Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Any Help Would Be Greatly Appreciated!


  • Please log in to reply
3 replies to this topic

#1 wv14

wv14

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:30 PM

Posted 04 March 2008 - 03:01 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:07 PM, on 3/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
c:\program files\ahmcc\ftpit\ftpitscheduler.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Lexmark 6200 Series\lxbumon.exe
C:\Program Files\Lexmark 6200 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\lxbucoms.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Ryan\LOCALS~1\Temp\Temporary Directory 1 for HiJackThis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alliedmortgagecorp.com/mgr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {36F469EF-255C-4D93-B6BA-EF4665C05F46} - C:\WINDOWS\System32\glru32.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [lxbumon.exe] "C:\Program Files\Lexmark 6200 Series\lxbumon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 6200 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://www.spywarenuker.com/product/camp/o...erInstaller.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.taylorbeanonline.com/scriptx/smsx.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173281665734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173327098250
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_In...ller/dwnldr.cab
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FTPitScheduler - - c:\program files\ahmcc\ftpit\ftpitscheduler.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - Unknown owner - C:\WINDOWS\wanmpsvc.exe (file missing)

--
End of file - 10769 bytes

BC AdBot (Login to Remove)

 


m

#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:11:30 PM

Posted 15 March 2008 - 01:51 AM

Hello wv14 and welcome to the BC HijackThis forum. I don't see anything active in the log but it looks like there might have been something at one time. Is there anything currently going on that shouldn't be (or something not going on that should be)?

Let's take a look and see if anything else is left.

Before running a new scan let's clean out the temporoary folders.

Download ATF Cleaner to your Desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Close ALL Internet browsers (very important).
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.

Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program (if you are running on Vista then right-click the program and choose Run as Administrator).
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    • Reg - BotCheck
      File - Additional Folder Scans
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. Make sure that the first line is code with brackets around it [] and that the last line is /code with brackets around it [].

If, after posting, the last line is not <End of Report> then the log is too big to fit into a single post and you will need to split it into multiple posts or attach it as a file.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 wv14

wv14
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:30 PM

Posted 18 March 2008 - 10:38 AM

Thank you sooo much for the help. I've been having troubles with my computer. Sometimes when I shut my computer down it will not reboot properly. It seems like it will reboot and then shuts itself down again. I have to boot it with "the last correct settings" in order to get it to boot up. Once again thank you so much for looking at all of this for me. Here is the report you wanted.

Ryan


OTScanIt logfile created on: 3/18/2008 11:25:36 AM
OTScanIt by OldTimer - Version 1.0.5.2	 Folder = C:\Documents and Settings\Ryan\Desktop\OTScanIt
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
254.98 Mb Total Physical Memory | 105.57 Mb Available Physical Memory | 41.40% Memory free
755.95 Mb Paging File | 437.38 Mb Available in Paging File | 57.86% Paging File free
Paging file location(s): c:\pagefile.sys 384 768;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.50 Gb Total Space | 52.91 Gb Free Space | 71.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALLIED
Current User Name: Ryan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user

[Processes - Non-Microsoft Only]
incdsrv.exe -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> Nero AG [Ver = 4, 3, 23, 0 | Size = 878592 bytes | Modified Date = 1/16/2006 12:46:12 PM | Attr =	]
photoshopelementsfileagent.exe -> %ProgramFiles%\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ->  [Ver =  | Size = 124832 bytes | Modified Date = 10/2/2007 3:46:56 PM | Attr =	]
acsd.exe -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,25,3 | Size = 1434848 bytes | Modified Date = 4/21/2004 12:16:02 PM | Attr =	]
ftpitscheduler.exe -> %ProgramFiles%\AHMCC\FTPit\FTPitScheduler.exe ->   [Ver = 4.2.2.0 | Size = 65536 bytes | Modified Date = 4/23/2006 4:03:44 PM | Attr =	]
directcd.exe -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.2.0.91 | Size = 679936 bytes | Modified Date = 4/10/2002 6:44:04 PM | Attr =	]
support.exe -> %CommonProgramFiles%\Dell\EUSW\Support.exe -> Dell [Ver = 2, 1, 1, 0 | Size = 323584 bytes | Modified Date = 5/27/2004 9:05:42 PM | Attr =	]
pptd40nt.exe -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 3/17/2005 2:25:54 PM | Attr =	]
notifyalert.exe -> %ProgramFiles%\Dell\Support\Alert\bin\NotifyAlert.exe ->   [Ver = 2.1.0.72 | Size = 352256 bytes | Modified Date = 10/7/2003 5:20:18 PM | Attr =	]
brctrcen.exe -> %ProgramFiles%\Brother\ControlCenter2\brctrcen.exe -> Brother Industries, Ltd. [Ver = 2, 1, 64, 48 | Size = 995328 bytes | Modified Date = 11/11/2005 6:30:22 PM | Attr =	]
apdproxy.exe -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 6/6/2005 11:46:24 PM | Attr =	]
nod32kui.exe -> %ProgramFiles%\ESET\nod32kui.exe -> Eset  [Ver = 2, 70, 39  | Size = 949376 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
fppdis3a.exe -> %SystemRoot%\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe -> FinePrint Software, LLC [Ver = 3.17 | Size = 503808 bytes | Modified Date = 4/20/2007 2:42:20 PM | Attr =	]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_05\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 144784 bytes | Modified Date = 2/22/2008 5:25:21 AM | Attr =	]
lxbumon.exe -> %ProgramFiles%\Lexmark 6200 Series\lxbumon.exe -> Lexmark International, Inc. [Ver = 1.206.0.0 | Size = 196608 bytes | Modified Date = 1/18/2005 10:35:38 AM | Attr =	]
ezprint.exe -> %ProgramFiles%\Lexmark 6200 Series\ezprint.exe ->  [Ver =  | Size = 61440 bytes | Modified Date = 9/17/2004 1:24:02 PM | Attr =	]
mssysmgr.exe -> %ProgramFiles%\Nero\data\Xtras\mssysmgr.exe -> Ahead Software [Ver = 1.0.1.0 | Size = 212992 bytes | Modified Date = 2/25/2005 8:28:03 PM | Attr =	]
nod32krn.exe -> %ProgramFiles%\ESET\nod32krn.exe -> Eset  [Ver = 2, 70, 39  | Size = 552064 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
nvsvc32.exe -> %SystemRoot%\SYSTEM32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.5216 | Size = 81920 bytes | Modified Date = 10/6/2003 3:16:00 PM | Attr =	]
symlcsvc.exe -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> Symantec Corporation [Ver = 1.9.1.1080 | Size = 1174152 bytes | Modified Date = 3/7/2007 12:09:48 PM | Attr =	]
lxbucoms.exe -> %SystemRoot%\SYSTEM32\lxbucoms.exe -> Lexmark International, Inc. [Ver = 1.101.75.0 | Size = 462848 bytes | Modified Date = 1/6/2005 6:41:22 PM | Attr =	]
otscanit.exe -> %UserProfile%\Desktop\OTScanIt\OTScanIt.exe -> OldTimer Tools [Ver = 1.0.5.2 | Size = 310784 bytes | Modified Date = 3/14/2008 2:57:26 PM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(AdobeActiveFileMonitor6.0) Adobe Active File Monitor V6 [Win32_Own | Auto | Running] -> %ProgramFiles%\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ->  [Ver =  | Size = 124832 bytes | Modified Date = 10/2/2007 3:46:56 PM | Attr =	]
(AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\acsd.exe -> America Online, Inc. [Ver = 1,0,25,3 | Size = 1434848 bytes | Modified Date = 4/21/2004 12:16:02 PM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 3:56:48 AM | Attr =	]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 1/14/2008 2:46:36 PM | Attr =	]
(FTPitScheduler) FTPitScheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\AHMCC\FTPit\FTPitScheduler.exe ->   [Ver = 4.2.2.0 | Size = 65536 bytes | Modified Date = 4/23/2006 4:03:44 PM | Attr =	]
(InCDsrvR) InCD Helper (read only) [Win32_Own | Auto | Running] -> %ProgramFiles%\Ahead\InCD\InCDsrv.exe -> Nero AG [Ver = 4, 3, 23, 0 | Size = 878592 bytes | Modified Date = 1/16/2006 12:46:12 PM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.1.1.5 | Size = 500800 bytes | Modified Date = 3/14/2007 7:05:42 PM | Attr =	]
(lxbu_device) lxbu_device [Win32_Own | On_Demand | Running] -> %SystemRoot%\SYSTEM32\lxbucoms.exe -> Lexmark International, Inc. [Ver = 1.101.75.0 | Size = 462848 bytes | Modified Date = 1/6/2005 6:41:22 PM | Attr =	]
(NMSSvc) Intel(R) NMS [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\NMSSvc.Exe -> Intel Corporation [Ver = 2.1.8.1 | Size = 1118208 bytes | Modified Date = 5/3/2002 1:29:42 PM | Attr =	]
(NOD32krn) NOD32 Kernel Service [Win32_Own | Auto | Running] -> %ProgramFiles%\ESET\nod32krn.exe -> Eset  [Ver = 2, 70, 39  | Size = 552064 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\SYSTEM32\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.5216 | Size = 81920 bytes | Modified Date = 10/6/2003 3:16:00 PM | Attr =	]
(SBService) ScriptBlocking Service [Win32_Own | Auto | Stopped] -> %SystemDrive%\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe -> File not found
(SNDSrvc) Symantec Network Drivers Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SNDSrvc.exe -> Symantec Corporation [Ver = 6.0.6.604 | Size = 214672 bytes | Modified Date = 3/28/2007 6:52:18 PM | Attr =	]
(STOPzilla Local Service) STOPzilla Local Service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\STOPzilla!\szntsvc.exe -> File not found
(SupportSoft RemoteAssist) SupportSoft RemoteAssist [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\supportsoft\bin\ssrc.exe -> SupportSoft, Inc. [Ver = 6.9.2555.0 | Size = 382320 bytes | Modified Date = 12/11/2007 5:39:12 AM | Attr =	]
(Symantec Core LC) Symantec Core LC [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> Symantec Corporation [Ver = 1.9.1.1080 | Size = 1174152 bytes | Modified Date = 3/7/2007 12:09:48 PM | Attr =	]
(WANMiniportService) WAN Miniport (ATW) Service [Win32_Own | Auto | Stopped] -> %SystemRoot%\wanmpsvc.exe -> File not found

[Driver Services - Non-Microsoft Only]
(Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] ->  -> File not found
(ac97intc) Intel(r) 82801 Audio Driver Install Service (WDM) [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ac97intc.sys -> Intel Corporation [Ver = 5.10.3523 built by: WinDDK | Size = 96256 bytes | Modified Date = 8/17/2001 2:20:04 PM | Attr =	]
(aeaudio) aeaudio [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\aeaudio.sys -> Andrea Electronics Corporation [Ver = 1.0.0.2 (STUB) | Size = 4816 bytes | Modified Date = 4/1/2002 3:15:00 PM | Attr =	]
(AliIde) AliIde [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\aliide.sys -> Acer Laboratories Inc. [Ver = 1.20 | Size = 5248 bytes | Modified Date = 9/3/2002 12:27:16 PM | Attr =	]
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\amdagp.sys -> Advanced Micro Devices, Inc. [Ver = 5.00 (xpsp_sp2_rtm.040803-2158) | Size = 43008 bytes | Modified Date = 8/4/2004 2:07:42 AM | Attr =	]
(AMON) AMON [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\amon.sys -> Eset  [Ver = 2, 70, 39  | Size = 512096 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
(asc) asc [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\asc.sys -> Advanced System Products, Inc. [Ver = 2.9I-MS (XPClient.010817-1148) | Size = 26496 bytes | Modified Date = 9/3/2002 12:27:30 PM | Attr =	]
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\asc3550.sys -> Advanced System Products, Inc. [Ver = 3.1E-MS (XPClient.010817-1148) | Size = 14848 bytes | Modified Date = 9/3/2002 12:27:30 PM | Attr =	]
(ASCTRM) ASCTRM [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\asctrm.sys -> Windows (R) 2000 DDK provider [Ver = 5.00.2195.1 | Size = 8552 bytes | Modified Date = 1/7/2003 2:32:59 AM | Attr =	]
(Atdisk) Atdisk [Kernel | Disabled | Stopped] ->  -> File not found
(ATWPKT2) ATWPKT2 [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\AOL\ACS\ATWPkt2.sys -> America Online [Ver = 9.0.0.5 | Size = 17937 bytes | Modified Date = 4/20/2004 2:49:06 PM | Attr =	]
(basic2) basic2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_BSC2.sys -> Conexant [Ver = 3.05.12.04 | Size = 67167 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(bvrp_pci) bvrp_pci [Kernel | On_Demand | Stopped] ->  -> File not found
(Cdr4_xp) Cdr4_xp [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\cdr4_xp.sys -> Sonic Solutions [Ver = 8.0.0.212  | Size = 9336 bytes | Modified Date = 1/14/2008 2:38:04 PM | Attr =	]
(Cdralw2k) Cdralw2k [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\cdralw2k.sys -> Sonic Solutions [Ver = 8.0.0.212  | Size = 9464 bytes | Modified Date = 1/14/2008 2:38:04 PM | Attr =	]
(cdudf_xp) cdudf_xp [File_System | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\cdudf_xp.sys -> Roxio [Ver = 5.2.0.91 built by: WinDDK | Size = 236032 bytes | Modified Date = 4/10/2002 6:48:04 PM | Attr =	]
(Changer) Changer [Kernel | System | Stopped] ->  -> File not found
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\cmdide.sys -> CMD Technology, Inc. [Ver = 2.0.7 (XPClient.010817-1148) | Size = 6656 bytes | Modified Date = 9/3/2002 12:29:01 PM | Attr =	]
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dac2w2k.sys -> Mylex Corporation [Ver = 6.00-21 (XPClient.010817-1148) | Size = 179584 bytes | Modified Date = 9/3/2002 12:30:26 PM | Attr =	]
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 8/4/2004 2:07:17 AM | Attr =	]
(dmio) dmio [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 8/4/2004 2:07:16 AM | Attr =	]
(dmload) dmload [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 9/3/2002 12:31:06 PM | Attr =	]
(dvd_2K) dvd_2K [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\Dvd_2k.sys -> Roxio [Ver = 5.2.0.91 | Size = 24554 bytes | Modified Date = 4/10/2002 7:01:12 PM | Attr =	]
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\e100b325.sys -> Intel Corporation [Ver = 6.01.03.0010 built by: WinDDK | Size = 139776 bytes | Modified Date = 4/30/2002 2:53:08 PM | Attr =	]
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> Symantec Corporation [Ver = 107.2.0.100 | Size = 389432 bytes | Modified Date = 4/4/2007 4:00:00 AM | Attr =	]
(EL90XBC) 3Com EtherLink XL 90XB/C Adapter Driver [Kernel | On_Demand | Stopped] ->  -> File not found
(EUSBMSD) eUSB SmartMedia Driver [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\EUSBMSD.SYS -> SCM Microsystems Inc. [Ver = 2.14 | Size = 50528 bytes | Modified Date = 8/27/2001 3:29:26 PM | Attr =	]
(Fallback) Fallback [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_FALL.sys -> Conexant [Ver = 3.05.12.04 | Size = 289887 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(fsbl) F-Secure BlackLight Engine Driver [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\Ryan\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsbldrv.sys -> File not found
(Fsks) Fsks [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_FSKS.sys -> Conexant [Ver = 3.05.12.04 | Size = 115807 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(GEARAspiWDM) GEARAspiWDM [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 4:44:04 PM | Attr =	]
(HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSFHWBS2.sys -> Conexant Systems [Ver = 5.03.04.05 | Size = 167155 bytes | Modified Date = 6/30/2002 9:50:12 PM | Attr =	]
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_DP.sys -> Conexant Systems [Ver = 5.03.04.05 | Size = 1172416 bytes | Modified Date = 6/30/2002 9:49:46 PM | Attr =	]
(hsf_msft) hsf_msft [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_MSFT.sys -> Conexant [Ver = 3.05.12.06 | Size = 542879 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(i81x) i81x [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\i81xnt5.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 161020 bytes | Modified Date = 8/3/2004 11:29:38 PM | Attr =	]
(iAimFP0) iAimFP0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wadv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12415 bytes | Modified Date = 8/3/2004 11:29:38 PM | Attr =	]
(iAimFP1) iAimFP1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wadv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12127 bytes | Modified Date = 8/3/2004 11:29:38 PM | Attr =	]
(iAimFP2) iAimFP2 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wadv05nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 11775 bytes | Modified Date = 8/3/2004 11:29:38 PM | Attr =	]
(iAimFP3) iAimFP3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wsiintxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 12063 bytes | Modified Date = 8/3/2004 11:29:48 PM | Attr =	]
(iAimFP4) iAimFP4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wvchntxx.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19455 bytes | Modified Date = 8/3/2004 11:29:50 PM | Attr =	]
(iAimTV0) iAimTV0 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\watv01nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 29311 bytes | Modified Date = 8/3/2004 11:29:42 PM | Attr =	]
(iAimTV1) iAimTV1 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\watv02nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 19551 bytes | Modified Date = 8/3/2004 11:29:44 PM | Attr =	]
(iAimTV2) iAimTV2 [Kernel | On_Demand | Stopped] ->  -> File not found
(iAimTV3) iAimTV3 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\watv04nt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 33599 bytes | Modified Date = 8/3/2004 11:29:44 PM | Attr =	]
(iAimTV4) iAimTV4 [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\wch7xxnt.sys -> Intel(R) Corporation [Ver = 6.13.01.3198  | Size = 23615 bytes | Modified Date = 8/3/2004 11:29:46 PM | Attr =	]
(InCDfs) InCD File System [File_System | Disabled | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\InCDfs.sys -> Nero AG [Ver = 4, 3, 23, 0 | Size = 102016 bytes | Modified Date = 1/17/2006 11:09:34 AM | Attr =	]
(InCDPass) InCDPass [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\InCDpass.sys -> Nero AG [Ver = 4, 3, 23, 0 | Size = 29440 bytes | Modified Date = 1/17/2006 11:09:28 AM | Attr =	]
(incdrm) InCD Reader [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\InCDrm.sys -> Nero AG [Ver = 4, 3, 23, 0 | Size = 32640 bytes | Modified Date = 1/17/2006 5:09:26 AM | Attr =	]
(K56) K56 [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_K56K.sys -> Conexant [Ver = 3.05.12.04 | Size = 391199 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(lbrtfdc) lbrtfdc [Kernel | System | Stopped] ->  -> File not found
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\mdmxsdk.sys -> Conexant [Ver = 101.001 | Size = 9855 bytes | Modified Date = 10/22/2001 4:46:42 PM | Attr =	]
(mmc_2K) mmc_2K [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\Mmc_2k.sys -> Roxio [Ver = 5.2.0.91 | Size = 29638 bytes | Modified Date = 4/10/2002 7:01:00 PM | Attr =	]
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\mraid35x.sys -> American Megatrends Inc. [Ver = 6.19 (XPClient.010817-1148) | Size = 17280 bytes | Modified Date = 9/3/2002 12:42:50 PM | Attr =	]
(MxlW2k) MxlW2k [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\MxlW2k.sys -> MusicMatch, Inc. [Ver = 1.1.0.121 | Size = 28352 bytes | Modified Date = 6/6/2004 8:56:02 PM | Attr =	]
(NAVAP) NAVAP [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\NAVAP.SYS -> File not found
(NMSCFG) NIC Management Service Configuration Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\NMSCFG.SYS -> Intel Corporation [Ver = 2.1.3.0 | Size = 9868 bytes | Modified Date = 5/3/2002 1:30:08 PM | Attr =	]
(nod32drv) nod32drv [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\nod32drv.sys ->  [Ver =  | Size = 15424 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\nv4_mini.sys -> NVIDIA Corporation [Ver = 6.14.10.5216 | Size = 1550043 bytes | Modified Date = 10/6/2003 3:16:00 PM | Attr =	]
(omci) OMCI WDM Device Driver [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\omci.sys -> Dell Computer Corporation [Ver = 7, 0, 318, 0 | Size = 17153 bytes | Modified Date = 7/19/2002 12:22:08 PM | Attr =	]
(PCIDump) PCIDump [Kernel | System | Stopped] ->  -> File not found
(PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] ->  -> File not found
(PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] ->  -> File not found
(PDRELI) PDRELI [Kernel | On_Demand | Stopped] ->  -> File not found
(PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] ->  -> File not found
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 9/3/2002 12:53:10 PM | Attr =	]
(pwd_2k) pwd_2k [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\pwd_2K.sys -> Roxio [Ver = 5.2.0.91 | Size = 117898 bytes | Modified Date = 4/10/2002 7:00:44 PM | Attr =	]
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\PxHelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 1/14/2008 2:38:02 PM | Attr =	]
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ql1080.sys -> QLogic Corporation [Ver = 3.04 | Size = 40320 bytes | Modified Date = 9/3/2002 12:53:20 PM | Attr =	]
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ql12160.sys -> QLogic Corporation [Ver = 7.13.02 (W64) | Size = 45312 bytes | Modified Date = 9/3/2002 12:53:21 PM | Attr =	]
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ql1280.sys -> QLogic Corporation [Ver = 7.13.01 (W2K) | Size = 49024 bytes | Modified Date = 9/3/2002 12:53:22 PM | Attr =	]
(Rksample) Rksample [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_SAMP.sys -> Conexant [Ver = 3.05.12.05 | Size = 57471 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 6:25:53 AM | Attr =	]
(Simbad) Simbad [Kernel | Disabled | Stopped] ->  -> File not found
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\sisagp.sys -> Silicon Integrated Systems Corporation [Ver = 5.12.01.2010 (xpsp_sp2_rtm.040803-2158) | Size = 41088 bytes | Modified Date = 8/4/2004 2:07:42 AM | Attr =	]
(smwdm) smwdm [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\smwdm.sys -> Analog Devices, Inc. [Ver = 5.12.01.3515 | Size = 545208 bytes | Modified Date = 8/5/2002 11:23:58 AM | Attr =	]
(SoftFax) SoftFax [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_FAXX.sys -> Conexant [Ver = 3.05.12.04 | Size = 199711 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\sparrow.sys -> Adaptec, Inc. [Ver = v2.0a (ReleaseBinaries.001205-1804) | Size = 19072 bytes | Modified Date = 9/3/2002 1:04:10 PM | Attr =	]
(symc810) symc810 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symc810.sys -> Symbios Logic Inc. [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 16256 bytes | Modified Date = 9/3/2002 1:05:44 PM | Attr =	]
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symc8xx.sys -> LSI Logic [Ver = 5.1.2409.1 (ReleaseBinaries.001205-1804) | Size = 32640 bytes | Modified Date = 9/3/2002 1:05:44 PM | Attr =	]
(SYMDNS) SYMDNS [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symdns.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 12944 bytes | Modified Date = 3/28/2007 6:51:20 PM | Attr =	]
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.3.0.14 | Size = 115000 bytes | Modified Date = 5/10/2007 10:46:54 PM | Attr =	]
(SYMFW) SYMFW [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symfw.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 97936 bytes | Modified Date = 3/28/2007 6:51:26 PM | Attr =	]
(SYMIDS) SYMIDS [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symids.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 31888 bytes | Modified Date = 3/28/2007 6:51:36 PM | Attr =	]
(symlcbrd) symlcbrd [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\symlcbrd.sys -> Symantec Corporation [Ver = 1.8.54.834 | Size = 10344 bytes | Modified Date = 3/6/2007 6:18:21 PM | Attr =	]
(SYMNDIS) SYMNDIS [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symndis.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 28304 bytes | Modified Date = 3/28/2007 6:51:32 PM | Attr =	]
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\symredrv.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 24208 bytes | Modified Date = 3/28/2007 6:51:42 PM | Attr =	]
(SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\symtdi.sys -> Symantec Corporation [Ver = 6.0.6.604 | Size = 189584 bytes | Modified Date = 3/28/2007 6:51:48 PM | Attr =	]
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\sym_hi.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 28384 bytes | Modified Date = 9/3/2002 1:05:45 PM | Attr =	]
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\sym_u3.sys -> LSI Logic [Ver = 5.1.2462.0 (Lab01_N.010309-0027) | Size = 30688 bytes | Modified Date = 9/3/2002 1:05:45 PM | Attr =	]
(Tones) Tones [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_TONE.sys -> Conexant [Ver = 3.05.12.04 | Size = 50751 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(UdfReadr_xp) UdfReadr_xp [File_System | System | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\udfreadr_xp.sys -> Roxio [Ver = 5.2.0.91 built by: WinDDK | Size = 206336 bytes | Modified Date = 4/10/2002 6:45:16 PM | Attr =	]
(ultra) ultra [Kernel | Disabled | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ultra.sys -> Promise Technology, Inc. [Ver =  1.43 (Build 0603) | Size = 36736 bytes | Modified Date = 9/3/2002 1:07:50 PM | Attr =	]
(USBFVNETR) NETGEAR MA101	USB Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\SYSTEM32\DRIVERS\ma101rnd.sys -> ATMEL [Ver = 1.03.04.0124 built by: WinDDK | Size = 80000 bytes | Modified Date = 5/29/2002 6:29:10 PM | Attr = R  ]
(V124) V124 [Kernel | Auto | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_V124.sys -> Conexant [Ver = 3.05.12.04 | Size = 488383 bytes | Modified Date = 9/3/2002 12:31:57 PM | Attr =	]
(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 10/9/2002 9:49:42 AM | Attr =	]
(WDICA) WDICA [Kernel | On_Demand | Stopped] ->  -> File not found
(winachsf) winachsf [Kernel | On_Demand | Running] -> %SystemRoot%\SYSTEM32\DRIVERS\HSF_CNXT.sys -> Conexant Systems [Ver = 5.03.04.05 | Size = 594832 bytes | Modified Date = 6/30/2002 9:45:12 PM | Attr =	]

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
AdaptecDirectCD -> %ProgramFiles%\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe -> Roxio [Ver = 5.2.0.91 | Size = 679936 bytes | Modified Date = 4/10/2002 6:44:04 PM | Attr =	]
Adobe Photo Downloader -> %ProgramFiles%\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe -> Adobe Systems Incorporated [Ver = 3.0.0.49815 | Size = 57344 bytes | Modified Date = 6/6/2005 11:46:24 PM | Attr =	]
Adobe Reader Speed Launcher -> %ProgramFiles%\Adobe\Reader 8.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 8.0.0.0 | Size = 39792 bytes | Modified Date = 1/11/2008 11:16:38 PM | Attr =	]
ControlCenter2.0 -> %ProgramFiles%\Brother\ControlCenter2\brctrcen.exe -> Brother Industries, Ltd. [Ver = 2, 1, 64, 48 | Size = 995328 bytes | Modified Date = 11/11/2005 6:30:22 PM | Attr =	]
DwlClient -> %CommonProgramFiles%\Dell\EUSW\Support.exe -> Dell [Ver = 2, 1, 1, 0 | Size = 323584 bytes | Modified Date = 5/27/2004 9:05:42 PM | Attr =	]
EzPrint -> %ProgramFiles%\Lexmark 6200 Series\ezprint.exe ->  [Ver =  | Size = 61440 bytes | Modified Date = 9/17/2004 1:24:02 PM | Attr =	]
IndexSearch -> %ProgramFiles%\ScanSoft\PaperPort\IndexSearch.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 40960 bytes | Modified Date = 3/17/2005 2:45:52 PM | Attr =	]
LXBUCATS -> %SystemRoot%\SYSTEM32\SPOOL\DRIVERS\W32X86\3\lxbutime.dll ->  [Ver = 0.1.11.5 | Size = 69632 bytes | Modified Date = 11/2/2004 4:03:26 PM | Attr =	]
lxbumon.exe -> %ProgramFiles%\Lexmark 6200 Series\lxbumon.exe -> Lexmark International, Inc. [Ver = 1.206.0.0 | Size = 196608 bytes | Modified Date = 1/18/2005 10:35:38 AM | Attr =	]
NAV Agent -> %SystemDrive%\PROGRA~1\NORTON~1\navapw32.exe -> File not found
NeroFilterCheck -> %SystemRoot%\SYSTEM32\NeroCheck.exe -> Nero AG [Ver = 1, 0, 0, 5 | Size = 155648 bytes | Modified Date = 1/12/2006 4:40:44 PM | Attr =	]
nod32kui -> %ProgramFiles%\ESET\nod32kui.exe -> Eset  [Ver = 2, 70, 39  | Size = 949376 bytes | Modified Date = 5/25/2007 10:42:43 AM | Attr =	]
NvCplDaemon -> %SystemRoot%\SYSTEM32\nvcpl.dll -> NVIDIA Corporation [Ver = 6.14.10.5216 | Size = 5058560 bytes | Modified Date = 10/6/2003 3:16:00 PM | Attr =	]
nwiz -> %SystemRoot%\SYSTEM32\nwiz.exe -> NVIDIA Corporation [Ver = 6.14.10.5216 | Size = 741376 bytes | Modified Date = 10/6/2003 3:16:00 PM | Attr =	]
PaperPort PTD -> %ProgramFiles%\ScanSoft\PaperPort\pptd40nt.exe -> ScanSoft, Inc. [Ver = 9.0 | Size = 57393 bytes | Modified Date = 3/17/2005 2:25:54 PM | Attr =	]
pdfFactory Dispatcher v3 -> %SystemRoot%\SYSTEM32\SPOOL\DRIVERS\W32X86\3\fppdis3a.exe -> FinePrint Software, LLC [Ver = 3.17 | Size = 503808 bytes | Modified Date = 4/20/2007 2:42:20 PM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.5 | Size = 282624 bytes | Modified Date = 2/16/2007 10:54:04 AM | Attr =	]
RealTray -> %ProgramFiles%\Real\RealPlayer\realplay.exe -> RealNetworks, Inc. [Ver = 6.0.9.584 | Size = 26112 bytes | Modified Date = 1/7/2003 2:32:52 AM | Attr =	]
SSBkgdUpdate -> %CommonProgramFiles%\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe -> Scansoft, Inc. [Ver = 1, 0, 0, 6 | Size = 155648 bytes | Modified Date = 10/14/2003 10:22:30 AM | Attr = R  ]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_05\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 144784 bytes | Modified Date = 2/22/2008 5:25:21 AM | Attr =	]
Symantec NetDriver Monitor -> %ProgramFiles%\SymNetDrv\SNDMon.exe -> Symantec Corporation [Ver = 6.0.6.604 | Size = 104080 bytes | Modified Date = 5/17/2007 5:15:53 PM | Attr =	]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> 
IMAIL-> Installed = 1 -> 
MAPI-> Installed = 1 -> 
MSFS-> Installed = 1 -> 
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
Microsoft Works Update Detection -> %ProgramFiles%\Microsoft Works\WkDetect.exe -> File not found
NBJ -> %ProgramFiles%\Ahead\Nero BackItUp\NBJ.exe -> Ahead Software AG [Ver = 1, 2, 0, 62 | Size = 2048000 bytes | Modified Date = 2/10/2006 9:40:20 PM | Attr =	]
PhotoShow Deluxe Media Manager -> %ProgramFiles%\Nero\data\Xtras\mssysmgr.exe -> Ahead Software [Ver = 1.0.1.0 | Size = 212992 bytes | Modified Date = 2/25/2005 8:28:03 PM | Attr =	]
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
< Ryan Startup Folder > -> C:\Documents and Settings\Ryan\Start Menu\Programs\Startup -> 
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> 
< HOSTS File > (736 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://go.microsoft.com/fwlink/?LinkId=69157 -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Bar -> http://search.msn.com/spbasic.htm -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://go.microsoft.com/fwlink/?LinkId=54896 -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.alliedmortgagecorp.com/mgr -> 
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. -> 
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> Adobe Systems Incorporated [Ver = 8.0.0.2006102200 | Size = 62080 bytes | Modified Date = 10/23/2006 12:08:42 AM | Attr =	]
{36F469EF-255C-4D93-B6BA-EF4665C05F46} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\System32\glru32.dll [] -> File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 509328 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr =	]
{BDF3E430-B101-42AD-A544-FADC6B084872} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton AntiVirus\NavShExt.dll [CNavExtBho Class] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> 
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton AntiVirus\NavShExt.dll [Norton AntiVirus] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton AntiVirus\NavShExt.dll [Norton AntiVirus] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 132496 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr =	]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_05\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 509328 bytes | Modified Date = 2/22/2008 5:25:19 AM | Attr =	]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{000007C6-17DF-4438-92A4-DE5537471BA3} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{A75C6120-9B36-11d4-A3F0-009027427750} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> 
{217CE92E-3A5D-4AED-ACD2-93C1ED7DF7C0} ->  -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{374AB8AA-DCBD-4E69-A4A1-F5A5454DE1EF} ->	() -> 
{E9E78E6D-1899-48B4-87B6-FDE04B71383C} ->	(Intel(R) PRO/100 M Network Connection) -> 
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{01113300-3E00-11D2-8470-0060089874ED}[HKEY_LOCAL_MACHINE] -> http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab[Support.com Configuration Class] -> 
{15589FA1-C456-11CE-BF01-00AA0055595A}[HKEY_LOCAL_MACHINE] -> http://www.spywarenuker.com/product/camp/overture/SpywareNukerInstaller.exe[Reg Error: Key does not exist or could not be opened.] -> 
{1663ed61-23eb-11d2-b92f-008048fdd814}[HKEY_LOCAL_MACHINE] -> https://www.taylorbeanonline.com/scriptx/smsx.cab[MeadCo ScriptX] -> 
{1D6711C8-7154-40BB-8380-3DEA45B69CBF}[HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.] -> 
{33564D57-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[Reg Error: Key does not exist or could not be opened.] -> 
{33564D57-9980-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://codecs.microsoft.com/codecs/i386/wmv9dmo.cab[Reg Error: Key does not exist or could not be opened.] -> 
{48DD0448-9209-4F81-9F6D-D83562940134}[HKEY_LOCAL_MACHINE] -> http://lads.myspace.com/upload/MySpaceUploader1005.cab[MySpace Uploader Control] -> 
{4F1E5B1A-2A80-42CA-8532-2D05CB959537}[HKEY_LOCAL_MACHINE] -> http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab[MSN Photo Upload Tool] -> 
{6414512B-B978-451D-A0D8-FCFDF33E833C}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173281665734[WUWebControl Class] -> 
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}[HKEY_LOCAL_MACHINE] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173327098250[MUWebControl Class] -> 
{89D75D39-5531-47BA-9E4F-B346BA9C362C}[HKEY_LOCAL_MACHINE] -> http://www.callwave.com/include/cab/CWDL_DownLoad.CAB[CWDL_DownLoadControl Class] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> 
{90C9629E-CD32-11D3-BBFB-00105A1F0D68}[HKEY_LOCAL_MACHINE] -> http://www.installengine.com/engine/isetup.cab[InstallShield International Setup Player] -> 
{BDBDE413-7B1C-4C68-A8FF-C5B2B4090876}[HKEY_LOCAL_MACHINE] -> http://support.f-secure.com/ols/fscax.cab[F-Secure Online Scanner 3.3] -> 
{CA034DCC-A580-4333-B52F-15F98C42E04C}[HKEY_LOCAL_MACHINE] -> https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab[Downloader Class] -> 
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab[Java Plug-in 1.5.0_11] -> 
{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.5.0/jinstall-1_5_0_12-windows-i586.cab[Java Plug-in 1.5.0_12] -> 
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> 
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> 
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab[Java Plug-in 1.6.0_05] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 
DirectAnimation Java Classes[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\dajava.cab[Reg Error: Key does not exist or could not be opened.] -> 
Microsoft XML Parser for Java[HKEY_LOCAL_MACHINE] -> file://C:\WINDOWS\Java\classes\xmldso.cab[Reg Error: Key does not exist or could not be opened.] -> 


[Registry - Additional Scans - Non-Microsoft Only]
< BotCheck > -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\DefaultLaunchPermission -> (binary data) -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\EnableDCOM -> Y -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineLaunchRestriction -> (binary data) -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\\MachineAccessRestriction -> (binary data) -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{A50398B8-9075-4FBF-A7A1-456BF21937AD} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{AD65A69D-3831-40D7-9629-9B0B50A93843} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{0040D221-54A1-11D1-9DE0-006097042D69} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\ActivationSecurityCheckExemptionList\\{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\NONREDIST\\System.EnterpriseServices.Thunk.dll ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusDisableNotify -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\UpdatesDisableNotify -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\AntiVirusOverride -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallOverride -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall\\DisableMonitoring -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall\ -> -> 
Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ not found. -> -> 
Reg Error: Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\ not found. -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\ -> ->
*Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages -> 
msv1_0 -> %SystemRoot%\SYSTEM32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr =	]
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Bounds -> (binary data) -> 
*Security Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Security Packages -> 
kerberos -> %SystemRoot%\SYSTEM32\kerberos.dll -> Microsoft Corporation [Ver = 5.1.2600.2698 (xpsp_sp2_gdr.050614-1522) | Size = 295936 bytes | Modified Date = 6/15/2005 1:49:30 PM | Attr =	]
msv1_0 -> %SystemRoot%\SYSTEM32\msv1_0.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 129536 bytes | Modified Date = 8/4/2004 3:56:43 AM | Attr =	]
schannel -> %SystemRoot%\SYSTEM32\schannel.dll -> Microsoft Corporation [Ver = 5.1.2600.3126 (xpsp_sp2_gdr.070425-0226) | Size = 144896 bytes | Modified Date = 4/25/2007 10:21:15 AM | Attr =	]
wdigest -> %SystemRoot%\SYSTEM32\wdigest.dll -> Microsoft Corporation [Ver = 5.1.2600.2874 (xpsp_sp2_gdr.060323-1516) | Size = 49152 bytes | Modified Date = 3/24/2006 12:37:50 AM | Attr =	]
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\LsaPid -> 536 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\SecureBoot -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\auditbaseobjects -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\crashonauditfail -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\disabledomaincreds -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\everyoneincludesanonymous -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fipsalgorithmpolicy -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\forceguest -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\fullprivilegeauditing -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\limitblankpassworduse -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\lmcompatibilitylevel -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nodefaultadminowner -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\nolmhash -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymous -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\restrictanonymoussam -> 1 -> 
*Notification Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Notification Packages -> 
scecli -> %SystemRoot%\SYSTEM32\scecli.dll -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 180224 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr =	]
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\ImpersonatePrivilegeUpgradeToolHasRun -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\ -> -> 
*ProviderOrder* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\\ProviderOrder -> 
Windows NT Access Provider ->  -> File not found
*MultiFile Done* -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\AccessProviders\Windows NT Access Provider\\ProviderPath -> C:\WINDOWS\SYSTEM32\ntmarta.dll [%SystemRoot%\system32\ntmarta.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 118784 bytes | Modified Date = 8/4/2004 3:56:44 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Audit\PerUserAuditing\System\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Data\\Pattern -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\GBG\\GrafBlumGroup -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\JD\\Lookup -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\SidCache\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminclientsec -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\msv1_0\\ntlmminserversec -> 0 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\\SkewMatrix -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SSO\Passport1.4\\SSOURL -> http://www.passport.com -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\\Time -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Name -> Digest -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Comment -> Digest SSPI Authentication Package -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Capabilities -> 16464 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\RpcId -> 65535 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Version -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\TokenSize -> 65535 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Time -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\digest.dll\\Type -> 49 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Name -> DPA -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Comment -> DPA Security Package -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Capabilities -> 55 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\RpcId -> 17 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Version -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\TokenSize -> 768 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Time -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msapsspc.dll\\Type -> 49 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Name -> MSN -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Comment -> MSN Security Package -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Capabilities -> 55 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\RpcId -> 18 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Version -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\TokenSize -> 768 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Time -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\msnsspc.dll\\Type -> 49 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%SystemRoot%\System32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Windows Firewall/Internet Connection Sharing (ICS) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;WinMgmt; -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup ->  -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 75933 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\ipnathlp.dll [%SystemRoot%\System32\ipnathlp.dll] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 331264 bytes | Modified Date = 8/4/2004 3:56:42 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\S\ -> -> 
-> Reg Error: Key does not exist or could not be opened. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{E9E78E6D-1899-48B4-87B6-FDE04B71383C} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{BAB2DE3E-A608-4D54-B48E-A8B49B64D686} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{392775EB-182C-42E7-A916-36FA99D2D167} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{28131825-0F94-49E9-A49E-DCDB097C6B53} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{497147C6-585A-405F-8AD6-844963BBB88A} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{E7C10E4B-1CF7-4A5F-B4FC-135F6664CBC0} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\{0846AEBA-9073-4159-8E3E-9B8D61ADB90B} -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\0 -> Root\LEGACY_SHAREDACCESS\0000 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> C:\WINDOWS\SYSTEM32\svchost.exe [%systemroot%\system32\svchost.exe -k netsvcs] -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 3:56:57 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Automatic Updates -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\SYSTEM32\wuauserv.dll [C:\WINDOWS\system32\wuauserv.dll] -> Microsoft Corporation [Ver = 5.4.3790.2180 (xpsp_sp2_rtm.040803-2158) | Size = 6656 bytes | Modified Date = 8/4/2004 3:56:46 AM | Attr =	]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> (binary data) -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\0 -> Root\LEGACY_WUAUSERV\0000 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> 
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry\ not found. -> -> 
Reg Error: Key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr\ not found. -> -> 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\ -> ->
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable -> 0 -> 


[Files/Folders - Created Within 30 days]
Config.Msi -> %SystemDrive%\Config.Msi ->  [Folder | Created Date = 3/12/2008 11:17:10 AM | Attr =  HS]
1 C:\*.tmp files -> C:\*.tmp -> 
fsaua.data -> %SystemDrive%\fsaua.data ->  [Folder | Created Date = 3/12/2008 10:08:10 AM | Attr =	]
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 267436032 bytes | Created Date = 2/28/2008 10:57:16 AM | Attr =  HS]
java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Created Date = 3/5/2008 10:00:35 AM | Attr =	]
javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Created Date = 3/5/2008 10:00:35 AM | Attr =	]
javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 139264 bytes | Created Date = 3/5/2008 10:00:35 AM | Attr =	]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
8.5X12Closing coupons.doc -> %UserProfile%\My Documents\8.5X12Closing coupons.doc ->  [Ver =  | Size = 2575872 bytes | Created Date = 3/11/2008 1:27:06 PM | Attr =	]
Closing coupons.doc -> %UserProfile%\My Documents\Closing coupons.doc ->  [Ver =  | Size = 2575872 bytes | Created Date = 3/3/2008 11:01:27 AM | Attr =	]
Closing Package -> %UserProfile%\My Documents\Closing Package ->  [Folder | Created Date = 2/27/2008 10:51:08 AM | Attr =	]
2 C:\Documents and Settings\Ryan\My Documents\*.tmp files -> C:\Documents and Settings\Ryan\My Documents\*.tmp -> 
Adobe Reader 8.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 8.lnk ->  [Ver =  | Size = 1729 bytes | Created Date = 3/7/2008 10:03:30 AM | Attr =	]
Appraisals -> %UserProfile%\Desktop\Appraisals ->  [Folder | Created Date = 2/22/2008 2:19:34 PM | Attr =	]
BRAGG_Appraisal.pdf -> %UserProfile%\Desktop\BRAGG_Appraisal.pdf ->  [Ver =  | Size = 2820110 bytes | Created Date = 3/11/2008 11:38:16 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\BRAGG_Appraisal.pdf:Zone.Identifier
Edwards, Jeremy1003.pdf -> %UserProfile%\Desktop\Edwards, Jeremy1003.pdf ->  [Ver =  | Size = 37760 bytes | Created Date = 3/13/2008 2:43:44 PM | Attr =	]
My Documents.lnk -> %UserProfile%\Desktop\My Documents.lnk ->  [Ver =  | Size = 338 bytes | Created Date = 3/11/2008 5:32:10 PM | Attr =	]
OTScanIt -> %UserProfile%\Desktop\OTScanIt ->  [Folder | Created Date = 3/18/2008 11:07:45 AM | Attr =	]

[Files/Folders - Modified Within 30 days]
Config.Msi -> %SystemDrive%\Config.Msi ->  [Folder | Modified Date = 3/12/2008 11:36:09 AM | Attr =  HS]
1 C:\*.tmp files -> C:\*.tmp -> 
fsaua.data -> %SystemDrive%\fsaua.data ->  [Folder | Modified Date = 3/12/2008 10:08:10 AM | Attr =	]
hiberfil.sys -> %SystemDrive%\hiberfil.sys ->  [Ver =  | Size = 267436032 bytes | Modified Date = 3/12/2008 11:36:14 AM | Attr =  HS]
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 3/12/2008 11:37:09 AM | Attr = R  ]
WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 3/18/2008 6:07:20 AM | Attr =	]
WINPOINT -> %SystemDrive%\WINPOINT ->  [Folder | Modified Date = 3/7/2008 2:26:02 PM | Attr =	]
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 3/11/2008 1:05:38 PM | Attr =	]
1732 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
java.exe -> %SystemRoot%\System32\java.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Modified Date = 2/22/2008 2:23:35 AM | Attr =	]
javacpl.cpl -> %SystemRoot%\System32\javacpl.cpl -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 69632 bytes | Modified Date = 2/22/2008 3:33:31 AM | Attr =	]
javaw.exe -> %SystemRoot%\System32\javaw.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 135168 bytes | Modified Date = 2/22/2008 2:23:39 AM | Attr =	]
javaws.exe -> %SystemRoot%\System32\javaws.exe -> Sun Microsystems, Inc. [Ver = 6.0.50.13 | Size = 139264 bytes | Modified Date = 2/22/2008 3:33:32 AM | Attr =	]
PERFC009.DAT -> %SystemRoot%\System32\PERFC009.DAT ->  [Ver =  | Size = 66936 bytes | Modified Date = 3/12/2008 12:37:43 PM | Attr =	]
PERFH009.DAT -> %SystemRoot%\System32\PERFH009.DAT ->  [Ver =  | Size = 421956 bytes | Modified Date = 3/12/2008 12:37:43 PM | Attr =	]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 493384 bytes | Modified Date = 3/12/2008 12:37:42 PM | Attr =	]
stat.xml -> %SystemRoot%\System32\stat.xml ->  [Ver =  | Size = 1696 bytes | Modified Date = 3/17/2008 11:58:59 AM | Attr =	]
upload.xml -> %SystemRoot%\System32\upload.xml ->  [Ver =  | Size = 593518 bytes | Modified Date = 3/17/2008 11:58:42 AM | Attr =	]
WBEM -> %SystemRoot%\System32\WBEM ->  [Folder | Modified Date = 3/12/2008 12:37:43 PM | Attr =	]
WPA.DBL -> %SystemRoot%\System32\WPA.DBL ->  [Ver =  | Size = 12598 bytes | Modified Date = 3/10/2008 8:57:08 AM | Attr =	]
BOOTSTAT.DAT -> %SystemRoot%\BOOTSTAT.DAT ->  [Ver =  | Size = 2048 bytes | Modified Date = 3/12/2008 11:36:22 AM | Attr =   S]
BRWMARK.INI -> %SystemRoot%\BRWMARK.INI ->  [Ver =  | Size = 426 bytes | Modified Date = 3/11/2008 3:05:01 PM | Attr =	]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Modified Date = 3/12/2008 10:12:06 AM | Attr =   S]
29 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 3/12/2008 11:25:25 AM | Attr =  HS]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 3/18/2008 11:24:38 AM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 2/27/2008 3:33:57 PM | Attr =  H ]
SYSTEM32 -> %SystemRoot%\SYSTEM32 ->  [Folder | Modified Date = 3/14/2008 3:42:04 PM | Attr =	]
Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 3/18/2008 11:14:24 AM | Attr =	]
WIN.INI -> %SystemRoot%\WIN.INI ->  [Ver =  | Size = 695 bytes | Modified Date = 3/12/2008 11:23:40 AM | Attr =	]
winpoint.ini -> %SystemRoot%\winpoint.ini ->  [Ver =  | Size = 1532 bytes | Modified Date = 3/18/2008 11:24:45 AM | Attr =	]
WinSxS -> %SystemRoot%\WinSxS ->  [Folder | Modified Date = 3/7/2008 10:03:19 AM | Attr =	]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 3/12/2008 11:36:34 AM | Attr =  H ]
ABOUT.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\10.0\Webcache\ABOUT.DAT ->  [Ver =  | Size = 1877 bytes | Modified Date = 7/25/2001 12:00:00 PM | Attr =	]
COLLEGE.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\10.0\Webcache\COLLEGE.DAT ->  [Ver =  | Size = 335916 bytes | Modified Date = 7/25/2001 12:00:00 PM | Attr =	]
YLPGSCAT.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\10.0\Webcache\YLPGSCAT.DAT ->  [Ver =  | Size = 12283223 bytes | Modified Date = 7/25/2001 12:00:00 PM | Attr =	]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 5396 bytes | Modified Date = 3/12/2008 11:39:48 AM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 5396 bytes | Modified Date = 3/12/2008 11:39:47 AM | Attr =	]
data.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\data.dat ->  [Ver =  | Size = 1728 bytes | Modified Date = 1/26/2004 9:39:42 PM | Attr =	]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Office\Data\opa11.dat ->  [Ver =  | Size = 11066 bytes | Modified Date = 10/4/2004 8:45:15 PM | Attr =	]
WKCALCAT.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\WKCALCAT.DAT ->  [Ver =  | Size = 16384 bytes | Modified Date = 9/9/2002 6:47:10 PM | Attr =	]
WKLNTNTS.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\WKLNTNTS.DAT ->  [Ver =  | Size = 847160 bytes | Modified Date = 6/20/2007 11:39:10 AM | Attr =	]
WKLNTSK.DAT -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\WKLNTSK.DAT ->  [Ver =  | Size = 847160 bytes | Modified Date = 6/20/2007 11:39:10 AM | Attr =	]
point60b-eu.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\point60b-eu.exe ->  [Ver =  | Size = 3773765 bytes | Modified Date = 11/21/2007 12:22:41 PM | Attr =	]
_is678.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\_is678.exe -> Macrovision Corporation [Ver = 12.0.49974 | Size = 455600 bytes | Modified Date = 10/27/2006 8:25:36 PM | Attr = R  ]
149 C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp -> 
BrMfcMon.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BrMfcMon.exe -> Brother Industries, Ltd. [Ver = 1, 1, 0, 4 | Size = 69632 bytes | Modified Date = 11/19/2004 8:50:26 PM | Attr =	]
BrMfcWnd.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BrMfcWnd.exe -> Brother Industries, Ltd. [Ver = 1, 2, 1, 3 | Size = 802816 bytes | Modified Date = 11/25/2005 2:51:50 PM | Attr =	]
BrMfimon.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BrMfimon.exe -> Brother Industries, Ltd. [Ver = 1, 0, 7, 3 | Size = 217088 bytes | Modified Date = 11/17/2005 7:12:08 PM | Attr =	]
BrCCStoFix.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\BrCCStoFix.exe -> Brother Industries, Ltd. [Ver = 1, 0, 2, 1 | Size = 49152 bytes | Modified Date = 6/18/2004 9:55:10 PM | Attr =	]
brctrcen.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brctrcen.exe -> Brother Industries, Ltd. [Ver = 2, 1, 64, 48 | Size = 995328 bytes | Modified Date = 11/11/2005 6:30:22 PM | Attr =	]
Brmd05.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\Brmd05.exe -> Brother Industries Ltd. [Ver = 1, 1, 1, 0 | Size = 45056 bytes | Modified Date = 1/14/2005 | Attr =	]
BrmfBAgP.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBAgP.exe -> Brother Industries, Ltd. [Ver = 1.10.10.121 | Size = 49152 bytes | Modified Date = 9/10/2004 3:37:44 PM | Attr =	]
BrmfBAgS.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBAgS.exe -> Brother Industries, Ltd. [Ver = 1.10.10.121 | Size = 53248 bytes | Modified Date = 9/10/2004 3:32:48 PM | Attr =	]
BrmfRsmg.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfRsmg.exe -> Brother Industries, Ltd. [Ver = 1.45.15.357 | Size = 31744 bytes | Modified Date = 4/8/2005 1:17:28 PM | Attr =	]
brms105a.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms105a.exe -> Brother Industries,ltd [Ver = 3.83 | Size = 139264 bytes | Modified Date = 8/2/2005 | Attr =	]
brms205a.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms205a.exe -> Brother Industries,ltd [Ver = 3.83 | Size = 139264 bytes | Modified Date = 8/2/2005 | Attr =	]
brms305a.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms305a.exe -> Brother Industries,ltd [Ver = 3.83 | Size = 139264 bytes | Modified Date = 8/2/2005 | Attr =	]
brms405a.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms405a.exe -> Brother Industries,ltd [Ver = 3.83 | Size = 139264 bytes | Modified Date = 8/2/2005 | Attr =	]
brms505a.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms505a.exe -> Brother Industries,ltd [Ver = 3.83 | Size = 139264 bytes | Modified Date = 8/2/2005 | Attr =	]
BRQIKMON.EXE -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRQIKMON.EXE -> Brother Industries Ltd. [Ver = 3.3 | Size = 101888 bytes | Modified Date = 6/16/2005 3:03:00 AM | Attr =	]
brrbtool.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brrbtool.exe -> Brother Industries Ltd [Ver = 1.24 | Size = 69632 bytes | Modified Date = 11/22/2005 1:24:00 AM | Attr =	]
BrmfBAgP.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBAgP.exe -> Brother Industries, Ltd. [Ver = 1.10.10.121 | Size = 49152 bytes | Modified Date = 9/10/2004 3:37:44 PM | Attr =	]
BrmfBAgS.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBAgS.exe -> Brother Industries, Ltd. [Ver = 1.10.10.121 | Size = 53248 bytes | Modified Date = 9/10/2004 3:32:48 PM | Attr =	]
BrmfRmPA.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfRmPA.exe -> Brother Industries, Ltd. [Ver = 1.10.10.248 | Size = 94208 bytes | Modified Date = 11/19/2004 1:57:26 PM | Attr =	]
BrmfRsmg.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfRsmg.exe -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 77824 bytes | Modified Date = 11/7/2005 6:06:44 PM | Attr =	]
AXDIST.EXE -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\WebUpdate\AXDIST.EXE -> Microsoft Corporation [Ver = 4.71.0030.1 | Size = 803680 bytes | Modified Date = 1/28/2000 12:19:24 PM | Attr =	]
WSH.EXE -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\WebUpdate\WSH.EXE -> Microsoft Corporation [Ver = 5.0.531.7 | Size = 574688 bytes | Modified Date = 1/28/2000 12:19:26 PM | Attr =	]
fsgk32.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgk32.exe -> F-Secure Corp. [Ver = 7.60.14020.0 | Size = 413696 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fssm32.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fssm32.exe -> F-Secure Corp. [Ver = 7.60.14020.0 | Size = 494592 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsgk32.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fsgk32.exe -> F-Secure Corp. [Ver = 7.60.14020.0 | Size = 413696 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fssm32.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fssm32.exe -> F-Secure Corp. [Ver = 7.60.14020.0 | Size = 494592 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
Setup.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Setup.exe -> InstallShield Software Corporation [Ver = 5, 52, 164, 0 | Size = 73728 bytes | Modified Date = 1/12/1999 11:42:20 AM | Attr = R  ]
_ISDel.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\_ISDel.exe -> InstallShield Software Corporation [Ver = 5, 51, 138, 0 | Size = 27648 bytes | Modified Date = 10/27/1998 12:06:48 PM | Attr = R  ]
AcroRd32.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\AcroRd32.exe -> Adobe Systems Incorporated [Ver = 5.0.1.2001032700 | Size = 3870784 bytes | Modified Date = 3/27/2001 9:44:58 PM | Attr = R  ]
autoruns.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\Temporary Directory 1 for Autoruns[1].zip\autoruns.exe -> Sysinternals - www.sysinternals.com [Ver = 8.73 | Size = 546176 bytes | Modified Date = 8/19/2007 9:40:16 PM | Attr = R  ]
HijackThis.exe -> C:\Documents and Settings\Ryan\Local Settings\Temp\Temporary Directory 1 for HiJackThis[1].zip\HijackThis.exe -> Trend Micro Inc. [Ver = 2.00.0002 | Size = 401720 bytes | Modified Date = 6/28/2007 3:36:16 PM | Attr =	]
7Z.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\_PASFX823\7Z.DLL ->  [Ver =  | Size = 76288 bytes | Modified Date = 1/14/2008 2:27:52 PM | Attr =	]
ISSetup.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{05798C4F-B76B-4970-BBED-1EB038817D05}\ISSetup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 552214 bytes | Modified Date = 10/27/2006 8:25:37 PM | Attr = R  ]
_Setup.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{05798C4F-B76B-4970-BBED-1EB038817D05}\_Setup.dll -> Macrovision Corporation [Ver = 12.0.49974 | Size = 164784 bytes | Modified Date = 10/27/2006 8:25:36 PM | Attr = R  ]
BRHOOK.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BRHOOK.DLL -> brother [Ver = 1, 0, 1, 0 | Size = 49152 bytes | Modified Date = 2/19/2004 9:58:06 AM | Attr =	]
brif03a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\brif03a.dll -> brother Industries,Ltd [Ver = 1, 0, 2, 1 | Size = 40960 bytes | Modified Date = 7/7/2004 | Attr =	]
brlm03a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\brlm03a.dll -> brother Industries Ltd [Ver = 1, 0, 5, 1 | Size = 24226 bytes | Modified Date = 10/6/2004 | Attr =	]
BRLMW03A.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BRLMW03A.DLL -> Brother Industries, Ltd. [Ver = 1, 0, 0, 182 | Size = 77824 bytes | Modified Date = 8/9/2004 3:42:08 PM | Attr =	]
Brmfcwnd.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\Brmfcwnd.dll -> Brother Industries, Ltd. [Ver = 1, 5, 0, 0 | Size = 53248 bytes | Modified Date = 11/9/2005 3:31:00 PM | Attr =	]
brccfile.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brccfile.dll -> Brother Industries, Ltd. [Ver = 2, 1, 10, 2 | Size = 77824 bytes | Modified Date = 8/4/2005 5:31:28 PM | Attr =	]
brccsrch.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brccsrch.dll -> Brother Industries, Ltd. [Ver = 2, 0, 8, 0 | Size = 53248 bytes | Modified Date = 10/14/2004 7:06:18 PM | Attr =	]
brcctwn.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brcctwn.dll -> Brother Industries, Ltd. [Ver = 2, 1, 17, 9 | Size = 65536 bytes | Modified Date = 11/21/2005 8:34:48 PM | Attr =	]
brccwia.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brccwia.dll -> Brother Industries, Ltd. [Ver = 2, 1, 11, 3 | Size = 102400 bytes | Modified Date = 4/22/2005 4:56:00 PM | Attr =	]
brcnceng.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brcnceng.dll -> Brother Industries, Ltd. [Ver = 2, 1, 8, 5 | Size = 126976 bytes | Modified Date = 10/14/2005 1:24:52 PM | Attr =	]
brcncimg.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brcncimg.dll -> Brother Industries, Ltd. [Ver = 2, 1, 2, 2 | Size = 3235840 bytes | Modified Date = 10/8/2005 9:32:04 AM | Attr =	]
brcncusa.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\brcncusa.dll -> Brother Industries, Ltd. [Ver = 2, 1, 5, 2 | Size = 126976 bytes | Modified Date = 10/14/2005 1:31:22 PM | Attr =	]
BrImgPDF.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\BrImgPDF.dll -> Brother Industries,LTD. [Ver = 1, 0, 0, 1 | Size = 40960 bytes | Modified Date = 4/9/2004 1:47:46 PM | Attr =	]
LFAWD12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFAWD12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 28672 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFBMP12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFBMP12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 36864 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFCMP12n.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFCMP12n.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 314368 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFEPS12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFEPS12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 57344 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFFAX12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFFAX12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 78336 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFLMA12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFLMA12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 35840 bytes | Modified Date = 1/17/2004 11:20:44 PM | Attr =	]
LFLMB12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFLMB12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 32256 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFMSP12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFMSP12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 26112 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFPCX12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFPCX12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 33280 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
Lfpng12n.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\Lfpng12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 164352 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFPNM12n.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFPNM12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 48640 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFTIF12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFTIF12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 155648 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFWFX12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFWFX12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 27136 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
Lfwmf12n.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\Lfwmf12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 59392 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LFWPG12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LFWPG12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 27648 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTDIS12n.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTDIS12n.dll -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 278528 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTEFX12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTEFX12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 227840 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTFIL12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTFIL12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 121344 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTIMG12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTIMG12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 166400 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTKRN12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTKRN12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.012 | Size = 406016 bytes | Modified Date = 1/17/2004 11:20:46 PM | Attr =	]
LTTWN12N.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTTWN12N.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 41472 bytes | Modified Date = 1/17/2004 11:20:48 PM | Attr =	]
LTWND12n.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\LTWND12n.DLL -> LEAD Technologies, Inc. [Ver = 12.1.0.009 | Size = 36864 bytes | Modified Date = 1/17/2004 11:20:48 PM | Attr =	]
maxutil.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\maxutil.dll -> ScanSoft, Inc. [Ver = 9.0 | Size = 106544 bytes | Modified Date = 3/9/2004 5:25:34 PM | Attr =	]
pperr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\ControlCenter\pperr.dll -> ScanSoft, Inc. [Ver = 9.0 | Size = 81966 bytes | Modified Date = 3/9/2004 5:23:26 PM | Attr =	]
BRB1F05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRB1F05A.dll ->  [Ver =  | Size = 71168 bytes | Modified Date = 10/11/2005 1:00:00 AM | Attr =	]
BRB2F05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRB2F05A.dll ->  [Ver =  | Size = 71168 bytes | Modified Date = 10/11/2005 1:00:00 AM | Attr =	]
BRB3F05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRB3F05A.dll ->  [Ver =  | Size = 71168 bytes | Modified Date = 10/4/2005 1:00:00 AM | Attr =	]
BRB4F05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRB4F05A.dll ->  [Ver =  | Size = 71168 bytes | Modified Date = 10/4/2005 1:00:00 AM | Attr =	]
BRB5F05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRB5F05A.dll ->  [Ver =  | Size = 71168 bytes | Modified Date = 10/4/2005 1:00:00 AM | Attr =	]
BrBidiIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrBidiIf.dll -> Brother Industries, Ltd. [Ver = 1.45.15.357 | Size = 19456 bytes | Modified Date = 4/8/2005 1:17:26 PM | Attr =	]
brcinsv2.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brcinsv2.dll -> Brother Industries Ltd. [Ver = 1.0.0.9 | Size = 12288 bytes | Modified Date = 7/15/2005 3:42:18 PM | Attr =	]
Brcolm32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\Brcolm32.dll ->  [Ver =  | Size = 61440 bytes | Modified Date = 4/8/2003 9:10:24 PM | Attr =	]
BrEvIF.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrEvIF.dll -> Brother Industries, Ltd. [Ver = 1.45.15.361 | Size = 13824 bytes | Modified Date = 11/11/2005 12:30:46 PM | Attr =	]
brlm03a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brlm03a.dll -> brother Industries Ltd [Ver = 1, 0, 4, 1 | Size = 24223 bytes | Modified Date = 9/24/2004 | Attr =	]
brlmw03a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brlmw03a.dll -> Brother Industries, Ltd. [Ver = 1, 0, 0, 182 | Size = 77824 bytes | Modified Date = 8/10/2004 12:42:08 AM | Attr =	]
BrmfBidi.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBidi.dll -> Brother Industries, Ltd. [Ver = 1.45.15.357 | Size = 14848 bytes | Modified Date = 4/8/2005 1:17:28 PM | Attr =	]
BrmfBiPP.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBiPP.dll -> Brother Industries, Ltd. [Ver = 1.45.15.472 | Size = 102400 bytes | Modified Date = 9/21/2004 4:57:44 PM | Attr =	]
BrmfLpt.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfLpt.dll -> Brother Industries, Ltd. [Ver = 1.45.15.361 | Size = 30208 bytes | Modified Date = 11/11/2005 12:31:04 PM | Attr =	]
brmfpmbd.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brmfpmbd.dll -> Brother Industries,Ltd. [Ver = 1.00 | Size = 29602 bytes | Modified Date = 9/10/2004 | Attr =	]
BrmfUSB.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfUSB.dll -> Brother Industries, Ltd. [Ver = 1.45.15.357 | Size = 43008 bytes | Modified Date = 4/8/2005 1:17:26 PM | Attr =	]
BRMS105A.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRMS105A.DLL -> Brother Industries, Ltd [Ver = 1.06 | Size = 163840 bytes | Modified Date = 10/11/2005 | Attr =	]
brms205a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms205a.dll -> Brother Industries, Ltd [Ver = 1.06 | Size = 163840 bytes | Modified Date = 10/11/2005 | Attr =	]
brms305a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms305a.dll -> Brother Industries, Ltd [Ver = 1.06 | Size = 163840 bytes | Modified Date = 9/30/2005 | Attr =	]
brms405a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms405a.dll -> Brother Industries, Ltd [Ver = 1.06 | Size = 163840 bytes | Modified Date = 9/30/2005 | Attr =	]
brms505a.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brms505a.dll -> Brother Industries, Ltd [Ver = 1.06 | Size = 163840 bytes | Modified Date = 9/30/2005 | Attr =	]
BROMF05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BROMF05A.dll -> Brother Industries Ltd. [Ver = 3.16 | Size = 326157 bytes | Modified Date = 11/22/2005 3:16:00 AM | Attr =	]
BROSNMP.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BROSNMP.DLL -> Brother Industries, Ltd. [Ver = 1, 0, 0, 1 | Size = 118784 bytes | Modified Date = 8/11/2005 9:14:52 PM | Attr =	]
BrRSi05c.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrRSi05c.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 2 | Size = 29184 bytes | Modified Date = 8/30/2005 3:44:32 PM | Attr =	]
BrScnDev.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrScnDev.dll -> Brother Industries, Ltd. [Ver = 3, 4, 21, 6 | Size = 61440 bytes | Modified Date = 11/10/2005 8:41:06 PM | Attr =	]
BrScnRsm.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrScnRsm.dll -> Brother Industries,Ltd. [Ver = 1.0.1.0 | Size = 6144 bytes | Modified Date = 4/22/2005 12:57:50 PM | Attr =	]
BrSerIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrSerIf.dll -> Brother Industries, Ltd. [Ver = 1.45.15.357 | Size = 9728 bytes | Modified Date = 4/8/2005 1:17:24 PM | Attr =	]
BrStiIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrStiIf.dll -> Brother Industries,Ltd. [Ver = 1, 1, 0, 3 | Size = 49152 bytes | Modified Date = 8/16/2004 3:49:14 PM | Attr =	]
brtcpcon.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brtcpcon.dll ->  [Ver =  | Size = 45056 bytes | Modified Date = 1/17/2005 4:10:16 PM | Attr =	]
BrTwdChn.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdChn.dll -> Brother Industries, Ltd. [Ver = 3, 4, 5, 3 | Size = 77824 bytes | Modified Date = 11/1/2005 6:56:06 PM | Attr =	]
BrTwdCze.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdCze.dll -> Brother Industries, Ltd. [Ver = 3, 4, 5, 2 | Size = 81920 bytes | Modified Date = 10/18/2005 7:24:58 AM | Attr =	]
BrTwdDan.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdDan.dll -> Brother Industries, Ltd. [Ver = 3, 4, 12, 2 | Size = 81920 bytes | Modified Date = 10/20/2005 7:53:10 AM | Attr =	]
BrTwdDut.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdDut.dll -> Brother Industries, Ltd. [Ver = 3, 4, 10, 2 | Size = 81920 bytes | Modified Date = 10/20/2005 7:14:48 AM | Attr =	]
BrTwdEng.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdEng.dll -> Brother Industries, Ltd. [Ver = 3, 4, 9, 1 | Size = 81920 bytes | Modified Date = 10/5/2005 1:45:08 PM | Attr =	]
BrTwdFin.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdFin.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 10/29/2005 10:19:06 AM | Attr =	]
BrTwdFre.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdFre.dll -> Brother Industries, Ltd. [Ver = 3, 4, 10, 2 | Size = 81920 bytes | Modified Date = 10/22/2005 10:19:54 AM | Attr =	]
BrTwdGer.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdGer.dll -> Brother Industries, Ltd. [Ver = 3, 4, 11, 3 | Size = 81920 bytes | Modified Date = 11/18/2005 5:38:56 PM | Attr =	]
BrTwdHun.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdHun.dll -> Brother Industries, Ltd. [Ver = 3, 4, 5, 1 | Size = 81920 bytes | Modified Date = 10/18/2005 7:18:38 AM | Attr =	]
BrTwdIta.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdIta.dll -> Brother Industries, Ltd. [Ver = 3, 4, 10, 2 | Size = 81920 bytes | Modified Date = 10/20/2005 6:53:24 AM | Attr =	]
BrTwdJpn.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdJpn.dll -> Brother Industries, Ltd. [Ver = 3, 4, 16, 4 | Size = 77824 bytes | Modified Date = 10/17/2005 3:59:50 PM | Attr =	]
BrTwdNor.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdNor.dll -> Brother Industries, Ltd. [Ver = 3, 4, 10, 2 | Size = 81920 bytes | Modified Date = 10/20/2005 7:45:52 AM | Attr =	]
BrTwdPol.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdPol.dll ->  [Ver =  | Size = 81920 bytes | Modified Date = 10/29/2005 2:52:30 AM | Attr =	]
BrTwdPor.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdPor.dll -> Brother Industries, Ltd. [Ver = 3, 4, 11, 2 | Size = 81920 bytes | Modified Date = 10/26/2005 12:01:16 PM | Attr =	]
BrTwdRus.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdRus.dll -> Brother Industries, Ltd. [Ver = 3, 4, 9, 3 | Size = 81920 bytes | Modified Date = 11/2/2005 8:20:16 AM | Attr =	]
BrTwds.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwds.dll -> Brother Industries, Ltd. [Ver = 3, 4, 36, 7 | Size = 118784 bytes | Modified Date = 11/25/2005 8:17:02 PM | Attr =	]
BrTwdScn.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdScn.dll -> Brother Industries, Ltd. [Ver = 3, 4, 49, 5 | Size = 1515520 bytes | Modified Date = 11/11/2005 1:56:40 PM | Attr =	]
BrTwdSpa.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdSpa.dll -> Brother Industries, Ltd. [Ver = 3, 4, 9, 2 | Size = 81920 bytes | Modified Date = 10/26/2005 12:15:02 PM | Attr =	]
BrTwdsUi.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdsUi.dll -> Brother Industries, Ltd. [Ver = 3, 4, 39, 9 | Size = 122880 bytes | Modified Date = 11/10/2005 8:42:06 PM | Attr =	]
BrTwdSwe.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdSwe.dll -> Brother Industries, Ltd. [Ver = 3, 4, 11, 2 | Size = 81920 bytes | Modified Date = 10/20/2005 9:34:34 AM | Attr =	]
BrTwdUsa.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrTwdUsa.dll -> Brother Industries, Ltd. [Ver = 3, 4, 9, 1 | Size = 81920 bytes | Modified Date = 11/7/2005 2:47:10 PM | Attr =	]
BRUMF05A.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BRUMF05A.dll -> Brother Industries Ltd. [Ver = 3.16 | Size = 1059085 bytes | Modified Date = 11/22/2005 3:16:00 AM | Attr =	]
BrUSi05c.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrUSi05c.dll -> Brother Industries, Ltd. [Ver = 1, 0, 0, 2 | Size = 38912 bytes | Modified Date = 8/30/2005 3:40:06 PM | Attr =	]
BrWia05c.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrWia05c.dll -> Brother Industries, Ltd. [Ver = 3.2.0.4 | Size = 1491456 bytes | Modified Date = 11/15/2005 7:03:34 PM | Attr =	]
RSMGRSTR.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\RSMGRSTR.dll -> Brother Industries, Ltd. [Ver = 1.45.15.340 | Size = 9728 bytes | Modified Date = 4/8/2005 1:17:28 PM | Attr =	]
BrBidiIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrBidiIf.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 81920 bytes | Modified Date = 11/7/2005 6:05:32 PM | Attr =	]
BrEvIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrEvIf.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 73728 bytes | Modified Date = 11/7/2005 6:05:42 PM | Attr =	]
BrmfBidi.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBidi.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 73728 bytes | Modified Date = 11/7/2005 6:07:16 PM | Attr =	]
BrmfBiPP.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBiPP.dll -> Brother Industries, Ltd. [Ver = 1.45.11.472 | Size = 102400 bytes | Modified Date = 9/21/2004 5:39:24 PM | Attr =	]
BrmfLPT.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfLPT.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 90112 bytes | Modified Date = 11/7/2005 6:06:26 PM | Attr =	]
brmfpmbd.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\brmfpmbd.dll -> Brother Industries,Ltd. [Ver = 1.01 | Size = 31894 bytes | Modified Date = 11/22/2004 | Attr =	]
BrmfUSB.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfUSB.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 106496 bytes | Modified Date = 11/7/2005 6:07:00 PM | Attr =	]
BrRSi05c.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrRSi05c.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 2 | Size = 29184 bytes | Modified Date = 8/30/2005 3:44:32 PM | Attr =	]
brscnrsm.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\brscnrsm.dll -> Brother Industries,Ltd. [Ver = 1,0,0,14 | Size = 49152 bytes | Modified Date = 6/18/2001 4:34:34 PM | Attr =	]
BrserIf.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrserIf.dll -> Brother Industries, Ltd. [Ver = 1.45.11.435 | Size = 65536 bytes | Modified Date = 11/7/2005 6:07:12 PM | Attr =	]
BrSti05c.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrSti05c.dll -> Brother Industries, Ltd. [Ver = 2, 0, 0, 2 | Size = 8192 bytes | Modified Date = 8/30/2005 3:52:04 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\chn\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 36864 bytes | Modified Date = 8/23/2004 4:20:48 PM | Attr =	]
RsmgrStr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\cze\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 11:01:14 AM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\dan\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:08:08 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\dut\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:08:44 PM | Attr =	]
RsmgrStr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\eng\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/17/2005 7:00:08 PM | Attr =	]
RsmgrStr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\fin\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.210 | Size = 49152 bytes | Modified Date = 10/26/2005 1:09:02 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\fre\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:14 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\ger\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.210 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:34 PM | Attr =	]
RsmgrStr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\hun\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 9:27:20 AM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\ita\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:09:52 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\jpn\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.209 | Size = 49152 bytes | Modified Date = 6/14/2005 4:45:12 PM | Attr =	]
rsmgrstr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\nor\rsmgrstr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.208 | Size = 40960 bytes | Modified Date = 10/21/2005 3:10:12 PM | Attr =	]
RsmgrStr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\RsmgLang\pol\RsmgrStr.dll -> Brother Industries, Ltd. [Ver = 1.40.10.207 | Size = 53248 bytes | Modified Date = 10/30/2004 11:48:14 AM | Attr = R  ]
AVPFPI0.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\AVPFPI0.dll -> Kaspersky Lab [Ver = 7.0.171.8410 | Size = 147538 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
avpproxy.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\avpproxy.dll -> F-Secure Corporation [Ver = 1.2.12160 | Size = 77910 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
daas_s.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\daas_s.dll -> F-Secure Corporation [Ver = 6.00.14023 | Size = 495616 bytes | Modified Date = 2/27/2008 3:59:28 PM | Attr =	]
fm4av.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fm4av.dll ->  [Ver =  | Size = 513536 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fpinor.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fpinor.dll -> F-Secure Corporation [Ver = 1.20.13330 | Size = 113664 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsbl.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsbl.dll -> F-Secure Corporation [Ver = 1, 0, 0, 1 | Size = 49152 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsbld.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsbld.dll -> F-Secure Corporation [Ver = 1, 0, 0, 64 | Size = 524288 bytes | Modified Date = 3/12/2008 10:11:01 AM | Attr =	]
fsblsen.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsblsen.dll -> F-Secure Corporation [Ver = 1, 0, 0, 8 | Size = 155648 bytes | Modified Date = 3/12/2008 10:34:01 AM | Attr =	]
fsecr32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsecr32.dll -> F-Secure Corporation [Ver = 2.06.7470 | Size = 262144 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsgkiapi.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsgkiapi.dll -> F-Secure Corp. [Ver = 7.60.13372.8144 | Size = 82432 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsmart.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsmart.dll -> F-Secure Corporation [Ver = 1, 0, 0, 28 | Size = 147456 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
fspe32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fspe32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 135168 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fssubmit.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fssubmit.dll -> F-Secure Corporation [Ver = 1.0.11 | Size = 651264 bytes | Modified Date = 3/12/2008 10:10:59 AM | Attr =	]
fsup32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsup32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 803328 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupcx32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupcx32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 131584 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupfg32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupfg32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 151552 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupmw32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupmw32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 146944 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupnp32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupnp32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 153600 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupux32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupux32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 155136 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupwu32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupwu32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 147968 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsusscr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsusscr.dll -> F-Secure Corporation [Ver = 2.30.14093 | Size = 880640 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
Nse_w32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\Nse_w32.dll ->  [Ver =  | Size = 506936 bytes | Modified Date = 3/12/2008 10:10:44 AM | Attr =	]
AVPFPI0.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\AVPFPI0.dll -> Kaspersky Lab [Ver = 7.0.171.8410 | Size = 147538 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
avpproxy.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\avpproxy.dll -> F-Secure Corporation [Ver = 1.2.12160 | Size = 77910 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fm4av.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fm4av.dll ->  [Ver =  | Size = 513536 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fpinor.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fpinor.dll -> F-Secure Corporation [Ver = 1.20.13330 | Size = 113664 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsbl.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fsbl.dll -> F-Secure Corporation [Ver = 1, 0, 0, 1 | Size = 49152 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsgkiapi.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\fsgkiapi.dll -> F-Secure Corp. [Ver = 7.60.13372.8144 | Size = 82432 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
fsecr32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsecr32.dll -> F-Secure Corporation [Ver = 2.06.7470 | Size = 262144 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fspe32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fspe32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 135168 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsup32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsup32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 803328 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupcx32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupcx32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 131584 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupfg32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupfg32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 151552 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupmw32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupmw32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 146944 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupnp32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupnp32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 153600 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupux32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupux32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 155136 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupwu32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupwu32.dll -> F-Secure Corporation [Ver = 1.0.375 | Size = 147968 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsmart.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\mlcwin\fsmart.dll -> F-Secure Corporation [Ver = 1, 0, 0, 28 | Size = 147456 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
fsusscr.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\mlcwin\fsusscr.dll -> F-Secure Corporation [Ver = 2.30.14093 | Size = 880640 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
Nse_w32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_30_pegdb\Nse_w32.dll ->  [Ver =  | Size = 506936 bytes | Modified Date = 3/12/2008 10:10:44 AM | Attr =	]
fssubmit.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_33_bin\fssubmit.dll -> F-Secure Corporation [Ver = 1.0.11 | Size = 651264 bytes | Modified Date = 3/12/2008 10:10:59 AM | Attr =	]
fsblu.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_bl\fsblu.dll -> F-Secure Corporation [Ver = 1, 0, 0, 64 | Size = 524288 bytes | Modified Date = 3/12/2008 10:11:01 AM | Attr =	]
_Setup.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\_Setup.dll -> InstallShield Software Corporation [Ver = 5, 50, 134, 0 | Size = 34816 bytes | Modified Date = 9/29/1998 4:34:56 PM | Attr = R  ]
AceLite.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\AceLite.dll -> Adobe Systems, Incorporated [Ver = 1.02.00 | Size = 397312 bytes | Modified Date = 2/28/2001 9:29:36 AM | Attr = R  ]
ACROFX32.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\ACROFX32.DLL ->  [Ver =  | Size = 53248 bytes | Modified Date = 5/12/2000 6:30:02 PM | Attr = R  ]
Agm.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\Agm.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1138688 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]
Bib.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\Bib.dll -> Adobe Systems, Incorporated [Ver = 1.0.20 | Size = 147456 bytes | Modified Date = 1/20/2001 10:13:36 PM | Attr = R  ]
CoolType.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\CoolType.dll -> Adobe Systems, Incorporated [Ver = 4.04.26 | Size = 1441792 bytes | Modified Date = 3/14/2001 10:06:02 AM | Attr = R  ]
msvcp60.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\msvcp60.dll -> Microsoft Corporation [Ver = 6.00.8168.0 | Size = 401462 bytes | Modified Date = 12/1/1999 12:40:28 AM | Attr = R  ]
msvcrt.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\msvcrt.dll -> Microsoft Corporation [Ver = 6.00.8397.0 | Size = 266293 bytes | Modified Date = 2/11/1999 3:33:58 AM | Attr = R  ]
oleaut32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\oleaut32.dll -> Microsoft Corporation [Ver = 2.30.4261 | Size = 598288 bytes | Modified Date = 6/18/1998 11:33:08 AM | Attr = R  ]
WHA Library.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\WHA Library.dll -> Adobe Systems Incorporated [Ver = 0.2.0.0 | Size = 167936 bytes | Modified Date = 3/15/2001 6:14:38 AM | Attr = R  ]
nppdf32.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\Browser\nppdf32.dll -> Adobe Systems Inc. [Ver = 5.0.0.2001031500 | Size = 103312 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]
NPDocBox.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\plug_ins\InterTrust\NPDocBox.dll -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 3/14/2001 4:52:06 AM | Attr = R  ]
QT2.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\plug_ins\Movie\QT2.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 24576 bytes | Modified Date = 3/15/2001 6:00:24 AM | Attr = R  ]
QT3.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\plug_ins\Movie\QT3.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 32768 bytes | Modified Date = 3/15/2001 6:00:42 AM | Attr = R  ]
QT4.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\plug_ins\Movie\QT4.dll -> Adobe Systems, Inc. [Ver = 5.0.0.0 | Size = 36864 bytes | Modified Date = 3/15/2001 6:01:02 AM | Attr = R  ]
Uninst.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Reader\Uninstall\Uninst.dll -> Adobe Systems, Inc. [Ver = 4.0.11 | Size = 81920 bytes | Modified Date = 2/26/2001 9:48:44 PM | Attr = R  ]
NPSVGVw.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SVG Files\NPSVGVw.dll -> Adobe Systems Inc. [Ver = 2, 0, 0, 55 | Size = 299059 bytes | Modified Date = 3/14/2001 2:10:56 PM | Attr = R  ]
SVGControl.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SVG Files\SVGControl.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 491574 bytes | Modified Date = 3/14/2001 2:14:00 PM | Attr = R  ]
SVGRSRC.DLL -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SVG Files\SVGRSRC.DLL ->  [Ver =  | Size = 12288 bytes | Modified Date = 3/14/2001 2:06:24 PM | Attr = R  ]
SVGView.dll -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SVG Files\SVGView.dll -> Adobe Systems Incorporated [Ver = 2, 0, 0, 55 | Size = 1597491 bytes | Modified Date = 3/14/2001 2:07:52 PM | Attr = R  ]
ExchangePerflog_8484fa317036791ecfcccd43.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\ExchangePerflog_8484fa317036791ecfcccd43.dat ->  [Ver =  | Size = 2084 bytes | Modified Date = 3/18/2008 11:24:50 AM | Attr =	]
Perflib_Perfdata_12c.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\Perflib_Perfdata_12c.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 3/7/2008 10:44:14 AM | Attr =	]
Perflib_Perfdata_c0.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\Perflib_Perfdata_c0.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 3/12/2008 11:37:22 AM | Attr =	]
149 C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp -> 
be8060.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\be8060.dat ->  [Ver =  | Size = 66 bytes | Modified Date = 9/3/2005 1:00:00 AM | Attr =	]
be8065dn.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\be8065dn.dat ->  [Ver =  | Size = 66 bytes | Modified Date = 9/3/2005 1:00:00 AM | Attr =	]
be8460n.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\be8460n.dat ->  [Ver =  | Size = 66 bytes | Modified Date = 9/3/2005 1:00:00 AM | Attr =	]
be8860dn.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\be8860dn.dat ->  [Ver =  | Size = 66 bytes | Modified Date = 9/3/2005 1:00:00 AM | Attr =	]
be8870dw.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\be8870dw.dat ->  [Ver =  | Size = 66 bytes | Modified Date = 9/3/2005 1:00:00 AM | Attr =	]
BM8460N.DAT -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BM8460N.DAT ->  [Ver =  | Size = 360 bytes | Modified Date = 9/6/2005 1:00:00 AM | Attr =	]
BM8860DN.DAT -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BM8860DN.DAT ->  [Ver =  | Size = 366 bytes | Modified Date = 9/6/2005 1:00:00 AM | Attr =	]
BM8870DW.DAT -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BM8870DW.DAT ->  [Ver =  | Size = 366 bytes | Modified Date = 9/6/2005 1:00:00 AM | Attr =	]
BP8060.DAT -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BP8060.DAT ->  [Ver =  | Size = 354 bytes | Modified Date = 9/6/2005 1:00:00 AM | Attr =	]
BP8065DN.DAT -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BP8065DN.DAT ->  [Ver =  | Size = 366 bytes | Modified Date = 9/6/2005 1:00:00 AM | Attr =	]
BrmfBiPP.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBiPP.dat ->  [Ver =  | Size = 36 bytes | Modified Date = 9/10/2004 4:01:54 PM | Attr =	]
BrmfBiPP.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBiPP.dat ->  [Ver =  | Size = 36 bytes | Modified Date = 9/10/2004 4:01:54 PM | Attr =	]
BrmfRmPA.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfRmPA.dat ->  [Ver =  | Size = 7792 bytes | Modified Date = 6/11/2004 1:05:28 PM | Attr =	]
ext.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\ext.dat ->  [Ver =  | Size = 444 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
fsedb.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsedb.dat ->  [Ver =  | Size = 609306 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupdllb.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupdllb.dat ->  [Ver =  | Size = 422594 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupplgn.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsupplgn.dat ->  [Ver =  | Size = 226 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsuptmpl.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\fsuptmpl.dat ->  [Ver =  | Size = 5858 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
perf.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\perf.dat ->  [Ver =  | Size = 128 bytes | Modified Date = 3/12/2008 10:12:27 AM | Attr =	]
sae.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\sae.dat ->  [Ver =  | Size = 243 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
sai.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\sai.dat ->  [Ver =  | Size = 1348 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
ext.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avmisc\ext.dat ->  [Ver =  | Size = 444 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
sae.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avmisc\sae.dat ->  [Ver =  | Size = 243 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
sai.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avmisc\sai.dat ->  [Ver =  | Size = 1348 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
fsedb.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsedb.dat ->  [Ver =  | Size = 609306 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupdllb.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupdllb.dat ->  [Ver =  | Size = 422594 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsupplgn.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsupplgn.dat ->  [Ver =  | Size = 226 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
fsuptmpl.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\fsuptmpl.dat ->  [Ver =  | Size = 5858 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
lang.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\lang.dat ->  [Ver =  | Size = 23541 bytes | Modified Date = 1/12/1999 10:34:42 AM | Attr = R  ]
os.dat -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\os.dat ->  [Ver =  | Size = 450 bytes | Modified Date = 7/27/1998 5:41:06 PM | Attr = R  ]
RunTime.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\RunTime.ini ->  [Ver =  | Size = 578 bytes | Modified Date = 6/20/2007 11:42:46 AM | Attr =	]
_isdelet.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\_isdelet.ini ->  [Ver =  | Size = 228 bytes | Modified Date = 8/8/2007 3:45:25 PM | Attr =	]
{AC76BA86-7AD7-1033-7B44-A81000000003}.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{AC76BA86-7AD7-1033-7B44-A81000000003}.ini ->  [Ver =  | Size = 802 bytes | Modified Date = 3/7/2008 10:01:25 AM | Attr =	]
{AC76BA86-7AD7-1033-7B44-A81200000003}.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{AC76BA86-7AD7-1033-7B44-A81200000003}.ini ->  [Ver =  | Size = 578 bytes | Modified Date = 3/7/2008 10:02:42 AM | Attr =	]
149 C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp -> 
BRLMW03A.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\BRLMW03A.INI ->  [Ver =  | Size = 114 bytes | Modified Date = 8/9/2004 4:00:42 PM | Attr =	]
Brstslst.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Brmfcmon\Brstslst.ini ->  [Ver =  | Size = 3858 bytes | Modified Date = 11/30/2005 1:09:44 PM | Attr = R  ]
bm8460n.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\bm8460n.ini ->  [Ver =  | Size = 19436 bytes | Modified Date = 11/1/2005 1:00:00 AM | Attr =	]
bm8860dn.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\bm8860dn.ini ->  [Ver =  | Size = 19287 bytes | Modified Date = 11/1/2005 1:00:00 AM | Attr =	]
bm8870dw.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\bm8870dw.ini ->  [Ver =  | Size = 19287 bytes | Modified Date = 11/1/2005 1:00:00 AM | Attr =	]
bp8060.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\bp8060.ini ->  [Ver =  | Size = 19436 bytes | Modified Date = 11/1/2005 1:00:00 AM | Attr =	]
bp8065dn.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\bp8065dn.ini ->  [Ver =  | Size = 19287 bytes | Modified Date = 11/1/2005 1:00:00 AM | Attr =	]
brlmw03a.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\brlmw03a.ini ->  [Ver =  | Size = 114 bytes | Modified Date = 8/10/2004 1:00:42 AM | Attr =	]
BrmfBAgP.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBAgP.ini ->  [Ver =  | Size = 52 bytes | Modified Date = 9/10/2004 3:40:38 PM | Attr =	]
BrmfBAgS.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\BrmfBAgS.ini ->  [Ver =  | Size = 29 bytes | Modified Date = 9/10/2004 3:40:28 PM | Attr =	]
MF8860DP.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\MF8860DP.INI ->  [Ver =  | Size = 729 bytes | Modified Date = 11/7/2005 10:23:32 AM | Attr =	]
MF8860DU.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\MF8860DU.INI ->  [Ver =  | Size = 724 bytes | Modified Date = 10/27/2005 4:46:26 PM | Attr =	]
TWMF8860DP.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\TWMF8860DP.INI ->  [Ver =  | Size = 732 bytes | Modified Date = 10/27/2005 4:46:24 PM | Attr =	]
TWMF8860DU.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\TWMF8860DU.INI ->  [Ver =  | Size = 727 bytes | Modified Date = 10/27/2005 4:46:24 PM | Attr =	]
BrmfBAgP.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBAgP.ini ->  [Ver =  | Size = 52 bytes | Modified Date = 9/10/2004 3:40:38 PM | Attr =	]
BrmfBAgS.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\{B02C4005-F6C3-498E-A05A-059AEDF95800}\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\Prtdrv\2000\BrmfBAgS.ini ->  [Ver =  | Size = 29 bytes | Modified Date = 9/10/2004 3:40:28 PM | Attr =	]
FS@av.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@av.ini ->  [Ver =  | Size = 203 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
FS@avpe.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@avpe.ini ->  [Ver =  | Size = 205 bytes | Modified Date = 3/12/2008 10:09:49 AM | Attr =	]
FS@bleng.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@bleng.ini ->  [Ver =  | Size = 241 bytes | Modified Date = 3/12/2008 10:11:01 AM | Attr =	]
FS@corp.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@corp.ini ->  [Ver =  | Size = 176 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
FS@hydra.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@hydra.ini ->  [Ver =  | Size = 250 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
FS@mlc.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@mlc.ini ->  [Ver =  | Size = 204 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
FS@ols.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@ols.ini ->  [Ver =  | Size = 168 bytes | Modified Date = 3/12/2008 10:10:58 AM | Attr =	]
FS@peg.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\FS@peg.ini ->  [Ver =  | Size = 204 bytes | Modified Date = 3/12/2008 10:10:44 AM | Attr =	]
verdicts.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\Anti-Virus\verdicts.ini ->  [Ver =  | Size = 2539 bytes | Modified Date = 3/12/2008 10:09:51 AM | Attr =	]
FS@av.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avmisc\FS@av.ini ->  [Ver =  | Size = 203 bytes | Modified Date = 3/12/2008 10:09:52 AM | Attr =	]
FS@avpe.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avpe\FS@avpe.ini ->  [Ver =  | Size = 205 bytes | Modified Date = 3/12/2008 10:09:49 AM | Attr =	]
verdicts.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\avpe\verdicts.ini ->  [Ver =  | Size = 2539 bytes | Modified Date = 3/12/2008 10:09:51 AM | Attr =	]
FS@corp.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\fsav_beta\FS@corp.ini ->  [Ver =  | Size = 176 bytes | Modified Date = 3/12/2008 10:11:16 AM | Attr =	]
FS@hydra.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\hydrawin\FS@hydra.ini ->  [Ver =  | Size = 250 bytes | Modified Date = 3/12/2008 10:11:08 AM | Attr =	]
FS@mlc.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\mlcwin\FS@mlc.ini ->  [Ver =  | Size = 204 bytes | Modified Date = 3/12/2008 10:11:11 AM | Attr =	]
FS@peg.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_30_pegdb\FS@peg.ini ->  [Ver =  | Size = 204 bytes | Modified Date = 3/12/2008 10:10:44 AM | Attr =	]
FS@ols.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_33_bin\FS@ols.ini ->  [Ver =  | Size = 168 bytes | Modified Date = 3/12/2008 10:10:58 AM | Attr =	]
FS@bleng.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\OnlineScanner\updates\ols_bl\FS@bleng.ini ->  [Ver =  | Size = 241 bytes | Modified Date = 3/12/2008 10:11:01 AM | Attr =	]
Abcpy.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\Abcpy.ini ->  [Ver =  | Size = 3026 bytes | Modified Date = 4/4/2001 2:57:10 PM | Attr = R  ]
SETUP.INI -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SETUP.INI ->  [Ver =  | Size = 103 bytes | Modified Date = 3/28/2001 3:30:20 PM | Attr = R  ]
SVGViewer.ini -> C:\Documents and Settings\Ryan\Local Settings\Temp\pft16~tmp\SVG Files\SVGViewer.ini ->  [Ver =  | Size = 0 bytes | Modified Date = 3/9/2001 11:13:50 AM | Attr = R  ]
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory ->  [Folder | Modified Date = 3/18/2008 6:07:21 AM | Attr =	]
8.5X12Closing coupons.doc -> %UserProfile%\My Documents\8.5X12Closing coupons.doc ->  [Ver =  | Size = 2575872 bytes | Modified Date = 3/13/2008 11:07:39 AM | Attr =	]
Closing coupons.doc -> %UserProfile%\My Documents\Closing coupons.doc ->  [Ver =  | Size = 2575872 bytes | Modified Date = 3/10/2008 1:40:56 PM | Attr =	]
Closing Package -> %UserProfile%\My Documents\Closing Package ->  [Folder | Modified Date = 3/6/2008 12:26:56 PM | Attr =	]
2 C:\Documents and Settings\Ryan\My Documents\*.tmp files -> C:\Documents and Settings\Ryan\My Documents\*.tmp -> 
Computer Maintenance -> %UserProfile%\My Documents\Computer Maintenance ->  [Folder | Modified Date = 3/4/2008 3:55:50 PM | Attr =	]
Courthouse.doc -> %UserProfile%\My Documents\Courthouse.doc ->  [Ver =  | Size = 2800128 bytes | Modified Date = 3/17/2008 1:54:11 PM | Attr =	]
courthouseleads.xls -> %UserProfile%\My Documents\courthouseleads.xls ->  [Ver =  | Size = 25600 bytes | Modified Date = 3/14/2008 10:29:34 AM | Attr =	]
My Pictures -> %UserProfile%\My Documents\My Pictures ->  [Folder | Modified Date = 2/28/2008 12:02:38 PM | Attr = R  ]
Thumbs.db -> %UserProfile%\My Documents\Thumbs.db ->  [Ver =  | Size = 27648 bytes | Modified Date = 3/6/2008 12:27:06 PM | Attr =  HS]
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
Adobe Reader 8.lnk -> %AllUsersProfile%\Desktop\Adobe Reader 8.lnk ->  [Ver =  | Size = 1729 bytes | Modified Date = 3/7/2008 10:03:31 AM | Attr =	]
Allied -> %UserProfile%\Desktop\Allied ->  [Folder | Modified Date = 3/17/2008 11:27:58 AM | Attr =	]
Appraisals -> %UserProfile%\Desktop\Appraisals ->  [Folder | Modified Date = 2/22/2008 2:28:48 PM | Attr =	]
BRAGG_Appraisal.pdf -> %UserProfile%\Desktop\BRAGG_Appraisal.pdf ->  [Ver =  | Size = 2820110 bytes | Modified Date = 3/11/2008 11:38:24 AM | Attr =	]
@Alternate Data Stream - 26 bytes -> %UserProfile%\Desktop\BRAGG_Appraisal.pdf:Zone.Identifier
Edwards, Jeremy1003.pdf -> %UserProfile%\Desktop\Edwards, Jeremy1003.pdf ->  [Ver =  | Size = 37760 bytes | Modified Date = 3/13/2008 2:43:45 PM | Attr =	]
Marketing -> %UserProfile%\Desktop\Marketing ->  [Folder | Modified Date = 3/13/2008 2:57:03 PM | Attr =	]
My Documents.lnk -> %UserProfile%\Desktop\My Documents.lnk ->  [Ver =  | Size = 338 bytes | Modified Date = 3/11/2008 5:32:10 PM | Attr =	]
OTScanIt -> %UserProfile%\Desktop\OTScanIt ->  [Folder | Modified Date = 3/18/2008 11:07:45 AM | Attr =	]
Shipments to Richmond -> %UserProfile%\Desktop\Shipments to Richmond ->  [Folder | Modified Date = 3/13/2008 2:57:25 PM | Attr =	]

< End of report >


#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:11:30 PM

Posted 18 March 2008 - 07:28 PM

Hi wv14. I don't5 see anything as malware goes in the log but there is some cleanup of alot of leftover entries and junk.

The biggest factor might be related to Symantec. It looks like it might have been installed at one time and now about half of it is left and half is missing. Go here and follow the directions for the particular version that was once on this system to remove the rest of it.

Then do the following:

Start OTScanIt. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Win32 Services - Non-Microsoft Only]
NY -> (STOPzilla Local Service) STOPzilla Local Service [Win32_Own | Auto | Stopped] -> %ProgramFiles%\STOPzilla!\szntsvc.exe
NY -> (WANMiniportService) WAN Miniport (ATW) Service [Win32_Own | Auto | Stopped] -> %SystemRoot%\wanmpsvc.exe
[Registry - Non-Microsoft Only]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> Microsoft Works Update Detection -> %ProgramFiles%\Microsoft Works\WkDetect.exe
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {36F469EF-255C-4D93-B6BA-EF4665C05F46} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\System32\glru32.dll []
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{40D41A8B-D79B-43D7-99A7-9EE0F344C385} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Norton AntiVirus\NavShExt.dll [Norton AntiVirus]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\{000007C6-17DF-4438-92A4-DE5537471BA3} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{A75C6120-9B36-11d4-A3F0-009027427750} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
[Files/Folders - Created Within 30 days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
[Files Created - Additional Folder Scans - Non-Microsoft Only]
NY -> 2 C:\Documents and Settings\Ryan\My Documents\*.tmp files -> C:\Documents and Settings\Ryan\My Documents\*.tmp
[Files/Folders - Modified Within 30 days]
NY -> 1 C:\*.tmp files -> C:\*.tmp
NY -> 1732 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 29 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
NY -> qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
NY -> 149 C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Ryan\Local Settings\Temp\*.tmp
[Empty Temp Folders]
[Start Explorer]

The fix should only take a very short time. When the fix is completed either a message box will popup telling you that it is finished or you will be asked to reboot to finish the fix. If it is finished, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

If you need to reboot, the log file will be placed in the MovedFiles folder in the folder that OTScanIt is running from. It will have a .log extension and a name in the format of mmddyyyy_hhmmss.log. Once you reboot, locate that file, open it with Notepad (not Write or any other text program) and post the contents back here.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users