[code] OTScanIt logfile created on: 5/7/2008 5:04:47 PM OTScanIt by OldTimer - Version 1.0.12.1 Folder = C:\Documents and Settings\brent\Desktop\OTScanIt Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2800.1106) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 254.48 Mb Total Physical Memory | 134.60 Mb Available Physical Memory | 52.89% Memory free 625.82 Mb Paging File | 423.26 Mb Available in Paging File | 67.63% Paging File free Paging file location(s): c:\pagefile.sys 384 768; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 55.87 Gb Total Space | 6.70 Gb Free Space | 11.99% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: HOME-H9I3MI4FZ6 Current User Name: brent Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users [Processes - Non-Microsoft Only] aswupdsv.exe -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 17272 bytes | Modified Date = 3/29/2008 1:11:18 PM | Attr = ] ashserv.exe -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 144760 bytes | Modified Date = 3/29/2008 1:37:02 PM | Attr = ] ashdisp.exe -> %ProgramFiles%\Alwil Software\Avast4\ashDisp.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 79224 bytes | Modified Date = 3/29/2008 1:37:13 PM | Attr = ] mpbtn.exe -> %ProgramFiles%\Virtual Assistant\bin\mpbtn.exe -> [Ver = | Size = 192512 bytes | Modified Date = 6/3/2005 9:25:18 AM | Attr = ] wtsrv.exe -> %SystemRoot%\system32\drivers\WTSrv.exe -> Tablet Driver [Ver = 4.03.02 | Size = 40960 bytes | Modified Date = 9/29/2003 9:41:32 PM | Attr = ] ashwebsv.exe -> %ProgramFiles%\Alwil Software\Avast4\ashWebSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 345464 bytes | Modified Date = 3/29/2008 1:30:47 PM | Attr = ] ashmaisv.exe -> %ProgramFiles%\Alwil Software\Avast4\ashMaiSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 247160 bytes | Modified Date = 3/29/2008 1:36:22 PM | Attr = ] otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.12.1 | Size = 372224 bytes | Modified Date = 5/6/2008 2:53:20 PM | Attr = ] [Win32 Services - Non-Microsoft Only] (aswUpdSv) avast! iAVS4 Control Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 17272 bytes | Modified Date = 3/29/2008 1:11:18 PM | Attr = ] (avast! Antivirus) avast! Antivirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 144760 bytes | Modified Date = 3/29/2008 1:37:02 PM | Attr = ] (avast! Mail Scanner) avast! Mail Scanner [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Alwil Software\Avast4\ashMaiSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 247160 bytes | Modified Date = 3/29/2008 1:36:22 PM | Attr = ] (avast! Web Scanner) avast! Web Scanner [Win32_Own | On_Demand | Running] -> %ProgramFiles%\Alwil Software\Avast4\ashWebSv.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 345464 bytes | Modified Date = 3/29/2008 1:30:47 PM | Attr = ] (BackWeb Plug-in - 7211241) EMBARQ Online Security [Win32_Own | Disabled | Stopped] -> %SystemDrive%\PROGRA~1\EMBARQ~1\backweb\7211241\Program\SERVIC~1.EXE -> File not found (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 204800 bytes | Modified Date = 9/3/2002 11:31:03 AM | Attr = ] (F-Secure Gatekeeper Handler Starter) FSGKHS [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\EMBARQ Online Security\Anti-Virus\fsgk32st.exe -> F-Secure Corporation [Ver = 7.30.13110 | Size = 47800 bytes | Modified Date = 11/1/2007 6:42:04 AM | Attr = ] (FSAUA) F-Secure Automatic Update Agent [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\EMBARQ Online Security\FSAUA\program\fsaua.exe -> F-Secure Corporation [Ver = 8.23.2376 | Size = 461408 bytes | Modified Date = 11/1/2007 6:41:52 AM | Attr = ] (FSDFWD) F-Secure Anti-Virus Firewall Daemon [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\EMBARQ Online Security\FWES\program\fsdfwd.exe -> F-Secure Corporation [Ver = 6.16.71 | Size = 453216 bytes | Modified Date = 11/1/2007 6:42:16 AM | Attr = ] (FSMA) FSMA [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\EMBARQ Online Security\Common\FSMA32.EXE -> F-Secure Corporation [Ver = 7.50.10035 | Size = 113304 bytes | Modified Date = 11/1/2007 6:42:56 AM | Attr = ] (iPodService) iPod Service [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.8.0.32 | Size = 327680 bytes | Modified Date = 5/13/2005 11:20:28 PM | Attr = ] (VundoFixSvc) VundoFix Service [Win32_Own | Disabled | Stopped] -> %SystemRoot%\system32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 3/29/2008 2:26:32 AM | Attr = ] (WinTabService) WinTab Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\drivers\WTSrv.exe -> Tablet Driver [Ver = 4.03.02 | Size = 40960 bytes | Modified Date = 9/29/2003 9:41:32 PM | Attr = ] (wuauservuploadmgr) Automatic Updates wuauservuploadmgr [Win32_Own | Disabled | Stopped] -> %SystemRoot%\System32\2052k.exe -> File not found [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> avast! -> %ProgramFiles%\Alwil Software\Avast4\ashDisp.exe [C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe] -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 79224 bytes | Modified Date = 3/29/2008 1:37:13 PM | Attr = ] < Administrator.HOME-H9I3MI4FZ6 Startup Folder > -> C:\Documents and Settings\Administrator.HOME-H9I3MI4FZ6\Start Menu\Programs\Startup -> < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\Virtual Assistant.lnk -> %ProgramFiles%\Virtual Assistant\bin\matcli.exe -> Motive Communications, Inc. [Ver = 5.8.15.asst_classic.asst_matcli.20050603_090500 | Size = 217088 bytes | Modified Date = 6/3/2005 9:25:18 AM | Attr = ] < B Startup Folder > -> C:\Documents and Settings\B\Start Menu\Programs\Startup -> < brent Startup Folder > -> C:\Documents and Settings\brent\Start Menu\Programs\Startup -> < Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup -> < Jenny Startup Folder > -> C:\Documents and Settings\Jenny\Start Menu\Programs\Startup -> < TEMP Startup Folder > -> C:\Documents and Settings\TEMP\Start Menu\Programs\Startup -> < TEMP.HOME-H9I3MI4FZ6.000 Startup Folder > -> C:\Documents and Settings\TEMP.HOME-H9I3MI4FZ6.000\Start Menu\Programs\Startup -> < TEMP.HOME-H9I3MI4FZ6.001 Startup Folder > -> C:\Documents and Settings\TEMP.HOME-H9I3MI4FZ6.001\Start Menu\Programs\Startup -> < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> *SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> zwebauth.dll -> %SystemRoot%\system32\ZWebAuth.dll -> [Ver = | Size = 16973 bytes | Modified Date = 9/18/2001 6:37:34 PM | Attr = ] *MultiFile Done* -> -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveAutoRun -> 67108863 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveTypeAutoRun -> 255 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableRegistryTools -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLegacyLogonScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideLogoffScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunLogonScriptSync -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\RunStartupScriptSync -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\HideStartupScripts -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\WindowsUpdate\ -> -> < CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> -> *DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup -> SCSI miniport -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> C:\WINDOWS\system32\drivers\cdrom.sys [System32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.1106 (xpsp1.020828-1920) | Size = 47488 bytes | Modified Date = 9/3/2002 11:28:26 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 -> *AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable -> NEC MBR-7 -> -> File not found NEC MBR-7.4 -> -> File not found PIONEER CHANGR DRM-1804X -> -> File not found PIONEER CD-ROM DRM-6324X -> -> File not found PIONEER CD-ROM DRM-624X -> -> File not found TORiSAN CD-ROM CDR_C36 -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomLite-On_LTN486S_48x_Max_________________YDS4____\5&1202a50f&0&0.0.0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\1 -> IDE\CdRomHL-DT-ST_CD-RW_GCE-8481B________________1.05____\5&1202a50f&0&0.1.0 -> < HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> C:\windows\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKEY_LOCAL_MACHINE\: URLSearchHooks\\{C8D1A46C-E60D-2C7C-7E2D-84A7A266EF23} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found HKEY_LOCAL_MACHINE\: ProxyOverride -> -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\SYSTEM32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_CURRENT_USER\: Main\\Start Page -> http://www.myembarq.com/index.php -> HKEY_CURRENT_USER\: SearchURL\\ -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch[] -> HKEY_CURRENT_USER\: URLSearchHooks\\{1392b8d2-5c05-419f-a8f6-b9f15a596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] HKEY_CURRENT_USER\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> -> HKEY_USERS\.DEFAULT\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm -> HKEY_USERS\.DEFAULT\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\.DEFAULT\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\.DEFAULT\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> -> HKEY_USERS\S-1-5-18\: Main\\Local Page -> C:\WINDOWS\System32\blank.htm -> HKEY_USERS\S-1-5-18\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-18\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome -> HKEY_USERS\S-1-5-18\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> -> HKEY_USERS\S-1-5-19\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> -> HKEY_USERS\S-1-5-20\: ProxyEnable -> 0 -> < Internet Explorer Settings [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: Main\\Local Page -> C:\WINDOWS\SYSTEM32\blank.htm -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: Main\\Start Page -> http://www.myembarq.com/index.php -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: SearchURL\\ -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch[] -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: URLSearchHooks\\{1392b8d2-5c05-419f-a8f6-b9f15a596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\: ProxyEnable -> 0 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 16 range(s) found. -> < Trusted Sites Domains [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> < Trusted Sites Ranges [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {1392b8d2-5c05-419f-a8f6-b9f15a596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] {53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 11:43:28 AM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {1392b8d2-5c05-419f-a8f6-b9f15a596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\Software\Microsoft\Internet Explorer\Toolbar\ -> WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Freecorder\tbFree.dll [Freecorder Toolbar] -> Conduit Ltd. [Ver = 4, 5, 185, 3 | Size = 1524760 bytes | Modified Date = 4/16/2008 11:06:12 AM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF}:Exec -> %ProgramFiles%\PokerStars\PokerStarsUpdate.exe [PokerStars] -> PokerStars [Ver = 1.030 | Size = 435088 bytes | Modified Date = 2/17/2008 10:46:45 PM | Attr = ] {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 11:43:28 AM | Attr = ] < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73F01} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{300DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\PokerStars\PokerStarsUpdate.exe [PokerStars] -> PokerStars [Ver = 1.030 | Size = 435088 bytes | Modified Date = 2/17/2008 10:46:45 PM | Attr = ] CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{d9288080-1baa-4bc4-9cf8-a92d743db949} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 11:43:28 AM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &Block this popup -> %ProgramFiles%\EMBARQ Online Security\Anti-Spyware\blockpopups.htm -> File not found < Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73F01} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{300DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{d9288080-1baa-4bc4-9cf8-a92d743db949} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73F01} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{300DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{d9288080-1baa-4bc4-9cf8-a92d743db949} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Extensions [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{200DB664-75B5-47c0-8B45-A44ACCF73F01} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{300DB664-75B5-47c0-8B45-A44ACCF73C00} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\PokerStars\PokerStarsUpdate.exe [PokerStars] -> PokerStars [Ver = 1.030 | Size = 435088 bytes | Modified Date = 2/17/2008 10:46:45 PM | Attr = ] CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{d9288080-1baa-4bc4-9cf8-a92d743db949} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [Spybot - Search & Destroy Configuration] -> Safer Networking Limited [Ver = 1, 5, 0, 11 | Size = 1554256 bytes | Modified Date = 1/28/2008 11:43:28 AM | Attr = ] CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> File not found < Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\Software\Microsoft\Internet Explorer\MenuExt\ -> &Block this popup -> %ProgramFiles%\EMBARQ Online Security\Anti-Spyware\blockpopups.htm -> File not found < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> Protocol_Catalog9\Catalog_Entries\000000000001 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000002 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000003 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000004 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000005 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000006 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000007 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000008 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000009 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000010 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000011 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000012 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000013 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000014 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000015 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000016 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000017 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000018 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000019 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000020 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000021 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000022 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000023 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000024 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000025 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000026 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000027 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000028 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] Protocol_Catalog9\Catalog_Entries\000000000029 -> %ProgramFiles%\EMBARQ Online Security\FSPS\program\fslsp.dll -> F-Secure Corporation [Ver = 2.00.240 | Size = 207456 bytes | Modified Date = 11/1/2007 6:43:24 AM | Attr = ] < Default Protocols [HKEY_CURRENT_USER\] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\.DEFAULT\] - Select to Repair > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-18\] - Select to Repair > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-19\] - Select to Repair > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-20\] - Select to Repair > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\] - Select to Repair > -> HKEY_USERS\S-1-5-21-484763869-261903793-1801674531-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx[AsyncPProt Class] -> [Ver = | Size = 842268 bytes | Modified Date = 9/3/2002 11:44:26 AM | Attr = ] < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {0B79F48A-E8D6-11DB-9283-E25056D89593}[HKEY_LOCAL_MACHINE] -> http://support.f-secure.com/ols/fscax.cab[F-Secure Online Scanner 3.1] -> {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}[HKEY_LOCAL_MACHINE] -> http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab[CKAVWebScan Object] -> {17492023-C23A-453E-A040-C7C580BBF700}[HKEY_LOCAL_MACHINE] -> http://go.microsoft.com/fwlink/?linkid=39204[Windows Genuine Advantage Validation Tool] -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}[HKEY_LOCAL_MACHINE] -> http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab[ActiveScan 2.0 Installer Class] -> DirectAnimation Java Classes[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\dajava.cab[Reg Error: Key does not exist or could not be opened.] -> Microsoft XML Parser for Java[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> < Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/as2stubie.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/as2stubie.dll\\.Owner -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/as2stubie.dll\\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/asinst.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/asinst.dll\\.Owner -> {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/asinst.dll\\{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ca.pub\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ca.pub\\.Owner -> {0B79F48A-E8D6-11DB-9283-E25056D89593} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ca.pub\\{0B79F48A-E8D6-11DB-9283-E25056D89593} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/detect.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/detect.dll\\.Owner -> {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/detect.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MVT.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MVT.dll\\.Owner -> {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MVT.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/detect.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/detect.dll\\.Owner -> {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/detect.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/MVT.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/MVT.dll\\.Owner -> {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.2/MVT.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.4/QDow_AS2.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.4/QDow_AS2.dll\\.Owner -> {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.4/QDow_AS2.dll\\{87067F04-DE4C-4688-BC3C-4FCF39D609E7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/daas_s.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/daas_s.dll\\.Owner -> {0B79F48A-E8D6-11DB-9283-E25056D89593} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/daas_s.dll\\{0B79F48A-E8D6-11DB-9283-E25056D89593} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fsauc.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fsauc.dll\\.Owner -> {0B79F48A-E8D6-11DB-9283-E25056D89593} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fsauc.dll\\{0B79F48A-E8D6-11DB-9283-E25056D89593} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fscax.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fscax.dll\\.Owner -> {0B79F48A-E8D6-11DB-9283-E25056D89593} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/fscax.dll\\{0B79F48A-E8D6-11DB-9283-E25056D89593} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ITDetector.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ITDetector.ocx\\.Owner -> {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ITDetector.ocx\\{D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libcomm.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libcomm.dll\\.Owner -> {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/libcomm.dll\\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/McUpdatePortal.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/McUpdatePortal.dll\\.Owner -> {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/McUpdatePortal.dll\\{5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/messengerstatsclient.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/messengerstatsclient.dll\\.Owner -> {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/messengerstatsclient.dll\\{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\.Owner -> {14B87622-7E19-4EA8-93B3-97215F77A6BC} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/MessengerStatsPAClient.dll\\{14B87622-7E19-4EA8-93B3-97215F77A6BC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/mnviewer.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/mnviewer.dll\\.Owner -> {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/mnviewer.dll\\{1239CC52-59EF-4DFA-8C61-90FFA846DF7E} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\\.Owner -> {00B71CFB-6864-4346-A978-C0A14556272C} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/msgrchkr.dll\\{00B71CFB-6864-4346-A978-C0A14556272C} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/solitaireshowdown.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/solitaireshowdown.dll\\.Owner -> {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/solitaireshowdown.dll\\{F6BF0D00-0B2A-4A75-BF7B-F385591623AF} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ZIntro.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ZIntro.ocx\\.Owner -> {B8BE5E93-A60C-4D26-A2DC-220313175592} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ZIntro.ocx\\{B8BE5E93-A60C-4D26-A2DC-220313175592} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/atl.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/atl.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/atl.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/LegitCheckControl.DLL\\{17492023-C23A-453E-A040-C7C580BBF700} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/MsVcp60.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/MsVcp60.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/MsVcp60.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/unicows.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/unicows.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/unicows.dll\\{78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\.Owner -> Unknown Owner -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/wuweb.dll\\{6414512B-B978-451D-A0D8-FCFDF33E833C} -> -> [Registry - Additional Scans - Non-Microsoft Only] < ControlSets > HKEY_LOCAL_MACHINE\SYSTEM\Select\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\Select\\Current -> 6 -> HKEY_LOCAL_MACHINE\SYSTEM\Select\\Default -> 6 -> HKEY_LOCAL_MACHINE\SYSTEM\Select\\Failed -> 4 -> HKEY_LOCAL_MACHINE\SYSTEM\Select\\LastKnownGood -> 7 -> < Disabled MSConfig Services [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services -> BackWeb Plug-in - 7211241 -> -> ccEvtMgr -> -> ccProxy -> -> Client IP-IPX -> -> cmdService -> -> Emproxy -> -> FSAUA -> -> FSDFWD -> -> F-Secure Gatekeeper Handler Starter -> -> FSMA -> -> iPodService -> -> ipv7 -> -> kq92 -> -> McAfee HackerWatch Service -> -> McRedirector -> -> McShield -> -> McSysmon -> -> mcupdmgr.exe -> -> MsaSvc -> -> MSLLR -> -> Navastc -> -> SERVICE32 -> -> sysmgr64 -> -> VundoFixSvc -> -> Windows System 32 -> -> wlmsngr -> -> wuauservuploadmgr -> -> < Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ -> C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Update_0711_KB060653.exe -> %AllUsersProfile%\Start Menu\Programs\Startup\Update_0711_KB060653.exe -> File not found < Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ -> AIM hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\instant messenger\aim.exe -> America Online, Inc. [Ver = 5.5.3596 | Size = 61440 bytes | Modified Date = 6/15/2004 10:36:14 AM | Attr = ] autoload hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %UserProfile%\cftmon.exe -> File not found E6TaskPanel hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\EarthLink TotalAccess\TaskPanl.exe -> EarthLink, Inc. [Ver = 2004.1.42.0 | Size = 733184 bytes | Modified Date = 12/8/2003 2:51:44 PM | Attr = ] F-Secure Manager hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\EMBARQ Online Security\Common\FSM32.EXE -> F-Secure Corporation [Ver = 7.50.10035 | Size = 182936 bytes | Modified Date = 11/1/2007 6:42:56 AM | Attr = ] F-Secure TNB hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\EMBARQ Online Security\FSGUI\tnbutil.exe -> F-Secure Corporation [Ver = 1.09.5230 | Size = 739936 bytes | Modified Date = 11/1/2007 6:42:48 AM | Attr = ] iTunesHelper hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 4.8.0.32 | Size = 278528 bytes | Modified Date = 5/13/2005 11:20:50 PM | Attr = ] KernelFaultCheck hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> -> File not found ntuser hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %SystemRoot%\system32\drivers\spools.exe -> File not found QuickTime Task hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.5a38 | Size = 282624 bytes | Modified Date = 1/17/2007 2:31:11 AM | Attr = ] SpybotSD TeaTimer hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe -> Safer Networking Limited [Ver = 1, 5, 2, 16 | Size = 2097488 bytes | Modified Date = 1/28/2008 11:43:40 AM | Attr = RHS] < File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ -> .bat [@ = batfile] -> -> File not found .cmd [@ = cmdfile] -> -> File not found .com [@ = comfile] -> -> File not found .exe [@ = exefile] -> -> File not found .pif [@ = piffile] -> -> File not found .scr [@ = scrfile] -> -> File not found [Files/Folders - Created Within 90 days] Boot.bak -> %SystemDrive%\Boot.bak -> [Ver = | Size = 194 bytes | Created Date = 2/21/2008 4:50:45 PM | Attr = ] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 2/21/2008 4:50:38 PM | Attr = ] cmldr -> %SystemDrive%\cmldr -> [Ver = | Size = 245920 bytes | Created Date = 2/21/2008 4:50:40 PM | Attr = ] QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 5/6/2008 8:35:03 PM | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 5/6/2008 9:03:50 PM | Attr = HS] VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Created Date = 3/29/2008 2:07:31 AM | Attr = ] aavmker4.sys -> %SystemRoot%\System32\drivers\aavmker4.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 26944 bytes | Created Date = 5/7/2008 10:37:18 AM | Attr = ] aswmon.sys -> %SystemRoot%\System32\drivers\aswmon.sys -> ALWIL Software [Ver = 4.7.1098.0 | Size = 93264 bytes | Created Date = 5/7/2008 10:37:01 AM | Attr = ] aswmon2.sys -> %SystemRoot%\System32\drivers\aswmon2.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 94544 bytes | Created Date = 5/7/2008 10:37:01 AM | Attr = ] aswSP.sys -> %SystemRoot%\System32\drivers\aswSP.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 75856 bytes | Created Date = 5/7/2008 10:37:01 AM | Attr = ] aswTdi.sys -> %SystemRoot%\System32\drivers\aswTdi.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 42912 bytes | Created Date = 5/7/2008 10:37:18 AM | Attr = ] AC3ACM.acm -> %SystemRoot%\System32\AC3ACM.acm -> fccHandler [Ver = 0, 7, 0, 0 | Size = 81920 bytes | Created Date = 5/2/2008 9:29:22 PM | Attr = ] alf2cd.acm -> %SystemRoot%\System32\alf2cd.acm -> NCT Company [Ver = 2.03 | Size = 38912 bytes | Created Date = 5/2/2008 9:29:22 PM | Attr = ] divx.dll -> %SystemRoot%\System32\divx.dll -> DivXNetworks, Inc. [Ver = 5.0.5.830 | Size = 638976 bytes | Created Date = 5/2/2008 9:29:23 PM | Attr = ] divxdec.ax -> %SystemRoot%\System32\divxdec.ax -> DivXNetworks, Inc. [Ver = 5.0.5.830 | Size = 221215 bytes | Created Date = 5/2/2008 9:29:24 PM | Attr = ] FTP34.0LL -> %SystemRoot%\System32\FTP34.0LL -> [Ver = | Size = 5120 bytes | Created Date = 5/5/2008 12:58:42 AM | Attr = ] IDME -> %SystemRoot%\System32\IDME -> [Folder | Created Date = 3/28/2008 3:49:38 AM | Attr = ] 6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Created Date = 2/22/2008 5:33:03 PM | Attr = ] mcdvd_32.dll -> %SystemRoot%\System32\mcdvd_32.dll -> MainConcept [Ver = 2.0.4 | Size = 261632 bytes | Created Date = 5/2/2008 9:29:23 PM | Attr = ] Scg726.acm -> %SystemRoot%\System32\Scg726.acm -> SHARP Corporation [Ver = 1, 0, 0, 3 | Size = 13239 bytes | Created Date = 5/2/2008 9:29:22 PM | Attr = ] vct3216.acm -> %SystemRoot%\System32\vct3216.acm -> Voxware, Inc. [Ver = 1.6.0.17 | Size = 82944 bytes | Created Date = 5/2/2008 9:29:22 PM | Attr = ] VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Created Date = 3/29/2008 2:26:32 AM | Attr = ] winz1 -> %SystemRoot%\System32\winz1 -> [Folder | Created Date = 3/28/2008 3:49:39 AM | Attr = ] xTmp -> %SystemRoot%\System32\xTmp -> [Folder | Created Date = 3/28/2008 3:49:38 AM | Attr = ] xvid.ax -> %SystemRoot%\System32\xvid.ax -> [Ver = | Size = 53248 bytes | Created Date = 5/2/2008 9:29:23 PM | Attr = ] xvidcore.dll -> %SystemRoot%\System32\xvidcore.dll -> [Ver = | Size = 524288 bytes | Created Date = 5/2/2008 9:29:23 PM | Attr = ] xvidvfw.dll -> %SystemRoot%\System32\xvidvfw.dll -> [Ver = | Size = 139264 bytes | Created Date = 5/2/2008 9:29:23 PM | Attr = ] Applian FLV Player -> %SystemRoot%\Applian FLV Player -> [Folder | Created Date = 5/2/2008 8:41:04 PM | Attr = ] 9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> cpu.PIF -> %SystemRoot%\cpu.PIF -> [Ver = | Size = 2855 bytes | Created Date = 2/23/2008 8:08:34 PM | Attr = ] fdsv.exe -> %SystemRoot%\fdsv.exe -> Smallfrogs Studio [Ver = 1.0.0.10 | Size = 73728 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] Freecorder Toolbar -> %SystemRoot%\Freecorder Toolbar -> [Folder | Created Date = 5/2/2008 8:52:17 PM | Attr = ] grep.exe -> %SystemRoot%\grep.exe -> [Ver = | Size = 80412 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] Nircmd.exe -> %SystemRoot%\Nircmd.exe -> NirSoft [Ver = 2.05 | Size = 28160 bytes | Created Date = 3/29/2008 6:21:35 PM | Attr = ] Replay Media Catcher -> %SystemRoot%\Replay Media Catcher -> [Folder | Created Date = 5/2/2008 8:48:07 PM | Attr = ] sed.exe -> %SystemRoot%\sed.exe -> [Ver = | Size = 98816 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] swreg.exe -> %SystemRoot%\swreg.exe -> SteelWerX [Ver = 3.0.0.0 | Size = 161792 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] swsc.exe -> %SystemRoot%\swsc.exe -> SteelWerX [Ver = 2.0.0.5 | Size = 136704 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] swxcacls.exe -> %SystemRoot%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] TEMP -> %SystemRoot%\TEMP -> [Folder | Created Date = 5/6/2008 8:57:12 PM | Attr = ] unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 2550 bytes | Created Date = 3/6/2008 10:28:22 PM | Attr = ] unins000.exe -> %SystemRoot%\unins000.exe -> [Ver = 51.49.0.0 | Size = 691545 bytes | Created Date = 3/6/2008 10:28:23 PM | Attr = ] VFind.exe -> %SystemRoot%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] WMSysPr8.prx -> %SystemRoot%\WMSysPr8.prx -> [Ver = | Size = 156910 bytes | Created Date = 5/2/2008 9:29:24 PM | Attr = ] zip.exe -> %SystemRoot%\zip.exe -> [Ver = | Size = 68096 bytes | Created Date = 5/6/2008 8:34:59 PM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] AVS4YOU -> %AllUsersProfile%\Application Data\AVS4YOU -> [Folder | Created Date = 5/2/2008 9:33:46 PM | Attr = ] Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Created Date = 2/22/2008 5:33:06 PM | Attr = ] Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Created Date = 2/25/2008 2:41:33 AM | Attr = ] AVS4YOU -> %AppData%\AVS4YOU -> [Folder | Created Date = 5/2/2008 9:34:19 PM | Attr = ] GetRightToGo -> %AppData%\GetRightToGo -> [Folder | Created Date = 5/2/2008 8:42:52 PM | Attr = ] Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Created Date = 2/25/2008 2:42:06 AM | Attr = ] Media Player Classic -> %AppData%\Media Player Classic -> [Folder | Created Date = 3/13/2008 7:37:31 AM | Attr = ] Conduit -> %UserProfile%\Local Settings\Application Data\Conduit -> [Folder | Created Date = 5/2/2008 8:54:06 PM | Attr = ] Freecorder -> %UserProfile%\Local Settings\Application Data\Freecorder -> [Folder | Created Date = 5/2/2008 8:53:38 PM | Attr = ] GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 50504 bytes | Created Date = 4/23/2008 3:16:37 AM | Attr = ] MediaMonkey -> %UserProfile%\Local Settings\Application Data\MediaMonkey -> [Folder | Created Date = 3/13/2008 3:36:21 AM | Attr = ] Commercial Luffa Sponge Gourd Production.htm -> %AllUsersProfile%\Documents\Commercial Luffa Sponge Gourd Production.htm -> [Ver = | Size = 15484 bytes | Created Date = 4/12/2008 4:44:42 PM | Attr = ] Commercial Luffa Sponge Gourd Production_files -> %AllUsersProfile%\Documents\Commercial Luffa Sponge Gourd Production_files -> [Folder | Created Date = 4/12/2008 4:44:43 PM | Attr = ] HHEELLPP -> %AllUsersProfile%\Documents\HHEELLPP -> [Folder | Created Date = 5/5/2008 11:18:17 PM | Attr = ] hil-120.html -> %AllUsersProfile%\Documents\hil-120.html -> [Ver = | Size = 15523 bytes | Created Date = 4/12/2008 4:43:37 PM | Attr = ] i1040gi.pdf -> %AllUsersProfile%\Documents\i1040gi.pdf -> [Ver = | Size = 1468206 bytes | Created Date = 4/7/2008 6:30:23 PM | Attr = ] V R Z -> %AllUsersProfile%\Documents\V R Z -> [Folder | Created Date = 3/18/2008 9:48:12 PM | Attr = ] application brnes&nbl.pdf -> %UserProfile%\My Documents\application brnes&nbl.pdf -> [Ver = | Size = 48766 bytes | Created Date = 4/14/2008 7:44:53 PM | Attr = ] aud 4 28 08 001.cl5 -> %UserProfile%\My Documents\aud 4 28 08 001.cl5 -> [Ver = | Size = 94689 bytes | Created Date = 4/28/2008 11:36:14 PM | Attr = ] aud files 01.cl5 -> %UserProfile%\My Documents\aud files 01.cl5 -> [Ver = | Size = 53127 bytes | Created Date = 3/12/2008 5:08:26 PM | Attr = ] aud files 02.cl5 -> %UserProfile%\My Documents\aud files 02.cl5 -> [Ver = | Size = 94175 bytes | Created Date = 3/12/2008 6:48:57 PM | Attr = ] backup of drives key.reg -> %UserProfile%\My Documents\backup of drives key.reg -> [Ver = | Size = 1074 bytes | Created Date = 3/13/2008 7:06:37 AM | Attr = ] dbtes -> %UserProfile%\My Documents\dbtes -> [Folder | Created Date = 3/18/2008 5:18:54 PM | Attr = ] diab shopping_list.pdf -> %UserProfile%\My Documents\diab shopping_list.pdf -> [Ver = | Size = 65025 bytes | Created Date = 3/6/2008 11:52:29 PM | Attr = ] Downloads -> %UserProfile%\My Documents\Downloads -> [Folder | Created Date = 5/2/2008 8:43:07 PM | Attr = ] FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News.htm -> %UserProfile%\My Documents\FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News.htm -> [Ver = | Size = 60776 bytes | Created Date = 3/18/2008 12:33:39 PM | Attr = ] FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News_files -> %UserProfile%\My Documents\FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News_files -> [Folder | Created Date = 3/18/2008 12:33:16 PM | Attr = ] FRUIT FACTS -> %UserProfile%\My Documents\FRUIT FACTS -> [Folder | Created Date = 4/2/2008 1:24:21 AM | Attr = ] i1040gi.pdf -> %UserProfile%\My Documents\i1040gi.pdf -> [Ver = | Size = 1468206 bytes | Created Date = 4/11/2008 3:14:19 AM | Attr = ] i4562.pdf -> %UserProfile%\My Documents\i4562.pdf -> [Ver = | Size = 157293 bytes | Created Date = 4/11/2008 2:17:04 AM | Attr = ] manual motorola prepaid phone.pdf -> %UserProfile%\My Documents\manual motorola prepaid phone.pdf -> [Ver = | Size = 3021196 bytes | Created Date = 2/16/2008 4:10:14 AM | Attr = ] My Recordings -> %UserProfile%\My Documents\My Recordings -> [Folder | Created Date = 5/2/2008 9:17:43 PM | Attr = ] avast! Antivirus.lnk -> %AllUsersProfile%\Desktop\avast! Antivirus.lnk -> [Ver = | Size = 1709 bytes | Created Date = 5/7/2008 10:37:22 AM | Attr = ] MediaMonkey.lnk -> %AllUsersProfile%\Desktop\MediaMonkey.lnk -> [Ver = | Size = 660 bytes | Created Date = 3/13/2008 3:36:35 AM | Attr = ] PokerStars.lnk -> %AllUsersProfile%\Desktop\PokerStars.lnk -> [Ver = | Size = 736 bytes | Created Date = 2/17/2008 10:46:55 PM | Attr = ] 09 bluegrass blues.mp3 -> %UserProfile%\Desktop\09 bluegrass blues.mp3 -> [Ver = | Size = 2159177 bytes | Created Date = 4/19/2008 12:34:50 AM | Attr = ] 47b7734cb8aedf53f5416fe83cdaff1f.avi -> %UserProfile%\Desktop\47b7734cb8aedf53f5416fe83cdaff1f.avi -> [Ver = | Size = 13016094 bytes | Created Date = 5/2/2008 9:51:47 PM | Attr = ] AAAAAAA -> %UserProfile%\Desktop\AAAAAAA -> [Folder | Created Date = 3/13/2008 4:15:39 AM | Attr = ] All Files.fnd -> %UserProfile%\Desktop\All Files.fnd -> [Ver = | Size = 198 bytes | Created Date = 3/28/2008 4:13:09 AM | Attr = ] Applian FLV Player.lnk -> %UserProfile%\Desktop\Applian FLV Player.lnk -> [Ver = | Size = 1573 bytes | Created Date = 5/2/2008 8:41:19 PM | Attr = ] AVS Video Converter.lnk -> %UserProfile%\Desktop\AVS Video Converter.lnk -> [Ver = | Size = 890 bytes | Created Date = 5/2/2008 9:39:49 PM | Attr = ] AVS4YOU Software Navigator.lnk -> %UserProfile%\Desktop\AVS4YOU Software Navigator.lnk -> [Ver = | Size = 946 bytes | Created Date = 5/2/2008 9:41:31 PM | Attr = ] AVSVideoConverter.exe -> %UserProfile%\Desktop\AVSVideoConverter.exe -> Online Media Technologies Ltd. [Ver = 5.6.1.715 | Size = 43697632 bytes | Created Date = 5/2/2008 9:24:12 PM | Attr = ] CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [Ver = | Size = 1548 bytes | Created Date = 2/27/2008 2:55:16 PM | Attr = ] CD-R drive or CD-RW drive is not recognized as a recordable device.htm -> %UserProfile%\Desktop\CD-R drive or CD-RW drive is not recognized as a recordable device.htm -> [Ver = | Size = 54594 bytes | Created Date = 3/13/2008 6:23:13 AM | Attr = ] CD-R drive or CD-RW drive is not recognized as a recordable device_files -> %UserProfile%\Desktop\CD-R drive or CD-RW drive is not recognized as a recordable device_files -> [Folder | Created Date = 3/13/2008 6:23:14 AM | Attr = ] CDex.lnk -> %UserProfile%\Desktop\CDex.lnk -> [Ver = | Size = 672 bytes | Created Date = 3/13/2008 3:11:33 AM | Attr = ] Defraggler.lnk -> %UserProfile%\Desktop\Defraggler.lnk -> [Ver = | Size = 1580 bytes | Created Date = 2/28/2008 3:18:12 PM | Attr = ] df-rg-type2-drugs-0108.pdf -> %UserProfile%\Desktop\df-rg-type2-drugs-0108.pdf -> [Ver = | Size = 89092 bytes | Created Date = 3/14/2008 6:58:09 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 06 April 2008 123814.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 06 April 2008 123814.htm -> [Ver = | Size = 19169 bytes | Created Date = 4/6/2008 12:40:11 PM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 21 April 2008 231844.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 21 April 2008 231844.htm -> [Ver = | Size = 7997 bytes | Created Date = 4/21/2008 11:19:29 PM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 050117.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 050117.htm -> [Ver = | Size = 20230 bytes | Created Date = 3/30/2008 5:01:40 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 053940.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 053940.htm -> [Ver = | Size = 9453 bytes | Created Date = 3/30/2008 5:39:51 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 31 March 2008 122645.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 31 March 2008 122645.htm -> [Ver = | Size = 8298 bytes | Created Date = 3/31/2008 12:27:19 PM | Attr = ] F-Secure Spyware Information Pages Virtumonde.htm -> %UserProfile%\Desktop\F-Secure Spyware Information Pages Virtumonde.htm -> [Ver = | Size = 23213 bytes | Created Date = 3/30/2008 5:00:39 AM | Attr = ] F-Secure Spyware Information Pages Virtumonde_files -> %UserProfile%\Desktop\F-Secure Spyware Information Pages Virtumonde_files -> [Folder | Created Date = 3/30/2008 5:00:42 AM | Attr = ] Flash Video Player.lnk -> %UserProfile%\Desktop\Flash Video Player.lnk -> [Ver = | Size = 1663 bytes | Created Date = 5/2/2008 8:50:02 PM | Attr = ] FLVPlayerSetup.exe -> %UserProfile%\Desktop\FLVPlayerSetup.exe -> [Ver = 7.0.6.1 | Size = 2567167 bytes | Created Date = 5/2/2008 8:39:19 PM | Attr = ] GCE-8481B105(win).exe -> %UserProfile%\Desktop\GCE-8481B105(win).exe -> [Ver = | Size = 590470 bytes | Created Date = 3/14/2008 9:41:14 PM | Attr = ] GCE-8481B_105.exe -> %UserProfile%\Desktop\GCE-8481B_105.exe -> [Ver = | Size = 620819 bytes | Created Date = 3/14/2008 9:38:40 PM | Attr = ] HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Created Date = 4/1/2008 1:07:35 AM | Attr = ] kspr.html -> %UserProfile%\Desktop\kspr.html -> [Ver = | Size = 4929900 bytes | Created Date = 5/5/2008 2:37:00 PM | Attr = ] mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes [Ver = 1.0.0.0 | Size = 1505568 bytes | Created Date = 4/1/2008 4:46:25 AM | Attr = ] music from web pages -> %UserProfile%\Desktop\music from web pages -> [Folder | Created Date = 5/3/2008 3:42:39 AM | Attr = ] OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Created Date = 5/7/2008 5:00:40 PM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 543384 bytes | Created Date = 5/7/2008 4:06:58 PM | Attr = ] R86898.EXE -> %UserProfile%\Desktop\R86898.EXE -> Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com [Ver = 1, 3, 1, 4 | Size = 11702480 bytes | Created Date = 3/14/2008 8:41:14 PM | Attr = ] Replay Media Catcher.lnk -> %UserProfile%\Desktop\Replay Media Catcher.lnk -> [Ver = | Size = 1684 bytes | Created Date = 5/2/2008 8:50:10 PM | Attr = ] send to CD R for storage -> %UserProfile%\Desktop\send to CD R for storage -> [Folder | Created Date = 4/28/2008 1:38:01 PM | Attr = ] Shortcut to Removable Disk (G).lnk -> %UserProfile%\Desktop\Shortcut to Removable Disk (G).lnk -> [Ver = | Size = 179 bytes | Created Date = 3/27/2008 8:31:45 PM | Attr = ] Silent Runners.vbs -> %UserProfile%\Desktop\Silent Runners.vbs -> [Ver = | Size = 365587 bytes | Created Date = 5/5/2008 5:52:31 PM | Attr = ] sound check mp3s -> %UserProfile%\Desktop\sound check mp3s -> [Folder | Created Date = 4/18/2008 4:08:44 PM | Attr = ] spybotsd152.exe -> %UserProfile%\Desktop\spybotsd152.exe -> Safer Networking Limited [Ver = 1.5.2 | Size = 9723880 bytes | Created Date = 3/6/2008 10:27:18 PM | Attr = ] V R Z -> %UserProfile%\Desktop\V R Z -> [Folder | Created Date = 3/18/2008 7:29:03 PM | Attr = ] vixybeta_install_0.5.exe -> %UserProfile%\Desktop\vixybeta_install_0.5.exe -> Farside Inc. [Ver = BETA version | Size = 1676293 bytes | Created Date = 5/2/2008 10:10:43 PM | Attr = ] AVSMedia -> %CommonProgramFiles%\AVSMedia -> [Folder | Created Date = 5/2/2008 9:29:28 PM | Attr = ] AVS4YOU -> %ProgramFiles%\AVS4YOU -> [Folder | Created Date = 5/2/2008 9:29:21 PM | Attr = ] CCleaner -> %ProgramFiles%\CCleaner -> [Folder | Created Date = 2/27/2008 2:55:16 PM | Attr = ] CDex_170b2 -> %ProgramFiles%\CDex_170b2 -> [Folder | Created Date = 3/13/2008 3:11:31 AM | Attr = ] Conduit -> %ProgramFiles%\Conduit -> [Folder | Created Date = 5/2/2008 8:53:19 PM | Attr = ] Defraggler -> %ProgramFiles%\Defraggler -> [Folder | Created Date = 2/28/2008 3:18:12 PM | Attr = ] FLV Player -> %ProgramFiles%\FLV Player -> [Folder | Created Date = 5/2/2008 8:41:04 PM | Attr = ] FLV PlayerFCSetup.exe -> %ProgramFiles%\FLV PlayerFCSetup.exe -> [Ver = 7.0.6.1 | Size = 2725048 bytes | Created Date = 5/2/2008 8:51:25 PM | Attr = ] FLV PlayerRCATSetup.exe -> %ProgramFiles%\FLV PlayerRCATSetup.exe -> [Ver = 7.0.6.1 | Size = 4500672 bytes | Created Date = 5/2/2008 8:46:45 PM | Attr = ] FLV PlayerRCSetup.exe -> %ProgramFiles%\FLV PlayerRCSetup.exe -> Applian Technologies Inc. [Ver = 1.0.0 | Size = 411248 bytes | Created Date = 5/2/2008 8:42:33 PM | Attr = ] Freecorder -> %ProgramFiles%\Freecorder -> [Folder | Created Date = 5/2/2008 8:53:12 PM | Attr = ] Freecorder Toolbar -> %ProgramFiles%\Freecorder Toolbar -> [Folder | Created Date = 5/2/2008 8:52:16 PM | Attr = ] HJT -> %ProgramFiles%\HJT -> [Folder | Created Date = 4/1/2008 1:13:46 AM | Attr = ] MediaMonkey -> %ProgramFiles%\MediaMonkey -> [Folder | Created Date = 3/13/2008 3:36:19 AM | Attr = ] New Folder -> %ProgramFiles%\New Folder -> [Folder | Created Date = 4/1/2008 1:13:18 AM | Attr = ] Panda Security -> %ProgramFiles%\Panda Security -> [Folder | Created Date = 5/6/2008 1:03:10 AM | Attr = ] PokerStars -> %ProgramFiles%\PokerStars -> [Folder | Created Date = 2/17/2008 10:46:15 PM | Attr = ] Replay Media Catcher -> %ProgramFiles%\Replay Media Catcher -> [Folder | Created Date = 5/2/2008 8:47:33 PM | Attr = ] vixy.net -> %ProgramFiles%\vixy.net -> [Folder | Created Date = 5/2/2008 10:11:09 PM | Attr = ] [Files/Folders - Modified Within 90 days] Boot.bak -> %SystemDrive%\Boot.bak -> [Ver = | Size = 194 bytes | Modified Date = 2/21/2008 1:11:19 AM | Attr = ] boot.ini -> %SystemDrive%\boot.ini -> [Ver = | Size = 264 bytes | Modified Date = 5/7/2008 11:24:10 AM | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 2/21/2008 4:50:44 PM | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 2/12/2008 4:28:28 PM | Attr = HS] New Folder -> %SystemDrive%\New Folder -> [Folder | Modified Date = 2/25/2008 4:46:02 AM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 5/6/2008 1:03:10 AM | Attr = R ] QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 5/6/2008 8:56:43 PM | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 5/7/2008 3:12:08 AM | Attr = HS] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 5/6/2008 9:06:12 PM | Attr = HS] temp -> %SystemDrive%\temp -> [Folder | Modified Date = 3/29/2008 6:24:18 PM | Attr = ] VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Modified Date = 5/5/2008 2:51:56 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 5/7/2008 2:24:11 PM | Attr = ] aavmker4.sys -> %SystemRoot%\System32\drivers\aavmker4.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 26944 bytes | Modified Date = 3/29/2008 1:26:52 PM | Attr = ] aswmon2.sys -> %SystemRoot%\System32\drivers\aswmon2.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 94544 bytes | Modified Date = 3/29/2008 1:35:21 PM | Attr = ] aswRdr.sys -> %SystemRoot%\System32\drivers\aswRdr.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 23152 bytes | Modified Date = 3/29/2008 1:29:08 PM | Attr = ] aswSP.sys -> %SystemRoot%\System32\drivers\aswSP.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 75856 bytes | Modified Date = 3/29/2008 1:31:34 PM | Attr = ] aswTdi.sys -> %SystemRoot%\System32\drivers\aswTdi.sys -> ALWIL Software [Ver = 4.8.1169.0 | Size = 42912 bytes | Modified Date = 3/29/2008 1:27:33 PM | Attr = ] etc -> %SystemRoot%\System32\drivers\etc -> [Folder | Modified Date = 3/29/2008 6:36:31 PM | Attr = ] hosts -> %SystemRoot%\System32\drivers\etc\hosts -> [Ver = | Size = 27 bytes | Modified Date = 3/29/2008 6:36:31 PM | Attr = ] aswBoot.exe -> %SystemRoot%\System32\aswBoot.exe -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 1146232 bytes | Modified Date = 3/29/2008 1:45:49 PM | Attr = ] AVASTSS.scr -> %SystemRoot%\System32\AVASTSS.scr -> ALWIL Software [Ver = 4, 8, 1169, 0 | Size = 95608 bytes | Modified Date = 3/29/2008 1:23:22 PM | Attr = ] CatRoot -> %SystemRoot%\System32\CatRoot -> [Folder | Modified Date = 3/14/2008 6:27:47 PM | Attr = ] 6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 5/6/2008 9:23:12 PM | Attr = ] config -> %SystemRoot%\System32\config -> [Folder | Modified Date = 3/29/2008 6:33:45 PM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 3/17/2008 3:17:32 AM | Attr = ] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 5/7/2008 2:21:37 PM | Attr = ] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 181040 bytes | Modified Date = 5/4/2008 1:36:13 AM | Attr = ] FTP34.0LL -> %SystemRoot%\System32\FTP34.0LL -> [Ver = | Size = 5120 bytes | Modified Date = 5/5/2008 2:18:36 AM | Attr = ] IDME -> %SystemRoot%\System32\IDME -> [Folder | Modified Date = 4/21/2008 11:18:02 PM | Attr = ] inetsrv -> %SystemRoot%\System32\inetsrv -> [Folder | Modified Date = 2/25/2008 4:43:34 AM | Attr = ] Kaspersky Lab -> %SystemRoot%\System32\Kaspersky Lab -> [Folder | Modified Date = 2/22/2008 5:33:03 PM | Attr = ] NtmsData -> %SystemRoot%\System32\NtmsData -> [Folder | Modified Date = 5/7/2008 3:55:42 AM | Attr = ] perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [Ver = | Size = 165758 bytes | Modified Date = 5/7/2008 2:26:42 PM | Attr = ] perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [Ver = | Size = 642868 bytes | Modified Date = 5/7/2008 2:26:43 PM | Attr = ] PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [Ver = | Size = 2236 bytes | Modified Date = 5/7/2008 2:26:41 PM | Attr = ] Restore -> %SystemRoot%\System32\Restore -> [Folder | Modified Date = 5/6/2008 9:06:12 PM | Attr = ] Roboex32.dll -> %SystemRoot%\System32\Roboex32.dll -> eHelp Corporation. [Ver = 9.10.520 | Size = 1044480 bytes | Modified Date = 3/14/2008 8:43:37 PM | Attr = ] VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 3/29/2008 2:26:32 AM | Attr = ] winz1 -> %SystemRoot%\System32\winz1 -> [Folder | Modified Date = 3/30/2008 4:58:53 AM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 13646 bytes | Modified Date = 4/7/2008 5:04:15 PM | Attr = ] xTmp -> %SystemRoot%\System32\xTmp -> [Folder | Modified Date = 4/1/2008 11:10:04 AM | Attr = ] afs.bmp -> %SystemRoot%\afs.bmp -> [Ver = | Size = 2359350 bytes | Modified Date = 2/18/2008 12:19:24 AM | Attr = ] Applian FLV Player -> %SystemRoot%\Applian FLV Player -> [Folder | Modified Date = 5/2/2008 8:41:04 PM | Attr = ] 9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 5/7/2008 2:20:04 PM | Attr = S] cdPlayer.ini -> %SystemRoot%\cdPlayer.ini -> [Ver = | Size = 49007 bytes | Modified Date = 5/3/2008 4:38:17 PM | Attr = ] Config -> %SystemRoot%\Config -> [Folder | Modified Date = 2/25/2008 4:43:35 AM | Attr = ] cpu.PIF -> %SystemRoot%\cpu.PIF -> [Ver = | Size = 2855 bytes | Modified Date = 2/23/2008 8:08:34 PM | Attr = ] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 5/7/2008 2:22:02 PM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 5/6/2008 1:02:17 AM | Attr = S] erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 3/29/2008 6:33:02 PM | Attr = ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 5/2/2008 9:41:42 PM | Attr = R S] Freecorder Toolbar -> %SystemRoot%\Freecorder Toolbar -> [Folder | Modified Date = 5/2/2008 8:52:17 PM | Attr = ] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 3/13/2008 7:21:50 AM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 5/6/2008 1:03:08 AM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 2/12/2008 4:28:28 PM | Attr = HS] Media -> %SystemRoot%\Media -> [Folder | Modified Date = 2/25/2008 4:43:32 AM | Attr = ] Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 2/27/2008 3:16:52 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 5/7/2008 5:00:41 PM | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 5/5/2008 2:49:54 PM | Attr = ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 3/28/2008 3:43:47 AM | Attr = ] Replay Media Catcher -> %SystemRoot%\Replay Media Catcher -> [Folder | Modified Date = 5/2/2008 8:48:08 PM | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 227 bytes | Modified Date = 5/7/2008 11:24:10 AM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 5/7/2008 2:26:42 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 2/20/2008 2:57:58 PM | Attr = S] TEMP -> %SystemRoot%\TEMP -> [Folder | Modified Date = 5/7/2008 2:35:17 PM | Attr = ] unins000.dat -> %SystemRoot%\unins000.dat -> [Ver = | Size = 2550 bytes | Modified Date = 3/6/2008 10:28:30 PM | Attr = ] unins000.exe -> %SystemRoot%\unins000.exe -> [Ver = 51.49.0.0 | Size = 691545 bytes | Modified Date = 3/6/2008 10:26:33 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 828 bytes | Modified Date = 5/7/2008 11:24:10 AM | Attr = ] wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 192 bytes | Modified Date = 3/29/2008 1:44:57 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 5/7/2008 2:21:40 PM | Attr = H ] Scheduled scanning task.job -> %SystemRoot%\tasks\Scheduled scanning task.job -> [Ver = | Size = 544 bytes | Modified Date = 5/2/2008 12:00:07 AM | Attr = ] XoftSpySE 2.job -> %SystemRoot%\tasks\XoftSpySE 2.job -> [Ver = | Size = 432 bytes | Modified Date = 5/7/2008 5:00:25 PM | Attr = ] XoftSpySE.job -> %SystemRoot%\tasks\XoftSpySE.job -> [Ver = | Size = 362 bytes | Modified Date = 5/1/2008 3:01:31 AM | Attr = ] C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help -> [Folder | Modified Date = 8/28/2004 3:46:54 AM | Attr = ] hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [Ver = | Size = 26057 bytes | Modified Date = 3/13/2008 6:04:23 AM | Attr = ] C:\WINDOWS\Temp\ -> C:\WINDOWS\TEMP -> [Folder | Modified Date = 5/7/2008 2:35:17 PM | Attr = ] Perflib_Perfdata_5ac.dat -> C:\WINDOWS\TEMP\Perflib_Perfdata_5ac.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/7/2008 2:21:39 PM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> [Files Modified - Additional Folder Scans - Non-Microsoft Only] AVS4YOU -> %AllUsersProfile%\Application Data\AVS4YOU -> [Folder | Modified Date = 5/2/2008 9:33:46 PM | Attr = ] fssg -> %AllUsersProfile%\Application Data\fssg -> [Folder | Modified Date = 3/29/2008 4:51:16 PM | Attr = ] Kaspersky Lab -> %AllUsersProfile%\Application Data\Kaspersky Lab -> [Folder | Modified Date = 2/22/2008 5:33:06 PM | Attr = ] Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes -> [Folder | Modified Date = 2/25/2008 2:41:33 AM | Attr = ] Microsoft -> %AllUsersProfile%\Application Data\Microsoft -> [Folder | Modified Date = 2/25/2008 4:43:37 AM | Attr = S] Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy -> [Folder | Modified Date = 3/29/2008 3:14:06 AM | Attr = ] Adobe -> %AppData%\Adobe -> [Folder | Modified Date = 5/2/2008 9:07:36 PM | Attr = ] AVS4YOU -> %AppData%\AVS4YOU -> [Folder | Modified Date = 5/2/2008 9:34:19 PM | Attr = ] GetRightToGo -> %AppData%\GetRightToGo -> [Folder | Modified Date = 5/2/2008 8:46:27 PM | Attr = ] Malwarebytes -> %AppData%\Malwarebytes -> [Folder | Modified Date = 2/25/2008 2:42:06 AM | Attr = ] Media Player Classic -> %AppData%\Media Player Classic -> [Folder | Modified Date = 3/13/2008 7:38:59 AM | Attr = ] Microsoft -> %AppData%\Microsoft -> [Folder | Modified Date = 2/25/2008 4:43:37 AM | Attr = S] Conduit -> %UserProfile%\Local Settings\Application Data\Conduit -> [Folder | Modified Date = 5/2/2008 8:54:06 PM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 156672 bytes | Modified Date = 5/7/2008 12:53:46 AM | Attr = ] Freecorder -> %UserProfile%\Local Settings\Application Data\Freecorder -> [Folder | Modified Date = 5/6/2008 7:36:34 AM | Attr = ] GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [Ver = | Size = 50504 bytes | Modified Date = 4/23/2008 3:16:37 AM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 3721082 bytes | Modified Date = 5/7/2008 11:24:22 AM | Attr = H ] MediaMonkey -> %UserProfile%\Local Settings\Application Data\MediaMonkey -> [Folder | Modified Date = 4/18/2008 4:51:28 PM | Attr = ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 4/7/2008 6:01:57 PM | Attr = ] Commercial Luffa Sponge Gourd Production.htm -> %AllUsersProfile%\Documents\Commercial Luffa Sponge Gourd Production.htm -> [Ver = | Size = 15484 bytes | Modified Date = 4/12/2008 4:44:43 PM | Attr = ] Commercial Luffa Sponge Gourd Production_files -> %AllUsersProfile%\Documents\Commercial Luffa Sponge Gourd Production_files -> [Folder | Modified Date = 4/12/2008 4:44:43 PM | Attr = ] Dell Image Expert - Standard Edition (2).lnk -> %AllUsersProfile%\Documents\Dell Image Expert - Standard Edition (2).lnk -> [Ver = | Size = 2369 bytes | Modified Date = 3/19/2008 12:19:30 AM | Attr = ] HHEELLPP -> %AllUsersProfile%\Documents\HHEELLPP -> [Folder | Modified Date = 5/5/2008 11:18:17 PM | Attr = ] hil-120.html -> %AllUsersProfile%\Documents\hil-120.html -> [Ver = | Size = 15523 bytes | Modified Date = 4/12/2008 4:43:37 PM | Attr = ] i1040gi.pdf -> %AllUsersProfile%\Documents\i1040gi.pdf -> [Ver = | Size = 1468206 bytes | Modified Date = 4/7/2008 6:30:23 PM | Attr = ] OUR CATS -> %AllUsersProfile%\Documents\OUR CATS -> [Folder | Modified Date = 4/27/2008 3:48:11 PM | Attr = ] V R Z -> %AllUsersProfile%\Documents\V R Z -> [Folder | Modified Date = 3/18/2008 9:48:12 PM | Attr = ] application brnes&nbl.pdf -> %UserProfile%\My Documents\application brnes&nbl.pdf -> [Ver = | Size = 48766 bytes | Modified Date = 4/14/2008 7:44:53 PM | Attr = ] aud 4 28 08 001.cl5 -> %UserProfile%\My Documents\aud 4 28 08 001.cl5 -> [Ver = | Size = 94689 bytes | Modified Date = 4/28/2008 11:36:14 PM | Attr = ] aud files 01.cl5 -> %UserProfile%\My Documents\aud files 01.cl5 -> [Ver = | Size = 53127 bytes | Modified Date = 3/12/2008 5:08:26 PM | Attr = ] aud files 02.cl5 -> %UserProfile%\My Documents\aud files 02.cl5 -> [Ver = | Size = 94175 bytes | Modified Date = 3/12/2008 6:48:58 PM | Attr = ] backup of drives key.reg -> %UserProfile%\My Documents\backup of drives key.reg -> [Ver = | Size = 1074 bytes | Modified Date = 3/13/2008 7:06:37 AM | Attr = ] dbtes -> %UserProfile%\My Documents\dbtes -> [Folder | Modified Date = 3/22/2008 2:29:30 AM | Attr = ] diab shopping_list.pdf -> %UserProfile%\My Documents\diab shopping_list.pdf -> [Ver = | Size = 65025 bytes | Modified Date = 3/6/2008 11:52:29 PM | Attr = ] Downloads -> %UserProfile%\My Documents\Downloads -> [Folder | Modified Date = 5/2/2008 8:43:07 PM | Attr = ] FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News.htm -> %UserProfile%\My Documents\FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News.htm -> [Ver = | Size = 60776 bytes | Modified Date = 3/18/2008 12:33:39 PM | Attr = ] FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News_files -> %UserProfile%\My Documents\FOXNews_com - Forget Types 1, 2 New Diabetes Subtypes Discovered - Health News Current Health News Medical News_files -> [Folder | Modified Date = 3/18/2008 12:33:37 PM | Attr = ] FRUIT FACTS -> %UserProfile%\My Documents\FRUIT FACTS -> [Folder | Modified Date = 4/2/2008 1:54:10 AM | Attr = ] i1040gi.pdf -> %UserProfile%\My Documents\i1040gi.pdf -> [Ver = | Size = 1468206 bytes | Modified Date = 4/11/2008 3:14:20 AM | Attr = ] i4562.pdf -> %UserProfile%\My Documents\i4562.pdf -> [Ver = | Size = 157293 bytes | Modified Date = 4/11/2008 2:17:04 AM | Attr = ] manual motorola prepaid phone.pdf -> %UserProfile%\My Documents\manual motorola prepaid phone.pdf -> [Ver = | Size = 3021196 bytes | Modified Date = 2/16/2008 4:10:15 AM | Attr = ] My Music -> %UserProfile%\My Documents\My Music -> [Folder | Modified Date = 3/27/2008 11:23:13 PM | Attr = R ] My Pictures -> %UserProfile%\My Documents\My Pictures -> [Folder | Modified Date = 4/20/2008 3:22:49 AM | Attr = R ] My Recordings -> %UserProfile%\My Documents\My Recordings -> [Folder | Modified Date = 5/2/2008 10:25:54 PM | Attr = ] My Videos -> %UserProfile%\My Documents\My Videos -> [Folder | Modified Date = 5/7/2008 12:52:06 AM | Attr = R ] avast! Antivirus.lnk -> %AllUsersProfile%\Desktop\avast! Antivirus.lnk -> [Ver = | Size = 1709 bytes | Modified Date = 5/7/2008 10:37:22 AM | Attr = ] MediaMonkey.lnk -> %AllUsersProfile%\Desktop\MediaMonkey.lnk -> [Ver = | Size = 660 bytes | Modified Date = 3/13/2008 3:36:35 AM | Attr = ] PokerStars.lnk -> %AllUsersProfile%\Desktop\PokerStars.lnk -> [Ver = | Size = 736 bytes | Modified Date = 2/17/2008 10:46:55 PM | Attr = ] 09 bluegrass blues.mp3 -> %UserProfile%\Desktop\09 bluegrass blues.mp3 -> [Ver = | Size = 2159177 bytes | Modified Date = 4/16/2008 11:25:16 AM | Attr = ] 47b7734cb8aedf53f5416fe83cdaff1f.avi -> %UserProfile%\Desktop\47b7734cb8aedf53f5416fe83cdaff1f.avi -> [Ver = | Size = 13016094 bytes | Modified Date = 5/2/2008 10:07:30 PM | Attr = ] AAAAAAA -> %UserProfile%\Desktop\AAAAAAA -> [Folder | Modified Date = 4/20/2008 7:09:43 AM | Attr = ] All Files.fnd -> %UserProfile%\Desktop\All Files.fnd -> [Ver = | Size = 198 bytes | Modified Date = 3/28/2008 4:13:11 AM | Attr = ] Applian FLV Player.lnk -> %UserProfile%\Desktop\Applian FLV Player.lnk -> [Ver = | Size = 1573 bytes | Modified Date = 5/2/2008 8:41:26 PM | Attr = ] AVS Video Converter.lnk -> %UserProfile%\Desktop\AVS Video Converter.lnk -> [Ver = | Size = 890 bytes | Modified Date = 5/2/2008 9:39:49 PM | Attr = ] AVS4YOU Software Navigator.lnk -> %UserProfile%\Desktop\AVS4YOU Software Navigator.lnk -> [Ver = | Size = 946 bytes | Modified Date = 5/2/2008 9:41:31 PM | Attr = ] AVSVideoConverter.exe -> %UserProfile%\Desktop\AVSVideoConverter.exe -> Online Media Technologies Ltd. [Ver = 5.6.1.715 | Size = 43697632 bytes | Modified Date = 5/2/2008 9:28:03 PM | Attr = ] CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [Ver = | Size = 1548 bytes | Modified Date = 2/27/2008 2:55:17 PM | Attr = ] CD-R drive or CD-RW drive is not recognized as a recordable device.htm -> %UserProfile%\Desktop\CD-R drive or CD-RW drive is not recognized as a recordable device.htm -> [Ver = | Size = 54594 bytes | Modified Date = 3/13/2008 6:23:20 AM | Attr = ] CD-R drive or CD-RW drive is not recognized as a recordable device_files -> %UserProfile%\Desktop\CD-R drive or CD-RW drive is not recognized as a recordable device_files -> [Folder | Modified Date = 3/13/2008 6:23:20 AM | Attr = ] CDex.lnk -> %UserProfile%\Desktop\CDex.lnk -> [Ver = | Size = 672 bytes | Modified Date = 3/13/2008 3:11:33 AM | Attr = ] Defraggler.lnk -> %UserProfile%\Desktop\Defraggler.lnk -> [Ver = | Size = 1580 bytes | Modified Date = 2/28/2008 3:18:12 PM | Attr = ] DESKLINKS -> %UserProfile%\Desktop\DESKLINKS -> [Folder | Modified Date = 5/5/2008 5:36:53 PM | Attr = ] df-rg-type2-drugs-0108.pdf -> %UserProfile%\Desktop\df-rg-type2-drugs-0108.pdf -> [Ver = | Size = 89092 bytes | Modified Date = 3/14/2008 6:58:10 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 06 April 2008 123814.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 06 April 2008 123814.htm -> [Ver = | Size = 19169 bytes | Modified Date = 4/6/2008 12:40:15 PM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 21 April 2008 231844.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 21 April 2008 231844.htm -> [Ver = | Size = 7997 bytes | Modified Date = 4/21/2008 11:19:33 PM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 050117.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 050117.htm -> [Ver = | Size = 20230 bytes | Modified Date = 3/30/2008 5:01:41 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 053940.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 30 March 2008 053940.htm -> [Ver = | Size = 9453 bytes | Modified Date = 3/30/2008 5:39:52 AM | Attr = ] EMBARQ Online Security 7_03 - Scanning Report - 31 March 2008 122645.htm -> %UserProfile%\Desktop\EMBARQ Online Security 7_03 - Scanning Report - 31 March 2008 122645.htm -> [Ver = | Size = 8298 bytes | Modified Date = 3/31/2008 12:27:23 PM | Attr = ] F-Secure Spyware Information Pages Virtumonde.htm -> %UserProfile%\Desktop\F-Secure Spyware Information Pages Virtumonde.htm -> [Ver = | Size = 23213 bytes | Modified Date = 3/30/2008 5:00:46 AM | Attr = ] F-Secure Spyware Information Pages Virtumonde_files -> %UserProfile%\Desktop\F-Secure Spyware Information Pages Virtumonde_files -> [Folder | Modified Date = 3/30/2008 5:00:46 AM | Attr = ] Flash Video Player.lnk -> %UserProfile%\Desktop\Flash Video Player.lnk -> [Ver = | Size = 1663 bytes | Modified Date = 5/2/2008 8:50:04 PM | Attr = ] FLVPlayerSetup.exe -> %UserProfile%\Desktop\FLVPlayerSetup.exe -> [Ver = 7.0.6.1 | Size = 2567167 bytes | Modified Date = 5/2/2008 8:39:29 PM | Attr = ] GCE-8481B_105.exe -> %UserProfile%\Desktop\GCE-8481B_105.exe -> [Ver = | Size = 620819 bytes | Modified Date = 3/14/2008 9:38:43 PM | Attr = ] HJTInstall.exe -> %UserProfile%\Desktop\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 4/1/2008 1:07:50 AM | Attr = ] kspr.html -> %UserProfile%\Desktop\kspr.html -> [Ver = | Size = 4929900 bytes | Modified Date = 5/5/2008 2:37:08 PM | Attr = ] mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes [Ver = 1.0.0.0 | Size = 1505568 bytes | Modified Date = 4/1/2008 4:46:25 AM | Attr = ] music from web pages -> %UserProfile%\Desktop\music from web pages -> [Folder | Modified Date = 5/7/2008 4:44:56 PM | Attr = ] OTScanIt -> %UserProfile%\Desktop\OTScanIt -> [Folder | Modified Date = 5/7/2008 5:00:40 PM | Attr = ] OTScanIt.exe -> %UserProfile%\Desktop\OTScanIt.exe -> [Ver = | Size = 543384 bytes | Modified Date = 5/7/2008 4:07:02 PM | Attr = ] R86898.EXE -> %UserProfile%\Desktop\R86898.EXE -> Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com [Ver = 1, 3, 1, 4 | Size = 11702480 bytes | Modified Date = 3/14/2008 8:41:14 PM | Attr = ] Replay Media Catcher.lnk -> %UserProfile%\Desktop\Replay Media Catcher.lnk -> [Ver = | Size = 1684 bytes | Modified Date = 5/2/2008 8:50:10 PM | Attr = ] send to CD R for storage -> %UserProfile%\Desktop\send to CD R for storage -> [Folder | Modified Date = 4/29/2008 12:37:55 AM | Attr = ] Shortcut to CD Drive.lnk -> %UserProfile%\Desktop\Shortcut to CD Drive.lnk -> [Ver = | Size = 206 bytes | Modified Date = 3/18/2008 12:52:19 AM | Attr = ] Shortcut to Removable Disk (G).lnk -> %UserProfile%\Desktop\Shortcut to Removable Disk (G).lnk -> [Ver = | Size = 179 bytes | Modified Date = 3/27/2008 8:31:45 PM | Attr = ] Shortcut to Shared Documents.lnk -> %UserProfile%\Desktop\Shortcut to Shared Documents.lnk -> [Ver = | Size = 444 bytes | Modified Date = 3/23/2008 1:06:34 AM | Attr = ] Silent Runners.vbs -> %UserProfile%\Desktop\Silent Runners.vbs -> [Ver = | Size = 365587 bytes | Modified Date = 5/5/2008 5:52:34 PM | Attr = ] sound check mp3s -> %UserProfile%\Desktop\sound check mp3s -> [Folder | Modified Date = 4/19/2008 5:31:31 AM | Attr = ] Spybot - Search & Destroy.lnk -> %UserProfile%\Desktop\Spybot - Search & Destroy.lnk -> [Ver = | Size = 933 bytes | Modified Date = 3/6/2008 10:32:44 PM | Attr = ] spybotsd152.exe -> %UserProfile%\Desktop\spybotsd152.exe -> Safer Networking Limited [Ver = 1.5.2 | Size = 9723880 bytes | Modified Date = 3/6/2008 10:28:21 PM | Attr = ] stuff -> %UserProfile%\Desktop\stuff -> [Folder | Modified Date = 5/5/2008 11:30:14 PM | Attr = ] V R Z -> %UserProfile%\Desktop\V R Z -> [Folder | Modified Date = 3/22/2008 6:05:59 PM | Attr = ] vixybeta_install_0.5.exe -> %UserProfile%\Desktop\vixybeta_install_0.5.exe -> Farside Inc. [Ver = BETA version | Size = 1676293 bytes | Modified Date = 5/2/2008 10:10:50 PM | Attr = ] Adaptec Shared -> %CommonProgramFiles%\Adaptec Shared -> [Folder | Modified Date = 3/14/2008 8:43:43 PM | Attr = ] AVSMedia -> %CommonProgramFiles%\AVSMedia -> [Folder | Modified Date = 5/2/2008 9:41:39 PM | Attr = ] [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] < End of report > [/code]