Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hjt Logfile - I Don't Know What Kind Of Infection It Is.


  • Please log in to reply
14 replies to this topic

#1 kellydoz

kellydoz

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 05 February 2008 - 06:22 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:09:57 PM, on 2/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\WINDOWS\system32\ntvdm.exe
C:\VSTASCAN\vsaccess.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~2.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [64541f71] rundll32.exe "C:\WINDOWS\system32\lpqqyhbs.dll",b
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\10.0.368.0\Weather.exe" -auto
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...81/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1162985822921
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,19/mcgdmgr.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 10179 bytes

BC AdBot (Login to Remove)

 


#2 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 05 February 2008 - 08:17 PM

I keep getting this pop-up message.

Microsoft Visual C++ Runtime Library

Buffer overrun detected

Program: C:\WINDOWS\explorer.exe

a buffer overrun has been detected which has corrupted the program's internal state. The program cannot safely continue execution and must now be terminated.


***McAfee just IDed Vundo and Generic.dx today. It claims to have deleted Generic.dx but I don't trust it. I still have the original virus that it found that it called New Malware.bx.

Edited by kellydoz, 06 February 2008 - 06:28 PM.


#3 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 11 February 2008 - 01:36 PM

Hello kellydoz and welcome to the BC HijackThis forum. Let's try a different scanner and see what it shows us.

Before running the scan let's clean out the temporoary folders.

Download ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now download WinPFind35u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind35U.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].

If, after posting, the last line is not /code with brackets around it then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#4 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 11 February 2008 - 03:13 PM

WinPFind35 logfile created on: 2/11/2008 1:58:11 PM

WinPFind35U Version Beta49	 Folder = C:\Documents and Settings\Kelly\Desktop\WinPFind35u

Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 7.0.5730.11)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

254.00 Mb Total Physical Memory | 28.09 Mb Available Physical Memory | 11.06% Memory free

641.04 Mb Paging File | 185.32 Mb Available in Paging File | 28.91% Paging File free

Paging file location(s): C:\pagefile.sys 384 768;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 38.25 Gb Total Space | 22.72 Gb Free Space | 59.41% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded



Computer Name: MACK

Current User Name: Kelly

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user



[Processes - Non-Microsoft Only]

aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]

acsd.exe -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]

applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]

mcdetect.exe -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]

mctskshd.exe -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]

ncupdatesvc.exe -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]

mm_tray.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

tgcmd.exe -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]

mcvsshld.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]

bcmsmmsg.exe -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]

mcvsescn.exe -> %ProgramFiles%\McAfee.com\VSO\McVSEscn.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 483328 bytes | Modified Date = 7/8/2005 5:16:16 PM | Attr =	]

mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]

mmtask.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

hpwuschd.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]

hpcmpmgr.exe -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]

ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]

ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]

hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]

pi monitor.exe -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]

ocrawr32.exe -> %SystemDrive%\OPLIMIT\OCRAWR32.EXE -> Caere Corporation [Ver = 5, 0, 0, 1 | Size = 41984 bytes | Modified Date = 3/19/1998 2:22:02 PM | Attr =	]

mm_tray.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

tgcmd.exe -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]

mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]

mcvsshld.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]

bcmsmmsg.exe -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]

mmtask.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

hpwuschd.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]

mcvsescn.exe -> %ProgramFiles%\McAfee.com\VSO\McVSEscn.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 483328 bytes | Modified Date = 7/8/2005 5:16:16 PM | Attr =	]

ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]

dsagnt.exe -> %ProgramFiles%\DellSupport\DSAgnt.exe -> Gteko Ltd. [Ver = 3, 0, 0, 197 | Size = 460784 bytes | Modified Date = 3/15/2007 10:09:36 AM | Attr =	]

sprtcmd.exe -> %ProgramFiles%\Dell Support Center\bin\sprtcmd.exe -> SupportSoft, Inc. [Ver = 7.0.585.0 | Size = 202544 bytes | Modified Date = 11/15/2007 9:23:56 AM | Attr =	]

hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]

mcmnhdlr.exe -> %ProgramFiles%\McAfee.com\VSO\mcmnhdlr.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 151552 bytes | Modified Date = 7/8/2005 5:18:22 PM | Attr =	]

mcshield.exe -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]

oasclnt.exe -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]

oasclnt.exe -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]

yahoomessenger.exe -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 9:49:04 PM | Attr =	]

realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]

realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]

winpfind35u.exe -> %UserDesktop%\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 310272 bytes | Modified Date = 2/10/2008 1:10:14 PM | Attr =	]



[Win32 Services - Non-Microsoft Only]

(aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]

(AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]

(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]

(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 1:56:48 AM | Attr =	]

(DSBrokerService) DSBrokerService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\brkrsvc.exe ->  [Ver = 1, 0, 0, 8 | Size = 76848 bytes | Modified Date = 3/7/2007 2:47:46 PM | Attr =	]

(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr =	]

(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]

(McDetect.exe) McAfee WSC Integration [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]

(McShield) McAfee.com McShield [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]

(McTskshd.exe) McAfee Task Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]

(mcupdmgr.exe) McAfee SecurityCenter Update Manager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee.com\Agent\mcupdmgr.exe -> McAfee, Inc [Ver = 6, 0, 0, 4 | Size = 245760 bytes | Modified Date = 7/1/2005 6:22:50 PM | Attr =	]

(NCUpdateSvc) Netscape Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]

(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Stopped] -> %System32%\HPZipm12.exe -> HP [Ver = 7, 0, 0, 0 | Size = 65795 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]



[Driver Services - Non-Microsoft Only]

(Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] ->  -> File not found

(aeaudio) aeaudio [Kernel | On_Demand | Running] -> %System32%\DRIVERS\aeaudio.sys -> Andrea Electronics Corporation [Ver = 1.0.0.2 (STUB) | Size = 4816 bytes | Modified Date = 4/1/2002 1:15:00 PM | Attr =	]

(AFS2K) AFS2K [Kernel | System | Running] -> %System32%\DRIVERS\AFS2K.SYS -> Oak Technology Inc. [Ver = 3.1.21.1103 | Size = 35840 bytes | Modified Date = 10/7/2004 7:16:04 PM | Attr =	]

(AliIde) AliIde [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\ALIIDE.SYS -> Acer Laboratories Inc. [Ver = 1.20 | Size = 5248 bytes | Modified Date = 8/17/2001 1:51:56 PM | Attr =	]

(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\amdagp.sys -> Advanced Micro Devices, Inc. [Ver = 5.00 (xpsp_sp2_rtm.040803-2158) | Size = 43008 bytes | Modified Date = 8/4/2004 12:07:42 AM | Attr =	]

(asc) asc [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\ASC.SYS -> Advanced System Products, Inc. [Ver = 2.9I-MS (XPClient.010817-1148) | Size = 26496 bytes | Modified Date = 8/17/2001 1:52:00 PM | Attr =	]

(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\ASC3550.SYS -> Advanced System Products, Inc. [Ver = 3.1E-MS (XPClient.010817-1148) | Size = 14848 bytes | Modified Date = 8/17/2001 1:51:58 PM | Attr =	]

(Atdisk) Atdisk [Kernel | Disabled | Stopped] ->  -> File not found

(bcm4sbxp) Broadcom 440x 10/100 Integrated Controller XP Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\bcm4sbxp.sys -> Broadcom Corporation [Ver = 3.60.0.0 built by: WinDDK | Size = 43136 bytes | Modified Date = 5/23/2003 12:58:30 PM | Attr =	]

(BCMModem) BCM V.92 56K Modem [Kernel | On_Demand | Running] -> %System32%\DRIVERS\BCMSM.sys -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:05:01 | Size = 1101696 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]

(bvrp_pci) bvrp_pci [Kernel | On_Demand | Stopped] ->  -> File not found

(Changer) Changer [Kernel | System | Stopped] ->  -> File not found

(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\CMDIDE.SYS -> CMD Technology, Inc. [Ver = 2.0.7 (XPClient.010817-1148) | Size = 6656 bytes | Modified Date = 8/17/2001 1:51:54 PM | Attr =	]

(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\DAC2W2K.SYS -> Mylex Corporation [Ver = 6.00-21 (XPClient.010817-1148) | Size = 179584 bytes | Modified Date = 8/17/2001 1:52:16 PM | Attr =	]

(dmboot) dmboot [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 12:07:17 AM | Attr =	]

(dmio) dmio [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 12:07:16 AM | Attr =	]

(dmload) dmload [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\DMLOAD.SYS -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 8/29/2002 5:00:00 AM | Attr =	]

(drvmcdb) drvmcdb [Kernel | Boot | Running] -> %System32%\DRIVERS\drvmcdb.sys -> Sonic Solutions [Ver = 3.21.65a | Size = 84576 bytes | Modified Date = 7/31/2003 3:21:00 AM | Attr =	]

(drvnddm) drvnddm [File_System | Auto | Running] -> %System32%\DRIVERS\drvnddm.sys -> Sonic Solutions [Ver = 2.56.38a | Size = 40448 bytes | Modified Date = 6/20/2003 2:56:00 AM | Attr =	]

(DSproct) DSproct [Kernel | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\GTAction\triggers\DSproct.sys -> Gteko Ltd. [Ver = 2, 0, 0, 30 | Size = 4736 bytes | Modified Date = 10/5/2006 3:07:28 PM | Attr =	]

(dsunidrv) DellSupport UniDriver [Kernel | Auto | Running] -> %System32%\DRIVERS\dsunidrv.sys -> Gteko Ltd. [Ver = 1, 0, 0, 12 | Size = 5376 bytes | Modified Date = 2/25/2007 11:10:48 AM | Attr =   S]

(EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\EL90XBC5.SYS -> 3Com Corporation [Ver = 4.05.00.0000 | Size = 66591 bytes | Modified Date = 8/17/2001 12:11:06 PM | Attr =	]

(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %System32%\DRIVERS\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 1:44:04 PM | Attr =	]

(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\hpzid412.sys -> HP [Ver = 7, 0, 0, 0 | Size = 51056 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]

(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\HPZipr12.sys -> HP [Ver = 7, 0, 0, 0 | Size = 16496 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]

(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\HPZius12.sys -> HP [Ver = 7, 0, 0, 0 | Size = 21488 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]

(i81x) i81x [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\i81xnt5.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 161020 bytes | Modified Date = 8/3/2004 11:29:36 PM | Attr =	]

(iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wadv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12415 bytes | Modified Date = 8/3/2004 11:29:37 PM | Attr =	]

(iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wadv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12127 bytes | Modified Date = 8/3/2004 11:29:37 PM | Attr =	]

(iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wadv05nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 11775 bytes | Modified Date = 8/3/2004 11:29:37 PM | Attr =	]

(iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wsiintxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12063 bytes | Modified Date = 8/3/2004 11:29:47 PM | Attr =	]

(iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wvchntxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19455 bytes | Modified Date = 8/3/2004 11:29:49 PM | Attr =	]

(iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\watv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 29311 bytes | Modified Date = 8/3/2004 11:29:41 PM | Attr =	]

(iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\watv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19551 bytes | Modified Date = 8/3/2004 11:29:42 PM | Attr =	]

(iAimTV2) iAimTV2 [Kernel | On_Demand | Stopped] -> System32\DRIVERS\wATV03nt.sys -> File not found

(iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\watv04nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 33599 bytes | Modified Date = 8/3/2004 11:29:43 PM | Attr =	]

(iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\wch7xxnt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 23615 bytes | Modified Date = 8/3/2004 11:29:45 PM | Attr =	]

(ialm) ialm [Kernel | On_Demand | Running] -> %System32%\DRIVERS\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.4342 | Size = 807998 bytes | Modified Date = 10/19/2005 7:59:12 AM | Attr =	]

(lbrtfdc) lbrtfdc [Kernel | System | Stopped] ->  -> File not found

(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\MRAID35X.SYS -> American Megatrends Inc. [Ver = 6.19 (XPClient.010817-1148) | Size = 17280 bytes | Modified Date = 8/17/2001 1:52:12 PM | Attr =	]

(NaiAvFilter1) NaiAvFilter1 [Kernel | On_Demand | Running] -> %System32%\DRIVERS\naiavf5x.sys -> McAfee Inc. [Ver = 11.0.0.142 | Size = 114464 bytes | Modified Date = 8/10/2005 10:22:10 AM | Attr =	]

(nv) nv [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\nv4_mini.sys -> NVIDIA Corporation [Ver = 6.14.10.5673 | Size = 1897408 bytes | Modified Date = 8/3/2004 11:29:54 PM | Attr =	]

(omci) OMCI WDM Device Driver [Kernel | System | Running] -> %System32%\DRIVERS\omci.sys -> Dell Computer Corporation [Ver = 7, 0, 323, 0 | Size = 17217 bytes | Modified Date = 11/8/2002 1:45:06 PM | Attr =	]

(PCIDump) PCIDump [Kernel | System | Stopped] ->  -> File not found

(PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] ->  -> File not found

(PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] ->  -> File not found

(PDRELI) PDRELI [Kernel | On_Demand | Stopped] ->  -> File not found

(PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] ->  -> File not found

(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %System32%\DRIVERS\PTILINK.SYS -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 8/29/2002 5:00:00 AM | Attr =	]

(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %System32%\DRIVERS\pxhelp20.sys -> Sonic Solutions [Ver = 2.03.18a | Size = 20576 bytes | Modified Date = 7/19/2005 10:43:27 AM | Attr =	]

(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\QL1080.SYS -> QLogic Corporation [Ver = 3.04 | Size = 40320 bytes | Modified Date = 8/17/2001 1:52:20 PM | Attr =	]

(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\QL12160.SYS -> QLogic Corporation [Ver = 7.13.02 (W64) | Size = 45312 bytes | Modified Date = 8/17/2001 1:52:20 PM | Attr =	]

(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\QL1280.SYS -> QLogic Corporation [Ver = 7.13.01 (W2K) | Size = 49024 bytes | Modified Date = 8/17/2001 1:52:18 PM | Attr =	]

(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 4:25:53 AM | Attr =	]

(Simbad) Simbad [Kernel | Disabled | Stopped] ->  -> File not found

(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\sisagp.sys -> Silicon Integrated Systems Corporation [Ver = 5.12.01.2010 (xpsp_sp2_rtm.040803-2158) | Size = 41088 bytes | Modified Date = 8/4/2004 12:07:42 AM | Attr =	]

(smwdm) smwdm [Kernel | On_Demand | Running] -> %System32%\DRIVERS\smwdm.sys -> Analog Devices, Inc. [Ver = 5.12.01.3555 | Size = 545024 bytes | Modified Date = 2/28/2003 9:17:18 AM | Attr =	]

(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\SPARROW.SYS -> Adaptec, Inc. [Ver = v2.0a (ReleaseBinaries.001205-1804) | Size = 19072 bytes | Modified Date = 8/17/2001 2:07:44 PM | Attr =	]

(sscdbhk5) sscdbhk5 [File_System | System | Running] -> %System32%\DRIVERS\sscdbhk5.sys -> Sonic Solutions [Ver = 1.10.81a | Size = 5621 bytes | Modified Date = 7/14/2003 11:28:40 AM | Attr =	]

(ssrtln) ssrtln [File_System | System | Running] -> %System32%\DRIVERS\ssrtln.sys -> Sonic Solutions [Ver = 1.10.81a | Size = 23219 bytes | Modified Date = 7/14/2003 11:28:22 AM | Attr =	]

(symc810) symc810 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\SYMC810.SYS -> Symbios Logic Inc. [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 16256 bytes | Modified Date = 8/17/2001 2:07:34 PM | Attr =	]

(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\SYMC8XX.SYS -> LSI Logic [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 32640 bytes | Modified Date = 8/17/2001 2:07:36 PM | Attr =	]

(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\SYM_HI.SYS -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 28384 bytes | Modified Date = 8/17/2001 2:07:40 PM | Attr =	]

(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\SYM_U3.SYS -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 30688 bytes | Modified Date = 8/17/2001 2:07:42 PM | Attr =	]

(tfsnboio) tfsnboio [File_System | Auto | Running] -> %System32%\dla\tfsnboio.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 25685 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsncofs) tfsncofs [File_System | Auto | Running] -> %System32%\dla\tfsncofs.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 34837 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsndrct) tfsndrct [File_System | Auto | Running] -> %System32%\dla\tfsndrct.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 4117 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsndres) tfsndres [File_System | Auto | Running] -> %System32%\dla\tfsndres.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 2233 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsnifs) tfsnifs [File_System | Auto | Running] -> %System32%\dla\tfsnifs.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 83284 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsnopio) tfsnopio [File_System | Auto | Running] -> %System32%\dla\tfsnopio.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 14229 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsnpool) tfsnpool [File_System | Auto | Running] -> %System32%\dla\tfsnpool.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 6357 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsnudf) tfsnudf [File_System | Auto | Running] -> %System32%\dla\tfsnudf.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 98068 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(tfsnudfa) tfsnudfa [File_System | Auto | Running] -> %System32%\dla\tfsnudfa.sys -> Sonic Solutions [Ver = 1.04.05b | Size = 100373 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

(ultra) ultra [Kernel | Disabled | Stopped] -> %System32%\DRIVERS\ULTRA.SYS -> Promise Technology, Inc. [Ver =  1.43 (Build 0603) | Size = 36736 bytes | Modified Date = 8/17/2001 1:52:22 PM | Attr =	]

(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %System32%\DRIVERS\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 1/10/2003 5:13:04 PM | Attr =	]

(WDICA) WDICA [Kernel | On_Demand | Stopped] ->  -> File not found

({6080A529-897E-4629-A488-ABA0C29B635E}) Intel(R) Graphics Platform (SoftBIOS) Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\ialmsbw.sys -> Intel Corporation [Ver = 6.13.10.3510 | Size = 113504 bytes | Modified Date = 4/15/2003 10:40:54 AM | Attr =	]

({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) Intel(R) Graphics Chipset (KCH) Driver [Kernel | On_Demand | Stopped] -> %System32%\DRIVERS\ialmkchw.sys -> Intel Corporation [Ver = 6.13.10.3510 | Size = 78752 bytes | Modified Date = 4/15/2003 10:40:46 AM | Attr =	]



[Registry - Non-Microsoft Only]

< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

BCMSMMSG -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]

dscactivate -> %ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe ->   [Ver = 1.0.2767.18581 | Size = 16384 bytes | Modified Date = 11/15/2007 9:24:00 AM | Attr =	]

HP Component Manager -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]

HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]

iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]

MCAgentExe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]

MCUpdateExe -> %ProgramFiles%\McAfee.com\Agent\mcupdate.exe -> McAfee, Inc [Ver = 6, 0, 0, 21 | Size = 212992 bytes | Modified Date = 1/11/2006 12:05:42 PM | Attr =	]

mmtask -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

MMTray -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]

OASClnt -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]

QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.3.1 | Size = 286720 bytes | Modified Date = 12/11/2007 10:56:54 AM | Attr =	]

tgcmd -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]

TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]

UserFaultCheck ->  -> File not found

VirusScan Online -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]

VSOCheckTask -> %ProgramFiles%\McAfee.com\VSO\mcmnhdlr.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 151552 bytes | Modified Date = 7/8/2005 5:18:22 PM | Attr =	]

< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 

msnmsgr -> %ProgramFiles%\MSN Messenger\msnmsgr.exe -> File not found

WeatherDPA -> %ProgramFiles%\Hotbar\bin\10.0.368.0\Weather.exe -> File not found

Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 9:49:04 PM | Attr =	]

< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 

%AllUsersStartup%\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 40048 bytes | Modified Date = 10/23/2006 1:48:20 AM | Attr =	]

%AllUsersStartup%\Adobe Reader Synchronizer.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ->  [Ver = 8.0.0.0 | Size = 734872 bytes | Modified Date = 10/23/2006 12:01:50 AM | Attr =	]

%AllUsersStartup%\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]

%AllUsersStartup%\PI Monitor.lnk -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]

< Kelly Startup Folder > -> C:\Documents and Settings\Kelly\Start Menu\Programs\Startup -> 

%UserStartup%\OCRAWARE.lnk -> %SystemDrive%\OPLIMIT\OCRAWARE.EXE -> Caere Corporation [Ver =  | Size = 51360 bytes | Modified Date = 7/18/1998 10:26:06 AM | Attr =	]

%UserStartup%\UMAX VistaAccess.lnk -> %SystemDrive%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 2.0 | Size = 266240 bytes | Modified Date = 7/21/2000 2:34:52 PM | Attr =	]

< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 

< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 

< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 

gebcaww -> gebcaww.dll -> File not found

igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 348160 bytes | Modified Date = 10/19/2005 7:59:14 AM | Attr =	]

naubekkj -> %System32%\naubekkj.dll ->  [Ver =  | Size = 163904 bytes | Modified Date = 2/4/2008 8:18:01 PM | Attr =	]

pmnll -> pmnll.dll -> File not found

vtstr -> %System32%\vtstr.dll -> File not found

< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 

< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 

< HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 

< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 

HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.yahoo.com/ -> 

HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com -> 

HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 

HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html -> 

HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 

HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.yahoo.com/ -> 

HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 

HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://www.comcast.net/toolbar2.0/search/ -> 

< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 

HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://www.dell4me.com/myway -> 

HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 

HKEY_CURRENT_USER\: Main\\Search Bar -> http://www.comcast.net/toolbar2.0/search/ -> 

HKEY_CURRENT_USER\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 

HKEY_CURRENT_USER\: Main\\Start Page -> http://www.comcast.net -> 

HKEY_CURRENT_USER\: SearchURL\\ -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com[Reg Error: Value provider does not exist or could not be read.] -> 

HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found

HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 

< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 

1 domain(s) and sub-domain(s) not assigned to a zone.

< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 

objects_aol.com [*] -> Out of zone range - ( 5 ) -> 

1 domain(s) and sub-domain(s) not assigned to a zone.

< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 

< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 

{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2} [HKEY_LOCAL_MACHINE] -> %System32%\vtsqq.dll [Reg Error: Value  does not exist or could not be read.] -> File not found

{4115122B-85FF-4DD3-9515-F075BEDE5EB5} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]

{549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]

{5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %System32%\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.05b | Size = 106548 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]

{67ce851b-47ce-4ac9-833e-7ff4ece09e36} [HKEY_LOCAL_MACHINE] -> %System32%\lthcdugi.dll [Reg Error: Value  does not exist or could not be read.] ->  [Ver =  | Size = 94272 bytes | Modified Date = 2/5/2008 9:48:43 PM | Attr =	]

{A95B2816-1D7E-4561-A202-68C0DE02353A} [HKEY_LOCAL_MACHINE] -> %System32%\naubekkj.dll [Reg Error: Value  does not exist or could not be read.] ->  [Ver =  | Size = 163904 bytes | Modified Date = 2/4/2008 8:18:01 PM | Attr =	]

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]

< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 

{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]

{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 

{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]

{BA52B914-B692-46c4-B683-905236F6F655} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee.com\VSO\mcvsshl.dll [McAfee VirusScan] -> McAfee, Inc. [Ver = 10, 0, 0, 19 | Size = 114688 bytes | Modified Date = 7/1/2005 7:44:30 PM | Attr =	]

< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 

WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found

WebBrowser\\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]

WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found

< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %System32%\msjava.dll [Sun Java Console] -> File not found

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}:{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! Services] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]

{669B269B-0D4E-41FB-A3D8-FD67CA94F646}:Exec ->  [ComcastHSI] -> File not found

{8828075D-D097-4055-AA02-2DBFA9D85E8A}:Exec ->  [Support] -> File not found

{97809617-3937-4F84-B335-9BB05EF1A8D4}:Exec ->  [Help] -> File not found

< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 

&Yahoo! Search ->  -> File not found

Add to Windows &Live Favorites ->  -> File not found

Yahoo! &Dictionary ->  -> File not found

Yahoo! &Maps ->  -> File not found

Yahoo! &SMS ->  -> File not found

< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 

PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 

PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 

Extension\.pdf -> %ProgramFiles%\Internet Explorer\PLUGINS\nppdf32.dll [Adobe Acrobat] -> File not found

< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 

{0032BCDA-5210-4EC7-9BFA-77D00F012DC8} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 

{0990A63A-9C1D-4800-92AB-CB095EA7DE84} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 

{30709FBE-EF58-40D9-B4D2-DE076C914147} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 

{45D6247E-106B-46B8-A29C-FDA5061867CC} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 

{82E6535A-D32A-481B-9D7E-3D0693E66193} ->	(Broadcom 440x 10/100 Integrated Controller) -> 

< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 

Protocol_Catalog9\Catalog_Entries\000000000001 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000002 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000003 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000004 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000005 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000006 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000007 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000008 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000009 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000010 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000011 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000012 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000013 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000014 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000015 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000016 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000017 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000018 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000019 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000020 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000021 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000022 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000023 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000024 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000025 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000026 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

Protocol_Catalog9\Catalog_Entries\000000000027 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]

< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 

cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\HP\hpcoretech\comp\hpuiprot.dll[CZipHandler Object] -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 81920 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]

ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found

msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 

{11260943-421B-11D0-8EAC-0000C07D88CF}[HKEY_LOCAL_MACHINE] -> http://www.ipix.com/viewers/ipixx.cab[iPIX ActiveX Control] -> 

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab[McAfee.com Operating System Class] -> 

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162985822921[MUWebControl Class] -> 

{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 

{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] -> 

{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab[DwnldGroupMgr Class] -> 

{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 

{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 





[Registry - Additional Scans - Non-Microsoft Only]

< BotCheck > -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> (binary data) -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> (binary data) -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll ->  -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\\DisableMonitoring -> 1 -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> 

Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> 

Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->

*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 

msv1_0 -> %System32%\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 1:56:43 AM | Attr =	]

C:\WINDOWS\system32\vtsqq ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) -> 

*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 

kerberos -> %System32%\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 11:49:30 AM | Attr =	]

msv1_0 -> %System32%\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 1:56:43 AM | Attr =	]

schannel -> %System32%\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 8:21:15 AM | Attr =	]

wdigest -> %System32%\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 3/23/2006 10:37:50 PM | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 676 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> 

*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> 

scecli -> %System32%\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 1:56:44 AM | Attr =	]

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> 

*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> 

Windows NT Access Provider ->  -> File not found

*MultiFile Done* -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\SYSTEM32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 1:56:44 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 1:56:57 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup ->  -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 282947 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 1:56:42 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\SYSTEM32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 1:56:56 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\America Online 9.0\waol.exe -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~1.0] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.3012 (xpsp.061010-0355) | Size = 557568 bytes | Modified Date = 10/10/2006 6:44:50 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall -> 0 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\system32\sessmgr.exe -> C:\WINDOWS\SYSTEM32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 1:56:56 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\support.com\bin\tgcmd.exe -> C:\Program Files\support.com\bin\tgcmd.exe [C:\Program Files\support.com\bin\tgcmd.exe:*:Disabled:Support.com Scheduler and Command Dispatcher] -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\LEXPPS.EXE -> C:\WINDOWS\SYSTEM32\LEXPPS.EXE [C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YPager.exe -> C:\Program Files\Yahoo!\Messenger\YPager.exe [C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YServer.exe -> C:\Program Files\Yahoo!\Messenger\YServer.exe [C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server] -> Yahoo! Inc. [Ver = 3, 0, 0, 1 | Size = 91640 bytes | Modified Date = 11/30/2006 9:49:06 PM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\America Online 9.0\waol.exe -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~1.0] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger] -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 9:49:04 PM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\%windir%\Network Diagnostic\xpnetdiag.exe -> C:\WINDOWS\network diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> Microsoft Corporation [Ver = 5.1.2600.3012 (xpsp.061010-0355) | Size = 557568 bytes | Modified Date = 10/10/2006 6:44:50 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\iTunes\iTunes.exe -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> Apple Inc. [Ver = 7.5.0.20 | Size = 17152808 bytes | Modified Date = 12/11/2007 12:10:18 PM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll [1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll [2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008] -> File not found

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{82E6535A-D32A-481B-9D7E-3D0693E66193} -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{4E466873-2693-4BDA-8518-EDA6CDFDD866} -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{0990A63A-9C1D-4800-92AB-CB095EA7DE84} -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 272 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 1:56:57 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site. -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 1:56:46 AM | Attr =	]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> 

Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> -> 

Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> -> 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> 





[Files/Folders - Created Within 30 days]

09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier

aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier

HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier

HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier

fufrppig.ini -> %System32%\fufrppig.ini ->  [Ver =  | Size = 1194402 bytes | Modified Date = 2/6/2008 4:21:29 PM | Attr =  HS]

gipprfuf.dll -> %System32%\gipprfuf.dll ->  [Ver =  | Size = 90688 bytes | Modified Date = 2/5/2008 9:50:35 PM | Attr =	]

lthcdugi.dll -> %System32%\lthcdugi.dll ->  [Ver =  | Size = 94272 bytes | Modified Date = 2/5/2008 9:48:43 PM | Attr =	]

naubekkj.dll -> %System32%\naubekkj.dll ->  [Ver =  | Size = 163904 bytes | Modified Date = 2/4/2008 8:18:01 PM | Attr =	]

naubekkj.dllbox -> %System32%\naubekkj.dllbox ->  [Ver =  | Size = 31014 bytes | Modified Date = 2/10/2008 12:01:55 PM | Attr =  HS]

nGpxx01 -> %System32%\nGpxx01 ->  [Folder | Created Date = 2/4/2008 8:02:38 PM | Attr =	]

2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 

qqstv.ini -> %System32%\qqstv.ini ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:15:36 PM | Attr =  HS]

qqstv.ini2 -> %System32%\qqstv.ini2 ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:14:22 PM | Attr =  HS]

sbhyqqpl.ini -> %System32%\sbhyqqpl.ini ->  [Ver =  | Size = 1192238 bytes | Modified Date = 2/4/2008 8:22:06 PM | Attr =  HS]

cookies.ini -> %SystemRoot%\cookies.ini ->  [Ver =  | Size = 177 bytes | Modified Date = 2/6/2008 4:21:58 PM | Attr =	]

[Files Created - Additional Folder Scans - Non-Microsoft Only]

SupportSoft -> %AllUsersAppData%\SupportSoft ->  [Folder | Created Date = 1/28/2008 6:34:10 AM | Attr =	]

SupportSoft -> %LocalAppData%\SupportSoft ->  [Folder | Created Date = 2/5/2008 9:06:23 AM | Attr =	]

Ad-Aware 2007.lnk -> %AllUsersDesktop%\Ad-Aware 2007.lnk ->  [Ver =  | Size = 1790 bytes | Modified Date = 2/7/2008 5:44:57 PM | Attr =	]

Ad-Watch 2007.lnk -> %AllUsersDesktop%\Ad-Watch 2007.lnk ->  [Ver =  | Size = 1790 bytes | Modified Date = 2/7/2008 5:44:57 PM | Attr =	]

Dell Support Center.lnk -> %AllUsersDesktop%\Dell Support Center.lnk ->  [Ver =  | Size = 2415 bytes | Modified Date = 2/8/2008 8:55:38 PM | Attr =	]

ATF-Cleaner.exe -> %UserDesktop%\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 2/11/2008 1:37:18 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\ATF-Cleaner.exe:Zone.Identifier

Help and Support Center.lnk -> %UserDesktop%\Help and Support Center.lnk ->  [Ver =  | Size = 1936 bytes | Modified Date = 2/6/2008 10:05:20 AM | Attr =	]

TheWeatherChannel_dw5_Stubweather2.exe -> %UserDesktop%\TheWeatherChannel_dw5_Stubweather2.exe -> The Weather Channel Interactive [Ver = 4, 1, 0, 5 | Size = 277616 bytes | Modified Date = 1/31/2008 8:34:47 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\TheWeatherChannel_dw5_Stubweather2.exe:Zone.Identifier

Windows Update.lnk -> %UserDesktop%\Windows Update.lnk ->  [Ver =  | Size = 1930 bytes | Modified Date = 2/6/2008 10:05:23 AM | Attr =	]

WinPFind35u -> %UserDesktop%\WinPFind35u ->  [Folder | Created Date = 2/11/2008 1:49:00 PM | Attr =	]

WinPFind35u.exe -> %UserDesktop%\WinPFind35u.exe ->  [Ver =  | Size = 481041 bytes | Modified Date = 2/11/2008 1:47:17 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\WinPFind35u.exe:Zone.Identifier

supportsoft -> %CommonProgramFiles%\supportsoft ->  [Folder | Created Date = 1/28/2008 6:31:46 AM | Attr =	]

Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard ->  [Folder | Created Date = 2/7/2008 5:42:05 PM | Attr =	]



[Files/Folders - Modified Within 30 days]

09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier

9f0e322cd95532de9dec04aff738e10c -> %SystemDrive%\9f0e322cd95532de9dec04aff738e10c ->  [Folder | Modified Date = 2/5/2008 9:50:23 AM | Attr =	]

2172 C:\*.tmp files -> C:\*.tmp -> 

aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier

hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 266407936 bytes | Modified Date = 2/8/2008 6:09:13 PM | Attr =  HS]

HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier

HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier

Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 2/5/2008 5:09:56 PM | Attr =	]

Temp -> %SystemDrive%\Temp ->  [Folder | Modified Date = 2/4/2008 8:02:36 PM | Attr =	]

WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 2/8/2008 8:54:29 PM | Attr =	]

CatRoot2 -> %System32%\CatRoot2 ->  [Folder | Modified Date = 2/8/2008 6:18:17 PM | Attr =	]

2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 

DRIVERS -> %System32%\DRIVERS ->  [Folder | Modified Date = 2/7/2008 5:44:30 PM | Attr =	]

fufrppig.ini -> %System32%\fufrppig.ini ->  [Ver =  | Size = 1194402 bytes | Modified Date = 2/6/2008 4:21:29 PM | Attr =  HS]

gipprfuf.dll -> %System32%\gipprfuf.dll ->  [Ver =  | Size = 90688 bytes | Modified Date = 2/5/2008 9:50:35 PM | Attr =	]

lthcdugi.dll -> %System32%\lthcdugi.dll ->  [Ver =  | Size = 94272 bytes | Modified Date = 2/5/2008 9:48:43 PM | Attr =	]

naubekkj.dll -> %System32%\naubekkj.dll ->  [Ver =  | Size = 163904 bytes | Modified Date = 2/4/2008 8:18:01 PM | Attr =	]

naubekkj.dllbox -> %System32%\naubekkj.dllbox ->  [Ver =  | Size = 31014 bytes | Modified Date = 2/10/2008 12:01:55 PM | Attr =  HS]

nGpxx01 -> %System32%\nGpxx01 ->  [Folder | Modified Date = 2/4/2008 8:06:14 PM | Attr =	]

qqstv.ini -> %System32%\qqstv.ini ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:15:36 PM | Attr =  HS]

qqstv.ini2 -> %System32%\qqstv.ini2 ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:14:22 PM | Attr =  HS]

sbhyqqpl.ini -> %System32%\sbhyqqpl.ini ->  [Ver =  | Size = 1192238 bytes | Modified Date = 2/4/2008 8:22:06 PM | Attr =  HS]

WPA.DBL -> %System32%\WPA.DBL ->  [Ver =  | Size = 1170 bytes | Modified Date = 2/8/2008 8:53:06 PM | Attr =	]

BOOTSTAT.DAT -> %SystemRoot%\BOOTSTAT.DAT ->  [Ver =  | Size = 2048 bytes | Modified Date = 2/8/2008 6:09:14 PM | Attr =   S]

cookies.ini -> %SystemRoot%\cookies.ini ->  [Ver =  | Size = 177 bytes | Modified Date = 2/6/2008 4:21:58 PM | Attr =	]

Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 2/7/2008 10:04:16 PM | Attr =  HS]

1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 

oplimit.ini -> %SystemRoot%\oplimit.ini ->  [Ver =  | Size = 732 bytes | Modified Date = 2/8/2008 9:58:35 AM | Attr =	]

Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 2/11/2008 1:55:33 PM | Attr =	]

QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 2/8/2008 8:53:35 PM | Attr =  H ]

SYSTEM32 -> %System32% ->  [Folder | Modified Date = 2/8/2008 6:13:46 PM | Attr =	]

Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 2/11/2008 1:39:11 PM | Attr =	]

vista32.ini -> %SystemRoot%\vista32.ini ->  [Ver =  | Size = 1050 bytes | Modified Date = 2/8/2008 6:16:02 PM | Attr =	]

AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Modified Date = 2/1/2008 3:52:08 PM | Attr =	]

SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 2/8/2008 6:09:27 PM | Attr =  H ]

about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat ->  [Ver =  | Size = 1528 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]

college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat ->  [Ver =  | Size = 327746 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]

moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat ->  [Ver =  | Size = 102 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]

ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat ->  [Ver =  | Size = 12283223 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]

qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 15531 bytes | Modified Date = 2/8/2008 9:01:15 PM | Attr =	]

qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 4232 bytes | Modified Date = 2/8/2008 9:05:13 PM | Attr =	]

getseal[1].com&size=S&use_flash=YES&use_transparent=YES&lang=en -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\MR2V6PUB\getseal[1].com ->  [Ver =  | Size = 3568 bytes | Modified Date = 10/6/2006 7:02:49 AM | Attr =	]

ChkTrust.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ChkTrust.exe -> Microsoft Corporation [Ver = 5.131.2134.1 | Size = 18192 bytes | Modified Date = 5/14/2004 6:42:00 AM | Attr =	]

messenger_update.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\messenger_update.exe ->  [Ver =  | Size = 606000 bytes | Modified Date = 8/29/2007 5:08:19 PM | Attr =	]

mofugclq.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\mofugclq.exe -> Locus Software, Inc. [Ver = 1.3.122.1 | Size = 259336 bytes | Modified Date = 2/7/2008 5:13:44 PM | Attr =	]

qrjatydi.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\qrjatydi.exe -> Locus Software, Inc. [Ver = 1.3.122.1 | Size = 259336 bytes | Modified Date = 2/7/2008 10:06:52 AM | Attr =	]

TA2004_1_42_0_0_1_XP.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\TA2004_1_42_0_0_1_XP.exe ->  [Ver =  | Size = 32767 bytes | Modified Date = 5/14/2004 6:41:48 AM | Attr =	]

TA2004_1_42_0_0_1_XP_P.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\TA2004_1_42_0_0_1_XP_P.exe -> EarthLink, Inc.											  [Ver = 2004.1.42.0												  | Size = 16098864 bytes | Modified Date = 5/13/2004 8:03:34 PM | Attr =	]

yacscom_update.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\yacscom_update.exe ->  [Ver =  | Size = 285696 bytes | Modified Date = 4/3/2007 4:21:54 PM | Attr =	]

ytb_6.3.4.0_pub_us_setup_.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ytb_6.3.4.0_pub_us_setup_.exe ->  [Ver =  | Size = 962072 bytes | Modified Date = 9/20/2006 4:27:48 AM | Attr =	]

ywc_update2.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ywc_update2.exe ->  [Ver =  | Size = 302648 bytes | Modified Date = 6/8/2007 10:28:58 PM | Attr =	]

688 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 

CDVIEWER.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\CDVIEWER.EXE -> Noritsu KOKI [Ver = 2, 0, 0, 25 | Size = 2732544 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]

ShFolder.Exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\ShFolder.Exe -> Microsoft Corporation [Ver = 5.50.4027.300 | Size = 117288 bytes | Modified Date = 4/16/2001 4:39:02 PM | Attr =	]

HSBR.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP2.DIR\_ISTMP0.DIR\HSBR.exe -> Leader Technologies/Hasbro [Ver = 1, 0, 0, 1 | Size = 4789248 bytes | Modified Date = 7/29/1999 3:01:16 PM | Attr =	]

install.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\install.exe -> SupportSoft, Inc. [Ver = 6,2,399,0 | Size = 1321104 bytes | Modified Date = 3/4/2005 2:25:38 PM | Attr =	]

cipherchk.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\cipherchk.exe -> SupportSoft, Inc. [Ver = 1, 0, 0, 1 | Size = 55488 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]

Encpack_Win2000_EN.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\Encpack_Win2000_EN.exe -> Microsoft Corporation [Ver = 5.00.2150.1 | Size = 193768 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]

ie501dom.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\ie501dom.exe -> Microsoft Corporation [Ver = 5.00.2013.1301 | Size = 218704 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]

ie5dom.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\ie5dom.exe -> Microsoft Corporation [Ver = 5.00.2013.1301 | Size = 219216 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60194E\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:00:14 PM | Attr =	]

Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60194E\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:00:14 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60678E\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:01:34 PM | Attr =	]

Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60678E\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:01:34 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60740EUW\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:02:54 PM | Attr =	]

Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60740EUW\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:02:54 PM | Attr =	]

SETUP.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Belkin_F5D5530-W\SETUP.EXE ->  [Ver =  | Size = 2016768 bytes | Modified Date = 3/6/2005 11:07:52 PM | Attr =	]

UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\2k\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:04 PM | Attr =	]

UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\98\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:12 PM | Attr =	]

UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\me\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:16 PM | Attr =	]

UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\xp\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:22 PM | Attr =	]

Remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Castlenet_DP1110XB2\Remove.exe ->  [Ver =  | Size = 32768 bytes | Modified Date = 3/6/2005 11:18:18 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Com21_DP1110\REMOVE.EXE ->  [Ver =  | Size = 463872 bytes | Modified Date = 3/6/2005 11:18:28 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Com21_DP1110XB\REMOVE.EXE ->  [Ver =  | Size = 463872 bytes | Modified Date = 3/6/2005 11:18:38 PM | Attr =	]

UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10_H\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:32 PM | Attr =	]

UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10_V\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:34 PM | Attr =	]

UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v2\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:38 PM | Attr =	]

UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v2\patch\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:28:10 PM | Attr =	]

UNBEFCM3.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v3\UNBEFCM3.exe -> Linksys. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:25:42 PM | Attr =	]

UNWCGB.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_WCG200\UNWCGB.exe -> Linksys. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:25:44 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4100\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:25:52 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4101\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:25:58 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4200\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:29:18 PM | Attr =	]

CLEANUP.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4220\CLEANUP.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:29:26 PM | Attr =	]

RemoveUSB.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB5100\RemoveUSB.exe ->  [Ver = 1, 0, 0, 1 | Size = 385024 bytes | Modified Date = 3/6/2005 11:29:34 PM | Attr =	]

remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB5120\remove.exe ->  [Ver = 1, 0, 0, 1 | Size = 389120 bytes | Modified Date = 3/6/2005 11:29:42 PM | Attr =	]

REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SBG1000\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:55:54 PM | Attr =	]

remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SBG900\remove.exe ->  [Ver = 1, 0, 0, 1 | Size = 389120 bytes | Modified Date = 3/6/2005 11:56:02 PM | Attr =	]

UNDPX2A.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DCP2100\UNDPX2A.EXE ->  [Ver = 2, 8, 4, 0 | Size = 135168 bytes | Modified Date = 3/6/2005 11:48:56 PM | Attr =	]

UNDPX2K.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DCP2100\UNDPX2K.EXE ->  [Ver = 2, 8, 2, 0 | Size = 135168 bytes | Modified Date = 3/6/2005 11:48:56 PM | Attr =	]

undpx.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX100\undpx.exe -> Scientific Atlanta. [Ver = 1.00 Build 004 | Size = 13490 bytes | Modified Date = 3/6/2005 11:48:58 PM | Attr =	]

undpx.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX110\undpx.exe -> Scientific Atlanta. [Ver = 1.00 Build 004 | Size = 13490 bytes | Modified Date = 3/6/2005 11:49:02 PM | Attr =	]

UNDPX.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX2100\UNDPX.exe -> Scientific Atlanta. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:49:04 PM | Attr =	]

setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SMC_8002\setup.exe ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/6/2005 11:49:08 PM | Attr =	]

setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SMC_8011CM-B\setup.exe ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/6/2005 11:49:16 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SpeedStream_SS6101\Setup.exe ->															  [Ver = 1.10.35.1001												 | Size = 3695494 bytes | Modified Date = 3/6/2005 11:48:04 PM | Attr =	]

pcx2000-usbscrub.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Toshiba_PCX2000\pcx2000-usbscrub.exe ->  [Ver =  | Size = 41984 bytes | Modified Date = 3/6/2005 11:45:32 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Zoom_5041\Setup.exe -> InstallShield Software Corporation [Ver = 6, 31, 100, 1190 | Size = 56320 bytes | Modified Date = 3/6/2005 11:43:42 PM | Attr =	]

chsi_uninstaller.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\uninstall\chsi_uninstaller.exe -> Comcast Cable Communications, LLC.						   [Ver = 2.1														  | Size = 330312 bytes | Modified Date = 7/22/2005 1:01:42 PM | Attr =	]

Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Setup.exe -> InstallShield Software Corporation [Ver = 5, 52, 164, 0 | Size = 73728 bytes | Modified Date = 1/12/1999 11:42:20 AM | Attr = R  ]

_ISDel.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\_ISDel.exe -> InstallShield Software Corporation [Ver = 5, 51, 138, 0 | Size = 27648 bytes | Modified Date = 10/27/1998 12:06:48 PM | Attr = R  ]

AcroRd32.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\AcroRd32.exe -> Adobe Systems Incorporated [Ver = 5.0.1.2001032700 | Size = 3870784 bytes | Modified Date = 3/27/2001 9:44:58 PM | Attr = R  ]

Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Walgreens PhotoShow Express CD.exe -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 79076 bytes | Modified Date = 12/5/2004 7:42:06 PM | Attr =	]

photoshow_express_setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\app\shared\data\photoshow_express_setup.exe -> Simple Star, Inc. [Ver = 3.0.0.97 | Size = 480520 bytes | Modified Date = 8/5/2005 2:06:12 PM | Attr =	]

Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\boot_strap\Walgreens PhotoShow Express CD.exe -> Simple Star, Inc. [Ver = 3.0.1.177 | Size = 135168 bytes | Modified Date = 8/5/2005 3:02:20 PM | Attr =	]

Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Walgreens PhotoShow Express CD.exe -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 79076 bytes | Modified Date = 5/12/2006 4:57:51 PM | Attr =	]

photoshow_express_setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\app\shared\data\photoshow_express_setup.exe -> Simple Star, Inc. [Ver = 4.5.1.55 | Size = 4308236 bytes | Modified Date = 7/24/2006 12:12:47 PM | Attr =	]

Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\boot_strap\Walgreens PhotoShow Express CD.exe -> Simple Star, Inc. [Ver = 4.0.0.88 | Size = 139264 bytes | Modified Date = 10/11/2006 1:08:18 PM | Attr =	]

acsdir.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\acsdir.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 8/6/2003 4:02:18 PM | Attr =	]

AOLFirewallMgr.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLFirewallMgr.dll -> America Online, Inc. [Ver = 1, 0, 0, 0 | Size = 57344 bytes | Modified Date = 5/12/2004 1:53:48 PM | Attr =	]

AOLInstallerFW.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLInstallerFW.dll -> America Online, Inc. [Ver = 1, 0, 0, 0 | Size = 73728 bytes | Modified Date = 5/12/2004 1:53:48 PM | Attr =	]

InstHelp.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\InstHelp.dll ->  [Ver =  | Size = 56832 bytes | Modified Date = 8/5/2004 6:35:14 PM | Attr =	]

shfolder.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\shfolder.dll -> Microsoft Corporation [Ver = 5.50.4522.1800 | Size = 23312 bytes | Modified Date = 2/21/2003 9:24:20 AM | Attr =	]

uninst.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\uninst.dll ->  [Ver =  | Size = 110592 bytes | Modified Date = 9/24/2003 10:42:16 AM | Attr =	]

wyb64.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\wyb64.dll -> Yahoo! Inc. [Ver = 2004.12.4.1 | Size = 58464 bytes | Modified Date = 12/3/2004 2:34:26 PM | Attr =	]

yvertr.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\yvertr.dll ->  [Ver = 2004, 1, 15, 1 | Size = 42080 bytes | Modified Date = 1/15/2004 1:48:38 PM | Attr =	]

688 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 

EXIF.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\EXIF.DLL -> FUJI PHOTO FILM CO., LTD [Ver = 2, 3, 4, 0 | Size = 548352 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]

IJL11.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\IJL11.DLL -> Intel Corporation [Ver = 1.1.2 | Size = 180224 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]

BrwsrPI.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\BrwsrPI.dll -> Adobe Systems, Inc. [Ver = 5.05 | Size = 53248 bytes | Modified Date = 8/8/2001 9:22:42 PM | Attr =	]

IccTest.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IccTest.dll -> Adobe Systems, Inc. [Ver = 1.2 | Size = 126976 bytes | Modified Date = 8/7/2001 4:48:00 PM | Attr =	]

Permission.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Permission.dll ->  [Ver = 1.1 | Size = 98304 bytes | Modified Date = 4/16/2001 4:39:02 PM | Attr =	]

sdcnetcheck.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\sdcnetcheck.dll -> SupportSoft, Inc. [Ver = 6,0,1023,0 | Size = 202320 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

ssctlnwk.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\ssctlnwk.dll -> SupportSoft, Inc. [Ver = 6,0,1148,0 | Size = 292432 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

tgctlcm.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlcm.dll -> SupportSoft, Inc. [Ver = 6,0,997,0 | Size = 222800 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

tgctlpw.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlpw.dll -> SupportSoft, Inc. [Ver = 6,0,1334,0 | Size = 112208 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

tgctlsi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlsi.dll -> Support.com, Inc. [Ver = 5,5,741,0 | Size = 1701456 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

tglib.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tglib.dll -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 2180688 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]

mPlayer.3.1.1b.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\mProjector1101327051\mPlayer.3.1.1b.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 2/9/2008 9:37:27 AM | Attr =	]

_Setup.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\_Setup.dll -> InstallShield Software Corporation [Ver = 5, 50, 134, 0 | Size = 34816 bytes | Modified Date = 9/29/1998 4:34:56 PM | Attr = R  ]

AceLite.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\AceLite.dll -> Adobe Systems, Incorporated [Ver = 1.02.00 | Size = 397312 bytes | Modified Date = 2/28/2001 9:29:36 AM | Attr = R  ]

ACROFX32.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\ACROFX32.DLL ->  [Ver =  | Size = 53248 bytes | Modified Date = 5/12/2000 6:30:02 PM | Attr = R  ]

Agm.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Agm.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1138688 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]

Bib.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Bib.dll -> Adobe Systems, Incorporated [Ver = 1.0.20 | Size = 147456 bytes | Modified Date = 1/20/2001 10:13:36 PM | Attr = R  ]

CoolType.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\CoolType.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1441792 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]

msvcp60.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\msvcp60.dll -> Microsoft Corporation [Ver = 6.00.8168.0 | Size = 401462 bytes | Modified Date = 12/1/1999 12:40:28 AM | Attr = R  ]

msvcrt.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\msvcrt.dll -> Microsoft Corporation [Ver = 6.00.8397.0 | Size = 266293 bytes | Modified Date = 2/11/1999 3:33:58 AM | Attr = R  ]

oleaut32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\oleaut32.dll -> Microsoft Corporation [Ver = 2.30.4261 | Size = 598288 bytes | Modified Date = 6/18/1998 11:33:08 AM | Attr = R  ]

WHA Library.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\WHA Library.dll -> Adobe Systems Incorporated [Ver = 0.2.0.0 | Size = 167936 bytes | Modified Date = 3/15/2001 6:14:38 AM | Attr = R  ]

nppdf32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Browser\nppdf32.dll -> Adobe Systems Inc. [Ver = 5.0.0.2001031500 | Size = 103312 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]

NPDocBox.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\InterTrust\NPDocBox.dll -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 3/14/2001 4:52:06 AM | Attr = R  ]

QT2.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT2.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 24576 bytes | Modified Date = 3/15/2001 6:00:24 AM | Attr = R  ]

QT3.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT3.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 32768 bytes | Modified Date = 3/15/2001 6:00:42 AM | Attr = R  ]

QT4.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT4.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 36864 bytes | Modified Date = 3/15/2001 6:01:02 AM | Attr = R  ]

Uninst.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Uninstall\Uninst.dll -> Adobe Systems, Inc. [Ver = 4.0.11 | Size = 81920 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]

NPSVGVw.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\NPSVGVw.dll -> Adobe Systems Inc. [Ver = 2, 0, 0, 55 | Size = 299059 bytes | Modified Date = 3/14/2001 2:10:56 PM | Attr = R  ]

SVGControl.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGControl.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 491574 bytes | Modified Date = 3/14/2001 2:14:00 PM | Attr = R  ]

SVGRSRC.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGRSRC.DLL ->  [Ver =  | Size = 12288 bytes | Modified Date = 3/14/2001 2:06:24 PM | Attr = R  ]

SVGView.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGView.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 1597491 bytes | Modified Date = 3/14/2001 2:07:52 PM | Attr = R  ]

eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\eBayISAPI[1].dll ->  [Ver =  | Size = 9591 bytes | Modified Date = 10/10/2006 8:38:19 AM | Attr =	]

eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\eBayISAPI[2].dll ->  [Ver =  | Size = 9495 bytes | Modified Date = 10/10/2006 8:38:47 AM | Attr =	]

eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[1].dll ->  [Ver =  | Size = 5147 bytes | Modified Date = 10/9/2006 12:03:50 PM | Attr =	]

eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[2].dll ->  [Ver =  | Size = 17869 bytes | Modified Date = 10/9/2006 12:18:49 PM | Attr =	]

eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[3].dll ->  [Ver =  | Size = 18151 bytes | Modified Date = 10/9/2006 2:09:18 PM | Attr =	]

eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[4].dll ->  [Ver =  | Size = 19125 bytes | Modified Date = 10/9/2006 2:17:10 PM | Attr =	]

eBayISAPI[5].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[5].dll ->  [Ver =  | Size = 10370 bytes | Modified Date = 10/9/2006 2:19:37 PM | Attr =	]

eBayISAPI[6].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[6].dll ->  [Ver =  | Size = 7817 bytes | Modified Date = 10/9/2006 2:21:59 PM | Attr =	]

eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[1].dll ->  [Ver =  | Size = 16154 bytes | Modified Date = 10/9/2006 12:05:52 PM | Attr =	]

eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[2].dll ->  [Ver =  | Size = 2709 bytes | Modified Date = 10/9/2006 12:26:39 PM | Attr =	]

eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[3].dll ->  [Ver =  | Size = 17888 bytes | Modified Date = 10/9/2006 12:40:09 PM | Attr =	]

eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[4].dll ->  [Ver =  | Size = 10338 bytes | Modified Date = 10/10/2006 11:34:50 AM | Attr =	]

eBayISAPI[5].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[5].dll ->  [Ver =  | Size = 7535 bytes | Modified Date = 10/10/2006 11:35:09 AM | Attr =	]

eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[1].dll ->  [Ver =  | Size = 3828 bytes | Modified Date = 10/9/2006 11:49:38 AM | Attr =	]

eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[2].dll ->  [Ver =  | Size = 4413 bytes | Modified Date = 10/9/2006 11:53:00 AM | Attr =	]

eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[3].dll ->  [Ver =  | Size = 9882 bytes | Modified Date = 10/9/2006 12:37:09 PM | Attr =	]

eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[4].dll ->  [Ver =  | Size = 9808 bytes | Modified Date = 10/9/2006 12:41:37 PM | Attr =	]

eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[1].dll ->  [Ver =  | Size = 4584 bytes | Modified Date = 10/9/2006 11:49:09 AM | Attr =	]

eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[2].dll ->  [Ver =  | Size = 4728 bytes | Modified Date = 10/9/2006 12:27:28 PM | Attr =	]

eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[3].dll ->  [Ver =  | Size = 18350 bytes | Modified Date = 10/9/2006 12:35:07 PM | Attr =	]

eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[4].dll ->  [Ver =  | Size = 7851 bytes | Modified Date = 10/9/2006 12:43:09 PM | Attr =	]

UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr54b6.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 1/18/2005 12:34:27 PM | Attr =	]

UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr5665.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 12/29/2004 6:52:45 PM | Attr =	]

UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr77da.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 12/31/2004 8:21:29 PM | Attr =	]

UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr95d.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 1/14/2005 6:47:54 AM | Attr =	]

simple_jpeg.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\boot_strap\simple_jpeg.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 9/9/2004 7:34:24 PM | Attr =	]

Dirapi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Dirapi.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 1097728 bytes | Modified Date = 5/18/2004 6:20:15 PM | Attr =	]

Iml32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Iml32.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 561152 bytes | Modified Date = 5/18/2004 6:20:15 PM | Attr =	]

Proj.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Proj.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 151552 bytes | Modified Date = 5/18/2004 6:20:16 PM | Attr =	]

simple_jpeg.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\boot_strap\simple_jpeg.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 5/12/2006 5:45:11 PM | Attr =	]

Dirapi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Dirapi.dll -> Macromedia, Inc. [Ver = 8.5.1r104 | Size = 1097728 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]

Iml32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Iml32.dll -> Macromedia, Inc. [Ver = 8.5.1r104 | Size = 561152 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]

Proj.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Proj.dll -> Macromedia, Inc. [Ver = 9.0r371 | Size = 159744 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]

AIM_PH.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\AIM_PH.dat ->  [Ver =  | Size = 287 bytes | Modified Date = 5/25/2005 10:42:06 AM | Attr =	]

Perflib_Perfdata_100.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_100.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 11/9/2007 11:32:08 AM | Attr =	]

Perflib_Perfdata_1a40.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_1a40.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/23/2007 7:54:47 AM | Attr =	]

Perflib_Perfdata_1cc8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_1cc8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 5/10/2007 5:56:39 AM | Attr =	]

Perflib_Perfdata_22c.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_22c.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 1/9/2008 5:51:55 AM | Attr =	]

Perflib_Perfdata_24f4.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_24f4.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 9/20/2007 4:25:52 PM | Attr =	]

Perflib_Perfdata_330.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_330.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/29/2006 8:22:44 AM | Attr =	]

Perflib_Perfdata_454.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_454.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 11/13/2007 12:54:50 PM | Attr =	]

Perflib_Perfdata_8c0.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_8c0.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 1/20/2008 1:26:24 PM | Attr =	]

Perflib_Perfdata_984.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_984.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 2/10/2008 1:39:36 PM | Attr =	]

Perflib_Perfdata_a08.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_a08.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/20/2006 4:54:29 PM | Attr =	]

Perflib_Perfdata_abc.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_abc.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/21/2007 4:20:06 PM | Attr =	]

Perflib_Perfdata_b50.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_b50.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 10/13/2006 1:16:10 PM | Attr =	]

Perflib_Perfdata_de8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_de8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 7/17/2006 5:29:16 PM | Attr =	]

Perflib_Perfdata_fa8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_fa8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 2/6/2008 8:11:55 AM | Attr =	]

Perflib_Perfdata_fac.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_fac.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/26/2007 1:38:18 PM | Attr =	]

Perflib_Perfdata_ff8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_ff8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/13/2006 12:25:24 PM | Attr =	]

688 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 

index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\index.dat ->  [Ver =  | Size = 65536 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]

index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\History\History.IE5\index.dat ->  [Ver =  | Size = 917504 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]

lang.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\lang.dat ->  [Ver =  | Size = 23541 bytes | Modified Date = 1/12/1999 10:34:42 AM | Attr = R  ]

os.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\os.dat ->  [Ver =  | Size = 450 bytes | Modified Date = 7/27/1998 5:41:06 PM | Attr = R  ]

index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat ->  [Ver =  | Size = 9158656 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]

AOLFirewallMgr.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLFirewallMgr.ini ->  [Ver =  | Size = 6460 bytes | Modified Date = 5/12/2004 1:53:28 PM | Attr =	]

smi.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\smi.ini ->  [Ver =  | Size = 868 bytes | Modified Date = 5/14/2004 6:41:16 AM | Attr =	]

688 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 

AdobeIns.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\AdobeIns.ini ->  [Ver =  | Size = 6260 bytes | Modified Date = 9/17/2001 5:58:18 PM | Attr =	]

install.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\install.ini ->  [Ver =  | Size = 1951 bytes | Modified Date = 9/8/2005 2:45:04 PM | Attr =	]

Setup.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Zoom_5041\Setup.ini ->  [Ver =  | Size = 138 bytes | Modified Date = 3/6/2005 11:43:42 PM | Attr =	]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\History\History.IE5\desktop.ini ->  [Ver =  | Size = 113 bytes | Modified Date = 8/14/2005 4:03:34 PM | Attr =  HS]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu101.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/16/2007 2:12:44 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu110.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/14/2007 4:15:47 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu114.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/21/2007 6:55:17 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu118.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 6/7/2007 8:19:59 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu121.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 4/10/2007 11:42:32 AM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu122.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/16/2007 3:57:46 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu140.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/22/2007 9:04:40 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu141.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/22/2007 6:15:33 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu143.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 10/15/2007 6:21:54 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu146.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/28/2007 2:54:18 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu14D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/17/2007 5:18:43 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu156.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 6/8/2007 7:26:19 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu16.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 8/10/2006 4:35:04 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu168.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/23/2007 11:44:01 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu17D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/13/2006 7:57:46 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu17E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/23/2007 9:06:42 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu18.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 6/9/2006 2:35:51 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu186.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/16/2007 4:52:56 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu19.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/3/2006 2:16:30 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu190.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/18/2007 3:05:05 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu199.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/29/2005 3:36:55 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 6/28/2006 3:03:10 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/1/2006 1:11:27 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1BF.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/17/2007 3:43:04 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1DE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 6/11/2007 4:14:50 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1E2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/18/2007 2:51:10 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1EA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/26/2007 2:33:00 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 7/11/2006 3:32:22 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1FE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/21/2007 2:18:54 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu20.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/15/2006 3:48:02 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu215.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/18/2006 8:00:37 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu217.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/27/2007 11:08:08 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu21E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 5/30/2007 8:10:41 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu232.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/27/2007 4:56:56 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu238.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/14/2006 5:30:40 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu24A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/31/2007 2:18:29 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu25.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/9/2007 6:07:30 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu251.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/22/2007 1:05:16 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu272.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/28/2007 3:10:45 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu28.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/6/2007 6:46:10 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu28B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/29/2007 5:03:23 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu29.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/11/2006 3:21:28 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/13/2006 7:44:55 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/18/2006 5:23:43 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 6/1/2007 5:23:23 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/30/2007 2:36:57 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/23/2007 1:01:45 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/3/2007 4:06:55 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/26/2005 3:36:32 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D5.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/30/2007 11:18:58 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2E4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/15/2006 3:53:42 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2F6.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/30/2005 2:34:40 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2FA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/28/2007 5:16:17 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu30.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/4/2007 6:00:15 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu31.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/10/2007 2:41:22 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu37.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 7/10/2006 4:44:52 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu37C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/27/2005 7:30:34 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu38.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/14/2006 4:41:03 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu387.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/20/2006 5:38:51 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu398.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/16/2006 3:26:03 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3B0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/1/2005 1:28:32 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/4/2006 6:29:05 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/14/2006 4:30:11 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 3/7/2007 5:23:00 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3ED.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/29/2007 9:34:24 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu44.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 7/24/2006 4:13:50 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu440.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/28/2005 4:44:34 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu45.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/19/2006 4:13:50 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu451.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/17/2006 4:45:05 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu459.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/2/2005 4:37:53 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu46.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/23/2007 2:51:51 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/15/2006 12:52:35 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 11/14/2007 2:41:48 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 3/8/2007 3:09:59 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/24/2006 1:50:16 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/11/2007 1:16:37 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4E2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/29/2005 3:21:18 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu53.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/5/2007 4:38:26 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu56F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/24/2006 12:56:14 AM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu5A0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/30/2005 3:17:39 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu5D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 6/12/2006 3:16:56 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu627.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/24/2006 6:06:49 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu63.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/15/2006 2:38:34 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu652.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/20/2006 8:31:34 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu656.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/5/2005 5:53:18 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 6/4/2007 9:14:52 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 7/25/2006 6:29:19 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6D3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 1/25/2006 4:59:49 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6E4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/1/2006 1:33:20 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6FA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/21/2006 2:42:14 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu70.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 6/13/2006 2:26:18 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu70C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/6/2005 4:23:07 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu71.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/24/2007 12:55:49 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu72.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/20/2006 7:22:04 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu78.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 4/6/2007 2:34:35 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu79F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/2/2006 12:27:36 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7AA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/22/2006 3:54:20 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7BB.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/7/2005 2:38:09 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/19/2007 1:44:08 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu81F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/27/2006 6:12:57 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu83.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/24/2007 2:47:54 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu855.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/3/2006 3:07:33 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu875.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/8/2005 5:45:20 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu8FD.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/24/2006 2:35:03 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu918.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/9/2005 3:35:26 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu93.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 991 bytes | Modified Date = 6/5/2007 6:54:28 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu97.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/25/2007 4:35:40 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu99.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/22/2006 2:38:45 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu9C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/14/2007 9:05:46 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu9F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/12/2007 3:25:36 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/25/2006 3:02:38 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB5.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/16/2006 1:47:09 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB9.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/12/2007 3:10:26 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB9D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/28/2006 5:08:26 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuBE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/25/2007 1:21:42 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/20/2007 5:16:08 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/15/2007 2:42:48 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/19/2007 11:19:58 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCB.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 11/15/2007 4:59:27 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCDA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/30/2006 4:23:09 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCF.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 991 bytes | Modified Date = 6/6/2007 12:18:01 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 9/27/2006 5:56:20 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 4/9/2007 1:37:12 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD70.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/31/2006 3:45:43 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuDE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/13/2007 5:06:29 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuE1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/28/2005 4:58:26 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuE2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 9/28/2006 4:53:11 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuEB4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/30/2006 11:59:27 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuF0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/21/2007 3:29:14 PM | Attr =	]

mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuF4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/20/2007 4:49:24 PM | Attr =	]

Abcpy.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Abcpy.ini ->  [Ver =  | Size = 3026 bytes | Modified Date = 4/4/2001 2:57:10 PM | Attr = R  ]

SETUP.INI -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SETUP.INI ->  [Ver =  | Size = 103 bytes | Modified Date = 3/28/2001 3:30:20 PM | Attr = R  ]

SVGViewer.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGViewer.ini ->  [Ver =  | Size = 0 bytes | Modified Date = 3/9/2001 11:13:50 AM | Attr = R  ]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\0VBZ2C5L\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DO985W5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4NID4BGZ\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4PSJ0B87\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDGP6RS5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT9AYMIS\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXOHAF4D\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\MR2V6PUB\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NUKZR50X\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]

desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]

options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr54b6.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 1/18/2005 12:34:27 PM | Attr =	]

options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr5665.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 12/29/2004 6:52:45 PM | Attr =	]

options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr77da.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 12/31/2004 8:21:29 PM | Attr =	]

options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr95d.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 1/14/2005 6:47:54 AM | Attr =	]

[Files Modified - Additional Folder Scans - Non-Microsoft Only]

Dell -> %AllUsersAppData%\Dell ->  [Folder | Modified Date = 1/28/2008 6:42:29 AM | Attr =	]

Lavasoft -> %AllUsersAppData%\Lavasoft ->  [Folder | Modified Date = 2/7/2008 5:46:33 PM | Attr =	]

SupportSoft -> %AllUsersAppData%\SupportSoft ->  [Folder | Modified Date = 1/28/2008 6:34:10 AM | Attr =	]

COMCASTTOOLBAR -> %UserAppData%\COMCASTTOOLBAR ->  [Folder | Modified Date = 2/11/2008 1:44:09 PM | Attr =	]

ApplicationHistory -> %LocalAppData%\ApplicationHistory ->  [Folder | Modified Date = 2/8/2008 9:05:32 AM | Attr =	]

SupportSoft -> %LocalAppData%\SupportSoft ->  [Folder | Modified Date = 2/5/2008 9:06:23 AM | Attr =	]

My Pictures -> %UserDocuments%\My Pictures ->  [Folder | Modified Date = 2/4/2008 9:14:13 AM | Attr = R  ]

2000 C:\Documents and Settings\Kelly\My Documents\*.tmp files -> C:\Documents and Settings\Kelly\My Documents\*.tmp -> 

Ad-Aware 2007.lnk -> %AllUsersDesktop%\Ad-Aware 2007.lnk ->  [Ver =  | Size = 1790 bytes | Modified Date = 2/7/2008 5:44:57 PM | Attr =	]

Ad-Watch 2007.lnk -> %AllUsersDesktop%\Ad-Watch 2007.lnk ->  [Ver =  | Size = 1790 bytes | Modified Date = 2/7/2008 5:44:57 PM | Attr =	]

Dell Support Center.lnk -> %AllUsersDesktop%\Dell Support Center.lnk ->  [Ver =  | Size = 2415 bytes | Modified Date = 2/8/2008 8:55:38 PM | Attr =	]

iTunes.lnk -> %AllUsersDesktop%\iTunes.lnk ->  [Ver =  | Size = 2137 bytes | Modified Date = 2/6/2008 6:05:09 PM | Attr =	]

ATF-Cleaner.exe -> %UserDesktop%\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 2/11/2008 1:37:18 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\ATF-Cleaner.exe:Zone.Identifier

Help and Support Center.lnk -> %UserDesktop%\Help and Support Center.lnk ->  [Ver =  | Size = 1936 bytes | Modified Date = 2/6/2008 10:05:20 AM | Attr =	]

TheWeatherChannel_dw5_Stubweather2.exe -> %UserDesktop%\TheWeatherChannel_dw5_Stubweather2.exe -> The Weather Channel Interactive [Ver = 4, 1, 0, 5 | Size = 277616 bytes | Modified Date = 1/31/2008 8:34:47 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\TheWeatherChannel_dw5_Stubweather2.exe:Zone.Identifier

Windows Update.lnk -> %UserDesktop%\Windows Update.lnk ->  [Ver =  | Size = 1930 bytes | Modified Date = 2/6/2008 10:05:23 AM | Attr =	]

WinPFind35u -> %UserDesktop%\WinPFind35u ->  [Folder | Modified Date = 2/11/2008 1:49:00 PM | Attr =	]

WinPFind35u.exe -> %UserDesktop%\WinPFind35u.exe ->  [Ver =  | Size = 481041 bytes | Modified Date = 2/11/2008 1:47:17 PM | Attr =	]

@Alternate Data Stream - 26 bytes -> %UserDesktop%\WinPFind35u.exe:Zone.Identifier

Adobe -> %CommonProgramFiles%\Adobe ->  [Folder | Modified Date = 1/20/2008 7:44:34 AM | Attr =	]

supportsoft -> %CommonProgramFiles%\supportsoft ->  [Folder | Modified Date = 1/28/2008 6:32:29 AM | Attr =	]

Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard ->  [Folder | Modified Date = 2/7/2008 5:42:05 PM | Attr =	]



< End of report >


#5 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 11 February 2008 - 04:11 PM

Hi kellydoz. Let's try this the easy way first.

Step #1

Open Notepad and copy/paste the text in the codebox below into the new document:

[Kill Explorer]
[Unregister Dlls]
[Registry - Non-Microsoft Only]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> msnmsgr -> %ProgramFiles%\MSN Messenger\msnmsgr.exe
YN -> WeatherDPA -> %ProgramFiles%\Hotbar\bin\10.0.368.0\Weather.exe
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YY -> gebcaww -> gebcaww.dll
YY -> naubekkj -> %System32%\naubekkj.dll
YY -> pmnll -> pmnll.dll
YY -> vtstr -> %System32%\vtstr.dll
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> 
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2} [HKEY_LOCAL_MACHINE] -> %System32%\vtsqq.dll [Reg Error: Value  does not exist or could not be read.]
YN -> {4115122B-85FF-4DD3-9515-F075BEDE5EB5} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YY -> {67ce851b-47ce-4ac9-833e-7ff4ece09e36} [HKEY_LOCAL_MACHINE] -> %System32%\lthcdugi.dll [Reg Error: Value  does not exist or could not be read.]
YY -> {A95B2816-1D7E-4561-A202-68C0DE02353A} [HKEY_LOCAL_MACHINE] -> %System32%\naubekkj.dll [Reg Error: Value  does not exist or could not be read.]
YN -> {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %System32%\msjava.dll [Sun Java Console]
[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > -> 
*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YN -> C:\WINDOWS\system32\vtsqq -> 
< BotCheck > -> 
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\America Online 9.0\waol.exe -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~1.0]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\SYSTEM32\LEXPPS.EXE -> C:\WINDOWS\SYSTEM32\LEXPPS.EXE [C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YPager.exe -> C:\Program Files\Yahoo!\Messenger\YPager.exe [C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\America Online 9.0\waol.exe -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AMERIC~1.0]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\msnmsgr.exe -> C:\Program Files\MSN Messenger\msnmsgr.exe [C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1]
YN -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\MSN Messenger\livecall.exe -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)]
[Files/Folders - Created Within 30 days]
NY -> fufrppig.ini -> %System32%\fufrppig.ini
NY -> gipprfuf.dll -> %System32%\gipprfuf.dll
NY -> lthcdugi.dll -> %System32%\lthcdugi.dll
NY -> naubekkj.dll -> %System32%\naubekkj.dll
NY -> naubekkj.dllbox -> %System32%\naubekkj.dllbox
NY -> nGpxx01 -> %System32%\nGpxx01
NY -> qqstv.ini -> %System32%\qqstv.ini
NY -> qqstv.ini2 -> %System32%\qqstv.ini2
NY -> sbhyqqpl.ini -> %System32%\sbhyqqpl.ini
NY -> cookies.ini -> %SystemRoot%\cookies.ini
[Files/Folders - Modified Within 30 days]
NY -> fufrppig.ini -> %System32%\fufrppig.ini
NY -> gipprfuf.dll -> %System32%\gipprfuf.dll
NY -> lthcdugi.dll -> %System32%\lthcdugi.dll
NY -> naubekkj.dll -> %System32%\naubekkj.dll
NY -> naubekkj.dllbox -> %System32%\naubekkj.dllbox
NY -> nGpxx01 -> %System32%\nGpxx01
NY -> qqstv.ini -> %System32%\qqstv.ini
NY -> qqstv.ini2 -> %System32%\qqstv.ini2
NY -> sbhyqqpl.ini -> %System32%\sbhyqqpl.ini
NY -> cookies.ini -> %SystemRoot%\cookies.ini
[Empty Temp Folders]
[Start Explorer]

Save the document to your desktop as wpf35.txt and close Notepad.

Step #2

Download SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Close SUPERAntiSpyware, we will come back to it later on.
Step #3

Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
Step #4

Start SUPERAntiSpyware again and run a scan by doing the following:
  • On the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.
Step #5

Now start WinPFind35U. Open Notepad and then open the wpf35.txt file that you saved to your desktop. Copy/paste the contents of the Notepad file into the WinPFind35u textbox where it says Paste Fix Here and click the Run Fix button.

The fix should only take a very short time. Your desktop will disappear and then reappear when the fix is complete, this is normal. You might be asked to reboot if any of the files could not be moved during the fix. If so, choose Yes and reboot the computer normally.

Step #6

Post the following back here:
  • the VundoFix log (c:\vundofix.txt)
  • the SUPERAntiSpyware report
  • the latest .log file from the WinPFind3u\MovedFiles folder (it will be a .log file and have a date_time name in the format mmddyyyy_hhmmss.log)
  • a new WinPFind35U report (just use the default settings)
I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#6 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 11 February 2008 - 10:01 PM

It freezes up when I try to run the fix. I don't know what I'm doing wrong.

#7 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 11 February 2008 - 10:15 PM

Hi kellydoz. Which fix? The WinPFind35 fix? If so, that just means that the infection is still active and we will need to use something else to remove it. Go ahead and do a new scan with the default optios and post that log along with the SuperAntiSpyware report.

Cheers.

OT

P.S. Before you run the new scan, delete the current copy of WinPFind35u.exe on your desktop and the WinPFind35u folder and download the latest version.

Edited by OldTimer, 11 February 2008 - 10:17 PM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#8 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 11 February 2008 - 11:40 PM

Here is the WinPFind35U log ran with default settings.

WinPFind35 logfile created on: 2/11/2008 10:35:12 PM
WinPFind35U Version Beta50	 Folder = C:\Documents and Settings\Kelly\Desktop\WinPFind35u
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
254.00 Mb Total Physical Memory | 100.90 Mb Available Physical Memory | 39.73% Memory free
625.04 Mb Paging File | 322.91 Mb Available in Paging File | 51.66% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 22.68 Gb Free Space | 59.30% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MACK
Current User Name: Kelly
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user

[Processes - Non-Microsoft Only]
aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
acsd.exe -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]
mcdetect.exe -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]
mcshield.exe -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]
mctskshd.exe -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]
ncupdatesvc.exe -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]
oasclnt.exe -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]
mcvsshld.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]
mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]
mcvsescn.exe -> %ProgramFiles%\McAfee.com\VSO\McVSEscn.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 483328 bytes | Modified Date = 7/8/2005 5:16:16 PM | Attr =	]
mm_tray.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
tgcmd.exe -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]
bcmsmmsg.exe -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]
mmtask.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
hpwuschd.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]
hpcmpmgr.exe -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr =	]
ymsgr_tray.exe -> %ProgramFiles%\Yahoo!\Messenger\Ymsgr_tray.exe -> Yahoo! Inc. [Ver = 8,1,0,0 | Size = 103928 bytes | Modified Date = 11/30/2006 9:49:06 PM | Attr =	]
hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]
pi monitor.exe -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]
vsaccess.exe -> %SystemDrive%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 2.0 | Size = 266240 bytes | Modified Date = 7/21/2000 2:34:52 PM | Attr =	]
ocrawr32.exe -> %SystemDrive%\OPLIMIT\OCRAWR32.EXE -> Caere Corporation [Ver = 5, 0, 0, 1 | Size = 41984 bytes | Modified Date = 3/19/1998 2:22:02 PM | Attr =	]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]
winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 309248 bytes | Modified Date = 2/11/2008 7:14:48 PM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
(AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 1:56:48 AM | Attr =	]
(DSBrokerService) DSBrokerService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\brkrsvc.exe ->  [Ver = 1, 0, 0, 8 | Size = 76848 bytes | Modified Date = 3/7/2007 2:47:46 PM | Attr =	]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]
(McDetect.exe) McAfee WSC Integration [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]
(McShield) McAfee.com McShield [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]
(McTskshd.exe) McAfee Task Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]
(mcupdmgr.exe) McAfee SecurityCenter Update Manager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee.com\Agent\mcupdmgr.exe -> McAfee, Inc [Ver = 6, 0, 0, 4 | Size = 245760 bytes | Modified Date = 7/1/2005 6:22:50 PM | Attr =	]
(NCUpdateSvc) Netscape Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\HPZipm12.exe -> HP [Ver = 7, 0, 0, 0 | Size = 65795 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
BCMSMMSG -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]
dscactivate -> %ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe ->   [Ver = 1.0.2767.18581 | Size = 16384 bytes | Modified Date = 11/15/2007 9:24:00 AM | Attr =	]
HP Component Manager -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]
MCAgentExe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]
MCUpdateExe -> %ProgramFiles%\McAfee.com\Agent\mcupdate.exe -> McAfee, Inc [Ver = 6, 0, 0, 21 | Size = 212992 bytes | Modified Date = 1/11/2006 12:05:42 PM | Attr =	]
mmtask -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
MMTray -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
OASClnt -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.3.1 | Size = 286720 bytes | Modified Date = 12/11/2007 10:56:54 AM | Attr =	]
tgcmd -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]
TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]
UserFaultCheck ->  -> File not found
VirusScan Online -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]
VSOCheckTask -> %ProgramFiles%\McAfee.com\VSO\mcmnhdlr.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 151552 bytes | Modified Date = 7/8/2005 5:18:22 PM | Attr =	]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr =	]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 9:49:04 PM | Attr =	]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 40048 bytes | Modified Date = 10/23/2006 1:48:20 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ->  [Ver = 8.0.0.0 | Size = 734872 bytes | Modified Date = 10/23/2006 12:01:50 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\PI Monitor.lnk -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]
< Kelly Startup Folder > -> C:\Documents and Settings\Kelly\Start Menu\Programs\Startup -> 
%UserProfile%\Start Menu\Programs\Startup\OCRAWARE.lnk -> %SystemDrive%\OPLIMIT\OCRAWARE.EXE -> Caere Corporation [Ver =  | Size = 51360 bytes | Modified Date = 7/18/1998 10:26:06 AM | Attr =	]
%UserProfile%\Start Menu\Programs\Startup\UMAX VistaAccess.lnk -> %SystemDrive%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 2.0 | Size = 266240 bytes | Modified Date = 7/21/2000 2:34:52 PM | Attr =	]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 12/20/2006 1:55:48 PM | Attr =	]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
!SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1046 | Size = 294912 bytes | Modified Date = 4/19/2007 1:41:36 PM | Attr =	]
igfxcui -> %SystemRoot%\SYSTEM32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 348160 bytes | Modified Date = 10/19/2005 7:59:14 AM | Attr =	]
pmnll -> pmnll.dll -> File not found
vtstr -> %SystemRoot%\system32\vtstr.dll -> File not found
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
< HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.yahoo.com/ -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.yahoo.com/ -> 
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://www.comcast.net/toolbar2.0/search/ -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://www.dell4me.com/myway -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Bar -> http://www.comcast.net/toolbar2.0/search/ -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.comcast.net -> 
HKEY_CURRENT_USER\: SearchURL\\ -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com[Reg Error: Value provider does not exist or could not be read.] -> 
HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
objects_aol.com [*] -> Out of zone range - ( 5 ) -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{4115122B-85FF-4DD3-9515-F075BEDE5EB5} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
{549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]
{5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\SYSTEM32\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.05b | Size = 106548 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]
{67ce851b-47ce-4ac9-833e-7ff4ece09e36} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\lthcdugi.dll [Reg Error: Value  does not exist or could not be read.] -> File not found
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
{BA52B914-B692-46c4-B683-905236F6F655} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee.com\VSO\mcvsshl.dll [McAfee VirusScan] -> McAfee, Inc. [Ver = 10, 0, 0, 19 | Size = 114688 bytes | Modified Date = 7/1/2005 7:44:30 PM | Attr =	]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\System32\msjava.dll [Sun Java Console] -> File not found
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}:{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! Services] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]
{669B269B-0D4E-41FB-A3D8-FD67CA94F646}:Exec ->  [ComcastHSI] -> File not found
{8828075D-D097-4055-AA02-2DBFA9D85E8A}:Exec ->  [Support] -> File not found
{97809617-3937-4F84-B335-9BB05EF1A8D4}:Exec ->  [Help] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&Yahoo! Search ->  -> File not found
Add to Windows &Live Favorites ->  -> File not found
Yahoo! &Dictionary ->  -> File not found
Yahoo! &Maps ->  -> File not found
Yahoo! &SMS ->  -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
Extension\.pdf -> %ProgramFiles%\Internet Explorer\PLUGINS\nppdf32.dll [Adobe Acrobat] -> File not found
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{0032BCDA-5210-4EC7-9BFA-77D00F012DC8} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{0990A63A-9C1D-4800-92AB-CB095EA7DE84} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{30709FBE-EF58-40D9-B4D2-DE076C914147} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{45D6247E-106B-46B8-A29C-FDA5061867CC} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{82E6535A-D32A-481B-9D7E-3D0693E66193} ->	(Broadcom 440x 10/100 Integrated Controller) -> 
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
Protocol_Catalog9\Catalog_Entries\000000000001 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000002 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000003 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000004 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000005 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000006 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000007 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000008 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000009 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000010 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000011 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000012 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000013 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000014 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000015 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000016 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000017 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000018 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000019 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000020 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000021 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000022 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000023 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000024 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000025 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000026 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000027 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\HP\hpcoretech\comp\hpuiprot.dll[CZipHandler Object] -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 81920 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{11260943-421B-11D0-8EAC-0000C07D88CF}[HKEY_LOCAL_MACHINE] -> http://www.ipix.com/viewers/ipixx.cab[iPIX ActiveX Control] -> 
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab[McAfee.com Operating System Class] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162985822921[MUWebControl Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] -> 
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab[DwnldGroupMgr Class] -> 
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 



[Files/Folders - Created Within 30 days]
09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier
aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier
HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier
HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier
VundoFix Backups -> %SystemDrive%\VundoFix Backups ->  [Folder | Created Date = 2/11/2008 4:09:28 PM | Attr =	]
2172 C:\*.tmp files -> C:\*.tmp -> 
fufrppig.ini -> %SystemRoot%\System32\fufrppig.ini ->  [Ver =  | Size = 1194402 bytes | Modified Date = 2/6/2008 4:21:29 PM | Attr =  HS]
nGpxx01 -> %SystemRoot%\System32\nGpxx01 ->  [Folder | Created Date = 2/4/2008 8:02:38 PM | Attr =	]
2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
qqstv.ini2 -> %SystemRoot%\System32\qqstv.ini2 ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:14:22 PM | Attr =  HS]
sbhyqqpl.ini -> %SystemRoot%\System32\sbhyqqpl.ini ->  [Ver =  | Size = 1192238 bytes | Modified Date = 2/4/2008 8:22:06 PM | Attr =  HS]
VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 2/11/2008 4:38:42 PM | Attr =	]
cookies.ini -> %SystemRoot%\cookies.ini ->  [Ver =  | Size = 177 bytes | Modified Date = 2/6/2008 4:21:58 PM | Attr =	]

[Files/Folders - Modified Within 30 days]
09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier
9f0e322cd95532de9dec04aff738e10c -> %SystemDrive%\9f0e322cd95532de9dec04aff738e10c ->  [Folder | Modified Date = 2/5/2008 9:50:23 AM | Attr =	]
2172 C:\*.tmp files -> C:\*.tmp -> 
aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 266407936 bytes | Modified Date = 2/11/2008 8:45:28 PM | Attr =  HS]
HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier
HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 2/11/2008 6:09:17 PM | Attr =	]
Temp -> %SystemDrive%\Temp ->  [Folder | Modified Date = 2/4/2008 8:02:36 PM | Attr =	]
VundoFix Backups -> %SystemDrive%\VundoFix Backups ->  [Folder | Modified Date = 2/11/2008 5:32:46 PM | Attr =	]
WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 2/11/2008 8:49:33 PM | Attr =	]
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 2/11/2008 8:51:55 PM | Attr =	]
2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
DRIVERS -> %SystemRoot%\System32\DRIVERS ->  [Folder | Modified Date = 2/7/2008 5:44:30 PM | Attr =	]
fufrppig.ini -> %SystemRoot%\System32\fufrppig.ini ->  [Ver =  | Size = 1194402 bytes | Modified Date = 2/6/2008 4:21:29 PM | Attr =  HS]
nGpxx01 -> %SystemRoot%\System32\nGpxx01 ->  [Folder | Modified Date = 2/4/2008 8:06:14 PM | Attr =	]
qqstv.ini2 -> %SystemRoot%\System32\qqstv.ini2 ->  [Ver =  | Size = 940614 bytes | Modified Date = 2/6/2008 5:14:22 PM | Attr =  HS]
sbhyqqpl.ini -> %SystemRoot%\System32\sbhyqqpl.ini ->  [Ver =  | Size = 1192238 bytes | Modified Date = 2/4/2008 8:22:06 PM | Attr =  HS]
VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 2/11/2008 4:38:42 PM | Attr =	]
WPA.DBL -> %SystemRoot%\System32\WPA.DBL ->  [Ver =  | Size = 1170 bytes | Modified Date = 2/11/2008 8:49:08 PM | Attr =	]
BOOTSTAT.DAT -> %SystemRoot%\BOOTSTAT.DAT ->  [Ver =  | Size = 2048 bytes | Modified Date = 2/11/2008 8:45:29 PM | Attr =   S]
cookies.ini -> %SystemRoot%\cookies.ini ->  [Ver =  | Size = 177 bytes | Modified Date = 2/6/2008 4:21:58 PM | Attr =	]
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 2/11/2008 3:43:35 PM | Attr =  HS]
1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
oplimit.ini -> %SystemRoot%\oplimit.ini ->  [Ver =  | Size = 732 bytes | Modified Date = 2/11/2008 8:43:44 PM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 2/11/2008 10:14:39 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 2/11/2008 8:47:37 PM | Attr =  H ]
SYSTEM32 -> %SystemRoot%\SYSTEM32 ->  [Folder | Modified Date = 2/11/2008 6:09:20 PM | Attr =	]
Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 2/11/2008 8:49:20 PM | Attr =	]
vista32.ini -> %SystemRoot%\vista32.ini ->  [Ver =  | Size = 1050 bytes | Modified Date = 2/11/2008 8:49:32 PM | Attr =	]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Modified Date = 2/1/2008 3:52:08 PM | Attr =	]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 2/11/2008 8:45:36 PM | Attr =  H ]
about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat ->  [Ver =  | Size = 1528 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat ->  [Ver =  | Size = 327746 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat ->  [Ver =  | Size = 102 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat ->  [Ver =  | Size = 12283223 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 15531 bytes | Modified Date = 2/8/2008 9:01:15 PM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 4232 bytes | Modified Date = 2/8/2008 9:05:13 PM | Attr =	]
getseal[1].com&size=S&use_flash=YES&use_transparent=YES&lang=en -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\MR2V6PUB\getseal[1].com ->  [Ver =  | Size = 3568 bytes | Modified Date = 10/6/2006 7:02:49 AM | Attr =	]
ChkTrust.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ChkTrust.exe -> Microsoft Corporation [Ver = 5.131.2134.1 | Size = 18192 bytes | Modified Date = 5/14/2004 6:42:00 AM | Attr =	]
messenger_update.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\messenger_update.exe ->  [Ver =  | Size = 606000 bytes | Modified Date = 8/29/2007 5:08:19 PM | Attr =	]
mofugclq.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\mofugclq.exe -> Locus Software, Inc. [Ver = 1.3.122.1 | Size = 259336 bytes | Modified Date = 2/7/2008 5:13:44 PM | Attr =	]
qrjatydi.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\qrjatydi.exe -> Locus Software, Inc. [Ver = 1.3.122.1 | Size = 259336 bytes | Modified Date = 2/7/2008 10:06:52 AM | Attr =	]
SSUPDATE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\SSUPDATE.EXE -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 146672 bytes | Modified Date = 6/21/2007 2:07:10 PM | Attr =	]
TA2004_1_42_0_0_1_XP.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\TA2004_1_42_0_0_1_XP.exe ->  [Ver =  | Size = 32767 bytes | Modified Date = 5/14/2004 6:41:48 AM | Attr =	]
TA2004_1_42_0_0_1_XP_P.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\TA2004_1_42_0_0_1_XP_P.exe -> EarthLink, Inc.											  [Ver = 2004.1.42.0												  | Size = 16098864 bytes | Modified Date = 5/13/2004 8:03:34 PM | Attr =	]
yacscom_update.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\yacscom_update.exe ->  [Ver =  | Size = 285696 bytes | Modified Date = 4/3/2007 4:21:54 PM | Attr =	]
ytb_6.3.4.0_pub_us_setup_.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ytb_6.3.4.0_pub_us_setup_.exe ->  [Ver =  | Size = 962072 bytes | Modified Date = 9/20/2006 4:27:48 AM | Attr =	]
ywc_update2.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ywc_update2.exe ->  [Ver =  | Size = 302648 bytes | Modified Date = 6/8/2007 10:28:58 PM | Attr =	]
691 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 
CDVIEWER.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\CDVIEWER.EXE -> Noritsu KOKI [Ver = 2, 0, 0, 25 | Size = 2732544 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]
ShFolder.Exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\ShFolder.Exe -> Microsoft Corporation [Ver = 5.50.4027.300 | Size = 117288 bytes | Modified Date = 4/16/2001 4:39:02 PM | Attr =	]
HSBR.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP2.DIR\_ISTMP0.DIR\HSBR.exe -> Leader Technologies/Hasbro [Ver = 1, 0, 0, 1 | Size = 4789248 bytes | Modified Date = 7/29/1999 3:01:16 PM | Attr =	]
install.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\install.exe -> SupportSoft, Inc. [Ver = 6,2,399,0 | Size = 1321104 bytes | Modified Date = 3/4/2005 2:25:38 PM | Attr =	]
cipherchk.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\cipherchk.exe -> SupportSoft, Inc. [Ver = 1, 0, 0, 1 | Size = 55488 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]
Encpack_Win2000_EN.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\Encpack_Win2000_EN.exe -> Microsoft Corporation [Ver = 5.00.2150.1 | Size = 193768 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]
ie501dom.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\ie501dom.exe -> Microsoft Corporation [Ver = 5.00.2013.1301 | Size = 218704 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]
ie5dom.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\cipher\ie5dom.exe -> Microsoft Corporation [Ver = 5.00.2013.1301 | Size = 219216 bytes | Modified Date = 1/18/2005 1:02:38 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60194E\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:00:14 PM | Attr =	]
Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60194E\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:00:14 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60678E\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:01:34 PM | Attr =	]
Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60678E\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:01:34 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60740EUW\Setup.exe ->															  [Ver = 1.10.35.1002												 | Size = 1757905 bytes | Modified Date = 3/6/2005 11:02:54 PM | Attr =	]
Uninstall.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Ambit_60740EUW\Uninstall.exe ->															  [Ver = 2.10.35.1003												 | Size = 1550480 bytes | Modified Date = 3/6/2005 11:02:54 PM | Attr =	]
SETUP.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Belkin_F5D5530-W\SETUP.EXE ->  [Ver =  | Size = 2016768 bytes | Modified Date = 3/6/2005 11:07:52 PM | Attr =	]
UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\2k\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:04 PM | Attr =	]
UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\98\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:12 PM | Attr =	]
UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\me\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:16 PM | Attr =	]
UNBXNTCM.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Broadxant_8601\xp\UNBXNTCM.exe -> Broadxent, Inc. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:15:22 PM | Attr =	]
Remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Castlenet_DP1110XB2\Remove.exe ->  [Ver =  | Size = 32768 bytes | Modified Date = 3/6/2005 11:18:18 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Com21_DP1110\REMOVE.EXE ->  [Ver =  | Size = 463872 bytes | Modified Date = 3/6/2005 11:18:28 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Com21_DP1110XB\REMOVE.EXE ->  [Ver =  | Size = 463872 bytes | Modified Date = 3/6/2005 11:18:38 PM | Attr =	]
UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10_H\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:32 PM | Attr =	]
UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10_V\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:34 PM | Attr =	]
UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v2\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 004 | Size = 13484 bytes | Modified Date = 3/6/2005 11:25:38 PM | Attr =	]
UNBEFCM.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v2\patch\UNBEFCM.EXE -> Linksys Corp. [Ver = 1.00 Build 005 | Size = 13490 bytes | Modified Date = 3/6/2005 11:28:10 PM | Attr =	]
UNBEFCM3.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_BEFCMU10v3\UNBEFCM3.exe -> Linksys. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:25:42 PM | Attr =	]
UNWCGB.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Linksys_WCG200\UNWCGB.exe -> Linksys. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:25:44 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4100\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:25:52 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4101\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:25:58 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4200\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:29:18 PM | Attr =	]
CLEANUP.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB4220\CLEANUP.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:29:26 PM | Attr =	]
RemoveUSB.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB5100\RemoveUSB.exe ->  [Ver = 1, 0, 0, 1 | Size = 385024 bytes | Modified Date = 3/6/2005 11:29:34 PM | Attr =	]
remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SB5120\remove.exe ->  [Ver = 1, 0, 0, 1 | Size = 389120 bytes | Modified Date = 3/6/2005 11:29:42 PM | Attr =	]
REMOVE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SBG1000\REMOVE.EXE -> Motorola BCS [Ver = 2.5 | Size = 274432 bytes | Modified Date = 3/6/2005 11:55:54 PM | Attr =	]
remove.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Motorola_SBG900\remove.exe ->  [Ver = 1, 0, 0, 1 | Size = 389120 bytes | Modified Date = 3/6/2005 11:56:02 PM | Attr =	]
UNDPX2A.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DCP2100\UNDPX2A.EXE ->  [Ver = 2, 8, 4, 0 | Size = 135168 bytes | Modified Date = 3/6/2005 11:48:56 PM | Attr =	]
UNDPX2K.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DCP2100\UNDPX2K.EXE ->  [Ver = 2, 8, 2, 0 | Size = 135168 bytes | Modified Date = 3/6/2005 11:48:56 PM | Attr =	]
undpx.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX100\undpx.exe -> Scientific Atlanta. [Ver = 1.00 Build 004 | Size = 13490 bytes | Modified Date = 3/6/2005 11:48:58 PM | Attr =	]
undpx.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX110\undpx.exe -> Scientific Atlanta. [Ver = 1.00 Build 004 | Size = 13490 bytes | Modified Date = 3/6/2005 11:49:02 PM | Attr =	]
UNDPX.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SA_DPX2100\UNDPX.exe -> Scientific Atlanta. [Ver = 1.00 Build 006 | Size = 14011 bytes | Modified Date = 3/6/2005 11:49:04 PM | Attr =	]
setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SMC_8002\setup.exe ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/6/2005 11:49:08 PM | Attr =	]
setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SMC_8011CM-B\setup.exe ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/6/2005 11:49:16 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\SpeedStream_SS6101\Setup.exe ->															  [Ver = 1.10.35.1001												 | Size = 3695494 bytes | Modified Date = 3/6/2005 11:48:04 PM | Attr =	]
pcx2000-usbscrub.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Toshiba_PCX2000\pcx2000-usbscrub.exe ->  [Ver =  | Size = 41984 bytes | Modified Date = 3/6/2005 11:45:32 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Zoom_5041\Setup.exe -> InstallShield Software Corporation [Ver = 6, 31, 100, 1190 | Size = 56320 bytes | Modified Date = 3/6/2005 11:43:42 PM | Attr =	]
chsi_uninstaller.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\uninstall\chsi_uninstaller.exe -> Comcast Cable Communications, LLC.						   [Ver = 2.1														  | Size = 330312 bytes | Modified Date = 7/22/2005 1:01:42 PM | Attr =	]
Setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Setup.exe -> InstallShield Software Corporation [Ver = 5, 52, 164, 0 | Size = 73728 bytes | Modified Date = 1/12/1999 11:42:20 AM | Attr = R  ]
_ISDel.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\_ISDel.exe -> InstallShield Software Corporation [Ver = 5, 51, 138, 0 | Size = 27648 bytes | Modified Date = 10/27/1998 12:06:48 PM | Attr = R  ]
AcroRd32.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\AcroRd32.exe -> Adobe Systems Incorporated [Ver = 5.0.1.2001032700 | Size = 3870784 bytes | Modified Date = 3/27/2001 9:44:58 PM | Attr = R  ]
Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Walgreens PhotoShow Express CD.exe -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 79076 bytes | Modified Date = 12/5/2004 7:42:06 PM | Attr =	]
photoshow_express_setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\app\shared\data\photoshow_express_setup.exe -> Simple Star, Inc. [Ver = 3.0.0.97 | Size = 480520 bytes | Modified Date = 8/5/2005 2:06:12 PM | Attr =	]
Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\boot_strap\Walgreens PhotoShow Express CD.exe -> Simple Star, Inc. [Ver = 3.0.1.177 | Size = 135168 bytes | Modified Date = 8/5/2005 3:02:20 PM | Attr =	]
Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Walgreens PhotoShow Express CD.exe -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 79076 bytes | Modified Date = 5/12/2006 4:57:51 PM | Attr =	]
photoshow_express_setup.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\app\shared\data\photoshow_express_setup.exe -> Simple Star, Inc. [Ver = 4.5.1.55 | Size = 4308236 bytes | Modified Date = 7/24/2006 12:12:47 PM | Attr =	]
Walgreens PhotoShow Express CD.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\boot_strap\Walgreens PhotoShow Express CD.exe -> Simple Star, Inc. [Ver = 4.0.0.88 | Size = 139264 bytes | Modified Date = 10/11/2006 1:08:18 PM | Attr =	]
acsdir.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\acsdir.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 8/6/2003 4:02:18 PM | Attr =	]
AOLFirewallMgr.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLFirewallMgr.dll -> America Online, Inc. [Ver = 1, 0, 0, 0 | Size = 57344 bytes | Modified Date = 5/12/2004 1:53:48 PM | Attr =	]
AOLInstallerFW.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLInstallerFW.dll -> America Online, Inc. [Ver = 1, 0, 0, 0 | Size = 73728 bytes | Modified Date = 5/12/2004 1:53:48 PM | Attr =	]
InstHelp.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\InstHelp.dll ->  [Ver =  | Size = 56832 bytes | Modified Date = 8/5/2004 6:35:14 PM | Attr =	]
shfolder.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\shfolder.dll -> Microsoft Corporation [Ver = 5.50.4522.1800 | Size = 23312 bytes | Modified Date = 2/21/2003 9:24:20 AM | Attr =	]
uninst.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\uninst.dll ->  [Ver =  | Size = 110592 bytes | Modified Date = 9/24/2003 10:42:16 AM | Attr =	]
wyb64.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\wyb64.dll -> Yahoo! Inc. [Ver = 2004.12.4.1 | Size = 58464 bytes | Modified Date = 12/3/2004 2:34:26 PM | Attr =	]
yvertr.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\yvertr.dll ->  [Ver = 2004, 1, 15, 1 | Size = 42080 bytes | Modified Date = 1/15/2004 1:48:38 PM | Attr =	]
691 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 
EXIF.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\EXIF.DLL -> FUJI PHOTO FILM CO., LTD [Ver = 2, 3, 4, 0 | Size = 548352 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]
IJL11.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\$CD_Viewer\IJL11.DLL -> Intel Corporation [Ver = 1.1.2 | Size = 180224 bytes | Modified Date = 8/8/2006 11:04:44 AM | Attr = R  ]
BrwsrPI.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\BrwsrPI.dll -> Adobe Systems, Inc. [Ver = 5.05 | Size = 53248 bytes | Modified Date = 8/8/2001 9:22:42 PM | Attr =	]
IccTest.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\IccTest.dll -> Adobe Systems, Inc. [Ver = 1.2 | Size = 126976 bytes | Modified Date = 8/7/2001 4:48:00 PM | Attr =	]
Permission.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\Permission.dll ->  [Ver = 1.1 | Size = 98304 bytes | Modified Date = 4/16/2001 4:39:02 PM | Attr =	]
sdcnetcheck.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\sdcnetcheck.dll -> SupportSoft, Inc. [Ver = 6,0,1023,0 | Size = 202320 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
ssctlnwk.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\ssctlnwk.dll -> SupportSoft, Inc. [Ver = 6,0,1148,0 | Size = 292432 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
tgctlcm.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlcm.dll -> SupportSoft, Inc. [Ver = 6,0,997,0 | Size = 222800 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
tgctlpw.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlpw.dll -> SupportSoft, Inc. [Ver = 6,0,1334,0 | Size = 112208 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
tgctlsi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tgctlsi.dll -> Support.com, Inc. [Ver = 5,5,741,0 | Size = 1701456 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
tglib.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\bin\tglib.dll -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 2180688 bytes | Modified Date = 1/18/2005 12:55:50 PM | Attr =	]
mPlayer.3.1.1b.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\mProjector1101327051\mPlayer.3.1.1b.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 2/9/2008 9:37:27 AM | Attr =	]
_Setup.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\_Setup.dll -> InstallShield Software Corporation [Ver = 5, 50, 134, 0 | Size = 34816 bytes | Modified Date = 9/29/1998 4:34:56 PM | Attr = R  ]
AceLite.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\AceLite.dll -> Adobe Systems, Incorporated [Ver = 1.02.00 | Size = 397312 bytes | Modified Date = 2/28/2001 9:29:36 AM | Attr = R  ]
ACROFX32.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\ACROFX32.DLL ->  [Ver =  | Size = 53248 bytes | Modified Date = 5/12/2000 6:30:02 PM | Attr = R  ]
Agm.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Agm.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1138688 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]
Bib.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Bib.dll -> Adobe Systems, Incorporated [Ver = 1.0.20 | Size = 147456 bytes | Modified Date = 1/20/2001 10:13:36 PM | Attr = R  ]
CoolType.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\CoolType.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1441792 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]
msvcp60.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\msvcp60.dll -> Microsoft Corporation [Ver = 6.00.8168.0 | Size = 401462 bytes | Modified Date = 12/1/1999 12:40:28 AM | Attr = R  ]
msvcrt.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\msvcrt.dll -> Microsoft Corporation [Ver = 6.00.8397.0 | Size = 266293 bytes | Modified Date = 2/11/1999 3:33:58 AM | Attr = R  ]
oleaut32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\oleaut32.dll -> Microsoft Corporation [Ver = 2.30.4261 | Size = 598288 bytes | Modified Date = 6/18/1998 11:33:08 AM | Attr = R  ]
WHA Library.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\WHA Library.dll -> Adobe Systems Incorporated [Ver = 0.2.0.0 | Size = 167936 bytes | Modified Date = 3/15/2001 6:14:38 AM | Attr = R  ]
nppdf32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Browser\nppdf32.dll -> Adobe Systems Inc. [Ver = 5.0.0.2001031500 | Size = 103312 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]
NPDocBox.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\InterTrust\NPDocBox.dll -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 3/14/2001 4:52:06 AM | Attr = R  ]
QT2.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT2.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 24576 bytes | Modified Date = 3/15/2001 6:00:24 AM | Attr = R  ]
QT3.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT3.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 32768 bytes | Modified Date = 3/15/2001 6:00:42 AM | Attr = R  ]
QT4.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\plug_ins\Movie\QT4.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 36864 bytes | Modified Date = 3/15/2001 6:01:02 AM | Attr = R  ]
Uninst.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Reader\Uninstall\Uninst.dll -> Adobe Systems, Inc. [Ver = 4.0.11 | Size = 81920 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]
NPSVGVw.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\NPSVGVw.dll -> Adobe Systems Inc. [Ver = 2, 0, 0, 55 | Size = 299059 bytes | Modified Date = 3/14/2001 2:10:56 PM | Attr = R  ]
SVGControl.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGControl.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 491574 bytes | Modified Date = 3/14/2001 2:14:00 PM | Attr = R  ]
SVGRSRC.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGRSRC.DLL ->  [Ver =  | Size = 12288 bytes | Modified Date = 3/14/2001 2:06:24 PM | Attr = R  ]
SVGView.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGView.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 1597491 bytes | Modified Date = 3/14/2001 2:07:52 PM | Attr = R  ]
eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\eBayISAPI[1].dll ->  [Ver =  | Size = 9591 bytes | Modified Date = 10/10/2006 8:38:19 AM | Attr =	]
eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\eBayISAPI[2].dll ->  [Ver =  | Size = 9495 bytes | Modified Date = 10/10/2006 8:38:47 AM | Attr =	]
eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[1].dll ->  [Ver =  | Size = 5147 bytes | Modified Date = 10/9/2006 12:03:50 PM | Attr =	]
eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[2].dll ->  [Ver =  | Size = 17869 bytes | Modified Date = 10/9/2006 12:18:49 PM | Attr =	]
eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[3].dll ->  [Ver =  | Size = 18151 bytes | Modified Date = 10/9/2006 2:09:18 PM | Attr =	]
eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[4].dll ->  [Ver =  | Size = 19125 bytes | Modified Date = 10/9/2006 2:17:10 PM | Attr =	]
eBayISAPI[5].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[5].dll ->  [Ver =  | Size = 10370 bytes | Modified Date = 10/9/2006 2:19:37 PM | Attr =	]
eBayISAPI[6].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\eBayISAPI[6].dll ->  [Ver =  | Size = 7817 bytes | Modified Date = 10/9/2006 2:21:59 PM | Attr =	]
eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[1].dll ->  [Ver =  | Size = 16154 bytes | Modified Date = 10/9/2006 12:05:52 PM | Attr =	]
eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[2].dll ->  [Ver =  | Size = 2709 bytes | Modified Date = 10/9/2006 12:26:39 PM | Attr =	]
eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[3].dll ->  [Ver =  | Size = 17888 bytes | Modified Date = 10/9/2006 12:40:09 PM | Attr =	]
eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[4].dll ->  [Ver =  | Size = 10338 bytes | Modified Date = 10/10/2006 11:34:50 AM | Attr =	]
eBayISAPI[5].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\eBayISAPI[5].dll ->  [Ver =  | Size = 7535 bytes | Modified Date = 10/10/2006 11:35:09 AM | Attr =	]
eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[1].dll ->  [Ver =  | Size = 3828 bytes | Modified Date = 10/9/2006 11:49:38 AM | Attr =	]
eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[2].dll ->  [Ver =  | Size = 4413 bytes | Modified Date = 10/9/2006 11:53:00 AM | Attr =	]
eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[3].dll ->  [Ver =  | Size = 9882 bytes | Modified Date = 10/9/2006 12:37:09 PM | Attr =	]
eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\eBayISAPI[4].dll ->  [Ver =  | Size = 9808 bytes | Modified Date = 10/9/2006 12:41:37 PM | Attr =	]
eBayISAPI[1].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[1].dll ->  [Ver =  | Size = 4584 bytes | Modified Date = 10/9/2006 11:49:09 AM | Attr =	]
eBayISAPI[2].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[2].dll ->  [Ver =  | Size = 4728 bytes | Modified Date = 10/9/2006 12:27:28 PM | Attr =	]
eBayISAPI[3].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[3].dll ->  [Ver =  | Size = 18350 bytes | Modified Date = 10/9/2006 12:35:07 PM | Attr =	]
eBayISAPI[4].dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\eBayISAPI[4].dll ->  [Ver =  | Size = 7851 bytes | Modified Date = 10/9/2006 12:43:09 PM | Attr =	]
UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr54b6.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 1/18/2005 12:34:27 PM | Attr =	]
UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr5665.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 12/29/2004 6:52:45 PM | Attr =	]
UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr77da.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 12/31/2004 8:21:29 PM | Attr =	]
UpdateInfo.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr95d.tmp\UpdateInfo.dll ->  [Ver = 2, 0, 0, 19 | Size = 24651 bytes | Modified Date = 1/14/2005 6:47:54 AM | Attr =	]
simple_jpeg.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\boot_strap\simple_jpeg.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 9/9/2004 7:34:24 PM | Attr =	]
Dirapi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Dirapi.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 1097728 bytes | Modified Date = 5/18/2004 6:20:15 PM | Attr =	]
Iml32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Iml32.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 561152 bytes | Modified Date = 5/18/2004 6:20:15 PM | Attr =	]
Proj.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 3_0_0 0177\Xtras\Proj.dll -> Macromedia, Inc. [Ver = 8.5.1r102 | Size = 151552 bytes | Modified Date = 5/18/2004 6:20:16 PM | Attr =	]
simple_jpeg.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\boot_strap\simple_jpeg.dll ->  [Ver =  | Size = 126976 bytes | Modified Date = 5/12/2006 5:45:11 PM | Attr =	]
Dirapi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Dirapi.dll -> Macromedia, Inc. [Ver = 8.5.1r104 | Size = 1097728 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]
Iml32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Iml32.dll -> Macromedia, Inc. [Ver = 8.5.1r104 | Size = 561152 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]
Proj.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\Walgreens PhotoShow Express CD 4_0_0 0088\Xtras\Proj.dll -> Macromedia, Inc. [Ver = 9.0r371 | Size = 159744 bytes | Modified Date = 7/18/2006 1:10:51 PM | Attr =	]
AIM_PH.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\AIM_PH.dat ->  [Ver =  | Size = 287 bytes | Modified Date = 5/25/2005 10:42:06 AM | Attr =	]
Perflib_Perfdata_100.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_100.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 11/9/2007 11:32:08 AM | Attr =	]
Perflib_Perfdata_1a40.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_1a40.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/23/2007 7:54:47 AM | Attr =	]
Perflib_Perfdata_1cc8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_1cc8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 5/10/2007 5:56:39 AM | Attr =	]
Perflib_Perfdata_22c.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_22c.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 1/9/2008 5:51:55 AM | Attr =	]
Perflib_Perfdata_24f4.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_24f4.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 9/20/2007 4:25:52 PM | Attr =	]
Perflib_Perfdata_330.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_330.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/29/2006 8:22:44 AM | Attr =	]
Perflib_Perfdata_454.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_454.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 11/13/2007 12:54:50 PM | Attr =	]
Perflib_Perfdata_8c0.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_8c0.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 1/20/2008 1:26:24 PM | Attr =	]
Perflib_Perfdata_a08.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_a08.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/20/2006 4:54:29 PM | Attr =	]
Perflib_Perfdata_abc.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_abc.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/21/2007 4:20:06 PM | Attr =	]
Perflib_Perfdata_b50.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_b50.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 10/13/2006 1:16:10 PM | Attr =	]
Perflib_Perfdata_de8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_de8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 7/17/2006 5:29:16 PM | Attr =	]
Perflib_Perfdata_fa8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_fa8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 2/6/2008 8:11:55 AM | Attr =	]
Perflib_Perfdata_fac.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_fac.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 6/26/2007 1:38:18 PM | Attr =	]
Perflib_Perfdata_ff8.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Perflib_Perfdata_ff8.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 4/13/2006 12:25:24 PM | Attr =	]
691 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 
index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\index.dat ->  [Ver =  | Size = 65536 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]
index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\History\History.IE5\index.dat ->  [Ver =  | Size = 917504 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]
lang.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\lang.dat ->  [Ver =  | Size = 23541 bytes | Modified Date = 1/12/1999 10:34:42 AM | Attr = R  ]
os.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\os.dat ->  [Ver =  | Size = 450 bytes | Modified Date = 7/27/1998 5:41:06 PM | Attr = R  ]
index.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat ->  [Ver =  | Size = 9158656 bytes | Modified Date = 10/12/2006 6:40:08 PM | Attr =	]
AOLFirewallMgr.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\AOLFirewallMgr.ini ->  [Ver =  | Size = 6460 bytes | Modified Date = 5/12/2004 1:53:28 PM | Attr =	]
smi.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\smi.ini ->  [Ver =  | Size = 868 bytes | Modified Date = 5/14/2004 6:41:16 AM | Attr =	]
691 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 
AdobeIns.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\_ISTMP1.DIR\_ISTMP0.DIR\AdobeIns.ini ->  [Ver =  | Size = 6260 bytes | Modified Date = 9/17/2001 5:58:18 PM | Attr =	]
install.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\install.ini ->  [Ver =  | Size = 1951 bytes | Modified Date = 9/8/2005 2:45:04 PM | Attr =	]
Setup.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\ComcastHSI Install Wizard\drivers\Zoom_5041\Setup.ini ->  [Ver =  | Size = 138 bytes | Modified Date = 3/6/2005 11:43:42 PM | Attr =	]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\History\History.IE5\desktop.ini ->  [Ver =  | Size = 113 bytes | Modified Date = 8/14/2005 4:03:34 PM | Attr =  HS]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu101.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/16/2007 2:12:44 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu110.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/14/2007 4:15:47 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu114.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/21/2007 6:55:17 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu118.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 6/7/2007 8:19:59 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu121.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 4/10/2007 11:42:32 AM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu122.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/16/2007 3:57:46 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu140.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/22/2007 9:04:40 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu141.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/22/2007 6:15:33 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu143.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 10/15/2007 6:21:54 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu146.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/28/2007 2:54:18 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu14D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/17/2007 5:18:43 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu156.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 6/8/2007 7:26:19 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu16.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 8/10/2006 4:35:04 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu168.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/23/2007 11:44:01 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu17D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/13/2006 7:57:46 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu17E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/23/2007 9:06:42 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu18.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 6/9/2006 2:35:51 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu186.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/16/2007 4:52:56 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu19.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/3/2006 2:16:30 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu190.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/18/2007 3:05:05 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu199.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/29/2005 3:36:55 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 6/28/2006 3:03:10 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/1/2006 1:11:27 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1BF.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/17/2007 3:43:04 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1DE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 6/11/2007 4:14:50 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1E2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 10/18/2007 2:51:10 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1EA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/26/2007 2:33:00 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 7/11/2006 3:32:22 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu1FE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/21/2007 2:18:54 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu20.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/15/2006 3:48:02 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu215.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/18/2006 8:00:37 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu217.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/27/2007 11:08:08 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu21E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 5/30/2007 8:10:41 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu232.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/27/2007 4:56:56 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu238.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/14/2006 5:30:40 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu24A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/31/2007 2:18:29 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu25.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/9/2007 6:07:30 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu251.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/22/2007 1:05:16 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu272.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/28/2007 3:10:45 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu28.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/6/2007 6:46:10 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu28B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/29/2007 5:03:23 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu29.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/11/2006 3:21:28 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/13/2006 7:44:55 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/18/2006 5:23:43 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 6/1/2007 5:23:23 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2B3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/30/2007 2:36:57 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/23/2007 1:01:45 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/3/2007 4:06:55 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/26/2005 3:36:32 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2D5.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/30/2007 11:18:58 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2E4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/15/2006 3:53:42 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2F6.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/30/2005 2:34:40 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu2FA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/28/2007 5:16:17 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu30.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/4/2007 6:00:15 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu31.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/10/2007 2:41:22 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu37.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 7/10/2006 4:44:52 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu37C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/27/2005 7:30:34 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu38.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/14/2006 4:41:03 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu387.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/20/2006 5:38:51 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu398.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/16/2006 3:26:03 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3B0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/1/2005 1:28:32 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 5/4/2006 6:29:05 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 9/14/2006 4:30:11 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 3/7/2007 5:23:00 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu3ED.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 11/29/2007 9:34:24 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu44.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 7/24/2006 4:13:50 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu440.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/28/2005 4:44:34 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu45.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/19/2006 4:13:50 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu451.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/17/2006 4:45:05 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu459.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/2/2005 4:37:53 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu46.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/23/2007 2:51:51 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4A.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 8/15/2006 12:52:35 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 11/14/2007 2:41:48 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 3/8/2007 3:09:59 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/24/2006 1:50:16 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4E.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/11/2007 1:16:37 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu4E2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/29/2005 3:21:18 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu53.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 4/5/2007 4:38:26 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu56F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/24/2006 12:56:14 AM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu5A0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/30/2005 3:17:39 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu5D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 6/12/2006 3:16:56 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu627.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/24/2006 6:06:49 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu63.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/15/2006 2:38:34 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu652.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/20/2006 8:31:34 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu656.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/5/2005 5:53:18 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6B.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 992 bytes | Modified Date = 6/4/2007 9:14:52 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 7/25/2006 6:29:19 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6D3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 1/25/2006 4:59:49 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6E4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/1/2006 1:33:20 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu6FA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/21/2006 2:42:14 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu70.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 6/13/2006 2:26:18 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu70C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/6/2005 4:23:07 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu71.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/24/2007 12:55:49 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu72.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 1000 bytes | Modified Date = 9/20/2006 7:22:04 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu78.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 4/6/2007 2:34:35 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu79F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/2/2006 12:27:36 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7AA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/22/2006 3:54:20 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7BB.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 12/7/2005 2:38:09 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu7C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/19/2007 1:44:08 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu81F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 1/27/2006 6:12:57 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu83.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 5/24/2007 2:47:54 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu855.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 1/3/2006 3:07:33 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu875.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/8/2005 5:45:20 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu8FD.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 3/24/2006 2:35:03 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu918.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 12/9/2005 3:35:26 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu93.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 991 bytes | Modified Date = 6/5/2007 6:54:28 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu97.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 4/25/2007 4:35:40 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu99.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/22/2006 2:38:45 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu9C.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/14/2007 9:05:46 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcu9F.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 10/12/2007 3:25:36 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 9/25/2006 3:02:38 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB5.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/16/2006 1:47:09 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB9.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 3/12/2007 3:10:26 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuB9D.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/28/2006 5:08:26 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuBE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 993 bytes | Modified Date = 5/25/2007 1:21:42 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/20/2007 5:16:08 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 999 bytes | Modified Date = 5/15/2007 2:42:48 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuC3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/19/2007 11:19:58 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCB.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 11/15/2007 4:59:27 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCDA.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 994 bytes | Modified Date = 3/30/2006 4:23:09 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuCF.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 991 bytes | Modified Date = 6/6/2007 12:18:01 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 9/27/2006 5:56:20 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD3.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 4/9/2007 1:37:12 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuD70.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/31/2006 3:45:43 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuDE.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/13/2007 5:06:29 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuE1.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 11/28/2005 4:58:26 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuE2.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 9/28/2006 4:53:11 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuEB4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 1/30/2006 11:59:27 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuF0.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 995 bytes | Modified Date = 3/21/2007 3:29:14 PM | Attr =	]
mcdelta.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\mcuF4.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 997 bytes | Modified Date = 11/20/2007 4:49:24 PM | Attr =	]
Abcpy.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\Abcpy.ini ->  [Ver =  | Size = 3026 bytes | Modified Date = 4/4/2001 2:57:10 PM | Attr = R  ]
SETUP.INI -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SETUP.INI ->  [Ver =  | Size = 103 bytes | Modified Date = 3/28/2001 3:30:20 PM | Attr = R  ]
SVGViewer.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\pft754~tmp\SVG Files\SVGViewer.ini ->  [Ver =  | Size = 0 bytes | Modified Date = 3/9/2001 11:13:50 AM | Attr = R  ]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\0VBZ2C5L\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DO985W5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4NID4BGZ\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4PSJ0B87\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDGP6RS5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT9AYMIS\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/3/2006 6:08:29 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXOHAF4D\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\MR2V6PUB\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/5/2006 7:40:09 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NUKZR50X\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/6/2006 1:16:47 PM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]
desktop.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 10/9/2006 10:37:46 AM | Attr =  HS]
options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr54b6.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 1/18/2005 12:34:27 PM | Attr =	]
options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr5665.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 12/29/2004 6:52:45 PM | Attr =	]
options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr77da.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 12/31/2004 8:21:29 PM | Attr =	]
options.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\vmgr95d.tmp\options.ini ->  [Ver =  | Size = 79 bytes | Modified Date = 1/14/2005 6:47:54 AM | Attr =	]
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat ->  [Ver =  | Size = 32768 bytes | Modified Date = 2/11/2008 5:52:09 PM | Attr =  HS]
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 2/11/2008 5:52:09 PM | Attr =  HS]
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat ->  [Ver =  | Size = 32768 bytes | Modified Date = 2/11/2008 5:52:09 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\History\History.IE5\desktop.ini ->  [Ver =  | Size = 145 bytes | Modified Date = 2/11/2008 5:52:04 PM | Attr =  HS]
mcdelta.ini -> C:\WINDOWS\Temp\mcu11.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 996 bytes | Modified Date = 2/11/2008 5:53:51 PM | Attr =	]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/11/2008 5:52:01 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\283GGT7B\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/11/2008 5:52:03 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\37KC98PR\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/11/2008 5:52:03 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FG8A0Q7Z\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/11/2008 5:52:03 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UC2M152T\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/11/2008 5:52:03 PM | Attr =  HS]

< End of report >


#9 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 11 February 2008 - 11:41 PM

Here is the SAS log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/11/2008 at 06:00 PM

Application Version : 3.9.1008

Core Rules Database Version : 3399
Trace Rules Database Version: 1391

Scan type : Complete Scan
Total Scan Time : 01:14:10

Memory items scanned : 433
Memory threats detected : 0
Registry items scanned : 5313
Registry threats detected : 172
File items scanned : 48290
File threats detected : 270

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2}
HKCR\CLSID\{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2}
HKCR\CLSID\{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2}\InprocServer32
HKCR\CLSID\{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\VTSQQ.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{119CF1DB-9F6B-4FE3-BDE3-FA49AE30E6D2}

Registry Cleaner Trial
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#C:\WINDOWS\Downloaded Program Files\Install.dll [  ]

Adware.HotBar/SpamBlockerUtility (Low Risk)
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\3_Shot Gun.wav
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\ASAPCom.dll
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbShprRprt.exe
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0
C:\Program Files\SpamBlockerUtility\bin
C:\Program Files\SpamBlockerUtility\SpamBlockerUtility.log
C:\Program Files\SpamBlockerUtility
C:\WINDOWS\Downloaded Program Files\SpamBlockerUtility.inf
HKLM\Software\SpamBlockerUtility
HKLM\Software\SpamBlockerUtility\Install
HKLM\Software\SpamBlockerUtility\Install#IE
HKLM\Software\SpamBlockerUtility\Install#OL
HKLM\Software\SpamBlockerUtility\Install#WT
HKLM\Software\SpamBlockerUtility\Install#WP
HKLM\Software\SpamBlockerUtility\Install#Install_Dir
HKLM\Software\SpamBlockerUtility\Install#Installed_From
HKLM\Software\SpamBlockerUtility\Install\CmpMap
HKLM\Software\SpamBlockerUtility\Install\CmpMap#IE
HKLM\Software\SpamBlockerUtility\Install\CmpMap#OL
HKLM\Software\SpamBlockerUtility\Install\CmpMap#WT
HKLM\Software\SpamBlockerUtility\Install\CmpMap#WP
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#SearchAssistant
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#Use Custom Search URL
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#IID
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#instcklm/instdata/iid
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#reqid
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#instcklm/instdata/requestor
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#bannerid
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#instcklm/instdata/bannerid
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#HbHostOEPath
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#PrevVer
HKLM\Software\SpamBlockerUtility\SpamBlockerUtility\Install#CurrentVer
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports#URLInfoAbout
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spam Blocker Utility ShopperReports#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerOutlookTools
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerOutlookTools#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerOutlookTools#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerOutlookTools#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerWebTools
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerWebTools#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerWebTools#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpamBlockerWebTools#UninstallString

Adware.HotBar/ShopperReports (Low Risk)
C:\Program Files\ShopperReports\Bin\1.0.8.0
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\Uninstall.exe
C:\Program Files\ShopperReports

Adware.180solutions/Seekmo
HKU\S-1-5-21-3096662371-2005070961-3468233762-1007\Software\Microsoft\Internet Explorer\Explorer Bars\{93B0FA7B-50F6-41B4-AC7E-612A72CE8C3C}

Adware.Zango Toolbar/Hb
HKCR\Srv.CoreServices
HKCR\Srv.CoreServices\CLSID
HKCR\Srv.CoreServices\CurVer
HKCR\Srv.CoreServices.1
HKCR\Srv.CoreServices.1\CLSID
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\LocalServer32
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\ProgID
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\Programmable
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\TypeLib
HKCR\CLSID\{7138F250-5B72-48DD-ADFB-9A83B429DD9E}\VersionIndependentProgID
HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}
HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories
HKCR\CLSID\{BF1BF02C-5A86-4ECF-ADAC-472C54C4D21E}\Implemented Categories\{170D6199-022A-4319-93F6-E45E3BEF11DA}
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\0
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\0\win32
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\FLAGS
HKCR\TypeLib\{0923208C-E259-4ED5-A778-CB607DA350AD}\1.0\HELPDIR
HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}
HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid
HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\ProxyStubClsid32
HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib
HKCR\Interface\{00B77587-BE1B-4201-B8E9-09FCF50AB771}\TypeLib#Version
HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}
HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid
HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\ProxyStubClsid32
HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib
HKCR\Interface\{067C6A37-72EA-4437-863A-5BE20C246F3C}\TypeLib#Version
HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}
HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid
HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\ProxyStubClsid32
HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib
HKCR\Interface\{1230CF51-6BC4-4A23-B3F1-C7CF0AFED619}\TypeLib#Version
HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}
HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid
HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\ProxyStubClsid32
HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib
HKCR\Interface\{1A2AF056-1FE1-47CA-993D-5D09D18E674E}\TypeLib#Version
HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}
HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid
HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\ProxyStubClsid32
HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib
HKCR\Interface\{34E29700-0D13-46AA-B9A5-ACE68E21A091}\TypeLib#Version
HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}
HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid
HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\ProxyStubClsid32
HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib
HKCR\Interface\{3661AF2D-C27B-499C-9BCF-66C8502A3806}\TypeLib#Version
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\ProxyStubClsid32
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib
HKCR\Interface\{3F0915B8-B238-4C2D-AD1E-60DB1E14D27A}\TypeLib#Version
HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}
HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid
HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\ProxyStubClsid32
HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib
HKCR\Interface\{4E8B851B-05B0-4BAF-B24D-D0DFE88DDED3}\TypeLib#Version
HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}
HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid
HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\ProxyStubClsid32
HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib
HKCR\Interface\{50C3E2B3-4FD7-4CB9-91F9-641A6E6B3689}\TypeLib#Version
HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}
HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid
HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\ProxyStubClsid32
HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib
HKCR\Interface\{5A4737A8-B92A-4E54-970E-C2891D98CE3F}\TypeLib#Version
HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}
HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid
HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\ProxyStubClsid32
HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib
HKCR\Interface\{62B0B239-F9AC-4A5B-BFAE-62C7A23F7627}\TypeLib#Version
HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}
HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid
HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\ProxyStubClsid32
HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib
HKCR\Interface\{726F0AB9-B842-4AE4-90C7-230E233E6A99}\TypeLib#Version
HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}
HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid
HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\ProxyStubClsid32
HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib
HKCR\Interface\{99123AC9-7DDA-4C82-B252-44C2804BF392}\TypeLib#Version
HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}
HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid
HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\ProxyStubClsid32
HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib
HKCR\Interface\{ACE99E77-AA2A-43C2-8C9D-CAF2020FDF2B}\TypeLib#Version
HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}
HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid
HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\ProxyStubClsid32
HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib
HKCR\Interface\{B247F5BF-BD9D-4ECD-8FC1-365F36A1FDA1}\TypeLib#Version
HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}
HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid
HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\ProxyStubClsid32
HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib
HKCR\Interface\{B9CC2B92-5611-453F-8381-8B6F72D9C0B8}\TypeLib#Version
HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}
HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid
HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\ProxyStubClsid32
HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib
HKCR\Interface\{BBBFB891-98AE-4678-86F3-BD5A2EED86C9}\TypeLib#Version
HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}
HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid
HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\ProxyStubClsid32
HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib
HKCR\Interface\{C4543E64-1498-410D-8E72-4744EEA99AB9}\TypeLib#Version
HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}
HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid
HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\ProxyStubClsid32
HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib
HKCR\Interface\{E0FB1610-B25B-49F6-BE20-751B2F230E6F}\TypeLib#Version
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\ProxyStubClsid32
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib
HKCR\Interface\{EA58C2EA-BE26-49DD-9B9A-C8E4E5CA7791}\TypeLib#Version
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\ProxyStubClsid32
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib
HKCR\Interface\{FCA28AC5-C1E1-4D67-A5AE-C44D6C374D9F}\TypeLib#Version

Adware.Tracking Cookie
C:\Documents and Settings\James\Cookies\james@247realmedia[2].txt
C:\Documents and Settings\James\Cookies\james@247realmedia[3].txt
C:\Documents and Settings\James\Cookies\james@247realmedia[4].txt
C:\Documents and Settings\James\Cookies\james@2o7[2].txt
C:\Documents and Settings\James\Cookies\james@3.adbrite[1].txt
C:\Documents and Settings\James\Cookies\james@a.websponsors[2].txt
C:\Documents and Settings\James\Cookies\james@ad.motiveinteractive[2].txt
C:\Documents and Settings\James\Cookies\james@ad.scanmedios[2].txt
C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[1].txt
C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[2].txt
C:\Documents and Settings\James\Cookies\james@ad.yieldmanager[3].txt
C:\Documents and Settings\James\Cookies\james@ad.zanox[2].txt
C:\Documents and Settings\James\Cookies\james@adbrite[2].txt
C:\Documents and Settings\James\Cookies\james@adecn[2].txt
C:\Documents and Settings\James\Cookies\james@adinterax[1].txt
C:\Documents and Settings\James\Cookies\james@adinterax[2].txt
C:\Documents and Settings\James\Cookies\james@adlegend[1].txt
C:\Documents and Settings\James\Cookies\james@adlegend[2].txt
C:\Documents and Settings\James\Cookies\james@adopt.euroclick[1].txt
C:\Documents and Settings\James\Cookies\james@adopt.euroclick[3].txt
C:\Documents and Settings\James\Cookies\james@adopt.specificclick[2].txt
C:\Documents and Settings\James\Cookies\james@adrevolver[1].txt
C:\Documents and Settings\James\Cookies\james@adrevolver[2].txt
C:\Documents and Settings\James\Cookies\james@adrevolver[4].txt
C:\Documents and Settings\James\Cookies\james@ads.as4x.tmcs.ticketmaster[2].txt
C:\Documents and Settings\James\Cookies\james@ads.as4x.tmcs[1].txt
C:\Documents and Settings\James\Cookies\james@ads.belointeractive[2].txt
C:\Documents and Settings\James\Cookies\james@ads.cnn[1].txt
C:\Documents and Settings\James\Cookies\james@ads.cnn[2].txt
C:\Documents and Settings\James\Cookies\james@ads.cnn[3].txt
C:\Documents and Settings\James\Cookies\james@ads.espn.adsonar[1].txt
C:\Documents and Settings\James\Cookies\james@ads.flooble[1].txt
C:\Documents and Settings\James\Cookies\james@ads.monster[1].txt
C:\Documents and Settings\James\Cookies\james@ads.realcastmedia[1].txt
C:\Documents and Settings\James\Cookies\james@ads.revsci[1].txt
C:\Documents and Settings\James\Cookies\james@ads.telegraph.co[1].txt
C:\Documents and Settings\James\Cookies\james@ads.traderonline[2].txt
C:\Documents and Settings\James\Cookies\james@ads.veoh[2].txt
C:\Documents and Settings\James\Cookies\james@ads4.blastro[2].txt
C:\Documents and Settings\James\Cookies\james@adserving.cpxinteractive[2].txt
C:\Documents and Settings\James\Cookies\james@adultadworld[2].txt
C:\Documents and Settings\James\Cookies\james@adv.webmd[1].txt
C:\Documents and Settings\James\Cookies\james@advertising[1].txt
C:\Documents and Settings\James\Cookies\james@anad.tacoda[2].txt
C:\Documents and Settings\James\Cookies\james@anad.tacoda[3].txt
C:\Documents and Settings\James\Cookies\james@anad.tacoda[4].txt
C:\Documents and Settings\James\Cookies\james@anat.tacoda[2].txt
C:\Documents and Settings\James\Cookies\james@apmebf[1].txt
C:\Documents and Settings\James\Cookies\james@apmebf[2].txt
C:\Documents and Settings\James\Cookies\james@atdmt[2].txt
C:\Documents and Settings\James\Cookies\james@atwola[2].txt
C:\Documents and Settings\James\Cookies\james@atwola[3].txt
C:\Documents and Settings\James\Cookies\james@automedia[2].txt
C:\Documents and Settings\James\Cookies\james@azjmp[2].txt
C:\Documents and Settings\James\Cookies\james@banners.pictures.sprintpcs[1].txt
C:\Documents and Settings\James\Cookies\james@belnk[1].txt
C:\Documents and Settings\James\Cookies\james@bigbanners[2].txt
C:\Documents and Settings\James\Cookies\james@bizrate[1].txt
C:\Documents and Settings\James\Cookies\james@blubboz.freestats[2].txt
C:\Documents and Settings\James\Cookies\james@bluestreak[2].txt
C:\Documents and Settings\James\Cookies\james@bluestreak[3].txt
C:\Documents and Settings\James\Cookies\james@brightcove.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@bs.serving-sys[1].txt
C:\Documents and Settings\James\Cookies\james@bs.serving-sys[3].txt
C:\Documents and Settings\James\Cookies\james@burstnet[2].txt
C:\Documents and Settings\James\Cookies\james@casalemedia[2].txt
C:\Documents and Settings\James\Cookies\james@click2houston[1].txt
C:\Documents and Settings\James\Cookies\james@clicksor[1].txt
C:\Documents and Settings\James\Cookies\james@collective-media[2].txt
C:\Documents and Settings\James\Cookies\james@comcast.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@comcast.112.2o7[2].txt
C:\Documents and Settings\James\Cookies\james@counter.hitslink[1].txt
C:\Documents and Settings\James\Cookies\james@counter.hitslink[2].txt
C:\Documents and Settings\James\Cookies\james@counter2.hitslink[1].txt
C:\Documents and Settings\James\Cookies\james@crateenginedepot[1].txt
C:\Documents and Settings\James\Cookies\james@data4.perf.overture[1].txt
C:\Documents and Settings\James\Cookies\james@dist.belnk[2].txt
C:\Documents and Settings\James\Cookies\james@doubleclick[1].txt
C:\Documents and Settings\James\Cookies\james@doubleclick[2].txt
C:\Documents and Settings\James\Cookies\james@e-2dj6wfkoqnazigo.stats.esomniture[2].txt
C:\Documents and Settings\James\Cookies\james@easy-hit-counters[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-autozone.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-campaignsolutions.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-cardomain.hitbox[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-chrysler.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-cskautocorporation.hitbox[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-cskautocorporation.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-dig.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-dig.hitbox[3].txt
C:\Documents and Settings\James\Cookies\james@ehg-findlaw.hitbox[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-foxsports.hitbox[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-foxsports.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-hyundaiusa.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-magicalia.hitbox[1].txt
C:\Documents and Settings\James\Cookies\james@ehg-playboy.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-vzw.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-youtube.hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@ehg-youtube.hitbox[3].txt
C:\Documents and Settings\James\Cookies\james@ems.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@enhance[1].txt
C:\Documents and Settings\James\Cookies\james@eyeblast.adbureau[2].txt
C:\Documents and Settings\James\Cookies\james@eyewonder[2].txt
C:\Documents and Settings\James\Cookies\james@eyewonder[3].txt
C:\Documents and Settings\James\Cookies\james@ez-tracks[2].txt
C:\Documents and Settings\James\Cookies\james@eztracks.aavalue[2].txt
C:\Documents and Settings\James\Cookies\james@ezzs.valueclick[2].txt
C:\Documents and Settings\James\Cookies\james@fastclick[1].txt
C:\Documents and Settings\James\Cookies\james@fastclick[2].txt
C:\Documents and Settings\James\Cookies\james@findlaw[1].txt
C:\Documents and Settings\James\Cookies\james@focalex[2].txt
C:\Documents and Settings\James\Cookies\james@ford.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@gmgmacfs.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@goclick[2].txt
C:\Documents and Settings\James\Cookies\james@hc2.humanclick[1].txt
C:\Documents and Settings\James\Cookies\james@hc2.humanclick[3].txt
C:\Documents and Settings\James\Cookies\james@hitbox[2].txt
C:\Documents and Settings\James\Cookies\james@hitbox[3].txt
C:\Documents and Settings\James\Cookies\james@i.screensavers[1].txt
C:\Documents and Settings\James\Cookies\james@icc.intellisrv[2].txt
C:\Documents and Settings\James\Cookies\james@image.masterstats[2].txt
C:\Documents and Settings\James\Cookies\james@immigration.findlaw[1].txt
C:\Documents and Settings\James\Cookies\james@imp.partner2profit[2].txt
C:\Documents and Settings\James\Cookies\james@indexstats[2].txt
C:\Documents and Settings\James\Cookies\james@interclick[2].txt
C:\Documents and Settings\James\Cookies\james@kanoodle[2].txt
C:\Documents and Settings\James\Cookies\james@keywordmax[1].txt
C:\Documents and Settings\James\Cookies\james@kmpads[2].txt
C:\Documents and Settings\James\Cookies\james@likecrack[1].txt
C:\Documents and Settings\James\Cookies\james@marketlive.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@maxserving[1].txt
C:\Documents and Settings\James\Cookies\james@media-general[2].txt
C:\Documents and Settings\James\Cookies\james@media.adrevolver[1].txt
C:\Documents and Settings\James\Cookies\james@media.adrevolver[2].txt
C:\Documents and Settings\James\Cookies\james@media.adrevolver[3].txt
C:\Documents and Settings\James\Cookies\james@media.mtvnservices[1].txt
C:\Documents and Settings\James\Cookies\james@media.putfile[1].txt
C:\Documents and Settings\James\Cookies\james@media.sensis.com[2].txt
C:\Documents and Settings\James\Cookies\james@media1.break[1].txt
C:\Documents and Settings\James\Cookies\james@media4.sitebrand[2].txt
C:\Documents and Settings\James\Cookies\james@media6degrees[1].txt
C:\Documents and Settings\James\Cookies\james@mediafetcher[2].txt
C:\Documents and Settings\James\Cookies\james@mediamgr.ugo[2].txt
C:\Documents and Settings\James\Cookies\james@mediaonenetwork[1].txt
C:\Documents and Settings\James\Cookies\james@mediaplex[2].txt
C:\Documents and Settings\James\Cookies\james@metareward[1].txt
C:\Documents and Settings\James\Cookies\james@msnportal.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@my.traffic[1].txt
C:\Documents and Settings\James\Cookies\james@nextag[2].txt
C:\Documents and Settings\James\Cookies\james@nielsen.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@omnistats[1].txt
C:\Documents and Settings\James\Cookies\james@ordie.adbureau[1].txt
C:\Documents and Settings\James\Cookies\james@overture[1].txt
C:\Documents and Settings\James\Cookies\james@overture[2].txt
C:\Documents and Settings\James\Cookies\james@partner2profit[1].txt
C:\Documents and Settings\James\Cookies\james@partner2profit[2].txt
C:\Documents and Settings\James\Cookies\james@perf.overture[1].txt
C:\Documents and Settings\James\Cookies\james@precisionclick[1].txt
C:\Documents and Settings\James\Cookies\james@primedia.us.intellitxt[1].txt
C:\Documents and Settings\James\Cookies\james@qnsr[2].txt
C:\Documents and Settings\James\Cookies\james@questionmarket[1].txt
C:\Documents and Settings\James\Cookies\james@questionmarket[2].txt
C:\Documents and Settings\James\Cookies\james@realmedia[1].txt
C:\Documents and Settings\James\Cookies\james@redirect.clickshield[1].txt
C:\Documents and Settings\James\Cookies\james@reduxads.valuead[2].txt
C:\Documents and Settings\James\Cookies\james@review-adult-dating[2].txt
C:\Documents and Settings\James\Cookies\james@richmedia.yahoo[1].txt
C:\Documents and Settings\James\Cookies\james@richmedia.yahoo[2].txt
C:\Documents and Settings\James\Cookies\james@rightmedia[2].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[1].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[2].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[3].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[4].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[5].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[6].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[7].txt
C:\Documents and Settings\James\Cookies\james@sales.liveperson[9].txt
C:\Documents and Settings\James\Cookies\james@screensavers.us.intellitxt[1].txt
C:\Documents and Settings\James\Cookies\james@screensavers[2].txt
C:\Documents and Settings\James\Cookies\james@secure.winantivirus[2].txt
C:\Documents and Settings\James\Cookies\james@server.iad.liveperson[1].txt
C:\Documents and Settings\James\Cookies\james@server.iad.liveperson[2].txt
C:\Documents and Settings\James\Cookies\james@server.iad.liveperson[4].txt
C:\Documents and Settings\James\Cookies\james@server.iad.liveperson[5].txt
C:\Documents and Settings\James\Cookies\james@server.iad.liveperson[6].txt
C:\Documents and Settings\James\Cookies\james@server.lon.liveperson[1].txt
C:\Documents and Settings\James\Cookies\james@server.lon.liveperson[2].txt
C:\Documents and Settings\James\Cookies\james@sex-superstore[2].txt
C:\Documents and Settings\James\Cookies\james@sexy.liveleak[2].txt
C:\Documents and Settings\James\Cookies\james@smileycentral[2].txt
C:\Documents and Settings\James\Cookies\james@sources.sourcetool[1].txt
C:\Documents and Settings\James\Cookies\james@spamblockerutility[2].txt
C:\Documents and Settings\James\Cookies\james@specificclick[2].txt
C:\Documents and Settings\James\Cookies\james@specificclick[3].txt
C:\Documents and Settings\James\Cookies\james@stat.onestat[2].txt
C:\Documents and Settings\James\Cookies\james@statcounter[1].txt
C:\Documents and Settings\James\Cookies\james@statcounter[3].txt
C:\Documents and Settings\James\Cookies\james@stats1.reliablestats[1].txt
C:\Documents and Settings\James\Cookies\james@statse.webtrendslive[1].txt
C:\Documents and Settings\James\Cookies\james@superstats[1].txt
C:\Documents and Settings\James\Cookies\james@tacoda[1].txt
C:\Documents and Settings\James\Cookies\james@tacoda[2].txt
C:\Documents and Settings\James\Cookies\james@toplist[1].txt
C:\Documents and Settings\James\Cookies\james@track.adform[2].txt
C:\Documents and Settings\James\Cookies\james@tracking.coorslight[1].txt
C:\Documents and Settings\James\Cookies\james@trafficdashboard[1].txt
C:\Documents and Settings\James\Cookies\james@trafficmp[2].txt
C:\Documents and Settings\James\Cookies\james@traffic[1].txt
C:\Documents and Settings\James\Cookies\james@tremor.adbureau[1].txt
C:\Documents and Settings\James\Cookies\james@tremor.adbureau[3].txt
C:\Documents and Settings\James\Cookies\james@tribalfusion[1].txt
C:\Documents and Settings\James\Cookies\james@whitehorse.112.2o7[1].txt
C:\Documents and Settings\James\Cookies\james@winantivirus[2].txt
C:\Documents and Settings\James\Cookies\james@winfixer[2].txt
C:\Documents and Settings\James\Cookies\james@www.adtrak[1].txt
C:\Documents and Settings\James\Cookies\james@www.burstbeacon[2].txt
C:\Documents and Settings\James\Cookies\james@www.burstnet[1].txt
C:\Documents and Settings\James\Cookies\james@www.burstnet[3].txt
C:\Documents and Settings\James\Cookies\james@www.checkmystats.com[2].txt
C:\Documents and Settings\James\Cookies\james@www.click2houston[1].txt
C:\Documents and Settings\James\Cookies\james@www.coversexperts[2].txt
C:\Documents and Settings\James\Cookies\james@www.crateenginedepot[2].txt
C:\Documents and Settings\James\Cookies\james@www.ez-tracks[1].txt
C:\Documents and Settings\James\Cookies\james@www.findlaw[1].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[1].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[2].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[3].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[4].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[5].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[6].txt
C:\Documents and Settings\James\Cookies\james@www.googleadservices[7].txt
C:\Documents and Settings\James\Cookies\james@www.mysitetraffic[2].txt
C:\Documents and Settings\James\Cookies\james@www.paintball-discounters[2].txt
C:\Documents and Settings\James\Cookies\james@www.screensavers[1].txt
C:\Documents and Settings\James\Cookies\james@www.trackspace[1].txt
C:\Documents and Settings\James\Cookies\james@www.traffic[1].txt
C:\Documents and Settings\James\Cookies\james@www.winantiviruspro[1].txt
C:\Documents and Settings\James\Cookies\james@www.winantivirus[2].txt
C:\Documents and Settings\James\Cookies\james@www.winfixer[2].txt
C:\Documents and Settings\James\Cookies\james@yadro[1].txt
C:\Documents and Settings\James\Cookies\james@zedo[1].txt
C:\Documents and Settings\Kelly\Cookies\kelly@2o7[1].txt
C:\Documents and Settings\Kelly\Cookies\kelly@ad.yieldmanager[1].txt
C:\Documents and Settings\Kelly\Cookies\kelly@ads.bleepingcomputer[2].txt
C:\Documents and Settings\Kelly\Cookies\kelly@advertising[1].txt
C:\Documents and Settings\Kelly\Cookies\kelly@atdmt[1].txt
C:\Documents and Settings\Kelly\Cookies\kelly@doubleclick[1].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@admarketplace[1].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@adopt.specificclick[2].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@data1.perf.overture[1].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@icc.intellisrv[2].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@nextag[2].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@partner2profit[2].txt
C:\Documents and Settings\Kelly\Local Settings\Temp\Cookies\kelly@qnsr[1].txt

Adware.180solutions/ZangoSearch
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP371\A0022209.DLL

Adware.Vundo-Variant/Small-A
C:\SYSTEM VOLUME INFORMATION\_RESTORE{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP448\A0026930.DLL
C:\WINDOWS\SYSTEM32\GIPPRFUF.DLL

Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\QQSTV.INI

Thank you!!!

#10 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 12 February 2008 - 12:02 AM

Hi kellydoz. Actually, that looks pretty good. It looks like it got most of them in the first pass. We have a few files to cleanup yet so follow the steps below in order.

Step #1

Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
%SystemRoot%\system32\pmnll.dll
%SystemRoot%\system32\vtstr.dll
%SystemRoot%\system32\lthcdugi.dll 
%SystemRoot%\System32\fufrppig.ini
%SystemRoot%\System32\qqstv.ini2
%SystemRoot%\System32\sbhyqqpl.ini
%SystemRoot%\cookies.ini
Folders to delete:
%SystemRoot%\System32\nGpxx01

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Step #2

Start WinPFind35U. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Registry - Non-Microsoft Only]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YY -> pmnll -> %SystemRoot%\system32\pmnll.dll
YY -> vtstr -> %SystemRoot%\system32\vtstr.dll
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {4115122B-85FF-4DD3-9515-F075BEDE5EB5} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> {549B5CA7-4A86-11D7-A4DF-000874180BB3} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YY -> {67ce851b-47ce-4ac9-833e-7ff4ece09e36} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\lthcdugi.dll [Reg Error: Value  does not exist or could not be read.]
YN -> {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
[Files/Folders - Created Within 30 days]
NY -> 2172 C:\*.tmp files -> C:\*.tmp
NY -> fufrppig.ini -> %SystemRoot%\System32\fufrppig.ini
NY -> nGpxx01 -> %SystemRoot%\System32\nGpxx01
NY -> 2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> qqstv.ini2 -> %SystemRoot%\System32\qqstv.ini2
NY -> sbhyqqpl.ini -> %SystemRoot%\System32\sbhyqqpl.ini
NY -> cookies.ini -> %SystemRoot%\cookies.ini
[Files/Folders - Modified Within 30 days]
NY -> 2172 C:\*.tmp files -> C:\*.tmp
NY -> fufrppig.ini -> %SystemRoot%\System32\fufrppig.ini
NY -> nGpxx01 -> %SystemRoot%\System32\nGpxx01
NY -> qqstv.ini2 -> %SystemRoot%\System32\qqstv.ini2
NY -> sbhyqqpl.ini -> %SystemRoot%\System32\sbhyqqpl.ini
NY -> cookies.ini -> %SystemRoot%\cookies.ini
NY -> 1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Empty Temp Folders]
[Start Explorer]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.

Step #3

Run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Click on Online Services and then Online Scanner
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.
Step #4

Run a new WinPFind35u scan with the default options.

Step #5

Post the following back here:The Avenger report (c:\Avenger.txt)
The latest WinPFind35u fix log (look in the WinPFind35u folder for the MovedFiles folder. In that folder will be a file with a name in the form of mmddyyyy_hhmmss.log for month, day, year, hours, minutes, and seconds that the scan was run. )
The new WinPFind35u scan log
I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#11 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 13 February 2008 - 10:20 AM

Sorry it's taken me so long to get back. Thanks for your patience.

I started the F-Secure Online scan last night and since it was taking so long to run I decided to go to bed and let it run overnight. When I got up this morning, Windows had installed an update and rebooted the computer. *insert cursing smilie here* I tried to re-run the F-Secure but I keep getting an error message that tells me to close the scanner and my browser and restart the scan. My browser was closed so I don't know what's up.

#12 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 13 February 2008 - 11:19 AM

Hi kellydoz. You just gotta love MS Updates lol. Just skip that then and post the logs from Avenger and the WPF fix and a new WPF scan.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#13 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 13 February 2008 - 12:36 PM

Avenger report...


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\mewpvbtd

*******************

Script file located at: \??\C:\Documents and Settings\kvfrdkfb.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\pmnll.dll not found!
Deletion of file C:\WINDOWS\system32\pmnll.dll failed!

Could not process line:
C:\WINDOWS\system32\pmnll.dll
Status: 0xc0000034



File C:\WINDOWS\system32\vtstr.dll not found!
Deletion of file C:\WINDOWS\system32\vtstr.dll failed!

Could not process line:
C:\WINDOWS\system32\vtstr.dll
Status: 0xc0000034



File C:\WINDOWS\system32\lthcdugi.dll not found!
Deletion of file C:\WINDOWS\system32\lthcdugi.dll failed!

Could not process line:
C:\WINDOWS\system32\lthcdugi.dll
Status: 0xc0000034

File C:\WINDOWS\System32\fufrppig.ini deleted successfully.
File C:\WINDOWS\System32\qqstv.ini2 deleted successfully.
File C:\WINDOWS\System32\sbhyqqpl.ini deleted successfully.
File C:\WINDOWS\cookies.ini deleted successfully.
Folder C:\WINDOWS\System32\nGpxx01 deleted successfully.

Completed script processing.

*******************

Finished! Terminate.


WinPFind35U log...

Explorer killed successfully
[Registry - Non-Microsoft Only]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnll\ deleted successfully.
File C:\WINDOWS\system32\pmnll.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstr\ deleted successfully.
File C:\WINDOWS\system32\vtstr.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4115122B-85FF-4DD3-9515-F075BEDE5EB5}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4115122B-85FF-4DD3-9515-F075BEDE5EB5}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{549B5CA7-4A86-11D7-A4DF-000874180BB3}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67ce851b-47ce-4ac9-833e-7ff4ece09e36}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67ce851b-47ce-4ac9-833e-7ff4ece09e36}\ deleted successfully.
File C:\WINDOWS\system32\lthcdugi.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32683183-48a0-441b-a342-7c2a440a9478}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07AA283A-43D7-4CBE-A064-32A21112D94D} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07AA283A-43D7-4CBE-A064-32A21112D94D}\ not found.
[Files/Folders - Created Within 30 days]
File C:\WINDOWS\System32\fufrppig.ini not found!
File C:\WINDOWS\System32\nGpxx01 not found!
File C:\WINDOWS\System32\qqstv.ini2 not found!
File C:\WINDOWS\System32\sbhyqqpl.ini not found!
File C:\WINDOWS\cookies.ini not found!
[Files/Folders - Modified Within 30 days]
File C:\WINDOWS\System32\fufrppig.ini not found!
File C:\WINDOWS\System32\nGpxx01 not found!
File C:\WINDOWS\System32\qqstv.ini2 not found!
File C:\WINDOWS\System32\sbhyqqpl.ini not found!
File C:\WINDOWS\cookies.ini not found!
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\SLR3074R\christmas_Girls-Clothing_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfgtpZQQfposZ37062QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQlopgZQQsacatZ57808QQs[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\AccountOverview-inside;lang=en_US;acct=pers;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\OT6ROD2B\AuctionTools-outside;lang=en_US;acct=;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;PVDNi=false;id=;sz=150x100;tile=1;ord=31620[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ550QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ650QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ700QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\NF9VVLWC\christmas_Dresses_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfgtpZQQfposZ37062QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQlopgZQQsacatZ57822QQs[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXOHAF4D\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfgtpZQQfposZ37062QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQlopgZQQs[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXOHAF4D\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ500QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\KXOHAF4D\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ600QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\AccountOverview-inside;lang=en_US;acct=pers;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\K12V896J\AuctionTools-outside;lang=en_US;acct=;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;PVDNi=false;id=;sz=150x100;tile=2;ord=31620[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ150QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\J9DB3MJG\christmas-dresses_3-6-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfgtpZQQfposZ37062QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQlopgZQQsac[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ400QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\I50VA1I5\christmas-dresses_3-6-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ100QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57820[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT9AYMIS\AccountOverview-inside;lang=en_US;acct=pers;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT9AYMIS\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ50QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\GT9AYMIS\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ800QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDGP6RS5\christmas-dresses_3-6-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ50QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57820[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4PSJ0B87\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ200QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4PSJ0B87\christmas-dresses_3-6-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ150QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57820[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4NID4BGZ\AccountOverview-inside;lang=en_US;acct=pers;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4NID4BGZ\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ750QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4NID4BGZ\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ850QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DO985W5\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ300QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\4DO985W5\ShopsLogout-outside;lang=en_US;acct=;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8=f;F9=f[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ250QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ350QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\Infants-Toddlers_Girls-Clothing_W0QQcatrefZC4QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57808QQsocmdZListing[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\2JERG3WF\ShopsLogout-outside;lang=en_US;acct=;resid=US;PVDN=none;debit=false;bcapp=false;bcpre=false;verif=false;ebayS=false;ebayB=false;F1=f;F2=f;F3=f;F4=f;F5=f;F6=f;F7=f;F8=f;F9=f[2] scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\0VBZ2C5L\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ100QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\0VBZ2C5L\christmas-dresses_12-24-Months_W0QQcatrefZC6QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfrtsZ450QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Kelly\Local Settings\Temp\Temporary Internet Files\Content.IE5\0VBZ2C5L\Girls-Clothing_12-24-Months_W0QQcatrefZC4QQcoactionZcompareQQcoentrypageZsearchQQcopagenumZ1QQfclZ3QQfromZR2QQfsooZ2QQfsopZ2QQftrtZ1QQftrvZ1QQsacatZ57844QQsocmdZListingItem[1].htm scheduled to be deleted on reboot.
User temp folders emptied.
SystemRoot temp folder emptied.
IE temp folders emptied
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
WinPFind35U Version Beta50 fix logfile created on 02122008_201613

WinPFind35U scan log...

WinPFind35 logfile created on: 2/13/2008 11:22:46 AM
WinPFind35U Version Beta50	 Folder = C:\Documents and Settings\Kelly\Desktop\WinPFind35u
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
254.00 Mb Total Physical Memory | 127.35 Mb Available Physical Memory | 50.14% Memory free
625.04 Mb Paging File | 316.12 Mb Available in Paging File | 50.58% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.25 Gb Total Space | 22.80 Gb Free Space | 59.61% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MACK
Current User Name: Kelly
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user

[Processes - Non-Microsoft Only]
aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
acsd.exe -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]
mcdetect.exe -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]
mcshield.exe -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]
mctskshd.exe -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]
ncupdatesvc.exe -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]
mm_tray.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
tgcmd.exe -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]
mcagent.exe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]
oasclnt.exe -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]
bcmsmmsg.exe -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]
mmtask.exe -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
hpwuschd.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]
hpcmpmgr.exe -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
mcvsshld.exe -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]
mcvsescn.exe -> %ProgramFiles%\McAfee.com\VSO\McVSEscn.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 483328 bytes | Modified Date = 7/8/2005 5:16:16 PM | Attr =	]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr =	]
ymsgr_tray.exe -> %ProgramFiles%\Yahoo!\Messenger\Ymsgr_tray.exe -> Yahoo! Inc. [Ver = 8,1,0,0 | Size = 103928 bytes | Modified Date = 11/30/2006 9:49:06 PM | Attr =	]
hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]
pi monitor.exe -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]
vsaccess.exe -> %SystemDrive%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 2.0 | Size = 266240 bytes | Modified Date = 7/21/2000 2:34:52 PM | Attr =	]
ocrawr32.exe -> %SystemDrive%\OPLIMIT\OCRAWR32.EXE -> Caere Corporation [Ver = 5, 0, 0, 1 | Size = 41984 bytes | Modified Date = 3/19/1998 2:22:02 PM | Attr =	]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]
winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 309248 bytes | Modified Date = 2/11/2008 7:14:48 PM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
(AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,17,5 | Size = 1376360 bytes | Modified Date = 8/6/2003 3:58:26 PM | Attr =	]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 10/31/2007 2:09:16 PM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 1:56:48 AM | Attr =	]
(DSBrokerService) DSBrokerService [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\DellSupport\brkrsvc.exe ->  [Ver = 1, 0, 0, 8 | Size = 76848 bytes | Modified Date = 3/7/2007 2:47:46 PM | Attr =	]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 12/11/2007 12:10:16 PM | Attr =	]
(McDetect.exe) McAfee WSC Integration [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\Mcdetect.exe -> McAfee, Inc [Ver = 6, 0, 0, 19 | Size = 126976 bytes | Modified Date = 10/13/2005 6:56:16 PM | Attr =	]
(McShield) McAfee.com McShield [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\VSO\McShield.exe -> McAfee Inc. [Ver = 11.0.0.151 | Size = 221184 bytes | Modified Date = 8/10/2005 10:22:02 AM | Attr =	]
(McTskshd.exe) McAfee Task Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\McAfee.com\Agent\McTskshd.exe -> McAfee, Inc [Ver = 6, 0, 0, 13 | Size = 122368 bytes | Modified Date = 8/24/2005 3:01:04 PM | Attr =	]
(mcupdmgr.exe) McAfee SecurityCenter Update Manager [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\McAfee.com\Agent\mcupdmgr.exe -> McAfee, Inc [Ver = 6, 0, 0, 4 | Size = 245760 bytes | Modified Date = 7/1/2005 6:22:50 PM | Attr =	]
(NCUpdateSvc) Netscape Update Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Netscape Internet Service\ncupdatesvc.exe -> Netscape Communications Corporation [Ver = 1, 0, 0, 5 | Size = 53248 bytes | Modified Date = 2/1/2005 11:52:29 AM | Attr =	]
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\HPZipm12.exe -> HP [Ver = 7, 0, 0, 0 | Size = 65795 bytes | Modified Date = 8/11/2003 2:07:38 AM | Attr = R  ]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
BCMSMMSG -> %SystemRoot%\BCMSMMSG.exe -> Broadcom Corporation [Ver =  3.5.25 08/27/2003 20:04:35 | Size = 122880 bytes | Modified Date = 8/29/2003 4:59:24 AM | Attr =	]
dscactivate -> %ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe ->   [Ver = 1.0.2767.18581 | Size = 16384 bytes | Modified Date = 11/15/2007 9:24:00 AM | Attr =	]
HP Component Manager -> %ProgramFiles%\HP\hpcoretech\hpcmpmgr.exe -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 212992 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
HP Software Update -> %ProgramFiles%\HP\HP Software Update\hpwuSchd.exe -> Hewlett-Packard [Ver = 1, 0, 0, 2 | Size = 49152 bytes | Modified Date = 6/25/2003 10:24:48 AM | Attr =	]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 12/11/2007 12:10:26 PM | Attr =	]
MCAgentExe -> %ProgramFiles%\McAfee.com\Agent\mcagent.exe -> McAfee, Inc [Ver = 6, 0, 0, 16 | Size = 303104 bytes | Modified Date = 9/22/2005 5:29:08 PM | Attr =	]
MCUpdateExe -> %ProgramFiles%\McAfee.com\Agent\mcupdate.exe -> McAfee, Inc [Ver = 6, 0, 0, 21 | Size = 212992 bytes | Modified Date = 1/11/2006 12:05:42 PM | Attr =	]
mmtask -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe -> Musicmatch Inc. [Ver = 9.0.0.1 | Size = 53248 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
MMTray -> %ProgramFiles%\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe -> Musicmatch, Inc. [Ver = 9.00.5100 | Size = 135168 bytes | Modified Date = 1/17/2006 12:03:06 PM | Attr =	]
OASClnt -> %ProgramFiles%\McAfee.com\VSO\oasclnt.exe -> McAfee, Inc. [Ver = 10, 0, 0, 24 | Size = 53248 bytes | Modified Date = 8/11/2005 9:02:44 PM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.3.1 | Size = 286720 bytes | Modified Date = 12/11/2007 10:56:54 AM | Attr =	]
tgcmd -> %ProgramFiles%\support.com\bin\tgcmd.exe -> Support.com, Inc. [Ver = 5,5,402,0 | Size = 1544192 bytes | Modified Date = 4/24/2002 7:37:43 PM | Attr =	]
TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3208 | Size = 180269 bytes | Modified Date = 10/14/2004 12:35:17 PM | Attr =	]
UserFaultCheck ->  -> File not found
VirusScan Online -> %ProgramFiles%\McAfee.com\VSO\mcvsshld.exe -> McAfee, Inc. [Ver = 10, 0, 0, 22 | Size = 163840 bytes | Modified Date = 8/10/2005 11:49:20 AM | Attr =	]
VSOCheckTask -> %ProgramFiles%\McAfee.com\VSO\mcmnhdlr.exe -> McAfee, Inc. [Ver = 10, 0, 0, 20 | Size = 151552 bytes | Modified Date = 7/8/2005 5:18:22 PM | Attr =	]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr =	]
Yahoo! Pager -> %ProgramFiles%\Yahoo!\Messenger\YahooMessenger.exe -> Yahoo! Inc. [Ver = 8,1,0,209 | Size = 4662776 bytes | Modified Date = 11/30/2006 9:49:04 PM | Attr =	]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 40048 bytes | Modified Date = 10/23/2006 1:48:20 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk -> %ProgramFiles%\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ->  [Ver = 8.0.0.0 | Size = 734872 bytes | Modified Date = 10/23/2006 12:01:50 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> Hewlett-Packard Co. [Ver = 5.31.0.147 | Size = 233472 bytes | Modified Date = 7/7/2003 12:20:40 AM | Attr =	]
%AllUsersProfile%\Start Menu\Programs\Startup\PI Monitor.lnk -> %ProgramFiles%\ArcSoft\PhotoImpression 5\PI Monitor.exe -> Arcsoft, Inc. [Ver = 1, 0, 0, 7 | Size = 86016 bytes | Modified Date = 1/6/2004 1:55:16 PM | Attr =	]
< Kelly Startup Folder > -> C:\Documents and Settings\Kelly\Start Menu\Programs\Startup -> 
%UserProfile%\Start Menu\Programs\Startup\OCRAWARE.lnk -> %SystemDrive%\OPLIMIT\OCRAWARE.EXE -> Caere Corporation [Ver =  | Size = 51360 bytes | Modified Date = 7/18/1998 10:26:06 AM | Attr =	]
%UserProfile%\Start Menu\Programs\Startup\UMAX VistaAccess.lnk -> %SystemDrive%\VSTASCAN\vsaccess.exe -> UMAX [Ver = 2.0 | Size = 266240 bytes | Modified Date = 7/21/2000 2:34:52 PM | Attr =	]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 12/20/2006 1:55:48 PM | Attr =	]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
!SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1046 | Size = 294912 bytes | Modified Date = 4/19/2007 1:41:36 PM | Attr =	]
igfxcui -> %SystemRoot%\SYSTEM32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.4342 | Size = 348160 bytes | Modified Date = 10/19/2005 7:59:14 AM | Attr =	]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
< HOSTS File > (734 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.yahoo.com/ -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Bar -> http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.yahoo.com/ -> 
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://www.comcast.net/toolbar2.0/search/ -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Default_Page_URL -> http://www.dell4me.com/myway -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Bar -> http://www.comcast.net/toolbar2.0/search/ -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.comcast.net -> 
HKEY_CURRENT_USER\: SearchURL\\ -> http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com[Reg Error: Value provider does not exist or could not be read.] -> 
HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. -> 
objects_aol.com [*] -> Out of zone range - ( 5 ) -> 
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]
{5CA3D70E-1895-11CF-8E15-001234567890} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\SYSTEM32\dla\tfswshx.dll [DriveLetterAccess] -> Sonic Solutions [Ver = 1.04.05b | Size = 106548 bytes | Modified Date = 8/6/2003 1:04:00 AM | Attr =	]
< Internet Explorer Bars [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{4528BBE0-4E08-11D5-AD55-00010333D0AD} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yhexbmesus.dll [&Yahoo! Messenger] -> Yahoo! Inc. [Ver = 2005, 12, 13, 1 | Size = 325184 bytes | Modified Date = 12/14/2005 3:29:40 PM | Attr =	]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
{BA52B914-B692-46c4-B683-905236F6F655} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\McAfee.com\VSO\mcvsshl.dll [McAfee VirusScan] -> McAfee, Inc. [Ver = 10, 0, 0, 19 | Size = 114688 bytes | Modified Date = 7/1/2005 7:44:30 PM | Attr =	]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> Comcast Cable Communications.				 [Ver = 5.0.0.72 | Size = 1821184 bytes | Modified Date = 11/7/2006 1:21:58 PM | Attr =	]
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\System32\msjava.dll [Sun Java Console] -> File not found
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}:{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! Services] -> Yahoo! Inc. [Ver = 2006, 10, 31, 3 | Size = 198136 bytes | Modified Date = 10/31/2006 3:29:16 PM | Attr =	]
{669B269B-0D4E-41FB-A3D8-FD67CA94F646}:Exec ->  [ComcastHSI] -> File not found
{8828075D-D097-4055-AA02-2DBFA9D85E8A}:Exec ->  [Support] -> File not found
{97809617-3937-4F84-B335-9BB05EF1A8D4}:Exec ->  [Help] -> File not found
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> 
&Yahoo! Search ->  -> File not found
Add to Windows &Live Favorites ->  -> File not found
Yahoo! &Dictionary ->  -> File not found
Yahoo! &Maps ->  -> File not found
Yahoo! &SMS ->  -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
Extension\.pdf -> %ProgramFiles%\Internet Explorer\PLUGINS\nppdf32.dll [Adobe Acrobat] -> File not found
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{0032BCDA-5210-4EC7-9BFA-77D00F012DC8} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{0990A63A-9C1D-4800-92AB-CB095EA7DE84} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{30709FBE-EF58-40D9-B4D2-DE076C914147} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{45D6247E-106B-46B8-A29C-FDA5061867CC} ->	(Motorola SURFboard SB5120 USB Cable Modem) -> 
{82E6535A-D32A-481B-9D7E-3D0693E66193} ->	(Broadcom 440x 10/100 Integrated Controller) -> 
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
Protocol_Catalog9\Catalog_Entries\000000000001 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000002 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000003 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000004 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000005 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000006 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000007 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000008 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000009 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000010 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000011 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000012 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000013 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000014 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000015 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000016 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000017 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000018 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000019 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000020 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000021 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000022 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000023 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000024 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000025 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000026 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
Protocol_Catalog9\Catalog_Entries\000000000027 -> %ProgramFiles%\Netscape Internet Service\Netscape Web Accelerator\sliplsp.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 3/11/2004 4:56:30 PM | Attr =	]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\HP\hpcoretech\comp\hpuiprot.dll[CZipHandler Object] -> Hewlett-Packard Company [Ver = 1.76.0 | Size = 81920 bytes | Modified Date = 6/26/2003 5:50:24 PM | Attr =	]
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{0B79F48A-E8D6-11DB-9283-E25056D89593}[HKEY_LOCAL_MACHINE] -> http://support.f-secure.com/ols/fscax.cab[F-Secure Online Scanner 3.1] -> 
{11260943-421B-11D0-8EAC-0000C07D88CF}[HKEY_LOCAL_MACHINE] -> http://www.ipix.com/viewers/ipixx.cab[iPIX ActiveX Control] -> 
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab[McAfee.com Operating System Class] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162985822921[MUWebControl Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab[Reg Error: Key does not exist or could not be opened.] -> 
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}[HKEY_LOCAL_MACHINE] -> http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab[DwnldGroupMgr Class] -> 
{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 



[Files/Folders - Created Within 30 days]
09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier
aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier
avenger -> %SystemDrive%\avenger ->  [Folder | Created Date = 2/12/2008 8:10:33 PM | Attr =	]
HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier
HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier
VundoFix Backups -> %SystemDrive%\VundoFix Backups ->  [Folder | Created Date = 2/11/2008 4:09:28 PM | Attr =	]
VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 2/11/2008 4:38:42 PM | Attr =	]
LastGood -> %SystemRoot%\LastGood ->  [Folder | Created Date = 2/13/2008 8:30:29 AM | Attr =	]

[Files/Folders - Modified Within 30 days]
09_bobble_pooh.zip -> %SystemDrive%\09_bobble_pooh.zip ->  [Ver =  | Size = 262756 bytes | Modified Date = 2/9/2008 9:36:49 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\09_bobble_pooh.zip:Zone.Identifier
9f0e322cd95532de9dec04aff738e10c -> %SystemDrive%\9f0e322cd95532de9dec04aff738e10c ->  [Folder | Modified Date = 2/5/2008 9:50:23 AM | Attr =	]
aaw2007.exe -> %SystemDrive%\aaw2007.exe ->  [Ver =  | Size = 21364592 bytes | Modified Date = 2/7/2008 5:41:58 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\aaw2007.exe:Zone.Identifier
avenger -> %SystemDrive%\avenger ->  [Folder | Modified Date = 2/12/2008 8:10:33 PM | Attr =	]
Documents and Settings -> %SystemDrive%\Documents and Settings ->  [Folder | Modified Date = 2/12/2008 8:04:58 PM | Attr =	]
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 266407936 bytes | Modified Date = 2/13/2008 3:13:27 AM | Attr =  HS]
HiJackThis.zip -> %SystemDrive%\HiJackThis.zip ->  [Ver =  | Size = 318369 bytes | Modified Date = 2/5/2008 12:10:09 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HiJackThis.zip:Zone.Identifier
HJTInstall.exe -> %SystemDrive%\HJTInstall.exe -> Trend Micro Inc. [Ver = 2.00.2 | Size = 812344 bytes | Modified Date = 2/5/2008 12:09:46 PM | Attr =	]
@Alternate Data Stream - 26 bytes -> %SystemDrive%\HJTInstall.exe:Zone.Identifier
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 2/11/2008 6:09:17 PM | Attr =	]
Temp -> %SystemDrive%\Temp ->  [Folder | Modified Date = 2/4/2008 8:02:36 PM | Attr =	]
VundoFix Backups -> %SystemDrive%\VundoFix Backups ->  [Folder | Modified Date = 2/11/2008 5:32:46 PM | Attr =	]
WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 2/13/2008 8:30:29 AM | Attr =	]
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 2/13/2008 8:07:45 AM | Attr =	]
DLLCACHE -> %SystemRoot%\System32\DLLCACHE ->  [Folder | Modified Date = 2/13/2008 3:04:36 AM | Attr = RHS]
DRIVERS -> %SystemRoot%\System32\DRIVERS ->  [Folder | Modified Date = 2/13/2008 3:04:36 AM | Attr =	]
VundoFixSVC.exe -> %SystemRoot%\System32\VundoFixSVC.exe -> Atribune.org [Ver = 1.00.0003 | Size = 24576 bytes | Modified Date = 2/11/2008 4:38:42 PM | Attr =	]
WPA.DBL -> %SystemRoot%\System32\WPA.DBL ->  [Ver =  | Size = 1170 bytes | Modified Date = 2/13/2008 7:44:14 AM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Modified Date = 2/12/2008 7:36:51 PM | Attr =  H ]
BOOTSTAT.DAT -> %SystemRoot%\BOOTSTAT.DAT ->  [Ver =  | Size = 2048 bytes | Modified Date = 2/13/2008 3:13:28 AM | Attr =   S]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Modified Date = 2/13/2008 9:08:42 AM | Attr =   S]
imsins.BAK -> %SystemRoot%\imsins.BAK ->  [Ver =  | Size = 1374 bytes | Modified Date = 2/13/2008 3:04:15 AM | Attr =	]
INF -> %SystemRoot%\INF ->  [Folder | Modified Date = 2/13/2008 3:04:40 AM | Attr =  H ]
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 2/11/2008 3:43:35 PM | Attr =  HS]
LastGood -> %SystemRoot%\LastGood ->  [Folder | Modified Date = 2/13/2008 8:30:29 AM | Attr =	]
oplimit.ini -> %SystemRoot%\oplimit.ini ->  [Ver =  | Size = 732 bytes | Modified Date = 2/12/2008 8:34:08 PM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 2/13/2008 3:04:53 AM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 2/13/2008 7:45:44 AM | Attr =  H ]
SYSTEM32 -> %SystemRoot%\SYSTEM32 ->  [Folder | Modified Date = 2/13/2008 3:13:25 AM | Attr =	]
Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 2/13/2008 9:08:42 AM | Attr =	]
vista32.ini -> %SystemRoot%\vista32.ini ->  [Ver =  | Size = 1050 bytes | Modified Date = 2/13/2008 7:46:51 AM | Attr =	]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job ->  [Ver =  | Size = 284 bytes | Modified Date = 2/1/2008 3:52:08 PM | Attr =	]
HP DArC Task #Hewlett-Packard#hp psc 1300 series#1160674985.job -> %SystemRoot%\tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1160674985.job ->  [Ver =  | Size = 344 bytes | Modified Date = 2/12/2008 12:46:08 PM | Attr =	]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 2/13/2008 3:13:35 AM | Attr =  H ]
about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat ->  [Ver =  | Size = 1528 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat ->  [Ver =  | Size = 327746 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat ->  [Ver =  | Size = 102 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat ->  [Ver =  | Size = 12283223 bytes | Modified Date = 6/18/2003 12:00:00 PM | Attr =	]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 4617 bytes | Modified Date = 2/12/2008 7:37:36 PM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 4232 bytes | Modified Date = 2/12/2008 7:37:36 PM | Attr =	]
SSUPDATE.EXE -> C:\Documents and Settings\Kelly\Local Settings\Temp\SSUPDATE.EXE -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 146672 bytes | Modified Date = 6/21/2007 2:07:10 PM | Attr =	]
136 C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Kelly\Local Settings\Temp\*.tmp -> 
fsgk32.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe -> F-Secure Corp. [Ver = 7.50.13332.1 | Size = 368640 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
fssm32.exe -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe -> F-Secure Corp. [Ver = 7.50.13332.1 | Size = 446464 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
lsse.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Spyware\lsse.dll -> Lavasoft [Ver = 1.0.35.0 | Size = 184320 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
AVPFPI0.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\AVPFPI0.dll -> Kaspersky Lab [Ver = 7.0.171.8410 | Size = 147538 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
avpproxy.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\avpproxy.dll -> F-Secure Corporation [Ver = 1.2.12160 | Size = 77910 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
daas_s.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\daas_s.dll -> F-Secure Corporation [Ver = 6.00.12471 | Size = 500120 bytes | Modified Date = 5/7/2007 4:38:46 PM | Attr =	]
DFFPI.DLL -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\DFFPI.DLL -> F-Secure Corporation [Ver = 1.02.37 | Size = 151552 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
fm4av.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fm4av.dll ->  [Ver =  | Size = 486912 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
fpinor.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fpinor.dll -> F-Secure Corporation [Ver = 1.20.13100 | Size = 113664 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
fsbl.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fsbl.dll -> F-Secure Corporation [Ver = 1, 0, 0, 1 | Size = 49152 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
fsbld.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fsbld.dll -> F-Secure Corporation [Ver = 1, 0, 0, 64 | Size = 524288 bytes | Modified Date = 2/13/2008 9:09:45 AM | Attr =	]
fsgkiapi.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgkiapi.dll -> F-Secure Corp. [Ver = 7.50.13330.18100 | Size = 68096 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
FSHKE.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FSHKE.dll -> F-Secure Corporation [Ver = 1, 0, 0, 4 | Size = 61440 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
FSLFPI.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FSLFPI.dll -> F-Secure Corporation [Ver = 2.04.02 | Size = 237664 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
fssubmit.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fssubmit.dll -> F-Secure Corporation [Ver = 1.0.11 | Size = 651264 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
lsse.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\lsse.dll -> Lavasoft [Ver = 1.0.35.0 | Size = 184320 bytes | Modified Date = 2/13/2008 8:38:36 AM | Attr =	]
Nse_w32.dll -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\Nse_w32.dll ->  [Ver =  | Size = 506936 bytes | Modified Date = 2/13/2008 8:38:04 AM | Attr =	]
segrules.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\segrules.dat ->  [Ver =  | Size = 707 bytes | Modified Date = 2/12/2008 8:44:34 PM | Attr =	]
ext.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\ext.dat ->  [Ver =  | Size = 444 bytes | Modified Date = 2/12/2008 8:50:01 PM | Attr =	]
fshke.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\fshke.dat ->  [Ver =  | Size = 84 bytes | Modified Date = 2/12/2008 8:50:02 PM | Attr =	]
orion.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\orion.dat ->  [Ver =  | Size = 737214 bytes | Modified Date = 2/13/2008 8:36:23 AM | Attr =	]
orioneng.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\orioneng.dat ->  [Ver =  | Size = 1325 bytes | Modified Date = 2/13/2008 8:36:23 AM | Attr =	]
orionfin.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\orionfin.dat ->  [Ver =  | Size = 1599 bytes | Modified Date = 2/13/2008 8:36:23 AM | Attr =	]
perf.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\perf.dat ->  [Ver =  | Size = 128 bytes | Modified Date = 2/13/2008 9:10:24 AM | Attr =	]
sae.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\sae.dat ->  [Ver =  | Size = 243 bytes | Modified Date = 2/12/2008 8:50:01 PM | Attr =	]
sai.dat -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\sai.dat ->  [Ver =  | Size = 1348 bytes | Modified Date = 2/12/2008 8:50:01 PM | Attr =	]
FS@swdb.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Spyware\FS@swdb.ini ->  [Ver =  | Size = 205 bytes | Modified Date = 2/12/2008 8:50:00 PM | Attr =	]
FS@av.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@av.ini ->  [Ver =  | Size = 203 bytes | Modified Date = 2/12/2008 8:50:01 PM | Attr =	]
FS@avpe.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@avpe.ini ->  [Ver =  | Size = 205 bytes | Modified Date = 2/13/2008 8:36:16 AM | Attr =	]
FS@bleng.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@bleng.ini ->  [Ver =  | Size = 241 bytes | Modified Date = 2/13/2008 9:09:44 AM | Attr =	]
FS@hkeng.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@hkeng.ini ->  [Ver =  | Size = 206 bytes | Modified Date = 2/12/2008 8:50:02 PM | Attr =	]
FS@libra.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@libra.ini ->  [Ver =  | Size = 206 bytes | Modified Date = 2/13/2008 8:36:30 AM | Attr =	]
FS@ols3bin.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@ols3bin.ini ->  [Ver =  | Size = 175 bytes | Modified Date = 2/13/2008 8:38:35 AM | Attr =	]
FS@orion.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@orion.ini ->  [Ver =  | Size = 206 bytes | Modified Date = 2/13/2008 8:36:23 AM | Attr =	]
FS@peg.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@peg.ini ->  [Ver =  | Size = 204 bytes | Modified Date = 2/13/2008 8:38:04 AM | Attr =	]
verdicts.ini -> C:\Documents and Settings\Kelly\Local Settings\Temp\OnlineScanner\Anti-Virus\verdicts.ini ->  [Ver =  | Size = 2539 bytes | Modified Date = 2/13/2008 8:36:19 AM | Attr =	]
index.dat -> C:\WINDOWS\Temp\Cookies\index.dat ->  [Ver =  | Size = 32768 bytes | Modified Date = 2/13/2008 7:48:14 AM | Attr =  HS]
index.dat -> C:\WINDOWS\Temp\History\History.IE5\index.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 2/13/2008 7:48:14 AM | Attr =  HS]
index.dat -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat ->  [Ver =  | Size = 32768 bytes | Modified Date = 2/13/2008 7:48:14 AM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\History\History.IE5\desktop.ini ->  [Ver =  | Size = 145 bytes | Modified Date = 2/12/2008 9:45:41 PM | Attr =  HS]
mcdelta.ini -> C:\WINDOWS\Temp\mcu45.tmp\vso\mcdelta.ini ->  [Ver =  | Size = 998 bytes | Modified Date = 2/12/2008 9:47:04 PM | Attr =	]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/12/2008 9:45:39 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\50WJWV3B\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/12/2008 9:45:40 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8AUZV1FT\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/12/2008 9:45:40 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\C329C8AE\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/12/2008 9:45:40 PM | Attr =  HS]
desktop.ini -> C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\W0J0F6FR\desktop.ini ->  [Ver =  | Size = 67 bytes | Modified Date = 2/12/2008 9:45:40 PM | Attr =  HS]

< End of report >


#14 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:10:33 PM

Posted 13 February 2008 - 01:15 PM

Hi kellydoz. Everything looks fine in all the logs and reports. Good job! How are things runing? Any more issues? If not, run the system for a few days and then get back to me. We've got some final cleanup to do and then you are free!

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#15 kellydoz

kellydoz
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:11:33 PM

Posted 13 February 2008 - 01:26 PM

Things seem to be running smoothly. Thank you!!! I will check back in a few days! After I get the "all clear", do you have a recommendation for some good antispyware software for maintenence to keep it form getting this bad again?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users