Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winantivirus Pro 2006


  • Please log in to reply
8 replies to this topic

#1 jaleo78

jaleo78

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:25 PM

Posted 12 January 2007 - 04:57 PM

Hi, I need some help. Every time I turn on my computer this program opens up in a window telling me to register this antivirus software. I normally have to close the two windows that pop up and then right-click on the icon at the bottom toolbar and select exit. It will stop popping up as long as I dont log off. ONce I log back on I have to go through the same steps again. If you can help that would be great!!

Logfile of HijackThis v1.99.1
Scan saved at 1:32:51 PM, on 1/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe
C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINNT\system32\sbslyqio.dll",setvm
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [CaseyVideo[2]] c:\windows\CaseyVideo[2].scr
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig...loadControl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63E83BDC-CBA2-403C-BB4E-2F30E49BDA1C}: NameServer = 194.25.0.68,194.25.0.60
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Firewall service (FWSvc) - WinSoftware, Ltd. - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 12 January 2007 - 05:30 PM

Add remove programs - remove WinAntiVirus Pro 2006 if present

Download Superantispyware

http://www.superantispyware.com/superantis...efreevspro.html

Install it and double-click the icon on your desktop to run it.
· It will ask if you want to update the program definitions, click Yes.
· Under Configuration and Preferences, click the Preferences button.
· Click the Scanning Control tab.
· Under Scanner Options make sure the following are checked:
o Close browsers before scanning
o Scan for tracking cookies
o Terminate memory threats before quarantining.
o Please leave the others unchecked.
o Click the Close button to leave the control center screen.
· On the main screen, under Scan for Harmful Software click Scan your computer.
· On the left check C:\Fixed Drive.
· On the right, under Complete Scan, choose Perform Complete Scan.
· Click Next to start the scan. Please be patient while it scans your computer.
· After the scan is complete a summary box will appear. Click OK.
· Make sure everything in the white box has a check next to it, then click Next.
· It will quarantine what it found and if it asks if you want to reboot, click Yes.
· To retrieve the removal information for me please do the following:
o After reboot, double-click the SUPERAntispyware icon on your desktop.
o Click Preferences. Click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o It will open in your default text editor (such as Notepad/Wordpad).
o Please highlight everything in the notepad, then right-click and choose copy.
· Click close and close again to exit the program.
· Please paste that information here for me with a new HijackThis log.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 jaleo78

jaleo78
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:25 PM

Posted 12 January 2007 - 08:48 PM

It took a while but here are the results. I had to send it in two replies because of the size. Thanks again.

SUPERAntiSpyware Scan Log
Generated 01/12/2007 at 05:19 PM

Application Version : 3.4.1000

Core Rules Database Version : 3163
Trace Rules Database Version: 1175

Scan type : Complete Scan
Total Scan Time : 02:28:02

Memory items scanned : 488
Memory threats detected : 6
Registry items scanned : 5430
Registry threats detected : 1324
File items scanned : 78681
File threats detected : 207

Trojan.Downloader-PATDUM
C:\WINNT\SERVICEPACKFILES\DAARS.DLL
C:\WINNT\SERVICEPACKFILES\DAARS.DLL
HKLM\Software\Classes\CLSID\{721A89A7-D367-43A2-A999-98A9366A6B66}
HKCR\CLSID\{721A89A7-D367-43A2-A999-98A9366A6B66}
HKCR\CLSID\{721A89A7-D367-43A2-A999-98A9366A6B66}\InprocServer32
HKCR\CLSID\{721A89A7-D367-43A2-A999-98A9366A6B66}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{721A89A7-D367-43A2-A999-98A9366A6B66}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\daars

Trojan.Downloader-VSAddIn
C:\PROGRAM FILES\VSADD-IN\VSADD-IN.DLL
C:\PROGRAM FILES\VSADD-IN\VSADD-IN.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP342\A0039902.DLL
C:\WINNT\SYSTEM32\SOVREVVT.EXE

Trojan.Downloader-Crew
C:\WINNT\SYSTEM32\XPRJQOXH.DLL
C:\WINNT\SYSTEM32\XPRJQOXH.DLL
C:\WINNT\SYSTEM32\QLXMOPTI.DLL

Trojan.Virtumonde/Resident
C:\WINNT\SYSTEM32\VJERUVSJ.DLL
C:\WINNT\SYSTEM32\VJERUVSJ.DLL

Trojan.WinAntiSpyware/WinAntiVirus 2006/2007
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\FWSVC.EXE
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\FWSVC.EXE
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\RULSRV.DLL
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\RULSRV.DLL
[WinAntiVirusPro2006] C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\WINAV.EXE
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\WINAV.EXE
HKCR\AntiVirusCOM.AVOfficeProtect
HKCR\AntiVirusCOM.AVOfficeProtect\CLSID
HKCR\AntiVirusCOM.AVOfficeProtect.1
HKCR\AntiVirusCOM.AVOfficeProtect.1\CLSID
HKCR\AVExplorer.ShellExtension
HKCR\AVExplorer.ShellExtension\CLSID
HKCR\AVExplorer.ShellExtension\CurVer
HKCR\AVExplorer.ShellExtension.2
HKCR\AVExplorer.ShellExtension.2\CLSID
HKCR\WAP6.PCheck
HKCR\WAP6.PCheck\CLSID
HKCR\WAP6.PCheck\CurVer
HKCR\WAP6.PCheck.1
HKCR\WAP6.PCheck.1\CLSID
HKCR\WinPGIntegrator.IEIntegrator
HKCR\WinPGIntegrator.IEIntegrator\CLSID
HKCR\WinPGIntegrator.IEIntegrator\CurVer
HKCR\WinPGIntegrator.IEIntegrator.1
HKCR\WinPGIntegrator.IEIntegrator.1\CLSID
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}#AppID
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\InprocServer32#ThreadingModel
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\ProgID
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\Programmable
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\TypeLib
HKCR\CLSID\{1AC5C88A-DEA7-462b-A232-04AF5CA42E7E}\VersionIndependentProgID
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Implemented Categories
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Implemented Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\InprocServer32#ThreadingModel
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\ProgID
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\Programmable
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\TypeLib
HKCR\CLSID\{723D54C7-7483-4EB8-8EED-CE5B2AEA534D}\VersionIndependentProgID
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\InprocServer32#ThreadingModel
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\ProgID
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\Programmable
HKCR\CLSID\{B2A3156E-3332-4b47-AF5A-5B121503514F}\VersionIndependentProgID
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\0\win32
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\FLAGS
HKCR\TypeLib\{1234890A-5E6E-4867-8136-CA6F1456B235}\1.0\HELPDIR
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\0\win32
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\FLAGS
HKCR\TypeLib\{367A86A5-D048-4785-86BE-4E2706AAFDD9}\1.0\HELPDIR
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\0\win32
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\FLAGS
HKCR\TypeLib\{732B6533-7F78-4C47-9C01-2979BA0829B9}\1.0\HELPDIR
HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}
HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid
HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\ProxyStubClsid32
HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib
HKCR\Interface\{0B9A27EB-125F-4F3E-A35C-2769C47A1442}\TypeLib#Version
HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}
HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid
HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\ProxyStubClsid32
HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib
HKCR\Interface\{E18B69D0-7E9E-4C6E-BDD8-879A1FFF7123}\TypeLib#Version
HKCR\AppId\WinPGI.DLL
HKCR\AppId\WinPGI.DLL#AppID
HKCR\AppId\{367A86A5-D048-4785-86BE-4E2706AAFDD9}
HKU\S-1-5-21-367768924-3279092438-3500024551-1003\Software\WinAntiVirus Pro 2006
HKLM\Software\WinAntiVirus Pro 2006
HKLM\Software\WinAntiVirus Pro 2006#EulUWA6P_0001_N822M1605
HKLM\Software\WinAntiVirus Pro 2006#ProductCode
HKLM\Software\WinAntiVirus Pro 2006#InstallPath
HKLM\Software\WinAntiVirus Pro 2006#Abbr
HKLM\Software\WinAntiVirus Pro 2006#ActivationCode
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Setup Version
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: App Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: Icon Group
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Inno Setup: User
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#QuietUninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLInfoAbout
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#URLUpdateInfo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WA6P_is1#NoRepair
HKLM\SYSTEM\CurrentControlSet\Services\FOPN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Type
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Start
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Tag
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Group
HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Overflow
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\blocked#\DEVICE\HARDDISKVOLUME1\WINNT\TEMP\IXP000.TMP\INSTALL_FP6_WU.EXE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\RECYCLER\S-1-5-21-367768924-3279092438-3500024551-1003
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_SYMEVENT$20INSTALLER$20$2D$20CONSUMER_11.6_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\START MENU\PROGRAMS\CLEANUP!
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_AVENGE$201.5$20MICRODEFS2$20NAV2004_MICRODEFSB.ERRO_SYMALLLANGUAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_SYMNET$20CONSUMER_5.4.4_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_COMMON$20CLIENT$20CORE_2.1.5_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\CLEANUP!
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\PFT1.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\WBEM\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\TASKS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CATROOT2
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\COMMON CLIENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DATASTORE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DATASTORE\LOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\NORTON ANTIVIRUS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CONFIG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\NETWORK\DOWNLOADER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\PREFETCH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\CLS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\BFTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\HSPERFDATA_OWNER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\REAL\RNADMIN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\P2P NETWORKING\CACHE\DATABASE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SERVICEPACKFILES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_SYMNET_4.7.2_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_SYMEVENT$20INSTALLER$20$2D$20CONSUMER_11.3_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_LIVEREG_2.4.0_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_COMMON$20CLIENT$20CORE_2.0.0_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_AVENGE$201.5$20MICRODEFS2$20NAV2004_MICRODEFSB.OLD_SYMALLLANGUAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\TRIFILE_AVENGE$201.5$20MICRODEFS2$20NAV2004_MICRODEFSB.CURDEFS_SYMALLLANGUAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\.LIMEWIRE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\INCOMPLETE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1\IDS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\TMPC.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\TMP1E.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NLU1F.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\BINHUB
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\ITEM1599_AVENGE$201.5$20MICRODEFS2$20NAV2004_MICRODEFSB.CURDEFS_SYMALLLANGUAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\EXITEM4641_SYMNET_4.7.2_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\SYMANTEC
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\SYMANTEC\TEMP.^^^
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SPMANIFESTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\DRIVERS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\IDS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\INSTALLER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\PC CLEAN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\CONFIG.MSI
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\DESKTOP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\SYMNETDRV
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\1136397616\OWNER\METRICS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\EXITEM2812_COMMON$20CLIENT$20CORE_2.0.0_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\COMMON~1\SYMANT~1\DECOMP~1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\ITEM1371_SYMEVENT$20INSTALLER$20$2D$20CONSUMER_11.3_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\EXITEM1923_LIVEREG_2.4.0_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS\EXITEM1922_LIVEREG_2.4.0_ENGLISH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVEUPDATE\DOWNLOADS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\INF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CATROOT\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\REAL\MSG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VGX
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\LIVESUBSCRIBE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\SYMANTEC\SHARED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\LIVEREG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U743KP41
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SZ6X6X2V
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB929969$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB929969\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB929969
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB929969\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\DLLCACHE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB929969$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRA~1\SYMANTEC\LIVEUP~1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\METRICS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\6
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\5
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\DEBUG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\59303FC0E08EBA5CB2B4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CONFIG\SYSTEMPROFILE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\GUEST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\DEFAULT USER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\WINANTIVIRUS PRO 2006\LOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\WINANTIVIRUS PRO 2006
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\WUREDIR\9482F4B4-E343-43B6-B170-9A65BC822C77
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\AOLDIAG\AOL\SERVICEHOSTUSGM\WIN32\1.5.3.1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\WORKS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\MINIDUMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\CREDENTIALS\S-1-5-21-367768924-3279092438-3500024551-1003
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\CREDENTIALS\S-1-5-21-367768924-3279092438-3500024551-1003
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\1136397616\OWNER\METRICS\DATA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\AOLDIAG\AOL\LAUNCHUSGM\WIN32\1.5.3.1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBEUM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\WER381A.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\TEMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\WBEM\LOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBE\ACROBAT\7.0\JAVASCRIPTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\JAVASCRIPTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBE\ACROBAT\7.0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\WEBSEARCH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\PFTD.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE\LINGUISTICS\PROVIDERS\PROXIMITY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\INSTALLER\{AC76BA86-7AD7-1033-7B44-A70000000000}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\18028
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS3D
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\MESSAGES\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\MULTIMEDIA\MPP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\ACROFORM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\ACTIVEX
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE\FONT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE\LINGUISTICS\LANGUAGENAMES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\ADOBE\TYPESPT\UNICODE\ICU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\ADOBE\TYPESPT\UNICODE\MAPPINGS\MAC
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\ADOBE\TYPESPT\UNICODE\MAPPINGS\WIN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\ADOBE\TYPESPT\UNICODE\MAPPINGS\ADOBE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\IMAGEVIEWER\EN_US
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\MESSAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\HOWTO\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\ADOBE\ACROBAT\7.0\REPLICATE\SECURITY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\LEGAL\ADOBE READER\7.0.0\EN_US
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\HOWTO\ENU\IMAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\ANNOTATIONS\STAMPS\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\ANNOTATIONS\STAMPS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\OPTIONAL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE\FONT\PFM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\RESOURCE\CMAP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\UPDATER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\PICTURETASKS\HOWTO\IMAGES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\PICTURETASKS\TEMPLATES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\PICTURETASKS\OLS\LOCALE\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\PICTURETASKS\HOWTO
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\HELP\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\VDKHOME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\VDKHOME\ENU
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\.LIMEWIRE\XML\SCHEMAS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\SHARED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\COOKIES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\SELFUPDATE\DEFAULT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\QUICKTIME\QTSYSTEM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5NE42S1M.DEFAULT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\32YTZR7U\STATIC.USERPLANE.COM\PRESENCE\PRESENCE.SWF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\MEDIA PLAYER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\PCHEALTH\HELPCTR\DATACOLL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP350
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP351
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP351\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP351\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP350
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP351\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\LOCALSERVICE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\NETWORKSERVICE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\32YTZR7U\LOCALHOST\MAIN.SWF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#LOCAL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\PT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\JA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\FR-CA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\FR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\ES-US
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\ES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\EN-GB
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\EN-CA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\EN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG\LOCALE\DE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\AOLDIAG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\SUN\JAVA\DEPLOYMENT\LOG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5NE42S1M.DEFAULT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5NE42S1M.DEFAULT\CACHE.TRASH\TRASH\CACHE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\5NE42S1M.DEFAULT\BLUEORGANIZER\THOMASRANGEL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\OFFICE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\TEMPLATES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\RECENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBE\ACROBAT\7.0\COLLAB
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBE\ACROBAT\7.0\PREFERENCES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\AOD\AOL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\IMAPP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\OFFICE\RECENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\WORD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\PROOF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\MICROSOFT OFFICE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\32YTZR7U\BISK.COM\V40\123FLASHCHAT.SWF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\MACROMEDIA.COM\SUPPORT\FLASHPLAYER\SYS\#BISK.COM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\ADOBE\ACROBAT\7.0\CACHE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\32YTZR7U\LEARNINGMODULES.BISK.COM\APP\MAIN.SWF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\MINIXML\VER1_5_1_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\SOFTWAREUPDATE\VER1_14_10_2\RESOURCES\EN-US
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\HTTP\VER1_19_1_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\AUTHENTICATION\VER5_2_6_3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\2
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\SOFTWAREUPDATE\VER1_14_10_2
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ADOBE\ACROBAT\7.0\UPDATER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\PFT5C.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\ESL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\AOD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\LAUNCH
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\AIM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\INTERNET EXPLORER\PLUGINS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\BROWSER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\PLUG_INS\ACROFORM\PMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\SPPLUGINS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\BFTS\VER2_13_3_3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\PREFERENCES\VER3_4_1_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\LOCALSTORAGE\VER4_7_2_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\NOTIFICATION\VER6_2_5_2
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\CONNECTION\VER6_0_2_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\BASICS\VER7_4_3_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\OS\VER4_2_7_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\CRYPTNETURLCACHE\METADATA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\CRYPTNETURLCACHE\CONTENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\ADOBE\COLOR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\VIEWPOINT\VIEWPOINT EXPERIENCE TECHNOLOGY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\1136397616\OWNER\METRICS\RAWDATA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\TOASTER\VER4_1_1_3\RESOURCES\EN-US
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\URLDISPATCHER\VER4_2_8_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\TOASTER\VER4_1_1_3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\SECURITY\VER1_0_6_2
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\SYNC\VER3_4_2_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\SCRIPT\VER2_3_3_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\ONLINEALERTS\VER2_3_1_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\PLAXO\VER2_7_8_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\PLAXOAPP\VER0_7_14_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\IMAPP\VER1_3_30
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\IDENTITYINFORMATION\VER4_4_1_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\IMAGEPROCESSOR\VER_2_0_12_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\IM\VER1_7_6_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\DEFAULTAUTHENTICATIONHANDLERAPP\VER2_1_3_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\HTMLRENDERER\VER1_0_14_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\BOXELYTOOLKIT\VER1_5_11_4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\BOXELYRENDERER\VER1_5_11_4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\ADDRESSBOOKPRINT\VER1_4_3_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\AOL\1136397616\EE\SERVICES\ADDRESSBOOK\VER1_9_12_1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PRO

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 12 January 2007 - 09:03 PM

Need a new hijack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 jaleo78

jaleo78
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:25 PM

Posted 12 January 2007 - 09:13 PM

Here is part two. It includes HiJackThis Logfile. I have to send a third post as well. Sorry :thumbsup:

HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\TALKBACK@MOZILLA.ORG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\TALKBACK@MOZILLA.ORG\COMPONENTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\INSPECTOR@MOZILLA.ORG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\INSPECTOR@MOZILLA.ORG\DEFAULTS\PREFERENCES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\INSPECTOR@MOZILLA.ORG\COMPONENTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\INSPECTOR@MOZILLA.ORG\CHROME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\OPTIONAL\EXTENSIONS\INSPECTOR@MOZILLA.ORG\CHROME\ICONS\DEFAULT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\RES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\RES\HTML
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\RES\FONTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\RES\ENTITYTABLES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\RES\DTD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\PLUGINS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\EXTENSIONS\{972CE4C6-7E08-4474-A285-3208198CE6FD}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\DEFAULTS\AUTOCONFIG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\DEFAULTS\PREF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\GREPREFS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\COMPONENTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\NONLOCALIZED\CHROME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\UNINSTALL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\SEARCHPLUGINS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\DICTIONARIES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\DEFAULTS\PROFILE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\DEFAULTS\PROFILE\CHROME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\DEFAULTS\PREF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\7ZS7.TMP\LOCALIZED\CHROME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NSM9.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\UNINSTALL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\TALKBACK@MOZILLA.ORG\COMPONENTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\DEFAULTS\PROFILE\CHROME
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\DEFAULTS\PROFILE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\DEFAULTS\AUTOCONFIG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\RES\DTD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\RES\ENTITYTABLES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\MOZILLA FIREFOX\RES\HTML
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS MEDIA\10.0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\REAL\MSG\20_1166729380
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB925454$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925454\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925454
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925454\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\INTERNET EXPLORER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB925454$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB925398_WMP64$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB926255\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB926255\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB926255
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB925398_WMP64$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923689$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923689$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB926255$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB926255$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP347\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP346
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP347\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP347\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP345
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP346\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP346\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP345
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP346\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\EVENTCACHE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0AF8CCBF848834C4D945C262A211C5FE\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0AF8CCBF848834C4D945C262A211C5FE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0AF8CCBF848834C4D945C262A211C5FE\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0AF8CCBF848834C4D945C262A211C5FE\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E42ED9B4C83AB2E200B2E2B67275EDEF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E42ED9B4C83AB2E200B2E2B67275EDEF\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\WMP9NL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\WMP9L
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\WMP10NL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\WMP10L
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0C096B9A042A9952F5FAB6FF1BD528F3\EMERALD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\CDA0537E8E2624C74CDAEA2D34C7C7DF\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\CDA0537E8E2624C74CDAEA2D34C7C7DF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\CDA0537E8E2624C74CDAEA2D34C7C7DF\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\CDA0537E8E2624C74CDAEA2D34C7C7DF\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923694$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923694\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923694
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923694\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\OUTLOOK EXPRESS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\SYSTEM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923694$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\INSTALL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\1BB0953D91621D95804E1DED
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP345\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP344
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP345\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP345\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP343
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP342
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP341
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP340
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP339
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP338
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP337
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP336
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP343
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP344\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP344\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP344\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SECURITY\LOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\.LIMEWIRE\XML\DATA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\54JQBN53
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\CLS\CLSFOLDER.000
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\MSAGENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP343\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP343\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923980$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923980\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923980
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923980\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923980$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924270\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924270
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924270\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922760\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922760
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922760\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920213\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920213
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920213\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB924270$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB924270$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\MANIFESTS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\463259A2736A15CB4024B08A483F5B
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\INSTALLER\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\POLICIES\X86_POLICY.4.20.MICROSOFT.MSXML2_6BD6B9ABF345378F_X-WW_88E8EAB8
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\X86_MICROSOFT.MSXML2_6BD6B9ABF345378F_4.20.9841.0_X-WW_18171213
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\MICROSOFT\CRYPTNETURLCACHE\CONTENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\CONFIG\SYSTEMPROFILE\APPLICATION DATA\MICROSOFT\CRYPTNETURLCACHE\METADATA
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\ED9514E261FA7C1CED0E20212F29
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB920213$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB920213$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB922760$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB922760$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\TEMP\IXP001.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\TEMP\NSJ7.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP343\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISK1\MUSIC
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISK1\DP(1)0-0+4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\DRM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\8
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\TEMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\VSADD-IN
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\MICROSOFT\PROTECT\S-1-5-18\USER
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\D4EAA046A678ABDA51679D3B3C3211B7
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\D4EAA046A678ABDA51679D3B3C3211B7\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\D4EAA046A678ABDA51679D3B3C3211B7\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\D4EAA046A678ABDA51679D3B3C3211B7\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\7DF587B4C3DD29899DE0720914884FB1\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\7DF587B4C3DD29899DE0720914884FB1
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\7DF587B4C3DD29899DE0720914884FB1\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\7DF587B4C3DD29899DE0720914884FB1\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\20A6EE57C9AA86DC69C469737391488D
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\20A6EE57C9AA86DC69C469737391488D\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\20A6EE57C9AA86DC69C469737391488D\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\20A6EE57C9AA86DC69C469737391488D\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E8D2337F79EB39F5B85A4E9CF3285273\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E8D2337F79EB39F5B85A4E9CF3285273
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E8D2337F79EB39F5B85A4E9CF3285273\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\E8D2337F79EB39F5B85A4E9CF3285273\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\X86_MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_8.0.50727.163_X-WW_681E29FB
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\POLICIES\X86_POLICY.8.0.MICROSOFT.VC80.CRT_1FC8B3B9A1E18E3B_X-WW_77C24773
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\IDENTITYCRL\PRODUCTION
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP341\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\9
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\1136397616\TWELBY1978\CLS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\INSTALLER\{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\REAL\RHAPSODYPLAYERENGINE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DW
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP342\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP341
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP342\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP342\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP340
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP341\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP341\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP340\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP339
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP340\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP340\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\INSTALLER\MSN MESSENGER 8.1.0106
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\DRVSTORE\WLPHONEC_A6FBDDFD78E9FD2D94C453BC7FCFBE6BEE0A125E
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\DRVSTORE\DFX2A.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP338
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP339\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP339\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP339\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\WEREACA.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\AOLBARTCACHE\0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\ACCCORE\CACHES\BART\0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\STATIC.USERPLANE.COM\PRESENCE\PRESENCE.SWF
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\PROTECT\S-1-5-21-367768924-3279092438-3500024551-1003
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\CACHE\3999.1.4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\MICROSOFT\IDENTITYCRL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\WER8D9D.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\CLS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\JHH58YHM
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\6T9ISMYC
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\PDVSZUN3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\0JTLVWOP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\APPLICATION DATA\SUN\JAVA\DEPLOYMENT\LOG
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\1136397616\BECCA\METRICS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\COOKIES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB917734_WMP10$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB917734_WMP10$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP337\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\START MENU\PROGRAMS\ACCESSORIES\ENTERTAINMENT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\START MENU\PROGRAMS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\CLS\CLSFOLDER.000
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AOL\USERPROFILES\ALL USERS\SUDS\PERSISTENT\11
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\23D1508D2F9CB06248202F4107AB1C5F
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\36A2D56BFAF653641B67E8413870534A
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\23D1508D2F9CB06248202F4107AB1C5F\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\36A2D56BFAF653641B67E8413870534A\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS MEDIA\9.0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\REAL\REALPLAYER\ERRORLOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SYSTEM32\WBEM\PERFORMANCE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\APPLICATION DATA\WINANTIVIRUS PRO 2006\LOGS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP333
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP333\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP333\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP332
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP333\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\APPLICATION DATA\ADOBE\ACROBAT\6.0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\APPLICATION DATA\ADOBE\ACROBAT\6.0\COLLAB
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\APPLICATION DATA\ADOBE\ACROBAT\6.0\PREFERENCES
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\HISTORY\HISTORY.IE5\MSHIST012006102120061022
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP331
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP330
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP332\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP332\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP332\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\REAL\MSG\20_1161113038
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME2\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP330
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP331\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP331\SNAPSHOT\REPOSITORY
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP331\SNAPSHOT
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER46F7.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WERA521.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WERB498.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER9C59.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CX6J0D2V
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\U743KP41
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\0HOL4TWV
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SZ6X6X2V
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER0021.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER4AC5.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER1ABD.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER75B3.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER0C45.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WERE4F8.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER9770.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WERA039.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\BECCA\LOCALS~1\TEMP\WER4053.DIR00
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\X86_MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_6.0.2600.2982_X-WW_AC3F9C03
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\WINSXS\POLICIES\X86_POLICY.6.0.MICROSOFT.WINDOWS.COMMON-CONTROLS_6595B64144CCF1DF_X-WW_5DDAD775
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP329
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP328
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP324
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP323
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP330\SNAPSHOT\REPOSITORY\FS
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUMENTS AND SETTINGS\BECCA\LOCAL SETTINGS\HISTORY\HISTORY.IE5
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\PROGRAM FILES\VSTOOLBAR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB924191$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924191\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924191
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924191\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB924191$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925486\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925486
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB925486\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924496\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924496
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB924496\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923414\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923414
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB923414\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922819\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922582\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922582
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922582\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922819
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB922819\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920872\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920872
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920872\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920685\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920685
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB920685\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB919007\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB919007
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$HF_MIG$\KB919007\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB922819$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB922819$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923414$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB923414$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB920685$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB920685$
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\$NTUNINSTALLKB924496$\SPUNINST
HKLM\SYSTEM\CurrentControlSet\Services&

#6 jaleo78

jaleo78
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:25 PM

Posted 12 January 2007 - 09:14 PM

Here's the third post. Thanks again!!



HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NSQ24.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NSE2D.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NSY2B.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\DOCUME~1\OWNER\LOCALS~1\TEMP\NSZ29.TMP
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\187D2AB765F3595DE795D17271E0496C\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\EC4BD1527B43D202E7C5588F67B971F6\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FDE4A5AF73D5AEE9B5FABA71CBFF1D6C\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\0F1D9525936BD5663571785A751B32E3\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\DC632B620DC2D521266BE7BCE2A259FD\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\437C027C64A0CDEA5E7269513CCD1066\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\05C415EF6D072EB49A51AE487BFC11A6\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\DD5F937D0EFD28640769C02449CB1C5F\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\6EBD16CFA495ACCD1804CD7DE17CEE70
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\6EBD16CFA495ACCD1804CD7DE17CEE70\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\6EBD16CFA495ACCD1804CD7DE17CEE70\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\6EBD16CFA495ACCD1804CD7DE17CEE70\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\6EBD16CFA495ACCD1804CD7DE17CEE70\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\BD2C412F5748F6BD7110BAE5C7F908E8\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FD021E0D3BE9E9D32612EEF4C870A5B4
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FD021E0D3BE9E9D32612EEF4C870A5B4\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FD021E0D3BE9E9D32612EEF4C870A5B4\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FD021E0D3BE9E9D32612EEF4C870A5B4\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\FD021E0D3BE9E9D32612EEF4C870A5B4\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\066A41ED535918E38A94467822E67B8C\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\1C57749E6715414B7025F8D316D91DB9
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\1C57749E6715414B7025F8D316D91DB9\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\1C57749E6715414B7025F8D316D91DB9\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\DOWNLOAD
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\1C57749E6715414B7025F8D316D91DB9\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\1C57749E6715414B7025F8D316D91DB9\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\BACKUP\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\1677BDDC08FB72DA2E81378C43C92308\BACKUP\SP2GDR
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\E533F2B7494D7E198F7FD652BEEA5687
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\E533F2B7494D7E198F7FD652BEEA5687\UPDATE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\74FCDFBC02664DCE84136C891758E123
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\E533F2B7494D7E198F7FD652BEEA5687\SP2QFE\ASMS\60\POLICY\60\COMCTL
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\log#\DEVICE\HARDDISKVOLUME1\WINNT\SOFTWAREDISTRIBUTION\DOWNLOAD\S-1-5-18\74FCDFBC02664DCE84136C891758E123\SP2QFE
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Enum#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000#Capabilities
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\LogConf
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF\0000\Control#ActiveService
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000#Capabilities
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\LogConf
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_VSPF_HK\0000\Control#ActiveService
HKLM\SYSTEM\CurrentControlSet\Services\vspf#Type
HKLM\SYSTEM\CurrentControlSet\Services\vspf#Start
HKLM\SYSTEM\CurrentControlSet\Services\vspf#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\vspf#Tag
HKLM\SYSTEM\CurrentControlSet\Services\vspf#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\vspf#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\vspf#Group
HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnService
HKLM\SYSTEM\CurrentControlSet\Services\vspf#DependOnGroup
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum#NextInstance
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Type
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Start
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Tag
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk#Group
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum#NextInstance
HKCR\IEFWBHO.IEFW
HKCR\IEFWBHO.IEFW\CLSID
HKCR\IEFWBHO.IEFW\CurVer
HKCR\IEFWBHO.IEFW.2
HKCR\IEFWBHO.IEFW.2\CLSID
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\0\win32
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\FLAGS
HKCR\TypeLib\{2BC32EF8-BB73-4099-BB2E-0F2951B3E276}\1.0\HELPDIR
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000#DeviceDesc
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000\Control
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FWSVC\0000\Control#ActiveService
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Type
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Start
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ErrorControl
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ImagePath
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#DisplayName
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#ObjectName
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc#Description
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Security
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Security#Security
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#0
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#Count
HKLM\SYSTEM\CurrentControlSet\Services\FWSvc\Enum#NextInstance
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll [  ]
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#WinAntiVirusPro2006 [ "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" /min ]
C:\WINNT\system32\av.cpl
C:\WINNT\system32\drivers\FOPN.sys
C:\WINNT\system32\stera.exe
C:\WINNT\system32\stera.job
C:\Documents and Settings\All Users\Desktop\WinAntiVirus Pro 2006.lnk
C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
C:\Program Files\Common Files\WinAntiVirus Pro 2006
C:\Program Files\WinAntiVirus Pro 2006\Activate.exe
C:\Program Files\WinAntiVirus Pro 2006\alerts.txt
C:\Program Files\WinAntiVirus Pro 2006\alerts.txt211_19_9_25.gz
C:\Program Files\WinAntiVirus Pro 2006\alerts.txt281_8_44_45.gz
C:\Program Files\WinAntiVirus Pro 2006\asmngr.dll
C:\Program Files\WinAntiVirus Pro 2006\ASupdater.dat
C:\Program Files\WinAntiVirus Pro 2006\avcom.log
C:\Program Files\WinAntiVirus Pro 2006\avkernel.dll
C:\Program Files\WinAntiVirus Pro 2006\AWBase\database\enemies.dat
C:\Program Files\WinAntiVirus Pro 2006\AWBase\database
C:\Program Files\WinAntiVirus Pro 2006\AWBase\vbpv.dat
C:\Program Files\WinAntiVirus Pro 2006\AWBase
C:\Program Files\WinAntiVirus Pro 2006\BkSites.dat
C:\Program Files\WinAntiVirus Pro 2006\bnlink.dat
C:\Program Files\WinAntiVirus Pro 2006\bpupdater.dat
C:\Program Files\WinAntiVirus Pro 2006\CompWiz.exe
C:\Program Files\WinAntiVirus Pro 2006\Download\awboymqe
C:\Program Files\WinAntiVirus Pro 2006\Download\bbbtafva
C:\Program Files\WinAntiVirus Pro 2006\Download\dcsdnvbx
C:\Program Files\WinAntiVirus Pro 2006\Download\fdomrntd
C:\Program Files\WinAntiVirus Pro 2006\Download\gkrlbzat
C:\Program Files\WinAntiVirus Pro 2006\Download\gukmbmbr
C:\Program Files\WinAntiVirus Pro 2006\Download\iyixfzsk
C:\Program Files\WinAntiVirus Pro 2006\Download\jiitgljd
C:\Program Files\WinAntiVirus Pro 2006\Download\kmyrqqzp
C:\Program Files\WinAntiVirus Pro 2006\Download\ltlqrlqn
C:\Program Files\WinAntiVirus Pro 2006\Download\mzqczjax
C:\Program Files\WinAntiVirus Pro 2006\Download\nfqrjraj
C:\Program Files\WinAntiVirus Pro 2006\Download\ocgvgfib
C:\Program Files\WinAntiVirus Pro 2006\Download\ofnjfyya
C:\Program Files\WinAntiVirus Pro 2006\Download\prvnphjk
C:\Program Files\WinAntiVirus Pro 2006\Download\ujyiygbg
C:\Program Files\WinAntiVirus Pro 2006\Download\xtruywte
C:\Program Files\WinAntiVirus Pro 2006\Download\yupyseoa
C:\Program Files\WinAntiVirus Pro 2006\Download
C:\Program Files\WinAntiVirus Pro 2006\fat.exe
C:\Program Files\WinAntiVirus Pro 2006\fopn.exe
C:\Program Files\WinAntiVirus Pro 2006\fopn.sys
C:\Program Files\WinAntiVirus Pro 2006\fopnl.dll
C:\Program Files\WinAntiVirus Pro 2006\history.db
C:\Program Files\WinAntiVirus Pro 2006\img\button.gif
C:\Program Files\WinAntiVirus Pro 2006\img\button2.gif
C:\Program Files\WinAntiVirus Pro 2006\img\header.gif
C:\Program Files\WinAntiVirus Pro 2006\img\logo.gif
C:\Program Files\WinAntiVirus Pro 2006\img\spacer.gif
C:\Program Files\WinAntiVirus Pro 2006\img\top1.jpg
C:\Program Files\WinAntiVirus Pro 2006\img\top2.jpg
C:\Program Files\WinAntiVirus Pro 2006\img\top_line.gif
C:\Program Files\WinAntiVirus Pro 2006\img
C:\Program Files\WinAntiVirus Pro 2006\install.exe
C:\Program Files\WinAntiVirus Pro 2006\InstHelp.exe
C:\Program Files\WinAntiVirus Pro 2006\lapv.dat
C:\Program Files\WinAntiVirus Pro 2006\License.rtf
C:\Program Files\WinAntiVirus Pro 2006\online.url
C:\Program Files\WinAntiVirus Pro 2006\PGBase\vbpv.dat
C:\Program Files\WinAntiVirus Pro 2006\PGBase
C:\Program Files\WinAntiVirus Pro 2006\PGupdater.dat
C:\Program Files\WinAntiVirus Pro 2006\PGUpLst.dat
C:\Program Files\WinAntiVirus Pro 2006\phigh.bin
C:\Program Files\WinAntiVirus Pro 2006\plugins\BORLNDMM.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\NEWVIR.DAT
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANADWR.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANBCDR.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANDOS1.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANFUNC.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANKRNL.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANMCR1.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANOTHR.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANSCR.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANTOOL.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANTROJ.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\SCANWIN1.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNACPU.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNADBX.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\unamscan.dll
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNMIME.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNPACK.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNPACKS.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNPACKS2.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UNPEPACK.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27201.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27202.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27203.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27204.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27205.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27206.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27207.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27208.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27209.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27210.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27211.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UA27212.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\UADAILY.DLL
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate\wininit.ini
C:\Program Files\WinAntiVirus Pro 2006\plugins\UpDate
C:\Program Files\WinAntiVirus Pro 2006\plugins\vbpv.dat
C:\Program Files\WinAntiVirus Pro 2006\plugins
C:\Program Files\WinAntiVirus Pro 2006\pmedium.bin
C:\Program Files\WinAntiVirus Pro 2006\prc.dat
C:\Program Files\WinAntiVirus Pro 2006\prerules.xml
C:\Program Files\WinAntiVirus Pro 2006\programs.bin
C:\Program Files\WinAntiVirus Pro 2006\ps.dat
C:\Program Files\WinAntiVirus Pro 2006\pv.dat
C:\Program Files\WinAntiVirus Pro 2006\pv.exe
C:\Program Files\WinAntiVirus Pro 2006\res\cross.gif
C:\Program Files\WinAntiVirus Pro 2006\res\Register.gif
C:\Program Files\WinAntiVirus Pro 2006\res\wa6p.gif
C:\Program Files\WinAntiVirus Pro 2006\res
C:\Program Files\WinAntiVirus Pro 2006\rpt.dll
C:\Program Files\WinAntiVirus Pro 2006\settings.bin
C:\Program Files\WinAntiVirus Pro 2006\sqlite3.dll
C:\Program Files\WinAntiVirus Pro 2006\sr.log
C:\Program Files\WinAntiVirus Pro 2006\st.dat
C:\Program Files\WinAntiVirus Pro 2006\support.url
C:\Program Files\WinAntiVirus Pro 2006\traffic.txt
C:\Program Files\WinAntiVirus Pro 2006\UBUpdater.dat
C:\Program Files\WinAntiVirus Pro 2006\unins000.dat
C:\Program Files\WinAntiVirus Pro 2006\unins000.exe
C:\Program Files\WinAntiVirus Pro 2006\uninstall.ico
C:\Program Files\WinAntiVirus Pro 2006\UninstallPage.html
C:\Program Files\WinAntiVirus Pro 2006\up.dat
C:\Program Files\WinAntiVirus Pro 2006\updater.dat
C:\Program Files\WinAntiVirus Pro 2006\Updater.exe
C:\Program Files\WinAntiVirus Pro 2006\VAExt.exe
C:\Program Files\WinAntiVirus Pro 2006\WAV6COM.dll
C:\Program Files\WinAntiVirus Pro 2006\WinAV.xml
C:\Program Files\WinAntiVirus Pro 2006\worldmap.swf
C:\Program Files\WinAntiVirus Pro 2006
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006\Logs\update.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006\Logs
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006\PGE.dat
C:\Documents and Settings\Owner\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\Uninstall WinAntiVirus Pro 2006.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006 Manual.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006\WinAntiVirus Pro 2006.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\WinAntiVirus Pro 2006
C:\WINNT\Prefetch\FWSVC.EXE-0C4639C9.pf
C:\WINNT\Prefetch\UPDATER.EXE-14D32685.pf
C:\WINNT\Prefetch\VAEXT.EXE-335FBDDE.pf
C:\WINNT\Prefetch\WINAV.EXE-24BCCFDE.pf

Trojan.Downloader-WNA
HKLM\Software\Classes\CLSID\{013A653B-49A6-4f76-8B68-E4875EA6BA54}
HKCR\CLSID\{013A653B-49A6-4F76-8B68-E4875EA6BA54}
HKCR\CLSID\{013A653B-49A6-4F76-8B68-E4875EA6BA54}\InprocServer32
HKCR\CLSID\{013A653B-49A6-4F76-8B68-E4875EA6BA54}\InprocServer32#ThreadingModel
C:\WINNT\SYSTEM32\WMEKDOAV.DLL

Trojan.WinAntiSpyware/WinAntiVirus 2006
HKLM\Software\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4}
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}#AppID
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\InprocServer32
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\InprocServer32#ThreadingModel
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\ProgID
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\Programmable
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\TypeLib
HKCR\CLSID\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}\VersionIndependentProgID
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\WINPGI.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
HKLM\System\ControlSet001\Services\vspf
C:\WINNT\SYSTEM32\DRIVERS\VSPF5.SYS
HKLM\System\ControlSet001\Services\vspf_hk
C:\WINNT\SYSTEM32\DRIVERS\VSPF_HK5.SYS
HKLM\System\ControlSet002\Services\vspf
HKLM\System\ControlSet002\Services\vspf_hk
HKLM\System\CurrentControlSet\Services\vspf
HKLM\System\CurrentControlSet\Services\vspf_hk
C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\WINANTIVIRUSPRO2006FREEINSTALL[1].EXE
C:\WINNT\DOWNLOADED PROGRAM FILES\UWA6P_0001_N91M1807NETINSTALLER.EXE
C:\WINNT\DOWNLOADED PROGRAM FILES\UWA6P_0001_N91M1807NETINSTALLER.INF

Adware.VSToolbar
HKLM\Software\Classes\CLSID\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}
HKCR\CLSID\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}
HKCR\CLSID\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\InProcServer32
HKCR\CLSID\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\InProcServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}
HKCR\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}
HKCR\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}
HKCR\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}\InProcServer32
HKCR\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}\InProcServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{74DD705D-6834-439C-A735-A6DBE2677452}
HKU\S-1-5-21-367768924-3279092438-3500024551-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{74DD705D-6834-439C-A735-A6DBE2677452}
HKU\S-1-5-21-367768924-3279092438-3500024551-1003\Software\Search Toolbar Corp
C:\Program Files\VSToolbar\VSToolBar.dll
C:\Program Files\VSToolbar
C:\Documents and Settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision
C:\Documents and Settings\Owner\Application Data\SearchToolbarCorp

Trojan.WinSoftware/WinFixer
HKLM\Software\Classes\CLSID\{B5141620-C2B2-4d95-9F0F-134D99C87AB0}
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}#AppID
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\InprocServer32
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\InprocServer32#ThreadingModel
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\ProgID
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\Programmable
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\TypeLib
HKCR\CLSID\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}\VersionIndependentProgID
C:\PROGRAM FILES\WINANTIVIRUS PRO 2006\IEFWBHO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@www.winantivirus[2].txt

Adware.MyWay
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}\InProcServer32
HKCR\CLSID\{014DA6CD-189F-421a-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6CD-189F-421a-88CD-07CFE51CFF10}\InProcServer32
HKLM\Software\MyWay
HKLM\Software\MyWay\myBar
HKLM\Software\MyWay\myBar#Dir
HKLM\Software\MyWay\myBar#ShzmCurInstall
HKLM\Software\MyWay\myBar#pid
HKLM\Software\MyWay\myBar#strings
HKLM\Software\MyWay\myBar#CurInstall
HKLM\Software\MyWay\myBar#sr
HKLM\Software\MyWay\myBar#pl
HKLM\Software\MyWay\myBar#Id
HKLM\Software\MyWay\myBar#Build
HKLM\Software\MyWay\myBar#CacheDir
HKLM\Software\MyWay\myBar#HistoryDir
HKLM\Software\MyWay\myBar#Visible
HKLM\Software\MyWay\myBar#SettingsDir
HKLM\Software\MyWay\myBar#ConfigRevision
HKLM\Software\MyWay\myBar#ConfigRevisionURL
HKLM\Software\MyWay\myBar#ConfigDateStamp
HKLM\Software\MyWay\myBar#Maximized
HKLM\Software\MyWay\myBar\partner
HKLM\Software\MyWay\myBar\partner#bitmap
HKLM\Software\MyWay\myBar\partner#name
HKLM\Software\MyWay\myBar\partner#test
HKLM\Software\MyWay\myBar\partner#PM-Home
HKLM\Software\MyWay\myBar\partner#PM-Points
HKLM\Software\MyWay\myBar\partner#PM-Redeem
HKLM\Software\MyWay\myBar\partner#PM-Wallet
HKLM\Software\MyWay\myBar\partner#PM-Settings
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall#UrlInfoAbout
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{0494D0D9-F8E0-41ad-92A3-14154ECE70AC}
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
C:\Program Files\MyWay\myBar\1.bin\MYWAYPLUGINPROXY.CLASS
C:\Program Files\MyWay\myBar\1.bin\PARTNER.BMP
C:\Program Files\MyWay\myBar\1.bin\PARTNER.DAT
C:\Program Files\MyWay\myBar\1.bin\PARTNER2.DAT
C:\Program Files\MyWay\myBar\1.bin\PARTNER3.DAT
C:\Program Files\MyWay\myBar\1.bin\PARTNER4.DAT
C:\Program Files\MyWay\myBar\1.bin\PARTNER5.DAT
C:\Program Files\MyWay\myBar\1.bin\PARTNER6.DAT
C:\Program Files\MyWay\myBar\1.bin
C:\Program Files\MyWay\myBar\Cache\0063079C.bin
C:\Program Files\MyWay\myBar\Cache\00631A45.bin
C:\Program Files\MyWay\myBar\Cache\00632402.bin
C:\Program Files\MyWay\myBar\Cache\0266C4A3
C:\Program Files\MyWay\myBar\Cache\files.ini
C:\Program Files\MyWay\myBar\Cache
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\myBar\History
C:\Program Files\MyWay\myBar\Settings\prevcfg.htm
C:\Program Files\MyWay\myBar\Settings
C:\Program Files\MyWay\myBar
C:\Program Files\MyWay

Unclassified.Unknown Origin
HKCR\CLSID\{013A653B-49A6-4F76-8B68-E4875EA6BA54}
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}\InprocServer32
HKCR\CLSID\{1DAEFCB9-06C8-47C6-8F20-3FB54B244DAA}\InprocServer32#ThreadingModel
HKCR\CLSID\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}
HKCR\CLSID\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\InprocServer32
HKCR\CLSID\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}\InprocServer32#ThreadingModel
HKCR\CLSID\{3FD6B99C-A275-46EA-8FD1-3D63986E51E4}
HKCR\CLSID\{3FD6B99C-A275-46EA-8FD1-3D63986E51E4}\InprocServer32
HKCR\CLSID\{3FD6B99C-A275-46EA-8FD1-3D63986E51E4}\InprocServer32#ThreadingModel
HKCR\CLSID\{7DA39570-5FD2-4F18-94B4-20730CB3F727}
HKCR\CLSID\{7DA39570-5FD2-4F18-94B4-20730CB3F727}\InprocServer32
HKCR\CLSID\{7DA39570-5FD2-4F18-94B4-20730CB3F727}\InprocServer32#ThreadingModel
HKCR\CLSID\{F18F04B0-9CF1-4B93-B004-77A288BEE28B}
HKCR\CLSID\{F18F04B0-9CF1-4B93-B004-77A288BEE28B}\InprocServer32
HKCR\CLSID\{F18F04B0-9CF1-4B93-B004-77A288BEE28B}\InprocServer32#ThreadingModel

Adware.Vundo Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8002FAC4-987A-423F-A02F-FD2F3B3F135B}\RP350\A0043359.DLL

Trojan.Downloader-DoWork
C:\WINNT\SYSTEM32\CKQONFLK.DLL

Trojan.Downloader-VSToolbar
C:\WINNT\SYSTEM32\DHKERKAI.EXE
C:\WINNT\SYSTEM32\REDBOGNH.EXE
C:\WINNT\SYSTEM32\TNMEJLND.EXE

Trojan.Virtumonde
C:\WINNT\SYSTEM32\KMSRQAYG.DLL

Trojan.Downloader-Gen/LIB
C:\WINNT\SYSTEM32\NVOWBNIY.DLL
C:\WINNT\SYSTEM32\RLUYCVHK.DLL

Trojan.Downloader-SpyTool
C:\WINNT\SYSTEM32\RBXAQWJS.DLL
C:\WINNT\SYSTEM32\WBTQFWMY.DLL

Trojan.WinFixer
C:\WINNT\SYSTEM32\SSQRQ.DLL


Logfile of HijackThis v1.99.1
Scan saved at 5:48:51 PM, on 1/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 3 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {51EF1D96-35E7-4B87-AC91-E34842A44486} - C:\WINNT\system32\xprjqoxh.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {721A89A7-D367-43A2-A999-98A9366A6B66} - (no file)
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [CaseyVideo[2]] c:\windows\CaseyVideo[2].scr
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} -

#7 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 13 January 2007 - 09:36 AM

Sorry - HiJackThis is runing from a temp directory and must be moved to run correctly

Click here to download HJTsetup.exe:

http://www.thespykiller.co.uk/forum/index....=tpmod;dl=item5
Scroll down to the download section

Save HJTsetup.exe to your desktop.

Double click on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
Put a check by Create a desktop icon then click Next again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click Finish and it will launch Hijack This.
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.


========================

You did not post the entire log

Open the log in notepad

EDIT - SELECT ALL
EDIT - COPY

Then come to this message, and in the quick reply box click in the white space and then EDIT - PASTE
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#8 jaleo78

jaleo78
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:08:25 PM

Posted 13 January 2007 - 11:11 AM

Here is the new HiJackThis Logfile. Again thanks for all your help!!

Logfile of HijackThis v1.99.1
Scan saved at 8:07:53 AM, on 1/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\PanelICON.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\Program Files\Wistron\AVManager\AVManager.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTRay.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {51EF1D96-35E7-4B87-AC91-E34842A44486} - C:\WINNT\system32\xprjqoxh.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {721A89A7-D367-43A2-A999-98A9366A6B66} - (no file)
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [HotkeyApp] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrPanelICON] C:\Program Files\Launch Manager\PanelICON.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [AVManager] "C:\Program Files\Wistron\AVManager\AVManager.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136397616\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [CaseyVideo[2]] c:\windows\CaseyVideo[2].scr
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Reality Fusion GameCam SE.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/...FreeInstall.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig...loadControl.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63E83BDC-CBA2-403C-BB4E-2F30E49BDA1C}: NameServer = 194.25.0.68,194.25.0.60
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

#9 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 13 January 2007 - 11:19 AM

Please click here http://www.majorgeeks.com/Sun_Java_Runtime...ment_d4648.html to download the latest version of JAVA Install the application, then go to the Add/Remove Programs options in the Control Panel and Remove ALL previous versions of JAVA.


You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

O2 - BHO: (no name) - {51EF1D96-35E7-4B87-AC91-E34842A44486} - C:\WINNT\system32\xprjqoxh.dll (file missing)

O2 - BHO: (no name) - {721A89A7-D367-43A2-A999-98A9366A6B66} - (no file)

O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART

O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s

O4 - HKCU\..\Run: [CaseyVideo[2]] c:\windows\CaseyVideo[2].scr

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -

DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINNT\System32\P2P Networking
C:\Program Files\Altnet
c:\windows\CaseyVideo[2].scr

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new hijack log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users