Gary R
This topic has been reopened by request of the starter of this topic.
Hi Junebug,
Please post me a new HJT log, and describe any problems that you're still having.
134 min read
OTScanIt logfile created on: 6/25/2008 12:18:41 AM
OTScanIt by OldTimer - Version 1.0.15.16 Folder = C:\Documents and Settings\Rushelle Byfield\Desktop\OTScanIt
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
255.23 Mb Total Physical Memory | 82.28 Mb Available Physical Memory | 32.24% Memory free
808.11 Mb Paging File | 473.20 Mb Available in Paging File | 58.56% Paging File free
Paging file location(s): C:\pagefile.sys 576 576;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.20 Gb Total Space | 8.46 Gb Free Space | 22.75% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RB627
Current User Name: Rushelle Byfield
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
[Processes - Non-Microsoft Only]
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [Ver = | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr = ]
wltrysvc.exe -> %SystemRoot%\system32\WLTRYSVC.EXE -> [Ver = | Size = 20480 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr = ]
bcmwltry.exe -> %SystemRoot%\system32\BCMWLTRY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1253376 bytes | Modified Date = 11/1/2006 12:48:26 PM | Attr = ]
ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> [Ver = | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr = ]
apoint.exe -> %ProgramFiles%\Apoint\Apoint.exe -> Alps Electric Co., Ltd. [Ver = 5.5.101.123 | Size = 155648 bytes | Modified Date = 2/3/2004 11:32:16 AM | Attr = ]
atiptaxx.exe -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.14.10.5028 | Size = 335872 bytes | Modified Date = 7/30/2003 3:30:00 AM | Attr = ]
quickset.exe -> %ProgramFiles%\Dell\QuickSet\quickset.exe -> [Ver = 1, 0, 0, 1 | Size = 487424 bytes | Modified Date = 3/5/2004 10:59:30 AM | Attr = ]
dsentry.exe -> %SystemRoot%\system32\DSentry.exe -> Dell - Advanced Desktop Engineering [Ver = 1, 0, 0, 0 | Size = 28672 bytes | Modified Date = 7/18/2002 12:18:06 AM | Attr = ]
apntex.exe -> %ProgramFiles%\Apoint\ApntEx.exe -> Alps Electric Co., Ltd. [Ver = 5.0.1.15 | Size = 45056 bytes | Modified Date = 2/27/2003 7:08:42 AM | Attr = ]
directcd.exe -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.3.4.21 | Size = 684032 bytes | Modified Date = 12/18/2002 2:28:00 AM | Attr = ]
lwbwheel.exe -> %ProgramFiles%\COMPAQ\CPQ650TP\Ver. 2.3\LwbWheel.exe -> [Ver = 9.5.2.0 | Size = 438272 bytes | Modified Date = 5/19/2003 12:24:20 PM | Attr = ]
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 11/11/2004 8:11:54 AM | Attr = ]
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 PM | Attr = ]
ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 52840 bytes | Modified Date = 11/22/2006 6:38:28 AM | Attr = ]
vptray.exe -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 125632 bytes | Modified Date = 3/15/2007 8:49:02 AM | Attr = ]
winampa.exe -> %ProgramFiles%\Winamp\winampa.exe -> [Ver = | Size = 36352 bytes | Modified Date = 10/10/2007 2:28:32 PM | Attr = ]
qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4.5 | Size = 413696 bytes | Modified Date = 3/29/2008 1:37:20 PM | Attr = ]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/31/2008 12:36:40 AM | Attr = ]
wltray.exe -> %SystemRoot%\system32\WLTRAY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr = ]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 144784 bytes | Modified Date = 3/25/2008 4:28:02 AM | Attr = ]
exec.exe -> %ProgramFiles%\NetZero\exec.exe -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
acrotray.exe -> %ProgramFiles%\Adobe\Acrobat 5.0\Distillr\AcroTray.exe -> Adobe Systems Inc. [Ver = 5, 0, 0, 0 | Size = 49254 bytes | Modified Date = 3/15/2001 7:18:18 PM | Attr = ]
dlg.exe -> %ProgramFiles%\Digital Line Detect\DLG.exe -> BVRP Software [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 6/20/2003 5:43:00 PM | Attr = ]
hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 45.4.157.000 | Size = 258048 bytes | Modified Date = 11/5/2004 8:28:24 AM | Attr = ]
spuvolumewatcher.exe -> %ProgramFiles%\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe -> Sony Corporation [Ver = 1.2.00.12060 | Size = 344064 bytes | Modified Date = 12/6/2006 6:09:30 PM | Attr = ]
hpqgalry.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqgalry.exe -> Hewlett-Packard Co. [Ver = 045.004.157.000 | Size = 425984 bytes | Modified Date = 11/5/2004 8:36:46 AM | Attr = ]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 2/19/2008 1:16:30 AM | Attr = ]
basfipm.exe -> %SystemRoot%\system32\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.3 | Size = 77824 bytes | Modified Date = 4/18/2003 2:00:12 AM | Attr = ]
ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 169576 bytes | Modified Date = 11/22/2006 6:38:40 AM | Attr = ]
cvpnd.exe -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 1516584 bytes | Modified Date = 4/4/2007 5:18:08 AM | Attr = ]
defwatch.exe -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 31424 bytes | Modified Date = 3/15/2007 8:48:40 AM | Attr = ]
spbbcsvc.exe -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.3.0.2 | Size = 1160792 bytes | Modified Date = 1/11/2007 5:27:38 AM | Attr = ]
rtvscan.exe -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 1816768 bytes | Modified Date = 3/15/2007 8:48:50 AM | Attr = ]
ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 192104 bytes | Modified Date = 11/22/2006 6:38:32 AM | Attr = ]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/31/2008 12:36:30 AM | Attr = ]
exec.exe -> %ProgramFiles%\NetZero\exec.exe -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
x1exec.exe -> %ProgramFiles%\NetZero\qsacc\x1exec.exe -> NetZero, Inc. [Ver = 4.4.00 | Size = 1291736 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr = ]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.15.16 | Size = 397312 bytes | Modified Date = 6/20/2008 1:47:40 PM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 2/19/2008 1:16:30 AM | Attr = ]
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> [Ver = | Size = 323584 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr = ]
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> Symantec Corporation [Ver = 3.4.1.234 | Size = 238968 bytes | Modified Date = 2/22/2008 7:02:53 AM | Attr = ]
(BAsfIpM) Broadcom ASF IP monitoring service v6.0.3 [Win32_Own | Auto | Running] -> %SystemRoot%\system32\BAsfIpM.exe -> Broadcom Corp. [Ver = 6.0.3 | Size = 77824 bytes | Modified Date = 4/18/2003 2:00:12 AM | Attr = ]
(ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 192104 bytes | Modified Date = 11/22/2006 6:38:32 AM | Attr = ]
(ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe -> Symantec Corporation [Ver = 104.0.13.2 | Size = 169576 bytes | Modified Date = 11/22/2006 6:38:40 AM | Attr = ]
(CVPND) Cisco Systems, Inc. VPN Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Cisco Systems\VPN Client\cvpnd.exe -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 1516584 bytes | Modified Date = 4/4/2007 5:18:08 AM | Attr = ]
(DefWatch) Symantec AntiVirus Definition Watcher [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\DefWatch.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 31424 bytes | Modified Date = 3/15/2007 8:48:40 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 4:56:48 PM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 2:41:10 PM | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.2.9 | Size = 504104 bytes | Modified Date = 3/31/2008 12:36:30 AM | Attr = ]
(LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_4.EXE -> Symantec Corporation [Ver = 3.4.1.234 | Size = 3220856 bytes | Modified Date = 2/22/2008 7:02:44 AM | Attr = ]
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Stopped] -> %SystemRoot%\system32\HPZipm12.exe -> HP [Ver = 9, 0, 0, 0 | Size = 69632 bytes | Modified Date = 9/30/2004 1:14:36 AM | Attr = ]
(rpcapd) Remote Packet Capture Protocol v.0 (experimental) [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\WinPcap\rpcapd.exe -d -f %ProgramFiles%\WinPcap\rpcapd.ini -> File not found
(SavRoam) SavRoam [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec AntiVirus\SavRoam.exe -> symantec [Ver = 10.1.6.6000 | Size = 116416 bytes | Modified Date = 3/15/2007 8:48:56 AM | Attr = ]
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.5.506 | Size = 214672 bytes | Modified Date = 2/13/2007 6:23:10 AM | Attr = ]
(SPBBCSvc) SPBBCSvc [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCSvc.exe -> Symantec Corporation [Ver = 2.3.0.2 | Size = 1160792 bytes | Modified Date = 1/11/2007 5:27:38 AM | Attr = ]
(Symantec AntiVirus) Symantec AntiVirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec AntiVirus\Rtvscan.exe -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 1816768 bytes | Modified Date = 3/15/2007 8:48:50 AM | Attr = ]
(Symantec RemoteAssist) Symantec RemoteAssist [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\Support Controls\ssrc.exe -> Symantec, Inc. [Ver = 6.9.2894.0 | Size = 394704 bytes | Modified Date = 1/29/2008 4:09:02 PM | Attr = ]
(wltrysvc) Dell Wireless WLAN Tray Service [Win32_Own | Auto | Running] -> %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe -> File not found
[Driver Services - Non-Microsoft Only]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\aliide.sys -> Acer Laboratories Inc. [Ver = 1.20 | Size = 5248 bytes | Modified Date = 8/18/2001 3:51:56 AM | Attr = ]
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\amdagp.sys -> Advanced Micro Devices, Inc. [Ver = 5.00 (xpsp_sp2_rtm.040803-2158) | Size = 43008 bytes | Modified Date = 8/4/2004 3:07:42 PM | Attr = ]
(ApfiltrService) Alps Touch Pad Filter Driver for Windows 2000/XP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Apfiltr.sys -> Alps Electric Co., Ltd. [Ver = 5.3.1.232 | Size = 94600 bytes | Modified Date = 8/22/2003 2:25:52 PM | Attr = ]
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\asc.sys -> Advanced System Products, Inc. [Ver = 2.9I-MS (XPClient.010817-1148) | Size = 26496 bytes | Modified Date = 8/18/2001 3:52:00 AM | Attr = ]
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\asc3550.sys -> Advanced System Products, Inc. [Ver = 3.1E-MS (XPClient.010817-1148) | Size = 14848 bytes | Modified Date = 8/18/2001 3:51:58 AM | Attr = ]
(ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6371 | Size = 587264 bytes | Modified Date = 7/30/2003 9:13:00 AM | Attr = ]
(b57w2k) Broadcom 570x Gigabit Integrated Controller [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\b57xp32.sys -> Broadcom Corporation [Ver = 6.64.0.0 built by: WinDDK | Size = 175360 bytes | Modified Date = 5/22/2003 1:47:12 PM | Attr = R ]
(BASFND) BASFND [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\BASFND.sys -> Broadcom Corporation [Ver = 6.0.0.0 | Size = 6025 bytes | Modified Date = 4/25/2003 6:21:50 AM | Attr = ]
(BCM43XX) Dell Wireless WLAN Card Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\BCMWL5.SYS -> Broadcom Corporation [Ver = 4.100.15.5 | Size = 604928 bytes | Modified Date = 11/3/2006 2:34:00 PM | Attr = ]
(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\ComboFix\catchme.sys -> File not found
(Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdr4_xp.sys -> Sonic Solutions [Ver = 8.0.0.212 | Size = 2432 bytes | Modified Date = 8/29/2006 11:48:26 AM | Attr = ]
(Cdralw2k) Cdralw2k [Kernel | System | Running] -> %SystemRoot%\System32\drivers\cdralw2k.sys -> Sonic Solutions [Ver = 8.0.0.212 | Size = 2560 bytes | Modified Date = 8/29/2006 11:48:26 AM | Attr = ]
(cdrbsdrv) cdrbsdrv [Kernel | System | Running] -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Modified Date = 3/9/2004 2:55:50 AM | Attr = ]
(cdudf_xp) cdudf_xp [File_System | System | Running] -> %SystemRoot%\System32\drivers\cdudf_xp.sys -> Roxio [Ver = 5.3.4.21 built by: WinDDK | Size = 241152 bytes | Modified Date = 12/18/2002 2:27:32 AM | Attr = ]
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\cmdide.sys -> CMD Technology, Inc. [Ver = 2.0.7 (XPClient.010817-1148) | Size = 6656 bytes | Modified Date = 8/18/2001 3:51:54 AM | Attr = ]
(CVirtA) Cisco Systems VPN Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\CVirtA.sys -> Cisco Systems, Inc. [Ver = 5.0.0.1 | Size = 5275 bytes | Modified Date = 1/19/2007 3:28:02 AM | Attr = ]
(CVPNDRVA) Cisco Systems Inc. IPSec Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\CVPNDRVA.sys -> Cisco Systems, Inc. [Ver = 5.0.00.0340 | Size = 306295 bytes | Modified Date = 4/4/2007 5:17:08 AM | Attr = ]
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dac2w2k.sys -> Mylex Corporation [Ver = 6.00-21 (XPClient.010817-1148) | Size = 179584 bytes | Modified Date = 8/18/2001 3:52:16 AM | Attr = ]
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 3:07:17 PM | Attr = ]
(dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 3:07:16 PM | Attr = ]
(dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 4/20/2004 1:26:20 AM | Attr = ]
(DNE) Deterministic Network Enhancer Miniport [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\dne2000.sys -> Deterministic Networks, Inc. [Ver = 3.20.5.16093 | Size = 127376 bytes | Modified Date = 2/1/2007 2:45:06 AM | Attr = ]
(dvd_2K) dvd_2K [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\drivers\Dvd_2k.sys -> Roxio [Ver = 5.3.4.59 | Size = 25898 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr = ]
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> Symantec Corporation [Ver = 107.4.1.2 | Size = 385072 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr = ]
(EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\el90xbc5.sys -> 3Com Corporation [Ver = 4.05.00.0000 | Size = 66591 bytes | Modified Date = 8/18/2001 2:11:06 AM | Attr = ]
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> Symantec Corporation [Ver = 107.4.1.2 | Size = 109616 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr = ]
(GEARAspiWDM) GEAR CDRom Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.00.07.03 | Size = 16168 bytes | Modified Date = 1/30/2008 2:01:28 AM | Attr = ]
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZid412.sys -> HP [Ver = 9, 0, 0, 0 | Size = 51120 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R ]
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZipr12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 16496 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R ]
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZius12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 21744 bytes | Modified Date = 12/15/2004 1:07:44 AM | Attr = R ]
(HSFHWICH) HSFHWICH [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSFHWICH.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 | Size = 189056 bytes | Modified Date = 7/4/2003 10:59:06 AM | Attr = R ]
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_DP.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 | Size = 1063936 bytes | Modified Date = 7/4/2003 10:55:48 AM | Attr = R ]
(i81x) i81x [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\i81xnt5.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 161020 bytes | Modified Date = 8/4/2004 2:29:36 PM | Attr = ]
(iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12415 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr = ]
(iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12127 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr = ]
(iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wadv05nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 11775 bytes | Modified Date = 8/4/2004 2:29:37 PM | Attr = ]
(iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wsiintxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 12063 bytes | Modified Date = 8/4/2004 2:29:47 PM | Attr = ]
(iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wvchntxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 19455 bytes | Modified Date = 8/4/2004 2:29:49 PM | Attr = ]
(iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 29311 bytes | Modified Date = 8/4/2004 2:29:41 PM | Attr = ]
(iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 19551 bytes | Modified Date = 8/4/2004 2:29:42 PM | Attr = ]
(iAimTV2) iAimTV2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\DRIVERS\wATV03nt.sys -> File not found
(iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\watv04nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 33599 bytes | Modified Date = 8/4/2004 2:29:43 PM | Attr = ]
(iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\wch7xxnt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198 | Size = 23615 bytes | Modified Date = 8/4/2004 2:29:45 PM | Attr = ]
(MCSTRM) MCSTRM [Kernel | Auto | Running] -> %SystemRoot%\System32\drivers\mcstrm.sys -> RealNetworks, Inc. [Ver = 5.0.2195.8 | Size = 8413 bytes | Modified Date = 10/12/2006 1:25:23 PM | Attr = ]
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\mdmxsdk.sys -> Conexant [Ver = 1.0.2.002 | Size = 11043 bytes | Modified Date = 4/10/2003 8:48:08 AM | Attr = R ]
(mmc_2K) mmc_2K [Kernel | On_Demand | Running] -> %SystemRoot%\System32\drivers\Mmc_2k.sys -> Roxio [Ver = 5.3.4.59 | Size = 30630 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr = ]
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\mraid35x.sys -> American Megatrends Inc. [Ver = 6.19 (XPClient.010817-1148) | Size = 17280 bytes | Modified Date = 8/18/2001 3:52:12 AM | Attr = ]
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20080620.003\NAVENG.SYS -> Symantec Corporation [Ver = 20081.1.1.13 | Size = 89936 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr = ]
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20080620.003\NAVEX15.SYS -> Symantec Corporation [Ver = 20081.1.1.13 | Size = 856336 bytes | Modified Date = 6/18/2008 5:00:00 PM | Attr = ]
(O2SCBUS) O2Micro SmartCardBus Reader [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ozscr.sys -> O2Micro [Ver = 2, 7, 2, 8 | Size = 20579 bytes | Modified Date = 11/9/2002 9:13:50 AM | Attr = ]
(omci) OMCI WDM Device Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\omci.sys -> Dell Inc [Ver = 7, 1, 382, 0 | Size = 17153 bytes | Modified Date = 2/14/2004 12:46:00 AM | Attr = ]
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 4/20/2004 1:30:36 AM | Attr = ]
(pwd_2k) pwd_2k [Kernel | System | Running] -> %SystemRoot%\System32\drivers\pwd_2K.sys -> Roxio [Ver = 5.3.4.59 | Size = 143834 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr = ]
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 8/16/2007 7:33:10 AM | Attr = ]
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql1080.sys -> QLogic Corporation [Ver = 3.04 | Size = 40320 bytes | Modified Date = 8/18/2001 3:52:20 AM | Attr = ]
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql12160.sys -> QLogic Corporation [Ver = 7.13.02 (W64) | Size = 45312 bytes | Modified Date = 8/18/2001 3:52:20 AM | Attr = ]
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ql1280.sys -> QLogic Corporation [Ver = 7.13.01 (W2K) | Size = 49024 bytes | Modified Date = 8/18/2001 3:52:18 AM | Attr = ]
(SAVRT) SAVRT [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\savrt.sys -> Symantec Corporation [Ver = 9.7.2.3 | Size = 337592 bytes | Modified Date = 9/7/2006 3:41:20 AM | Attr = ]
(SAVRTPEL) SAVRTPEL [Kernel | System | Running] -> %ProgramFiles%\Symantec AntiVirus\Savrtpel.sys -> Symantec Corporation [Ver = 9.7.2.3 | Size = 54968 bytes | Modified Date = 9/7/2006 3:41:20 AM | Attr = ]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 7:25:53 PM | Attr = ]
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sisagp.sys -> Silicon Integrated Systems Corporation [Ver = 5.12.01.2010 (xpsp_sp2_rtm.040803-2158) | Size = 41088 bytes | Modified Date = 8/4/2004 3:07:42 PM | Attr = ]
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sparrow.sys -> Adaptec, Inc. [Ver = v2.0a (ReleaseBinaries.001205-1804) | Size = 19072 bytes | Modified Date = 8/18/2001 4:07:44 AM | Attr = ]
(SPBBCDrv) SPBBCDrv [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCDrv.sys -> Symantec Corporation [Ver = 2.3.0.2 | Size = 390744 bytes | Modified Date = 1/11/2007 5:27:26 AM | Attr = ]
(STAC97) Audio Driver (WDM) - SigmaTel CODEC [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\STAC97.sys -> SigmaTel, Inc. [Ver = 5.10.3794 | Size = 220176 bytes | Modified Date = 4/26/2003 12:10:52 PM | Attr = ]
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc810.sys -> Symbios Logic Inc. [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 16256 bytes | Modified Date = 8/18/2001 4:07:34 AM | Attr = ]
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\symc8xx.sys -> LSI Logic [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 32640 bytes | Modified Date = 8/18/2001 4:07:36 AM | Attr = ]
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.2.1.1 | Size = 110952 bytes | Modified Date = 1/7/2008 2:30:08 PM | Attr = ]
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symredrv.sys -> Symantec Corporation [Ver = 6.0.5.506 | Size = 24720 bytes | Modified Date = 2/13/2007 6:22:36 AM | Attr = ]
(SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> Symantec Corporation [Ver = 6.0.5.506 | Size = 196752 bytes | Modified Date = 2/13/2007 6:22:40 AM | Attr = ]
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_hi.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 28384 bytes | Modified Date = 8/18/2001 4:07:40 AM | Attr = ]
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\sym_u3.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 30688 bytes | Modified Date = 8/18/2001 4:07:42 AM | Attr = ]
(tmcomm) tmcomm [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 6/20/2008 4:37:52 AM | Attr = ]
(UdfReadr_xp) UdfReadr_xp [File_System | System | Running] -> %SystemRoot%\System32\drivers\udfreadr_xp.sys -> Roxio [Ver = 5.3.4.60 built by: WinDDK | Size = 206464 bytes | Modified Date = 7/27/2004 1:40:31 AM | Attr = ]
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\ultra.sys -> Promise Technology, Inc. [Ver = 1.43 (Build 0603) | Size = 36736 bytes | Modified Date = 8/18/2001 3:52:22 AM | Attr = ]
(vsdatant) vsdatant [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\vsdatant.sys -> Zone Labs LLC [Ver = 5.5.062.011 | Size = 280344 bytes | Modified Date = 1/26/2005 9:22:20 PM | Attr = ]
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_CNXT.sys -> Conexant Systems, Inc. [Ver = 6.02.09.02 built by: WinDDK | Size = 631680 bytes | Modified Date = 7/4/2003 10:56:58 AM | Attr = R ]
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
AdaptecDirectCD -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe ["C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"] -> Roxio [Ver = 5.3.4.21 | Size = 684032 bytes | Modified Date = 12/18/2002 2:28:00 AM | Attr = ]
Apoint -> %ProgramFiles%\Apoint\Apoint.exe [C:\Program Files\Apoint\Apoint.exe] -> Alps Electric Co., Ltd. [Ver = 5.5.101.123 | Size = 155648 bytes | Modified Date = 2/3/2004 11:32:16 AM | Attr = ]
ATIModeChange -> %SystemRoot%\system32\Ati2mdxx.exe [Ati2mdxx.exe] -> ATI Technologies, Inc. [Ver = 4.13.3 | Size = 28672 bytes | Modified Date = 9/5/2001 11:24:00 AM | Attr = ]
ATIPTA -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe [C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] -> ATI Technologies, Inc. [Ver = 6.14.10.5028 | Size = 335872 bytes | Modified Date = 7/30/2003 3:30:00 AM | Attr = ]
bascstray -> [BascsTray.exe] -> File not found
Broadcom Wireless Manager UI -> %SystemRoot%\system32\WLTRAY.EXE [C:\WINDOWS\system32\WLTRAY.exe] -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Modified Date = 11/1/2006 12:48:28 PM | Attr = ]
ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> Symantec Corporation [Ver = 104.0.13.2 | Size = 52840 bytes | Modified Date = 11/22/2006 6:38:28 AM | Attr = ]
ClubBox -> [] -> File not found
Dell QuickSet -> %ProgramFiles%\Dell\QuickSet\quickset.exe [C:\Program Files\Dell\QuickSet\quickset.exe] -> [Ver = 1, 0, 0, 1 | Size = 487424 bytes | Modified Date = 3/5/2004 10:59:30 AM | Attr = ]
DVDSentry -> %SystemRoot%\system32\DSentry.exe [C:\WINDOWS\System32\DSentry.exe] -> Dell - Advanced Desktop Engineering [Ver = 1, 0, 0, 0 | Size = 28672 bytes | Modified Date = 7/18/2002 12:18:06 AM | Attr = ]
HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] -> Hewlett-Packard Co. [Ver = 50.0.146.000 | Size = 49152 bytes | Modified Date = 2/17/2005 1:11:42 PM | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> Apple Inc. [Ver = 7.6.2.9 | Size = 267048 bytes | Modified Date = 3/31/2008 12:36:40 AM | Attr = ]
LWBMOUSE -> %ProgramFiles%\COMPAQ\CPQ650TP\Ver. 2.3\LwbWheel.exe [C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe] -> [Ver = 9.5.2.0 | Size = 438272 bytes | Modified Date = 5/19/2003 12:24:20 PM | Attr = ]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\FirstStart.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 40960 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> Apple Inc. [Ver = 7.4.5 | Size = 413696 bytes | Modified Date = 3/29/2008 1:37:20 PM | Attr = ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_06\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 144784 bytes | Modified Date = 3/25/2008 4:28:02 AM | Attr = ]
TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 11/11/2004 8:11:54 AM | Attr = ]
vptray -> %ProgramFiles%\Symantec AntiVirus\VPTray.exe [C:\PROGRA~1\SYMANT~1\VPTray.exe] -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 125632 bytes | Modified Date = 3/15/2007 8:49:02 AM | Attr = ]
WinampAgent -> %ProgramFiles%\Winamp\winampa.exe ["C:\Program Files\Winamp\winampa.exe"] -> [Ver = | Size = 36352 bytes | Modified Date = 10/10/2007 2:28:32 PM | Attr = ]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL-> Installed = 1 ->
MAPI-> Installed = 1 ->
MSFS-> Installed = 1 ->
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
NetZero_uoltray -> %ProgramFiles%\NetZero\exec.exe [C:\Program Files\NetZero\exec.exe regrun] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\Monitor.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 57344 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr = ]
Skype -> %ProgramFiles%\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] -> [Ver = | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr = ]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\ypager.exe [C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet] -> File not found
< Run [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
NetZero_uoltray -> %ProgramFiles%\NetZero\exec.exe [C:\Program Files\NetZero\exec.exe regrun] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 1629184 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
OM_Monitor -> %ProgramFiles%\OLYMPUS\OLYMPUS Master\Monitor.exe [C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart] -> OLYMPUS IMAGING CORP. [Ver = 1, 4, 1, 3 | Size = 57344 bytes | Modified Date = 11/30/2005 9:19:00 AM | Attr = ]
Skype -> %ProgramFiles%\Skype\Phone\Skype.exe ["C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized] -> [Ver = | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr = ]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\ypager.exe [C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet] -> File not found
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Acrobat Assistant.lnk -> %ProgramFiles%\Adobe\Acrobat 5.0\Distillr\AcroTray.exe -> Adobe Systems Inc. [Ver = 5, 0, 0, 0 | Size = 49254 bytes | Modified Date = 3/15/2001 7:18:18 PM | Attr = ]
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.1.0.2008042300 | Size = 29696 bytes | Modified Date = 4/23/2008 5:38:16 PM | Attr = ]
%AllUsersProfile%\Start Menu\Programs\Startup\Digital Line Detect.lnk -> %ProgramFiles%\Digital Line Detect\DLG.exe -> BVRP Software [Ver = 1, 0, 0, 1 | Size = 24576 bytes | Modified Date = 6/20/2003 5:43:00 PM | Attr = ]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 45.4.157.000 | Size = 258048 bytes | Modified Date = 11/5/2004 8:28:24 AM | Attr = ]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqthb08.exe -> Hewlett-Packard Co. [Ver = 045.004.157.000 | Size = 53248 bytes | Modified Date = 11/5/2004 8:50:52 AM | Attr = ]
%AllUsersProfile%\Start Menu\Programs\Startup\VPN Client.lnk -> %SystemRoot%\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico -> [Ver = | Size = 6144 bytes | Modified Date = 7/13/2007 10:02:55 AM | Attr = R ]
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< Rushelle Byfield Startup Folder > -> C:\Documents and Settings\Rushelle Byfield\Start Menu\Programs\Startup ->
%UserProfile%\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk -> %ProgramFiles%\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe -> Sony Corporation [Ver = 1.2.00.12060 | Size = 344064 bytes | Modified Date = 12/6/2006 6:09:30 PM | Attr = ]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Qualcomm\Eudora\EuShlExt.dll [Eudora's Shell Extension] -> File not found
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> [Ver = | Size = 86016 bytes | Modified Date = 7/30/2003 9:11:00 AM | Attr = ]
NavLogon -> %SystemRoot%\system32\NavLogon.dll -> Symantec Corporation [Ver = 10.1.6.6000 | Size = 43712 bytes | Modified Date = 3/15/2007 8:49:14 AM | Attr = ]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLegacyLogonScripts -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideLogoffScripts -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunLogonScriptSync -> 1 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\RunStartupScriptSync -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\HideStartupScripts -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> ->
< CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> ->
*DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup ->
SCSI miniport -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\drivers\cdrom.sys [System32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 8/4/2004 2:59:52 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 ->
*AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable ->
NEC MBR-7 -> -> File not found
NEC MBR-7.4 -> -> File not found
PIONEER CHANGR DRM-1804X -> -> File not found
PIONEER CD-ROM DRM-6324X -> -> File not found
PIONEER CD-ROM DRM-624X -> -> File not found
TORiSAN CD-ROM CDR_C36 -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomHL-DT-ST_RW/DVD_GCC-4243N_______________A102____\5&18c802ac&0&0.0.0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 1 ->
< Drives - Autoruns > -> ->
AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [Ver = | Size = 0 bytes | Modified Date = 4/20/2004 1:32:30 AM | Attr = ]
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://search.msn.com/spbasic.htm ->
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.google.com ->
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie ->
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.google.com/ ->
HKEY_CURRENT_USER\: SearchURL\\ -> http://my.netzero.net/s/search?r=minisearch[Reg Error: Value provider does not exist or could not be read.] ->
HKEY_CURRENT_USER\: URLSearchHooks\\{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\SearchEnh1.dll [URLSearchHook Class] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 266240 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
HKEY_CURRENT_USER\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: Main\\Default_Page_URL -> http://www.dell.com ->
HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: Main\\Default_Page_URL -> http://www.dell.com ->
HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome ->
HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
HKEY_USERS\S-1-5-19\: Main\\Search Bar -> http://search.msn.com/spbasic.htm ->
HKEY_USERS\S-1-5-19\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-19\: Main\\Start Page -> http://securityresponse.symantec.com/avcenter/fix_homepage ->
HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
HKEY_USERS\S-1-5-20\: Main\\Search Bar -> http://search.msn.com/spbasic.htm ->
HKEY_USERS\S-1-5-20\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-20\: Main\\Start Page -> http://securityresponse.symantec.com/avcenter/fix_homepage ->
HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: Main\\Start Page -> http://www.google.com/ ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: SearchURL\\ -> http://my.netzero.net/s/search?r=minisearch[Reg Error: Value provider does not exist or could not be read.] ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: URLSearchHooks\\{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\SearchEnh1.dll [URLSearchHook Class] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 266240 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\: ProxyEnable -> 0 ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 8397 domain(s) found. ->
free_aol.com [http] -> Trusted sites ->
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 8397 domain(s) found. ->
free_aol.com [http] -> Trusted sites ->
2 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{52706EF7-D7A2-49AD-A615-E903858CF284} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\qsacc\X1IEBHO.dll [Pop-up Blocker] -> NetZero, Inc. [Ver = 4.4.00 | Size = 211456 bytes | Modified Date = 6/5/2008 6:57:20 AM | Attr = ]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 509328 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
{D0943516-5076-4020-A3B5-AEFAF26AB263} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [Veoh Browser Plug-in] -> Veoh Networks Inc [Ver = 1.0.1.6 | Size = 352256 bytes | Modified Date = 4/2/2008 8:23:42 AM | Attr = ]
{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM Toolbar\AIMBar.dll [AIM Search] -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr = ]
WebBrowser\\{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
WebBrowser\\{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM Toolbar\AIMBar.dll [AIM Search] -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr = ]
WebBrowser\\{F0F8ECBE-D460-4B34-B007-56A92E8F84A7} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
WebBrowser\\{F5735C15-1FB2-41FE-BA12-242757E69DDE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\NetZero\Toolbar.dll [ZeroBar] -> NetZero, Inc. [Ver = 8.5.9.0 | Size = 297456 bytes | Modified Date = 3/7/2007 9:51:59 AM | Attr = ]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_06\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 509328 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}:Exec -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr = ]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
CmdMapping\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr = ]
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
&AIM Search -> %ProgramFiles%\AIM Toolbar\AIMBar.dll -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr = ]
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
Display All Images with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr = ]
Display Image with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr = ]
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr = ]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr = ]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_06\bin\npjpi160_06.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 132496 bytes | Modified Date = 3/25/2008 4:28:01 AM | Attr = ]
CmdMapping\\{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AIM\aim.exe [AIM] -> America Online, Inc. [Ver = 5.9.3861 | Size = 67160 bytes | Modified Date = 8/6/2005 4:08:26 AM | Attr = ]
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Microsoft\Internet Explorer\MenuExt\ ->
&AIM Search -> %ProgramFiles%\AIM Toolbar\AIMBar.dll -> America Online, Inc [Ver = 2004.00.003 | Size = 172032 bytes | Modified Date = 10/4/2004 4:09:26 AM | Attr = ]
&D&ownload &with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
&D&ownload all video with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
&D&ownload all with BitComet -> %ProgramFiles%\BitComet\BitComet.exe -> www.BitComet.com [Ver = 0.84 | Size = 4526144 bytes | Modified Date = 2/8/2007 5:49:42 PM | Attr = ]
Display All Images with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr = ]
Display Image with Full Quality -> %ProgramFiles%\NetZero\qsacc\appres.dll -> NetZero, Inc. [Ver = 4.4.00 | Size = 361472 bytes | Modified Date = 2/24/2007 9:33:10 AM | Attr = ]
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
Extension\.spop -> %ProgramFiles%\Internet Explorer\plugins\NPDocBox.dll [] -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 1/31/2001 3:56:24 AM | Attr = ]
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{3FF1B4F1-1FA8-429C-8A84-040A7A38E583} -> (Dell Wireless 1350 WLAN Mini-PCI Card) ->
{5CD7EE64-2BA9-4C26-B1DB-468B5D6465F6} -> (Broadcom 570x Gigabit Integrated Controller) ->
{84D269EC-098C-482A-963C-F2B1548430A4} -> () ->
< Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults ->
shell -> shell protocol not assigned ->
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab[CKAVWebScan Object] ->
{33564D57-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[Reg Error: Key does not exist or could not be opened.] ->
{44990301-3C9D-426D-81DF-AAB636FA4345}[HKEY_LOCAL_MACHINE] -> https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab[Symantec Script Runner Class] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211693090298[WUWebControl Class] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1211693062538[MUWebControl Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab[Java Plug-in 1.6.0_06] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] ->
< Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\\.Owner -> {205FF73B-CA67-11D5-99DD-444553540012} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Install.dll\\{205FF73B-CA67-11D5-99DD-444553540012} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\\.Owner -> {44990301-3C9D-426D-81DF-AAB636FA4345} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/tgctlsr.dll\\{44990301-3C9D-426D-81DF-AAB636FA4345} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\\.Owner -> {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/muweb.dll\\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\.Owner -> Unknown Owner ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\{6414512B-B978-451D-A0D8-FCFDF33E833C} -> ->
[Registry - Additional Scans - Non-Microsoft Only]
< Security Settings > -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\\DisableMonitoring -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Background Intelligent Transfer Service ->
*DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService ->
Rpcss -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 1:39:49 PM | Attr = ]
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfers files in the background using idle network bandwidth. If the service is stopped, features such as Windows Update, and MSN Explorer will be unable to automatically download programs and other information. If this service is disabled, any services that explicitly depend on it may fail to transfer files if they do not have a fail safe mechanism to transfer files directly through IE in case BITS has been disabled. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\FailureActions -> 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 68 E3 0C 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 60 EA 00 00 [binary data] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> %SystemRoot%\system32\qmgr.dll [%systemroot%\system32\qmgr.dll] -> Microsoft Corporation [Ver = 6.6.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 382464 bytes | Modified Date = 8/4/2004 4:56:44 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\0 -> Root\LEGACY_BITS\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 1539 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 4:56:42 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 4:56:56 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 4:56:56 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Skype\Phone\Skype.exe -> %ProgramFiles%\Skype\Phone\Skype.exe [C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype] -> [Ver = | Size = 20058152 bytes | Modified Date = 10/14/2006 7:20:08 AM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Veoh Networks\Veoh\VeohClient.exe -> %ProgramFiles%\Veoh Networks\Veoh\VeohClient.exe [C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client] -> Veoh Networks [Ver = 3.9.1.1165 | Size = 3587120 bytes | Modified Date = 4/2/2008 8:35:26 AM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{54134CC3-1080-4F43-BBF1-6FCDDF2AE5A1} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{BC18CA29-7195-4E27-8AB6-FC0A8A02EC5C} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{D5DD5E9F-A4F0-4E0A-921C-CBE66B4380EA} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{3FF1B4F1-1FA8-429C-8A84-040A7A38E583} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{C8FC09D7-2DCE-4176-AE3B-6C08F3C82988} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{84D269EC-098C-482A-963C-F2B1548430A4} -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 4:56:57 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 4:56:46 PM | Attr = ]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\\NoSplash -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Messenger\Client\\PreventAutoRun -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Installer\\EnableAdminTSRemote -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Psched\\NonBestEffortLimit -> -5 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\PortRange\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\RTC\PortRange\\Enabled -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\ -> ->
*ExecutableTypes* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\ExecutableTypes ->
ADE -> -> File not found
ADP -> -> File not found
BAS -> -> File not found
BAT -> -> File not found
CHM -> -> File not found
CMD -> %SystemRoot%\system32\cmd.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 388608 bytes | Modified Date = 8/4/2004 4:56:48 PM | Attr = ]
COM -> -> File not found
CPL -> -> File not found
CRT -> -> File not found
EXE -> -> File not found
HLP -> -> File not found
HTA -> -> File not found
INF -> -> File not found
INS -> -> File not found
ISP -> -> File not found
LNK -> -> File not found
MDB -> -> File not found
MDE -> -> File not found
MSC -> -> File not found
MSI -> %SystemRoot%\system32\msi.dll -> Microsoft Corporation [Ver = 3.1.4000.4039 | Size = 2854400 bytes | Modified Date = 4/19/2007 1:12:23 AM | Attr = ]
MSP -> -> File not found
MST -> -> File not found
OCX -> -> File not found
PCD -> -> File not found
PIF -> -> File not found
REG -> %SystemRoot%\system32\reg.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 50176 bytes | Modified Date = 8/4/2004 4:56:55 PM | Attr = ]
SCR -> -> File not found
SHS -> -> File not found
URL -> %SystemRoot%\system32\url.dll -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 37888 bytes | Modified Date = 8/4/2004 4:56:46 PM | Attr = ]
VB -> -> File not found
WSC -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\TransparentEnabled -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\DefaultLevel -> 262144 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\AuthenticodeEnabled -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\\PolicyScope -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\Description -> Stop the download of this file ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\FriendlyName -> Mdac11.cab ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\HashAlg -> 32771 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemData -> 5E AB 30 4F 95 7A 49 89 6A 00 6C 1C 31 15 40 15 [binary data] ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\LastModified -> ->
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\\ItemSize ->
̋ -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\Description -> Stop the download of this file ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\FriendlyName -> mdac20.cab ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\HashAlg -> 32771 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemData -> 67 B0 D4 8B 34 3A 3F D3 BC E9 DC 64 67 04 F3 94 [binary data] ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\LastModified -> ->
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\\ItemSize ->
ȅ -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\Description -> Stop the download of this file ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\FriendlyName -> mdac20_a.cab ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\HashAlg -> 32771 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemData -> 32 78 02 DC FE F8 C8 93 DC 8A B0 06 DD 84 7D 1D [binary data] ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\LastModified -> ->
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\\ItemSize ->
Ζ -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\Description -> Stop the download of this file ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\FriendlyName -> _msadc10.cab ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\HashAlg -> 32771 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemData -> BD 9A 2A DB 42 EB D8 56 0E 25 0E 4D F8 16 2F 67 [binary data] ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\LastModified -> ->
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\\ItemSize ->
å -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\Description -> Stop the download of this file ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\FriendlyName -> msadc11.cab ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\HashAlg -> 32771 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemData -> 38 6B 08 5F 84 EC F6 69 D3 6B 95 6A 22 C0 1E 80 [binary data] ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\LastModified -> ->
*ItemSize* -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\\ItemSize ->
Ų -> -> File not found
*MultiFile Done* -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\Description -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\SaferFlags -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\ItemData -> %HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK* ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\\LastModified -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\\DoNotAllowXPSP2 -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\WindowsUpdate\AU\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows NT\Terminal Services\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\DomainProfile\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\WindowsFirewall\StandardProfile\ -> ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\policies\ ->
HKEY_CURRENT_USER\Software\Policies\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\AppCompat\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\ -> ->
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System\\DisableCMD -> 0 ->
< Software Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\policies\ ->
HKEY_USERS\.DEFAULT\Software\Policies\ -> ->
HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\ -> ->
< Software Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\policies\ ->
HKEY_USERS\S-1-5-18\Software\Policies\ -> ->
HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\ -> ->
< Software Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\policies\ ->
HKEY_USERS\S-1-5-19\Software\Policies\ -> ->
HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\ -> ->
< Software Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\policies\ ->
HKEY_USERS\S-1-5-20\Software\Policies\ -> ->
HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\ -> ->
< Software Policy Settings [HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005] > -> HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\SOFTWARE\policies\ ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Internet Explorer\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\AppCompat\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\System\ -> ->
HKEY_USERS\S-1-5-21-3344718509-2843401551-520714115-1005\Software\Policies\Microsoft\Windows\System\\DisableCMD -> 0 ->
< EventViewer Logs > -> Errors and Warnings -> Description
Application - Warning - 6/18/2008 11:20:24 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/19/2008 10:11:12 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/19/2008 10:39:22 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryAlexaRelatedzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDCONzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploitzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:23 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit10zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit11zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit12zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit13zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit14zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit15zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit16zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit17zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit18zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit19zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit20zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit21zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit22zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit23zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:25 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit24zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit25zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit26zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit27zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit28zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit29zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit30zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit31zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit32zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit33zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit34zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit35zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit36zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit37zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit38zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit39zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit4zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit40zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit41zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit42zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit43zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit44zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit45zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit46zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit47zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit48zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit49zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit5zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit50zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit51zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit52zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit53zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit54zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit55zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit56zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit57zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit58zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit59zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit6zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit60zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit61zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit62zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:29 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit63zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit64zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit7zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit8zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryDSOExploit9zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryErrorGuardzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryErrorGuard1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryErrorGuard2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMaxSearchzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabledzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:30 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled4zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled5zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled6zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled7zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterdisabled8zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterFirewallDisabledzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryMicrosoftWindowsSecurityCenterFirewallDisabled1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryNoAdwarezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryNoAdware1zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryNoAdware2zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryNoAdware3zip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryNurechzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterAntiVirusDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterAntiVirusOverridezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterFirewallDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterFirewallOverridezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterSPUpdatezip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/19/2008 10:39:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CDocuments and SettingsAll UsersApplication DataSpybot - Search DestroyRecoveryWindowsSecurityCenterUpdateDisableNotifyzip due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:03:09 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 1 files inside Ci386softbarin due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:41:18 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 41 files inside CProgram FilesLavasoftAd-Aware SE PersonalSkinsAd-Aware SE defaultask due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:53:15 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 2 files inside CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP797A0210503exe due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 12:53:36 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Could not scan 8 files inside CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP797A0210504exe due to extraction errors encountered by the Decomposer Engines
Application - Warning - 6/20/2008 1:18:09 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/20/2008 3:27:14 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Error - 6/20/2008 3:44:05 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowssystem32cru629dat by Startup scan Action Clean failed Quarantine failed Action Description The file was left unchanged
Application - Error - 6/20/2008 3:45:10 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowssystem32cru629dat by Startup scan Action Cleaned by Deletion Action Description
Application - Warning - 6/20/2008 3:59:06 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Error - 6/20/2008 4:08:17 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowscru629dat by Startup scan Action Clean failed Quarantine failed Action Description The file was left unchanged
Application - Error - 6/20/2008 4:08:33 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanPerfcoo in File cwindowscru629dat by Startup scan Action Cleaned by Deletion Action Description
Application - Warning - 6/20/2008 8:28:19 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/21/2008 4:23:32 AM -> Computer Name = RB627 - User Name = (blank) - Source = ASP.NET 1.1.4322.0 -> Description = Updates to the IIS metabase were aborted because IIS is either not installed or is disabled on this machine To configure ASPNET to run in IIS please install or enable IIS and re-register ASPNET using aspnetregiisexe i
Application - Warning - 6/21/2008 5:23:34 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Error - 6/21/2008 5:36:40 AM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = SYMANTEC TAMPER PROTECTION ALERTTarget CProgram FilesSymantec AntiVirusDoScanexeEvent Info Terminate ProcessAction Taken BlockedActor Process CComboFixpvcfexe (PID 2788)Time 2008-06-21 0536
Application - Warning - 6/21/2008 5:45:04 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/21/2008 10:09:08 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Error - 6/21/2008 9:46:15 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 9:46:16 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 9:46:18 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CQooBoxQuarantineCwindowssystem32aspimgrexevir by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 9:46:19 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan Action Pending Side Effects Analysis Access denied Action Description
Application - Error - 6/21/2008 9:47:31 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan Action Quarantine failed Action Description The file was left unchanged
Application - Error - 6/21/2008 9:47:33 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File cQooBoxquarantineCwindowssystem32winivstrexevir by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 9:47:33 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CQooBoxQuarantineCwindowssystem32winivstrexevir by Auto-Protect scan Action Quarantine succeeded Access denied Action Description The file was quarantined successfully
Application - Error - 6/21/2008 9:58:21 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan Action Pending Side Effects Analysis Access denied Action Description
Application - Error - 6/21/2008 10:00:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan Action Quarantine failed Action Description The file was left unchanged
Application - Error - 6/21/2008 10:00:19 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP808A0219054exe by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:00:20 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP808A0219054exe by Auto-Protect scan Action Quarantine succeeded Access denied Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:00:20 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan Action Pending Side Effects Analysis Access denied Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:01:17 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219082sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:03:07 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan Action Quarantine failed Action Description The file was left unchanged
Application - Error - 6/21/2008 10:03:11 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP809A0219076exe by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:03:11 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP809A0219076exe by Auto-Protect scan Action Quarantine succeeded Access denied Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:04:46 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk HacktoolRootkit in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219083sys by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:04:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan Action Pending Side Effects Analysis Access denied Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:05:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk TrojanAsprox in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220693exe by Auto-Protect scan Action Cleaned by Deletion Action Description
Application - Error - 6/21/2008 10:06:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan Action Quarantine failed Action Description The file was left unchanged
Application - Error - 6/21/2008 10:06:51 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP810A0219101exe by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:52 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP811A0220100exe by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP810A0219101exe by Auto-Protect scan Action Quarantine succeeded Access denied Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:06:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan Action Pending Side Effects Analysis Access denied Action Description
Application - Error - 6/21/2008 10:08:00 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan Action Quarantine failed Action Description The file was left unchanged
Application - Error - 6/21/2008 10:08:01 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Risk FoundRisk XPSecurityCenter in File csystem volume informationrestore9b539e66-d85a-41e7-acfd-ae0f6cd9dce9RP813A0220696exe by Auto-Protect scan Action Quarantine succeeded Action Description The file was quarantined successfully
Application - Error - 6/21/2008 10:08:01 PM -> Computer Name = RB627 - User Name = (blank) - Source = Symantec AntiVirus -> Description = Security Risk FoundRisk XPSecurityCenter in File CSystem Volume Informationrestore9B539E66-D85A-41E7-ACFD-AE0F6CD9DCE9RP813A0220696exe by Auto-Protect scan Action Quarantine succeeded Access denied Action Description The file was quarantined successfully
Application - Warning - 6/22/2008 4:24:42 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/22/2008 7:21:45 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/23/2008 12:54:36 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/23/2008 8:14:00 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Error - 6/23/2008 3:11:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = Application Hang -> Description = Hanging application firefoxexe version 182008040413 hang module hungapp version 0000 hang address 0x00000000
Application - Error - 6/23/2008 3:11:58 PM -> Computer Name = RB627 - User Name = (blank) - Source = Application Hang -> Description = Fault bucket 713234062
Application - Warning - 6/24/2008 1:20:40 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/24/2008 4:47:56 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
Application - Warning - 6/24/2008 6:56:19 PM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = Userenv -> Description =
System - Warning - 6/18/2008 2:27:27 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/18/2008 2:47:59 PM -> Computer Name = RB627 - User Name = (blank) - Source = Dhcp -> Description = Your computer was not able to renew its address from the network (from theDHCP Server) for the Network Card with network address 000F1FB683F3 The followingerror occurred 1223Your computer will continue to try and obtain an address on its own fromthe network address (DHCP) server
System - Warning - 6/18/2008 7:06:44 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/18/2008 11:19:38 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Error - 6/19/2008 2:36:31 PM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description =
System - Warning - 6/19/2008 3:21:05 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/19/2008 3:23:49 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/19/2008 3:39:08 PM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description =
System - Warning - 6/19/2008 10:00:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/19/2008 10:00:34 PM -> Computer Name = RB627 - User Name = (blank) - Source = Dhcp -> Description = Your computer was not able to renew its address from the network (from theDHCP Server) for the Network Card with network address 000F1FB683F3 The followingerror occurred 1223Your computer will continue to try and obtain an address on its own fromthe network address (DHCP) server
System - Error - 6/19/2008 10:00:39 PM -> Computer Name = RB627 - User Name = (blank) - Source = ipnathlp -> Description = The Network Address Translator (NAT) was unable to request an operationof the kernel-mode translation moduleThis may indicate misconfiguration insufficient resources oran internal errorThe data is the error code
System - Error - 6/20/2008 1:19:24 AM -> Computer Name = RB627 - User Name = (blank) - Source = sr -> Description =
System - Error - 6/20/2008 3:32:59 AM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description =
System - Error - 6/20/2008 3:32:59 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = DCOM -> Description =
System - Error - 6/20/2008 3:33:59 AM -> Computer Name = RB627 - User Name = RB627\Rushelle Byfield - Source = DCOM -> Description =
System - Error - 6/20/2008 3:35:12 AM -> Computer Name = RB627 - User Name = NT AUTHORITY\SYSTEM - Source = DCOM -> Description =
System - Warning - 6/20/2008 3:44:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/20/2008 4:35:14 AM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description =
System - Warning - 6/20/2008 7:09:20 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/20/2008 3:49:26 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/20/2008 4:52:37 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 4:04:02 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 4:05:42 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 4:16:34 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:04:31 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:06:08 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:19:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:24:50 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:46:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 7:50:15 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 7:54:39 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 7:55:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = Tcpip -> Description =
System - Warning - 6/21/2008 8:52:23 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 8:58:54 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:02:24 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:02:56 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:03:02 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:13:58 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:20:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:48:32 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 9:57:37 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 10:08:04 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 12:22:08 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 4:50:27 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 4:50:42 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 5:06:28 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 6:37:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 7:52:03 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 7:53:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/21/2008 8:00:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:20:54 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:33:40 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:34:42 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 4:13:48 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 4:22:59 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 1:04:12 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 1:16:06 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 1:36:24 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 2:12:48 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 2:58:32 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:24:53 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:25:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/22/2008 3:25:57 PM -> Computer Name = RB627 - User Name = (blank) - Source = Server -> Description = The server could not bind to the transport DeviceNetBTTcpip5CD7EE64-2BA9-4C26-B1DB-468B5D6465F6
System - Warning - 6/22/2008 10:28:05 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/23/2008 7:01:21 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/23/2008 2:45:50 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/24/2008 1:19:11 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/24/2008 3:10:41 PM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
System - Warning - 6/25/2008 12:19:00 AM -> Computer Name = RB627 - User Name = (blank) - Source = b57w2k -> Description =
[Files/Folders - Created Within 30 days]
Binaries -> %SystemDrive%\Binaries -> [Folder | Created Date = 6/4/2008 3:02:01 AM | Attr = ]
Boot.bak -> %SystemDrive%\Boot.bak -> [Ver = | Size = 211 bytes | Created Date = 6/21/2008 5:38:02 AM | Attr = ]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 6/21/2008 5:37:39 AM | Attr = ]
cmldr -> %SystemDrive%\cmldr -> [Ver = | Size = 260272 bytes | Created Date = 6/21/2008 5:37:50 AM | Attr = ]
ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 6/22/2008 4:22:22 AM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 267694080 bytes | Created Date = 6/20/2008 3:36:45 AM | Attr = HS]
NetZeroInstaller -> %SystemDrive%\NetZeroInstaller -> [Folder | Created Date = 6/11/2008 8:45:11 AM | Attr = ]
RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 6/21/2008 7:57:32 PM | Attr = HS]
BCMWLNPF.SYS -> %SystemRoot%\System32\drivers\BCMWLNPF.SYS -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 33664 bytes | Created Date = 6/12/2008 9:04:59 PM | Attr = ]
CDRBSDRV.SYS -> %SystemRoot%\System32\drivers\CDRBSDRV.SYS -> B.H.A Corporation [Ver = 7. 0. 0. 5 | Size = 13567 bytes | Created Date = 6/4/2008 3:00:53 AM | Attr = ]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Created Date = 6/21/2008 5:21:53 PM | Attr = ]
mbamcatchme.sys -> %SystemRoot%\System32\drivers\mbamcatchme.sys -> [Ver = | Size = 34296 bytes | Created Date = 6/21/2008 5:21:53 PM | Attr = ]
tmcomm.sys -> %SystemRoot%\System32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Created Date = 6/20/2008 4:39:56 AM | Attr = ]
UMDF -> %SystemRoot%\System32\drivers\UMDF -> [Folder | Created Date = 6/7/2008 10:55:20 AM | Attr = ]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Created Date = 6/7/2008 10:55:32 AM | Attr = H ]
bcm1xsup.dll -> %SystemRoot%\System32\bcm1xsup.dll -> [Ver = | Size = 757760 bytes | Created Date = 6/12/2008 9:04:47 PM | Attr = ]
bcmwlpkt.dll -> %SystemRoot%\System32\bcmwlpkt.dll -> CACE Technologies [Ver = 3, 1, 0, 27 | Size = 69632 bytes | Created Date = 6/12/2008 9:04:54 PM | Attr = ]
java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 135168 bytes | Created Date = 6/22/2008 9:43:28 PM | Attr = ]
javacpl.cpl -> %SystemRoot%\System32\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 69632 bytes | Created Date = 6/22/2008 4:19:28 AM | Attr = ]
javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 135168 bytes | Created Date = 6/22/2008 9:43:29 PM | Attr = ]
javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.60.2 | Size = 139264 bytes | Created Date = 6/22/2008 9:43:29 PM | Attr = ]
Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Created Date = 6/21/2008 8:01:11 PM | Attr = ]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg -> [Ver = | Size = 11946 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr = ]
preflib.dll -> %SystemRoot%\System32\preflib.dll -> [Ver = | Size = 86016 bytes | Created Date = 6/12/2008 9:04:55 PM | Attr = ]
PreInstall -> %SystemRoot%\System32\PreInstall -> [Folder | Created Date = 6/20/2008 3:02:05 AM | Attr = ]
Pvmjpg21.dll -> %SystemRoot%\System32\Pvmjpg21.dll -> Pegasus Imaging Corporation [Ver = 2.10.0.29 | Size = 319488 bytes | Created Date = 6/4/2008 3:01:00 AM | Attr = ]
QuickTime -> %SystemRoot%\System32\QuickTime -> [Folder | Created Date = 6/4/2008 3:01:37 AM | Attr = ]
WLBCGCBPRO731.DLL -> %SystemRoot%\System32\WLBCGCBPRO731.DLL -> BCGSoft Ltd [Ver = 7, 31, 0, 0 | Size = 2129920 bytes | Created Date = 6/12/2008 9:04:48 PM | Attr = ]
WLTRAY.EXE -> %SystemRoot%\System32\WLTRAY.EXE -> Dell Inc. [Ver = 4.100.15.8 | Size = 1392640 bytes | Created Date = 6/12/2008 9:04:51 PM | Attr = ]
wltrynt.dll -> %SystemRoot%\System32\wltrynt.dll -> Broadcom Corporation [Ver = 4.100.15.8 | Size = 44032 bytes | Created Date = 6/12/2008 9:04:54 PM | Attr = ]
WLTRYSVC.EXE -> %SystemRoot%\System32\WLTRYSVC.EXE -> [Ver = | Size = 20480 bytes | Created Date = 6/12/2008 9:04:49 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 6/20/2008 3:01:57 AM | Attr = H ]
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
aqucutuq.inf -> %SystemRoot%\aqucutuq.inf -> [Ver = | Size = 13916 bytes | Created Date = 6/19/2008 10:21:24 PM | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 6/21/2008 5:36:13 AM | Attr = ]
hucyl._dl -> %SystemRoot%\hucyl._dl -> [Ver = | Size = 12438 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr = ]
jadematy._sy -> %SystemRoot%\jadematy._sy -> [Ver = | Size = 13319 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr = ]
kiqyji.scr -> %SystemRoot%\kiqyji.scr -> [Ver = | Size = 12375 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr = ]
miwohej.lib -> %SystemRoot%\miwohej.lib -> [Ver = | Size = 18221 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr = ]
nypejuh.dll -> %SystemRoot%\nypejuh.dll -> [Ver = | Size = 15290 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 6/19/2008 3:55:04 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 6/19/2008 3:55:04 PM | Attr = H ]
TEMP -> %SystemRoot%\TEMP -> [Folder | Created Date = 6/21/2008 5:19:23 PM | Attr = ]
ufokypi.exe -> %SystemRoot%\ufokypi.exe -> [Ver = | Size = 13228 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr = ]
ysej.bat -> %SystemRoot%\ysej.bat -> [Ver = | Size = 12076 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr = ]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat -> [Ver = | Size = 10127 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr = ]
Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Created Date = 6/21/2008 8:01:16 PM | Attr = ]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Created Date = 6/21/2008 5:21:54 PM | Attr = ]
McAfee -> %AllUsersProfile%\Application Data\McAfee -> [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr = ]
NetZero -> %AllUsersProfile%\Application Data\NetZero -> [Folder | Created Date = 6/11/2008 8:45:13 AM | Attr = ]
SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor -> [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr = ]
ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe -> [Ver = | Size = 16907 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr = ]
fijizojeqy.scr -> %AppData%\fijizojeqy.scr -> [Ver = | Size = 19403 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr = ]
Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Created Date = 6/21/2008 5:21:59 PM | Attr = ]
OLYMPUS -> %AppData%\OLYMPUS -> [Folder | Created Date = 6/4/2008 3:15:39 AM | Attr = ]
Qualcomm -> %AppData%\Qualcomm -> [Folder | Created Date = 5/31/2008 11:43:53 PM | Attr = ]
SiteAdvisor -> %AppData%\SiteAdvisor -> [Folder | Created Date = 6/22/2008 10:09:07 PM | Attr = ]
subybalus.vbs -> %AppData%\subybalus.vbs -> [Ver = | Size = 13212 bytes | Created Date = 6/19/2008 10:21:23 PM | Attr = ]
ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com -> [Ver = | Size = 15688 bytes | Created Date = 6/19/2008 10:21:20 PM | Attr = ]
NOS -> %UserProfile%\Local Settings\Application Data\NOS -> [Folder | Created Date = 6/2/2008 9:51:04 PM | Attr = ]
ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib -> [Ver = | Size = 16217 bytes | Created Date = 6/19/2008 10:21:25 PM | Attr = ]
ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db -> [Ver = | Size = 10240 bytes | Created Date = 6/19/2008 10:21:21 PM | Attr = ]
onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib -> [Ver = | Size = 10336 bytes | Created Date = 6/19/2008 10:21:26 PM | Attr = ]
yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban -> [Ver = | Size = 15937 bytes | Created Date = 6/19/2008 10:21:26 PM | Attr = ]
yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat -> [Ver = | Size = 12956 bytes | Created Date = 6/19/2008 10:21:18 PM | Attr = ]
agnes.doc -> %UserProfile%\My Documents\agnes.doc -> [Ver = | Size = 19456 bytes | Created Date = 5/29/2008 1:22:47 AM | Attr = ]
Backup of blog.wbk -> %UserProfile%\My Documents\Backup of blog.wbk -> [Ver = | Size = 288768 bytes | Created Date = 6/21/2008 5:13:30 AM | Attr = ]
blog.doc -> %UserProfile%\My Documents\blog.doc -> [Ver = | Size = 303104 bytes | Created Date = 6/21/2008 5:13:30 AM | Attr = ]
Adobe Reader 7.0.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 7.0.lnk -> [Ver = | Size = 1740 bytes | Created Date = 6/2/2008 9:54:53 PM | Attr = ]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [Ver = | Size = 696 bytes | Created Date = 6/21/2008 5:21:55 PM | Attr = ]
NetZero Internet.lnk -> %AllUsersProfile%\Desktop\NetZero Internet.lnk -> [Ver = | Size = 1649 bytes | Created Date = 6/11/2008 8:47:01 AM | Attr = ]
OLYMPUS Master.lnk -> %AllUsersProfile%\Desktop\OLYMPUS Master.lnk -> [Ver = | Size = 774 bytes | Created Date = 6/4/2008 3:02:26 AM | Attr = ]
edu01.pdf -> %UserProfile%\Desktop\edu01.pdf -> [Ver = | Size = 322314 bytes | Created Date = 6/11/2008 4:35:19 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\edu01.pdf:Zone.Identifier
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1717 bytes | Created Date = 6/20/2008 1:53:39 AM | Attr = ]
Houding Request Form 08-09.doc -> %UserProfile%\Desktop\Houding Request Form 08-09.doc -> [Ver = | Size = 34304 bytes | Created Date = 5/28/2008 4:07:54 AM | Attr = ]
hrd01.pdf -> %UserProfile%\Desktop\hrd01.pdf -> [Ver = | Size = 132425 bytes | Created Date = 6/11/2008 5:09:27 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\hrd01.pdf:Zone.Identifier
Kobukuro All Singles Best Disk 1.zip -> %UserProfile%\Desktop\Kobukuro All Singles Best Disk 1.zip -> [Ver = | Size = 122004021 bytes | Created Date = 5/28/2008 3:24:05 PM | Attr = ]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes [Ver = 1.0.0.0 | Size = 1665344 bytes | Created Date = 6/21/2008 5:02:56 PM | Attr = ]
OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Created Date = 6/25/2008 12:17:16 AM | Attr = ]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 568483 bytes | Created Date = 6/25/2008 12:16:14 AM | Attr = ]
review.pdf -> %UserProfile%\Desktop\review.pdf -> [Ver = | Size = 4219863 bytes | Created Date = 6/8/2008 1:00:33 PM | Attr = ]
shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> %UserProfile%\Desktop\shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> [Ver = | Size = 317927018 bytes | Created Date = 6/22/2008 10:22:32 PM | Attr = ]
unem01.pdf -> %UserProfile%\Desktop\unem01.pdf -> [Ver = | Size = 334437 bytes | Created Date = 6/11/2008 4:48:30 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\unem01.pdf:Zone.Identifier
zeroincomeselfcertifyingstatement.pdf -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf -> [Ver = | Size = 1311577 bytes | Created Date = 6/11/2008 5:06:48 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf:Zone.Identifier
[G no Arashi] 2006.02.08 - ep18.avi -> %UserProfile%\Desktop\[G no Arashi] 2006.02.08 - ep18.avi -> [Ver = | Size = 231014400 bytes | Created Date = 6/16/2008 6:27:44 PM | Attr = ]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> [Ver = | Size = 1757 bytes | Created Date = 6/2/2008 9:54:52 PM | Attr = ]
ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl -> [Ver = | Size = 14741 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr = ]
exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys -> [Ver = | Size = 19255 bytes | Created Date = 6/19/2008 10:21:22 PM | Attr = ]
qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat -> [Ver = | Size = 19448 bytes | Created Date = 6/19/2008 10:21:17 PM | Attr = ]
ziti.db -> %CommonProgramFiles%\ziti.db -> [Ver = | Size = 16038 bytes | Created Date = 6/19/2008 10:21:20 PM | Attr = ]
Malwarebytes' Anti-Malware -> %ProgramFiles%\Malwarebytes' Anti-Malware -> [Folder | Created Date = 6/21/2008 5:21:52 PM | Attr = ]
MSXML 4.0 -> %ProgramFiles%\MSXML 4.0 -> [Folder | Created Date = 6/21/2008 4:17:07 AM | Attr = ]
OLYMPUS -> %ProgramFiles%\OLYMPUS -> [Folder | Created Date = 6/4/2008 3:01:30 AM | Attr = ]
PIXELA -> %ProgramFiles%\PIXELA -> [Folder | Created Date = 6/4/2008 2:59:45 AM | Attr = ]
Qualcomm -> %ProgramFiles%\Qualcomm -> [Folder | Created Date = 5/31/2008 11:42:46 PM | Attr = ]
Trend Micro -> %ProgramFiles%\Trend Micro -> [Folder | Created Date = 6/20/2008 1:53:39 AM | Attr = ]
Windows Media Connect 2 -> %ProgramFiles%\Windows Media Connect 2 -> [Folder | Created Date = 6/7/2008 10:59:16 AM | Attr = ]
[Files/Folders - Modified Within 30 days]
Binaries -> %SystemDrive%\Binaries -> [Folder | Modified Date = 6/4/2008 3:02:01 AM | Attr = ]
boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 281 bytes | Modified Date = 6/21/2008 5:38:03 AM | Attr = RHS]
cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 6/21/2008 5:38:02 AM | Attr = ]
ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 6/22/2008 4:22:37 AM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 6/22/2008 9:43:43 PM | Attr = H ]
dell -> %SystemDrive%\dell -> [Folder | Modified Date = 6/11/2008 2:49:46 PM | Attr = ]
Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 6/11/2008 8:33:53 AM | Attr = ]
hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 267694080 bytes | Modified Date = 6/24/2008 11:54:17 PM | Attr = HS]
NetZeroInstaller -> %SystemDrive%\NetZeroInstaller -> [Folder | Modified Date = 6/11/2008 8:47:02 AM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 6/21/2008 5:21:52 PM | Attr = R ]
RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 6/21/2008 7:57:32 PM | Attr = HS]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 6/22/2008 1:09:06 PM | Attr = HS]
windows -> %SystemRoot% -> [Folder | Modified Date = 6/25/2008 12:00:10 AM | Attr = ]
etc -> %SystemRoot%\System32\drivers\etc -> [Folder | Modified Date = 6/21/2008 5:49:49 AM | Attr = ]
hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [Ver = | Size = 27 bytes | Modified Date = 6/21/2008 5:49:49 AM | Attr = ]
mbam.sys -> %SystemRoot%\System32\drivers\mbam.sys -> Malwarebytes [Ver = 1, 0, 0, 1 | Size = 17144 bytes | Modified Date = 6/19/2008 5:47:58 PM | Attr = ]
mbamcatchme.sys -> %SystemRoot%\System32\drivers\mbamcatchme.sys -> [Ver = | Size = 34296 bytes | Modified Date = 6/19/2008 5:48:04 PM | Attr = ]
tmcomm.sys -> %SystemRoot%\System32\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 6/20/2008 4:37:52 AM | Attr = ]
UMDF -> %SystemRoot%\System32\drivers\UMDF -> [Folder | Modified Date = 6/11/2008 7:43:13 AM | Attr = ]
MsftWdf_user_01_00_00.Wdf -> %SystemRoot%\System32\drivers\UMDF\MsftWdf_user_01_00_00.Wdf -> [Ver = | Size = 0 bytes | Modified Date = 6/7/2008 10:55:32 AM | Attr = H ]
CatRoot -> %SystemRoot%\System32\CatRoot -> [Folder | Modified Date = 6/11/2008 8:07:54 AM | Attr = ]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 6/21/2008 5:17:37 PM | Attr = ]
Com -> %SystemRoot%\System32\Com -> [Folder | Modified Date = 6/21/2008 4:39:36 AM | Attr = ]
config -> %SystemRoot%\System32\config -> [Folder | Modified Date = 6/21/2008 5:44:14 AM | Attr = ]
d3d9caps.dat -> %SystemRoot%\System32\d3d9caps.dat -> [Ver = | Size = 664 bytes | Modified Date = 5/26/2008 2:38:37 AM | Attr = ]
DllCache -> %SystemRoot%\System32\DllCache -> [Folder | Modified Date = 6/21/2008 5:25:08 AM | Attr = RHS]
drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 6/21/2008 5:21:53 PM | Attr = ]
fntcache.dat -> %SystemRoot%\System32\fntcache.dat -> [Ver = | Size = 122928 bytes | Modified Date = 6/21/2008 5:25:16 AM | Attr = ]
FxsTmp -> %SystemRoot%\System32\FxsTmp -> [Folder | Modified Date = 5/31/2008 4:05:17 PM | Attr = ]
Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Modified Date = 6/21/2008 8:01:11 PM | Attr = ]
kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg -> [Ver = | Size = 11946 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr = ]
Logfiles -> %SystemRoot%\System32\Logfiles -> [Folder | Modified Date = 6/11/2008 7:43:24 AM | Attr = ]
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 53838 bytes | Modified Date = 6/21/2008 5:55:25 AM | Attr = ]
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 382260 bytes | Modified Date = 6/21/2008 5:55:26 AM | Attr = ]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 441626 bytes | Modified Date = 6/21/2008 5:55:19 AM | Attr = ]
PreInstall -> %SystemRoot%\System32\PreInstall -> [Folder | Modified Date = 6/20/2008 3:02:05 AM | Attr = ]
QuickTime -> %SystemRoot%\System32\QuickTime -> [Folder | Modified Date = 6/4/2008 3:01:37 AM | Attr = ]
Restore -> %SystemRoot%\System32\Restore -> [Folder | Modified Date = 6/22/2008 1:09:06 PM | Attr = ]
wbem -> %SystemRoot%\System32\wbem -> [Folder | Modified Date = 6/11/2008 7:43:50 AM | Attr = ]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 2278 bytes | Modified Date = 6/15/2008 5:23:40 PM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 6/21/2008 4:54:44 AM | Attr = H ]
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 6/11/2008 7:43:07 AM | Attr = ]
aqucutuq.inf -> %SystemRoot%\aqucutuq.inf -> [Ver = | Size = 13916 bytes | Modified Date = 6/19/2008 10:21:24 PM | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 6/24/2008 11:54:38 PM | Attr = S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 6/21/2008 8:01:15 PM | Attr = S]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 6/22/2008 4:22:28 AM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 6/12/2008 9:05:44 PM | Attr = ]
hucyl._dl -> %SystemRoot%\hucyl._dl -> [Ver = | Size = 12438 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 6/21/2008 4:55:11 AM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 6/21/2008 8:01:10 PM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 6/22/2008 9:45:04 PM | Attr = HS]
jadematy._sy -> %SystemRoot%\jadematy._sy -> [Ver = | Size = 13319 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr = ]
kiqyji.scr -> %SystemRoot%\kiqyji.scr -> [Ver = | Size = 12375 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr = ]
miwohej.lib -> %SystemRoot%\miwohej.lib -> [Ver = | Size = 18221 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr = ]
msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 6/21/2008 5:25:07 AM | Attr = ]
nypejuh.dll -> %SystemRoot%\nypejuh.dll -> [Ver = | Size = 15290 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 6/25/2008 12:16:33 AM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 6/19/2008 3:55:04 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 6/24/2008 11:55:42 PM | Attr = H ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 6/21/2008 4:23:35 AM | Attr = ]
security -> %SystemRoot%\security -> [Folder | Modified Date = 6/11/2008 7:18:11 AM | Attr = ]
SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 6/20/2008 1:30:23 AM | Attr = ]
system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 264 bytes | Modified Date = 6/21/2008 5:12:50 PM | Attr = ]
system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 6/24/2008 3:46:23 PM | Attr = ]
TEMP -> %SystemRoot%\TEMP -> [Folder | Modified Date = 6/24/2008 6:31:19 PM | Attr = ]
ufokypi.exe -> %SystemRoot%\ufokypi.exe -> [Ver = | Size = 13228 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr = ]
win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 685 bytes | Modified Date = 6/7/2008 10:59:44 AM | Attr = ]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 6/21/2008 4:47:57 AM | Attr = ]
ysej.bat -> %SystemRoot%\ysej.bat -> [Ver = | Size = 12076 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr = ]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 6/18/2008 5:26:24 PM | Attr = ]
sa.dat -> %SystemRoot%\tasks\sa.dat -> [Ver = | Size = 6 bytes | Modified Date = 6/24/2008 11:54:51 PM | Attr = H ]
C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [Folder | Modified Date = 11/18/2006 3:07:45 AM | Attr = ]
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [Ver = | Size = 1307 bytes | Modified Date = 11/18/2006 3:07:45 AM | Attr = ]
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [Folder | Modified Date = 7/27/2004 1:33:11 AM | Attr = ]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 6740 bytes | Modified Date = 6/25/2008 12:01:01 AM | Attr = ]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 6740 bytes | Modified Date = 6/25/2008 12:01:00 AM | Attr = ]
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
Adobe -> %AllUsersProfile%\Application Data\Adobe -> [Folder | Modified Date = 6/2/2008 9:54:35 PM | Attr = ]
esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat -> [Ver = | Size = 10127 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr = ]
Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Modified Date = 6/21/2008 8:01:16 PM | Attr = ]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Modified Date = 6/21/2008 5:21:54 PM | Attr = ]
McAfee -> %AllUsersProfile%\Application Data\McAfee -> [Folder | Modified Date = 6/22/2008 10:09:07 PM | Attr = ]
Microsoft -> %AllUsersProfile%\Application Data\Microsoft -> [Folder | Modified Date = 5/28/2008 11:36:48 AM | Attr = S]
NetZero -> %AllUsersProfile%\Application Data\NetZero -> [Folder | Modified Date = 6/11/2008 8:45:14 AM | Attr = ]
SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor -> [Folder | Modified Date = 6/22/2008 10:09:16 PM | Attr = ]
Symantec -> %AllUsersProfile%\Application Data\Symantec -> [Folder | Modified Date = 6/20/2008 4:21:24 AM | Attr = ]
ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe -> [Ver = | Size = 16907 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr = ]
AdobeUM -> %AppData%\AdobeUM -> [Folder | Modified Date = 6/2/2008 9:50:56 PM | Attr = ]
fijizojeqy.scr -> %AppData%\fijizojeqy.scr -> [Ver = | Size = 19403 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr = ]
Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Modified Date = 6/21/2008 5:21:59 PM | Attr = ]
Move Networks -> %AppData%\Move Networks -> [Folder | Modified Date = 6/9/2008 3:13:10 AM | Attr = H ]
OLYMPUS -> %AppData%\OLYMPUS -> [Folder | Modified Date = 6/4/2008 3:15:39 AM | Attr = ]
Qualcomm -> %AppData%\Qualcomm -> [Folder | Modified Date = 5/31/2008 11:43:53 PM | Attr = ]
SiteAdvisor -> %AppData%\SiteAdvisor -> [Folder | Modified Date = 6/25/2008 12:03:46 AM | Attr = ]
Skype -> %AppData%\Skype -> [Folder | Modified Date = 6/25/2008 12:16:21 AM | Attr = ]
subybalus.vbs -> %AppData%\subybalus.vbs -> [Ver = | Size = 13212 bytes | Modified Date = 6/19/2008 10:21:23 PM | Attr = ]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory -> [Folder | Modified Date = 6/24/2008 11:56:16 PM | Attr = ]
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 135680 bytes | Modified Date = 6/4/2008 3:53:25 AM | Attr = ]
ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com -> [Ver = | Size = 15688 bytes | Modified Date = 6/19/2008 10:21:20 PM | Attr = ]
Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 6/7/2008 11:05:18 AM | Attr = ]
NOS -> %UserProfile%\Local Settings\Application Data\NOS -> [Folder | Modified Date = 6/2/2008 9:55:39 PM | Attr = ]
ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib -> [Ver = | Size = 16217 bytes | Modified Date = 6/19/2008 10:21:25 PM | Attr = ]
ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db -> [Ver = | Size = 10240 bytes | Modified Date = 6/19/2008 10:21:21 PM | Attr = ]
onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib -> [Ver = | Size = 10336 bytes | Modified Date = 6/19/2008 10:21:26 PM | Attr = ]
yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban -> [Ver = | Size = 15937 bytes | Modified Date = 6/19/2008 10:21:26 PM | Attr = ]
yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat -> [Ver = | Size = 12956 bytes | Modified Date = 6/19/2008 10:21:18 PM | Attr = ]
agnes.doc -> %UserProfile%\My Documents\agnes.doc -> [Ver = | Size = 19456 bytes | Modified Date = 5/29/2008 1:22:47 AM | Attr = ]
Asempa -> %UserProfile%\My Documents\Asempa -> [Folder | Modified Date = 6/4/2008 3:53:14 AM | Attr = ]
5 C:\Documents and Settings\Rushelle Byfield\My Documents\*.tmp files -> C:\Documents and Settings\Rushelle Byfield\My Documents\*.tmp ->
Backup of blog.wbk -> %UserProfile%\My Documents\Backup of blog.wbk -> [Ver = | Size = 288768 bytes | Modified Date = 6/21/2008 8:29:50 PM | Attr = ]
blog.doc -> %UserProfile%\My Documents\blog.doc -> [Ver = | Size = 303104 bytes | Modified Date = 6/22/2008 4:17:27 AM | Attr = ]
Junior Year -> %UserProfile%\My Documents\Junior Year -> [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr = ]
My Digital Editions -> %UserProfile%\My Documents\My Digital Editions -> [Folder | Modified Date = 6/6/2008 4:01:11 PM | Attr = ]
My Media -> %UserProfile%\My Documents\My Media -> [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr = ]
My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 6/13/2008 4:46:55 PM | Attr = R ]
My Skype Pictures -> %UserProfile%\My Documents\My Skype Pictures -> [Folder | Modified Date = 6/4/2008 3:53:16 AM | Attr = ]
Adobe Reader 7.0.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 7.0.lnk -> [Ver = | Size = 1740 bytes | Modified Date = 6/2/2008 9:54:53 PM | Attr = ]
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk -> [Ver = | Size = 2137 bytes | Modified Date = 6/24/2008 3:32:37 PM | Attr = ]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk -> [Ver = | Size = 696 bytes | Modified Date = 6/21/2008 7:58:32 PM | Attr = ]
NetZero Internet.lnk -> %AllUsersProfile%\Desktop\NetZero Internet.lnk -> [Ver = | Size = 1649 bytes | Modified Date = 6/11/2008 8:47:02 AM | Attr = ]
OLYMPUS Master.lnk -> %AllUsersProfile%\Desktop\OLYMPUS Master.lnk -> [Ver = | Size = 774 bytes | Modified Date = 6/4/2008 3:02:26 AM | Attr = ]
DT music -> %UserProfile%\Desktop\DT music -> [Folder | Modified Date = 5/28/2008 3:27:07 PM | Attr = ]
edu01.pdf -> %UserProfile%\Desktop\edu01.pdf -> [Ver = | Size = 322314 bytes | Modified Date = 6/11/2008 4:35:20 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\edu01.pdf:Zone.Identifier
EE -> %UserProfile%\Desktop\EE -> [Folder | Modified Date = 6/4/2008 2:50:07 AM | Attr = ]
HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1717 bytes | Modified Date = 6/20/2008 3:15:26 PM | Attr = ]
Houding Request Form 08-09.doc -> %UserProfile%\Desktop\Houding Request Form 08-09.doc -> [Ver = | Size = 34304 bytes | Modified Date = 5/28/2008 4:07:41 AM | Attr = ]
hrd01.pdf -> %UserProfile%\Desktop\hrd01.pdf -> [Ver = | Size = 132425 bytes | Modified Date = 6/11/2008 5:09:27 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\hrd01.pdf:Zone.Identifier
Japan Apps -> %UserProfile%\Desktop\Japan Apps -> [Folder | Modified Date = 6/22/2008 9:55:26 PM | Attr = ]
Kobukuro All Singles Best Disk 1.zip -> %UserProfile%\Desktop\Kobukuro All Singles Best Disk 1.zip -> [Ver = | Size = 122004021 bytes | Modified Date = 5/28/2008 3:25:31 PM | Attr = ]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes [Ver = 1.0.0.0 | Size = 1665344 bytes | Modified Date = 6/21/2008 5:02:56 PM | Attr = ]
Microsoft Word.lnk -> %UserProfile%\Desktop\Microsoft Word.lnk -> [Ver = | Size = 2473 bytes | Modified Date = 6/21/2008 5:12:36 AM | Attr = ]
New Folder -> %UserProfile%\Desktop\New Folder -> [Folder | Modified Date = 6/11/2008 7:42:58 AM | Attr = ]
OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Modified Date = 6/25/2008 12:17:16 AM | Attr = ]
OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 568483 bytes | Modified Date = 6/25/2008 12:16:10 AM | Attr = ]
Poland.doc -> %UserProfile%\Desktop\Poland.doc -> [Ver = | Size = 46080 bytes | Modified Date = 6/11/2008 10:21:56 AM | Attr = ]
review.pdf -> %UserProfile%\Desktop\review.pdf -> [Ver = | Size = 4219863 bytes | Modified Date = 6/8/2008 1:01:08 PM | Attr = ]
shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> %UserProfile%\Desktop\shounen_club_premium_2006.06.18_nagase_tomoya_english_subs.avi -> [Ver = | Size = 317927018 bytes | Modified Date = 6/22/2008 11:07:58 PM | Attr = ]
unem01.pdf -> %UserProfile%\Desktop\unem01.pdf -> [Ver = | Size = 334437 bytes | Modified Date = 6/11/2008 4:48:31 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\unem01.pdf:Zone.Identifier
Unused Desktop Shortcuts -> %UserProfile%\Desktop\Unused Desktop Shortcuts -> [Folder | Modified Date = 6/4/2008 3:46:10 AM | Attr = ]
Videos -> %UserProfile%\Desktop\Videos -> [Folder | Modified Date = 5/31/2008 4:07:27 PM | Attr = ]
zeroincomeselfcertifyingstatement.pdf -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf -> [Ver = | Size = 1311577 bytes | Modified Date = 6/11/2008 5:06:48 AM | Attr = ]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\zeroincomeselfcertifyingstatement.pdf:Zone.Identifier
[G no Arashi] 2006.02.08 - ep18.avi -> %UserProfile%\Desktop\[G no Arashi] 2006.02.08 - ep18.avi -> [Ver = | Size = 231014400 bytes | Modified Date = 6/16/2008 6:56:50 PM | Attr = ]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> [Ver = | Size = 1757 bytes | Modified Date = 6/2/2008 9:54:53 PM | Attr = ]
VPN Client.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\VPN Client.lnk -> [Ver = | Size = 2447 bytes | Modified Date = 6/24/2008 11:55:33 PM | Attr = ]
Picture Motion Browser Media Check Tool.lnk -> %UserProfile%\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk -> [Ver = | Size = 1983 bytes | Modified Date = 6/20/2008 3:53:55 PM | Attr = ]
Adobe -> %CommonProgramFiles%\Adobe -> [Folder | Modified Date = 6/2/2008 9:54:16 PM | Attr = ]
ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl -> [Ver = | Size = 14741 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr = ]
exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys -> [Ver = | Size = 19255 bytes | Modified Date = 6/19/2008 10:21:22 PM | Attr = ]
qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat -> [Ver = | Size = 19448 bytes | Modified Date = 6/19/2008 10:21:17 PM | Attr = ]
Symantec Shared -> %CommonProgramFiles%\Symantec Shared -> [Folder | Modified Date = 6/20/2008 4:21:23 AM | Attr = ]
System -> %CommonProgramFiles%\System -> [Folder | Modified Date = 6/21/2008 4:40:36 AM | Attr = ]
ziti.db -> %CommonProgramFiles%\ziti.db -> [Ver = | Size = 16038 bytes | Modified Date = 6/19/2008 10:21:20 PM | Attr = ]
[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden files …
IPC error: 2 The system cannot find the file specified.
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\EE\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\Desktop\senior slide\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Videos\Veoh\AppBackup\Images\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Videos\Veoh\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Random Stuff\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Junior Year\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Media\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Aim music\In My Own Words\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Aim music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Bismol\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\corazon\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\mytunes\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Other\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Music\Other Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-18-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-21-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\1-27-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-1-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-10-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-17-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\11-7-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-13-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-13-2007(2)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-29-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\12-3-2007\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\2-25-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\2-7-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-1-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-10-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\4-29-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-18-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-24-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-26-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\5-27-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\6-4-2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\Japan 1\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\Nihon\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\other\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\ramification\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\silly 'ol me\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\The fam\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\weasels\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\ANAE\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\my pic_jpg_files\John Legend\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Pictures\Random\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2005-09 (Sep)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2005-12 (Dec)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-03 (Mar)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-09 (Sep)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Scans\2006-10 (Oct)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Skype Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\My Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\Asempa\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\2006_10_02\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Rushelle Byfield\My Documents\download\junebug6272\Adobe_Acrobat_5.0\Thumbs.db:encryptable 0 bytes
scan completed successfully
hidden files: 65
< End of report >[Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run YN -> ClubBox -> [] [Files/Folders - Created Within 30 days] NY -> kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg NY -> aqucutuq.inf -> %SystemRoot%\aqucutuq.inf NY -> hucyl._dl -> %SystemRoot%\hucyl._dl NY -> jadematy._sy -> %SystemRoot%\jadematy._sy NY -> kiqyji.scr -> %SystemRoot%\kiqyji.scr NY -> miwohej.lib -> %SystemRoot%\miwohej.lib NY -> nypejuh.dll -> %SystemRoot%\nypejuh.dll NY -> QTFont.for -> %SystemRoot%\QTFont.for NY -> QTFont.qfn -> %SystemRoot%\QTFont.qfn NY -> TEMP -> %SystemRoot%\TEMP NY -> ufokypi.exe -> %SystemRoot%\ufokypi.exe NY -> ysej.bat -> %SystemRoot%\ysej.bat [Files Created - Additional Folder Scans - Non-Microsoft Only] NY -> esabodomy.dat -> %AllUsersProfile%\Application Data\esabodomy.dat NY -> ydedotyne.exe -> %AllUsersProfile%\Application Data\ydedotyne.exe NY -> subybalus.vbs -> %AppData%\subybalus.vbs NY -> ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com NY -> ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib NY -> ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db NY -> onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib NY -> yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban NY -> yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat NY -> ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl NY -> qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat NY -> ziti.db -> %CommonProgramFiles%\ziti.db [Files/Folders - Modified Within 30 days] NY -> kiqeduh.reg -> %SystemRoot%\System32\kiqeduh.reg NY -> aqucutuq.inf -> %SystemRoot%\aqucutuq.inf NY -> hucyl._dl -> %SystemRoot%\hucyl._dl NY -> imsins.BAK -> %SystemRoot%\imsins.BAK NY -> jadematy._sy -> %SystemRoot%\jadematy._sy NY -> kiqyji.scr -> %SystemRoot%\kiqyji.scr NY -> miwohej.lib -> %SystemRoot%\miwohej.lib NY -> nypejuh.dll -> %SystemRoot%\nypejuh.dll NY -> QTFont.for -> %SystemRoot%\QTFont.for NY -> QTFont.qfn -> %SystemRoot%\QTFont.qfn NY -> ufokypi.exe -> %SystemRoot%\ufokypi.exe NY -> ysej.bat -> %SystemRoot%\ysej.bat [Files Modified - Additional Folder Scans - Non-Microsoft Only] NY -> fijizojeqy.scr -> %AppData%\fijizojeqy.scr NY -> ilafubopop.com -> %UserProfile%\Local Settings\Application Data\ilafubopop.com NY -> ufuhuwokub.lib -> %UserProfile%\Local Settings\Application Data\ufuhuwokub.lib NY -> ujulis.db -> %UserProfile%\Local Settings\Application Data\ujulis.db NY -> onecybov.lib -> %AllUsersProfile%\Documents\onecybov.lib NY -> yxivuseleh.ban -> %AllUsersProfile%\Documents\yxivuseleh.ban NY -> yzalape.bat -> %AllUsersProfile%\Documents\yzalape.bat NY -> ebyjodav._dl -> %CommonProgramFiles%\ebyjodav._dl NY -> exehiqudaw.sys -> %CommonProgramFiles%\exehiqudaw.sys NY -> qymywyxa.bat -> %CommonProgramFiles%\qymywyxa.bat NY -> ziti.db -> %CommonProgramFiles%\ziti.db [Extra Files] c:\windows\system32\cru629.dat
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI