45200-91E6-11CE-8A4F-0080C81A28D4} - TMD Shell Extension = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )
{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data - Key not found (File not found)
{771A9DA0-731A-11CE-993C-00AA004ADB6C} - VBPropSheet = C:\Program Files\Trend Micro\Internet Security 2007\VBProp.dll (Trend Micro Inc. )
{7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = Reg Data - Key not found (File not found)
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data - Key not found (File not found)
{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc. )
{acb4a560-3606-11d3-aef4-00104bd0f92d} - KodakShellExtension = C:\Program Files\Common Files\Kodak\ifscore\KodakShX.dll (Eastman Kodak Company )
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - iTunes = C:\Program Files\iTunes\iTunesMiniPlayer.dll (Apple Computer, Inc. )
{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} - Adobe.Acrobat.ContextMenu = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. )
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealPlayer\rpshell.dll (RealNetworks, Inc. )

[>> ContextMenuHandlers (Non-Microsoft only) <<]

[HKLM-> ContextMenuHandlers]
* - {48F45200-91E6-11CE-8A4F-0080C81A28D4} - = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )
* - Adobe.Acrobat.ContextMenu - {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll (Adobe Systems Inc. )
* - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
Directory - AVG Anti-Spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll (Anti-Malware Development a.s. )
Folder - {48F45200-91E6-11CE-8A4F-0080C81A28D4} - = C:\Program Files\Trend Micro\Internet Security 2007\Tmdshell.dll (Trend Micro Inc. )

[>> ColumnHandlers (Non-Microsoft only) <<]

[HKLM-> ColumnHandlers]
Folder - {F9DB5320-233E-11D1-9F84-707F02C10627} - PDF Shell Extension = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll (Adobe Systems, Inc. )

[>> File Associations Keys <<]
HKLM->SOFTWARE\Classes\.bat\\'' - batfile
HKLM->SOFTWARE\Classes\batfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.cmd\\'' - cmdfile
HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.com\\'' - comfile
HKLM->SOFTWARE\Classes\comfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.exe\\'' - exefile
HKLM->SOFTWARE\Classes\exefile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.hta\\'' - htafile
HKLM->SOFTWARE\Classes\htafile\shell\open\command\\'' - C:\WINDOWS\System32\mshta.exe "%1" %*
HKLM->SOFTWARE\Classes\.js\\'' - JSFile
HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.jse\\'' - JSEFile
HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.scr\\'' - scrfile
HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\'' - "%1" /S
HKLM->SOFTWARE\Classes\.vbe\\'' - VBEFile
HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.vbs\\'' - VBSFile
HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsf\\'' - WSFFile
HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsh\\'' - WSHFile
HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.txt\\'' - txtfile
HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\'' - %SystemRoot%\system32\NOTEPAD.EXE %1

[>> Registry Run Keys <<]
HKLM->Run\\ - (File not found)
HKLM->Run\\!AVG Anti-Spyware - "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized (Anti-Malware Development a.s. )
HKLM->Run\\Acrobat Assistant 7.0 - "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" (Adobe Systems Inc. )
HKLM->Run\\ATIPTA - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc. )
HKLM->Run\\C-Media Mixer - Mixer.exe /startup (C-Media Electronic Inc. (www.cmedia.com.tw) )
HKLM->Run\\iTunesHelper - "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Computer, Inc. )
HKLM->Run\\pccguide.exe - "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" (Trend Micro Inc. )
HKLM->Run\\QuickTime Task - "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. )
HKLM->Run\\SoundMax - "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray (Analog Devices, Inc. )
HKLM->Run\\SoundMAXPnP - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc. )
HKLM->Run\\SunJavaUpdateSched - "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" (Sun Microsystems, Inc. )
HKLM->Run\\TkBellExe - "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc. )
HKLM->RunOnceEx\\ - (File not found)
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\OE - "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" (Trend Micro Inc. )
HKCU->Run\\swg - C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe (File not found)

[>> Miscellaneous Startup Keys <<]

[AppInit DLLs]
AppInit_DLL - (File not found)

[Image File Execution Options]
Your Image File Name Here without a path - Debugger = ntsd -d

[Shell Service Object Delay Load]
CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll (Microsoft Corporation )

[Shell Execute Hooks]
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (Anti-Malware Development a.s. )
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )

[Shared Task Scheduler]
{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )
{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\System32\browseui.dll (Microsoft Corporation )

[SafeBoot Option]

[HKLM Command Processor AutoRun]
HKLM->Command Processor\\AutoRun -

[HKCU Command Processor AutoRun]

[Security Providers]
SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[BootExecute]
Session Manager\\BootExecute - autocheck autochk *;

[PendingFileRenameOperations]
Session Manager\\PendingFileRenameOperations - \??\C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\swg3.tmp;

[FileRenameOperations]

[ExcludeFromKnownDlls]
Session Manager\\ExcludeFromKnownDlls -

[>> Disabled MSConfig Items <<]

[>> User Agent Post Platform <<]
SV1 -

[>> Winlogon <<]
HMLM->AltDefaultDomainName - FUR
HMLM->AltDefaultUserName - dave and michelle
HMLM->AutoAdminLogon - Reg Data - Value does not exist
HMLM->DefaultDomainName - FUR
HMLM->DefaultUserName - dave and michelle
HKLM->Shell - Explorer.exe (Microsoft Corporation )
HKLM->System - (File not found)
HMLM->UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation )
HKLM->VMApplet - rundll32 shell32,Control_RunDLL "sysdm.cpl"
Notify\AtiExtEvent - Ati2evxx.dll ( )
Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
Notify\cscdll - cscdll.dll (Microsoft Corporation )
Notify\ScCertProp - wlnotify.dll (Microsoft Corporation )
Notify\Schedule - wlnotify.dll (Microsoft Corporation )
Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
Notify\termsrv - wlnotify.dll (Microsoft Corporation )
Notify\wlballoon - wlnotify.dll (Microsoft Corporation )

[>> DNS Name Servers <<]
{C2586ADE-A4AC-4D53-9359-3779599B6936} - (Marvell Yukon Gigabit Ethernet 10/100/1000Base-T Adapter, Copper RJ-45)

[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 (Tcpip) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 (NTDS) - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000003 (Network Location Awareness (NLA) Namespace) - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation )

[>> Protocol Handlers (Non-Microsoft only) <<]
ipp - (File not found)
msdaipp - (File not found)

[>> Protocol Filters (Non-Microsoft only) <<]

< Services (Non-Microsoft Only) >
Ati HotKey Poller (Ati HotKey Poller) - C:\WINDOWS\System32\Ati2evxx.exe ( ) [Automatic - Running - Win32, running in it's own process]
AVG Anti-Spyware Guard (AVG Anti-Spyware Guard) - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (Anti-Malware Development a.s. ) [Automatic - Running - Win32, running in it's own process]
iPodService (iPodService) - C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc. ) [On Demand - Running - Win32, running in it's own process]
Trend Micro Central Control Component (PcCtlCom) - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Protection Against Spyware (PcScnSrv) - "C:\PROGRA~1\TRENDM~1\INTERN~3\PcScnSrv.exe" (Trend Micro Inc. ) [On Demand - Running - Win32, running in it's own process]
SoundMAX Agent Service (SoundMAX Agent Service (default)) - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Real-time Service (Tmntsrv) - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Personal Firewall (TmPfw) - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]
Trend Micro Proxy Service (tmproxy) - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe (Trend Micro Inc. ) [Automatic - Running - Win32, running in it's own process]

< Files >

Auto-Start Folders

HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc. [Ver = 1, 0, 0, 1 | Size = 113664 bytes | Date = 11/4/1999 3:06:48 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated [Ver = 7.0.5.2005092300 | Size = 29696 bytes | Date = 9/23/2005 9:05:26 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 1/5/2002 10:49:00 PM | Attr = HS])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe (Hewlett-Packard Co. [Ver = 4.2.0.020 | Size = 323646 bytes | Date = 4/5/2003 11:37:10 PM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard [Ver = 1, 0, 0, 1 | Size = 28672 bytes | Date = 4/6/2003 12:06:58 AM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk - C:\Program Files\KodakEasyShare\Kodak EasyShare software\bin\EasyShare.exe ( [Ver = 5, 0, 25, 230 | Size = 151552 bytes | Date = 7/22/2005 3:47:22 AM | Attr = ])
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation [Ver = 10.0.2609 | Size = 83360 bytes | Date = 2/13/2001 1:01:04 AM | Attr = ])

HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Start Menu\Programs\Startup

HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\dave and michelle\Start Menu\Programs\Startup
C:\Documents and Settings\dave and michelle\Start Menu\Programs\Startup\desktop.ini - ( [Ver = | Size = 84 bytes | Date = 1/5/2002 10:49:00 PM | Attr = HS])

HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Start Menu\Programs\Startup

Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - Explorer.exe

Miscellaneous Folders

AllUsers ApplicationData Folder
C:\Documents and Settings\All Users\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 1/5/2002 2:21:00 PM | Attr = HS])
C:\Documents and Settings\All Users\Application Data\hpzinstall.log - ( [Ver = | Size = 188 bytes | Date = 10/3/2004 5:16:00 PM | Attr = ])
C:\Documents and Settings\All Users\Application Data\OutlookFail.20070113.log - ( [Ver = | Size = 175 bytes | Date = 1/13/2007 7:42:10 PM | Attr = ])
C:\Documents and Settings\All Users\Application Data\OutlookFail.20070204.log - ( [Ver = | Size = 175 bytes | Date = 2/4/2007 10:56:28 AM | Attr = ])

CurrentUser ApplicationData Folder
C:\Documents and Settings\dave and michelle\Application Data\desktop.ini - ( [Ver = | Size = 62 bytes | Date = 1/5/2002 2:21:00 PM | Attr = HS])
C:\Documents and Settings\dave and michelle\Application Data\dm.ini - ( [Ver = | Size = 0 bytes | Date = 10/7/2004 4:39:26 PM | Attr = ])
C:\Documents and Settings\dave and michelle\Application Data\GDIPFONTCACHEV1.DAT - ( [Ver = | Size = 145640 bytes | Date = 1/24/2007 7:39:44 PM | Attr = ])

Program Files Folder

Common Files Folder

DPF files
{02BCC737-B171-4746-94C9-0D8A0B2C0089} - Microsoft Office Template and Media Control - CodeBase = http://office.microsoft.com/templates/ieawsdc.cab
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - CKAVWebScan Object - CodeBase = http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
{17492023-C23A-453E-A040-C7C580BBF700} - Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - MUWebControl Class - CodeBase = http://update.microsoft.com/microsoftupdat…b?1168658939905
{8AD9C840-044E-11D1-B3E9-00805F499D93} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - Java Plug-in 1.6.0 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
{D27CDB6E-AE6D-11CF-96B8-444553540000} - - CodeBase = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

Hosts file = 734 bytes. Reading all entries. C:\WINDOWS\System32\drivers\etc\Hosts
# Copyright © 1993-1999 Microsoft Corp. -
# -
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. -
# -
# This file contains the mappings of IP addresses to host names. Each -
# entry should be kept on an individual line. The IP address should -
# be placed in the first column followed by the corresponding host name. -
# The IP address and the host name should be separated by at least one -
# space. -
# -
# Additionally, comments (such as these) may be inserted on individual -
# lines or following the machine name denoted by a '#' symbol. -
# -
# For example: -
# -
# 102.54.94.97 rhino.acme.com # source server -
# 38.25.63.10 x.acme.com # x client host -
-
127.0.0.1 localhost -

< Add On's >

>>>>Output for AddOn file awf.def<<<<

DIR - C:\*.* - Parameters = Size of 21504; Include SubFolders
C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\Address Book 6.0 for Windows\ab6.cfg - ( [Ver = | Size = 21504 bytes | Date = 1/24/2007 7:39:22 PM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\Blinders\jasmine-8-01-05-dt.doc - ( [Ver = | Size = 21504 bytes | Date = 8/10/2005 10:44:00 AM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\war pigeon\bio-wp.doc - ( [Ver = | Size = 21504 bytes | Date = 10/12/2005 3:41:18 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\Copy of student project\Summary.doc - ( [Ver = | Size = 21504 bytes | Date = 10/22/2005 8:33:04 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\student project\Summary.doc - ( [Ver = | Size = 21504 bytes | Date = 10/22/2005 8:33:04 PM | Attr = ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfCUT13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 21504 bytes | Date = 9/25/2002 5:37:22 PM | Attr = R ])
C:\Program Files\Microsoft Office\Templates\Presentation Designs\Capsules.pot - ( [Ver = | Size = 21504 bytes | Date = 11/27/2000 11:54:32 PM | Attr = ])
C:\Program Files\The Print Shop 20\Thesaurus.dll - (Broderbund Properties LLC [Ver = 6, 0, 0, 1336 | Size = 21504 bytes | Date = 7/29/2003 7:43:30 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\CUSTOMGR.CDR - ( [Ver = | Size = 21504 bytes | Date = 12/1/2000 2:39:46 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\phframes.KDR - ( [Ver = | Size = 21504 bytes | Date = 7/9/1999 11:36:04 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS15ART4.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/15/2003 11:47:38 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\Ps15PrtH.KDR - ( [Ver = | Size = 21504 bytes | Date = 5/19/2003 1:25:02 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS20HIRES.KDR - ( [Ver = | Size = 21504 bytes | Date = 6/3/2003 3:03:30 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\Ps20OnPj.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/17/2003 11:02:12 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj1.SD1 - ( [Ver = | Size = 21504 bytes | Date = 7/7/2003 1:58:34 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj2.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/19/2003 10:45:34 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\ps20prj4.NDR - ( [Ver = | Size = 21504 bytes | Date = 7/17/2003 11:16:48 AM | Attr = ])
C:\Program Files\The Print Shop 20\Content\PS20Sets.CDR - ( [Ver = | Size = 21504 bytes | Date = 7/14/2003 12:51:16 PM | Attr = ])
C:\Program Files\The Print Shop 20\Content\STAMPS.CDR - ( [Ver = | Size = 21504 bytes | Date = 5/25/2001 1:02:32 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB840987\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB841356\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB841533\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB873376\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 1:22:04 PM | Attr = ])
C:\WINDOWS\$hf_mig$\KB887822\update\spcustom.dll - (Microsoft Corporation [Ver = 5.5.0031.0 (SRV03_QFE.031113-0918) | Size = 21504 bytes | Date = 9/19/2004 12:22:02 PM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\agentpsh.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\agtintl.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\dmserver.dll - (Microsoft Corp. [Ver = 2600.0.503.0 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\iisadmin.dll - (Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\userinit.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\wsock32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\Fonts\smallf.fon - (Microsoft Corporation [Ver = 3.10 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = H ])
C:\WINDOWS\msagent\intl\agt0407.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\msagent\intl\agt040c.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\brpinfo.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\dpvacm.dll - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\feclient.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\hidserv.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\rcp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\spupdwxp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\lang\cintlgnt.ime - (Microsoft Corporation [Ver = 4.4.2714 | Size = 21504 bytes | Date = 8/3/2004 9:31:54 PM | Attr = ])
C:\WINDOWS\system32\dpvacm.dll - (Microsoft Corporation [Ver = 5.03.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\system32\feclient.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:42 PM | Attr = ])
C:\WINDOWS\system32\ipxrip.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\pathping.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\rcp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\spupdwxp.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 21504 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\system32\dllcache\agt0407.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\agt040c.dll - (Microsoft Corporation [Ver = 2.00.0.3422 | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\brpinfo.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\cintlgnt.ime - (Microsoft Corporation [Ver = 4.4.2714 | Size = 21504 bytes | Date = 8/3/2004 9:31:54 PM | Attr = ])
C:\WINDOWS\system32\dllcache\ipxrip.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\pathping.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 21504 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])

DIR - C:\*.* - Parameters = Size of 25600; Include SubFolders
C:\Documents and Settings\dave and michelle\My Documents\Dave\Blinders\test-7-21-05-meeting-dt.doc - ( [Ver = | Size = 25600 bytes | Date = 11/13/2006 9:43:50 AM | Attr = ])
C:\Documents and Settings\dave and michelle\My Documents\Dave\war pigeon\WAR PIGEON MASTER LOGIN LIST.doc - ( [Ver = | Size = 25600 bytes | Date = 9/27/2006 3:53:00 PM | Attr = ])
C:\Documents and Settings\Sweet Pea\My Documents\Wedding\~WRL0004.tmp - ( [Ver = | Size = 25600 bytes | Date = 4/16/2006 10:53:26 AM | Attr = H ])
C:\Program Files\Adobe\Acrobat 7.0\Designer 7.0\xfatraversalservice.dll - (Adobe Systems Incorporated [Ver = 2.2.4330.0 | Size = 25600 bytes | Date = 11/26/2004 10:51:42 AM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfani13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 25600 bytes | Date = 9/25/2002 5:37:22 PM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfavi12n.dll - (LEAD Technologies, Inc. [Ver = 12.1.0.000 | Size = 25600 bytes | Date = 8/13/2001 9:03:06 AM | Attr = ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\lfxwd13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 25600 bytes | Date = 9/25/2002 5:37:26 PM | Attr = R ])
C:\Program Files\Java\jre1.6.0\bin\keytool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\kinit.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\klist.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\ktab.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\orbd.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\pack200.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\policytool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\rmid.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\rmiregistry.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\Java\jre1.6.0\bin\servertool.exe - (Sun Microsystems, Inc. [Ver = 6.0.0.105 | Size = 25600 bytes | Date = 1/30/2007 8:37:16 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\PictureViewer.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:08 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:14 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj\PictureViewerLocalized.dll - ( [Ver = | Size = 25600 bytes | Date = 8/25/2005 3:41:14 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:08 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj\PictureViewerLocalized.dll - ( [Ver = | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\no.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj\PictureViewerLocalized.dll - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:12 PM | Attr = ])
C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\PanelHelperBase.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\CoreVideo.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:07:00 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\da.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 25600 bytes | Date = 9/1/2005 4:06:58 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\es.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fi.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\fr.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ja.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\ko.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\no.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\sv.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeH264.Resources\zh_TW.lproj\QuickTimeH264Localized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 25600 bytes | Date = 8/25/2005 3:41:08 PM | Attr = ])
C:\Program Files\Trend Micro\PCC2005_1244\Setup\program files\Trend Micro\PC-cillin\MEMBOOT.DLL - ( [Ver = | Size = 25600 bytes | Date = 5/11/2004 12:48:42 PM | Attr = ])
C:\Program Files\Trend Micro\TIS11_1120\Setup\program files\Trend Micro\PC-cillin\MEMBOOT.DLL - ( [Ver = | Size = 25600 bytes | Date = 4/4/2003 7:42:14 PM | Attr = ])
C:\WINDOWS\twunk_32.exe - (Twain Working Group [Ver = 1,7,1,0 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\pstorsvc.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\winipsec.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\hidbth.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:10:36 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:46 PM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\usbser.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:08:42 PM | Attr = ])
C:\WINDOWS\system32\aaaamon.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\comaddin.dll - (Microsoft Corporation [Ver = 2001.12.4414.42 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\format.com - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\msvidc32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\netsetup.cpl - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:58 PM | Attr = ])
C:\WINDOWS\system32\routemon.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\udhisapi.dll - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 11:56:46 PM | Attr = ])
C:\WINDOWS\system32\utildll.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\aaaamon.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\comaddin.dll - (Microsoft Corporation [Ver = 2001.12.4414.42 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\msvidc32.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\routemon.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\twunk_32.exe - (Twain Working Group [Ver = 1,7,1,0 | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\utildll.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 25600 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\drivers\hidbth.sys - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 25600 bytes | Date = 8/3/2004 10:10:36 PM | Attr = ])

DIR - C:\*.* - Parameters = Size of 27510; Include SubFolders

DIR - C:\*.* - Parameters = Size of 26450; Include SubFolders

DIR - C:\*.* - Parameters = Size of 31232; Include SubFolders
C:\Program Files\Adobe\Acrobat 7.0\Designer 7.0\jfprotocol.dll - (Adobe Systems Incorporated [Ver = 2.2.4330.0 | Size = 31232 bytes | Date = 11/26/2004 10:03:16 AM | Attr = R ])
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\LFPNM13n.dll - (LEAD Technologies, Inc. [Ver = 13.0.0.036 | Size = 31232 bytes | Date = 9/25/2002 5:37:26 PM | Attr = R ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj\QuickTime3GPPLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:10 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\QuickTime3GPPAuthoring.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 31232 bytes | Date = 9/1/2005 4:06:58 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeMPEG.Resources\QuickTimeMPEG.qtr - (Apple Computer, Inc. [Ver = 7.0.2 | Size = 31232 bytes | Date = 9/1/2005 4:07:00 PM | Attr = ])
C:\Program Files\QuickTime\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr - (Apple Computer, Inc. [Ver = 7.0.2b20 | Size = 31232 bytes | Date = 8/25/2005 3:41:02 PM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\inetmib1.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\$NtServicePackUninstall$\wpabaln.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\ServicePackFiles\i386\sethc.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 31232 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\sc.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\sethc.exe - (Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 31232 bytes | Date = 8/3/2004 11:56:56 PM | Attr = ])
C:\WINDOWS\system32\traffic.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\sc.exe - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\tools.dll - (Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\traffic.dll - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\wbemads.tlb - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\dllcache\weitekp9.sys - (Microsoft Corporation [Ver = 5.1.2600.0 (XPClient.010817-1148) | Size = 3123
Continued…

| Date = 8/23/2001 4:00:00 AM | Attr = ])
C:\WINDOWS\system32\wbem\wbemads.tlb - (Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 31232 bytes | Date = 8/23/2001 4:00:00 AM | Attr = ])

DIR - C:\\\bak - Parameters = Include SubFolders
C:\Program Files\Trend Micro\Internet Security 2005\bak\pccguide.exe - (Trend Micro Incorporated. [Ver = 12.40.0.1015 | Size = 819262 bytes | Date = 11/25/2005 8:51:34 PM | Attr = ])

>>>>Output for AddOn file HKCU_IEDesktop.def<<<<

KEY - HKCU\Software\Microsoft\Internet Explorer\Desktop - Include SUBKEYS
HKCU\Software\Microsoft\Internet Explorer\Desktop -
Desktop\Components -
Desktop\Components\\DeskHtmlVersion - 272
Desktop\Components\\DeskHtmlMinorVersion - 5
Desktop\Components\\Settings - 1
Desktop\Components\\GeneralFlags - 5
Desktop\Components\0 -
Desktop\Components\0\\Source - About:Home
Desktop\Components\0\\SubscribedURL - About:Home
Desktop\Components\0\\FriendlyName - My Current Home Page
Desktop\Components\0\\Flags - 2
Desktop\Components\0\\Position - 2C 00 00 00 2C 01 00 00 00 00 00 00 D4 03 00 00 E2 03 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00
Desktop\Components\0\\CurrentState - 04 00 00 40
Desktop\Components\0\\OriginalStateInfo - 18 00 00 00 00 01 00 00 00 00 00 00 00 04 00 00 E2 03 00 00 04 00 00 40
Desktop\Components\0\\RestoredStateInfo - 18 00 00 00 00 01 00 00 00 00 00 00 00 04 00 00 E2 03 00 00 01 00 00 00
Desktop\General -
Desktop\General\\BackupWallpaper - %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
Desktop\General\\WallpaperFileTime - 48 B3 93 C8 20 A6 C6 01
Desktop\General\\WallpaperLocalFileTime - 48 DB 34 1C E6 A5 C6 01
Desktop\General\\TileWallpaper - 0
Desktop\General\\WallpaperStyle - 2
Desktop\General\\Wallpaper - %USERPROFILE%\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
Desktop\General\\ComponentsPositioned - 1
Desktop\Old WorkAreas -
Desktop\Old WorkAreas\\NoOfOldWorkAreas - 1
Desktop\Old WorkAreas\\OldWorkAreaRects - 00 00 00 00 00 00 00 00 00 05 00 00 E2 03 00 00
Desktop\SafeMode -
Desktop\SafeMode\General -
Desktop\SafeMode\General\\Wallpaper - %SystemRoot%\Web\SafeMode.htt
Desktop\SafeMode\General\\VisitGallery - 0
Desktop\Scheme -
Desktop\Scheme\\Edit -
Desktop\Scheme\\Display -

>>>>Output for AddOn file Jobs.def<<<<

DIR - C:\WINDOWS\tasks\*.* - Parameters = Include SubFolders
C:\WINDOWS\tasks\desktop.ini - ( [Ver = | Size = 65 bytes | Date = 8/23/2001 4:00:00 AM | Attr = RH ])
C:\WINDOWS\tasks\SA.DAT - ( [Ver = | Size = 6 bytes | Date = 2/3/2007 2:56:18 PM | Attr = H ])

>>>>Output for AddOn file Policies.def<<<<

KEY - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\explorer -
policies\explorer\run -
policies\NonEnum -
policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} - 1
policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} - 1073741857
policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} - 32
policies\Ratings -
policies\system -
policies\system\\dontdisplaylastusername - 0
policies\system\\legalnoticecaption -
policies\system\\legalnoticetext -
policies\system\\shutdownwithoutlogon - 1
policies\system\\undockwithoutlogon - 1

KEY - HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer not found. -

KEY - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies - Include SUBKEYS
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies -
policies\ActiveDesktop -
policies\Associations -
policies\Explorer -
policies\Explorer\\NoDriveTypeAutoRun - 255
policies\Explorer\\_NoDriveTypeAutoRun - 145
policies\Explorer\Run -
policies\System -
policies\System\\DisableRegistryTools - 0

KEY - HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer - Include SUBKEYS
HKCU\SOFTWARE\Policies\Microsoft\Internet Explorer -
Internet Explorer\Control Panel -

>>>>Output for AddOn file SID_Run_Policies.def<<<<

KEY - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run - No SUBKEYS
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run -

KEY - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run - No SUBKEYS
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run -

KEY - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies - Include SUBKEYS
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies -
Policies\Explorer -
Policies\Explorer\\NoDriveTypeAutoRun - 145
Policies\Explorer\Run -
Policies\system -

KEY - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies - Include SUBKEYS
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies -
Policies\Explorer -
Policies\Explorer\\NoDriveTypeAutoRun - 145
Policies\Explorer\Run -
Policies\system -

>>>>Output for AddOn file ZoneMap.def<<<<

KEY - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings - No SUBKEYS
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings -
Internet Settings\\CodeBaseSearchPath - CODEBASE;<http://activex.microsoft.com/objects/ocget.dll>;
Internet Settings\\UrlEncoding - 0x00000000
Internet Settings\\ActiveXCache - C:\WINDOWS\Downloaded Program Files
Internet Settings\\MinorVersion - ;SP2;
Internet Settings\5.0 -
Internet Settings\Accepted Documents -
Internet Settings\ActiveX Cache -
Internet Settings\AllowedBehaviors -
Internet Settings\AllowedDragProtocols -
Internet Settings\Cache -
Internet Settings\Last Update -
Internet Settings\Lockdown_Zones -
Internet Settings\Passport -
Internet Settings\SafeSites -
Internet Settings\Secure Mime Handlers -
Internet Settings\SO -
Internet Settings\SOIEAK -
Internet Settings\Subscription Folder -
Internet Settings\TemplatePolicies -
Internet Settings\Url History -
Internet Settings\User Agent -
Internet Settings\ZoneMap -
Internet Settings\Zones -

KEY - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies - Include SUBKEYS
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies -
TemplatePolicies\\ -
TemplatePolicies\High -
TemplatePolicies\High\\ -
TemplatePolicies\High\\TemplateIndex - 73728
TemplatePolicies\High\\DisplayName - High safety (very secure)
TemplatePolicies\High\\Description - Exclude content that could damage your computer.
TemplatePolicies\High\\Icon - wininet.dll#00001205
TemplatePolicies\High\\1001 - 3
TemplatePolicies\High\\1004 - 3
TemplatePolicies\High\\1200 - 3
TemplatePolicies\High\\1201 - 3
TemplatePolicies\High\\1400 - 3
TemplatePolicies\High\\1402 - 3
TemplatePolicies\High\\1405 - 3
TemplatePolicies\High\\1406 - 3
TemplatePolicies\High\\1407 - 3
TemplatePolicies\High\\1601 - 1
TemplatePolicies\High\\1604 - 1
TemplatePolicies\High\\1605 - 0
TemplatePolicies\High\\1606 - 3
TemplatePolicies\High\\1607 - 3
TemplatePolicies\High\\1608 - 3
TemplatePolicies\High\\1609 - 1
TemplatePolicies\High\\1800 - 3
TemplatePolicies\High\\1802 - 1
TemplatePolicies\High\\1803 - 3
TemplatePolicies\High\\1804 - 3
TemplatePolicies\High\\1A00 - 65536
TemplatePolicies\High\\1A02 - 3
TemplatePolicies\High\\1A03 - 3
TemplatePolicies\High\\1A04 - 3
TemplatePolicies\High\\1A05 - 3
TemplatePolicies\High\\1A06 - 3
TemplatePolicies\High\\1C00 - 0
TemplatePolicies\High\\1E05 - 65536
TemplatePolicies\High\\2001 - 3
TemplatePolicies\High\\2004 - 3
TemplatePolicies\High\\2000 - 3
TemplatePolicies\High\\2100 - 3
TemplatePolicies\High\\2101 - 3
TemplatePolicies\High\\2102 - 3
TemplatePolicies\High\\2200 - 3
TemplatePolicies\High\\2201 - 3
TemplatePolicies\High\\2300 - 3
TemplatePolicies\High\\1809 - 0
TemplatePolicies\Low -
TemplatePolicies\Low\\ -
TemplatePolicies\Low\\TemplateIndex - 65536
TemplatePolicies\Low\\DisplayName - Low safety (very insecure)
TemplatePolicies\Low\\Description - Do not warn before running potentially damaging content.
TemplatePolicies\Low\\Icon - wininet.dll#00001207
TemplatePolicies\Low\\1001 - 0
TemplatePolicies\Low\\1004 - 1
TemplatePolicies\Low\\1200 - 0
TemplatePolicies\Low\\1201 - 1
TemplatePolicies\Low\\1400 - 0
TemplatePolicies\Low\\1402 - 0
TemplatePolicies\Low\\1405 - 0
TemplatePolicies\Low\\1406 - 0
TemplatePolicies\Low\\1407 - 0
TemplatePolicies\Low\\1601 - 0
TemplatePolicies\Low\\1604 - 0
TemplatePolicies\Low\\1605 - 0
TemplatePolicies\Low\\1606 - 0
TemplatePolicies\Low\\1607 - 0
TemplatePolicies\Low\\1608 - 0
TemplatePolicies\Low\\1609 - 1
TemplatePolicies\Low\\1800 - 0
TemplatePolicies\Low\\1802 - 0
TemplatePolicies\Low\\1803 - 0
TemplatePolicies\Low\\1804 - 0
TemplatePolicies\Low\\1A00 - 0
TemplatePolicies\Low\\1A02 - 0
TemplatePolicies\Low\\1A03 - 0
TemplatePolicies\Low\\1A04 - 0
TemplatePolicies\Low\\1A05 - 0
TemplatePolicies\Low\\1A06 - 0
TemplatePolicies\Low\\1C00 - 196608
TemplatePolicies\Low\\1E05 - 196608
TemplatePolicies\Low\\2001 - 0
TemplatePolicies\Low\\2004 - 0
TemplatePolicies\Low\\2000 - 0
TemplatePolicies\Low\\2100 - 0
TemplatePolicies\Low\\2101 - 1
TemplatePolicies\Low\\2102 - 0
TemplatePolicies\Low\\2200 - 0
TemplatePolicies\Low\\2201 - 0
TemplatePolicies\Low\\2300 - 1
TemplatePolicies\Low\\1809 - 3
TemplatePolicies\Medium -
TemplatePolicies\Medium\\ -
TemplatePolicies\Medium\\TemplateIndex - 69632
TemplatePolicies\Medium\\DisplayName - Medium safety (medium security)
TemplatePolicies\Medium\\Description - Warn before running potentially damaging content.
TemplatePolicies\Medium\\Icon - wininet.dll#00001206
TemplatePolicies\Medium\\1001 - 1
TemplatePolicies\Medium\\1004 - 3
TemplatePolicies\Medium\\1200 - 0
TemplatePolicies\Medium\\1201 - 3
TemplatePolicies\Medium\\1400 - 0
TemplatePolicies\Medium\\1402 - 0
TemplatePolicies\Medium\\1405 - 0
TemplatePolicies\Medium\\1406 - 3
TemplatePolicies\Medium\\1407 - 0
TemplatePolicies\Medium\\1601 - 1
TemplatePolicies\Medium\\1604 - 0
TemplatePolicies\Medium\\1605 - 0
TemplatePolicies\Medium\\1606 - 0
TemplatePolicies\Medium\\1607 - 0
TemplatePolicies\Medium\\1608 - 0
TemplatePolicies\Medium\\1609 - 1
TemplatePolicies\Medium\\1800 - 1
TemplatePolicies\Medium\\1802 - 0
TemplatePolicies\Medium\\1803 - 0
TemplatePolicies\Medium\\1804 - 1
TemplatePolicies\Medium\\1A00 - 131072
TemplatePolicies\Medium\\1A02 - 0
TemplatePolicies\Medium\\1A03 - 0
TemplatePolicies\Medium\\1A04 - 3
TemplatePolicies\Medium\\1A05 - 1
TemplatePolicies\Medium\\1A06 - 0
TemplatePolicies\Medium\\1C00 - 65536
TemplatePolicies\Medium\\1E05 - 131072
TemplatePolicies\Medium\\2001 - 0
TemplatePolicies\Medium\\2004 - 0
TemplatePolicies\Medium\\2000 - 0
TemplatePolicies\Medium\\2100 - 0
TemplatePolicies\Medium\\2101 - 0
TemplatePolicies\Medium\\2102 - 3
TemplatePolicies\Medium\\2200 - 3
TemplatePolicies\Medium\\2201 - 3
TemplatePolicies\Medium\\2300 - 1
TemplatePolicies\Medium\\1809 - 0
TemplatePolicies\MedLow -
TemplatePolicies\MedLow\\ -
TemplatePolicies\MedLow\\TemplateIndex - 66816
TemplatePolicies\MedLow\\DisplayName - Intranet recommended safety (less secure)
TemplatePolicies\MedLow\\Description - Recommended for intranet.
TemplatePolicies\MedLow\\Icon - wininet.dll#00001206
TemplatePolicies\MedLow\\1001 - 1
TemplatePolicies\MedLow\\1004 - 3
TemplatePolicies\MedLow\\1200 - 0
TemplatePolicies\MedLow\\1201 - 3
TemplatePolicies\MedLow\\1400 - 0
TemplatePolicies\MedLow\\1402 - 0
TemplatePolicies\MedLow\\1405 - 0
TemplatePolicies\MedLow\\1406 - 1
TemplatePolicies\MedLow\\1407 - 0
TemplatePolicies\MedLow\\1601 - 0
TemplatePolicies\MedLow\\1604 - 0
TemplatePolicies\MedLow\\1605 - 0
TemplatePolicies\MedLow\\1606 - 0
TemplatePolicies\MedLow\\1607 - 0
TemplatePolicies\MedLow\\1608 - 0
TemplatePolicies\MedLow\\1609 - 1
TemplatePolicies\MedLow\\1800 - 1
TemplatePolicies\MedLow\\1802 - 0
TemplatePolicies\MedLow\\1803 - 0
TemplatePolicies\MedLow\\1804 - 1
TemplatePolicies\MedLow\\1A00 - 131072
TemplatePolicies\MedLow\\1A02 - 0
TemplatePolicies\MedLow\\1A03 - 0
TemplatePolicies\MedLow\\1A04 - 0
TemplatePolicies\MedLow\\1A05 - 0
TemplatePolicies\MedLow\\1A06 - 0
TemplatePolicies\MedLow\\1C00 - 131072
TemplatePolicies\MedLow\\1E05 - 131072
TemplatePolicies\MedLow\\2001 - 0
TemplatePolicies\MedLow\\2004 - 0
TemplatePolicies\MedLow\\2000 - 0
TemplatePolicies\MedLow\\2100 - 0
TemplatePolicies\MedLow\\2101 - 0
TemplatePolicies\MedLow\\2102 - 0
TemplatePolicies\MedLow\\2200 - 0
TemplatePolicies\MedLow\\2201 - 0
TemplatePolicies\MedLow\\2300 - 1
TemplatePolicies\MedLow\\1809 - 3

KEY - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults - No SUBKEYS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -
ProtocolDefaults\\ -
ProtocolDefaults\\http - 3
ProtocolDefaults\\https - 3
ProtocolDefaults\\ftp - 3
ProtocolDefaults\\file - 3
ProtocolDefaults\\@ivt - 1
ProtocolDefaults\\shell - 0

KEY - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones - Include SUBKEYS
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones -
Zones\\ -
Zones\0 -
Zones\0\\ -
Zones\0\\DisplayName - My Computer
Zones\0\\Description - Your computer
Zones\0\\Icon - explorer.exe#0100
Zones\0\\CurrentLevel - 0
Zones\0\\Flags - 33
Zones\0\\1001 - 0
Zones\0\\1004 - 0
Zones\0\\1200 - 0
Zones\0\\1201 - 1
Zones\0\\1400 - 0
Zones\0\\1402 - 0
Zones\0\\1405 - 0
Zones\0\\1406 - 0
Zones\0\\1407 - 0
Zones\0\\1601 - 0
Zones\0\\1604 - 0
Zones\0\\1605 - 0
Zones\0\\1606 - 0
Zones\0\\1607 - 0
Zones\0\\1608 - 0
Zones\0\\1609 - 1
Zones\0\\1800 - 0
Zones\0\\1802 - 0
Zones\0\\1803 - 0
Zones\0\\1804 - 0
Zones\0\\1805 - 0
Zones\0\\1A00 - 0
Zones\0\\1A02 - 0
Zones\0\\1A03 - 0
Zones\0\\1A04 - 0
Zones\0\\1A05 - 0
Zones\0\\1A06 - 0
Zones\0\\1A10 - 0
Zones\0\\1C00 - 131072
Zones\0\\1E05 - 196608
Zones\0\\2001 - 3
Zones\0\\2004 - 3
Zones\0\\1806 - 0
Zones\0\\1206 - 0
Zones\0\\1807 - 0
Zones\0\\1808 - 0
Zones\0\\2000 - 0
Zones\0\\2100 - 0
Zones\0\\2101 - 3
Zones\0\\2102 - 0
Zones\0\\2200 - 0
Zones\0\\2201 - 0
Zones\0\\2300 - 1
Zones\0\\1809 - 3
Zones\1 -
Zones\1\\ -
Zones\1\\DisplayName - Local intranet
Zones\1\\Description - This zone contains all Web sites that are on your organization's intranet.
Zones\1\\Icon - shell32.dll#0018
Zones\1\\CurrentLevel - 66816
Zones\1\\MinLevel - 65536
Zones\1\\RecommendedLevel - 66816
Zones\1\\Flags - 219
Zones\1\\1001 - 1
Zones\1\\1004 - 3
Zones\1\\1200 - 0
Zones\1\\1201 - 3
Zones\1\\1400 - 0
Zones\1\\1402 - 0
Zones\1\\1405 - 0
Zones\1\\1406 - 1
Zones\1\\1407 - 0
Zones\1\\1601 - 0
Zones\1\\1604 - 0
Zones\1\\1605 - 0
Zones\1\\1606 - 0
Zones\1\\1607 - 0
Zones\1\\1608 - 0
Zones\1\\1609 - 1
Zones\1\\1800 - 1
Zones\1\\1802 - 0
Zones\1\\1803 - 0
Zones\1\\1804 - 1
Zones\1\\1805 - 0
Zones\1\\1A00 - 131072
Zones\1\\1A02 - 0
Zones\1\\1A03 - 0
Zones\1\\1A04 - 0
Zones\1\\1A05 - 0
Zones\1\\1A06 - 0
Zones\1\\1A10 - 0
Zones\1\\1C00 - 131072
Zones\1\\1E05 - 131072
Zones\1\\2001 - 0
Zones\1\\2004 - 0
Zones\1\\1806 - 0
Zones\1\\1206 - 0
Zones\1\\1807 - 0
Zones\1\\1808 - 0
Zones\1\\2000 - 0
Zones\1\\2100 - 0
Zones\1\\2101 - 0
Zones\1\\2102 - 0
Zones\1\\2200 - 0
Zones\1\\2201 - 0
Zones\1\\2300 - 1
Zones\1\\1809 - 3
Zones\2 -
Zones\2\\ -
Zones\2\\DisplayName - Trusted sites
Zones\2\\Description - This zone contains Web sites that you trust not to damage your computer or data.
Zones\2\\Icon - inetcpl.cpl#00004480
Zones\2\\CurrentLevel - 65536
Zones\2\\MinLevel - 65536
Zones\2\\RecommendedLevel - 65536
Zones\2\\Flags - 71
Zones\2\\1001 - 0
Zones\2\\1004 - 1
Zones\2\\1200 - 0
Zones\2\\1201 - 1
Zones\2\\1400 - 0
Zones\2\\1402 - 0
Zones\2\\1405 - 0
Zones\2\\1406 - 0
Zones\2\\1407 - 0
Zones\2\\1601 - 0
Zones\2\\1604 - 0
Zones\2\\1605 - 0
Zones\2\\1606 - 0
Zones\2\\1607 - 0
Zones\2\\1608 - 0
Zones\2\\1609 - 1
Zones\2\\1800 - 0
Zones\2\\1802 - 0
Zones\2\\1803 - 0
Zones\2\\1804 - 0
Zones\2\\1805 - 0
Zones\2\\1A00 - 0
Zones\2\\1A02 - 0
Zones\2\\1A03 - 0
Zones\2\\1A04 - 0
Zones\2\\1A05 - 0
Zones\2\\1A06 - 0
Zones\2\\1A10 - 0
Zones\2\\1C00 - 196608
Zones\2\\1E05 - 196608
Zones\2\\2001 - 0
Zones\2\\2004 - 0
Zones\2\\1806 - 0
Zones\2\\1206 - 0
Zones\2\\1807 - 0
Zones\2\\1808 - 0
Zones\2\\2000 - 0
Zones\2\\2100 - 0
Zones\2\\2101 - 1
Zones\2\\2102 - 0
Zones\2\\2200 - 0
Zones\2\\2201 - 0
Zones\2\\2300 - 1
Zones\2\\1809 - 3
Zones\3 -
Zones\3\\ -
Zones\3\\DisplayName - Internet
Zones\3\\Description - This zone contains all Web sites you haven't placed in other zones
Zones\3\\Icon - inetcpl.cpl#001313
Zones\3\\CurrentLevel - 69632
Zones\3\\MinLevel - 69632
Zones\3\\RecommendedLevel - 69632
Zones\3\\Flags - 1
Zones\3\\1001 - 1
Zones\3\\1004 - 3
Zones\3\\1200 - 0
Zones\3\\1201 - 3
Zones\3\\1400 - 0
Zones\3\\1402 - 0
Zones\3\\1405 - 0
Zones\3\\1406 - 3
Zones\3\\1407 - 0
Zones\3\\1601 - 1
Zones\3\\1604 - 0
Zones\3\\1605 - 0
Zones\3\\1606 - 0
Zones\3\\1607 - 0
Zones\3\\1608 - 0
Zones\3\\1609 - 1
Zones\3\\1800 - 1
Zones\3\\1802 - 0
Zones\3\\1803 - 0
Zones\3\\1804 - 1
Zones\3\\1805 - 1
Zones\3\\1A00 - 131072
Zones\3\\1A02 - 0
Zones\3\\1A03 - 0
Zones\3\\1A04 - 3
Zones\3\\1A05 - 1
Zones\3\\1A06 - 0
Zones\3\\1A10 - 1
Zones\3\\1C00 - 65536
Zones\3\\1E05 - 131072
Zones\3\\2001 - 0
Zones\3\\2004 - 0
Zones\3\\1806 - 1
Zones\3\\1206 - 3
Zones\3\\1807 - 1
Zones\3\\1808 - 0
Zones\3\\2000 - 0
Zones\3\\2100 - 0
Zones\3\\2101 - 0
Zones\3\\2102 - 3
Zones\3\\2200 - 3
Zones\3\\2201 - 3
Zones\3\\2300 - 1
Zones\3\\1809 - 0
Zones\4 -
Zones\4\\ -
Zones\4\\DisplayName - Restricted sites
Zones\4\\Description - This zone contains Web sites that could potentially damage your computer or data.
Zones\4\\Icon - inetcpl.cpl#00004481
Zones\4\\CurrentLevel - 73728
Zones\4\\MinLevel - 73728
Zones\4\\RecommendedLevel - 73728
Zones\4\\Flags - 3
Zones\4\\1001 - 3
Zones\4\\1004 - 3
Zones\4\\1200 - 3
Zones\4\\1201 - 3
Zones\4\\1400 - 3
Zones\4\\1402 - 3
Zones\4\\1405 - 3
Zones\4\\1406 - 3
Zones\4\\1407 - 3
Zones\4\\1601 - 1
Zones\4\\1604 - 1
Zones\4\\1605 - 0
Zones\4\\1606 - 3
Zones\4\\1607 - 3
Zones\4\\1608 - 3
Zones\4\\1609 - 1
Zones\4\\1800 - 3
Zones\4\\1802 - 1
Zones\4\\1803 - 3
Zones\4\\1804 - 3
Zones\4\\1805 - 1
Zones\4\\1A00 - 65536
Zones\4\\1A02 - 3
Zones\4\\1A03 - 3
Zones\4\\1A04 - 3
Zones\4\\1A05 - 3
Zones\4\\1A06 - 3
Zones\4\\1A10 - 3
Zones\4\\1C00 - 0
Zones\4\\1E05 - 65536
Zones\4\\2001 - 3
Zones\4\\2004 - 3
Zones\4\\1806 - 3
Zones\4\\1206 - 3
Zones\4\\1807 - 1
Zones\4\\1808 - 0
Zones\4\\2000 - 3
Zones\4\\2100 - 3
Zones\4\\2101 - 3
Zones\4\\2102 - 3
Zones\4\\2200 - 3
Zones\4\\2201 - 3
Zones\4\\2300 - 3
Zones\4\\1809 - 0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI