[code] OTScanIt logfile created on: 7/10/2008 3:37:45 PM OTScanIt by OldTimer - Version 1.0.16.1 Folder = C:\Documents and Settings\HP_Administrator\My Documents\OTScanIt Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.11) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 958.48 Mb Total Physical Memory | 385.32 Mb Available Physical Memory | 40.20% Memory free 2.26 Gb Paging File | 1.68 Gb Available in Paging File | 74.55% Paging File free Paging file location(s): C:\pagefile.sys 1440 2880; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 177.80 Gb Total Space | 136.70 Gb Free Space | 76.89% Space Free | Partition Type: NTFS Drive D: | 8.50 Gb Total Space | 1.11 Gb Free Space | 13.11% Space Free | Partition Type: FAT32 E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: BONITAGARNER1 Current User Name: HP_Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user [Processes - Non-Microsoft Only] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4119 | Size = 376832 bytes | Modified Date = 8/14/2005 12:29:40 AM | Attr = ] aolacsd.exe -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 7:50:35 AM | Attr = R ] aoltsmon.exe -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltsmon.exe -> America Online, Inc [Ver = 2, 0, 0, 0 | Size = 100016 bytes | Modified Date = 10/15/2004 3:54:14 PM | Attr = ] arservice.exe -> %SystemRoot%\arservice.exe -> Microsoft [Ver = 6.0.0160.0 | Size = 58880 bytes | Modified Date = 8/3/2005 2:19:16 AM | Attr = ] aoltpspd.exe -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltpspd.exe -> America Online Inc [Ver = 2, 0, 0, 0 | Size = 46768 bytes | Modified Date = 10/15/2004 3:54:12 PM | Attr = ] googleupdaterservice.exe -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.2.824.5515.beta | Size = 138680 bytes | Modified Date = 5/9/2007 1:56:59 AM | Attr = ] lssrvc.exe -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.52.1 | Size = 69632 bytes | Modified Date = 10/23/2005 8:46:44 AM | Attr = ] linksysupdater.exe -> %ProgramFiles%\Linksys\Linksys Updater\bin\LinksysUpdater.exe -> [Ver = | Size = 204800 bytes | Modified Date = 1/15/2008 10:28:20 AM | Attr = ] mcmscsvc.exe -> %ProgramFiles%\McAfee\MSC\mcmscsvc.exe -> McAfee, Inc. [Ver = 8,1,159,0 | Size = 767976 bytes | Modified Date = 1/9/2008 4:50:22 PM | Attr = ] ati2evxx.exe -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4119 | Size = 376832 bytes | Modified Date = 8/14/2005 12:29:40 AM | Attr = ] java.exe -> %SystemRoot%\system32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 135168 bytes | Modified Date = 9/24/2007 10:30:28 PM | Attr = ] mcnasvc.exe -> %CommonProgramFiles%\McAfee\MNA\McNASvc.exe -> McAfee, Inc. [Ver = 2,1,143,0 | Size = 2458128 bytes | Modified Date = 1/25/2008 1:38:12 AM | Attr = ] mcproxy.exe -> %CommonProgramFiles%\McAfee\McProxy\McProxy.exe -> McAfee, Inc. [Ver = 2,0,150,0 | Size = 359248 bytes | Modified Date = 8/15/2007 12:36:04 PM | Attr = ] redirsvc.exe -> %CommonProgramFiles%\McAfee\RedirSvc\RedirSvc.exe -> McAfee, Inc. [Ver = 1,2,112,0 | Size = 248416 bytes | Modified Date = 1/15/2007 11:25:22 AM | Attr = ] mcshield.exe -> %ProgramFiles%\McAfee\VirusScan\Mcshield.exe -> McAfee, Inc. [Ver = VSCORE.14.0.0.349.x86 | Size = 144704 bytes | Modified Date = 7/24/2007 12:02:14 PM | Attr = ] mpfsrv.exe -> %ProgramFiles%\McAfee\MPF\MpfSrv.exe -> McAfee, Inc. [Ver = 9.0.136.0 | Size = 856864 bytes | Modified Date = 7/18/2007 3:54:42 PM | Attr = ] msksrver.exe -> %ProgramFiles%\McAfee\MSK\msksrver.exe -> McAfee, Inc. [Ver = 9.1.107.0 | Size = 23880 bytes | Modified Date = 11/26/2007 10:46:14 AM | Attr = ] hpzipm12.exe -> %SystemRoot%\system32\spool\drivers\w32x86\3\HPZIPM12.EXE -> HP [Ver = 10, 1, 1, 6 | Size = 73728 bytes | Modified Date = 8/9/2007 2:27:52 AM | Attr = ] saservice.exe -> %ProgramFiles%\SiteAdvisor\6261\SAService.exe -> [Ver = | Size = 345376 bytes | Modified Date = 7/8/2008 3:29:12 PM | Attr = ] iebtm.exe -> %ProgramFiles%\Web Technologies\iebtm.exe -> [Ver = | Size = 19968 bytes | Modified Date = 7/6/2008 6:27:12 PM | Attr = ] hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe -> Hewlett-Packard [Ver = 80, 1, 0, 0 | Size = 54840 bytes | Modified Date = 5/8/2007 4:24:20 PM | Attr = ] aolsoftware.exe -> %CommonProgramFiles%\AOL\1139609045\EE\aolsoftware.exe -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 12:16:08 PM | Attr = ] googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> Google [Ver = 5.1.706.29690 | Size = 1836544 bytes | Modified Date = 8/15/2007 10:57:47 AM | Attr = ] discupdatemgr.exe -> %ProgramFiles%\DISC\DISCUpdateMgr.exe -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.926 | Size = 61440 bytes | Modified Date = 9/27/2005 2:42:26 AM | Attr = ] discover.exe -> %ProgramFiles%\DISC\DISCover.exe -> Digital Interactive Systems Corporation [Ver = 3.21.2005.0926 | Size = 1060864 bytes | Modified Date = 9/27/2005 2:43:29 AM | Attr = ] wcm.exe -> %ProgramFiles%\Web Technologies\wcm.exe -> [Ver = | Size = 7680 bytes | Modified Date = 7/10/2008 2:56:45 PM | Attr = ] arpwrmsg.exe -> %SystemRoot%\arpwrmsg.exe -> Microsoft [Ver = 6.0.0160.0 | Size = 77312 bytes | Modified Date = 8/3/2005 2:19:16 AM | Attr = ] qttask.exe -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.0.4 | Size = 155648 bytes | Modified Date = 6/24/2007 5:21:44 AM | Attr = ] kbd.exe -> %SystemDrive%\hp\KBD\kbd.exe -> Hewlett-Packard Company [Ver = 1.0.2.2.20205 | Size = 61440 bytes | Modified Date = 2/2/2005 4:44:24 PM | Attr = ] realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.1.45 | Size = 185896 bytes | Modified Date = 4/27/2008 1:41:04 PM | Attr = ] m3srchmn.exe -> %ProgramFiles%\MyWebSearch\bar\1.bin\M3SRCHMN.EXE -> MyWebSearch.com [Ver = 1, 0, 0, 4 | Size = 24688 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] mwsoemon.exe -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSOEMON.EXE -> MyWebSearch.com [Ver = 1,2,2,5 | Size = 32838 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc. [Ver = 8,0,237,0 | Size = 582992 bytes | Modified Date = 11/1/2007 7:12:38 PM | Attr = ] jusched.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr = ] iebtmm.exe -> %ProgramFiles%\Web Technologies\iebtmm.exe -> [Ver = | Size = 5632 bytes | Modified Date = 7/10/2008 2:56:46 PM | Attr = ] uav.exe -> %ProgramFiles%\UAV\uav.exe -> [Ver = 1, 0, 0, 1 | Size = 333824 bytes | Modified Date = 7/3/2008 10:55:07 AM | Attr = ] aolload.exe -> %CommonProgramFiles%\AOL\Loader\aolload.exe -> AOL LLC [Ver = 9.3.2.2 | Size = 10800 bytes | Modified Date = 11/3/2006 2:17:27 AM | Attr = ] siteadv.exe -> %ProgramFiles%\SiteAdvisor\6261\SiteAdv.exe -> [Ver = | Size = 36640 bytes | Modified Date = 6/21/2007 3:06:20 PM | Attr = ] discgui.exe -> %ProgramFiles%\DISC\DiscGui.exe -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.0926 | Size = 237568 bytes | Modified Date = 9/27/2005 2:42:32 AM | Attr = ] googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 4/3/2007 7:17:32 PM | Attr = ] googledesktop.exe -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> Google [Ver = 5.1.706.29690 | Size = 1836544 bytes | Modified Date = 8/15/2007 10:57:47 AM | Attr = ] av2009.exe -> %ProgramFiles%\Antivirus 2009\av2009.exe -> [Ver = | Size = 957952 bytes | Modified Date = 7/6/2008 9:55:44 PM | Attr = ] discstreamhub.exe -> %ProgramFiles%\DISC\DiscStreamHub.exe -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.926 | Size = 45056 bytes | Modified Date = 9/27/2005 2:42:26 AM | Attr = ] mcsysmon.exe -> %ProgramFiles%\McAfee\VirusScan\mcsysmon.exe -> McAfee, Inc. [Ver = 12,1,111,0 | Size = 695624 bytes | Modified Date = 12/5/2007 10:04:10 AM | Attr = ] jucheck.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jucheck.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 329104 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr = ] mcuimgr.exe -> %ProgramFiles%\McAfee\MSC\mcuimgr.exe -> McAfee, Inc. [Ver = 8,0,226,0 | Size = 265040 bytes | Modified Date = 11/1/2007 7:12:38 PM | Attr = ] alcxmntr.exe -> %SystemRoot%\ALCXMNTR.EXE -> Realtek Semiconductor Corp. [Ver = 1.5 | Size = 57344 bytes | Modified Date = 9/7/2004 3:47:52 PM | Attr = ] atiptaxx.exe -> %ProgramFiles%\ATI Technologies\ATI Control Panel\atiptaxx.exe -> ATI Technologies, Inc. [Ver = 6.14.10.5166 | Size = 344064 bytes | Modified Date = 8/14/2005 7:05:00 AM | Attr = ] hpsysdrv.exe -> %SystemRoot%\system\hpsysdrv.exe -> Hewlett-Packard Company [Ver = 1, 7, 0, 0 | Size = 52736 bytes | Modified Date = 5/7/1998 11:04:38 AM | Attr = ] ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 6.0.4.2 | Size = 278528 bytes | Modified Date = 2/23/2006 3:45:20 PM | Attr = ] ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 6.0.4.2 | Size = 323584 bytes | Modified Date = 2/23/2006 3:45:06 PM | Attr = ] wcs.exe -> %ProgramFiles%\Web Technologies\wcs.exe -> [Ver = | Size = 15872 bytes | Modified Date = 7/6/2008 6:27:09 PM | Attr = ] otscanit.exe -> %UserProfile%\My Documents\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.16.1 | Size = 396800 bytes | Modified Date = 7/5/2008 11:19:06 AM | Attr = ] [Win32 Services - Non-Microsoft Only] (Adobe LM Service) Adobe LM Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Adobe Systems Shared\Service\Adobelmsvc.exe -> Adobe Systems [Ver = 2.67.010 | Size = 72704 bytes | Modified Date = 12/26/2006 8:30:33 PM | Attr = ] (AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 7:50:35 AM | Attr = R ] (AOL TopSpeedMonitor) AOL TopSpeed Monitor [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltsmon.exe -> America Online, Inc [Ver = 2, 0, 0, 0 | Size = 100016 bytes | Modified Date = 10/15/2004 3:54:14 PM | Attr = ] (ARSVC) ARSVC [Win32_Own | Auto | Running] -> %SystemRoot%\arservice.exe -> Microsoft [Ver = 6.0.0160.0 | Size = 58880 bytes | Modified Date = 8/3/2005 2:19:16 AM | Attr = ] (Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Running] -> %SystemRoot%\system32\ati2evxx.exe -> ATI Technologies Inc. [Ver = 6.14.10.4119 | Size = 376832 bytes | Modified Date = 8/14/2005 12:29:40 AM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (GoogleDesktopManager) GoogleDesktopManager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe -> Google [Ver = 5.1.706.29690 | Size = 1836544 bytes | Modified Date = 8/15/2007 10:57:47 AM | Attr = ] (gusvc) Google Updater Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.2.824.5515.beta | Size = 138680 bytes | Modified Date = 5/9/2007 1:56:59 AM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ] (iPodService) iPodService [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 6.0.4.2 | Size = 323584 bytes | Modified Date = 2/23/2006 3:45:06 PM | Attr = ] (LightScribeService) LightScribeService Direct Disc Labeling Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\LightScribe\LSSrvc.exe -> Hewlett-Packard Company [Ver = 1.4.52.1 | Size = 69632 bytes | Modified Date = 10/23/2005 8:46:44 AM | Attr = ] (LinksysUpdater) Linksys Updater [Win32_Own | Auto | Running] -> %ProgramFiles%\Linksys\Linksys Updater\bin\LinksysUpdater.exe -s C:\Program Files\Linksys\Linksys Updater\conf\ -> File not found (mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MSC\mcmscsvc.exe -> McAfee, Inc. [Ver = 8,1,159,0 | Size = 767976 bytes | Modified Date = 1/9/2008 4:50:22 PM | Attr = ] (McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\MNA\McNASvc.exe -> McAfee, Inc. [Ver = 2,1,143,0 | Size = 2458128 bytes | Modified Date = 1/25/2008 1:38:12 AM | Attr = ] (McODS) McAfee Scanner [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee\VirusScan\mcods.exe -> McAfee, Inc. [Ver = 12,0,172,0 | Size = 378184 bytes | Modified Date = 11/7/2007 9:35:40 AM | Attr = ] (McProxy) McAfee Proxy Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\McProxy\McProxy.exe -> McAfee, Inc. [Ver = 2,0,150,0 | Size = 359248 bytes | Modified Date = 8/15/2007 12:36:04 PM | Attr = ] (McRedirector) McAfee Redirector Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\McAfee\RedirSvc\RedirSvc.exe -> McAfee, Inc. [Ver = 1,2,112,0 | Size = 248416 bytes | Modified Date = 1/15/2007 11:25:22 AM | Attr = ] (McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> %SystemDrive%\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe -> McAfee, Inc. [Ver = VSCORE.14.0.0.349.x86 | Size = 144704 bytes | Modified Date = 7/24/2007 12:02:14 PM | Attr = ] (McSysmon) McAfee SystemGuards [Win32_Own | On_Demand | Running] -> %ProgramFiles%\McAfee\VirusScan\mcsysmon.exe -> McAfee, Inc. [Ver = 12,1,111,0 | Size = 695624 bytes | Modified Date = 12/5/2007 10:04:10 AM | Attr = ] (MpfService) McAfee Personal Firewall Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MPF\MpfSrv.exe -> McAfee, Inc. [Ver = 9.0.136.0 | Size = 856864 bytes | Modified Date = 7/18/2007 3:54:42 PM | Attr = ] (MSK80Service) McAfee SpamKiller Service [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee\MSK\msksrver.exe -> McAfee, Inc. [Ver = 9.1.107.0 | Size = 23880 bytes | Modified Date = 11/26/2007 10:46:14 AM | Attr = ] (MyWebSearchService) My Web Search Service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSSVC.EXE -> MyWebSearch.com [Ver = 1, 0, 0, 1 | Size = 28739 bytes | Modified Date = 4/29/2008 9:17:00 PM | Attr = ] (Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Auto | Running] -> %SystemRoot%\system32\spool\drivers\w32x86\3\HPZIPM12.EXE -> HP [Ver = 10, 1, 1, 6 | Size = 73728 bytes | Modified Date = 8/9/2007 2:27:52 AM | Attr = ] (SiteAdvisor Service) SiteAdvisor Service [Win32_Own | Auto | Running] -> %ProgramFiles%\SiteAdvisor\6261\SAService.exe -> [Ver = | Size = 345376 bytes | Modified Date = 7/8/2008 3:29:12 PM | Attr = ] (0240011215720315mcinstcleanup) McAfee Application Installer Cleanup (0240011215720315) [Win32_Own | Auto | Stopped] -> %SystemRoot%\TEMP\024001~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -> File not found [Driver Services - Non-Microsoft Only] (ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXWDM.SYS -> Realtek Semiconductor Corp. [Ver = 5.10.5910 built by: WinDDK | Size = 3644928 bytes | Modified Date = 8/29/2005 5:11:00 PM | Attr = ] (AmdK8) AMD Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AmdK8.sys -> Advanced Micro Devices [Ver = 1.2.2 (dnsrv(wmbla).050120-1444) | Size = 36352 bytes | Modified Date = 3/9/2005 4:53:00 PM | Attr = ] (ati2mtag) ati2mtag [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ati2mtag.sys -> ATI Technologies Inc. [Ver = 6.14.10.6571 | Size = 1313792 bytes | Modified Date = 8/14/2005 12:35:54 AM | Attr = ] (dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (dmio) Logical Disk Manager Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (dmload) dmload [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (ftsata2) ftsata2 [Kernel | Boot | Stopped] -> %SystemRoot%\system32\DRIVERS\ftsata2.sys -> File not found (GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.4.3 | Size = 14408 bytes | Modified Date = 2/2/2005 1:21:04 AM | Attr = ] (HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HPZid412.sys -> HP [Ver = 9, 0, 0, 0 | Size = 51120 bytes | Modified Date = 3/8/2005 6:52:26 AM | Attr = ] (HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HPZipr12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 16496 bytes | Modified Date = 3/8/2005 6:52:28 AM | Attr = ] (HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HPZius12.sys -> HP [Ver = 9, 0, 0, 0 | Size = 21744 bytes | Modified Date = 3/8/2005 6:52:28 AM | Attr = ] (HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSFHWBS2.sys -> Conexant Systems, Inc. [Ver = 7.20.00 built by: WinDDK | Size = 220928 bytes | Modified Date = 12/15/2004 5:18:32 PM | Attr = ] (HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_DP.sys -> Conexant Systems, Inc. [Ver = 7.20.00 built by: WinDDK | Size = 1038208 bytes | Modified Date = 12/15/2004 5:18:26 PM | Attr = ] (iaStor) Intel RAID Controller [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\iaStor.sys -> Intel Corporation [Ver = 5.1.0.1022 | Size = 872064 bytes | Modified Date = 6/17/2005 4:33:40 PM | Attr = ] (intelppm) Intel Processor Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\System32\DRIVERS\intelppm.sys -> File not found (mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\mdmxsdk.sys -> Conexant [Ver = 1.0.2.006 | Size = 13059 bytes | Modified Date = 3/17/2004 1:04:14 PM | Attr = ] (mfeavfk) McAfee Inc. mfeavfk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfeavfk.sys -> McAfee, Inc. [Ver = SYSCORE.14.0.0.291.x86 | Size = 79304 bytes | Modified Date = 11/22/2007 6:44:08 AM | Attr = ] (mfebopk) McAfee Inc. mfebopk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfebopk.sys -> McAfee, Inc. [Ver = SYSCORE.14.0.0.291.x86 | Size = 35240 bytes | Modified Date = 11/22/2007 6:44:08 AM | Attr = ] (mfehidk) McAfee Inc. mfehidk [Kernel | System | Running] -> %SystemRoot%\system32\drivers\mfehidk.sys -> McAfee, Inc. [Ver = SYSCORE.14.0.0.291.x86 | Size = 201320 bytes | Modified Date = 11/22/2007 6:44:08 AM | Attr = ] (mferkdk) McAfee Inc. mferkdk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mferkdk.sys -> McAfee, Inc. [Ver = SYSCORE.14.0.0.291.x86 | Size = 33832 bytes | Modified Date = 11/22/2007 6:44:04 AM | Attr = ] (mfesmfk) McAfee Inc. mfesmfk [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mfesmfk.sys -> McAfee, Inc. [Ver = SYSCORE.14.0.0.284.x86 | Size = 40488 bytes | Modified Date = 12/2/2007 12:51:42 PM | Attr = ] (MPFP) MPFP [Kernel | System | Running] -> %SystemRoot%\system32\drivers\Mpfp.sys -> McAfee, Inc. [Ver = 9.0.114.0 | Size = 113952 bytes | Modified Date = 7/13/2007 6:20:24 AM | Attr = ] (Ps2) Ps2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\PS2.sys -> Hewlett-Packard Company [Ver = 1.0.2.0 | Size = 19072 bytes | Modified Date = 12/12/2005 5:27:00 PM | Attr = ] (Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] (PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 2.03.32a | Size = 20640 bytes | Modified Date = 6/20/2005 6:05:58 PM | Attr = ] (RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\Rtlnicxp.sys -> Realtek Semiconductor Corporation [Ver = 5.621.0304.2005 built by: WinDDK | Size = 74496 bytes | Modified Date = 3/4/2005 1:10:26 PM | Attr = ] (rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> Realtek Semiconductor Corporation [Ver = 5.398.613.2003 built by: WinDDK | Size = 20992 bytes | Modified Date = 8/4/2004 12:31:34 AM | Attr = ] (Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 5:25:53 AM | Attr = ] (wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 1/10/2003 3:13:04 PM | Attr = ] (winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\HSF_CNXT.sys -> Conexant Systems, Inc. [Ver = 7.20.00 built by: WinDDK | Size = 703232 bytes | Modified Date = 12/15/2004 5:18:28 PM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AlwaysReady Power Message APP -> %SystemRoot%\arpwrmsg.exe [ARPWRMSG.EXE] -> Microsoft [Ver = 6.0.0160.0 | Size = 77312 bytes | Modified Date = 8/3/2005 2:19:16 AM | Attr = ] Antivirus -> %ProgramFiles%\UAV\uav.exe [C:\Program Files\UAV\uav.exe] -> [Ver = 1, 0, 0, 1 | Size = 333824 bytes | Modified Date = 7/3/2008 10:55:07 AM | Attr = ] AOLDialer -> %CommonProgramFiles%\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe] -> AOL LLC [Ver = 4.6.1.2 | Size = 71216 bytes | Modified Date = 10/23/2006 7:50:37 AM | Attr = R ] BearShare -> %ProgramFiles%\BearShare\BearShare.exe ["C:\Program Files\BearShare\BearShare.exe" /pause] -> File not found DISCover -> %ProgramFiles%\DISC\DISCover.exe [C:\Program Files\DISC\DISCover.exe] -> Digital Interactive Systems Corporation [Ver = 3.21.2005.0926 | Size = 1060864 bytes | Modified Date = 9/27/2005 2:43:29 AM | Attr = ] DiscUpdateManager -> %ProgramFiles%\DISC\DISCUpdateMgr.exe [C:\Program Files\DISC\DiscUpdateMgr.exe] -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.926 | Size = 61440 bytes | Modified Date = 9/27/2005 2:42:26 AM | Attr = ] Google Desktop Search -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktop.exe ["C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup] -> Google [Ver = 5.1.706.29690 | Size = 1836544 bytes | Modified Date = 8/15/2007 10:57:47 AM | Attr = ] HostManager -> %CommonProgramFiles%\AOL\1139609045\EE\aolsoftware.exe [C:\Program Files\Common Files\AOL\1139609045\ee\AOLSoftware.exe] -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 12:16:08 PM | Attr = ] HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] -> Hewlett-Packard [Ver = 80, 1, 0, 0 | Size = 54840 bytes | Modified Date = 5/8/2007 4:24:20 PM | Attr = ] HPBootOp -> %ProgramFiles%\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe ["C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run] -> Hewlett-Packard Company [Ver = 2, 0, 5, 1 | Size = 1605740 bytes | Modified Date = 9/21/2005 12:41:10 PM | Attr = ] HPHUPD08 -> %ProgramFiles%\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe [c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe] -> Hewlett-Packard [Ver = 8,1,0,12 | Size = 49152 bytes | Modified Date = 6/2/2005 1:35:56 AM | Attr = ] KBD -> %SystemDrive%\hp\KBD\kbd.exe [C:\HP\KBD\KBD.EXE] -> Hewlett-Packard Company [Ver = 1.0.2.2.20205 | Size = 61440 bytes | Modified Date = 2/2/2005 4:44:24 PM | Attr = ] mcagent_exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe [C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey] -> McAfee, Inc. [Ver = 8,0,237,0 | Size = 582992 bytes | Modified Date = 11/1/2007 7:12:38 PM | Attr = ] McENUI -> %ProgramFiles%\McAfee\MHN\McENUI.exe [C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide] -> McAfee, Inc. [Ver = 2,1,106,0 | Size = 1164576 bytes | Modified Date = 11/30/2007 5:42:30 AM | Attr = ] My Web Search Bar Search Scope Monitor -> %ProgramFiles%\MyWebSearch\bar\1.bin\M3SRCHMN.EXE ["C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0] -> MyWebSearch.com [Ver = 1, 0, 0, 4 | Size = 24688 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] MyWebSearch Email Plugin -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSOEMON.EXE [C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe] -> MyWebSearch.com [Ver = 1,2,2,5 | Size = 32838 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] MyWebSearch Plugin -> %ProgramFiles%\MyWebSearch\bar\1.bin\M3PLUGIN.DLL [rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF] -> MyWebSearch.com [Ver = 1, 0, 1, 4 | Size = 53352 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] PCDrProfiler -> [] -> File not found QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> Apple Computer, Inc. [Ver = 7.0.4 | Size = 155648 bytes | Modified Date = 6/24/2007 5:21:44 AM | Attr = ] SiteAdvisor -> %ProgramFiles%\SiteAdvisor\6261\SiteAdv.exe ["C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"] -> [Ver = | Size = 36640 bytes | Modified Date = 6/21/2007 3:06:20 PM | Attr = ] SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe ["C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr = ] TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] -> RealNetworks, Inc. [Ver = 0.1.1.45 | Size = 185896 bytes | Modified Date = 4/27/2008 1:41:04 PM | Attr = ] < OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL-> Installed = 1 -> MAPI-> Installed = 1 -> MSFS-> Installed = 1 -> < Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 42451903483765222325508719318137 -> %ProgramFiles%\Antivirus 2009\av2009.exe [C:\Program Files\Antivirus 2009\av2009.exe] -> [Ver = | Size = 957952 bytes | Modified Date = 7/6/2008 9:55:44 PM | Attr = ] Antivirus -> %ProgramFiles%\UAV\uav.exe [C:\Program Files\UAV\uav.exe] -> [Ver = 1, 0, 0, 1 | Size = 333824 bytes | Modified Date = 7/3/2008 10:55:07 AM | Attr = ] MySpaceIM -> %ProgramFiles%\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe] -> [Ver = 1.0.756.0 | Size = 9117696 bytes | Modified Date = 4/17/2008 6:27:00 PM | Attr = ] MyWebSearch Email Plugin -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSOEMON.EXE [C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe] -> MyWebSearch.com [Ver = 1,2,2,5 | Size = 32838 bytes | Modified Date = 4/29/2008 9:16:59 PM | Attr = ] swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] -> Google Inc. [Ver = 2, 0, 301, 1654 | Size = 68856 bytes | Modified Date = 4/3/2007 7:17:32 PM | Attr = ] updateMgr -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe ["C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1] -> Adobe Systems Incorporated [Ver = 3.1.0.10 | Size = 313472 bytes | Modified Date = 3/30/2006 5:45:08 PM | Attr = R ] < All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> %AllUsersProfile%\Start Menu\Programs\Startup\PalTalk.lnk -> %ProgramFiles%\Paltalk Messenger\paltalk.exe -> AVM Software Inc. [Ver = 9.92.2952.1026 | Size = 10452992 bytes | Modified Date = 5/8/2008 5:17:47 PM | Attr = ] < HP_Administrator Startup Folder > -> C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup -> < AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL -> %ProgramFiles%\Google\Google Desktop Search\GoogleDesktopNetwork3.dll -> Google [Ver = 5.1.706.29690 | Size = 145408 bytes | Modified Date = 8/13/2007 10:45:13 PM | Attr = ] *MultiFile Done* -> -> < SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler -> {d1577581-2ed7-469f-99b1-72c1339e0ee0} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\hkushdr.dll [doctordom] -> [Ver = | Size = 13312 bytes | Modified Date = 7/4/2008 1:26:04 PM | Attr = S] < SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> *Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell -> Explorer.exe -> %SystemRoot%\explorer.exe -> Microsoft Corporation [Ver = 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234) | Size = 1033216 bytes | Modified Date = 6/13/2007 5:23:07 AM | Attr = ] *MultiFile Done* -> -> *UserInit* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit -> C:\WINDOWS\system32\userinit.exe -> %SystemRoot%\system32\userinit.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 24576 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] *MultiFile Done* -> -> *UIHost* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost -> logonui.exe -> %SystemRoot%\system32\logonui.exe -> Microsoft Corporation [Ver = 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) | Size = 514560 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] *MultiFile Done* -> -> *VMApplet* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet -> rundll32 shell32 -> %SystemRoot%\system32\shell32.dll -> Microsoft Corporation [Ver = 6.00.2900.3241 (xpsp_sp2_qfe.071025-1245) | Size = 8460288 bytes | Modified Date = 10/25/2007 10:34:01 PM | Attr = ] Control_RunDLL "sysdm.cpl" -> %SystemRoot%\system32\sysdm.cpl -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 298496 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] *MultiFile Done* -> -> < Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> AtiExtEvent -> %SystemRoot%\system32\ati2evxx.dll -> ATI Technologies Inc. [Ver = 6.14.10.4119 | Size = 46080 bytes | Modified Date = 8/14/2005 12:30:44 AM | Attr = ] < CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 149 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCDBurning -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\some -> %ProgramFiles%\Web Technologies\wcs.exe [C:\Program Files\Web Technologies\wcs.exe] -> [Ver = | Size = 15872 bytes | Modified Date = 7/6/2008 6:27:09 PM | Attr = ] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\start -> %ProgramFiles%\Web Technologies\iebtm.exe [C:\Program Files\Web Technologies\iebtm.exe] -> [Ver = | Size = 19968 bytes | Modified Date = 7/6/2008 6:27:12 PM | Attr = ] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallVisualStyle -> %SystemRoot%\Resources\Themes\Royale\Royale.mss [C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles] -> File not found HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\InstallTheme -> %SystemRoot%\Resources\Themes\Royale.the [C:\WINDOWS\Resources\Themes\Royale.theme] -> File not found < CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> < CDROM Autorun Settings > [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\ -> -> *DependOnGroup* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DependOnGroup -> SCSI miniport -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Group -> SCSI CDROM Class -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Start -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Tag -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\Type -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\DisplayName -> CD-ROM Driver -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\ImagePath -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 49536 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun -> 1 -> *AutoRunAlwaysDisable* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRunAlwaysDisable -> NEC MBR-7 -> -> File not found NEC MBR-7.4 -> -> File not found PIONEER CHANGR DRM-1804X -> -> File not found PIONEER CD-ROM DRM-6324X -> -> File not found PIONEER CD-ROM DRM-624X -> -> File not found TORiSAN CD-ROM CDR_C36 -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\0 -> IDE\CdRomTSSTcorp_CD/DVDW_TS-H552L_______________0614____\5&17374bf3&0&0.0.0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\Enum\\NextInstance -> 1 -> < Drives - Autoruns > -> -> AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [Ver = | Size = 300 bytes | Modified Date = 3/28/2006 8:29:39 PM | Attr = ] AUTOEXEC.BAT [] -> D:\AUTOEXEC.BAT [ FAT32 ] -> [Ver = | Size = 0 bytes | Modified Date = 7/28/2001 5:07:38 AM | Attr = HS] Autorun.inf [[AUTORUN] | ShellExecute=Info.exe protect.ed 480 480 | ] -> D:\Autorun.inf [ FAT32 ] -> [Ver = | Size = 53 bytes | Modified Date = 4/30/2004 6:01:14 AM | Attr = HS] < HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> < Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://internetsearchservice.com -> HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://internetsearchservice.com/ie6.html -> HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://internetsearchservice.com -> HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 -> HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKEY_LOCAL_MACHINE\: Search\\Default_Search_URL -> http://www.google.com/ie -> HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://internetsearchservice.com -> < Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop -> HKEY_CURRENT_USER\: Main\\Default_Search_URL -> http://internetsearchservice.com -> HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> HKEY_CURRENT_USER\: Main\\Search Bar -> http://internetsearchservice.com/ie6.html -> HKEY_CURRENT_USER\: Main\\Search Page -> http://internetsearchservice.com -> HKEY_CURRENT_USER\: Main\\Start Page -> about:blank -> HKEY_CURRENT_USER\: Search\\SearchAssistant -> http://internetsearchservice.com -> HKEY_CURRENT_USER\: SearchURL\\ -> http://www.google.com/search?q=%s[Reg Error: Value provider does not exist or could not be read.] -> HKEY_CURRENT_USER\: URLSearchHooks\\ [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Value does not exist or could not be read.] -> File not found HKEY_CURRENT_USER\: URLSearchHooks\\{00A6FAF6-072E-44cf-8957-5838F569A31D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL [] -> File not found HKEY_CURRENT_USER\: URLSearchHooks\\{0A94B116-4504-4e26-AB05-E61E474AA38B} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL [] -> File not found HKEY_CURRENT_USER\: URLSearchHooks\\{D73F49B6-B51B-4d32-A3B7-BD04B8342F53} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL [] -> File not found HKEY_CURRENT_USER\: URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOLTBSearch Class] -> File not found HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found HKEY_CURRENT_USER\: ProxyEnable -> 0 -> < Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. -> trymedia.com .[https] -> Trusted sites -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> < Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 29 domain(s) found. -> objects_aol.com [*] -> Out of zone range - ( 5 ) -> 1 domain(s) and sub-domain(s) not assigned to a zone. < Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 30 range(s) found. -> < BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee\MSK\mcapbho.dll [McAfee Phishing Filter] -> [Ver = | Size = 324936 bytes | Modified Date = 11/26/2007 10:46:10 AM | Attr = ] {E2090673-256B-4632-94EE-FEC7F551543C} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Web Technologies\iebt.dll [Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 8192 bytes | Modified Date = 7/10/2008 2:56:45 PM | Attr = ] < Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {07B18EA9-A523-4961-B6BB-170DE4475CCA} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSBAR.DLL [My Web Search] -> File not found {0BF43445-2F28-4351-9252-17FE6E806AA0} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SiteAdvisor\6261\SiteAdv.dll [McAfee SiteAdvisor] -> [Ver = | Size = 927008 bytes | Modified Date = 5/16/2008 11:49:40 AM | Attr = ] {3F3714A9-89A4-46be-8AF3-D0C9D1FB03F9} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MorpheusBar\bar\1.bin\MORPHBAR.DLL [Morpheus Toolbar] -> File not found {C46F137F-2C2A-4714-AA14-323137F882AE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Web Technologies\iebr.dll [Internet Service] -> [Ver = | Size = 90624 bytes | Modified Date = 7/6/2008 6:27:13 PM | Attr = ] {DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> File not found {F4D76F09-7896-458a-890F-E1F05C46069F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AskPBar\bar\1.bin\ASKPBAR.DLL [Ask Toolbar] -> File not found < Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{3F3714A9-89A4-46BE-8AF3-D0C9D1FB03F9} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MorpheusBar\bar\1.bin\MORPHBAR.DLL [Morpheus Toolbar] -> File not found ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MyWebSearch\bar\1.bin\MWSBAR.DLL [My Web Search] -> File not found WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\google\googletoolbar1.dll [&Google] -> File not found WebBrowser\\{3F3714A9-89A4-46BE-8AF3-D0C9D1FB03F9} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MorpheusBar\bar\1.bin\MORPHBAR.DLL [Morpheus Toolbar] -> File not found WebBrowser\\{C46F137F-2C2A-4714-AA14-323137F882AE} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Web Technologies\iebr.dll [Internet Service] -> [Ver = | Size = 90624 bytes | Modified Date = 7/6/2008 6:27:13 PM | Attr = ] WebBrowser\\{D554D8FC-B36D-4BB4-93DB-4A3394D505E3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Netcraft Toolbar\nctb.dll [&Netcraft Toolbar] -> Netcraft [Ver = 1.07 | Size = 673536 bytes | Modified Date = 10/16/2006 3:36:18 PM | Attr = ] WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> File not found WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found WebBrowser\\{F4D76F09-7896-458A-890F-E1F05C46069F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AskPBar\bar\1.bin\ASKPBAR.DLL [Ask Toolbar] -> File not found < Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Sun Java Console] -> File not found {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [Sun Java Console] -> File not found {3369AF0D-62E9-4bda-8103-B4C75499B578}:{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> File not found {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE}:Exec -> %ProgramFiles%\Paltalk Messenger\paltalk.exe [PalTalk] -> AVM Software Inc. [Ver = 9.92.2952.1026 | Size = 10452992 bytes | Modified Date = 5/8/2008 5:17:47 PM | Attr = ] {9034A523-D068-4BE8-A284-9DF278BE776E}:Exec -> [IE Anti-Spyware] -> File not found {E2D4D26B-0180-43a4-B05F-462D6D54C789}: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Connection Help] -> File not found < Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> [Sun Java Console] -> File not found CmdMapping\\{3369AF0D-62E9-4bda-8103-B4C75499B578} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\AOL\AOL Toolbar 5.0\aoltb.dll [AOL Toolbar] -> File not found CmdMapping\\{E2D4D26B-0180-43a4-B05F-462D6D54C789} [HKEY_LOCAL_MACHINE] -> [Connection Help] -> File not found < Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &AOL Toolbar Search -> %ProgramFiles%\AOL\AOL Toolbar 5.0\resources\en-us\local\search.html -> [Ver = | Size = 747 bytes | Modified Date = 9/7/2006 3:59:50 PM | Attr = ] &Search -> -> File not found < Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> < User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> FunWebProducts -> -> < DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {109E7052-7208-403E-8A95-34111BF79CDC} -> (1394 Net Adapter) -> {892900FC-9814-4488-99C0-81491C1EE93D} -> (HP EN1207D-TX PCI 10/100 Fast Ethernet Adapter) -> {C066546D-7FD3-46A0-B822-4DFF2F44C84E} -> (Realtek RTL8139/810x Family Fast Ethernet NIC) -> < Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp: [HKEY_LOCAL_MACHINE] -> No CLSID value msdaipp: [HKEY_LOCAL_MACHINE] -> No CLSID value siteadvisor:{3A5DC592-7723-4EAA-9EE6-AF4222BCF879} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SiteAdvisor\6261\SiteAdv.dll[Reg Error: Value does not exist or could not be read.] -> [Ver = | Size = 927008 bytes | Modified Date = 5/16/2008 11:49:40 AM | Attr = ] < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {15B782AF-55D8-11D1-B477-006097098764}[HKEY_LOCAL_MACHINE] -> https://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab[Macromedia Authorware Web Player Control] -> {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}[HKEY_LOCAL_MACHINE] -> http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab[Reg Error: Key does not exist or could not be opened.] -> {21BB8360-F943-447E-98F3-3C22345375A7}[HKEY_LOCAL_MACHINE] -> http://www.freeworldgroup.com/games6/chocolatier/build/ChocolatierWeb.1.0.0.13.cab[CPlayFirstChocolatierControl Object] -> {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}[HKEY_LOCAL_MACHINE] -> C:\Program Files\Yahoo!\Common\yinsthelper.dll[YInstStarter Class] -> {639658F3-B141-4D6B-B936-226F75A5EAC3}[HKEY_LOCAL_MACHINE] -> file:///C:/Documents%20and%20Settings/HP_Administrator/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash2.1.0.0.68.cab[CPlayFirstDinerDash2Control Object] -> {8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {9522B3FB-7A2B-4646-8AF6-36E7F593073C}[HKEY_LOCAL_MACHINE] -> http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/Kraft/Coupons.cab[Reg Error: Key does not exist or could not be opened.] -> {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19}[HKEY_LOCAL_MACHINE] -> http://www.freeworldgroup.com/games6/dinerdash3/ddfotg.1.0.0.33.cab[CPlayFirstddfotgControl Object] -> {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> {D0C0F75C-683A-4390-A791-1ACFD5599AB8}[HKEY_LOCAL_MACHINE] -> http://playgames.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab[Oberon Flash Game Host] -> {D27CDB6E-AE6D-11CF-96B8-444553550000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Reg Error: Key does not exist or could not be opened.] -> {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}[HKEY_LOCAL_MACHINE] -> http://www.popcap.com/webgames/popcaploader_v10.cab[PopCapLoader Object] -> < Module Usage Keys [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/cpbrkpie.ocx\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/cpbrkpie.ocx\\.Owner -> {9522B3FB-7A2B-4646-8AF6-36E7F593073C} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/cpbrkpie.ocx\\{9522B3FB-7A2B-4646-8AF6-36E7F593073C} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Chocolatier.1.0.0.13.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Chocolatier.1.0.0.13.dll\\.Owner -> {21BB8360-F943-447E-98F3-3C22345375A7} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/Chocolatier.1.0.0.13.dll\\{21BB8360-F943-447E-98F3-3C22345375A7} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ddfotg.1.0.0.33.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ddfotg.1.0.0.33.dll\\.Owner -> {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ddfotg.1.0.0.33.dll\\{BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/DinerDash2.1.0.0.68.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/DinerDash2.1.0.0.68.dll\\.Owner -> {639658F3-B141-4D6B-B936-226F75A5EAC3} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/DinerDash2.1.0.0.68.dll\\{639658F3-B141-4D6B-B936-226F75A5EAC3} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/OberonGameHost.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/OberonGameHost.dll\\.Owner -> {D0C0F75C-683A-4390-A791-1ACFD5599AB8} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/OberonGameHost.dll\\{D0C0F75C-683A-4390-A791-1ACFD5599AB8} -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/popcaploader.dll\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/popcaploader.dll\\.Owner -> {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/popcaploader.dll\\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -> -> [Registry - Additional Scans - Non-Microsoft Only] < BotCheck > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirstRunDisabled -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\\DisableMonitoring -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\\DisableMonitoring -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> -> *Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> 0 [binary data] -> *Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> kerberos -> %SystemRoot%\system32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 12:49:30 PM | Attr = ] msv1_0 -> %SystemRoot%\system32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] schannel -> %SystemRoot%\system32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 9:21:15 AM | Attr = ] wdigest -> %SystemRoot%\system32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 3/23/2006 11:37:50 PM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 612 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> *Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> scecli -> %SystemRoot%\system32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> *ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> Windows NT Access Provider -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> %SystemRoot%\system32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> 6B 99 01 BC 9B F6 34 7D 58 98 7A 54 B1 2D 65 F0 65 63 33 35 38 35 31 38 00 00 00 00 72 21 00 00 18 CA 06 00 99 D0 BF 71 04 CA 06 00 10 00 00 00 00 00 00 00 75 8E 6A FC 3F 41 35 2B FB 00 A9 EC [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> 12 43 0E 75 6D 17 B0 FE A4 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> 53 EC 80 C4 B4 AB [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\Auth132 -> %SystemRoot%\system32\iissuba.dll [IISSUBA] -> Microsoft Corporation [Ver = 6.0.2600.0 (xpclient.010817-1148) | Size = 9216 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminclientsec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\\ntlmminserversec -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> 65 0F D4 89 2B BA 5E BE 6D C0 DE 26 C5 2A FC 8F [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> 72 B7 C1 B4 8C 2E C6 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> 00 60 DB 8F D1 7E C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> 00 60 DB 8F D1 7E C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> 00 60 DB 8F D1 7E C4 01 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 25769 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\system32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe -> %ProgramFiles%\Updates from HP\9972322\Program\Updates from HP.exe [C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP] -> Hewlett-Packard [Ver = Version 6.3.2 (Build 116R) | Size = 36903 bytes | Modified Date = 11/10/2005 7:50:28 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> %SystemRoot%\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.3012 (xpsp.061010-0355) | Size = 557568 bytes | Modified Date = 10/10/2006 7:44:50 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:*:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:*:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:*:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:*:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DoNotAllowExceptions -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\DisableNotifications -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe -> %CommonProgramFiles%\AOL\AOL Spyware Protection\asp.exe [C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Disabled:AOL] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe -> %CommonProgramFiles%\AOL\AOL Spyware Protection\AOLSP Scheduler.exe [C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Disabled:AOL] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\America Online 9.0\waol.exe -> %ProgramFiles%\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Disabled:AOL] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltpspd.exe [C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Disabled:AOLTopSpeed] -> America Online Inc [Ver = 2, 0, 0, 0 | Size = 46768 bytes | Modified Date = 10/15/2004 3:54:12 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltsmon.exe [C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Disabled:AOLTsMon] -> America Online, Inc [Ver = 2, 0, 0, 0 | Size = 100016 bytes | Modified Date = 10/15/2004 3:54:14 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\DISC\DISCover.exe -> %ProgramFiles%\DISC\DISCover.exe [C:\Program Files\DISC\DISCover.exe:*:Disabled:DISCover Drop & Play System] -> Digital Interactive Systems Corporation [Ver = 3.21.2005.0926 | Size = 1060864 bytes | Modified Date = 9/27/2005 2:43:29 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\DISC\myFTP.exe -> %ProgramFiles%\DISC\myFTP.exe [C:\Program Files\DISC\myFTP.exe:*:Disabled:DISCover FTP] -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.926 | Size = 90112 bytes | Modified Date = 9/27/2005 2:42:20 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\DISC\DiscStreamHub.exe -> %ProgramFiles%\DISC\DiscStreamHub.exe [C:\Program Files\DISC\DiscStreamHub.exe:*:Disabled:DISCover Stream Hub] -> Digital Interactive Systems Corporation, Inc. [Ver = 3.21.2005.926 | Size = 45056 bytes | Modified Date = 9/27/2005 2:42:26 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\EarthLink TotalAccess\TaskPanl.exe -> %ProgramFiles%\EarthLink TotalAccess\TaskPanl.exe [C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpfccopy.exe [C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe] -> Hewlett-Packard [Ver = 2.4 | Size = 151635 bytes | Modified Date = 5/11/2005 7:34:02 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpoews01.exe [C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 57344 bytes | Modified Date = 6/3/2005 8:06:04 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpofxm08.exe [C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 225280 bytes | Modified Date = 6/3/2005 7:50:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hposfx08.exe [C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 40960 bytes | Modified Date = 6/3/2005 7:50:14 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hposid01.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hposid01.exe [C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 81920 bytes | Modified Date = 6/3/2005 7:45:46 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqCopy.exe [C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 172032 bytes | Modified Date = 6/3/2005 8:12:34 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqDIA.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe] -> [Ver = 5.0.0.247 | Size = 704512 bytes | Modified Date = 3/16/2005 1:17:50 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqkygrp.exe [C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe] -> Hewlett-Packard [Ver = 5.1.0.940 | Size = 1081344 bytes | Modified Date = 5/11/2005 7:07:26 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqPhUnl.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe] -> [Ver = 5.0.0.247 | Size = 417792 bytes | Modified Date = 3/16/2005 1:12:10 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqscnvw.exe [C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe] -> [Ver = 3, 2, 0,940 | Size = 200704 bytes | Modified Date = 5/11/2005 7:50:34 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqste08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe] -> Hewlett-Packard Co. [Ver = 53.0.13.000 | Size = 204800 bytes | Modified Date = 5/12/2005 10:40:38 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe] -> Hewlett-Packard Co. [Ver = 53.0.13.000 | Size = 282624 bytes | Modified Date = 5/12/2005 9:23:26 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpzwiz01.exe [C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe] -> Hewlett-Packard Co. [Ver = 50.0.214.000 | Size = 458752 bytes | Modified Date = 6/3/2005 7:51:06 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\iTunes\iTunes.exe -> %ProgramFiles%\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes] -> Apple Computer, Inc. [Ver = 6.0.4.2 | Size = 14144000 bytes | Modified Date = 2/23/2006 4:31:58 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Morpheus\Morpheus.exe -> %ProgramFiles%\Morpheus\Morpheus.exe [C:\Program Files\Morpheus\Morpheus.exe:*:Disabled:M5Shell] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\Network Diagnostic\xpnetdiag.exe -> %SystemRoot%\network diagnostic\xpnetdiag.exe [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.3012 (xpsp.061010-0355) | Size = 557568 bytes | Modified Date = 10/10/2006 7:44:50 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\sessmgr.exe -> %SystemRoot%\system32\sessmgr.exe [C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe -> %ProgramFiles%\Updates from HP\9972322\Program\Updates from HP.exe [C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Disabled:Updates from HP] -> Hewlett-Packard [Ver = Version 6.3.2 (Build 116R) | Size = 36903 bytes | Modified Date = 11/10/2005 7:50:28 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YServer.exe -> %ProgramFiles%\Yahoo!\Messenger\YServer.exe [C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger] -> File not found HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Messenger\msmsgs.exe -> %ProgramFiles%\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger] -> Microsoft Corporation [Ver = 4.7.3001 | Size = 1694208 bytes | Modified Date = 10/13/2004 6:24:38 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AOL 9.0\waol.exe -> %ProgramFiles%\AOL 9.0\waol.exe [C:\Program Files\AOL 9.0\waol.exe:*:Enabled:AOL] -> AOL, LLC. [Ver = 9.05.001 | Size = 39472 bytes | Modified Date = 4/18/2007 1:49:07 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe -> %CommonProgramFiles%\AOL\TopSpeed\3.0\aoltpsd3.exe [C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed] -> AOL LLC [Ver = 3, 0, 0, 4 | Size = 63120 bytes | Modified Date = 4/2/2007 7:33:32 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\1139609045\EE\AOLServiceHost.exe -> %CommonProgramFiles%\AOL\1139609045\EE\AOLServiceHost.exe [C:\Program Files\Common Files\AOL\1139609045\EE\AOLServiceHost.exe:*:Enabled:AOL] -> America Online, Inc. [Ver = 1.3.6.0 | Size = 151128 bytes | Modified Date = 7/29/2005 11:53:51 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\Loader\aolload.exe -> %CommonProgramFiles%\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> AOL LLC [Ver = 9.3.2.2 | Size = 10800 bytes | Modified Date = 11/3/2006 2:17:27 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\System Information\sinf.exe -> %CommonProgramFiles%\AOL\System Information\sinf.exe [C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information] -> AOL LLC [Ver = 2, 4, 6, 2 | Size = 206176 bytes | Modified Date = 9/17/2007 8:02:47 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe -> %CommonProgramFiles%\AolCoach\en_en\player\AOLNySEV.exe [C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL] -> Gteko Ltd. [Ver = 1, 0, 0, 35 | Size = 59992 bytes | Modified Date = 10/14/2004 5:34:06 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\LimeWire\LimeWire.exe -> %ProgramFiles%\LimeWire\LimeWire.exe [C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire] -> Lime Wire, LLC [Ver = 1, 0, 0, 2 | Size = 147456 bytes | Modified Date = 2/8/2008 4:32:57 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\ACS\AOLDial.exe -> %CommonProgramFiles%\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL Connectivity Service Dialer] -> AOL LLC [Ver = 4.6.1.2 | Size = 71216 bytes | Modified Date = 10/23/2006 7:50:37 AM | Attr = R ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL Connectivity Service] -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 7:50:35 AM | Attr = R ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\AOL\1139609045\EE\aolsoftware.exe -> %CommonProgramFiles%\AOL\1139609045\EE\aolsoftware.exe [C:\Program Files\Common Files\AOL\1139609045\EE\aolsoftware.exe:*:Enabled:AOL Shared Components] -> AOL LLC [Ver = 15.5.1.2 | Size = 42032 bytes | Modified Date = 5/25/2007 12:16:08 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AOL 9.1\waol.exe -> %ProgramFiles%\AOL 9.1\waol.exe [C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL] -> AOL, LLC. [Ver = 9.05.001 | Size = 39264 bytes | Modified Date = 10/27/2007 12:45:07 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -> %CommonProgramFiles%\McAfee\MNA\McNASvc.exe [C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent] -> McAfee, Inc. [Ver = 2,1,143,0 | Size = 2458128 bytes | Modified Date = 1/25/2008 1:38:12 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Paltalk Messenger\paltalk.exe -> %ProgramFiles%\Paltalk Messenger\paltalk.exe [C:\Program Files\Paltalk Messenger\paltalk.exe:*:Disabled:PaltalkScene] -> AVM Software Inc. [Ver = 9.92.2952.1026 | Size = 10452992 bytes | Modified Date = 5/8/2008 5:17:47 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MySpace\IM\MySpaceIM.exe -> %ProgramFiles%\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM] -> [Ver = 1.0.756.0 | Size = 9117696 bytes | Modified Date = 4/17/2008 6:27:00 PM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %SystemRoot%\system32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> %SystemRoot%\system32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Description -> Enables remote users to modify registry settings on this computer. If this service is stopped, the registry can be modified only by users on this computer. If this service is disabled, any services that explicitly depend on it will fail to start. -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DependOnService -> RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 6:39:50 AM | Attr = ] *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\DisplayName -> Remote Registry -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ImagePath -> %SystemRoot%\system32\svchost.exe [%SystemRoot%\system32\svchost.exe -k LocalService] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\ObjectName -> NT AUTHORITY\LocalService -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Group -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\\FailureActions -> 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 E0 AD 08 00 01 00 00 00 E8 03 00 00 [binary data] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Parameters\\ServiceDll -> %SystemRoot%\system32\regsvc.dll [%SystemRoot%\system32\regsvc.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 59904 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\0 -> Root\LEGACY_REMOTEREGISTRY\0000 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Type -> 16 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Start -> 4 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ImagePath -> %SystemRoot%\system32\tlntsvr.exe [C:\WINDOWS\system32\tlntsvr.exe] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 73216 bytes | Modified Date = 8/10/2004 7:00:00 AM | Attr = ] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DisplayName -> Telnet -> *DependOnService* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnService -> RPCSS -> %SystemRoot%\system32\rpcss.dll -> Microsoft Corporation [Ver = 5.1.2600.2726 (xpsp_sp2_gdr.050725-1528) | Size = 397824 bytes | Modified Date = 7/26/2005 6:39:50 AM | Attr = ] TCPIP -> -> File not found NTLMSSP -> -> File not found *MultiFile Done* -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\\Description -> Enables a remote user to log on to this computer and run programs, and supports various TCP/IP Telnet clients, including UNIX-based and Windows-based computers. If this service is stopped, remote user access to programs might be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\Security\\Security -> [Binary data over 100 bytes] -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> [Files/Folders - Created Within 30 days] 734914 -> %SystemRoot%\System32\734914 -> [Folder | Created Date = 7/6/2008 6:27:27 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> Berlitz.scr -> %SystemRoot%\System32\Berlitz.scr -> [Ver = 1,0,13,4 | Size = 608768 bytes | Created Date = 6/27/2008 1:58:09 PM | Attr = ] BerlitzSCR.dat -> %SystemRoot%\System32\BerlitzSCR.dat -> [Ver = | Size = 86870 bytes | Created Date = 6/27/2008 1:58:09 PM | Attr = ] dunzip32.dll -> %SystemRoot%\System32\dunzip32.dll -> Inner Media, Inc. [Ver = 5.00.06 | Size = 143360 bytes | Created Date = 7/7/2008 8:41:21 PM | Attr = ] java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 135168 bytes | Created Date = 6/26/2008 12:46:21 PM | Attr = ] javacpl.cpl -> %SystemRoot%\System32\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 69632 bytes | Created Date = 6/26/2008 12:46:21 PM | Attr = ] javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 135168 bytes | Created Date = 6/26/2008 12:46:21 PM | Attr = ] javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 139264 bytes | Created Date = 6/26/2008 12:46:21 PM | Attr = ] MRT.INI -> %SystemRoot%\System32\MRT.INI -> [Ver = | Size = 118 bytes | Created Date = 7/8/2008 8:24:32 PM | Attr = ] scui.cpl -> %SystemRoot%\System32\scui.cpl -> [Ver = | Size = 78336 bytes | Created Date = 7/6/2008 9:55:45 PM | Attr = ] uav.cpl -> %SystemRoot%\System32\uav.cpl -> Ultimate Antivirus 2008 [Ver = 1, 0, 0, 1 | Size = 117248 bytes | Created Date = 7/6/2008 9:57:50 PM | Attr = ] wav.cpl -> %SystemRoot%\System32\wav.cpl -> Windows Antivirus 2008 [Ver = 1, 0, 0, 1 | Size = 117248 bytes | Created Date = 7/6/2008 7:36:47 PM | Attr = ] LastGood -> %SystemRoot%\LastGood -> [Folder | Created Date = 7/10/2008 3:04:52 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 7/1/2008 5:29:29 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 7/1/2008 5:29:29 PM | Attr = H ] TLTitleData.ini -> %SystemRoot%\TLTitleData.ini -> [Ver = | Size = 2020 bytes | Created Date = 6/27/2008 1:58:45 PM | Attr = ] Easy Internet Sign-up.job -> %SystemRoot%\tasks\Easy Internet Sign-up.job -> [Ver = | Size = 480 bytes | Created Date = 6/25/2008 2:23:45 PM | Attr = ] McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [Ver = | Size = 362 bytes | Created Date = 7/7/2008 8:43:47 PM | Attr = ] McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [Ver = | Size = 354 bytes | Created Date = 7/7/2008 8:43:46 PM | Attr = ] [Files Created - Additional Folder Scans - Non-Microsoft Only] Linksys -> %AllUsersProfile%\Application Data\Linksys -> [Folder | Created Date = 6/28/2008 12:50:56 PM | Attr = ] McAfee -> %AllUsersProfile%\Application Data\McAfee -> [Folder | Created Date = 6/23/2008 2:16:04 PM | Attr = ] McAfee.com -> %AllUsersProfile%\Application Data\McAfee.com -> [Folder | Created Date = 6/23/2008 2:16:28 PM | Attr = ] PopCap -> %AllUsersProfile%\Application Data\PopCap -> [Folder | Created Date = 7/5/2008 7:07:25 PM | Attr = ] SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor -> [Folder | Created Date = 7/7/2008 8:42:30 PM | Attr = ] McAfee.com Personal Firewall -> %AppData%\McAfee.com Personal Firewall -> [Folder | Created Date = 6/23/2008 2:16:41 PM | Attr = ] SiteAdvisor -> %AppData%\SiteAdvisor -> [Folder | Created Date = 7/7/2008 8:42:30 PM | Attr = ] SupportSoft -> %UserProfile%\Local Settings\Application Data\SupportSoft -> [Folder | Created Date = 6/25/2008 1:46:08 PM | Attr = ] ATF-Cleaner.exe -> %UserProfile%\My Documents\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Created Date = 7/10/2008 3:31:04 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\ATF-Cleaner.exe:Zone.Identifier God's gift.wps -> %UserProfile%\My Documents\God's gift.wps -> [Ver = | Size = 23040 bytes | Created Date = 6/28/2008 8:57:17 PM | Attr = ] HJTInstall.exe -> %UserProfile%\My Documents\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Created Date = 7/8/2008 10:05:47 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\HJTInstall.exe:Zone.Identifier Misty.wps -> %UserProfile%\My Documents\Misty.wps -> [Ver = | Size = 11264 bytes | Created Date = 6/22/2008 8:41:05 PM | Attr = ] My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [Ver = | Size = 140 bytes | Created Date = 7/6/2008 6:27:22 PM | Attr = ] OTScanIt -> %UserProfile%\My Documents\OTScanIt -> [Folder | Created Date = 7/10/2008 3:33:45 PM | Attr = ] OTScanIt.exe -> %UserProfile%\My Documents\OTScanIt.exe -> [Ver = | Size = 568114 bytes | Created Date = 7/10/2008 3:33:16 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\OTScanIt.exe:Zone.Identifier spybotsd160.exe -> %UserProfile%\My Documents\spybotsd160.exe -> Safer Networking Limited [Ver = 1.6.0 | Size = 15083520 bytes | Created Date = 7/8/2008 10:11:26 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\spybotsd160.exe:Zone.Identifier The race 046.jpg -> %UserProfile%\My Documents\The race 046.jpg -> [Ver = | Size = 550849 bytes | Created Date = 6/12/2008 1:43:12 PM | Attr = ] Antivirus Scan.url -> %AllUsersProfile%\Desktop\Antivirus Scan.url -> [Ver = | Size = 135 bytes | Created Date = 7/6/2008 6:27:22 PM | Attr = ] Berlitz Learning System.lnk -> %AllUsersProfile%\Desktop\Berlitz Learning System.lnk -> [Ver = | Size = 1769 bytes | Created Date = 6/27/2008 2:06:06 PM | Attr = ] McAfee Easy Network.lnk -> %AllUsersProfile%\Desktop\McAfee Easy Network.lnk -> [Ver = | Size = 677 bytes | Created Date = 7/7/2008 8:43:49 PM | Attr = ] Online Spyware Test.url -> %AllUsersProfile%\Desktop\Online Spyware Test.url -> [Ver = | Size = 135 bytes | Created Date = 7/6/2008 6:27:22 PM | Attr = ] Antivirus 2009.lnk -> %UserProfile%\Desktop\Antivirus 2009.lnk -> [Ver = | Size = 755 bytes | Created Date = 7/6/2008 9:55:45 PM | Attr = ] HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1745 bytes | Created Date = 7/8/2008 10:07:14 PM | Attr = ] Ultimate Antivirus 2008.lnk -> %UserProfile%\Desktop\Ultimate Antivirus 2008.lnk -> [Ver = | Size = 669 bytes | Created Date = 7/6/2008 9:57:48 PM | Attr = ] Windows Antivirus 2008.lnk -> %UserProfile%\Desktop\Windows Antivirus 2008.lnk -> [Ver = | Size = 667 bytes | Created Date = 7/6/2008 7:36:46 PM | Attr = ] SupportSoft -> %CommonProgramFiles%\SupportSoft -> [Folder | Created Date = 6/25/2008 1:46:06 PM | Attr = ] Antivirus 2009 -> %ProgramFiles%\Antivirus 2009 -> [Folder | Created Date = 7/6/2008 9:55:42 PM | Attr = ] Berlitz -> %ProgramFiles%\Berlitz -> [Folder | Created Date = 6/27/2008 1:57:59 PM | Attr = ] Linksys -> %ProgramFiles%\Linksys -> [Folder | Created Date = 6/26/2008 12:46:27 PM | Attr = ] SiteAdvisor -> %ProgramFiles%\SiteAdvisor -> [Folder | Created Date = 7/7/2008 8:42:31 PM | Attr = ] Trend Micro -> %ProgramFiles%\Trend Micro -> [Folder | Created Date = 7/8/2008 10:07:13 PM | Attr = ] UAV -> %ProgramFiles%\UAV -> [Folder | Created Date = 7/6/2008 9:57:48 PM | Attr = ] WAV -> %ProgramFiles%\WAV -> [Folder | Created Date = 7/6/2008 7:36:45 PM | Attr = ] Web Technologies -> %ProgramFiles%\Web Technologies -> [Folder | Created Date = 7/6/2008 6:27:09 PM | Attr = ] [Files/Folders - Modified Within 30 days] BEARWARE -> %SystemDrive%\BEARWARE -> [Folder | Modified Date = 6/20/2008 9:25:11 PM | Attr = ] Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 6/26/2008 12:46:31 PM | Attr = H ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 1005113344 bytes | Modified Date = 7/10/2008 2:56:13 PM | Attr = HS] mcafee_mcpr -> %SystemDrive%\mcafee_mcpr -> [Folder | Modified Date = 6/25/2008 6:08:05 PM | Attr = ] net_save.dna -> %SystemDrive%\net_save.dna -> [Ver = | Size = 1151 bytes | Modified Date = 6/25/2008 2:37:29 PM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 7/10/2008 3:29:13 PM | Attr = ] VETlog.dmp -> %SystemDrive%\VETlog.dmp -> [Ver = | Size = 56076 bytes | Modified Date = 7/10/2008 3:26:57 PM | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 7/10/2008 3:04:52 PM | Attr = ] 734914 -> %SystemRoot%\System32\734914 -> [Folder | Modified Date = 7/7/2008 8:48:41 PM | Attr = ] 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> CatRoot2 -> %SystemRoot%\System32\CatRoot2 -> [Folder | Modified Date = 7/10/2008 3:04:53 PM | Attr = ] config -> %SystemRoot%\System32\config -> [Folder | Modified Date = 6/23/2008 2:17:56 PM | Attr = ] Config.MPF -> %SystemRoot%\System32\Config.MPF -> [Ver = | Size = 9917 bytes | Modified Date = 7/10/2008 2:57:27 PM | Attr = ] dllcache -> %SystemRoot%\System32\dllcache -> [Folder | Modified Date = 7/8/2008 9:47:13 PM | Attr = RHS] drivers -> %SystemRoot%\System32\drivers -> [Folder | Modified Date = 7/8/2008 9:48:01 PM | Attr = ] FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [Ver = | Size = 469984 bytes | Modified Date = 6/30/2008 1:05:13 PM | Attr = ] FxsTmp -> %SystemRoot%\System32\FxsTmp -> [Folder | Modified Date = 7/10/2008 3:35:12 PM | Attr = ] hkushdr.dll -> %SystemRoot%\System32\hkushdr.dll -> [Ver = | Size = 13312 bytes | Modified Date = 7/4/2008 1:26:04 PM | Attr = S] ias -> %SystemRoot%\System32\ias -> [Folder | Modified Date = 6/25/2008 2:32:32 PM | Attr = ] MRT.INI -> %SystemRoot%\System32\MRT.INI -> [Ver = | Size = 118 bytes | Modified Date = 7/8/2008 8:24:32 PM | Attr = ] scui.cpl -> %SystemRoot%\System32\scui.cpl -> [Ver = | Size = 78336 bytes | Modified Date = 7/6/2008 9:55:45 PM | Attr = ] uav.cpl -> %SystemRoot%\System32\uav.cpl -> Ultimate Antivirus 2008 [Ver = 1, 0, 0, 1 | Size = 117248 bytes | Modified Date = 7/3/2008 10:54:35 AM | Attr = ] wav.cpl -> %SystemRoot%\System32\wav.cpl -> Windows Antivirus 2008 [Ver = 1, 0, 0, 1 | Size = 117248 bytes | Modified Date = 7/3/2008 10:40:12 AM | Attr = ] wbem -> %SystemRoot%\System32\wbem -> [Folder | Modified Date = 6/23/2008 2:17:26 PM | Attr = ] wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 7/10/2008 2:57:39 PM | Attr = ] hpsysdrv.DAT -> %SystemRoot%\System\hpsysdrv.DAT -> [Ver = | Size = 186 bytes | Modified Date = 7/10/2008 3:07:28 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 7/8/2008 2:35:33 PM | Attr = H ] 3DHOME.INI -> %SystemRoot%\3DHOME.INI -> [Ver = | Size = 461 bytes | Modified Date = 7/6/2008 7:24:26 PM | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 7/10/2008 2:56:15 PM | Attr = S] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 7/5/2008 7:07:09 PM | Attr = S] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 6/27/2008 2:02:30 PM | Attr = R S] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 7/6/2008 9:22:32 PM | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 6/26/2008 3:00:54 AM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 7/10/2008 3:05:07 PM | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 6/26/2008 12:46:31 PM | Attr = HS] LastGood -> %SystemRoot%\LastGood -> [Folder | Modified Date = 7/10/2008 3:04:52 PM | Attr = ] network diagnostic -> %SystemRoot%\network diagnostic -> [Folder | Modified Date = 6/22/2008 5:25:13 PM | Attr = ] popcinfo.dat -> %SystemRoot%\popcinfo.dat -> [Ver = | Size = 26 bytes | Modified Date = 6/20/2008 9:43:38 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 7/10/2008 3:32:37 PM | Attr = ] QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 7/1/2008 5:29:29 PM | Attr = ] QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 7/8/2008 4:06:05 PM | Attr = H ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 7/10/2008 2:57:12 PM | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 7/8/2008 3:02:12 PM | Attr = ] system32 -> %SystemRoot%\system32 -> [Folder | Modified Date = 7/10/2008 3:35:56 PM | Attr = ] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 7/7/2008 8:43:47 PM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 7/10/2008 3:32:36 PM | Attr = ] TLTitleData.ini -> %SystemRoot%\TLTitleData.ini -> [Ver = | Size = 2020 bytes | Modified Date = 6/27/2008 2:00:53 PM | Attr = ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 924 bytes | Modified Date = 7/10/2008 3:26:44 PM | Attr = ] Easy Internet Sign-up.job -> %SystemRoot%\tasks\Easy Internet Sign-up.job -> [Ver = | Size = 480 bytes | Modified Date = 6/25/2008 2:23:45 PM | Attr = ] McDefragTask.job -> %SystemRoot%\tasks\McDefragTask.job -> [Ver = | Size = 362 bytes | Modified Date = 7/7/2008 8:43:47 PM | Attr = ] McQcTask.job -> %SystemRoot%\tasks\McQcTask.job -> [Ver = | Size = 354 bytes | Modified Date = 7/7/2008 8:43:46 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 7/10/2008 2:56:17 PM | Attr = H ] C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [Folder | Modified Date = 11/10/2005 7:08:38 PM | Attr = ] qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [Ver = | Size = 5524 bytes | Modified Date = 7/10/2008 2:57:54 PM | Attr = ] qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [Ver = | Size = 5524 bytes | Modified Date = 7/10/2008 2:57:54 PM | Attr = ] C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [Folder | Modified Date = 12/6/2006 12:41:25 AM | Attr = ] opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [Ver = | Size = 8280 bytes | Modified Date = 12/6/2006 12:41:25 AM | Attr = ] C:\Documents and Settings\All Users\Application Data\Microsoft\Works\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works -> [Folder | Modified Date = 7/1/2008 9:43:22 PM | Attr = ] CalMRU.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\CalMRU.dat -> [Ver = | Size = 1036 bytes | Modified Date = 2/14/2008 5:29:25 PM | Attr = ] wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/11/2006 10:59:13 PM | Attr = ] wklntsk1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntsk1.dat -> [Ver = | Size = 166221 bytes | Modified Date = 2/11/2006 11:05:15 PM | Attr = ] C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~nsu.tmp\ -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~nsu.tmp\ -> [Folder | Modified Date = 7/10/2008 3:27:03 PM | Attr = ] Au_.exe -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\~nsu.tmp\Au_.exe -> AntiSpyCheck Software [Ver = 2.1.0.0 | Size = 37740 bytes | Modified Date = 7/6/2008 6:27:26 PM | Attr = ] C:\Documents and Settings\HP_Administrator\Local Settings\Temp\pdk-HP_Administrator\ -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\pdk-HP_Administrator -> [Folder | Modified Date = 7/6/2008 9:51:13 PM | Attr = ] 5fe6bfdd9ebfc4d9f299a7fecd62734f.dll -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\pdk-HP_Administrator\5fe6bfdd9ebfc4d9f299a7fecd62734f.dll -> [Ver = | Size = 90203 bytes | Modified Date = 5/1/2008 5:45:33 PM | Attr = R ] C:\Documents and Settings\HP_Administrator\Local Settings\Temp\ -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp -> [Folder | Modified Date = 7/10/2008 3:36:24 PM | Attr = ] Perflib_Perfdata_bc8.dat -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Perflib_Perfdata_bc8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/10/2008 2:59:27 PM | Attr = ] 3 C:\Documents and Settings\HP_Administrator\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\HP_Administrator\Local Settings\Temp\*.tmp -> C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [Folder | Modified Date = 7/10/2008 3:35:57 PM | Attr = ] Perflib_Perfdata_16c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_16c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/19/2007 11:28:31 PM | Attr = ] Perflib_Perfdata_184.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_184.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/20/2006 10:21:04 AM | Attr = ] Perflib_Perfdata_18c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_18c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/22/2008 4:19:08 PM | Attr = ] Perflib_Perfdata_1d8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_1d8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/12/2008 12:17:16 PM | Attr = ] Perflib_Perfdata_1f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_1f4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/1/2006 10:48:56 AM | Attr = ] Perflib_Perfdata_218.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_218.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/18/2008 5:58:21 PM | Attr = ] Perflib_Perfdata_220.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_220.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/29/2008 10:08:50 AM | Attr = ] Perflib_Perfdata_2a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_2a8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/19/2007 11:45:35 PM | Attr = ] Perflib_Perfdata_300.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_300.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/3/2008 9:46:15 AM | Attr = ] Perflib_Perfdata_33c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_33c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/8/2008 8:49:58 AM | Attr = ] Perflib_Perfdata_3ac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3ac.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/2/2006 10:50:09 AM | Attr = ] Perflib_Perfdata_3d0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_3d0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/3/2006 12:12:50 AM | Attr = ] Perflib_Perfdata_410.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_410.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/8/2008 11:47:09 PM | Attr = ] Perflib_Perfdata_424.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_424.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/25/2008 8:54:26 AM | Attr = ] Perflib_Perfdata_454.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_454.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/19/2007 11:41:58 PM | Attr = ] Perflib_Perfdata_478.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_478.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/19/2008 7:26:04 PM | Attr = ] Perflib_Perfdata_4d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_4d4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/28/2007 11:00:25 AM | Attr = ] Perflib_Perfdata_528.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_528.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/5/2008 10:08:57 AM | Attr = ] Perflib_Perfdata_544.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_544.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/23/2008 10:01:05 AM | Attr = ] Perflib_Perfdata_554.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_554.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/5/2008 2:55:58 PM | Attr = ] Perflib_Perfdata_570.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_570.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/24/2008 1:01:58 PM | Attr = ] Perflib_Perfdata_5e4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5e4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/8/2008 1:11:10 PM | Attr = ] Perflib_Perfdata_5f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_5f4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/15/2008 9:04:10 AM | Attr = ] Perflib_Perfdata_60c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_60c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/16/2008 10:16:35 AM | Attr = ] Perflib_Perfdata_63c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_63c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/21/2008 4:03:28 PM | Attr = ] Perflib_Perfdata_64c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_64c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/4/2008 5:56:07 PM | Attr = ] Perflib_Perfdata_684.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_684.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/22/2008 11:31:02 AM | Attr = ] Perflib_Perfdata_718.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_718.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/2/2008 8:43:04 PM | Attr = ] Perflib_Perfdata_744.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_744.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/21/2008 8:41:00 AM | Attr = ] Perflib_Perfdata_768.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_768.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/9/2008 5:48:13 AM | Attr = ] Perflib_Perfdata_7d4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7d4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/6/2008 2:39:17 PM | Attr = ] Perflib_Perfdata_7e8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7e8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/7/2008 8:51:53 PM | Attr = ] Perflib_Perfdata_7ec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7ec.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/5/2008 10:58:37 AM | Attr = ] Perflib_Perfdata_7f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7f0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/30/2008 12:32:29 PM | Attr = ] Perflib_Perfdata_7fc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_7fc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/18/2008 11:10:02 AM | Attr = ] Perflib_Perfdata_80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_80.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/11/2008 1:32:23 PM | Attr = ] Perflib_Perfdata_85c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_85c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/4/2008 2:16:32 PM | Attr = ] Perflib_Perfdata_870.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_870.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/6/2008 10:33:33 AM | Attr = ] Perflib_Perfdata_880.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_880.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/10/2007 1:00:43 AM | Attr = ] Perflib_Perfdata_890.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_890.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/2/2008 9:33:23 AM | Attr = ] Perflib_Perfdata_894.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_894.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/12/2008 12:24:35 PM | Attr = ] Perflib_Perfdata_898.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_898.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/22/2007 2:30:17 PM | Attr = ] Perflib_Perfdata_8c4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8c4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/13/2007 4:57:15 AM | Attr = ] Perflib_Perfdata_8d8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8d8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/17/2008 10:56:24 AM | Attr = ] Perflib_Perfdata_8f4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8f4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/24/2008 11:22:45 PM | Attr = ] Perflib_Perfdata_8fc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_8fc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/18/2008 11:50:34 AM | Attr = ] Perflib_Perfdata_92c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_92c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/24/2008 5:08:47 PM | Attr = ] Perflib_Perfdata_930.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_930.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/22/2008 5:55:20 PM | Attr = ] Perflib_Perfdata_934.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_934.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/19/2008 10:24:25 AM | Attr = ] Perflib_Perfdata_948.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_948.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/21/2008 10:20:03 AM | Attr = ] Perflib_Perfdata_96c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_96c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/7/2008 3:50:42 PM | Attr = ] Perflib_Perfdata_970.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_970.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/3/2008 12:07:57 PM | Attr = ] Perflib_Perfdata_974.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_974.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/26/2008 2:09:22 PM | Attr = ] Perflib_Perfdata_984.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_984.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/28/2007 12:27:41 PM | Attr = ] Perflib_Perfdata_98c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_98c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/5/2008 10:23:22 AM | Attr = ] Perflib_Perfdata_994.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_994.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/20/2007 7:04:05 PM | Attr = ] Perflib_Perfdata_9a8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9a8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/25/2007 6:25:55 AM | Attr = ] Perflib_Perfdata_9bc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9bc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/12/2007 12:51:40 AM | Attr = ] Perflib_Perfdata_9c0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9c0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/22/2007 10:12:22 AM | Attr = ] Perflib_Perfdata_9c8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9c8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/21/2007 12:09:55 AM | Attr = ] Perflib_Perfdata_9dc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9dc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/21/2007 1:44:05 AM | Attr = ] Perflib_Perfdata_9f0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_9f0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/8/2007 3:16:22 AM | Attr = ] Perflib_Perfdata_a08.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a08.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/16/2007 5:08:25 AM | Attr = ] Perflib_Perfdata_a1c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a1c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/17/2007 6:19:04 PM | Attr = ] Perflib_Perfdata_a20.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a20.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/18/2007 9:02:59 PM | Attr = ] Perflib_Perfdata_a24.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a24.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/23/2008 11:55:34 AM | Attr = ] Perflib_Perfdata_a28.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a28.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/20/2007 12:49:20 AM | Attr = ] Perflib_Perfdata_a2c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a2c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/30/2007 1:01:41 PM | Attr = ] Perflib_Perfdata_a34.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a34.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/15/2007 10:57:11 AM | Attr = ] Perflib_Perfdata_a38.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a38.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/30/2007 10:37:46 AM | Attr = ] Perflib_Perfdata_a40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a40.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/21/2007 3:02:56 PM | Attr = ] Perflib_Perfdata_a44.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a44.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/13/2007 9:58:09 AM | Attr = ] Perflib_Perfdata_a58.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a58.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/1/2008 10:10:12 AM | Attr = ] Perflib_Perfdata_a68.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a68.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/11/2007 7:52:02 PM | Attr = ] Perflib_Perfdata_a74.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a74.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/8/2008 8:29:54 PM | Attr = ] Perflib_Perfdata_a78.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a78.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/31/2007 11:14:29 PM | Attr = ] Perflib_Perfdata_a80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a80.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/8/2008 8:17:50 PM | Attr = ] Perflib_Perfdata_a84.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a84.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/29/2007 5:49:59 PM | Attr = ] Perflib_Perfdata_a88.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a88.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/14/2007 11:08:53 PM | Attr = ] Perflib_Perfdata_a94.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_a94.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/2/2007 1:49:08 AM | Attr = ] Perflib_Perfdata_aa0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_aa0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/3/2007 8:42:39 PM | Attr = ] Perflib_Perfdata_aa8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_aa8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/2/2007 2:48:55 PM | Attr = ] Perflib_Perfdata_ac0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ac0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/14/2007 7:06:13 AM | Attr = ] Perflib_Perfdata_adc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_adc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/15/2007 12:23:28 PM | Attr = ] Perflib_Perfdata_ae8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ae8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/23/2007 6:51:59 PM | Attr = ] Perflib_Perfdata_aec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_aec.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/4/2008 6:00:11 PM | Attr = ] Perflib_Perfdata_af0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_af0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/19/2007 12:50:42 AM | Attr = ] Perflib_Perfdata_af4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_af4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/3/2007 4:13:29 AM | Attr = ] Perflib_Perfdata_b00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b00.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/25/2007 1:02:51 AM | Attr = ] Perflib_Perfdata_b20.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b20.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/19/2007 2:37:44 PM | Attr = ] Perflib_Perfdata_b30.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b30.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/26/2008 4:31:27 PM | Attr = ] Perflib_Perfdata_b34.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b34.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/10/2005 7:49:14 PM | Attr = ] Perflib_Perfdata_b3c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b3c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/21/2008 11:28:59 AM | Attr = ] Perflib_Perfdata_b40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b40.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/29/2007 3:41:46 PM | Attr = ] Perflib_Perfdata_b44.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b44.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/17/2007 3:04:01 PM | Attr = ] Perflib_Perfdata_b4c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b4c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/30/2007 1:11:53 AM | Attr = ] Perflib_Perfdata_b54.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b54.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/29/2007 12:54:23 AM | Attr = ] Perflib_Perfdata_b58.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b58.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/10/2005 8:02:01 PM | Attr = ] Perflib_Perfdata_b5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b5c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/14/2006 5:43:53 PM | Attr = ] Perflib_Perfdata_b6c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b6c.dat -> [Ver = | Size = 0 bytes | Modified Date = 7/10/2008 2:57:27 PM | Attr = ] Perflib_Perfdata_b8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/30/2008 3:02:17 PM | Attr = ] Perflib_Perfdata_b80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b80.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/10/2005 7:30:17 PM | Attr = ] Perflib_Perfdata_b84.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b84.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/13/2006 2:31:41 AM | Attr = ] Perflib_Perfdata_b98.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_b98.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/26/2007 10:06:29 AM | Attr = ] Perflib_Perfdata_ba4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ba4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/12/2007 9:45:06 PM | Attr = ] Perflib_Perfdata_bb4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bb4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/27/2007 10:29:13 PM | Attr = ] Perflib_Perfdata_bb8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bb8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/28/2006 8:10:29 PM | Attr = ] Perflib_Perfdata_bd0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bd0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/16/2008 10:12:09 AM | Attr = ] Perflib_Perfdata_bd4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bd4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/11/2008 9:14:33 AM | Attr = ] Perflib_Perfdata_be0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_be0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/12/2007 5:22:07 AM | Attr = ] Perflib_Perfdata_bec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bec.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/8/2006 11:21:48 PM | Attr = ] Perflib_Perfdata_bf0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_bf0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/23/2007 2:19:17 AM | Attr = ] Perflib_Perfdata_c00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c00.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/28/2007 12:36:14 PM | Attr = ] Perflib_Perfdata_c04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c04.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/6/2006 2:35:04 PM | Attr = ] Perflib_Perfdata_c08.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c08.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/25/2008 1:16:39 PM | Attr = ] Perflib_Perfdata_c0c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c0c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/28/2007 11:00:29 AM | Attr = ] Perflib_Perfdata_c18.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c18.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/24/2008 2:58:21 PM | Attr = ] Perflib_Perfdata_c1c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c1c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/12/2007 4:45:41 PM | Attr = ] Perflib_Perfdata_c2c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c2c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/10/2007 4:29:17 PM | Attr = ] Perflib_Perfdata_c3c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c3c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/26/2008 12:35:35 PM | Attr = ] Perflib_Perfdata_c40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c40.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/23/2008 2:20:41 PM | Attr = ] Perflib_Perfdata_c44.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c44.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/11/2008 12:15:35 PM | Attr = ] Perflib_Perfdata_c4c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c4c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/19/2007 12:55:27 PM | Attr = ] Perflib_Perfdata_c50.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c50.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/16/2006 9:17:29 AM | Attr = ] Perflib_Perfdata_c5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c5c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/28/2008 9:30:35 AM | Attr = ] Perflib_Perfdata_c60.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c60.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/24/2007 8:47:31 AM | Attr = ] Perflib_Perfdata_c68.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c68.dat -> [Ver = | Size = 16384 bytes | Modified Date = 12/20/2007 10:56:39 AM | Attr = ] Perflib_Perfdata_c6c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c6c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/12/2006 11:06:47 AM | Attr = ] Perflib_Perfdata_c70.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c70.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/26/2008 10:58:11 PM | Attr = ] Perflib_Perfdata_c78.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c78.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/9/2007 12:49:17 PM | Attr = ] Perflib_Perfdata_c80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c80.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/22/2007 10:56:21 AM | Attr = ] Perflib_Perfdata_c88.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c88.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/1/2007 12:51:05 PM | Attr = ] Perflib_Perfdata_c90.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c90.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/11/2006 6:34:05 PM | Attr = ] Perflib_Perfdata_c94.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c94.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/14/2006 3:03:56 AM | Attr = ] Perflib_Perfdata_c98.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c98.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/3/2007 8:45:00 AM | Attr = ] Perflib_Perfdata_c9c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_c9c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/14/2008 10:12:16 AM | Attr = ] Perflib_Perfdata_ca0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ca0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/17/2006 11:43:38 AM | Attr = ] Perflib_Perfdata_ca8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ca8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/5/2008 9:31:19 PM | Attr = ] Perflib_Perfdata_cac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cac.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/22/2006 9:37:06 PM | Attr = ] Perflib_Perfdata_cb0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cb0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/16/2007 2:17:31 PM | Attr = ] Perflib_Perfdata_cb4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cb4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/11/2006 6:34:09 PM | Attr = ] Perflib_Perfdata_cb8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cb8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/28/2006 10:41:52 PM | Attr = ] Perflib_Perfdata_cbc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cbc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/22/2007 2:37:20 PM | Attr = ] Perflib_Perfdata_cc4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cc4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/21/2008 8:14:14 PM | Attr = ] Perflib_Perfdata_cc8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cc8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/24/2008 11:01:36 PM | Attr = ] Perflib_Perfdata_cd0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cd0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/16/2006 11:04:54 PM | Attr = ] Perflib_Perfdata_cd8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cd8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/10/2007 6:47:00 PM | Attr = ] Perflib_Perfdata_ce0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ce0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/24/2006 2:52:50 PM | Attr = ] Perflib_Perfdata_cf0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cf0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/24/2007 9:35:17 AM | Attr = ] Perflib_Perfdata_cf4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cf4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/31/2007 1:00:57 PM | Attr = ] Perflib_Perfdata_cf8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_cf8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/26/2008 2:17:51 PM | Attr = ] Perflib_Perfdata_d00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d00.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/5/2008 2:48:42 PM | Attr = ] Perflib_Perfdata_d04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d04.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/14/2006 1:48:59 PM | Attr = ] Perflib_Perfdata_d18.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d18.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/14/2006 8:03:20 AM | Attr = ] Perflib_Perfdata_d1c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d1c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/1/2007 3:52:50 PM | Attr = ] Perflib_Perfdata_d20.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d20.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/17/2006 11:51:13 AM | Attr = ] Perflib_Perfdata_d28.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d28.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/2/2006 2:05:53 AM | Attr = ] Perflib_Perfdata_d2c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d2c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/25/2006 5:09:24 AM | Attr = ] Perflib_Perfdata_d30.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d30.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/8/2007 5:48:31 PM | Attr = ] Perflib_Perfdata_d34.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d34.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/23/2008 12:25:09 PM | Attr = ] Perflib_Perfdata_d3c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d3c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/13/2007 4:52:05 PM | Attr = ] Perflib_Perfdata_d40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d40.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/16/2006 10:39:58 AM | Attr = ] Perflib_Perfdata_d44.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d44.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/23/2006 7:02:05 AM | Attr = ] Perflib_Perfdata_d4c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d4c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/6/2006 1:37:30 AM | Attr = ] Perflib_Perfdata_d50.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d50.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/16/2006 5:59:32 AM | Attr = ] Perflib_Perfdata_d54.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d54.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/30/2008 12:31:09 PM | Attr = ] Perflib_Perfdata_d58.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d58.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/22/2006 11:58:23 PM | Attr = ] Perflib_Perfdata_d64.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d64.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/11/2008 9:22:30 AM | Attr = ] Perflib_Perfdata_d68.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d68.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/26/2007 9:59:50 AM | Attr = ] Perflib_Perfdata_d70.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d70.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/31/2006 8:10:06 AM | Attr = ] Perflib_Perfdata_d74.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d74.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/22/2008 12:53:05 PM | Attr = ] Perflib_Perfdata_d78.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d78.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/22/2007 1:59:10 AM | Attr = ] Perflib_Perfdata_d80.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d80.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/18/2006 11:31:46 AM | Attr = ] Perflib_Perfdata_d84.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d84.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/20/2006 3:52:21 PM | Attr = ] Perflib_Perfdata_d88.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d88.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/10/2006 10:45:33 PM | Attr = ] Perflib_Perfdata_d8c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d8c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/4/2006 10:51:02 AM | Attr = ] Perflib_Perfdata_d94.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d94.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/20/2006 9:22:52 PM | Attr = ] Perflib_Perfdata_d98.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d98.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/11/2008 12:19:03 PM | Attr = ] Perflib_Perfdata_d9c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_d9c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/13/2006 9:06:59 AM | Attr = ] Perflib_Perfdata_da0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_da0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/13/2006 4:12:24 PM | Attr = ] Perflib_Perfdata_da4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_da4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/7/2006 8:22:37 AM | Attr = ] Perflib_Perfdata_da8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_da8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/30/2006 4:46:04 AM | Attr = ] Perflib_Perfdata_db8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_db8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/23/2007 2:41:34 PM | Attr = ] Perflib_Perfdata_dbc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dbc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/28/2006 5:24:28 AM | Attr = ] Perflib_Perfdata_dc0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dc0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/28/2007 1:13:56 PM | Attr = ] Perflib_Perfdata_dcc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dcc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/19/2006 5:03:58 AM | Attr = ] Perflib_Perfdata_dd4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dd4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/29/2006 11:21:42 AM | Attr = ] Perflib_Perfdata_dd8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dd8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/25/2007 11:21:34 AM | Attr = ] Perflib_Perfdata_ddc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ddc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/29/2008 4:37:55 PM | Attr = ] Perflib_Perfdata_de4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_de4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/15/2006 2:35:05 PM | Attr = ] Perflib_Perfdata_dec.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dec.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/21/2007 4:33:16 PM | Attr = ] Perflib_Perfdata_df0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_df0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/23/2008 4:58:23 PM | Attr = ] Perflib_Perfdata_df4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_df4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/18/2006 3:50:37 AM | Attr = ] Perflib_Perfdata_df8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_df8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/22/2006 6:15:23 AM | Attr = ] Perflib_Perfdata_dfc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_dfc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/9/2006 3:44:32 AM | Attr = ] Perflib_Perfdata_e00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e00.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/22/2006 7:42:16 PM | Attr = ] Perflib_Perfdata_e04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e04.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/20/2006 11:42:28 AM | Attr = ] Perflib_Perfdata_e08.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e08.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/2/2006 8:03:22 PM | Attr = ] Perflib_Perfdata_e14.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e14.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/27/2006 9:16:09 AM | Attr = ] Perflib_Perfdata_e18.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e18.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/12/2006 5:03:23 AM | Attr = ] Perflib_Perfdata_e20.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e20.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/30/2007 9:28:44 PM | Attr = ] Perflib_Perfdata_e24.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e24.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/20/2007 10:05:05 AM | Attr = ] Perflib_Perfdata_e2c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e2c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/15/2006 11:32:02 AM | Attr = ] Perflib_Perfdata_e30.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e30.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/23/2006 2:22:00 AM | Attr = ] Perflib_Perfdata_e34.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e34.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/27/2006 12:32:24 AM | Attr = ] Perflib_Perfdata_e38.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e38.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/20/2008 5:31:48 PM | Attr = ] Perflib_Perfdata_e40.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e40.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/24/2006 9:37:08 PM | Attr = ] Perflib_Perfdata_e44.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e44.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/27/2007 3:23:46 PM | Attr = ] Perflib_Perfdata_e48.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e48.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/15/2006 7:49:10 AM | Attr = ] Perflib_Perfdata_e50.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e50.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/23/2006 11:32:03 AM | Attr = ] Perflib_Perfdata_e54.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e54.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/24/2006 12:01:49 AM | Attr = ] Perflib_Perfdata_e58.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e58.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/23/2006 5:16:26 PM | Attr = ] Perflib_Perfdata_e5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e5c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/16/2006 6:44:52 PM | Attr = ] Perflib_Perfdata_e60.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e60.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/23/2007 6:36:53 PM | Attr = ] Perflib_Perfdata_e64.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e64.dat -> [Ver = | Size = 16384 bytes | Modified Date = 5/4/2008 8:39:09 AM | Attr = ] Perflib_Perfdata_e68.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e68.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/27/2006 3:09:07 AM | Attr = ] Perflib_Perfdata_e6c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e6c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/23/2006 7:07:54 AM | Attr = ] Perflib_Perfdata_e78.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e78.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/16/2008 10:20:50 AM | Attr = ] Perflib_Perfdata_e7c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e7c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/10/2006 5:03:06 PM | Attr = ] Perflib_Perfdata_e8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/18/2006 4:14:44 PM | Attr = ] Perflib_Perfdata_e84.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e84.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/20/2008 12:56:11 PM | Attr = ] Perflib_Perfdata_e88.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e88.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/14/2006 2:07:58 AM | Attr = ] Perflib_Perfdata_e8c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e8c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/8/2006 11:23:55 AM | Attr = ] Perflib_Perfdata_e90.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e90.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/1/2006 9:11:28 AM | Attr = ] Perflib_Perfdata_e98.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_e98.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/24/2007 9:38:26 PM | Attr = ] Perflib_Perfdata_ea0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ea0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/3/2006 1:34:31 AM | Attr = ] Perflib_Perfdata_eac.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_eac.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/3/2006 12:54:38 AM | Attr = ] Perflib_Perfdata_eb0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_eb0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/16/2007 9:11:16 AM | Attr = ] Perflib_Perfdata_eb4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_eb4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/29/2006 7:03:53 PM | Attr = ] Perflib_Perfdata_ebc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ebc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/17/2006 5:40:45 PM | Attr = ] Perflib_Perfdata_ec0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ec0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/21/2008 1:00:56 PM | Attr = ] Perflib_Perfdata_ec4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ec4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/28/2006 9:01:04 AM | Attr = ] Perflib_Perfdata_ecc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ecc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 6/5/2008 12:03:31 PM | Attr = ] Perflib_Perfdata_ed0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ed0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/8/2007 6:07:11 AM | Attr = ] Perflib_Perfdata_ed4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ed4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/8/2007 4:48:19 PM | Attr = ] Perflib_Perfdata_ed8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ed8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/3/2006 7:23:31 AM | Attr = ] Perflib_Perfdata_edc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_edc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/16/2006 6:59:19 PM | Attr = ] Perflib_Perfdata_ef4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ef4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 10/10/2007 11:41:09 AM | Attr = ] Perflib_Perfdata_ef8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ef8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 12/26/2007 4:09:17 PM | Attr = ] Perflib_Perfdata_f00.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f00.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/14/2007 4:25:03 PM | Attr = ] Perflib_Perfdata_f04.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f04.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/16/2008 3:47:48 PM | Attr = ] Perflib_Perfdata_f28.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f28.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/10/2005 8:09:12 PM | Attr = ] Perflib_Perfdata_f2c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f2c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/13/2006 4:07:43 PM | Attr = ] Perflib_Perfdata_f30.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f30.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/3/2006 4:32:30 AM | Attr = ] Perflib_Perfdata_f34.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f34.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/5/2006 7:17:41 AM | Attr = ] Perflib_Perfdata_f3c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f3c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/19/2008 3:17:22 PM | Attr = ] Perflib_Perfdata_f4c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f4c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 12/8/2007 11:56:52 AM | Attr = ] Perflib_Perfdata_f54.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f54.dat -> [Ver = | Size = 16384 bytes | Modified Date = 9/8/2007 5:40:50 PM | Attr = ] Perflib_Perfdata_f5c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f5c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/10/2008 10:55:06 AM | Attr = ] Perflib_Perfdata_f70.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f70.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/23/2007 7:09:41 PM | Attr = ] Perflib_Perfdata_f7c.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f7c.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/21/2008 6:42:06 PM | Attr = ] Perflib_Perfdata_f84.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f84.dat -> [Ver = | Size = 16384 bytes | Modified Date = 12/31/2007 4:32:50 PM | Attr = ] Perflib_Perfdata_f88.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f88.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/3/2008 4:04:05 PM | Attr = ] Perflib_Perfdata_f98.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_f98.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/15/2006 11:13:38 PM | Attr = ] Perflib_Perfdata_fa4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fa4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 8/27/2007 3:18:51 PM | Attr = ] Perflib_Perfdata_fa8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fa8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 7/4/2008 8:48:52 AM | Attr = ] Perflib_Perfdata_fb8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fb8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 1/15/2008 11:35:58 AM | Attr = ] Perflib_Perfdata_fc0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fc0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/15/2007 11:39:39 AM | Attr = ] Perflib_Perfdata_fc8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fc8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/1/2008 5:38:07 PM | Attr = ] Perflib_Perfdata_fcc.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fcc.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/3/2006 8:49:08 AM | Attr = ] Perflib_Perfdata_fd8.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fd8.dat -> [Ver = | Size = 16384 bytes | Modified Date = 4/20/2006 4:44:57 AM | Attr = ] Perflib_Perfdata_fe4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_fe4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 3/2/2006 4:20:43 AM | Attr = ] Perflib_Perfdata_ff0.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ff0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/30/2007 11:05:33 PM | Attr = ] Perflib_Perfdata_ff4.dat -> C:\WINDOWS\Temp\Perflib_Perfdata_ff4.dat -> [Ver = | Size = 16384 bytes | Modified Date = 11/14/2007 10:00:05 AM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat -> [Ver = | Size = 16384 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = ] C:\WINDOWS\Temp\ -> C:\WINDOWS\Temp -> [Folder | Modified Date = 7/10/2008 3:35:57 PM | Attr = ] sdpintl.ini -> C:\WINDOWS\Temp\sdpintl.ini -> [Ver = | Size = 0 bytes | Modified Date = 2/10/2006 4:59:27 PM | Attr = ] 3 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\ -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\2X2R2NYT\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\2X2R2NYT -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\2X2R2NYT\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\61KN236P\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\61KN236P -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\61KN236P\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CV4N8ZYB\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CV4N8ZYB -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CV4N8ZYB\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = HS] C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SFWVSL0B\ -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SFWVSL0B -> [Folder | Modified Date = 2/10/2006 4:58:17 PM | Attr = S] desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\SFWVSL0B\desktop.ini -> [Ver = | Size = 67 bytes | Modified Date = 2/10/2006 4:58:17 PM | Attr = HS] [Files Modified - Additional Folder Scans - Non-Microsoft Only] AOL Downloads -> %AllUsersProfile%\Application Data\AOL Downloads -> [Folder | Modified Date = 7/8/2008 9:58:50 PM | Attr = ] Google Updater -> %AllUsersProfile%\Application Data\Google Updater -> [Folder | Modified Date = 7/10/2008 3:09:40 PM | Attr = ] Linksys -> %AllUsersProfile%\Application Data\Linksys -> [Folder | Modified Date = 6/28/2008 12:50:56 PM | Attr = ] McAfee -> %AllUsersProfile%\Application Data\McAfee -> [Folder | Modified Date = 7/7/2008 8:44:01 PM | Attr = ] McAfee.com -> %AllUsersProfile%\Application Data\McAfee.com -> [Folder | Modified Date = 6/23/2008 2:16:28 PM | Attr = ] PopCap -> %AllUsersProfile%\Application Data\PopCap -> [Folder | Modified Date = 7/5/2008 7:07:25 PM | Attr = ] QTSBandwidthCache -> %AllUsersProfile%\Application Data\QTSBandwidthCache -> [Ver = | Size = 1376 bytes | Modified Date = 7/6/2008 4:09:32 PM | Attr = ] SiteAdvisor -> %AllUsersProfile%\Application Data\SiteAdvisor -> [Folder | Modified Date = 7/7/2008 8:42:40 PM | Attr = ] TEMP -> %AllUsersProfile%\Application Data\TEMP -> [Folder | Modified Date = 7/8/2008 10:08:23 PM | Attr = ] @Alternate Data Stream - 107 bytes -> %AllUsersProfile%\Application Data\TEMP:B894C266 @Alternate Data Stream - 117 bytes -> %AllUsersProfile%\Application Data\TEMP:F085C8A1 McAfee.com Personal Firewall -> %AppData%\McAfee.com Personal Firewall -> [Folder | Modified Date = 6/23/2008 2:16:41 PM | Attr = ] Mozilla -> %AppData%\Mozilla -> [Folder | Modified Date = 7/6/2008 9:47:49 PM | Attr = ] SiteAdvisor -> %AppData%\SiteAdvisor -> [Folder | Modified Date = 7/8/2008 8:13:00 PM | Attr = ] wklnhst.dat -> %AppData%\wklnhst.dat -> [Ver = | Size = 5768 bytes | Modified Date = 7/4/2008 10:05:29 PM | Attr = ] ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory -> [Folder | Modified Date = 7/8/2008 9:39:07 PM | Attr = ] DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [Ver = | Size = 120832 bytes | Modified Date = 6/27/2008 2:10:15 PM | Attr = ] IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [Ver = | Size = 3176818 bytes | Modified Date = 7/8/2008 9:46:24 PM | Attr = H ] Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft -> [Folder | Modified Date = 7/10/2008 3:19:43 PM | Attr = ] SupportSoft -> %UserProfile%\Local Settings\Application Data\SupportSoft -> [Folder | Modified Date = 6/25/2008 1:46:08 PM | Attr = ] ATF-Cleaner.exe -> %UserProfile%\My Documents\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 7/10/2008 3:31:05 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\ATF-Cleaner.exe:Zone.Identifier downloadable_install_wizard.exe -> %UserProfile%\My Documents\downloadable_install_wizard.exe -> Comcast Cable Communications, LLC [Ver = 5.0.1.1 | Size = 3889824 bytes | Modified Date = 6/25/2008 2:37:20 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\downloadable_install_wizard.exe:Zone.Identifier God's gift.wps -> %UserProfile%\My Documents\God's gift.wps -> [Ver = | Size = 23040 bytes | Modified Date = 7/4/2008 10:05:29 PM | Attr = ] HJTInstall.exe -> %UserProfile%\My Documents\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 7/8/2008 10:05:52 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\HJTInstall.exe:Zone.Identifier Misty.wps -> %UserProfile%\My Documents\Misty.wps -> [Ver = | Size = 11264 bytes | Modified Date = 6/26/2008 7:49:31 PM | Attr = ] My Documents.url -> %UserProfile%\My Documents\My Documents.url -> [Ver = | Size = 140 bytes | Modified Date = 7/6/2008 6:27:22 PM | Attr = ] My Music -> %UserProfile%\My Documents\My Music -> [Folder | Modified Date = 7/6/2008 6:27:22 PM | Attr = R ] My Videos -> %UserProfile%\My Documents\My Videos -> [Folder | Modified Date = 7/6/2008 6:27:22 PM | Attr = R ] MySpaceIM Pics -> %UserProfile%\My Documents\MySpaceIM Pics -> [Folder | Modified Date = 6/13/2008 5:17:17 PM | Attr = ] OTScanIt -> %UserProfile%\My Documents\OTScanIt -> [Folder | Modified Date = 7/10/2008 3:33:46 PM | Attr = ] OTScanIt.exe -> %UserProfile%\My Documents\OTScanIt.exe -> [Ver = | Size = 568114 bytes | Modified Date = 7/10/2008 3:33:17 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\OTScanIt.exe:Zone.Identifier spybotsd160.exe -> %UserProfile%\My Documents\spybotsd160.exe -> Safer Networking Limited [Ver = 1.6.0 | Size = 15083520 bytes | Modified Date = 7/8/2008 10:11:26 PM | Attr = ] @Alternate Data Stream - 26 bytes -> %UserProfile%\My Documents\spybotsd160.exe:Zone.Identifier The race 046.jpg -> %UserProfile%\My Documents\The race 046.jpg -> [Ver = | Size = 550849 bytes | Modified Date = 6/12/2008 1:43:14 PM | Attr = ] Thumbs.db -> %UserProfile%\My Documents\Thumbs.db -> [Ver = | Size = 337408 bytes | Modified Date = 6/23/2008 6:17:13 PM | Attr = HS] @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable Antivirus Scan.url -> %AllUsersProfile%\Desktop\Antivirus Scan.url -> [Ver = | Size = 135 bytes | Modified Date = 7/6/2008 6:27:22 PM | Attr = ] AOL Computer Check-Up.lnk -> %AllUsersProfile%\Desktop\AOL Computer Check-Up.lnk -> [Ver = | Size = 1979 bytes | Modified Date = 7/8/2008 10:01:31 PM | Attr = ] AOL Explorer Browser.lnk -> %AllUsersProfile%\Desktop\AOL Explorer Browser.lnk -> [Ver = | Size = 1814 bytes | Modified Date = 6/25/2008 1:45:31 PM | Attr = ] Berlitz Learning System.lnk -> %AllUsersProfile%\Desktop\Berlitz Learning System.lnk -> [Ver = | Size = 1769 bytes | Modified Date = 6/27/2008 2:06:06 PM | Attr = ] McAfee Easy Network.lnk -> %AllUsersProfile%\Desktop\McAfee Easy Network.lnk -> [Ver = | Size = 677 bytes | Modified Date = 7/7/2008 8:43:49 PM | Attr = ] Online Spyware Test.url -> %AllUsersProfile%\Desktop\Online Spyware Test.url -> [Ver = | Size = 135 bytes | Modified Date = 7/6/2008 6:27:22 PM | Attr = ] Antivirus 2009.lnk -> %UserProfile%\Desktop\Antivirus 2009.lnk -> [Ver = | Size = 755 bytes | Modified Date = 7/6/2008 9:55:45 PM | Attr = ] HijackThis.lnk -> %UserProfile%\Desktop\HijackThis.lnk -> [Ver = | Size = 1745 bytes | Modified Date = 7/8/2008 10:07:14 PM | Attr = ] Ultimate Antivirus 2008.lnk -> %UserProfile%\Desktop\Ultimate Antivirus 2008.lnk -> [Ver = | Size = 669 bytes | Modified Date = 7/8/2008 1:41:49 PM | Attr = ] Windows Antivirus 2008.lnk -> %UserProfile%\Desktop\Windows Antivirus 2008.lnk -> [Ver = | Size = 667 bytes | Modified Date = 7/8/2008 3:49:16 PM | Attr = ] AOL -> %CommonProgramFiles%\AOL -> [Folder | Modified Date = 7/8/2008 10:01:15 PM | Attr = ] McAfee -> %CommonProgramFiles%\McAfee -> [Folder | Modified Date = 7/7/2008 8:41:10 PM | Attr = ] SupportSoft -> %CommonProgramFiles%\SupportSoft -> [Folder | Modified Date = 6/25/2008 1:46:06 PM | Attr = ] < End of report > [/code]