This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unable to turn on Windows Firewall

134 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This topic has been reopened by request of the starter of this topic. Hi Junebug, Please post me a new HJT log, and describe any problems that you're still having.
the main problem that I'm having is that my computer seems to be running very slowly, and every now and again I get a message that my symantec autoprotect has been turned of.

here is log file from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:28:44 PM, on 6/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Trend Micro\HijackThis\junebug.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} - http://www.funnytaf.com/fun/installer/Install.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693090298
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693062538
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 10544 bytes


Thanks for your help.
Nothing much showing on your HJT log.

Run a scan with HJT and when finished check the following items (if found).

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} - http://www.funnytaf.com/fun/installer/Install.cab


Now close all open windows and click Fix Checked to remove them.

Let's look a little deeper into your computer and see if we can see anything.

Before running a new scan let's clean out your Temporary Files folders.

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Now download OTScanIt.exe by OldTimer to your Desktop.
  • Double-click on it to extract the files.
  • It will create a folder named OTScanIt on your desktop.
Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • Next check the following.
  • Scan all users
  • In the Drivers section click on Non-Microsoft.
  • In the Rootkit Search section click on Yes
  • Under Additional Scans click the checkboxes in front of the following items to select them:
  • Reg - Security Settings
  • Reg - Software Policy Settings
  • File - Additional Folder Scans
  • Evnt - Event Viewer Errors/Warnings (last 7 days)
[*]Do not change any other settings.

[*]Now click the Run Scan button on the toolbar.

[*]Let it run unhindered until it finishes.

[*]When the scan is complete Notepad will open with the report file loaded in it.

[*]Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.


Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].

If, after posting, the last line is not then the log is too big to fit into a single post and you will need to split it into multiple posts and post each separately.
OTScanIt logfile created on: 6/25/2008 12:18:41 AM
OTScanIt by OldTimer - Version 1.0.15.16	 Folder = C:\Documents and Settings\Rushelle Byfield\Desktop\OTScanIt
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
255.23 Mb Total Physical Memory | 82.28 Mb Available Physical Memory | 32.24% Memory free
808.11 Mb Paging File | 473.20 Mb Available in Paging File | 58.56% Paging File free
Paging file location(s): C:\pagefile.sys 576 576;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.20 Gb Total Space | 8.46 Gb Free Space | 22.75% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RB627
Current User Name: Rushelle Byfield
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users

[Processes - Non-Microsoft Only]
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe ->  [Ver =  | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr =	]
wltrysvc.exe -> %SystemRoot%\system32\WLTRYSVC.EXE ->  [Ver =  | Size = 20480 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr =	]
bcmwltry.exe -> %SystemRoot%\system32\BCMWLTRY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1253376 bytes | Modified Date = 11/1/2006 12:48:26 PM | Attr =	]
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe ->  [Ver =  | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr =	]
apoint.exe -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.123 | Size = 155648 bytes | Modified Date = 2/3/2004 11:32:16 AM | Attr =	]
atiptaxx.exe -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.14.10.5028 | Size = 335872 bytes | Modified Date = 7/30/2003 3:30:00 AM | Attr =	]
quickset.exe -> %ProgramFiles%\Dell\QuickSet\quickset.exe ->  [Ver = 1, 0, 0, 1 | Size = 487424 bytes | Modified Date = 3/5/2004 10:59:30 AM | Attr =	]
dsentry.exe -> %SystemRoot%\system32\DSentry.exe -> Dell - Advanced Desktop Engineering [Ver = 1, 0, 0, 0 | Size = 28672 bytes | Modified Date = 7/18/2002 12:18:06 AM | Attr =	]
apntex.exe -> %ProgramFiles%\Apoint\ApntEx.exe -> Alps Electric Co., Ltd. [Ver = 5.0.1.15 | Size = 45056 bytes | Modified Date = 2/27/2003 7:08:42 AM | Attr =	]
directcd.exe -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.3.4.21 | Size = 684032 bytes | Modified Date = 12/18/2002 2:28:00 AM | Attr =	]
lwbwheel.exe -> %ProgramFiles%\COMPAQ\CPQ650TP\Ver. 2.3\LwbWheel.exe ->  [Ver = 9.5.2.0 | Size = 438272 bytes | Modified Date = 5/19/2003 12:24:20 PM | Attr =	]
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 11/11/2004 8:11:54 AM | Attr =	]
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 PM | Attr =	]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 52840 bytes | Modified Date = 11/22/2006 6:38:28 AM | Attr =	]
vptray.exe -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 125632 bytes | Modified Date = 3/15/2007 8:49:02 AM | Attr =	]
winampa.exe -> %ProgramFiles%\Winamp\winampa.exe ->  [Ver =  | Size = 36352 bytes | Modified Date = 10/10/2007 2:28:32 PM | Attr =	]
qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4.5 | Size = 413696 bytes | Modified Date = 3/29/2008 1:37:20 PM | Attr =	]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/31/2008 12:36:40 AM | Attr =	]
wltray.exe -> %SystemRoot%\system32\WLTRAY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr =	]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 144784 bytes | Modified Date = 3/25/2008 4:28:02 AM | Attr =	]
exec.exe -> %ProgramFiles%\NetZero\exec.exe -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 5.0\Distillr\AcroTray.exe -> Adobe Systems Inc. [Ver = 5, 0, 0, 0 | Size = 49254 bytes | Modified Date = 3/15/2001 7:18:18 PM | Attr =	]
dlg.exe -> %ProgramFiles%\Digital Line Detect\DLG.exe -> BVRP Software [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 6/20/2003 5:43:00 PM | Attr =	]
hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 45.4.157.000 | Size = 258048 bytes | Modified Date = 11/5/2004 8:28:24 AM | Attr =	]
spuvolumewatcher.exe -> %ProgramFiles%\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe -> Sony Corporation [Ver = 1.2.00.12060 | Size = 344064 bytes | Modified Date = 12/6/2006 6:09:30 PM | Attr =	]
hpqgalry.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqgalry.exe -> Hewlett-Packard Co. [Ver = 045.004.157.000 | Size = 425984 bytes | Modified Date = 11/5/2004 8:36:46 AM | Attr =	]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 2/19/2008 1:16:30 AM | Attr =	]
basfipm.exe -> %SystemRoot%\system32\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.3 | Size = 77824 bytes | Modified Date = 4/18/2003 2:00:12 AM | Attr =	]
ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 169576 bytes | Modified Date = 11/22/2006 6:38:40 AM | Attr =	]
cvpnd.exe -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 1516584 bytes | Modified Date = 4/4/2007 5:18:08 AM | Attr =	]
defwatch.exe -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 31424 bytes | Modified Date = 3/15/2007 8:48:40 AM | Attr =	]
spbbcsvc.exe -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.3.0.2 | Size = 1160792 bytes | Modified Date = 1/11/2007 5:27:38 AM | Attr =	]
rtvscan.exe -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 1816768 bytes | Modified Date = 3/15/2007 8:48:50 AM | Attr =	]
ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 192104 bytes | Modified Date = 11/22/2006 6:38:32 AM | Attr =	]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/31/2008 12:36:30 AM | Attr =	]
exec.exe -> %ProgramFiles%\NetZero\exec.exe -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
x1exec.exe -> %ProgramFiles%\NetZero\qsacc\x1exec.exe -> NetZero, Inc. [Ver = 4.4.00 | Size = 1291736 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr =	]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.15.16 | Size = 397312 bytes | Modified Date = 6/20/2008 1:47:40 PM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 2/19/2008 1:16:30 AM | Attr =	]
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe ->  [Ver =  | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr =	]
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> Symantec Corporation [Ver = 3.4.1.234 | Size = 238968 bytes | Modified Date = 2/22/2008 7:02:53 AM | Attr =	]
(BAsfIpM) Broadcom ASF IP monitoring service v6.0.3 [Win32_Own | Auto | Running] -> %SystemRoot%\system32\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.3 | Size = 77824 bytes | Modified Date = 4/18/2003 2:00:12 AM | Attr =	]
(ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 192104 bytes | Modified Date = 11/22/2006 6:38:32 AM | Attr =	]
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 169576 bytes | Modified Date = 11/22/2006 6:38:40 AM | Attr =	]
(CVPND) Cisco Systems, Inc. VPN Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 1516584 bytes | Modified Date = 4/4/2007 5:18:08 AM | Attr =	]
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 31424 bytes | Modified Date = 3/15/2007 8:48:40 AM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 4:56:48 PM | Attr =	]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 2:41:10 PM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/31/2008 12:36:30 AM | Attr =	]
(LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_4.EXE -> Symantec Corporation [Ver = 3.4.1.234 | Size = 3220856 bytes | Modified Date = 2/22/2008 7:02:44 AM | Attr =	]
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\HPZipm12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 69632 bytes | Modified Date = 9/30/2004 1:14:36 AM | Attr =	]
(rpcapd) Remote Packet Capture Protocol v.0 (experimental) [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini -> File not found
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec AntiVirus\SavRoam.exe -> symantec [Ver = 10.1.6.6000 | Size = 116416 bytes | Modified Date = 3/15/2007 8:48:56 AM | Attr =	]
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.5.506 | Size = 214672 bytes | Modified Date = 2/13/2007 6:23:10 AM | Attr =	]
(SPBBCSvc) SPBBCSvc [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.3.0.2 | Size = 1160792 bytes | Modified Date = 1/11/2007 5:27:38 AM | Attr =	]
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 1816768 bytes | Modified Date = 3/15/2007 8:48:50 AM | Attr =	]
(Symantec RemoteAssist) Symantec RemoteAssist [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\Support Controls\ssrc.exe -> Symantec, Inc. [Ver = 6.9.2894.0 | Size = 394704 bytes | Modified Date = 1/29/2008 4:09:02 PM | Attr =	]
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe -> File not found

[Driver Services - Non-Microsoft Only]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\aliide.sys -> Acer Laboratories Inc. [Ver = 1.20 | Size = 5248 bytes | Modified Date = 8/18/2001 3:51:56 AM | Attr =	]
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\amdagp.sys -> Advanced Micro Devices, Inc. [Ver = 5.00 (xpsp_sp2_rtm.040803-2158) | Size = 43008 bytes | Modified Date = 8/4/2004 3:07:42 PM | Attr =	]
(ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Apfiltr.sys -> Alps Electric Co., Ltd. [Ver = 5.3.1.232 | Size = 94600 bytes | Modified Date = 8/22/2003 2:25:52 PM | Attr =	]
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\asc.sys -> Advanced System Products, Inc. [Ver = 2.9I-MS (XPClient.010817-1148) | Size = 26496 bytes | Modified Date = 8/18/2001 3:52:00 AM | Attr =	]
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\asc3550.sys -> Advanced System Products, Inc. [Ver = 3.1E-MS (XPClient.010817-1148) | Size = 14848 bytes | Modified Date = 8/18/2001 3:51:58 AM | Attr =	]
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6371 | Size = 587264 bytes | Modified Date = 7/30/2003 9:13:00 AM | Attr =	]
(b57w2k) Broadcom 570x Gigabit Integrated Controller [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\b57xp32.sys -> Broadcom Corporation [Ver = 6.64.0.0 built by: WinDDK | Size = 175360 bytes | Modified Date = 5/22/2003 1:47:12 PM | Attr = R  ]
(BASFND) BASFND [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\BASFND.sys -> Broadcom Corporation [Ver = 6.0.0.0 | Size = 6025 bytes | Modified Date = 4/25/2003 6:21:50 AM | Attr =	]
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\BCMWL5.SYS -> Broadcom Corporation [Ver = 4.100.15.5 | Size = 604928 bytes | Modified Date = 11/3/2006 2:34:00 PM | Attr =	]
(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\ComboFix\catchme.sys -> File not found
(Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdr4_xp.sys -> Sonic Solutions [Ver = 8.0.0.212  | Size = 2432 bytes | Modified Date = 8/29/2006 11:48:26 AM | Attr =	]
(Cdralw2k) Cdralw2k [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdralw2k.sys -> Sonic Solutions [Ver = 8.0.0.212  | Size = 2560 bytes | Modified Date = 8/29/2006 11:48:26 AM | Attr =	]
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Modified Date = 3/9/2004 2:55:50 AM | Attr =	]
(cdudf_xp) cdudf_xp [File_System | System | Running] -> %SystemRoot%\System32\drivers\cdudf_xp.sys -> Roxio [Ver = 5.3.4.21 built by: WinDDK | Size = 241152 bytes | Modified Date = 12/18/2002 2:27:32 AM | Attr =	]
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\cmdide.sys -> CMD Technology, Inc. [Ver = 2.0.7 (XPClient.010817-1148) | Size = 6656 bytes | Modified Date = 8/18/2001 3:51:54 AM | Attr =	]
(CVirtA) Cisco Systems VPN Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CVirtA.sys -> Cisco Systems, Inc. [Ver = 5.0.0.1 | Size = 5275 bytes | Modified Date = 1/19/2007 3:28:02 AM | Attr =	]
(CVPNDRVA) Cisco Systems Inc. IPSec Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\CVPNDRVA.sys -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 306295 bytes | Modified Date = 4/4/2007 5:17:08 AM | Attr =	]
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dac2w2k.sys -> Mylex Corporation [Ver = 6.00-21 (XPClient.010817-1148) | Size = 179584 bytes | Modified Date = 8/18/2001 3:52:16 AM | Attr =	]
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 3:07:17 PM | Attr =	]
(dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 3:07:16 PM | Attr =	]
(dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 4/20/2004 1:26:20 AM | Attr =	]
(DNE) Deterministic Network Enhancer Miniport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\dne2000.sys -> Deterministic Networks, Inc. [Ver = 3.20.5.16093 | Size = 127376 bytes | Modified Date = 2/1/2007 2:45:06 AM | Attr =	]
(dvd_2K) dvd_2K [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\Dvd_2k.sys -> Roxio [Ver = 5.3.4.59 | Size = 25898 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr =	]
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> Symantec Corporation [Ver = 107.4.1.2 | Size = 385072 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr =	]
(EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\el90xbc5.sys -> 3Com Corporation [Ver = 4.05.00.0000 | Size = 66591 bytes | Modified Date = 8/18/2001 2:11:06 AM | Attr =	]
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> Symantec Corporation [Ver = 107.4.1.2 | Size = 109616 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr =	]
(GEARAspiWDM) GEAR CDRom Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.00.07.03 | Size = 16168 bytes | Modified Date = 1/30/2008 2:01:28 AM | Attr =	]
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZid412.sys -> HP [Ver = 9, 0, 0, 0 | Size = 51120 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R  ]
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZipr12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 16496 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R  ]
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZius12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 21744 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R  ]
(HSFHWICH) HSFHWICH [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSFHWICH.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 | Size = 189056 bytes | Modified Date = 7/4/2003 10:59:06 AM | Attr = R  ]
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_DP.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 | Size = 1063936 bytes | Modified Date = 7/4/2003 10:55:48 AM | Attr = R  ]
(i81x) i81x [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\i81xnt5.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 161020 bytes | Modified Date = 8/4/2004 2:29:36 PM | Attr =	]
(iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12415 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr =	]
(iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12127 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr =	]
(iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv05nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 11775 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr =	]
(iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wsiintxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12063 bytes | Modified Date = 8/4/2004 2:29:47 PM | Attr =	]
(iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wvchntxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19455 bytes | Modified Date = 8/4/2004 2:29:49 PM | Attr =	]
(iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 29311 bytes | Modified Date = 8/4/2004 2:29:41 PM | Attr =	]
(iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19551 bytes | Modified Date = 8/4/2004 2:29:42 PM | Attr =	]
(iAimTV2) iAimTV2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\wATV03nt.sys -> File not found
(iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv04nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 33599 bytes | Modified Date = 8/4/2004 2:29:43 PM | Attr =	]
(iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wch7xxnt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 23615 bytes | Modified Date = 8/4/2004 2:29:45 PM | Attr =	]
(MCSTRM) MCSTRM [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\mcstrm.sys -> RealNetworks, Inc. [Ver = 5.0.2195.8 | Size = 8413 bytes | Modified Date = 10/12/2006 1:25:23 PM | Attr =	]
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\mdmxsdk.sys -> Conexant [Ver = 1.0.2.002 | Size = 11043 bytes | Modified Date = 4/10/2003 8:48:08 AM | Attr = R  ]
(mmc_2K) mmc_2K [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\Mmc_2k.sys -> Roxio [Ver = 5.3.4.59 | Size = 30630 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr =	]
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\mraid35x.sys -> American Megatrends Inc. [Ver = 6.19 (XPClient.010817-1148) | Size = 17280 bytes | Modified Date = 8/18/2001 3:52:12 AM | Attr =	]
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20080620.003\NAVENG.SYS -> Symantec Corporation [Ver = 20081.1.1.13 | Size = 89936 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr =	]
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20080620.003\NAVEX15.SYS -> Symantec Corporation [Ver = 20081.1.1.13 | Size = 856336 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr =	]
(O2SCBUS) O2Micro SmartCardBus Reader [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ozscr.sys -> O2Micro [Ver = 2, 7, 2, 8 | Size = 20579 bytes | Modified Date = 11/9/2002 9:13:50 AM | Attr =	]
(omci) OMCI WDM Device Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\omci.sys -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 17153 bytes | Modified Date = 2/14/2004 12:46:00 AM | Attr =	]
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 4/20/2004 1:30:36 AM | Attr =	]
(pwd_2k) pwd_2k [Kernel | System | Running] -> %SystemRoot%\System32\drivers\pwd_2K.sys -> Roxio [Ver = 5.3.4.59 | Size = 143834 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr =	]
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 8/16/2007 7:33:10 AM | Attr =	]
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql1080.sys -> QLogic Corporation [Ver = 3.04 | Size = 40320 bytes | Modified Date = 8/18/2001 3:52:20 AM | Attr =	]
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql12160.sys -> QLogic Corporation [Ver = 7.13.02 (W64) | Size = 45312 bytes | Modified Date = 8/18/2001 3:52:20 AM | Attr =	]
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql1280.sys -> QLogic Corporation [Ver = 7.13.01 (W2K) | Size = 49024 bytes | Modified Date = 8/18/2001 3:52:18 AM | Attr =	]
(SAVRT) SAVRT [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\savrt.sys -> Symantec Corporation [Ver = 9.7.2.3 | Size = 337592 bytes | Modified Date = 9/7/2006 3:41:20 AM | Attr =	]
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\Savrtpel.sys -> Symantec Corporation [Ver = 9.7.2.3 | Size = 54968 bytes | Modified Date = 9/7/2006 3:41:20 AM | Attr =	]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 7:25:53 PM | Attr =	]
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sisagp.sys -> Silicon Integrated Systems Corporation [Ver = 5.12.01.2010 (xpsp_sp2_rtm.040803-2158) | Size = 41088 bytes | Modified Date = 8/4/2004 3:07:42 PM | Attr =	]
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sparrow.sys -> Adaptec, Inc. [Ver = v2.0a (ReleaseBinaries.001205-1804) | Size = 19072 bytes | Modified Date = 8/18/2001 4:07:44 AM | Attr =	]
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCDrv.sys -> Symantec Corporation [Ver = 2.3.0.2 | Size = 390744 bytes | Modified Date = 1/11/2007 5:27:26 AM | Attr =	]
(STAC97) Audio Driver (WDM) - SigmaTel CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\STAC97.sys -> SigmaTel, Inc. [Ver = 5.10.3794 | Size = 220176 bytes | Modified Date = 4/26/2003 12:10:52 PM | Attr =	]
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc810.sys -> Symbios Logic Inc. [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 16256 bytes | Modified Date = 8/18/2001 4:07:34 AM | Attr =	]
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc8xx.sys -> LSI Logic [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 32640 bytes | Modified Date = 8/18/2001 4:07:36 AM | Attr =	]
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.2.1.1 | Size = 110952 bytes | Modified Date = 1/7/2008 2:30:08 PM | Attr =	]
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symredrv.sys -> Symantec Corporation [Ver = 6.0.5.506 | Size = 24720 bytes | Modified Date = 2/13/2007 6:22:36 AM | Attr =	]
(SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> Symantec Corporation [Ver = 6.0.5.506 | Size = 196752 bytes | Modified Date = 2/13/2007 6:22:40 AM | Attr =	]
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_hi.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 28384 bytes | Modified Date = 8/18/2001 4:07:40 AM | Attr =	]
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_u3.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 30688 bytes | Modified Date = 8/18/2001 4:07:42 AM | Attr =	]
(tmcomm) tmcomm [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 6/20/2008 4:37:52 AM | Attr =	]
(UdfReadr_xp) UdfReadr_xp [File_System | System | Running] -> %SystemRoot%\System32\drivers\udfreadr_xp.sys -> Roxio [Ver = 5.3.4.60 built by: WinDDK | Size = 206464 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr =	]
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ultra.sys -> Promise Technology, Inc. [Ver =  1.43 (Build 0603) | Size = 36736 bytes | Modified Date = 8/18/2001 3:52:22 AM | Attr =	]
(vsdatant) vsdatant [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\vsdatant.sys -> Zone Labs LLC [Ver = 5.5.062.011 | Size = 280344 bytes | Modified Date = 1/26/2005 9:22:20 PM | Attr =	]
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_CNXT.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 built by: WinDDK | Size = 631680 bytes | Modified Date = 7/4/2003 10:56:58 AM | Attr = R  ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
AdaptecDirectCD -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe ["C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"] -> Roxio [Ver = 5.3.4.21 | Size = 684032 bytes | Modified Date = 12/18/2002 2:28:00 AM | Attr =	]
Apoint -> %ProgramFiles%\Apoint\Apoint.exe [C:\Program Files\Apoint\Apoint.exe] -> Alps Electric Co., Ltd. [Ver = 5.5.101.123 | Size = 155648 bytes | Modified Date = 2/3/2004 11:32:16 AM | Attr =	]
ATIModeChange -> %SystemRoot%\system32\Ati2mdxx.exe [Ati2mdxx.exe] -> ATI Technologies, Inc. [Ver = 4.13.3 | Size = 28672 bytes | Modified Date = 9/5/2001 11:24:00 AM | Attr =	]
ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe [C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] -> ATI Technologies, Inc. [Ver = 6.14.10.5028 | Size = 335872 bytes | Modified Date = 7/30/2003 3:30:00 AM | Attr =	]
bascstray ->  [BascsTray.exe] -> File not found
Broadcom Wireless Manager UI -> %SystemRoot%\system32\WLTRAY.EXE [C:\WINDOWS\system32\WLTRAY.exe] -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr =	]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 104.0.13.2 | Size = 52840 bytes | Modified Date = 11/22/2006 6:38:28 AM | Attr =	]
ClubBox ->  [] -> File not found
Dell QuickSet -> %ProgramFiles%\Dell\QuickSet\quickset.exe [C:\Program Files\Dell\QuickSet\quickset.exe] ->  [Ver = 1, 0, 0, 1 | Size = 487424 bytes | Modified Date = 3/5/2004 10:59:30 AM | Attr =	]
DVDSentry -> %SystemRoot%\system32\DSentry.exe [C:\WINDOWS\System32\DSentry.exe] -> Dell - Advanced Desktop Engineering [Ver = 1, 0, 0, 0 | Size = 28672 bytes | Modified Date = 7/18/2002 12:18:06 AM | Attr =	]
HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 PM | Attr =	]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/31/2008 12:36:40 AM | Attr =	]
LWBMOUSE -> %ProgramFiles%\COMPAQ\CPQ650TP\Ver. 2.3\LwbWheel.exe [C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe] ->  [Ver = 9.5.2.0 | Size = 438272 bytes | Modified Date = 5/19/2003 12:24:20 PM | Attr =	]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\FirstStart.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 40960 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> Apple Inc. [Ver = 7.4.5 | Size = 413696 bytes | Modified Date = 3/29/2008 1:37:20 PM | Attr =	]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_06\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 144784 bytes | Modified Date = 3/25/2008 4:28:02 AM | Attr =	]
TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot] -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 11/11/2004 8:11:54 AM | Attr =	]
vptray -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 125632 bytes | Modified Date = 3/15/2007 8:49:02 AM | Attr =	]
WinampAgent -> %ProgramFiles%\Winamp\winampa.exe ["C:\Program Files\Winamp\winampa.exe"] ->  [Ver =  | Size = 36352 bytes | Modified Date = 10/10/2007 2:28:32 PM | Attr =	]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> 
IMAIL-> Installed = 1 -> 
MAPI-> Installed = 1 -> 
MSFS-> Installed = 1 -> 
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
NetZero_uoltray -> %ProgramFiles%\NetZero\exec.exe [C:\Program Files\NetZero\exec.exe regrun] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\Monitor.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 57344 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr =	]
Skype -> %ProgramFiles%\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] ->  [Ver =  | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr =	]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\ypager.exe [C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet] -> File not found
< Run [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
NetZero_uoltray -> %ProgramFiles%\NetZero\exec.exe [C:\Program Files\NetZero\exec.exe regrun] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\Monitor.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 57344 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr =	]
Skype -> %ProgramFiles%\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] ->  [Ver =  | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr =	]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\ypager.exe [C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet] -> File not found
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Acrobat Assistant.lnk -> %ProgramFiles%\Adobe\Acrobat 5.0\Distillr\AcroTray.exe -> Adobe Systems Inc. [Ver = 5, 0, 0, 0 | Size = 49254 bytes | Modified Date = 3/15/2001 7:18:18 PM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.1.0.2008042300 | Size = 29696 bytes | Modified Date = 4/23/2008 5:38:16 PM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\Digital Line Detect.lnk -> %ProgramFiles%\Digital Line Detect\DLG.exe -> BVRP Software [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 6/20/2003 5:43:00 PM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 45.4.157.000 | Size = 258048 bytes | Modified Date = 11/5/2004 8:28:24 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqthb08.exe -> Hewlett-Packard Co. [Ver = 045.004.157.000 | Size = 53248 bytes | Modified Date = 11/5/2004 8:50:52 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\VPN Client.lnk -> %SystemRoot%\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico ->  [Ver =  | Size = 6144 bytes | Modified Date = 7/13/2007 10:02:55 AM | Attr = R  ]
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> 
< Rushelle Byfield Startup Folder > -> C:\Documents and Settings\Rushelle Byfield\Start Menu\Programs\Startup -> 
%UserProfile%\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk -> %ProgramFiles%\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe -> Sony Corporation [Ver = 1.2.00.12060 | Size = 344064 bytes | Modified Date = 12/6/2006 6:09:30 PM | Attr =	]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Qualcomm\Eudora\EuShlExt.dll [Eudora's Shell Extension] -> File not found
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll ->  [Ver =  | Size = 86016 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr =	]
NavLogon -> %SystemRoot%\system32\NavLogon.dll -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 43712 bytes | Modified Date = 3/15/2007 8:49:14 AM | Attr =	]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> 
< CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> ->
*DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup -> 
SCSI miniport ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\drivers\cdrom.sys [System32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 8/4/2004 2:59:52 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 -> 
*AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable -> 
NEC	 MBR-7	->  -> File not found
NEC	 MBR-7.4  ->  -> File not found
PIONEER CHANGR DRM-1804X ->  -> File not found
PIONEER CD-ROM DRM-6324X ->  -> File not found
PIONEER CD-ROM DRM-624X  ->  -> File not found
TORiSAN CD-ROM CDR_C36 ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomHL-DT-ST_RW/DVD_GCC-4243N_______________A102____\5&18c802ac&0&0.0.0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 1 -> 
< Drives - Autoruns > ->  -> 
AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] ->  [Ver =  | Size = 0 bytes | Modified Date = 4/20/2004 1:32:30 AM | Attr =	]
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://search.msn.com/spbasic.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.google.com -> 
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie -> 
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.google.com/ -> 
HKEY_CURRENT_USER\: SearchURL\\ -> http://my.netzero.net/s/search?r=minisearch[Reg Error: Value provider does not exist or could not be read.] -> 
HKEY_CURRENT_USER\: URLSearchHooks\\{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\SearchEnh1.dll [URLSearchHook Class] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 266240 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> 
HKEY_USERS\.DEFAULT\: Main\\Default_Page_URL -> http://www.dell.com -> 
HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> 
HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> 
HKEY_USERS\S-1-5-18\: Main\\Default_Page_URL -> http://www.dell.com -> 
HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> 
HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> 
HKEY_USERS\S-1-5-19\: Main\\Search Bar -> http://search.msn.com/spbasic.htm -> 
HKEY_USERS\S-1-5-19\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\S-1-5-19\: Main\\Start Page -> http://securityresponse.symantec.com/avcenter/fix_homepage -> 
HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> 
HKEY_USERS\S-1-5-20\: Main\\Search Bar -> http://search.msn.com/spbasic.htm -> 
HKEY_USERS\S-1-5-20\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\S-1-5-20\: Main\\Start Page -> http://securityresponse.symantec.com/avcenter/fix_homepage -> 
HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 -> 
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Start Page -> http://www.google.com/ -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: SearchURL\\ -> http://my.netzero.net/s/search?r=minisearch[Reg Error: Value provider does not exist or could not be read.] -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: URLSearchHooks\\{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\SearchEnh1.dll [URLSearchHook Class] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 266240 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 8397 domain(s) found. -> 
free_aol.com [http] -> Trusted sites -> 
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 8397 domain(s) found. -> 
free_aol.com [http] -> Trusted sites -> 
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{52706EF7-D7A2-49AD-A615-E903858CF284} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\qsacc\X1IEBHO.dll [Pop-up Blocker] -> NetZero, Inc. [Ver = 4.4.00 | Size = 211456 bytes | Modified Date = 6/5/2008 6:57:20 AM | Attr =	]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 509328 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
{D0943516-5076-4020-A3B5-AEFAF26AB263} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> Veoh Networks Inc [Ver = 1.0.1.6 | Size = 352256 bytes | Modified Date = 4/2/2008 8:23:42 AM | Attr =	]
{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM Toolbar\AIMBar.dll [AIM Search] -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr =	]
WebBrowser\\{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
WebBrowser\\{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\Toolbar\ -> 
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM Toolbar\AIMBar.dll [AIM Search] -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr =	]
WebBrowser\\{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
WebBrowser\\{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr =	]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_06\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 509328 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}:Exec -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr =	]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
CmdMapping\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr =	]
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&AIM Search -> %ProgramFiles%\AIM Toolbar\AIMBar.dll -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr =	]
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
Display All Images with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr =	]
Display Image with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr =	]
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr =	]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr =	]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr =	]
CmdMapping\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr =	]
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&AIM Search -> %ProgramFiles%\AIM Toolbar\AIMBar.dll -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr =	]
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr =	]
Display All Images with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr =	]
Display Image with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr =	]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
Extension\.spop -> %ProgramFiles%\Internet Explorer\plugins\NPDocBox.dll [] -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 1/31/2001 3:56:24 AM | Attr =	]
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{3FF1B4F1-1FA8-429C-8A84-040A7A38E583} ->	(Dell Wireless 1350 WLAN Mini-PCI Card) -> 
{5CD7EE64-2BA9-4C26-B1DB-468B5D6465F6} ->	(Broadcom 570x Gigabit Integrated Controller) -> 
{84D269EC-098C-482A-963C-F2B1548430A4} ->	() -> 
< Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 
shell -> shell protocol not assigned -> 
< Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 
shell -> shell protocol not assigned -> 
< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 
shell -> shell protocol not assigned -> 
< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> 
shell -> shell protocol not assigned -> 
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab[CKAVWebScan Object] -> 
{33564D57-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[Reg Error: Key does not exist or could not be opened.] -> 
{44990301-3C9D-426D-81DF-AAB636FA4345}[HKEY_LOCAL_MACHINE] -> https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab[Symantec Script Runner Class] -> 
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211693090298[WUWebControl Class] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1211693062538[MUWebControl Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] -> 
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> 
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> 
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 
< Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\\.Owner -> {205FF73B-CA67-11D5-99DD-444553540012} -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\\{205FF73B-CA67-11D5-99DD-444553540012} ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\\.Owner -> {44990301-3C9D-426D-81DF-AAB636FA4345} -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\\{44990301-3C9D-426D-81DF-AAB636FA4345} ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\\.Owner -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\.Owner -> Unknown Owner -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\{6414512B-B978-451D-A0D8-FCFDF33E833C} ->  -> 


[Registry - Additional Scans - Non-Microsoft Only]
< Security Settings > -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Background Intelligent Transfer Service -> 
*DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> 
Rpcss -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 1:39:49 PM | Attr =	]
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions -> 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 68 E3 0C 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00  [binary data] -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> %SystemRoot%\system32\qmgr.dll [%systemroot%\system32\qmgr.dll] -> Microsoft Corporation [Ver = 6.6.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 382464 bytes | Modified Date = 8/4/2004 4:56:44 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security -> [Binary data over 100 bytes] -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\0 -> Root\LEGACY_BITS\0000 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 1539 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 4:56:42 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 4:56:56 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 4:56:56 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Skype\Phone\Skype.exe -> %ProgramFiles%\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] ->  [Ver =  | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Veoh Networks\Veoh\VeohClient.exe -> %ProgramFiles%\Veoh Networks\Veoh\VeohClient.exe [C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client] -> Veoh Networks [Ver = 3.9.1.1165 | Size = 3587120 bytes | Modified Date = 4/2/2008 8:35:26 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> [Binary data over 100 bytes] -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{54134CC3-1080-4F43-BBF1-6FCDDF2AE5A1} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{BC18CA29-7195-4E27-8AB6-FC0A8A02EC5C} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{D5DD5E9F-A4F0-4E0A-921C-CBE66B4380EA} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{3FF1B4F1-1FA8-429C-8A84-040A7A38E583} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{C8FC09D7-2DCE-4176-AE3B-6C08F3C82988} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{84D269EC-098C-482A-963C-F2B1548430A4} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 4:56:46 PM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> 
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\\NoSplash -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventAutoRun -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\EnableAdminTSRemote -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\\NonBestEffortLimit -> -5 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\PortRange\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\PortRange\\Enabled -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> -> 
*ExecutableTypes* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\ExecutableTypes -> 
ADE ->  -> File not found
ADP ->  -> File not found
BAS ->  -> File not found
BAT ->  -> File not found
CHM ->  -> File not found
CMD -> %SystemRoot%\system32\cmd.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 388608 bytes | Modified Date = 8/4/2004 4:56:48 PM | Attr =	]
COM ->  -> File not found
CPL ->  -> File not found
CRT ->  -> File not found
EXE ->  -> File not found
HLP ->  -> File not found
HTA ->  -> File not found
INF ->  -> File not found
INS ->  -> File not found
ISP ->  -> File not found
LNK ->  -> File not found
MDB ->  -> File not found
MDE ->  -> File not found
MSC ->  -> File not found
MSI -> %SystemRoot%\system32\msi.dll -> Microsoft Corporation [Ver = 3.1.4000.4039 | Size = 2854400 bytes | Modified Date = 4/19/2007 1:12:23 AM | Attr =	]
MSP ->  -> File not found
MST ->  -> File not found
OCX ->  -> File not found
PCD ->  -> File not found
PIF ->  -> File not found
REG -> %SystemRoot%\system32\reg.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50176 bytes | Modified Date = 8/4/2004 4:56:55 PM | Attr =	]
SCR ->  -> File not found
SHS ->  -> File not found
URL -> %SystemRoot%\system32\url.dll -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 37888 bytes | Modified Date = 8/4/2004 4:56:46 PM | Attr =	]
VB ->  -> File not found
WSC ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\TransparentEnabled -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\DefaultLevel -> 262144 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\AuthenticodeEnabled -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\PolicyScope -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\Description -> Stop the download of this file -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\FriendlyName -> Mdac11.cab -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\HashAlg -> 32771 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemData -> 5E AB 30 4F 95 7A 49 89 6A 00 6C 1C 31 15 40 15  [binary data] -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\LastModified ->  -> 
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemSize -> 
̋ ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\Description -> Stop the download of this file -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\FriendlyName -> mdac20.cab -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\HashAlg -> 32771 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemData -> 67 B0 D4 8B 34 3A 3F D3 BC E9 DC 64 67 04 F3 94  [binary data] -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\LastModified ->  -> 
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemSize -> 
ȅ ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\Description -> Stop the download of this file -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\FriendlyName -> mdac20_a.cab -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\HashAlg -> 32771 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemData -> 32 78 02 DC FE F8 C8 93 DC 8A B0 06 DD 84 7D 1D  [binary data] -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\LastModified ->  -> 
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemSize -> 
Ζ ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\Description -> Stop the download of this file -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\FriendlyName -> _msadc10.cab -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\HashAlg -> 32771 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemData -> BD 9A 2A DB 42 EB D8 56 0E 25 0E 4D F8 16 2F 67  [binary data] -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\LastModified ->  -> 
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemSize -> 
å ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\Description -> Stop the download of this file -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\FriendlyName -> msadc11.cab -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\HashAlg -> 32771 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemData -> 38 6B 08 5F 84 EC F6 69 D3 6B 95 6A 22 C0 1E 80  [binary data] -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\LastModified ->  -> 
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemSize -> 
Ų ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\Description ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\SaferFlags -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\ItemData -> %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\LastModified ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\\DoNotAllowXPSP2 -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\Terminal Services\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\DomainProfile\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\StandardProfile\ -> -> 
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\policies\ -> 
HKEY_CURRENT_USER\Software\Policies\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\AppCompat\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\ -> -> 
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\\DisableCMD -> 0 -> 
< Software Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\policies\ -> 
HKEY_USERS\.DEFAULT\Software\Policies\ -> ->
HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\ -> -> 
< Software Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\policies\ -> 
HKEY_USERS\S-1-5-18\Software\Policies\ -> ->
HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\ -> -> 
< Software Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\policies\ -> 
HKEY_USERS\S-1-5-19\Software\Policies\ -> ->
HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\ -> -> 
< Software Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\policies\ -> 
HKEY_USERS\S-1-5-20\Software\Policies\ -> ->
HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\ -> -> 
< Software Policy Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\policies\ -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Internet Explorer\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\AppCompat\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\System\ -> -> 
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\System\\DisableCMD -> 0 -> 
< EventViewer Logs > -> Errors and Warnings -> Description
Application - Warning - 6/18/2008 11:20:24 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/19/2008 10:11:12 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/19/2008 10:39:22 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryAlexaRelatedzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDCONzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploitzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit10zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit11zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit12zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit13zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit14zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit15zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit16zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit17zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit18zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit19zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit20zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit21zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit22zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit23zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit24zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit25zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit26zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit27zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit28zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit29zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit30zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit31zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit32zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit33zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit34zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit35zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit36zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit37zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit38zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit39zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit4zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit40zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit41zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit42zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit43zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit44zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit45zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit46zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit47zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit48zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit49zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit5zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit50zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit51zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit52zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit53zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit54zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit55zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit56zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit57zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit58zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit59zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit6zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit60zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit61zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit62zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit63zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit64zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit7zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit8zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryDSOExploit9zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryErrorGuardzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryErrorGuard1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryErrorGuard2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMaxSearchzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabledzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled4zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled5zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled6zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled7zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled8zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterFirewallDisabledzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryMicrosoftWindowsSecurityCenterFirewallDisabled1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryNoAdwarezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryNoAdware1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryNoAdware2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryNoAdware3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryNurechzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterAntiVirusDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterAntiVirusOverridezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterFirewallDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterFirewallOverridezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterSPUpdatezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search  DestroyRecoveryWindowsSecurityCenterUpdateDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:03:09 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 1 files inside Ci386softbarin due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:41:18 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 41 files inside CProgram FilesLavasoftAd-Aware SE PersonalSkinsAd-Aware SE defaultask due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:53:15 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP797A0210503exe due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:53:36 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 8 files inside CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP797A0210504exe due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 1:18:09 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/20/2008 3:27:14 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Error - 6/20/2008 3:44:05 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowssystem32cru629dat by Startup scan  Action Clean failed  Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/20/2008 3:45:10 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowssystem32cru629dat by Startup scan  Action Cleaned by Deletion  Action Description
Application - Warning - 6/20/2008 3:59:06 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Error - 6/20/2008 4:08:17 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowscru629dat by Startup scan  Action Clean failed  Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/20/2008 4:08:33 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowscru629dat by Startup scan  Action Cleaned by Deletion  Action Description
Application - Warning - 6/20/2008 8:28:19 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/21/2008 4:23:32 AM -> Computer Name = RB627 - User Name = (blank) - Source = ASP.NET 1.1.4322.0 -> Description = Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine To configure ASPNET to run in IIS please install or enable IIS and re-register ASPNET using aspnetregiisexe i
Application - Warning - 6/21/2008 5:23:34 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Error - 6/21/2008 5:36:40 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = SYMANTEC TAMPER PROTECTION ALERTTarget  CProgram FilesSymantec AntiVirusDoScanexeEvent Info  Terminate ProcessAction Taken  BlockedActor Process  CComboFixpvcfexe (PID 2788)Time  2008-06-21  0536
Application - Warning - 6/21/2008 5:45:04 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/21/2008 10:09:08 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Error - 6/21/2008 9:46:15 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 9:46:16 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 9:46:18 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 9:46:19 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan  Action Pending Side Effects Analysis  Access denied  Action Description
Application - Error - 6/21/2008 9:47:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan  Action Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/21/2008 9:47:33 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File cQooBoxquarantineCwindowssystem32winivstrexevir by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 9:47:33 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan  Action Quarantine succeeded  Access denied  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 9:58:21 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan  Action Pending Side Effects Analysis  Access denied  Action Description
Application - Error - 6/21/2008 10:00:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan  Action Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/21/2008 10:00:19 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP808A0219054exe by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:00:20 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan  Action Quarantine succeeded  Access denied  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:00:20 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan  Action Pending Side Effects Analysis  Access denied  Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:03:07 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan  Action Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/21/2008 10:03:11 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP809A0219076exe by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:03:11 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan  Action Quarantine succeeded  Access denied  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:04:46 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan  Action Pending Side Effects Analysis  Access denied  Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan  Action Cleaned by Deletion  Action Description
Application - Error - 6/21/2008 10:06:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan  Action Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/21/2008 10:06:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP810A0219101exe by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:52 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP811A0220100exe by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan  Action Quarantine succeeded  Access denied  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan  Action Pending Side Effects Analysis  Access denied  Action Description
Application - Error - 6/21/2008 10:08:00 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan  Action Quarantine failed  Action Description The file was left unchanged
Application - Error - 6/21/2008 10:08:01 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP813A0220696exe by Auto-Protect scan  Action Quarantine succeeded  Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:08:01 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan  Action Quarantine succeeded  Access denied  Action Description The file was quarantined successfully
Application - Warning - 6/22/2008 4:24:42 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/22/2008 7:21:45 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/23/2008 12:54:36 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/23/2008 8:14:00 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Error - 6/23/2008 3:11:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = Application Hang -> Description = Hanging application firefoxexe version 182008040413 hang module hungapp version 0000 hang address 0x00000000
Application - Error - 6/23/2008 3:11:58 PM -> Computer Name = RB627 - User Name = (blank) - Source = Application Hang -> Description = Fault bucket 713234062
Application - Warning - 6/24/2008 1:20:40 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/24/2008 4:47:56 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
Application - Warning - 6/24/2008 6:56:19 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description = 
System - Warning - 6/18/2008 2:27:27 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/18/2008 2:47:59 PM -> Computer Name = RB627 - User Name = (blank) - Source = Dhcp -> Description = Your computer was not able to renew its address from the network (from theDHCP Server) for the Network Card with network address 000F1FB683F3  The followingerror occurred 1223Your computer will continue to try and obtain an address on its own fromthe network address (DHCP) server
System - Warning - 6/18/2008 7:06:44 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/18/2008 11:19:38 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Error - 6/19/2008 2:36:31 PM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description = 
System - Warning - 6/19/2008 3:21:05 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/19/2008 3:23:49 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/19/2008 3:39:08 PM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description = 
System - Warning - 6/19/2008 10:00:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/19/2008 10:00:34 PM -> Computer Name = RB627 - User Name = (blank) - Source = Dhcp -> Description = Your computer was not able to renew its address from the network (from theDHCP Server) for the Network Card with network address 000F1FB683F3  The followingerror occurred 1223Your computer will continue to try and obtain an address on its own fromthe network address (DHCP) server
System - Error - 6/19/2008 10:00:39 PM -> Computer Name = RB627 - User Name = (blank) - Source = ipnathlp -> Description = The Network Address Translator (NAT) was unable to request an operationof the kernel-mode translation moduleThis may indicate misconfiguration insufficient resources oran internal errorThe data is the error code
System - Error - 6/20/2008 1:19:24 AM -> Computer Name = RB627 - User Name = (blank) - Source = sr -> Description = 
System - Error - 6/20/2008 3:32:59 AM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description = 
System - Error - 6/20/2008 3:32:59 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = DCOM -> Description = 
System - Error - 6/20/2008 3:33:59 AM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description = 
System - Error - 6/20/2008 3:35:12 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = DCOM -> Description = 
System - Warning - 6/20/2008 3:44:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/20/2008 4:35:14 AM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description = 
System - Warning - 6/20/2008 7:09:20 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/20/2008 3:49:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/20/2008 4:52:37 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 4:04:02 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 4:05:42 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 4:16:34 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:04:31 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:06:08 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:19:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:24:50 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:46:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 7:50:15 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 7:54:39 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 7:55:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description = 
System - Warning - 6/21/2008 8:52:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 8:58:54 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:02:24 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:02:56 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:03:02 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:13:58 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:20:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:48:32 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 9:57:37 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 10:08:04 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 12:22:08 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 4:50:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 4:50:42 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 5:06:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 6:37:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 7:52:03 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 7:53:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/21/2008 8:00:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:20:54 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:33:40 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:34:42 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 4:13:48 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 4:22:59 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 1:04:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 1:16:06 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 1:36:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 2:12:48 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 2:58:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:24:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:25:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/22/2008 3:25:57 PM -> Computer Name = RB627 - User Name = (blank) - Source = Server -> Description = The server could not bind to the transport DeviceNetBTTcpip5CD7EE64-2BA9-4C26-B1DB-468B5D6465F6
System - Warning - 6/22/2008 10:28:05 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/23/2008 7:01:21 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/23/2008 2:45:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/24/2008 1:19:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/24/2008 3:10:41 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 
System - Warning - 6/25/2008 12:19:00 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description = 


[Files/Folders - Created Within 30 days]
Binaries -> %SystemDrive%\Binaries ->  [Folder | Created Date = 6/4/2008 3:02:01 AM | Attr =	]
Boot.bak -> %SystemDrive%\Boot.bak ->  [Ver =  | Size = 211 bytes | Created Date = 6/21/2008 5:38:02 AM | Attr =	]
cmdcons -> %SystemDrive%\cmdcons ->  [Folder | Created Date = 6/21/2008 5:37:39 AM | Attr =	]
cmldr -> %SystemDrive%\cmldr ->  [Ver =  | Size = 260272 bytes | Created Date = 6/21/2008 5:37:50 AM | Attr =	]
ComboFix -> %SystemDrive%\ComboFix ->  [Folder | Created Date = 6/22/2008 4:22:22 AM | Attr =	]
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 267694080 bytes | Created Date = 6/20/2008 3:36:45 AM | Attr =  HS]
NetZeroInstaller -> %SystemDrive%\NetZeroInstaller ->  [Folder | Created Date = 6/11/2008 8:45:11 AM | Attr =	]
RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Created Date = 6/21/2008 7:57:32 PM | Attr =  HS]
BCMWLNPF.SYS -> %SystemRoot%\System32\drivers\BCMWLNPF.SYS -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 33664 bytes | Created Date = 6/12/2008 9:04:59 PM | Attr =	]
CDRBSDRV.SYS -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Created Date = 6/4/2008 3:00:53 AM | Attr =	]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Created Date = 6/21/2008 5:21:53 PM | Attr =	]
mbamcatchme.sys -> %SystemRoot%\System32\drivers\mbamcatchme.sys ->  [Ver =  | Size = 34296 bytes | Created Date = 6/21/2008 5:21:53 PM | Attr =	]
tmcomm.sys -> %SystemRoot%\System32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Created Date = 6/20/2008 4:39:56 AM | Attr =	]
UMDF -> %SystemRoot%\System32\drivers\UMDF ->  [Folder | Created Date = 6/7/2008 10:55:20 AM | Attr =	]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf ->  [Ver =  | Size = 0 bytes | Created Date = 6/7/2008 10:55:32 AM | Attr =  H ]
bcm1xsup.dll -> %SystemRoot%\System32\bcm1xsup.dll ->  [Ver =  | Size = 757760 bytes | Created Date = 6/12/2008 9:04:47 PM | Attr =	]
bcmwlpkt.dll -> %SystemRoot%\System32\bcmwlpkt.dll -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 69632 bytes | Created Date = 6/12/2008 9:04:54 PM | Attr =	]
java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 135168 bytes | Created Date = 6/22/2008 9:43:28 PM | Attr =	]
javacpl.cpl -> %SystemRoot%\System32\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 69632 bytes | Created Date = 6/22/2008 4:19:28 AM | Attr =	]
javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 135168 bytes | Created Date = 6/22/2008 9:43:29 PM | Attr =	]
javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 139264 bytes | Created Date = 6/22/2008 9:43:29 PM | Attr =	]
Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab ->  [Folder | Created Date = 6/21/2008 8:01:11 PM | Attr =	]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg ->  [Ver =  | Size = 11946 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr =	]
preflib.dll -> %SystemRoot%\System32\preflib.dll ->  [Ver =  | Size = 86016 bytes | Created Date = 6/12/2008 9:04:55 PM | Attr =	]
PreInstall -> %SystemRoot%\System32\PreInstall ->  [Folder | Created Date = 6/20/2008 3:02:05 AM | Attr =	]
Pvmjpg21.dll -> %SystemRoot%\System32\Pvmjpg21.dll -> Pegasus Imaging Corporation [Ver = 2.10.0.29 | Size = 319488 bytes | Created Date = 6/4/2008 3:01:00 AM | Attr =	]
QuickTime -> %SystemRoot%\System32\QuickTime ->  [Folder | Created Date = 6/4/2008 3:01:37 AM | Attr =	]
WLBCGCBPRO731.DLL -> %SystemRoot%\System32\WLBCGCBPRO731.DLL -> BCGSoft Ltd [Ver = 7, 31, 0, 0 | Size = 2129920 bytes | Created Date = 6/12/2008 9:04:48 PM | Attr =	]
WLTRAY.EXE -> %SystemRoot%\System32\WLTRAY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Created Date = 6/12/2008 9:04:51 PM | Attr =	]
wltrynt.dll -> %SystemRoot%\System32\wltrynt.dll -> Broadcom Corporation [Ver = 4.100.15.8 | Size = 44032 bytes | Created Date = 6/12/2008 9:04:54 PM | Attr =	]
WLTRYSVC.EXE -> %SystemRoot%\System32\WLTRYSVC.EXE ->  [Ver =  | Size = 20480 bytes | Created Date = 6/12/2008 9:04:49 PM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Created Date = 6/20/2008 3:01:57 AM | Attr =  H ]
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
aqucutuq.inf -> %SystemRoot%\aqucutuq.inf ->  [Ver =  | Size = 13916 bytes | Created Date = 6/19/2008 10:21:24 PM | Attr =	]
erdnt -> %SystemRoot%\erdnt ->  [Folder | Created Date = 6/21/2008 5:36:13 AM | Attr =	]
hucyl._dl -> %SystemRoot%\hucyl._dl ->  [Ver =  | Size = 12438 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr =	]
jadematy._sy -> %SystemRoot%\jadematy._sy ->  [Ver =  | Size = 13319 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr =	]
kiqyji.scr -> %SystemRoot%\kiqyji.scr ->  [Ver =  | Size = 12375 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr =	]
miwohej.lib -> %SystemRoot%\miwohej.lib ->  [Ver =  | Size = 18221 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr =	]
nypejuh.dll -> %SystemRoot%\nypejuh.dll ->  [Ver =  | Size = 15290 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr =	]
QTFont.for -> %SystemRoot%\QTFont.for ->  [Ver =  | Size = 1409 bytes | Created Date = 6/19/2008 3:55:04 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Created Date = 6/19/2008 3:55:04 PM | Attr =  H ]
TEMP -> %SystemRoot%\TEMP ->  [Folder | Created Date = 6/21/2008 5:19:23 PM | Attr =	]
ufokypi.exe -> %SystemRoot%\ufokypi.exe ->  [Ver =  | Size = 13228 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr =	]
ysej.bat -> %SystemRoot%\ysej.bat ->  [Ver =  | Size = 12076 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr =	]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat ->  [Ver =  | Size = 10127 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr =	]
Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab ->  [Folder | Created Date = 6/21/2008 8:01:16 PM | Attr =	]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes ->  [Folder | Created Date = 6/21/2008 5:21:54 PM | Attr =	]
McAfee -> %AllUsersProfile%\Application Data\McAfee ->  [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr =	]
NetZero -> %AllUsersProfile%\Application Data\NetZero ->  [Folder | Created Date = 6/11/2008 8:45:13 AM | Attr =	]
SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor ->  [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr =	]
ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe ->  [Ver =  | Size = 16907 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr =	]
fijizojeqy.scr -> %AppData%\fijizojeqy.scr ->  [Ver =  | Size = 19403 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr =	]
Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Created Date = 6/21/2008 5:21:59 PM | Attr =	]
OLYMPUS -> %AppData%\OLYMPUS ->  [Folder | Created Date = 6/4/2008 3:15:39 AM | Attr =	]
Qualcomm -> %AppData%\Qualcomm ->  [Folder | Created Date = 5/31/2008 11:43:53 PM | Attr =	]
SiteAdvisor -> %AppData%\SiteAdvisor ->  [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr =	]
subybalus.vbs -> %AppData%\subybalus.vbs ->  [Ver =  | Size = 13212 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr =	]
ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com ->  [Ver =  | Size = 15688 bytes | Created Date = 6/19/2008 10:21:20 PM | Attr =	]
NOS -> %UserProfile%\Local Settings\Application Data\NOS ->  [Folder | Created Date = 6/2/2008 9:51:04 PM | Attr =	]
ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib ->  [Ver =  | Size = 16217 bytes | Created Date = 6/19/2008 10:21:25 PM | Attr =	]
ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db ->  [Ver =  | Size = 10240 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr =	]
onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib ->  [Ver =  | Size = 10336 bytes | Created Date = 6/19/2008 10:21:26 PM | Attr =	]
yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban ->  [Ver =  | Size = 15937 bytes | Created Date = 6/19/2008 10:21:26 PM | Attr =	]
yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat ->  [Ver =  | Size = 12956 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr =	]
agnes.doc -> %UserProfile%\My Documents\agnes.doc ->  [Ver =  | Size = 19456 bytes | Created Date = 5/29/2008 1:22:47 AM | Attr =	]
Backup of blog.wbk -> %UserProfile%\My Documents\Backup of blog.wbk ->  [Ver =  | Size = 288768 bytes | Created Date = 6/21/2008 5:13:30 AM | Attr =	]
blog.doc -> %UserProfile%\My Documents\blog.doc ->  [Ver =  | Size = 303104 bytes | Created Date = 6/21/2008 5:13:30 AM | Attr =	]
Adobe Reader 7.0.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 7.0.lnk ->  [Ver =  | Size = 1740 bytes | Created Date = 6/2/2008 9:54:53 PM | Attr =	]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 696 bytes | Created Date = 6/21/2008 5:21:55 PM | Attr =	]
NetZero Internet.lnk -> %AllUsersProfile%\Desktop\NetZero Internet.lnk ->  [Ver =  | Size = 1649 bytes | Created Date = 6/11/2008 8:47:01 AM | Attr =	]
OLYMPUS Master.lnk -> %AllUsersProfile%\Desktop\OLYMPUS Master.lnk ->  [Ver =  | Size = 774 bytes | Created Date = 6/4/2008 3:02:26 AM | Attr =	]
edu01.pdf -> %UserProfile%\Desktop\edu01.pdf ->  [Ver =  | Size = 322314 bytes | Created Date = 6/11/2008 4:35:19 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\edu01.pdf:Zone.Identifier
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk ->  [Ver =  | Size = 1717 bytes | Created Date = 6/20/2008 1:53:39 AM | Attr =	]
Houding Request Form 08-09.doc -> %UserProfile%\Desktop\Houding Request Form 08-09.doc ->  [Ver =  | Size = 34304 bytes | Created Date = 5/28/2008 4:07:54 AM | Attr =	]
hrd01.pdf -> %UserProfile%\Desktop\hrd01.pdf ->  [Ver =  | Size = 132425 bytes | Created Date = 6/11/2008 5:09:27 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\hrd01.pdf:Zone.Identifier
Kobukuro All Singles Best Disk 1.zip -> %UserProfile%\Desktop\Kobukuro All Singles Best Disk 1.zip ->  [Ver =  | Size = 122004021 bytes | Created Date = 5/28/2008 3:24:05 PM | Attr =	]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes												 [Ver = 1.0.0.0			  | Size = 1665344 bytes | Created Date = 6/21/2008 5:02:56 PM | Attr =	]
OTScanIt -> %UserProfile%\Desktop\OTScanIt ->  [Folder | Created Date = 6/25/2008 12:17:16 AM | Attr =	]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe ->  [Ver =  | Size = 568483 bytes | Created Date = 6/25/2008 12:16:14 AM | Attr =	]
review.pdf -> %UserProfile%\Desktop\review.pdf ->  [Ver =  | Size = 4219863 bytes | Created Date = 6/8/2008 1:00:33 PM | Attr =	]
shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> %UserProfile%\Desktop\shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi ->  [Ver =  | Size = 317927018 bytes | Created Date = 6/22/2008 10:22:32 PM | Attr =	]
unem01.pdf -> %UserProfile%\Desktop\unem01.pdf ->  [Ver =  | Size = 334437 bytes | Created Date = 6/11/2008 4:48:30 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\unem01.pdf:Zone.Identifier
zeroincomeselfcertifyingstatement.pdf -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf ->  [Ver =  | Size = 1311577 bytes | Created Date = 6/11/2008 5:06:48 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf:Zone.Identifier
[G no Arashi] 2006.02.08 - ep18.avi -> %UserProfile%\Desktop\[G no Arashi] 2006.02.08 - ep18.avi ->  [Ver =  | Size = 231014400 bytes | Created Date = 6/16/2008 6:27:44 PM | Attr =	]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk ->  [Ver =  | Size = 1757 bytes | Created Date = 6/2/2008 9:54:52 PM | Attr =	]
ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl ->  [Ver =  | Size = 14741 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr =	]
exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys ->  [Ver =  | Size = 19255 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr =	]
qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat ->  [Ver =  | Size = 19448 bytes | Created Date = 6/19/2008 10:21:17 PM | Attr =	]
ziti.db -> %CommonProgramFiles%\ziti.db ->  [Ver =  | Size = 16038 bytes | Created Date = 6/19/2008 10:21:20 PM | Attr =	]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware ->  [Folder | Created Date = 6/21/2008 5:21:52 PM | Attr =	]
MSXML 4.0 -> %ProgramFiles%\MSXML 4.0 ->  [Folder | Created Date = 6/21/2008 4:17:07 AM | Attr =	]
OLYMPUS -> %ProgramFiles%\OLYMPUS ->  [Folder | Created Date = 6/4/2008 3:01:30 AM | Attr =	]
PIXELA -> %ProgramFiles%\PIXELA ->  [Folder | Created Date = 6/4/2008 2:59:45 AM | Attr =	]
Qualcomm -> %ProgramFiles%\Qualcomm ->  [Folder | Created Date = 5/31/2008 11:42:46 PM | Attr =	]
Trend Micro -> %ProgramFiles%\Trend Micro ->  [Folder | Created Date = 6/20/2008 1:53:39 AM | Attr =	]
Windows Media Connect 2 -> %ProgramFiles%\Windows Media Connect 2 ->  [Folder | Created Date = 6/7/2008 10:59:16 AM | Attr =	]

[Files/Folders - Modified Within 30 days]
Binaries -> %SystemDrive%\Binaries ->  [Folder | Modified Date = 6/4/2008 3:02:01 AM | Attr =	]
boot.ini -> %SystemDrive%\boot.ini ->  [Ver =  | Size = 281 bytes | Modified Date = 6/21/2008 5:38:03 AM | Attr = RHS]
cmdcons -> %SystemDrive%\cmdcons ->  [Folder | Modified Date = 6/21/2008 5:38:02 AM | Attr =	]
ComboFix -> %SystemDrive%\ComboFix ->  [Folder | Modified Date = 6/22/2008 4:22:37 AM | Attr =	]
Config.Msi -> %SystemDrive%\Config.Msi ->  [Folder | Modified Date = 6/22/2008 9:43:43 PM | Attr =  H ]
dell -> %SystemDrive%\dell ->  [Folder | Modified Date = 6/11/2008 2:49:46 PM | Attr =	]
Downloads -> %SystemDrive%\Downloads ->  [Folder | Modified Date = 6/11/2008 8:33:53 AM | Attr =	]
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 267694080 bytes | Modified Date = 6/24/2008 11:54:17 PM | Attr =  HS]
NetZeroInstaller -> %SystemDrive%\NetZeroInstaller ->  [Folder | Modified Date = 6/11/2008 8:47:02 AM | Attr =	]
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 6/21/2008 5:21:52 PM | Attr = R  ]
RECYCLER -> %SystemDrive%\RECYCLER ->  [Folder | Modified Date = 6/21/2008 7:57:32 PM | Attr =  HS]
System Volume Information -> %SystemDrive%\System Volume Information ->  [Folder | Modified Date = 6/22/2008 1:09:06 PM | Attr =  HS]
windows -> %SystemRoot% ->  [Folder | Modified Date = 6/25/2008 12:00:10 AM | Attr =	]
etc -> %SystemRoot%\System32\drivers\etc ->  [Folder | Modified Date = 6/21/2008 5:49:49 AM | Attr =	]
hosts -> %SystemRoot%\System32\drivers\etc\hosts ->  [Ver =  | Size = 27 bytes | Modified Date = 6/21/2008 5:49:49 AM | Attr =	]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Modified Date = 6/19/2008 5:47:58 PM | Attr =	]
mbamcatchme.sys -> %SystemRoot%\System32\drivers\mbamcatchme.sys ->  [Ver =  | Size = 34296 bytes | Modified Date = 6/19/2008 5:48:04 PM | Attr =	]
tmcomm.sys -> %SystemRoot%\System32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 6/20/2008 4:37:52 AM | Attr =	]
UMDF -> %SystemRoot%\System32\drivers\UMDF ->  [Folder | Modified Date = 6/11/2008 7:43:13 AM | Attr =	]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf ->  [Ver =  | Size = 0 bytes | Modified Date = 6/7/2008 10:55:32 AM | Attr =  H ]
CatRoot -> %SystemRoot%\System32\CatRoot ->  [Folder | Modified Date = 6/11/2008 8:07:54 AM | Attr =	]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 6/21/2008 5:17:37 PM | Attr =	]
Com -> %SystemRoot%\System32\Com ->  [Folder | Modified Date = 6/21/2008 4:39:36 AM | Attr =	]
config -> %SystemRoot%\System32\config ->  [Folder | Modified Date = 6/21/2008 5:44:14 AM | Attr =	]
d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat ->  [Ver =  | Size = 664 bytes | Modified Date = 5/26/2008 2:38:37 AM | Attr =	]
DllCache -> %SystemRoot%\System32\DllCache ->  [Folder | Modified Date = 6/21/2008 5:25:08 AM | Attr = RHS]
drivers -> %SystemRoot%\System32\drivers ->  [Folder | Modified Date = 6/21/2008 5:21:53 PM | Attr =	]
fntcache.dat -> %SystemRoot%\System32\fntcache.dat ->  [Ver =  | Size = 122928 bytes | Modified Date = 6/21/2008 5:25:16 AM | Attr =	]
FxsTmp -> %SystemRoot%\System32\FxsTmp ->  [Folder | Modified Date = 5/31/2008 4:05:17 PM | Attr =	]
Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab ->  [Folder | Modified Date = 6/21/2008 8:01:11 PM | Attr =	]
kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg ->  [Ver =  | Size = 11946 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr =	]
Logfiles -> %SystemRoot%\System32\Logfiles ->  [Folder | Modified Date = 6/11/2008 7:43:24 AM | Attr =	]
perfc009.dat -> %SystemRoot%\System32\perfc009.dat ->  [Ver =  | Size = 53838 bytes | Modified Date = 6/21/2008 5:55:25 AM | Attr =	]
perfh009.dat -> %SystemRoot%\System32\perfh009.dat ->  [Ver =  | Size = 382260 bytes | Modified Date = 6/21/2008 5:55:26 AM | Attr =	]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 441626 bytes | Modified Date = 6/21/2008 5:55:19 AM | Attr =	]
PreInstall -> %SystemRoot%\System32\PreInstall ->  [Folder | Modified Date = 6/20/2008 3:02:05 AM | Attr =	]
QuickTime -> %SystemRoot%\System32\QuickTime ->  [Folder | Modified Date = 6/4/2008 3:01:37 AM | Attr =	]
Restore -> %SystemRoot%\System32\Restore ->  [Folder | Modified Date = 6/22/2008 1:09:06 PM | Attr =	]
wbem -> %SystemRoot%\System32\wbem ->  [Folder | Modified Date = 6/11/2008 7:43:50 AM | Attr =	]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl ->  [Ver =  | Size = 2278 bytes | Modified Date = 6/15/2008 5:23:40 PM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Modified Date = 6/21/2008 4:54:44 AM | Attr =  H ]
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
AppPatch -> %SystemRoot%\AppPatch ->  [Folder | Modified Date = 6/11/2008 7:43:07 AM | Attr =	]
aqucutuq.inf -> %SystemRoot%\aqucutuq.inf ->  [Ver =  | Size = 13916 bytes | Modified Date = 6/19/2008 10:21:24 PM | Attr =	]
bootstat.dat -> %SystemRoot%\bootstat.dat ->  [Ver =  | Size = 2048 bytes | Modified Date = 6/24/2008 11:54:38 PM | Attr =   S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Modified Date = 6/21/2008 8:01:15 PM | Attr =   S]
erdnt -> %SystemRoot%\erdnt ->  [Folder | Modified Date = 6/22/2008 4:22:28 AM | Attr =	]
Help -> %SystemRoot%\Help ->  [Folder | Modified Date = 6/12/2008 9:05:44 PM | Attr =	]
hucyl._dl -> %SystemRoot%\hucyl._dl ->  [Ver =  | Size = 12438 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr =	]
imsins.BAK -> %SystemRoot%\imsins.BAK ->  [Ver =  | Size = 1374 bytes | Modified Date = 6/21/2008 4:55:11 AM | Attr =	]
inf -> %SystemRoot%\inf ->  [Folder | Modified Date = 6/21/2008 8:01:10 PM | Attr =  H ]
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 6/22/2008 9:45:04 PM | Attr =  HS]
jadematy._sy -> %SystemRoot%\jadematy._sy ->  [Ver =  | Size = 13319 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr =	]
kiqyji.scr -> %SystemRoot%\kiqyji.scr ->  [Ver =  | Size = 12375 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr =	]
miwohej.lib -> %SystemRoot%\miwohej.lib ->  [Ver =  | Size = 18221 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr =	]
msagent -> %SystemRoot%\msagent ->  [Folder | Modified Date = 6/21/2008 5:25:07 AM | Attr =	]
nypejuh.dll -> %SystemRoot%\nypejuh.dll ->  [Ver =  | Size = 15290 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 6/25/2008 12:16:33 AM | Attr =	]
QTFont.for -> %SystemRoot%\QTFont.for ->  [Ver =  | Size = 1409 bytes | Modified Date = 6/19/2008 3:55:04 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 6/24/2008 11:55:42 PM | Attr =  H ]
Registration -> %SystemRoot%\Registration ->  [Folder | Modified Date = 6/21/2008 4:23:35 AM | Attr =	]
security -> %SystemRoot%\security ->  [Folder | Modified Date = 6/11/2008 7:18:11 AM | Attr =	]
SoftwareDistribution -> %SystemRoot%\SoftwareDistribution ->  [Folder | Modified Date = 6/20/2008 1:30:23 AM | Attr =	]
system.ini -> %SystemRoot%\system.ini ->  [Ver =  | Size = 264 bytes | Modified Date = 6/21/2008 5:12:50 PM | Attr =	]
system32 -> %SystemRoot%\system32 ->  [Folder | Modified Date = 6/24/2008 3:46:23 PM | Attr =	]
TEMP -> %SystemRoot%\TEMP ->  [Folder | Modified Date = 6/24/2008 6:31:19 PM | Attr =	]
ufokypi.exe -> %SystemRoot%\ufokypi.exe ->  [Ver =  | Size = 13228 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr =	]
win.ini -> %SystemRoot%\win.ini ->  [Ver =  | Size = 685 bytes | Modified Date = 6/7/2008 10:59:44 AM | Attr =	]
WinSxS -> %SystemRoot%\WinSxS ->  [Folder | Modified Date = 6/21/2008 4:47:57 AM | Attr =	]
ysej.bat -> %SystemRoot%\ysej.bat ->  [Ver =  | Size = 12076 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr =	]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Modified Date = 6/18/2008 5:26:24 PM | Attr =	]
sa.dat -> %SystemRoot%\tasks\sa.dat ->  [Ver =  | Size = 6 bytes | Modified Date = 6/24/2008 11:54:51 PM | Attr =  H ]
C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help ->  [Folder | Modified Date = 11/18/2006 3:07:45 AM | Attr =	]
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat ->  [Ver =  | Size = 1307 bytes | Modified Date = 11/18/2006 3:07:45 AM | Attr =	]
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader ->  [Folder | Modified Date = 7/27/2004 1:33:11 AM | Attr =	]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 6740 bytes | Modified Date = 6/25/2008 12:01:01 AM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 6740 bytes | Modified Date = 6/25/2008 12:01:00 AM | Attr =	]
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
Adobe -> %AllUsersProfile%\Application Data\Adobe ->  [Folder | Modified Date = 6/2/2008 9:54:35 PM | Attr =	]
esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat ->  [Ver =  | Size = 10127 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr =	]
Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab ->  [Folder | Modified Date = 6/21/2008 8:01:16 PM | Attr =	]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes ->  [Folder | Modified Date = 6/21/2008 5:21:54 PM | Attr =	]
McAfee -> %AllUsersProfile%\Application Data\McAfee ->  [Folder | Modified Date = 6/22/2008 10:09:07 PM | Attr =	]
Microsoft -> %AllUsersProfile%\Application Data\Microsoft ->  [Folder | Modified Date = 5/28/2008 11:36:48 AM | Attr =   S]
NetZero -> %AllUsersProfile%\Application Data\NetZero ->  [Folder | Modified Date = 6/11/2008 8:45:14 AM | Attr =	]
SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor ->  [Folder | Modified Date = 6/22/2008 10:09:16 PM | Attr =	]
Symantec -> %AllUsersProfile%\Application Data\Symantec ->  [Folder | Modified Date = 6/20/2008 4:21:24 AM | Attr =	]
ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe ->  [Ver =  | Size = 16907 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr =	]
AdobeUM -> %AppData%\AdobeUM ->  [Folder | Modified Date = 6/2/2008 9:50:56 PM | Attr =	]
fijizojeqy.scr -> %AppData%\fijizojeqy.scr ->  [Ver =  | Size = 19403 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr =	]
Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Modified Date = 6/21/2008 5:21:59 PM | Attr =	]
Move Networks -> %AppData%\Move Networks ->  [Folder | Modified Date = 6/9/2008 3:13:10 AM | Attr =  H ]
OLYMPUS -> %AppData%\OLYMPUS ->  [Folder | Modified Date = 6/4/2008 3:15:39 AM | Attr =	]
Qualcomm -> %AppData%\Qualcomm ->  [Folder | Modified Date = 5/31/2008 11:43:53 PM | Attr =	]
SiteAdvisor -> %AppData%\SiteAdvisor ->  [Folder | Modified Date = 6/25/2008 12:03:46 AM | Attr =	]
Skype -> %AppData%\Skype ->  [Folder | Modified Date = 6/25/2008 12:16:21 AM | Attr =	]
subybalus.vbs -> %AppData%\subybalus.vbs ->  [Ver =  | Size = 13212 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr =	]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory ->  [Folder | Modified Date = 6/24/2008 11:56:16 PM | Attr =	]
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ->  [Ver =  | Size = 135680 bytes | Modified Date = 6/4/2008 3:53:25 AM | Attr =	]
ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com ->  [Ver =  | Size = 15688 bytes | Modified Date = 6/19/2008 10:21:20 PM | Attr =	]
Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft ->  [Folder | Modified Date = 6/7/2008 11:05:18 AM | Attr =	]
NOS -> %UserProfile%\Local Settings\Application Data\NOS ->  [Folder | Modified Date = 6/2/2008 9:55:39 PM | Attr =	]
ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib ->  [Ver =  | Size = 16217 bytes | Modified Date = 6/19/2008 10:21:25 PM | Attr =	]
ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db ->  [Ver =  | Size = 10240 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr =	]
onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib ->  [Ver =  | Size = 10336 bytes | Modified Date = 6/19/2008 10:21:26 PM | Attr =	]
yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban ->  [Ver =  | Size = 15937 bytes | Modified Date = 6/19/2008 10:21:26 PM | Attr =	]
yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat ->  [Ver =  | Size = 12956 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr =	]
agnes.doc -> %UserProfile%\My Documents\agnes.doc ->  [Ver =  | Size = 19456 bytes | Modified Date = 5/29/2008 1:22:47 AM | Attr =	]
Asempa -> %UserProfile%\My Documents\Asempa ->  [Folder | Modified Date = 6/4/2008 3:53:14 AM | Attr =	]
5 C:\Documents and Settings\Rushelle Byfield\My Documents\*.tmp files -> C:\Documents and Settings\Rushelle Byfield\My Documents\*.tmp -> 
Backup of blog.wbk -> %UserProfile%\My Documents\Backup of blog.wbk ->  [Ver =  | Size = 288768 bytes | Modified Date = 6/21/2008 8:29:50 PM | Attr =	]
blog.doc -> %UserProfile%\My Documents\blog.doc ->  [Ver =  | Size = 303104 bytes | Modified Date = 6/22/2008 4:17:27 AM | Attr =	]
Junior Year -> %UserProfile%\My Documents\Junior Year ->  [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr =	]
My Digital Editions -> %UserProfile%\My Documents\My Digital Editions ->  [Folder | Modified Date = 6/6/2008 4:01:11 PM | Attr =	]
My Media -> %UserProfile%\My Documents\My Media ->  [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr =	]
My Pictures -> %UserProfile%\My Documents\My Pictures ->  [Folder | Modified Date = 6/13/2008 4:46:55 PM | Attr = R  ]
My Skype Pictures -> %UserProfile%\My Documents\My Skype Pictures ->  [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr =	]
Adobe Reader 7.0.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 7.0.lnk ->  [Ver =  | Size = 1740 bytes | Modified Date = 6/2/2008 9:54:53 PM | Attr =	]
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk ->  [Ver =  | Size = 2137 bytes | Modified Date = 6/24/2008 3:32:37 PM | Attr =	]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 696 bytes | Modified Date = 6/21/2008 7:58:32 PM | Attr =	]
NetZero Internet.lnk -> %AllUsersProfile%\Desktop\NetZero Internet.lnk ->  [Ver =  | Size = 1649 bytes | Modified Date = 6/11/2008 8:47:02 AM | Attr =	]
OLYMPUS Master.lnk -> %AllUsersProfile%\Desktop\OLYMPUS Master.lnk ->  [Ver =  | Size = 774 bytes | Modified Date = 6/4/2008 3:02:26 AM | Attr =	]
DT music -> %UserProfile%\Desktop\DT music ->  [Folder | Modified Date = 5/28/2008 3:27:07 PM | Attr =	]
edu01.pdf -> %UserProfile%\Desktop\edu01.pdf ->  [Ver =  | Size = 322314 bytes | Modified Date = 6/11/2008 4:35:20 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\edu01.pdf:Zone.Identifier
EE -> %UserProfile%\Desktop\EE ->  [Folder | Modified Date = 6/4/2008 2:50:07 AM | Attr =	]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk ->  [Ver =  | Size = 1717 bytes | Modified Date = 6/20/2008 3:15:26 PM | Attr =	]
Houding Request Form 08-09.doc -> %UserProfile%\Desktop\Houding Request Form 08-09.doc ->  [Ver =  | Size = 34304 bytes | Modified Date = 5/28/2008 4:07:41 AM | Attr =	]
hrd01.pdf -> %UserProfile%\Desktop\hrd01.pdf ->  [Ver =  | Size = 132425 bytes | Modified Date = 6/11/2008 5:09:27 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\hrd01.pdf:Zone.Identifier
Japan Apps -> %UserProfile%\Desktop\Japan Apps ->  [Folder | Modified Date = 6/22/2008 9:55:26 PM | Attr =	]
Kobukuro All Singles Best Disk 1.zip -> %UserProfile%\Desktop\Kobukuro All Singles Best Disk 1.zip ->  [Ver =  | Size = 122004021 bytes | Modified Date = 5/28/2008 3:25:31 PM | Attr =	]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes												 [Ver = 1.0.0.0			  | Size = 1665344 bytes | Modified Date = 6/21/2008 5:02:56 PM | Attr =	]
Microsoft Word.lnk -> %UserProfile%\Desktop\Microsoft Word.lnk ->  [Ver =  | Size = 2473 bytes | Modified Date = 6/21/2008 5:12:36 AM | Attr =	]
New Folder -> %UserProfile%\Desktop\New Folder ->  [Folder | Modified Date = 6/11/2008 7:42:58 AM | Attr =	]
OTScanIt -> %UserProfile%\Desktop\OTScanIt ->  [Folder | Modified Date = 6/25/2008 12:17:16 AM | Attr =	]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe ->  [Ver =  | Size = 568483 bytes | Modified Date = 6/25/2008 12:16:10 AM | Attr =	]
Poland.doc -> %UserProfile%\Desktop\Poland.doc ->  [Ver =  | Size = 46080 bytes | Modified Date = 6/11/2008 10:21:56 AM | Attr =	]
review.pdf -> %UserProfile%\Desktop\review.pdf ->  [Ver =  | Size = 4219863 bytes | Modified Date = 6/8/2008 1:01:08 PM | Attr =	]
shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> %UserProfile%\Desktop\shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi ->  [Ver =  | Size = 317927018 bytes | Modified Date = 6/22/2008 11:07:58 PM | Attr =	]
unem01.pdf -> %UserProfile%\Desktop\unem01.pdf ->  [Ver =  | Size = 334437 bytes | Modified Date = 6/11/2008 4:48:31 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\unem01.pdf:Zone.Identifier
Unused Desktop Shortcuts -> %UserProfile%\Desktop\Unused Desktop Shortcuts ->  [Folder | Modified Date = 6/4/2008 3:46:10 AM | Attr =	]
Videos -> %UserProfile%\Desktop\Videos ->  [Folder | Modified Date = 5/31/2008 4:07:27 PM | Attr =	]
zeroincomeselfcertifyingstatement.pdf -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf ->  [Ver =  | Size = 1311577 bytes | Modified Date = 6/11/2008 5:06:48 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf:Zone.Identifier
[G no Arashi] 2006.02.08 - ep18.avi -> %UserProfile%\Desktop\[G no Arashi] 2006.02.08 - ep18.avi ->  [Ver =  | Size = 231014400 bytes | Modified Date = 6/16/2008 6:56:50 PM | Attr =	]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk ->  [Ver =  | Size = 1757 bytes | Modified Date = 6/2/2008 9:54:53 PM | Attr =	]
VPN Client.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\VPN Client.lnk ->  [Ver =  | Size = 2447 bytes | Modified Date = 6/24/2008 11:55:33 PM | Attr =	]
Picture Motion Browser Media Check Tool.lnk -> %UserProfile%\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk ->  [Ver =  | Size = 1983 bytes | Modified Date = 6/20/2008 3:53:55 PM | Attr =	]
Adobe -> %CommonProgramFiles%\Adobe ->  [Folder | Modified Date = 6/2/2008 9:54:16 PM | Attr =	]
ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl ->  [Ver =  | Size = 14741 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr =	]
exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys ->  [Ver =  | Size = 19255 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr =	]
qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat ->  [Ver =  | Size = 19448 bytes | Modified Date = 6/19/2008 10:21:17 PM | Attr =	]
Symantec Shared -> %CommonProgramFiles%\Symantec Shared ->  [Folder | Modified Date = 6/20/2008 4:21:23 AM | Attr =	]
System -> %CommonProgramFiles%\System ->  [Folder | Modified Date = 6/21/2008 4:40:36 AM | Attr =	]
ziti.db -> %CommonProgramFiles%\ziti.db ->  [Ver =  | Size = 16038 bytes | Modified Date = 6/19/2008 10:21:20 PM | Attr =	]

[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden files …
IPC error: 2 The system cannot find the file specified.
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\EE\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\senior slide\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Videos\Veoh\AppBackup\Images\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Videos\Veoh\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Random Stuff\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Junior Year\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Media\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Aim music\In My Own Words\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Aim music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Bismol\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\corazon\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\mytunes\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Other\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-18-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-21-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-27-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-1-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-10-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-17-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-7-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-13-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-13-2007(2)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-29-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-3-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\2-25-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\2-7-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-1-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-10-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-29-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-18-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-24-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-26-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-27-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\6-4-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\Japan 1\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\Nihon\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\other\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\ramification\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\silly 'ol me\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\The fam\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\weasels\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\ANAE\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\John Legend\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\Random\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2005-09 (Sep)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2005-12 (Dec)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-03 (Mar)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-09 (Sep)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-10 (Oct)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Skype Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Asempa\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\2006_10_02\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\Adobe_Acrobat_5.0\Thumbs.db:encryptable 0 bytes
scan completed successfully
hidden files: 65

< End of report >
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you're running Vista then right-click the program and choose Run as Administrator).
  • Copy/Paste the information in the codebox below into the pane where it says Paste fix here, then click the Run Fix button.
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> ClubBox -> []
[Files/Folders - Created Within 30 days]
NY -> kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg
NY -> aqucutuq.inf -> %SystemRoot%\aqucutuq.inf
NY -> hucyl._dl -> %SystemRoot%\hucyl._dl
NY -> jadematy._sy -> %SystemRoot%\jadematy._sy
NY -> kiqyji.scr -> %SystemRoot%\kiqyji.scr
NY -> miwohej.lib -> %SystemRoot%\miwohej.lib
NY -> nypejuh.dll -> %SystemRoot%\nypejuh.dll
NY -> QTFont.for -> %SystemRoot%\QTFont.for
NY -> QTFont.qfn -> %SystemRoot%\QTFont.qfn
NY -> TEMP -> %SystemRoot%\TEMP
NY -> ufokypi.exe -> %SystemRoot%\ufokypi.exe
NY -> ysej.bat -> %SystemRoot%\ysej.bat
[Files Created - Additional Folder Scans - Non-Microsoft Only]
NY -> esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat
NY -> ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe
NY -> subybalus.vbs -> %AppData%\subybalus.vbs
NY -> ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com
NY -> ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib
NY -> ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db
NY -> onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib
NY -> yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban
NY -> yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat
NY -> ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl
NY -> qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat
NY -> ziti.db -> %CommonProgramFiles%\ziti.db
[Files/Folders - Modified Within 30 days]
NY -> kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg
NY -> aqucutuq.inf -> %SystemRoot%\aqucutuq.inf
NY -> hucyl._dl -> %SystemRoot%\hucyl._dl
NY -> imsins.BAK -> %SystemRoot%\imsins.BAK
NY -> jadematy._sy -> %SystemRoot%\jadematy._sy
NY -> kiqyji.scr -> %SystemRoot%\kiqyji.scr
NY -> miwohej.lib -> %SystemRoot%\miwohej.lib
NY -> nypejuh.dll -> %SystemRoot%\nypejuh.dll
NY -> QTFont.for -> %SystemRoot%\QTFont.for
NY -> QTFont.qfn -> %SystemRoot%\QTFont.qfn
NY -> ufokypi.exe -> %SystemRoot%\ufokypi.exe
NY -> ysej.bat -> %SystemRoot%\ysej.bat
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
NY -> fijizojeqy.scr -> %AppData%\fijizojeqy.scr
NY -> ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com
NY -> ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib
NY -> ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db
NY -> onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib
NY -> yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban
NY -> yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat
NY -> ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl
NY -> exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys
NY -> qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat
NY -> ziti.db -> %CommonProgramFiles%\ziti.db
[Extra Files]
c:\windows\system32\cru629.dat
  • The fix should only take a very short time.
  • When it's completed either a message box will popup telling you that it's finished or you'll be asked to reboot to finish the fix.
    • If it's finished :-
    • Click the Ok button and Notepad will open with a log.
    • Post that information back here please.
  • If a reboot is required :-
    • Click the Yes button to reboot the machine.
    • After the reboot, OTScanIt will finish moving any files that could'nt be moved during the fix and NotePad will open with the final results.
    • Post that information back here please.

Next

Delete the backup files in Spybot S&D.

Your Symantec (Norton) was having a great deal of trouble with items you'd removed with Spybot, its scanner was detecting them as dangerous and kept trying (and failing) to delete them.

  • Launch Spybot S&D
  • Click on the Recovery button.
  • Check all items in the backup window.
  • Click on Purge selected items
  • A box will open asking if you want to purge the backups, answer Yes.

Norton/Symantec was also detecting encrypted backups made by Combofix, these should be deleted if you'd removed Combofix as I instructed.

If you haven't removed Combofix yet then do the following.

Let's clear out Combofix and the files/folders it created
  • Click Start > Run
  • Copy/Paste ComboFix /u into the Run box.
  • Click OK
  • The following items will now be processed.
    • Deletes the following files/folders:
    • ComboFix.exe
    • %system%\swxcacls.exe
    • %system%\swsc.exe
    • %system%\VFind.exe
    • %system%\moveex.exe
    • %system%\swreg.exe
    • %systemroot%\catchme.exe
    • \ComboFix
    • \Qoobox
    • \VundoFix Backups
    • \Deckard
    • \_OTMoveIt
    • %systemroot%\erdnt\subs
  • Resets the clock settings.
  • Hides file extensions
  • Hides System/Hidden files
  • Clears System Restore cache and create new Restore point

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Next

If you haven't removed Malwarebytes' Anti-Malware then.

  • Click on the Malwarebytes' Anti-Malware icon to launch the programme.
    • Click the Updates tab.
    • Click Check for Updates and allow the programme to download the latest definitions.
  • Click the Scanner tab.
    • Check Perform Full Scan.
    • Click Scan and wait for the scan to complete.
    • When the scan is complete, click OK, then Show Results.
    • Ensure all items are checked then click Remove Selected.
    • A box will pop-up telling you that files have been quarantined.
    • A log will pop-up.
  • Post the log in your next reply please.

You can also access the log by doing the following
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open

If you have removed it.

Please download Malwarebytes' Anti-Malware to your Desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
Then run the scan as directed above.

Summary of the logs I need from you in your next post:
  • OTScanIt log
  • MBAM log


Please post each log separately to prevent them being cut off by the forum post size limiter.

Let me know if you're still having any problems.
OTScanIt Log: [Registry - Non-Microsoft Only] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ClubBox deleted successfully. [Files/Folders - Created Within 30 days] C:\WINDOWS\System32\kiqeduh.reg moved successfully. C:\WINDOWS\aqucutuq.inf moved successfully. C:\WINDOWS\hucyl._dl moved successfully. C:\WINDOWS\jadematy._sy moved successfully. C:\WINDOWS\kiqyji.scr moved successfully. C:\WINDOWS\miwohej.lib moved successfully. C:\WINDOWS\nypejuh.dll moved successfully. C:\WINDOWS\QTFont.for moved successfully. C:\WINDOWS\QTFont.qfn moved successfully. C:\WINDOWS\TEMP folder moved successfully. C:\WINDOWS\ufokypi.exe moved successfully. C:\WINDOWS\ysej.bat moved successfully. [Files Created - Additional Folder Scans - Non-Microsoft Only] C:\Documents and Settings\All Users\Application Data\esabodomy.dat moved successfully. C:\Documents and Settings\All Users\Application Data\ydedotyne.exe moved successfully. C:\Documents and Settings\Rushelle Byfield\Application Data\subybalus.vbs moved successfully. C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ilafubopop.com moved successfully. C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ufuhuwokub.lib moved successfully. C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ujulis.db moved successfully. C:\Documents and Settings\All Users\Documents\onecybov.lib moved successfully. C:\Documents and Settings\All Users\Documents\yxivuseleh.ban moved successfully. C:\Documents and Settings\All Users\Documents\yzalape.bat moved successfully. C:\Program Files\Common Files\ebyjodav._dl moved successfully. C:\Program Files\Common Files\qymywyxa.bat moved successfully. C:\Program Files\Common Files\ziti.db moved successfully. [Files/Folders - Modified Within 30 days] File C:\WINDOWS\System32\kiqeduh.reg not found! File C:\WINDOWS\aqucutuq.inf not found! File C:\WINDOWS\hucyl._dl not found! C:\WINDOWS\imsins.BAK moved successfully. File C:\WINDOWS\jadematy._sy not found! File C:\WINDOWS\kiqyji.scr not found! File C:\WINDOWS\miwohej.lib not found! File C:\WINDOWS\nypejuh.dll not found! File C:\WINDOWS\QTFont.for not found! File C:\WINDOWS\QTFont.qfn not found! File C:\WINDOWS\ufokypi.exe not found! File C:\WINDOWS\ysej.bat not found! [Files Modified - Additional Folder Scans - Non-Microsoft Only] C:\Documents and Settings\Rushelle Byfield\Application Data\fijizojeqy.scr moved successfully. File C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ilafubopop.com not found! File C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ufuhuwokub.lib not found! File C:\Documents and Settings\Rushelle Byfield\Local Settings\Application Data\ujulis.db not found! File C:\Documents and Settings\All Users\Documents\onecybov.lib not found! File C:\Documents and Settings\All Users\Documents\yxivuseleh.ban not found! File C:\Documents and Settings\All Users\Documents\yzalape.bat not found! File C:\Program Files\Common Files\ebyjodav._dl not found! C:\Program Files\Common Files\exehiqudaw.sys moved successfully. File C:\Program Files\Common Files\qymywyxa.bat not found! File C:\Program Files\Common Files\ziti.db not found! [Extra Files] < c:\windows\system32\cru629.dat > File/Folder c:\windows\system32\cru629.dat not found. < End of fix log > OTScanIt by OldTimer - Version 1.0.15.16 fix logfile created on 06252008_141301
MBAM Log: Malwarebytes' Anti-Malware 1.18 Database version: 889 5:10:41 PM 6/25/2008 mbam-log-6-25-2008 (17-10-41).txt Scan type: Full Scan (C:\|) Objects scanned: 99833 Time elapsed: 1 hour(s), 3 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Things seem to be working ok now. One question though, everytime I reboot my computer it asks me if I want to start windows normally or run the recovery console, is there a reason that keeps happenning? Thanks for your help.
Hi Junebug,

Glad to hear things are running OK for you.

When we used Combofix earlier we installed Recovery Console, so you'll now have 2 boot options, your normal Windows or Recovery Console.

There's no need to make a choice when it shows on screen, if you don't click anything then after 2 seconds it will just boot into normal Windows. This shouldn't be too much of an inconvenience we hope.

If however at some time in the future your computer cannot boot for some reason, then Recovery Console can be used to repair your machine.

Having it will not affect the normal operation of your computer, and the amount of disk space it takes is very small. The only "downside" is the extra few seconds it takes to boot up.

We can remove it if you really want, but I would not recommend that you do so, it's a very handy thing to have if you have problems with your computer. You never know when it might come in handy.

I'll leave this thread open for 24 hours, so that if you want it removing you can let me know.


Let's remove the tools we used during the fix.


To remove all the tools we used and the files and folders they created do the following:

  • Start OTScanIt
    Click the CleanUp button
  • OTScanIt will download a small file from the Internet. If a security program or firewall warns you of this allow it to download.
  • OTScanIt will delete any tools downloaded and the files/folders they created and then ask you to reboot so it can remove itself. Click Yes.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI