|  | 
 
															
															
	
			
			
				| My computer has virus that want let me do a scan |  |  
					
					
				 
						| daddy163Junior Member 
   | 18. April 2006 @ 15:03 |  Link to this message   |  
						| 
							
							I have the McAfee virus scan but my computer want let me do a scan. Everytime I do 1 the system reboots itself.  I have tried to do a scan in safe mode but that don't work.  I have even tried McAfee stinger with no luck. PLEASE HELP ME!!!!!!!!!!!!  PS I am running windows XP on a built PC
							
						 |  
						| Advertisement   |   |  
						|  |  
						| Senior Member 
   | 18. April 2006 @ 21:30 |  Link to this message   |  
						| 
							
							I hate to say this, but get rid of McAfee.  It's by far the worst AV program on the market.  Last rating it received from reliable sources was no better than a 4 (outta 10).
 You could take your drive out of that system, set it as a slave in another and do an online scan from either AVG, Panda, or Trend Micro.
 
 If you know what the virus files are, by doing the above, you can delete those files having the drive in another system.
 
 |  
						| aabbccddSuspended permanently 
   | 18. April 2006 @ 22:02 |  Link to this message   |  
						| 
							
							or delete McAfee which is a crap program as said download and run Trend Mirco or AVG. thats a good free program ,DONT get norton either ,you may be able to delete the virus with "HighjackThis" its free download and try that first
 |  
						| xaznboitxSenior Member 
   | 18. April 2006 @ 23:06 |  Link to this message   |  
						| 
							
							Hm...
Trend Micro and the other two freezes my computer. I dont know why. It just does.
 
 There is a forum for this  you know..
 |  
						| Moderator 
   | 19. April 2006 @ 04:18 |  Link to this message   |  
						| 
							
							thread teleported to relevant forum
 
   Main PC ~ Intel C2Q Q6600 (G0 Stepping)/Gigabyte GA-EP45-DS3/2GB Crucial Ballistix PC2-8500/Zalman CNPS9700/Antec 900/Corsair HX 620W Network ~ DD-WRT ~ 2node WDS-WPA2/AES ~ Buffalo WHR-G54S. 3node WPA2/AES ~ WRT54GS v6 (inc. WEP BSSID), WRT54G v2, WRT54G2 v1.    *** Forum Rules *** |  
						| Senior Member 
   | 19. April 2006 @ 07:33 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Senior Member 
   | 19. April 2006 @ 13:55 |  Link to this message   |  
						| 
							
							You wanna remove whatever it is with HjT as i've seen in a few cases malware causes scanners to hang and do whats happening to you..
 JaPK's claimed your log so get it posted..
 
 
 |  
						| daddy163Junior Member 
   | 22. April 2006 @ 08:43 |  Link to this message   |  
						| 
							
							JaPK,
Every time I do a virus scan via your link my computer still reboots itself.  DO you think it would be better for me to just reboot my whole system.
 |  
						| Senior Member 
   | 22. April 2006 @ 08:48 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Senior Member 
   | 22. April 2006 @ 10:44 |  Link to this message   |  
						| 
							
							@daddy163
 Quote:Read it...You wanna remove whatever it is with HjT as i've seen in a few cases malware causes scanners to hang and do whats happening to you..
 
 
 "Every time I do a virus scan via your link my computer still reboots itself."
 
 Thats whats gonna happen..HjT log please, JaPK's clamied it...
 
 
 |  
						| daddy163Junior Member 
   | 22. April 2006 @ 20:13 |  Link to this message   |  
						| 
							
							OK I did the scan here is my log;
Logfile of HijackThis v1.99.1
 Scan saved at 11:46:46 PM, on 4/22/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\progra~1\mcafee\MCAFEE~1\masalert.exe
 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 c:\progra~1\mcafee.com\vso\mcvsescn.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 c:\progra~1\mcafee.com\vso\mcvsftsn.exe
 C:\Program Files\Microsoft Office\Office10\msoffice.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 c:\program files\mcafee.com\shared\mcinfo.exe
 C:\Program Files\Yahoo!\Messenger\ypager.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\HJT\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
 O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
 O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinprag.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
 O4 - HKCU\..\Run: [CU1]
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
 O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
 O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinprag.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
 O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
 O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
 O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
 O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: SAVScan - Unknown owner - C:\Program Files\Norton AntiVirus\SAVScan.exe (file missing)
 O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 I hope one of you guys can help me get this crap off of my pc
 |  
						| Senior Member 
   | 22. April 2006 @ 20:54 |  Link to this message   |  
						| 
							
							Hi daddy163.
 OK, you seem to have 3 different antiviruses (well, parts of those) running at the same time. This is propably one reason to your crashes.
 
 You seem to have uninstalled Norton earlier, but there are many remainings running. We'll take those off.
 Then you seem to have uninstalled AVG Antivirus too, there is a few remainings left. We'll take those off
 
 McAfee is your current antivirus, we'll left that.
 
 Then you have some infections....
 
 Cleaning instructions:
 
 Go to Control Panel -> Add or remove programs -> Remove Zeno Search, Surf SideKick if found
 
 Download BFU.zip -> http://www.merijn.org/files/bfu.zip
 Unzip it to folder C:\BFU
 
 Download this removal script (right-click with mouse, Save target as) ->http://downloads.subratam.org/Lon/sidekickFix.bat
 And save it to the same folder than where BFU was installed earlier (c:\BFU).
 
 Do NOT use this yet!
 
 Restart your computer to the safe mode (Press F8 button when computer is starting and choose safe mode)
 
 Press Start -> My Computer -> Go to folder C:\BFU
 ->Close all other windows, including explorer folders.
 ->Doubleclick sidekickFix.bat
 ->Click Yes and follow the instructions, when it asks a restart your pc, restart it.
 
 Run HijackThis and fix these entries (if found): (Do a system scan only, check entries, close all other windows, press Fix checked)
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http...
 O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinprag.exe
 O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinprag.exe
 O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2...
 O18 - Filter: text/html - {CEA53356-C414-4331-A35E-AA4CE9D8DFA2} - C:\WINDOWS\system32\w9seq.dll
 
 
 Then if my conclusions about your antivirus situation were right (at the beginning), remove the remainings of AVG and Norton:
 
 Fix these three entries with HijackThis
 
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
 O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
 
 
 Open Notepad
 -> copy the following lines into a new document:
 
 @echo off
 sc stop ccEvtMgr
 sc delete ccEvtMgr
 sc stop ccSetMgr
 sc delete ccSetMgr
 sc stop SAVScan
 sc delete SAVScan
 sc stop SNDSrvc
 sc delete SNDSrvc
 sc stop Symantec Core LC
 sc delete Symantec Core LC
 
 
 Save the document to your desktop as Removal.bat and filetype: All Files
 Go to your desktop and run the file Removal.bat and answer yes to any questions.
 
 Restart your computer to the safemode (Press F8 button when computer is starting and choose safemode)
 
 Make your hidden files visible:
 ->On the Tools menu in Windows Explorer, click Folder Options.
 ->Click the View tab.
 ->Under Hidden files and folders, click Show hidden files and folders.
 
 Delete these files if found:
 C:\WINDOWS\system32\pwinprag.exe
 C:\WINDOWS\system32\w9seq.dll
 
 Empty the Recycle Bin
 
 Make your hidden files invisible again:
 ->On the Tools menu in Windows Explorer, click Folder Options.
 ->Click the View tab.
 ->Under Hidden files and folders, click Do not show hidden files and folders.
 
 Restart your computer normally.
 
 Post a fresh HijackThis log to here so we can see if your computer is now clean.
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 22. April 2006 @ 23:08 |  
						| Senior Member 
   | 22. April 2006 @ 21:00 |  Link to this message   |  
						| 
							
							Now you can paypal JapK the $150 he just saved you in computer repairs.
 Also, the best antivirus is Kaspersky. Period. End of discussion. ;)
 
 
 |  
						| aabbccddSuspended permanently 
   | 22. April 2006 @ 21:49 |  Link to this message   |  
						| 
							
							TomMelee ,theres three that are all good ,Kaspersky being one of them Trend Mirco PC-cillin and Nod32 all the best
 |  
						| Senior Member 
   | 23. April 2006 @ 06:59 |  Link to this message   |  
						| 
							
							AVG/AVG free is always a good alternative..
 
 |  
						| daddy163Junior Member 
   | 23. April 2006 @ 08:15 |  Link to this message   |  
						| 
							
							new log
Logfile of HijackThis v1.99.1
 Scan saved at 12:13:50 PM, on 4/23/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\progra~1\mcafee\MCAFEE~1\masalert.exe
 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 c:\progra~1\mcafee.com\vso\mcvsescn.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\Microsoft Office\Office10\msoffice.exe
 c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 c:\progra~1\mcafee.com\vso\mcvsftsn.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
 C:\PROGRA~1\mcafee.com\shared\mghtml.exe
 C:\HJT\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
 O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
 O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
 O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
 O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
 O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
 
 ty
 |  
						| Senior Member 
   | 23. April 2006 @ 08:42 |  Link to this message   |  
						| 
							
							Hi daddy163.
 Ok, looking good. There is still one Norton remaining left....
 
 Open Notepad
 -> copy the following lines into a new document:
 
 @echo off
 sc stop SBService
 sc delete SBService
 
 Save the document to your desktop as Removal2.bat and filetype: All Files
 Go to your desktop and run the file Removal2.bat and answer yes to any questions.
 
 Then delete these folders:
 C:\Program Files\Common Files\Symantec Shared
 C:\Program Files\Grisoft
 C:\Program Files\Norton AntiVirus
 
 Then we'll clean your registry:
 Download CCleaner -> http://www.filehippo.com/download_ccleaner/
 Install it and clean your registry with it (take a backup when asked)
 
 Then you could download and install Ewido ->  http://www.ewido.net/en/download/
 Update it and run a Complete System Scan
 Clean the findings and save the log.
 
 Post a new HijackThis log and Ewidos log to here.
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 08:43 |  
						| daddy163Junior Member 
   | 23. April 2006 @ 12:18 |  Link to this message   |  
						| 
							
							I've done all that you told me and I hope and pray that this will cure my pc, here are the logs you ask me for;
 Logfile of HijackThis v1.99.1
 Scan saved at 4:00:14 PM, on 4/23/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\progra~1\mcafee\MCAFEE~1\masalert.exe
 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 c:\progra~1\mcafee.com\vso\mcvsescn.exe
 C:\Program Files\Microsoft Office\Office10\msoffice.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
 c:\progra~1\mcafee.com\vso\mcvsftsn.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\ewido anti-malware\ewidoguard.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\Program Files\ewido anti-malware\securitysuite.exe
 C:\HJT\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
 O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
 O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
 O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
 O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
 O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 
 ---------------------------------------------------------
 ewido anti-malware - Scan report
 ---------------------------------------------------------
 
 + Created on:			4:17:58 PM, 4/23/2006
 + Report-Checksum:		FF4CDA20
 
 + Scan result:
 
 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
 HKU\S-1-5-21-796845957-963894560-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6001CDF7-6F45-471B-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@com[2].txt -> TrackingCookie.Com : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ehg-foxsports.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@revenue[2].txt -> TrackingCookie.Revenue : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
 C:\Documents and Settings\Guest\Cookies\guest@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\Documents and Settings\keno cannady\Cookies\keno cannady@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\keno cannady\Cookies\keno cannady@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\keno cannady\Cookies\keno cannady@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bfast[1].txt -> TrackingCookie.Bfast : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@bookspan.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@clubmom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-acxiomcorporation.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-adteractive.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-cafepress.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-cbs.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-electricbusiness.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-lowermybills.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-medtronic.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-nestlepurinapetcare.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-rightnow.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@ehg-wachovia.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@marthastewart.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@partnerhealth.com.33473.fb.dbbsrv[2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@phg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@s.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@server3.web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@web4.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@webstat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
 C:\Documents and Settings\mable scurlock\Cookies\mable scurlock@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\HJT\backups\backup-20060422-235000-220.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
 C:\HJT\backups\backup-20060423-114147-630.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
 C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup
 
 
 ::Report End
 
 My Pc is still rebooting itself
 This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 13:05 |  
						| daddy163Junior Member 
   | 23. April 2006 @ 13:04 |  Link to this message   |  
						| 
							
							My PC is still rebooting itself.  I think that I have missed something
							
						 |  
						| Senior Member 
   | 23. April 2006 @ 21:09 |  Link to this message   |  
						| 
							
							Ok, try this...
 Download Blacklight and save it to your desktop http://www.f-secure.com/blacklight/try.shtml
 
 Doubleclick blbeta.exe, accept agreement, click > Scan, then > Next
 
 You'll see a list what have been found. There will appear a log in desktop named fsbl.xxxxxxx.log (xxxxxxx will be random numbers ).
 
 Don't choose Rename if something was found!
 
 Copy and paste this log to your next reply.
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 23. April 2006 @ 21:09 |  
						| daddy163Junior Member 
   | 24. April 2006 @ 06:53 |  Link to this message   |  
						| 
							
							Nothing found.  I do appreciate your help, what now?
							
						 |  
						| Senior Member 
   | 24. April 2006 @ 10:41 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 24. April 2006 @ 10:41 |  
						| daddy163Junior Member 
   | 24. April 2006 @ 13:31 |  Link to this message   |  
						| 
							
							here the log from registy mechanic: This is all the problem areas or files I have on my pc
 ----------------------------------------------------------------------------------------------------
 Registry Mechanic 5.2.0.310
 ----------------------------------------------------------------------------------------------------
 Start of Scan
 4/24/2006 4:54:46 PM
 Your System Information :
 CPU: Intel Pentium
 IE: Internet Explorer 6.0.2900
 MEMORY FREE: 494388
 MEMORY TOTAL: 785904
 VIRTUAL FREE: 2019252
 VIRTUAL TOTAL: 2097024
 WINDOWS VER: Windows XP   5.1 (Build 2600)
 
 ----------------------------------------------------------------------------------------------------
 Running processes:                      Process ID
 ----------------------------------------------------------------------------------------------------
 [System Process]                        0
 System                                  4
 smss.exe                                548
 csrss.exe                               612
 winlogon.exe                            636
 services.exe                            680
 lsass.exe                               700
 svchost.exe                             856
 svchost.exe                             916
 svchost.exe                             1016
 svchost.exe                             1096
 svchost.exe                             1164
 spoolsv.exe                             1388
 ewidoctrl.exe                           1936
 ewidoguard.exe                          1952
 MASSrv.exe                              2004
 Mcdetect.exe                            2028
 McShield.exe                            268
 McTskshd.exe                            316
 mcupdmgr.exe                            540
 MpfService.exe                          568
 nvsvc32.exe                             356
 locator.exe                             760
 wdfmgr.exe                              980
 wmiprvse.exe                            1480
 explorer.exe                            380
 ADeck.exe                               2184
 mcagent.exe                             2204
 MASAlert.exe                            2260
 BellSouthAlertManager.exe               2436
 oasclnt.exe                             2536
 MpfTray.exe                             2652
 McVSEscn.exe                            2668
 MpfAgent.exe                            3816
 msmsgs.exe                              4032
 Ymsgr_tray.exe                          1920
 PlgUni.exe                              2256
 mcvsftsn.exe                            2788
 WinCinemaMgr.exe                        3304
 MSOFFICE.EXE                            3580
 memtest.exe                             488
 iexplore.exe                            2052
 RegMech.exe                             2756
 ----------------------------------------------------------------------------------------------------
 Sections Scanned:
 ----------------------------------------------------------------------------------------------------
 
 FX - 2
 Location: HKEY_CLASSES_ROOT\.snp
 Value   : default = Snapshot File
 Parsed  :
 
 FX - 3
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bin\OpenWithList
 Value   : default = blank
 Parsed  :
 
 FX - 4
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.EX_\OpenWithList
 Value   : default = blank
 Parsed  :
 
 FX - 5
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.IN_\OpenWithList
 Value   : default = blank
 Parsed  :
 
 FX - 6
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
 Value   : default = blank
 Parsed  :
 
 FX - 7
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tlb\OpenWithList
 Value   : default = blank
 Parsed  :
 
 SP - 8
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
 Value   : C:\WINDOWS\Downloaded Program Files\popcaploader.dll = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
 Parsed  : C:\WINDOWS\Downloaded Program Files\popcaploader.dll
 
 ARP - 9
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BroadJump Client Foundation
 Value   : DisplayIcon = C:\Program Files\BroadJump\Client Foundation\CFD.exe
 Parsed  : C:\Program Files\BroadJump\Client Foundation\CFD.exe
 
 ARP - 10
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sevinst
 Value   : QuietUninstallString = C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE /U /Q
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE
 
 ARP - 11
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Genie OnlineMy Toolbar
 Value   : UninstallString = regsvr32 /u /s "C:\Program Files\KoolBar\koolbar.dll"
 Parsed  : C:\Program Files\KoolBar\koolbar.dll
 
 ARP - 12
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{228F6876-A313-40A3-91C0-C3CBE6997D09}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist
 
 ARP - 13
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2908F0CB-C1D4-447F-97A2-CFC135C9F8D4}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 ARP - 14
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet
 
 ARP - 15
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{34EEB1F5-E939-40A1-A6BA-957282A4B2C8}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help
 
 ARP - 16
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3E908702-AF35-4611-9518-955DA24B7E07}
 Value   : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
 Parsed  : C:\WINDOWS\TEMP\IXP000.TMP
 
 ARP - 17
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}
 Value   : DisplayIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
 Parsed  : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe
 
 ARP - 18
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
 Value   : InstallLocation = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 ARP - 19
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{77772678-817F-4401-9301-ED1D01A8DA56}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC
 
 ARP - 20
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B43D18F-DC74-4D44-814E-9BD3420B8E44}
 Value   : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
 Parsed  : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
 
 ARP - 21
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}
 Value   : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP
 
 ARP - 22
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C6F5B6CF-609C-428E-876F-CA83176C021B}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 ARP - 23
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}
 Value   : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E
 
 ARP - 24
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D1FF75E7-DD42-4CFD-B052-20B3FFF4EDB8}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 ARP - 25
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock
 
 ARP - 26
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon
 
 ARP - 27
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 ARP - 28
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F5346614-B7C4-4E94-826A-E2363155233D}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1\
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\bye16.tmp\Disk1
 
 ARP - 29
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F64306A5-4C32-41bb-B153-53986527FAB4}
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC
 
 CC - 30
 Location: HKEY_CLASSES_ROOT\AcroExch.Document.7\protocol\StdFileEditing\server
 Value   : (Default) = "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe"
 Parsed  : C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
 
 CC - 31
 Location: HKEY_CLASSES_ROOT\CLSID\{00CEDC01-864D-11D3-908D-00C0F03B3EDC}\ToolboxBitmap32
 Value   : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll, 1
 Parsed  : C:\Program Files\Real\RealOne Player\ierjplug.dll
 
 CC - 32
 Location: HKEY_CLASSES_ROOT\CLSID\{0494D0DE-F8E0-41ad-92A3-14154ECE70AC}\Instance\InitPropertyBag
 Value   : Url = res://C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL/105
 Parsed  : C:\PROGRA~1\MyWay\myBar\1.bin\MYBAR.DLL
 
 CC - 33
 Location: HKEY_CLASSES_ROOT\CLSID\{06290BD5-48AA-11D2-8432-006008C3FBFC}\InprocServer32
 Value   : ScriptStopper_InProcServer32 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
 
 CC - 34
 Location: HKEY_CLASSES_ROOT\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ToolboxBitmap32
 Value   : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll, 203
 Parsed  : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
 
 CC - 35
 Location: HKEY_CLASSES_ROOT\CLSID\{9ccfb0e0-fbce-11d6-8a38-00b0d0c6b814}\LocalServer
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
 
 CC - 36
 Location: HKEY_CLASSES_ROOT\CLSID\{CC2C83A6-9BE4-11D0-98E7-00C04FC2CAF5}\InprocServer32
 Value   : SystemDB = C:\Program Files\Microsoft Office\Office10\1033\system.mdw
 Parsed  : C:\Program Files\Microsoft Office\Office10\1033\system.mdw
 
 CC - 37
 Location: HKEY_CLASSES_ROOT\DVD\DefaultIcon
 Value   : MPlayer2.BAK = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
 Parsed  : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe
 
 CC - 38
 Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\0\win32
 Value   : (Default) = C:\Program Files\KoolBar\koolbar.dll
 Parsed  : C:\Program Files\KoolBar\koolbar.dll
 
 CC - 39
 Location: HKEY_CLASSES_ROOT\TypeLib\{00000000-0000-0000-0000-000000000002}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\KoolBar\
 Parsed  : C:\Program Files\KoolBar
 
 CC - 40
 Location: HKEY_CLASSES_ROOT\TypeLib\{00025E01-0000-0000-C000-000000000046}\3.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL
 Parsed  : C:\Program Files\Common Files\Microsoft Shared\DAO\DAO3032.DLL
 
 CC - 41
 Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft Office\Office\MSOWC.DLL
 Parsed  : C:\Program Files\Microsoft Office\Office\MSOWC.DLL
 
 CC - 42
 Location: HKEY_CLASSES_ROOT\TypeLib\{0002E540-0000-0000-C000-000000000046}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft Office\Office\
 Parsed  : C:\Program Files\Microsoft Office\Office
 
 CC - 43
 Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Real\RealOne Player\ierjplug.dll
 Parsed  : C:\Program Files\Real\RealOne Player\ierjplug.dll
 
 CC - 44
 Location: HKEY_CLASSES_ROOT\TypeLib\{00CEDBF1-864D-11D3-908D-00C0F03B3EDC}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Real\RealOne Player\
 Parsed  : C:\Program Files\Real\RealOne Player
 
 CC - 45
 Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\0\win32
 Value   : (Default) = C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 Parsed  : C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 
 CC - 46
 Location: HKEY_CLASSES_ROOT\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\MyWay\myBar\1.bin\
 Parsed  : C:\Program Files\MyWay\myBar\1.bin
 
 CC - 47
 Location: HKEY_CLASSES_ROOT\TypeLib\{06DD38D0-D187-11CF-A80D-00C04FD74AD8}\1.0\0\win32
 Value   : (Default) = C:\WINDOWS\System32\plugin.ocx
 Parsed  : C:\WINDOWS\System32\plugin.ocx
 
 CC - 48
 Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll
 Parsed  : C:\PROGRA~1\COMMON~1\SYMANT~1\SymLTCOM.dll
 
 CC - 49
 Location: HKEY_CLASSES_ROOT\TypeLib\{091FC996-00F1-4ED0-8351-7F0BFD553172}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 50
 Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\0\win32
 Value   : (Default) = C:\Program Files\CyberLink\PowerDVD\CLInet.dll
 Parsed  : C:\Program Files\CyberLink\PowerDVD\CLInet.dll
 
 CC - 51
 Location: HKEY_CLASSES_ROOT\TypeLib\{0A8B9461-3921-11D3-B1AB-0080C84E9C15}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\CyberLink\PowerDVD\
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 CC - 52
 Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 
 CC - 53
 Location: HKEY_CLASSES_ROOT\TypeLib\{0E9FFA9E-B267-44DF-BC81-2B08E3977ED5}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 54
 Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
 
 CC - 55
 Location: HKEY_CLASSES_ROOT\TypeLib\{140CF3D1-451B-4C9C-AB04-02C72D06A88D}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 56
 Location: HKEY_CLASSES_ROOT\TypeLib\{166B1BC7-3F9C-11CF-8075-444553540000}\1.0\0\win32
 Value   : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
 Parsed  : C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
 
 CC - 57
 Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\Navlcom.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Navlcom.dll
 
 CC - 58
 Location: HKEY_CLASSES_ROOT\TypeLib\{1C3159CA-948C-4290-A920-4C804DF9FB7D}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 59
 Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SLTCHK01.dll
 
 CC - 60
 Location: HKEY_CLASSES_ROOT\TypeLib\{20F6AEAC-284A-4022-A0A8-718AB2087D37}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 61
 Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccErrDsp.dll
 
 CC - 62
 Location: HKEY_CLASSES_ROOT\TypeLib\{226CDAFB-819C-4298-89FA-8A018BB188B5}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 63
 Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\NavShExt.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NavShExt.dll
 
 CC - 64
 Location: HKEY_CLASSES_ROOT\TypeLib\{2292E927-BD89-40DE-999A-4E72CE0EAA4F}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 65
 Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 
 CC - 66
 Location: HKEY_CLASSES_ROOT\TypeLib\{2CECFD1F-CA35-4558-AC7F-64B6B463714A}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 67
 Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
 
 CC - 68
 Location: HKEY_CLASSES_ROOT\TypeLib\{31DDE823-839A-4DD2-8D96-DF766052E142}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 69
 Location: HKEY_CLASSES_ROOT\TypeLib\{390CE9E4-C4A0-11D4-8A92-0090271D4F88}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Yahoo!\Messenger\ycrwin32.dll
 Parsed  : C:\Program Files\Yahoo!\Messenger\ycrwin32.dll
 
 CC - 70
 Location: HKEY_CLASSES_ROOT\TypeLib\{3A76A523-4FBC-487C-A94F-A94EA80E48EF}\1.0\0\win32
 Value   : (Default) = C:\WINDOWS\system32\w9seq.dll
 Parsed  : C:\WINDOWS\system32\w9seq.dll
 
 CC - 71
 Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVEVENT.DLL
 Parsed  : C:\PROGRA~1\NORTON~1\NAVEVENT.DLL
 
 CC - 72
 Location: HKEY_CLASSES_ROOT\TypeLib\{3ABF9055-667E-4FDF-ADDA-2622E8677CBC}\1.0\HELPDIR
 Value   : (Default) = C:\PROGRA~1\NORTON~1\
 Parsed  : C:\PROGRA~1\NORTON~1
 
 CC - 73
 Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVLUCBK.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVLUCBK.dll
 
 CC - 74
 Location: HKEY_CLASSES_ROOT\TypeLib\{3C2E74A0-887E-11D2-B40A-00600831DD76}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 75
 Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccPwd.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccPwd.dll
 
 CC - 76
 Location: HKEY_CLASSES_ROOT\TypeLib\{3C3D7949-0006-4745-B3F6-BED93B98FA9B}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 77
 Location: HKEY_CLASSES_ROOT\TypeLib\{3C878962-A37D-4674-AB76-2746A0E64CE7}\1.0\0\win32
 Value   : (Default) = C:\Program Files\BroadJump\Client Foundation\CFD.exe
 Parsed  : C:\Program Files\BroadJump\Client Foundation\CFD.exe
 
 CC - 78
 Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Real\RealOne Player\rpau3260.dll
 Parsed  : C:\Program Files\Real\RealOne Player\rpau3260.dll
 
 CC - 79
 Location: HKEY_CLASSES_ROOT\TypeLib\{405DE7B2-E7DD-11D2-92C5-00C0F01F77C1}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Real\RealOne Player\
 Parsed  : C:\Program Files\Real\RealOne Player
 
 CC - 80
 Location: HKEY_CLASSES_ROOT\TypeLib\{41695A81-6414-11D4-8FB3-00D0B7730277}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Yahoo!\Messenger\asw.dll
 Parsed  : C:\Program Files\Yahoo!\Messenger\asw.dll
 
 CC - 81
 Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
 
 CC - 82
 Location: HKEY_CLASSES_ROOT\TypeLib\{41949BA1-98CB-4D6F-B27B-4DA67A8B96A5}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 83
 Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
 
 CC - 84
 Location: HKEY_CLASSES_ROOT\TypeLib\{45A036EA-835E-4678-A5AC-1D117F555C06}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 85
 Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
 
 CC - 86
 Location: HKEY_CLASSES_ROOT\TypeLib\{47E5F2FC-9048-4D04-9A44-691584BE78A8}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 87
 Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 
 CC - 88
 Location: HKEY_CLASSES_ROOT\TypeLib\{4D26B19F-60BD-43DB-BC69-6B5A67BA8B71}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 
 CC - 89
 Location: HKEY_CLASSES_ROOT\TypeLib\{4E5A5CBD-2CE8-4085-B515-A20137D70D3D}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
 
 CC - 90
 Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\0\win32
 Value   : (Default) = C:\Program Files\YourSiteBar\ysb.dll
 Parsed  : C:\Program Files\YourSiteBar\ysb.dll
 
 CC - 91
 Location: HKEY_CLASSES_ROOT\TypeLib\{4EE12B71-AA5E-45EC-8666-2DB3AD3FDF44}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\YourSiteBar\
 Parsed  : C:\Program Files\YourSiteBar
 
 CC - 92
 Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
 
 CC - 93
 Location: HKEY_CLASSES_ROOT\TypeLib\{52D761FC-F7A2-4CF1-AEA9-B1746E2A2B5C}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 94
 Location: HKEY_CLASSES_ROOT\TypeLib\{52F2F122-2BC5-11D2-8FB7-000000000000}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Adobe\Photoshop CS\ImageReady.exe
 Parsed  : C:\Program Files\Adobe\Photoshop CS\ImageReady.exe
 
 CC - 95
 Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 CC - 96
 Location: HKEY_CLASSES_ROOT\TypeLib\{54635C92-DFAF-4A99-8802-92FB068A6154}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\CCPD-LC
 
 CC - 97
 Location: HKEY_CLASSES_ROOT\TypeLib\{54B0DF71-97D6-493C-834D-99FC9E19D612}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
 
 CC - 98
 Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVSTATS.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVSTATS.dll
 
 CC - 99
 Location: HKEY_CLASSES_ROOT\TypeLib\{54CC4A82-E256-4AB1-BA85-F8FF36619969}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 100
 Location: HKEY_CLASSES_ROOT\TypeLib\{56EBB89D-BB5A-4408-BA3F-04F68EB28690}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
 
 CC - 101
 Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\adm.exe
 Parsed  : C:\Program Files\Altnet\Download Manager\adm.exe
 
 CC - 102
 Location: HKEY_CLASSES_ROOT\TypeLib\{5830698F-7FC0-40CD-A453-9A0CAFDF3A64}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\
 Parsed  : C:\Program Files\Altnet\Download Manager
 
 CC - 103
 Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
 
 CC - 104
 Location: HKEY_CLASSES_ROOT\TypeLib\{586C6565-AEDF-4837-A1B2-9E98EB4BD8AD}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 105
 Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll
 Parsed  : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\SymIDSlu.dll
 
 CC - 106
 Location: HKEY_CLASSES_ROOT\TypeLib\{58C72A18-DF21-49BC-B0D6-2EDE23281506}\1.0\HELPDIR
 Value   : (Default) = C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\
 Parsed  : C:\PROGRA~1\COMMON~1\SYMANT~1\IDS
 
 CC - 107
 Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 
 CC - 108
 Location: HKEY_CLASSES_ROOT\TypeLib\{60681DC5-21B2-4264-B1F1-E1289819E023}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 109
 Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 
 CC - 110
 Location: HKEY_CLASSES_ROOT\TypeLib\{662ADDE9-5AB3-4A01-8015-FB61D18B0067}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC
 
 CC - 111
 Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\adm25.dll
 Parsed  : C:\Program Files\Altnet\Download Manager\adm25.dll
 
 CC - 112
 Location: HKEY_CLASSES_ROOT\TypeLib\{676F6D1D-C559-42A9-860B-27C1477B7179}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\
 Parsed  : C:\Program Files\Altnet\Download Manager
 
 CC - 113
 Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\OPScan.exe
 Parsed  : C:\Program Files\Norton AntiVirus\OPScan.exe
 
 CC - 114
 Location: HKEY_CLASSES_ROOT\TypeLib\{68786388-3E7A-4E69-BDB4-814A1EEB1C0D}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 115
 Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcAntiSpywareLibrary.dll
 
 CC - 116
 Location: HKEY_CLASSES_ROOT\TypeLib\{6B64D109-9674-4D70-8E63-EE0F9A7C9436}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 117
 Location: HKEY_CLASSES_ROOT\TypeLib\{6E2295DE-2B0E-4ED8-91A8-D9E9A514A027}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
 
 CC - 118
 Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
 
 CC - 119
 Location: HKEY_CLASSES_ROOT\TypeLib\{7479B280-A309-415C-A351-05483C51F75F}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 120
 Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
 Parsed  : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
 
 CC - 121
 Location: HKEY_CLASSES_ROOT\TypeLib\{77F05869-E2D3-430E-8364-4D2247DECDE4}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 122
 Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVTasks.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVTasks.dll
 
 CC - 123
 Location: HKEY_CLASSES_ROOT\TypeLib\{7C1B9D8B-2B5F-41B2-95F7-DE2C5BD594EC}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 124
 Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\ccIMScan.dll
 Parsed  : C:\Program Files\Norton AntiVirus\ccIMScan.dll
 
 CC - 125
 Location: HKEY_CLASSES_ROOT\TypeLib\{822E40E5-8012-40F0-AB0E-EC7B0DFF76BC}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 126
 Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRRES.DLL
 
 CC - 127
 Location: HKEY_CLASSES_ROOT\TypeLib\{838E8E82-F171-4006-A930-9D57949BC2AC}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg
 
 CC - 128
 Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSCTRL.DLL
 
 CC - 129
 Location: HKEY_CLASSES_ROOT\TypeLib\{84699B2B-F985-4C87-ADB8-6FDCAD52ED22}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg
 
 CC - 130
 Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\DefAlert.dll
 Parsed  : C:\PROGRA~1\NORTON~1\DefAlert.dll
 
 CC - 131
 Location: HKEY_CLASSES_ROOT\TypeLib\{852C26A8-5C40-4EFB-9D81-096B21BF9D81}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 132
 Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASPrivacyLib.dll
 
 CC - 133
 Location: HKEY_CLASSES_ROOT\TypeLib\{86073239-029C-458B-8546-383694B94B7D}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 134
 Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVUI.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVUI.dll
 
 CC - 135
 Location: HKEY_CLASSES_ROOT\TypeLib\{88734681-FCB2-11D2-B9D2-00C04FAC114C}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 136
 Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\0\win32
 Value   : (Default) = C:\Program Files\ISTbar\istbar.dll
 Parsed  : C:\Program Files\ISTbar\istbar.dll
 
 CC - 137
 Location: HKEY_CLASSES_ROOT\TypeLib\{89A10D64-83BF-41A4-86A3-7AAF1F8F3D1B}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\ISTbar\
 Parsed  : C:\Program Files\ISTbar
 
 CC - 138
 Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\AboutPlg.dll
 Parsed  : C:\PROGRA~1\NORTON~1\AboutPlg.dll
 
 CC - 139
 Location: HKEY_CLASSES_ROOT\TypeLib\{8A934650-3A3D-11D3-A2D4-005004184DF1}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 140
 Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll
 Parsed  : C:\Program Files\Common Files\ScanSoft Shared\ScnWizC.dll
 
 CC - 141
 Location: HKEY_CLASSES_ROOT\TypeLib\{903F7FB7-9888-4A4A-B1D5-2A13A7276589}\2.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\ScanSoft Shared\
 Parsed  : C:\Program Files\Common Files\ScanSoft Shared
 
 CC - 142
 Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVLnch.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVLnch.dll
 
 CC - 143
 Location: HKEY_CLASSES_ROOT\TypeLib\{9275E229-718E-4A2D-8EE0-10C5AA524C22}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 144
 Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 
 CC - 145
 Location: HKEY_CLASSES_ROOT\TypeLib\{941F23D1-BD56-4F90-B99F-134D55D86053}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 146
 Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll
 Parsed  : C:\PROGRA~1\NORTON~1\IWP\IWPLUCbk.dll
 
 CC - 147
 Location: HKEY_CLASSES_ROOT\TypeLib\{9B422879-A1BF-44C4-AC83-B4308A1B2272}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\
 Parsed  : C:\Program Files\Norton AntiVirus\IWP
 
 CC - 148
 Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\0\win32
 Value   : (Default) = C:\Program Files\iTunes\iTunes.exe
 Parsed  : C:\Program Files\iTunes\iTunes.exe
 
 CC - 149
 Location: HKEY_CLASSES_ROOT\TypeLib\{9E93C96F-CF0D-43F6-8BA8-B807A3370712}\1.5\HELPDIR
 Value   : (Default) = C:\Program Files\iTunes\
 Parsed  : C:\Program Files\iTunes
 
 CC - 150
 Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 
 CC - 151
 Location: HKEY_CLASSES_ROOT\TypeLib\{9F3B84DC-3631-4BCE-90E9-041A6198A2FA}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 152
 Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll
 Parsed  : C:\Program Files\Real\RealOne Player\rpplugins\ierpplug.dll
 
 CC - 153
 Location: HKEY_CLASSES_ROOT\TypeLib\{A67004E0-8362-42F9-B186-88706C346DD9}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Real\RealOne Player\rpplugins\
 Parsed  : C:\Program Files\Real\RealOne Player\rpplugins
 
 CC - 154
 Location: HKEY_CLASSES_ROOT\TypeLib\{A7336B62-3374-4D2F-8C3F-946D6A9DE725}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
 
 CC - 155
 Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccWebWnd.dll
 
 CC - 156
 Location: HKEY_CLASSES_ROOT\TypeLib\{ABA89334-36F7-4263-987C-941FF0C3E105}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 157
 Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SymBbaAx.ocx
 
 CC - 158
 Location: HKEY_CLASSES_ROOT\TypeLib\{B0BD3CBA-3FB8-4A77-B0BE-D3E9E2BB6FBD}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 159
 Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcSoftwareUpdateLib.dll
 
 CC - 160
 Location: HKEY_CLASSES_ROOT\TypeLib\{B53DE72C-31E1-49C7-97FD-D22CAA89B27E}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 161
 Location: HKEY_CLASSES_ROOT\TypeLib\{BE2DF74C-BDC0-4411-9641-4B811B82A3AF}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVComUI.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVComUI.dll
 
 CC - 162
 Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\0\win32
 Value   : (Default) = C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll
 Parsed  : C:\Program Files\CyberLink\PowerDVD\AppBarCom.dll
 
 CC - 163
 Location: HKEY_CLASSES_ROOT\TypeLib\{BFC07EE1-0EFF-11D4-AE9A-0000E88EB84F}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\CyberLink\PowerDVD\
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 CC - 164
 Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\adm4.dll
 Parsed  : C:\Program Files\Altnet\Download Manager\adm4.dll
 
 CC - 165
 Location: HKEY_CLASSES_ROOT\TypeLib\{BFF4F684-677E-44F4-8C74-1D575C950E10}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Altnet\Download Manager\
 Parsed  : C:\Program Files\Altnet\Download Manager
 
 CC - 166
 Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg\LRCTRL.DLL
 
 CC - 167
 Location: HKEY_CLASSES_ROOT\TypeLib\{C02ABA7B-5269-4737-8DAE-3A453E6C9CD3}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg
 
 CC - 168
 Location: HKEY_CLASSES_ROOT\TypeLib\{C2FC361F-2281-11D2-8E21-10B404C10000}\1.b\0\win32
 Value   : (Default) = C:\WINDOWS\System32\cNewMenu.dll
 Parsed  : C:\WINDOWS\System32\cNewMenu.dll
 
 CC - 169
 Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASThreatAudit.dll
 
 CC - 170
 Location: HKEY_CLASSES_ROOT\TypeLib\{C39962BA-5DDC-408D-9367-FEE637EE54D6}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 171
 Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCWb.dll
 
 CC - 172
 Location: HKEY_CLASSES_ROOT\TypeLib\{C3A4D68F-FD37-4617-9A58-D9BD1EE0D8D1}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\Security Center\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Security Center
 
 CC - 173
 Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccSetEvt.dll
 
 CC - 174
 Location: HKEY_CLASSES_ROOT\TypeLib\{C40049E7-5154-40E3-83B5-A94A89A29890}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 175
 Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcTCPObjLib.dll
 
 CC - 176
 Location: HKEY_CLASSES_ROOT\TypeLib\{C62B7AAE-194F-475C-AA49-DE7F12E6FC06}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 177
 Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCEvt.dll
 
 CC - 178
 Location: HKEY_CLASSES_ROOT\TypeLib\{C9C05A42-D571-4B3C-8F11-D6D6A81C90EB}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\SPBBC\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC
 
 CC - 179
 Location: HKEY_CLASSES_ROOT\TypeLib\{CC257918-F435-4A33-8231-2B8195990CCA}\1.0\0\win32
 Value   : (Default) = C:\WINDOWS\Downloaded Program Files\YSBactivex.dll
 Parsed  : C:\WINDOWS\Downloaded Program Files\YSBactivex.dll
 
 CC - 180
 Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcASSoapLib.dll
 
 CC - 181
 Location: HKEY_CLASSES_ROOT\TypeLib\{CE949EEF-0C75-4BCC-BF95-8173D44AEC6B}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 182
 Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 
 CC - 183
 Location: HKEY_CLASSES_ROOT\TypeLib\{CEACE91F-3F71-4A8C-B952-63716B2BC026}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Microsoft AntiSpyware
 Parsed  : C:\Program Files\Microsoft AntiSpyware
 
 CC - 184
 Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll
 Parsed  : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mlfoshim.dll
 
 CC - 185
 Location: HKEY_CLASSES_ROOT\TypeLib\{CF34D2A7-C8C6-4B4E-8752-F63C2BDF1CF0}\1.0\HELPDIR
 Value   : (Default) = C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\
 Parsed  : C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1
 
 CC - 186
 Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0
 Value   : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVError.dll
 
 CC - 187
 Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\NAVError.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVError.dll
 
 CC - 188
 Location: HKEY_CLASSES_ROOT\TypeLib\{D0FB5093-C2F0-4280-AAC9-3C35C6980FD8}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 189
 Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\0\win32
 Value   : (Default) = C:\PROGRA~1\NORTON~1\NAVOpts.dll
 Parsed  : C:\PROGRA~1\NORTON~1\NAVOpts.dll
 
 CC - 190
 Location: HKEY_CLASSES_ROOT\TypeLib\{D323F395-AA30-4DF9-A379-2F3F4819AB00}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 191
 Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
 
 CC - 192
 Location: HKEY_CLASSES_ROOT\TypeLib\{D935DFEC-4546-4119-94D5-91807C7BB363}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 193
 Location: HKEY_CLASSES_ROOT\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Messenger\rtcimsp.dll
 Parsed  : C:\Program Files\Messenger\rtcimsp.dll
 
 CC - 194
 Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\OfficeAV.dll
 Parsed  : C:\Program Files\Norton AntiVirus\OfficeAV.dll
 
 CC - 195
 Location: HKEY_CLASSES_ROOT\TypeLib\{DE1F7EE0-1851-11D3-939E-0004AC1ABE1F}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 196
 Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccProSub.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccProSub.dll
 
 CC - 197
 Location: HKEY_CLASSES_ROOT\TypeLib\{EB54C4A8-F9BE-429F-AA4F-F1FA39EA3537}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 198
 Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Kazaa\Topsearch.dll
 Parsed  : C:\Program Files\Kazaa\Topsearch.dll
 
 CC - 199
 Location: HKEY_CLASSES_ROOT\TypeLib\{EDD3B3E9-3FFD-4836-A6DE-D4A9C473A971}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Kazaa\
 Parsed  : C:\Program Files\Kazaa
 
 CC - 200
 Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
 
 CC - 201
 Location: HKEY_CLASSES_ROOT\TypeLib\{EF070A21-6AD8-470A-BA49-4AF45E07B55F}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 CC - 202
 Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Norton AntiVirus\navapsvc.exe
 Parsed  : C:\Program Files\Norton AntiVirus\navapsvc.exe
 
 CC - 203
 Location: HKEY_CLASSES_ROOT\TypeLib\{F743EA98-42BD-4E2C-A221-3F7B646748C7}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 CC - 204
 Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\0\win32
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg\LSPLUGIN.DLL
 
 CC - 205
 Location: HKEY_CLASSES_ROOT\TypeLib\{FF2802B8-8E99-4518-B350-DF088BD26CE7}\1.0\HELPDIR
 Value   : (Default) = C:\Program Files\Common Files\Symantec Shared\LiveReg\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg
 
 DEEP - 206
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Software\Microsoft\Outlook Express\5.0
 Value   : Store Root = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Identities\{7A9B0D75-49A0-4F63-A23C-A0DD4E68E543}\Microsoft\Outlook Express
 
 DEEP - 207
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Disney\DIGStream
 Value   : CachePath = C:\Documents and Settings\All Users\Application Data\DIGStream
 Parsed  : C:\Documents and Settings\All Users\Application Data\DIGStream
 
 DEEP - 208
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\GIANTCompany\AntiSpyware\Alerts\DE17EE69-5155-42EE-A618-968589
 Value   : FilePath = C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe
 Parsed  : C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hnhufu.exe
 
 DEEP - 209
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Macromedia\Shockwave 10\location\coreplayerxtras
 Value   : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
 Parsed  : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras
 
 DEEP - 210
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
 Value   : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 Parsed  : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 
 DEEP - 211
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 
 DEEP - 212
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 
 DEEP - 213
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006032720060403
 Value   : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006032720060403
 
 DEEP - 214
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
 Value   : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410
 
 DEEP - 215
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041020060417
 Value   : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041020060417
 
 DEEP - 216
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006041720060418
 Value   : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006041720060418
 
 DEEP - 217
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run
 Value   : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 
 DEEP - 218
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\BroadJump\Client Foundation\CFD.exe = C:\Program Files\BroadJump\Client Foundation\CFD.exe
 Parsed  : C:\Program Files\BroadJump\Client Foundation\CFD.exe
 
 DEEP - 219
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe = C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
 
 DEEP - 220
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe = C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
 Parsed  : C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
 
 DEEP - 221
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe = C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe
 Parsed  : C:\Program Files\MSN Toolbar Suite\DS\02.00.0001.1203\en-us\bin\msnlAdmin.exe
 
 DEEP - 222
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe = C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe
 
 DEEP - 223
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
 
 DEEP - 224
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe = C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareUpdater.exe
 
 DEEP - 225
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe = C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe
 Parsed  : C:\Program Files\Microsoft AntiSpyware\gcasSWUpdater.exe
 
 DEEP - 226
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
 Parsed  : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
 
 DEEP - 227
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe = C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
 Parsed  : C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
 
 DEEP - 228
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Common Files\Symantec Shared\ccApp.exe = C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 
 DEEP - 229
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\PROGRA~1\SYMNET~1\SNDMon.exe = C:\PROGRA~1\SYMNET~1\SNDMon.exe
 Parsed  : C:\PROGRA~1\SYMNET~1\SNDMon.exe
 
 DEEP - 230
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
 
 DEEP - 231
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\PROGRA~1\Grisoft\AVG7\avgw.exe = C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 
 DEEP - 232
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat = C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
 
 DEEP - 233
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE = C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
 Parsed  : C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
 
 DEEP - 234
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
 Parsed  : C:\WINDOWS\system32\slk8x2peu.exe
 
 DEEP - 235
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\system32\nwinmrag.exe = C:\WINDOWS\system32\nwinmrag.exe
 Parsed  : C:\WINDOWS\system32\nwinmrag.exe
 
 DEEP - 236
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe = C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe
 
 DEEP - 237
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 
 DEEP - 238
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe = C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
 Parsed  : C:\WINDOWS\Microsoft.NET\Framework\NETFXSBS10.exe
 
 DEEP - 239
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe = C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
 Parsed  : C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
 
 DEEP - 240
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
 Parsed  : C:\WINDOWS\system32\lwinrrag.exe
 
 DEEP - 241
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\security.zap
 
 DEEP - 242
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
 
 DEEP - 243
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\email.zap
 
 DEEP - 244
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
 
 DEEP - 245
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
 
 DEEP - 246
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
 
 DEEP - 247
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
 
 DEEP - 248
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
 
 DEEP - 249
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
 
 DEEP - 250
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-1004\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
 
 DEEP - 251
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
 Value   : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 Parsed  : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 
 DEEP - 252
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 
 DEEP - 253
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 
 DEEP - 254
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012006040320060410
 Value   : CachePath = C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\History\History.IE5\MSHist012006040320060410
 
 DEEP - 255
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\CurrentVersion\Run
 Value   : AVG7_Run = C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgw.exe
 
 DEEP - 256
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\system32\slk8x2peu.exe = C:\WINDOWS\system32\slk8x2peu.exe
 Parsed  : C:\WINDOWS\system32\slk8x2peu.exe
 
 DEEP - 257
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\WINDOWS\system32\lwinrrag.exe = C:\WINDOWS\system32\lwinrrag.exe
 Parsed  : C:\WINDOWS\system32\lwinrrag.exe
 
 DEEP - 258
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000001
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\security.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\security.zap
 
 DEEP - 259
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000002
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\firewall.zap
 
 DEEP - 260
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000004
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\email.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\email.zap
 
 DEEP - 261
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000008
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\scan.zap
 
 DEEP - 262
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000010
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\programs.zap
 
 DEEP - 263
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000020
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\imsecure.zap
 
 DEEP - 264
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000040
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\idlock.zap
 
 DEEP - 265
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000080
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\privacy.zap
 
 DEEP - 266
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000100
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\filter.zap
 
 DEEP - 267
 Location: HKEY_USERS\S-1-5-21-796845957-963894560-725345543-501\Software\Zone Labs\ZoneAlarm\plugin\obj\00000400
 Value   : path = C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
 Parsed  : C:\Program Files\Zone Labs\ZoneAlarm\alert.zap
 
 DEEP - 268
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Current
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 269
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Parental\.Default
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 270
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Current
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 271
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Privacy\.Default
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 272
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Current
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 273
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\McAfeePrivacyService\McAfeePrivacyService_Security\.Default
 Value   : (Default) = C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 Parsed  : C:\Program Files\McAfee\McAfee Privacy Service\SIREN.WAV
 
 DEEP - 274
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_ContactOnline\.Current
 Value   : (Default) = C:\Program Files\MSN Messenger\online.wav
 Parsed  : C:\Program Files\MSN Messenger\online.wav
 
 DEEP - 275
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewAlert\.Current
 Value   : (Default) = C:\Program Files\MSN Messenger\newalert.wav
 Parsed  : C:\Program Files\MSN Messenger\newalert.wav
 
 DEEP - 276
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMail\.Current
 Value   : (Default) = C:\Program Files\MSN Messenger\newemail.wav
 Parsed  : C:\Program Files\MSN Messenger\newemail.wav
 
 DEEP - 277
 Location: HKEY_CURRENT_USER\AppEvents\Schemes\Apps\MSNMSGR\MSNMSGR_NewMessage\.Current
 Value   : (Default) = C:\Program Files\MSN Messenger\type.wav
 Parsed  : C:\Program Files\MSN Messenger\type.wav
 
 DEEP - 278
 Location: HKEY_CURRENT_USER\EUDC\1252
 Value   : SystemDefaultEUDCFont = C:\WINDOWS\FONTS\EUDC.TTE
 Parsed  : C:\WINDOWS\FONTS\EUDC.TTE
 
 DEEP - 279
 Location: HKEY_CURRENT_USER\Software\Ahead\Nero - Burning Rom\Database
 Value   : UserDbPath = C:\Program Files\Ahead\nero\UsrDb
 Parsed  : C:\Program Files\Ahead\nero\UsrDb
 
 DEEP - 280
 Location: HKEY_CURRENT_USER\Software\Canon\ScanGear\7.0\Devices\CNQL30
 Value   : TempFolder = C:\Documents and Settings\keno cannady\Application Data\Canon
 Parsed  : C:\Documents and Settings\keno cannady\Application Data\Canon
 
 DEEP - 281
 Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
 Value   : InstallDir = C:\Program Files\CyberLink\PowerDVD
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 DEEP - 282
 Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
 Value   : InstallPath = C:\Program Files\CyberLink\PowerDVD
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 DEEP - 283
 Location: HKEY_CURRENT_USER\Software\Cyberlink\PowerDVD
 Value   : UISkinName = C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL
 Parsed  : C:\Program Files\CyberLink\PowerDVD\UI_Skin.DLL
 
 DEEP - 284
 Location: HKEY_CURRENT_USER\Software\DVD Shrink\DVD Shrink 3.2\Preferences
 Value   : TargetFolder = C:\INTERPRETER
 Parsed  : C:\INTERPRETER
 
 DEEP - 285
 Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
 Value   : File1 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\Untitled.bic
 Parsed  : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3
 
 DEEP - 286
 Location: HKEY_CURRENT_USER\Software\FIRAXIS\Civ3Edit\Recent File List
 Value   : File2 = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version\civ3mod.bic
 Parsed  : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3
 
 DEEP - 287
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\719B6D7D-2163-47F8-9C9F-5A9888
 Value   : FilePath = C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk
 Parsed  : C:\Documents and Settings\keno cannady\Start Menu\Programs\Startup\LimeWire On Startup.lnk
 
 DEEP - 288
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
 Value   : FilePath = c:\program files\istsvc\istsvc.exe
 Parsed  : c:\program files\istsvc\istsvc.exe
 
 DEEP - 289
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\9F3749B3-B089-4315-BF97-84F86B
 Value   : RegistryValue = C:\Program Files\ISTsvc\istsvc.exe
 Parsed  : C:\Program Files\ISTsvc\istsvc.exe
 
 DEEP - 290
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\CFBF341D-F22A-4775-AB40-7C2844
 Value   : DisplayDetails = Microsoft AntiSpyware has allowed the Internet Explorer Shell Browser MSN Toolbar Suite (msntb.dll) to be installed.||Name: MSN Toolbar Suite|File path: c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll
 Parsed  : c:\program files\msn toolbar suite\tb\02.00.0001.1203\en-us\msntb.dll
 
 DEEP - 291
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
 Value   : FilePath = c:\windows\farmmext.exe
 Parsed  : c:\windows\farmmext.exe
 
 DEEP - 292
 Location: HKEY_CURRENT_USER\Software\GIANTCompany\AntiSpyware\Alerts\E6CC22CA-C441-480A-AD2B-49BA13
 Value   : RegistryValue = C:\WINDOWS\farmmext.exe
 Parsed  : C:\WINDOWS\farmmext.exe
 
 DEEP - 293
 Location: HKEY_CURRENT_USER\Software\InterVideo\DVD5R
 Value   : CHANNEL_FILE = C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan
 Parsed  : C:\Documents and Settings\All Users\Application Data\InterVideo\Recorder\Recorder.chan
 
 DEEP - 294
 Location: HKEY_CURRENT_USER\Software\Macromedia\FlashPlayerUpdate
 Value   : Path = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\FlashPlayerUpdate.exe
 
 DEEP - 295
 Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\location\coreplayerxtras
 Value   : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
 Parsed  : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras
 
 DEEP - 296
 Location: HKEY_CURRENT_USER\Software\Macromedia\Shockwave 10\preffileloc
 Value   : (Default) = C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D\
 Parsed  : C:\Documents and Settings\keno cannady\Application Data\Macromedia\Shockwave Player\Prefs\7CPN7Q9D
 
 DEEP - 297
 Location: HKEY_CURRENT_USER\Software\McAfee.com\SpamKiller\Settings
 Value   : Install Dir = C:\PROGRA~1\mcafee\SPAMKI~1\
 Parsed  : C:\PROGRA~1\mcafee\SPAMKI~1
 
 DEEP - 298
 Location: HKEY_CURRENT_USER\Software\Microsoft\Keyboard\Native Media Players\QuickTime Player
 Value   : ExePath = C:\Program Files\Quick
 Parsed  : C:\Program Files\Quick
 
 DEEP - 299
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Preferences
 Value   : LastNotFoundDir = C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3\
 Parsed  : C:\Documents and Settings\keno cannady\My Documents\My Videos\RCT3
 
 DEEP - 300
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut0 = C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
 
 DEEP - 301
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\CreatedLinks
 Value   : Shortcut1 = C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 Parsed  : C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
 
 DEEP - 302
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
 Value   : 0 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb0.tmp
 
 DEEP - 303
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
 Value   : 1 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb1.tmp
 
 DEEP - 304
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
 Value   : 2 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb2.tmp
 
 DEEP - 305
 Location: HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Setup\FileMoveCache\Source
 Value   : 3 = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\setb3.tmp
 
 DEEP - 306
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
 Value   : FileName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\RSApp.edb
 
 DEEP - 307
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Databases\RSApp
 Value   : LogPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties\
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Properties
 
 DEEP - 308
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
 Value   : LogDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 
 DEEP - 309
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
 Value   : StreamLogsDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\GatherLogs
 
 DEEP - 310
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
 Value   : LogName = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Ntfy11.gthr
 
 DEEP - 311
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
 Value   : HistoryHashMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Hash.gthr
 
 DEEP - 312
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gather\RSApp\MyIndex
 Value   : DocIdMapFile = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex\MyIndex.Idm.gthr
 
 DEEP - 313
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager
 Value   : TempPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Temp\rssgthrsvc
 
 DEEP - 314
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Gathering Manager\Applications\RSApp\Projects\MyIndex
 Value   : WorkingDirectory = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 
 DEEP - 315
 Location: HKEY_CURRENT_USER\Software\Microsoft\MSN Apps\DS\RSSearchBackup\Indexer\RSApp\MyIndex
 Value   : ProjectPath = C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 Parsed  : C:\Documents and Settings\keno cannady\Local Settings\Application Data\Microsoft\Desktop Search\Applications\RSApp\Projects\MyIndex
 
 DEEP - 316
 Location: HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache
 Value   : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\is-M7D7L.tmp\is-4A07N.tmp
 
 DEEP - 317
 Location: HKEY_CURRENT_USER\Software\Microsoft\Works Suite
 Value   : C:\Program Files\Microsoft Money\System\msmoney.exe = C:\Program Files\Microsoft Money\System\msmoney.exe
 Parsed  : C:\Program Files\Microsoft Money\System\msmoney.exe
 
 DEEP - 318
 Location: HKEY_CURRENT_USER\Software\ScanSoft\OmniPagePro11.0\Scanner\ScanSoft API\PlugIn\1.0\Components\5
 Value   : InProcSrv = C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp
 Parsed  : C:\Program Files\ScanSoft\OmniPageSE\XSCAN32.psp
 
 DEEP - 319
 Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
 Value   : location = C:\Program Files\Take2 Interactive\Mall Tycoon
 Parsed  : C:\Program Files\Take2 Interactive\Mall Tycoon
 
 DEEP - 320
 Location: HKEY_CURRENT_USER\Software\Take2 Interactive\Mall Tycoon
 Value   : cdrom = C:\Documents and Settings\keno cannady\Shared\PC GAMES - Mall Tycoon\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\PC GAMES
 
 DEEP - 321
 Location: HKEY_CURRENT_USER\Software\Toolbar Genie Online\My Toolbar\Historyfiles
 Value   : C:\PROGRA~1\KoolBar\toolbar.xml = C:\PROGRA~1\KoolBar\toolbar.xml
 Parsed  : C:\PROGRA~1\KoolBar\toolbar.xml
 
 DEEP - 322
 Location: HKEY_CURRENT_USER\Software\Valve\Half-Life\Player Profiles\Player
 Value   : Archive = C:\Documents and Settings\keno cannady\Shared\Games - Half Life(2)\ProfileData\Player.dat
 Parsed  : C:\Documents and Settings\keno cannady\Shared\Games
 
 DEEP - 323
 Location: HKEY_CURRENT_USER\Software\VFPlugin
 Value   : DVD2AVI = C:\Program Files\GordianKnot\DVD2AVI.vfp
 Parsed  : C:\Program Files\GordianKnot\DVD2AVI.vfp
 
 DEEP - 324
 Location: HKEY_CURRENT_USER\Software\Yahoo\YServer
 Value   : HomeDir = C:\PROGRA~1\Yahoo!\MESSEN~1\data
 Parsed  : C:\PROGRA~1\Yahoo!\MESSEN~1\data
 
 DEEP - 325
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Ahead\shared
 Value   : OutputPath = C:\Program Files\Ahead\MyMusic
 Parsed  : C:\Program Files\Ahead\MyMusic
 
 DEEP - 326
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\JavaVM\MSJavaVM\InstallInfo
 Value   : VerifyFile = C:\WINDOWS\system32\msjava.dll
 Parsed  : C:\WINDOWS\system32\msjava.dll
 
 DEEP - 327
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\News\Microsoft Outlook
 Value   : DLLPath = C:\Program Files\Outlook ExpressMSIMNUI.DLL
 Parsed  : C:\Program Files\Outlook ExpressMSIMNUI.DLL
 
 DEEP - 328
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
 Value   : InstallDir = C:\Program Files\CyberLink\PowerDVD
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 DEEP - 329
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\CyberLink\PowerDVD
 Value   : InstallPath = C:\Program Files\CyberLink\PowerDVD
 Parsed  : C:\Program Files\CyberLink\PowerDVD
 
 DEEP - 330
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\EA GAMES\Harry Potter
 Value   : Install Dir = C:\Documents and Settings\keno cannady\Shared\Games - Harry Potter Full PC Game
 Parsed  : C:\Documents and Settings\keno cannady\Shared\Games
 
 DEEP - 331
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
 Value   : Path = C:\Program Files\Rollercoaster Tycoon
 Parsed  : C:\Program Files\Rollercoaster Tycoon
 
 DEEP - 332
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Fish Technology Group\RollerCoaster Tycoon Setup
 Value   : SetupPath = C:\Program Files\Rollercoaster Tycoon\
 Parsed  : C:\Program Files\Rollercoaster Tycoon
 
 DEEP - 333
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\GIANTCompany\AntiSpyware\CleanerExe\DelFiles
 Value   : c:\windows\system32\sfndcmsg.dll = c:\windows\system32\sfndcmsg.dll
 Parsed  : c:\windows\system32\sfndcmsg.dll
 
 DEEP - 334
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\GordianKnot
 Value   : InstallDir = C:\Program Files\GordianKnot
 Parsed  : C:\Program Files\GordianKnot
 
 DEEP - 335
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Grisoft\Clients\{3C9EFEC2-8D1A-11D5-989F-0000E87B4FB1}
 Value   : Config = C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll
 Parsed  : C:\PROGRA~1\Grisoft\AVG7\avgemsui.dll
 
 DEEP - 336
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\HipSoft\Trivia Machine
 Value   : InstallPath = C:\Program Files\Yahoo! Games\Trivia Machine
 Parsed  : C:\Program Files\Yahoo! Games\Trivia Machine
 
 DEEP - 337
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
 Value   : Install_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
 Parsed  : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3
 
 DEEP - 338
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
 Value   : Uninstall_Path = C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe
 Parsed  : C:\Program Files\InstallShield Installation Information\{0AD84416-63A4-4CF3-BDDF-8FA866711FB0}\Setup.exe
 
 DEEP - 339
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Civilization III
 Value   : CD_Path = C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3 - Working Full Version
 Parsed  : C:\Documents and Settings\keno cannady\Shared\PC Games - Civilization 3
 
 DEEP - 340
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Infogrames Interactive\Monopoly Tycoon
 Value   : PATH = C:\Documents and Settings\keno cannady\Shared\Game - Monopoly Tycoon (1)\Monopoly Tycoon
 Parsed  : C:\Documents and Settings\keno cannady\Shared\Game
 
 DEEP - 341
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\iWin\FamilyFeud
 Value   : InstallDir = C:\Program Files\iWin.com Games\Family Feud
 Parsed  : C:\Program Files\iWin.com Games\Family Feud
 
 DEEP - 342
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\Shockwave 10\location\coreplayerxtras
 Value   : (Default) = C:\WINDOWS\system32\Macromed\Shockwave 10\xtras\
 Parsed  : C:\WINDOWS\system32\Macromed\Shockwave 10\xtras
 
 DEEP - 343
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
 Value   : BrowserUpdateSched = C:\WINDOWS\system32\lwinrrag.exe CORN001
 Parsed  : C:\WINDOWS\system32\lwinrrag.exe
 
 DEEP - 344
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Disabled
 Value   : q8lg = "C:\WINDOWS\system32\slk8x2peu.exe"
 Parsed  : C:\WINDOWS\system32\slk8x2peu.exe
 
 DEEP - 345
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog047 = Exclude C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf from installation
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\unicows_cab\unicows.inf
 
 DEEP - 346
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\psapi_cab\psapi.inf
 
 DEEP - 347
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mas_cab\mas.inf
 
 DEEP - 348
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\mascfg_cab\mascfg.inf
 
 DEEP - 349
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog054 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masqlt_cab\masqlt.inf
 
 DEEP - 350
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog055 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\vmap_cab\vmap.inf
 
 DEEP - 351
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog056 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\maseng_cab\maseng.inf
 
 DEEP - 352
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog057 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masvscor_cab\masvscor.inf
 
 DEEP - 353
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog058 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masupd_cab\masupd.inf
 
 DEEP - 354
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog059 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masdat_cab\masdat.inf
 
 DEEP - 355
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog060 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\regwiz_cab\regwiz.inf
 
 DEEP - 356
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog061 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp\tempinst\masreg_cab\masreg.inf
 
 DEEP - 357
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog099 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result
 
 DEEP - 358
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\McAfee AntiSpyware\Installer
 Value   : MASLog101 = FinalizeMAsInstall: Removing Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result: 2
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA11.tmp$$Result
 
 DEEP - 359
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
 Value   : QclDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAC8.tmp
 
 DEEP - 360
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\QuickClean\Installer
 Value   : QclLog002 = FinalizeQCLInstall: Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA7.tmp$$Result
 
 DEEP - 361
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#022 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: Adding senddata handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list
 Parsed  : c:\program files\mcafee.com\agent\mcscentr.adf to the list
 
 DEEP - 362
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#023 = 4/24/2006 2:50:34 PM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
 Parsed  : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
 
 DEEP - 363
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#025 = 4/24/2006 2:50:37 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\app\mas.adf)
 
 DEEP - 364
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#026 = 4/24/2006 2:50:39 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\app\vso.adf)
 
 DEEP - 365
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#027 = 4/24/2006 2:50:40 PM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\mcscentr.adf)
 
 DEEP - 366
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#059 = 4/24/2006 10:45:05 AM - CHandler::CreateHandlersWithPriority: NOT Adding update handler of c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
 Parsed  : c:\program files\mcafee.com\agent\mcscentr.adf to the list because the desired priority does not match
 
 DEEP - 367
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#061 = 4/24/2006 10:45:09 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\mas.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\app\mas.adf)
 
 DEEP - 368
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#062 = 4/24/2006 10:45:12 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\app\vso.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\app\vso.adf)
 
 DEEP - 369
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Agent\Update\ResultLog
 Value   : Log#063 = 4/24/2006 10:45:14 AM - Priority: ASYNCHRONOUS; HandlerName: SendData (c:\program files\mcafee.com\agent\mcscentr.adf); ResultCode: 8 (DATA_SENT)
 Parsed  : c:\program files\mcafee.com\agent\mcscentr.adf)
 
 DEEP - 370
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
 Value   : Log#115 = 3/21/2006 10:06:21 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_24, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\MasVer.Ini
 
 DEEP - 371
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
 Value   : Log#123 = 3/21/2006 10:06:23 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mys_1, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\AgentVer.ini
 
 DEEP - 372
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
 Value   : Log#135 = 3/21/2006 10:06:27 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:mas_0, LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas\mas\gdeltapup.ini
 
 DEEP - 373
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\GDLog\UPD_mas
 Value   : Log#141 = 3/21/2006 10:06:28 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\UPD_mas
 
 DEEP - 374
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
 Value   : Log#043 = 3/21/2006 10:11:19 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1\AgentVer.ini
 
 DEEP - 375
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_AgentCabs
 Value   : Log#109 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~1
 
 DEEP - 376
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
 Value   : Log#017 = 3/21/2006 10:11:49 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Ini File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\QclVer.Ini
 
 DEEP - 377
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
 Value   : Log#025 = 3/21/2006 10:11:51 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 
 DEEP - 378
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
 Value   : Log#044 = 4/10/2006 12:20:30 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 
 DEEP - 379
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
 Value   : Log#065 = 4/10/2006 12:20:57 AM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Application Setup..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2\quickcleanh\QuickCleanSetup.exe
 
 DEEP - 380
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_QCL\GDLog\QCL_INSTALL_QCLCabs
 Value   : Log#071 = 4/10/2006 12:21:45 AM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\QCL_IN~2
 
 DEEP - 381
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
 Value   : Log#108 = 4/23/2006 12:16:58 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1\AgentVer.ini
 
 DEEP - 382
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_AgentCabs
 Value   : Log#122 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~1
 
 DEEP - 383
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoCabs
 Value   : Log#077 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~2
 
 DEEP - 384
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
 Value   : Log#021 = 4/23/2006 12:16:55 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Constants File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\VsoVer.ini
 
 DEEP - 385
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
 Value   : Log#025 = 4/23/2006 12:16:56 PM - CDwnldGroup::Download: DOWNLOAD_FILE_BEGIN:Downloading Virus Change File..., LocalPath:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3\vso\mcdelta.ini
 
 DEEP - 386
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Download\Inst_Vso\GDLog\VSO_INSTALL_VsoDatCabs
 Value   : Log#031 = 4/23/2006 12:17:31 PM - CDwnldGroup::GetDownloadLocation: Download location:C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com\download\VSO_IN~3
 
 DEEP - 387
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog029 = Backup mpf data file : \data\pcfg.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\pcfg.ent
 
 DEEP - 388
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog030 = Backup mpf data file : \data\rdns.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\rdns.idx
 
 DEEP - 389
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog031 = Backup mpf data file : \data\hwid.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\hwid.idx
 
 DEEP - 390
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog032 = Backup mpf data file : \data\banned.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\banned.idx
 
 DEEP - 391
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog033 = Backup mpf data file : \data\golden.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\golden.idx
 
 DEEP - 392
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog034 = Backup mpf data file : \data\sports.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.idx
 
 DEEP - 393
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog035 = Backup mpf data file : \data\sports.ent To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\sports.ent
 
 DEEP - 394
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog036 = Backup mpf data file : \data\winloc.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\winloc.idx
 
 DEEP - 395
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog037 = Backup mpf data file : \data\certi.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\certi.idx
 
 DEEP - 396
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog038 = Backup mpf data file : \data\options.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\options.idx
 
 DEEP - 397
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog039 = Backup mpf data file : \data\log.edb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.edb
 
 DEEP - 398
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog040 = Backup mpf data file : \data\log.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\log.idx
 
 DEEP - 399
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog041 = Backup mpf data file : \data\IpRules.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\IpRules.xdb
 
 DEEP - 400
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog042 = Backup mpf data file : \data\TrafficHist.xdb To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\TrafficHist.xdb
 
 DEEP - 401
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog043 = Backup mpf data file : \data\RIR.idx To C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata\RIR.idx
 
 DEEP - 402
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog047 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfcfg_cab\mpfcfg.inf
 
 DEEP - 403
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog048 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpftray_cab\mpftray.inf
 
 DEEP - 404
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog049 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfmain_cab\mpfmain.inf
 
 DEEP - 405
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog050 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpf_cab\mpf.inf
 
 DEEP - 406
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog051 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfadf_cab\mpfadf.inf
 
 DEEP - 407
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog052 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\regwiz_cab\regwiz.inf
 
 DEEP - 408
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog053 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp\tempinst\mpfreg_cab\mpfreg.inf
 
 DEEP - 409
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog071 = Removing temp mpf data folder : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\mpfdata
 
 DEEP - 410
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog099 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result
 
 DEEP - 411
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Personal Firewall\Installer
 Value   : MpfLog101 = Removing$$Extract Folder: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result: 2
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCAB1.tmp$$Result
 
 DEEP - 412
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
 Value   : RegWizLog#001 = c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration
 Parsed  : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini found for registration
 
 DEEP - 413
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\RegWiz\Installer
 Value   : RegWizLog#003 = Application already registered. Deleting file : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini
 Parsed  : c:\docume~1\alluse~1\applic~1\mcafee.com\agent\regwiz\regapp\vso.ini
 
 DEEP - 414
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
 Value   : ShredderDownloadPath = C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\SHR_6_~1.TMP
 
 DEEP - 415
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
 Value   : ShredderLog005 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlbin_cab\cntrlbin.inf
 
 DEEP - 416
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
 Value   : ShredderLog006 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\cntrlres_cab\cntrlres.inf
 
 DEEP - 417
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
 Value   : ShredderLog007 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredcfg_cab\shredcfg.inf
 
 DEEP - 418
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\McAfee.com\Shredder\Installer
 Value   : ShredderLog008 = Install: C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf$$ Result: 0
 Parsed  : C:\DOCUME~1\KENOCA~1\LOCALS~1\Temp\MCA69.tmp\tempinst\shredbin_cab\shredbin.inf
 
 DEEP - 419
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup
 Value   : JITSetupPage = file://C:\WINDOWS\web\iejit.htm
 Parsed  : C:\WINDOWS\web\iejit.htm
 
 DEEP - 420
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\b107806c-d088-4344-98b4-4839c7767af9
 Value   : StubPath = C:\WINDOWS\System32\hqhzxz.exe
 Parsed  : C:\WINDOWS\System32\hqhzxz.exe
 
 DEEP - 421
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
 Value   : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 422
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II
 Value   : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 423
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
 Value   : Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 424
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectPlay\Applications\Age of Empires II - The Conquerors Expansion
 Value   : CurrentDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 425
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions
 Value   : Remote Exchange Extensions = 4.0;C:\WINDOWS\System32\emsui32.dll;6;111;111;MSEMS
 Parsed  : C:\WINDOWS\System32\emsui32.dll
 
 DEEP - 426
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Default HTML Editor\shell\edit\command
 Value   : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 Parsed  : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 
 DEEP - 427
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer
 Value   : MetadataTemplatesDir = C:\Program Files\Windows Media Player\Templates
 Parsed  : C:\Program Files\Windows Media Player\Templates
 
 DEEP - 428
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
 Value   : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 429
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
 Value   : InstallationDirectory = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 430
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires\2.0
 Value   : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 431
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
 Value   : EXE Path = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 432
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft Games\Age of Empires II: The Conquerors Expansion\1.0
 Value   : CDPath = C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game - no cd crack\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\age of empires 2 - full game
 
 DEEP - 433
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\MPlayer2\Groups\Video\DVR-MS
 Value   : RequiredFile = C:\WINDOWS\system32\enable.dvd
 Parsed  : C:\WINDOWS\system32\enable.dvd
 
 DEEP - 434
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD
 Value   : RequiredFile = C:\WINDOWS\system32\enable.dvd
 Parsed  : C:\WINDOWS\system32\enable.dvd
 
 DEEP - 435
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS
 Value   : RequiredFile = C:\WINDOWS\system32\enable.dvd
 Parsed  : C:\WINDOWS\system32\enable.dvd
 
 DEEP - 436
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Default Editor\shell\Edit\command
 Value   : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 Parsed  : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 
 DEEP - 437
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared\HTML\Old Default Editor\shell\Edit\command
 Value   : (Default) = C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 Parsed  : C:\PROGRA~1\MI1933~1\Office\FRONTPG.EXE
 
 DEEP - 438
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0000
 Value   : ProviderLogo = C:\WINDOWS\System32\tunes.bmp
 Parsed  : C:\WINDOWS\System32\tunes.bmp
 
 DEEP - 439
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\DeluxeCD\Providers\Provider0001
 Value   : ProviderLogo = C:\WINDOWS\System32\n2k.bmp
 Parsed  : C:\WINDOWS\System32\n2k.bmp
 
 DEEP - 440
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\Paint Shop Pro 9ShowPicturesOnArrivalHandler
 Value   : DefaultIcon = C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE,0
 Parsed  : C:\PROGRA~1\JASCSO~1\PAINTS~1\PAINTS~1.EXE
 
 DEEP - 441
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\PDVDPlayDVDMovieOnArrival
 Value   : DefaultIcon = C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe,0
 Parsed  : C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe
 
 DEEP - 442
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\Avg7Find\0\DefaultIcon
 Value   : (Default) = C:\Program Files\Grisoft\AVG7\avgse.dll,0
 Parsed  : C:\Program Files\Grisoft\AVG7\avgse.dll
 
 DEEP - 443
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\BACKGROUNDIMAGE
 Value   : (Default) = C:\WINDOWS\Web\wvleft.bmp
 Parsed  : C:\WINDOWS\Web\wvleft.bmp
 
 DEEP - 444
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\LOGOLINE
 Value   : (Default) = C:\WINDOWS\Web\wvline.gif
 Parsed  : C:\WINDOWS\Web\wvline.gif
 
 DEEP - 445
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\00FF41F8FA41BC84091B4C07CABDF9E3
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 446
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0152806F405208847813DD8BED99D629
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ALEUpdat.exe
 
 DEEP - 447
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\024EC3F90C2DE7C4FB1FFB4F5F332623
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWiz.exe
 Parsed  : C:\Program Files\Norton AntiVirus\CfgWiz.exe
 
 DEEP - 448
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0322C474330FE1744AF900BCC66F5833
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\niscmnht.dll
 
 DEEP - 449
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03A9FC3E3E95C0740A521901F8767CB1
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 450
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0411415FD32B9B946A61D0C303BD27AD
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\TLevel.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\TLevel.dll
 
 DEEP - 451
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\044E7B0C1B06EC14E92B7D5969253EC2
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccALE.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ccALE.dll
 
 DEEP - 452
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04B22DD6AA9C23646A3C3F467E57860C
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Portal\
 Parsed  : C:\Program Files\Norton AntiVirus\Quarantine\Portal
 
 DEEP - 453
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05396EEFA666F7742A096C3DF3072D54
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwcmdNT.dll
 Parsed  : C:\Program Files\Norton AntiVirus\apwcmdNT.dll
 
 DEEP - 454
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\071A0387AE84BCF43AB238E53AB547C0
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Norton AntiVirus\ScriptUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\ScriptUI.dll
 
 DEEP - 455
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client
 
 DEEP - 456
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client
 
 DEEP - 457
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075603C1A0A349649BF01150129CC6A5
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec\Common Client
 
 DEEP - 458
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07B3E601E527C0949954E5851542466B
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 459
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07CEB7E467263F443B6E612F4B98D7F8
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 460
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\099321B84C2C2BB41851CA389FB70165
 Value   : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.spm
 
 DEEP - 461
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0AA8DBE6FFF98184CB16089724A103B2
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOptRF.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVOptRF.dll
 
 DEEP - 462
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C8F566CEA001F943A1DEEF074599FDF
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SMNLnch.exe
 
 DEEP - 463
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
 Value   : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Validate.dat
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Validate.dat
 
 DEEP - 464
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0DC310B120C02754683F563C5C11B7CC
 Value   : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Validate.dat
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Validate.dat
 
 DEEP - 465
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1060C7258FD43414295BB92A86DFD912
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Quarantine\Incoming\
 Parsed  : C:\Program Files\Norton AntiVirus\Quarantine\Incoming
 
 DEEP - 466
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10B257D254F25D11EA9F00054081F409
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32integ.dll
 Parsed  : C:\Program Files\Norton AntiVirus\S32integ.dll
 
 DEEP - 467
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10FC05BCE9FD5984389C446876524F82
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVCfgWz.dll
 
 DEEP - 468
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\16426ABC13D89D245B93A02C0DC9C224
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
 
 DEEP - 469
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\17AE107A723326C46A2C93522D3F59F8
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 470
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18CC08AD0DA03A34DAB29E0514DC04D1
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVShExt.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVShExt.dll
 
 DEEP - 471
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A3CD7C9A0AAA554DAAC220641E0D17E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navprod.dll
 Parsed  : C:\Program Files\Norton AntiVirus\navprod.dll
 
 DEEP - 472
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D666097B6EC4A44E844F041AC395953
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ALECmpBR.dll
 
 DEEP - 473
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F0DFF6444337B64A9497B276826DB8E
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 474
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20383D4B10B0E3346A8BD698FE0B295D
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\IWPLog.dll
 
 DEEP - 475
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\22BF77BEE865A83449FBD70DE99B5F7A
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NetBrExt.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\NetBrExt.DLL
 
 DEEP - 476
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2575DB0D1CB48604491FD73C89519EC8
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWP.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\IWP.dll
 
 DEEP - 477
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\262DD75104DBB3B498A0AA44A2F88A19
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\probeGSE.dll
 Parsed  : C:\Program Files\Norton AntiVirus\probeGSE.dll
 
 DEEP - 478
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2725A89474CB12C44BB65170875EBA48
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPW32.exe
 Parsed  : C:\Program Files\Norton AntiVirus\NAVAPW32.exe
 
 DEEP - 479
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\291736580EC2EED4397DA98BEF610A20
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\HNetCore.dll
 
 DEEP - 480
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2BCD27044B81E3D4EBD766BC953C323E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\savrt.sys
 Parsed  : C:\Program Files\Norton AntiVirus\savrt.sys
 
 DEEP - 481
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D40DF4A1B79BC94B8BB811C21CDB9F3
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\ActRes.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\ActRes.DLL
 
 DEEP - 482
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E0E3AC586E450848BDFF8BDAA3AF964
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus
 
 DEEP - 483
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccInst.dll
 
 DEEP - 484
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccInst.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccInst.dll
 
 DEEP - 485
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\39A23B5C4F5C6654693A6634C7824847
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\README.TXT
 Parsed  : C:\Program Files\Norton AntiVirus\README.TXT
 
 DEEP - 486
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A8C3EA18ADB24E4C8E1875EC8F06375
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrTrust.dll
 
 DEEP - 487
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B288C03487C8374F965BB84C5E356C2
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 488
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B2D8CCBDF636154CA11562FA1985814
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FRERules.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\FRERules.dll
 
 DEEP - 489
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C9A2AED576F5544193A0C5A8DC65BE7
 Value   : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.sig
 
 DEEP - 490
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
 
 DEEP - 491
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Text.dll
 
 DEEP - 492
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E63A1A0FC3E1F24BB302AC419D4841C
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\LRSend.exe
 Parsed  : C:\Program Files\Norton AntiVirus\LRSend.exe
 
 DEEP - 493
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
 
 DEEP - 494
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccVrTrst.dll
 
 DEEP - 495
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3EC45CFDA09D6744B8D8C04431ED1964
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AVRES.dll
 Parsed  : C:\Program Files\Norton AntiVirus\AVRES.dll
 
 DEEP - 496
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42D544166A9040246AE61A6BD1E89875
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 497
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43BE7E834BB89F74EA8045BE46CCB3F5
 Value   : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPManifests\Snd.grd
 
 DEEP - 498
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\441567AAA28618C46A8BACAAC9BD2047
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ecmldr32.DLL
 
 DEEP - 499
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\443CD4F6572D500468FFF934363232A4
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\IWPLUCbk.dll
 
 DEEP - 500
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4542E17C204027C4A9DB81B657767BE8
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREAles.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\FREAles.dll
 
 DEEP - 501
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\471F6E8954126A04AAA3FE5AA79243D3
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\Ales.xml
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\Ales.xml
 
 DEEP - 502
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4799D30A4DDA954429D8D4ED011517F9
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrAuth.dll
 
 DEEP - 503
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47E0174F57CC8504DA862CA99CBAEA31
 Value   : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SymUIAx2.ocx
 
 DEEP - 504
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48982BA41E042FE4893568B326EAE47E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DefAlert.dll
 Parsed  : C:\Program Files\Norton AntiVirus\DefAlert.dll
 
 DEEP - 505
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48F14AD033FE3EB4A87CDCEDC2AAE23B
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 506
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49769A67806F0484C968C8A5358B1098
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 507
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4AC03AFAAEE94804C8614EFF36AFC5A1
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SYMNAVO.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\SYMNAVO.DLL
 
 DEEP - 508
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 509
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 510
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CB829E5237898741983A2C0FB59BAEF
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 511
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CBC83BFDE475DB418A2AE96BCFDE865
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\avcompbr.dll
 Parsed  : C:\Program Files\Norton AntiVirus\avcompbr.dll
 
 DEEP - 512
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50A419CA949024647B7A0E569BA7918C
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVComUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVComUI.dll
 
 DEEP - 513
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
 
 DEEP - 514
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TNEF.dll
 
 DEEP - 515
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
 
 DEEP - 516
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\DefUtDCD.dll
 
 DEEP - 517
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
 
 DEEP - 518
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RTF.dll
 
 DEEP - 519
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5214FA3088B8BAD419A265B6153E97C0
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\VirusDefs
 
 DEEP - 520
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53EC7F36FB9D406418715FDA8AC5C485
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32call.dll
 Parsed  : C:\Program Files\Norton AntiVirus\N32call.dll
 
 DEEP - 521
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\595EDF0A76C2DF14DA38D14496F0422F
 Value   : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
 Parsed  : C:\Program Files\Common Files\Symantec Shared\CfgWiz.tlb
 
 DEEP - 522
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F14878ED4CBD6B4995778B62914DE82
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ScanMgr.dll
 Parsed  : C:\Program Files\Norton AntiVirus\ScanMgr.dll
 
 DEEP - 523
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5F711C7C816E497409B42799F858A73B
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 524
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\615168D24A7AD1745A12D7DBE603484A
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qspak32.dll
 Parsed  : C:\Program Files\Norton AntiVirus\qspak32.dll
 
 DEEP - 525
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6175647594900AC4AB89DA41EC22BDCA
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymLCUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\SymLCUI.dll
 
 DEEP - 526
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\663818B8178761A498A24322153E6C55
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\scancfg.dat
 Parsed  : C:\Program Files\Norton AntiVirus\scancfg.dat
 
 DEEP - 527
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\668C52B058E567C4A9461F74298A7B16
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navui.nsi
 Parsed  : C:\Program Files\Norton AntiVirus\navui.nsi
 
 DEEP - 528
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6714C945179DA67419B483C6A8082757
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 529
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\681293A7B6EE4994588C3F608CE24AE7
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 530
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6906F858261DD5142981FFF252CECF0C
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\apwutil.dll
 Parsed  : C:\Program Files\Norton AntiVirus\apwutil.dll
 
 DEEP - 531
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
 
 DEEP - 532
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2TAR.dll
 
 DEEP - 533
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A41CC073B92EE847B8FFCE9495410A9
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 534
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B0AE912F7ED2224CBB5D6B506795029
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVEvent.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVEvent.dll
 
 DEEP - 535
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C903CD2A490B0C4B817B5822363D670
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navwnt.exe
 Parsed  : C:\Program Files\Norton AntiVirus\Navwnt.exe
 
 DEEP - 536
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E567B288C21FE748928C2F767434E49
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 537
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
 
 DEEP - 538
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LZ.dll
 
 DEEP - 539
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F197F7372EA24349AC09AC49ABA402E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVAPSCR.dll
 
 DEEP - 540
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F8308D658EBA7E48AC20C2C1C53D51F
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLogV.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVLogV.dll
 
 DEEP - 541
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7029927AC4655CF4CA5476C0F7A0844A
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVOpts.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVOpts.dll
 
 DEEP - 542
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\717AB62A0DC6B434EA08A1A45AC41341
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccDec.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccDec.dll
 
 DEEP - 543
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\744510B0F96EA7346945429C47B772AB
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconsole.exe
 Parsed  : C:\Program Files\Norton AntiVirus\qconsole.exe
 
 DEEP - 544
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7469F3930A15C804EBC767838BD0E200
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\IDSDefs\
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\IDSDefs
 
 DEEP - 545
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74B65AE67660E0649AB135AA083E16D6
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScan.dll
 Parsed  : C:\Program Files\Norton AntiVirus\ccIMScan.dll
 
 DEEP - 546
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\758CEDE445E075242A1B28C209469190
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 547
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B50EBD049034D245BACB7DF3D3F0055
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 548
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B555CBEE5D5DC34DA22C85A114E44D6
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ccRuleIO.dll
 
 DEEP - 549
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccL30.dll
 
 DEEP - 550
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\ccL30.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccL30.dll
 
 DEEP - 551
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8009C7720B95C304C81241A8EC4D39D6
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccLogin.dll
 
 DEEP - 552
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81CE673053E252642B9EB19881D11525
 Value   : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 553
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82EF65EE71A8DFE46BF3103894868C74
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTasks.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVTasks.dll
 
 DEEP - 554
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83056920BAAA6E64A9DD0F72BB1F8568
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\S32NAVO.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\S32NAVO.DLL
 
 DEEP - 555
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8350CADA40F1245418AE0898B5F2CC8F
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat
 Parsed  : C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat
 
 DEEP - 556
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\846574CE2AA8B9C40AD64866F9DE77A7
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
 
 DEEP - 557
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\849F6BDFC1324574389DDBD802611B2D
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\ccGSE.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccGSE.dll
 
 DEEP - 558
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85A6640347184DE419174A7D938EE4A3
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 
 DEEP - 559
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B245E22A8EFDF94EBC89D75F9CB11EC
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVStub.exe
 Parsed  : C:\Program Files\Norton AntiVirus\NAVStub.exe
 
 DEEP - 560
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B45BF4DC2F0A1B4B9327CFFF2806334
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SavRT32.dll
 Parsed  : C:\Program Files\Norton AntiVirus\SavRT32.dll
 
 DEEP - 561
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B508B6DAB8B7964E8AD0D371CF29B5C
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\DJSAlert.dll
 Parsed  : C:\Program Files\Norton AntiVirus\DJSAlert.dll
 
 DEEP - 562
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CC0AB79D89CB4549B29F8FA2785D777
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SAVScan.exe
 Parsed  : C:\Program Files\Norton AntiVirus\SAVScan.exe
 
 DEEP - 563
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8E63A159A784DEF41BB6209B779E6D45
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 564
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8EF9EE1FC66940B468785FE27846A4B5
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 565
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
 
 DEEP - 566
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2Zip.dll
 
 DEEP - 567
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\932EEA56C5A47C8499E284F46ACC2016
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus\
 Parsed  : C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus
 
 DEEP - 568
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
 
 DEEP - 569
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\953E4C7EF5A3315458FC82A7BD02EE98
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\SPBBC\SPLVPlug.dll
 
 DEEP - 570
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9542A2F29521AEA49825DACE47ECB069
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\qconres.dll
 Parsed  : C:\Program Files\Norton AntiVirus\qconres.dll
 
 DEEP - 571
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
 
 DEEP - 572
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2RAR.dll
 
 DEEP - 573
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9650EFDF332FF2741B72B1F1F2CA1DA7
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUIHTM.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVUIHTM.dll
 
 DEEP - 574
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A31A16C69A2D4F40B30BC92212E9182
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ccFWSetg.dll
 
 DEEP - 575
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D20C7BA42CFF7A43BF7BB1BD173829F
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 576
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A0BBBFBB9DF126841A599E50CF74E420
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 577
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3CEBDA9EBF8DEA4FBE368F050BEE9B5
 Value   : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 578
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A53030D1FA7CD0C42A0CE951CD8D70B6
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navap32.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Navap32.dll
 
 DEEP - 579
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6AFA04EFD73D69418C4062C5576D74F
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 580
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
 
 DEEP - 581
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2AMG.dll
 
 DEEP - 582
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5473481968D2C449595600631BF60F
 Value   : 9399EE5EF9522ED40832C5941EA6F434 = C:\Program Files\Norton AntiVirus\AVSTE.dll
 Parsed  : C:\Program Files\Norton AntiVirus\AVSTE.dll
 
 DEEP - 583
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB41244462F87CA4B9F2050D4AF13DE0
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLUCBK.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVLUCBK.dll
 
 DEEP - 584
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC715C67C18D0E14986117D61115B5D9
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapw32.dll
 Parsed  : C:\Program Files\Norton AntiVirus\navapw32.dll
 
 DEEP - 585
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD0898EB938AF6148ACBF7D389DE3E3D
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Statushp.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Statushp.dll
 
 DEEP - 586
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE218B3D3A784674FA9D4ED959E3F941
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 587
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
 
 DEEP - 588
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\DecSDK.dll
 
 DEEP - 589
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B00431804170C134B939ED6830DA1C39
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSOK32I.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\SDSOK32I.DLL
 
 DEEP - 590
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B16AC77B767B76344ADD68B231863B6A
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\FREInteg.dll
 
 DEEP - 591
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B305EF16382BB1E43B550C61C5E6C983
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVSTATS.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVSTATS.dll
 
 DEEP - 592
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3131345148ADC043AA743CF15C58161
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandlvr.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Scandlvr.dll
 
 DEEP - 593
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 594
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 595
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3F6A2DB538BA6E44B9404005AFB41E2
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 596
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4AA92F71A4DC8843B921505A7EE1982
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVError.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVError.dll
 
 DEEP - 597
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B95F812E3128A514B869E6BFEE1FEDF3
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\COUNTRY.DAT
 Parsed  : C:\Program Files\Norton AntiVirus\COUNTRY.DAT
 
 DEEP - 598
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
 
 DEEP - 599
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2CAB.dll
 
 DEEP - 600
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBAE3AAB8D0042547990AF991553C16B
 Value   : 9CFA723DAAB7A3743891E67B0A4D1083 = C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Script Blocking\ScrBlock.dll
 
 DEEP - 601
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD04BAF963B867144BE7910CADB91EC8
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVUI.dll
 
 DEEP - 602
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BDEA5D3B2A1FFDC44B55F08AD7801175
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OPScan.exe
 Parsed  : C:\Program Files\Norton AntiVirus\OPScan.exe
 
 DEEP - 603
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
 
 DEEP - 604
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2LHA.dll
 
 DEEP - 605
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEB4972A12860764BB195C6D768E12A1
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 606
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF34ED1C895652B4D92C1D66CE00BF98
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\fwUI.dll
 
 DEEP - 607
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
 
 DEEP - 608
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2SS.dll
 
 DEEP - 609
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
 
 DEEP - 610
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ARJ.dll
 
 DEEP - 611
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C30AE6C259C7B424E914F0A0C4C244BA
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\N32Exclu.dll
 Parsed  : C:\Program Files\Norton AntiVirus\N32Exclu.dll
 
 DEEP - 612
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C33570307F55DB54396FFFF444D96E0B
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navapsvc.exe
 Parsed  : C:\Program Files\Norton AntiVirus\navapsvc.exe
 
 DEEP - 613
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3BD2CD6023CED14080DED74FA48DDCA
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
 Parsed  : C:\Program Files\Common Files\Symantec Shared\CCPD-LC
 
 DEEP - 614
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C519BC4820133E149AC900B6B2F708CA
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\CfgWzRes.dll
 Parsed  : C:\Program Files\Norton AntiVirus\CfgWzRes.dll
 
 DEEP - 615
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7C4F0E638DD18A46B7A39824E3A6EE8
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\SymFwAgt.DLL
 
 DEEP - 616
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C8C9E5A275AC91441BD5E7569AAFEDDC
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Savrtpel.sys
 Parsed  : C:\Program Files\Norton AntiVirus\Savrtpel.sys
 
 DEEP - 617
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB101FE8D11198442AB0CE71DBBB7996
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVLnch.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVLnch.dll
 
 DEEP - 618
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDAF0D299B31D614A997AC7EFF57FE6F
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Help\CCLGVIEW.CHM
 
 DEEP - 619
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CDB8298C7464d6d489512651FE1AADA4
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ISWrap.dll
 
 DEEP - 620
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D134FCA7554F39744BE3E935F5FDC7A8
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\quar32.dll
 Parsed  : C:\Program Files\Norton AntiVirus\quar32.dll
 
 DEEP - 621
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D1F9A4570B6A53B4ABA8EABBF618BACC
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ICFMgr.dll
 
 DEEP - 622
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2B1A54B84E046A40B699A99AA183415
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navntutl.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Navntutl.dll
 
 DEEP - 623
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2ED3A901D3C1E640A22123D3329A663
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\PtchInst.dll
 Parsed  : C:\Program Files\Norton AntiVirus\PtchInst.dll
 
 DEEP - 624
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
 
 DEEP - 625
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2ID.dll
 
 DEEP - 626
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D485B77AAFBE7FE4EB02F19B1C742D99
 Value   : 7E57FF1D24DDDFC40B25023BFF4FDE8B = C:\Program Files\Norton AntiVirus\SymUIHlp.dll
 Parsed  : C:\Program Files\Norton AntiVirus\SymUIHlp.dll
 
 DEEP - 627
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
 Value   : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Program Files\Common Files\Symantec Shared\Default.rul
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Default.rul
 
 DEEP - 628
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4C317E99F72CD94E80229440898C76B
 Value   : 45E1A0ACF0EC66340BC98AB716CD6533 = C:\Program Files\Common Files\Symantec Shared\Default.rul
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Default.rul
 
 DEEP - 629
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5C7E0ECE38B2204C81A6CAC7B563C1E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OEHeur.dll
 Parsed  : C:\Program Files\Norton AntiVirus\OEHeur.dll
 
 DEEP - 630
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB37AD6F8B343624D8A21F9536E244D0
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\ccScan.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\ccScan.dll
 
 DEEP - 631
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDBB2E3516FF53D49B7674092DF93A43
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Scandres.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Scandres.dll
 
 DEEP - 632
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
 
 DEEP - 633
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2GZIP.dll
 
 DEEP - 634
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E03493F9C46190242AE587161C8E1607
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 635
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E226A5EC6DBEB5B41AA58B99246CA6EA
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navlcom.dll
 Parsed  : C:\Program Files\Norton AntiVirus\Navlcom.dll
 
 DEEP - 636
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E41CAC9D612ABD845B8DB1A766C5818E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDPCK32I.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\SDPCK32I.DLL
 
 DEEP - 637
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5A2A8E777C123D41A1B9870787E7200
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ACDisp.dll
 
 DEEP - 638
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
 Value   : 6786F822313A3A04190C3CBC6E99D790 = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 639
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
 Value   : 20B58AD20C31D6E4A967226E3BDDC02B = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 640
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 641
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EACA16BD93C3AC64E9487A0F15FA0CB7
 Value   : 5A60346F23C4bb141B3535895672AF4B = C:\Documents and Settings\All Users\Application Data\Symantec\
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec
 
 DEEP - 642
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBB41D27C6D48A142A21DC74BA5CD4A7
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 643
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED9559B59719B7648A5698448B0F5C13
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSTP32I.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\SDSTP32I.DLL
 
 DEEP - 644
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDA2F868189B4BB43835954121D6D84F
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccAVMail.dll
 Parsed  : C:\Program Files\Norton AntiVirus\ccAVMail.dll
 
 DEEP - 645
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDB816C6DB3D2D34E9E028C26D00C79E
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 646
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EE7648442F6386F4B974667E874252D3
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\SDSND32I.DLL
 Parsed  : C:\Program Files\Norton AntiVirus\SDSND32I.DLL
 
 DEEP - 647
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF24F0C8CEA62F94AABE0F1D2DCFE65B
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\NAVTskWz.dll
 Parsed  : C:\Program Files\Norton AntiVirus\NAVTskWz.dll
 
 DEEP - 648
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F09CF45C228A5D946916CA86F0B28466
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\navsess.tpl
 Parsed  : C:\Program Files\Norton AntiVirus\navsess.tpl
 
 DEEP - 649
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1031A4EC1C5b044694350E3CF04BF73
 Value   : BC0F80924D1CF744792AFC1C539C8F4D = C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
 Parsed  : C:\Program Files\Norton AntiVirus\IWP\ISLuCbk.dll
 
 DEEP - 650
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F14B2730986758A4FACCDABB202D7702
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\ccIMScn.exe
 Parsed  : C:\Program Files\Norton AntiVirus\ccIMScn.exe
 
 DEEP - 651
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F297450C80AA7B44CAC9B12C24BFA5C5
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\LtChkRes.dll
 Parsed  : C:\Program Files\Norton AntiVirus\LtChkRes.dll
 
 DEEP - 652
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
 
 DEEP - 653
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1
 Value   : 00000000000000000000000000000000 = C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
 Parsed  : C:\Program Files\Common Files\Symantec Shared\Decomposers\Dec2.dll
 
 DEEP - 654
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4BA67E73F1500B44B2BE9626C16C657
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\patch25d.dll
 Parsed  : C:\Program Files\Norton AntiVirus\patch25d.dll
 
 DEEP - 655
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F890C1DE6479A8044916B360F03F6577
 Value   : 806763CD7A467FB4294FB8AA52AB20BD = C:\Program Files\Common Files\Symantec Shared\
 Parsed  : C:\Program Files\Common Files\Symantec Shared
 
 DEEP - 656
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F959C548DF373904DBA75FAB7EEDBB3C
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\end_user.txt
 Parsed  : C:\Program Files\Norton AntiVirus\end_user.txt
 
 DEEP - 657
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0AE70A711E43A4D845D528F62189C8
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\OfficeAV.dll
 Parsed  : C:\Program Files\Norton AntiVirus\OfficeAV.dll
 
 DEEP - 658
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FAE59BAC70CEF6B4C907FE4AF0B1C09A
 Value   : F81D34B847CD44D418E4B93D24B0E844 = C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll
 Parsed  : C:\Program Files\McAfee\McAfee QuickClean\Restore\ShredEnu.dll
 
 DEEP - 659
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB9E629FE71958F499EAB75A10C537C2
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\Navw32.exe
 Parsed  : C:\Program Files\Norton AntiVirus\Navw32.exe
 
 DEEP - 660
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDB73BAFBA2FA4448A9F560C8AE6AB05
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Program Files\Norton AntiVirus\AboutPlg.dll
 Parsed  : C:\Program Files\Norton AntiVirus\AboutPlg.dll
 
 DEEP - 661
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFEBF8E0EFEA5B440A054DF0D1F8C8C9
 Value   : FC6B5F6CC906E82478F6AC3871C620B1 = C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca
 Parsed  : C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\files.sca
 
 DEEP - 662
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\207809E353FA1164598159D52AB4E770\InstallProperties
 Value   : InstallSource = C:\WINDOWS\TEMP\IXP000.TMP\
 Parsed  : C:\WINDOWS\TEMP\IXP000.TMP
 
 DEEP - 663
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\20B58AD20C31D6E4A967226E3BDDC02B\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymNet
 
 DEEP - 664
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\45E1A0ACF0EC66340BC98AB716CD6533\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E\
 Parsed  : C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\EXITEM~1.0_E
 
 DEEP - 665
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5A60346F23C4bb141B3535895672AF4B\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SymSC
 
 DEEP - 666
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5F1BEE43939E1A046AAB5927284A2B8C\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\Help
 
 DEEP - 667
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6786F822313A3A04190C3CBC6E99D790\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\MSRedist
 
 DEEP - 668
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\7E57FF1D24DDDFC40B25023BFF4FDE8B\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 DEEP - 669
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\806763CD7A467FB4294FB8AA52AB20BD\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ccCommon
 
 DEEP - 670
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
 Value   : InstallLocation = C:\Program Files\Norton AntiVirus\
 Parsed  : C:\Program Files\Norton AntiVirus
 
 DEEP - 671
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\87627777F71810443910DED1108AAD65\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\SPBBC
 
 DEEP - 672
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040820900063D11C8EF00054038389C\InstallProperties
 Value   : InstallSource = C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP\
 Parsed  : C:\Documents and Settings\keno cannady\Shared\Microsoft Office XP Professional (Includes Serial Number)\Microsoft Office XP
 
 DEEP - 673
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9399EE5EF9522ED40832C5941EA6F434\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 DEEP - 674
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9CFA723DAAB7A3743891E67B0A4D1083\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\Support\ScrBlock
 
 DEEP - 675
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC0F80924D1CF744792AFC1C539C8F4D\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 DEEP - 676
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F81D34B847CD44D418E4B93D24B0E844\InstallProperties
 Value   : Readme = C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
 Parsed  : C:\Program Files\McAfee\McAfee QuickClean\Readme.txt
 
 DEEP - 677
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FC6B5F6CC906E82478F6AC3871C620B1\InstallProperties
 Value   : InstallSource = C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV\
 Parsed  : C:\DOCUME~1\KENOCA~1\Shared\NORTON~1\NORTON~1\NAV
 
 DEEP - 678
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
 Value   : Directory = C:\WINDOWS\History
 Parsed  : C:\WINDOWS\History
 
 DEEP - 679
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
 Value   : ServicePackCachePath = c:\windows\ServicePackFiles\ServicePackCache
 Parsed  : c:\windows\ServicePackFiles\ServicePackCache
 
 DEEP - 680
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Migration DLLs
 Value   : {5945c046-1e7d-11d1-bc44-00c04fd912be} = C:\Program Files\Messenger\migrate.dll
 Parsed  : C:\Program Files\Messenger\migrate.dll
 
 DEEP - 681
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\StillImage\Registered Applications
 Value   : OmniPage SE = C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe /StiDevice:%1 /StiEvent:%2
 Parsed  : C:\Program Files\ScanSoft\OmniPageSE\OmniPage.exe
 
 DEEP - 682
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\Sus
 Value   : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin
 Parsed  : C:\WINDOWS\SoftwareDistribution\EventCache\{07F5D015-59A7-4B7E-95D0-4A50A504ED85}.bin
 
 DEEP - 683
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU
 Value   : CurrentCacheFile = C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin
 Parsed  : C:\WINDOWS\SoftwareDistribution\EventCache\{E78161BE-AB16-4DEE-A62D-E3774298CEFC}.bin
 
 DEEP - 684
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit
 Value   : TemplateUsed = C:\WINDOWS\SEC129B.tmp
 Parsed  : C:\WINDOWS\SEC129B.tmp
 
 DEEP - 685
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar
 Value   : Dir = C:\Program Files\MyWay\myBar\
 Parsed  : C:\Program Files\MyWay\myBar
 
 DEEP - 686
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : bitmap = C:\Program Files\MyWay\myBar\1.bin\partner.bmp
 Parsed  : C:\Program Files\MyWay\myBar\1.bin\partner.bmp
 
 DEEP - 687
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : test = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 688
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : PM-Home = C:\Program Files\Altnet\Points Manager\Points Manager.exe
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 689
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : PM-Points = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 1
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 690
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : PM-Redeem = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 2
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 691
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : PM-Wallet = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 3
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 692
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner
 Value   : PM-Settings = C:\Program Files\Altnet\Points Manager\Points Manager.exe -p 4
 Parsed  : C:\Program Files\Altnet\Points Manager\Points Manager.exe
 
 DEEP - 693
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\mp3el
 Value   : Path = C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe
 Parsed  : C:\Program Files\NCH Swift Sound\Components\mp3el\mp3enc.exe
 
 DEEP - 694
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\22CD942489E05966FCC70B6D0C25B30B
 Value   : path = C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe
 Parsed  : C:\Program Files\PlayFirst\Diner Dash\Diner Dash.exe
 
 DEEP - 695
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\AC72B3AB1BCFC04699EA3EA6A35608AD
 Value   : path = C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe
 Parsed  : C:\Program Files\iWin.com Games\Family Feud\FamilyFeud.exe
 
 DEEP - 696
 Location: HKEY_LOCAL_MACHINE\SOFTWARE\Trymedia Systems\ActiveMARK Software\B1A6C040A5B0EA8E8F64BEED9FEBE83B
 Value   : path = C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe
 Parsed  : C:\Program Files\Yahoo! Games\Trivia Machine\TriviaMachine.exe
 
 ----------------------------------------------------------------------------------------------------
 Registry Mechanic 5.2.0.310
 ----------------------------------------------------------------------------------------------------
 End of Scan
 4/24/2006 5:20:09 PM
 Your System Information :
 CPU: Intel Pentium
 IE: Internet Explorer 6.0.2900
 MEMORY FREE: 494388
 MEMORY TOTAL: 785904
 VIRTUAL FREE: 2019252
 VIRTUAL TOTAL: 2097024
 WINDOWS VER: Windows XP   5.1 (Build 2600)
 This message has been edited since posting. Last time this message was edited on 24. April 2006 @ 13:45 |  
						| Senior Member 
   | 25. April 2006 @ 04:36 |  Link to this message   |  
						| 
							
							Ok, did you clean your registry with CCleaner?
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Advertisement   |   |  
						| 
 |  
						| daddy163Junior Member 
   | 25. April 2006 @ 07:27 |  Link to this message   |  
						| 
							
							I think all is well now here is the new hajthis log:
 Logfile of HijackThis v1.99.1
 Scan saved at 11:25:24 AM, on 4/25/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 C:\WINDOWS\Explorer.EXE
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
 C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\VIAudioi\SBADeck\ADeck.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\progra~1\mcafee\MCAFEE~1\masalert.exe
 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
 c:\progra~1\mcafee.com\vso\mcvsescn.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 c:\progra~1\mcafee.com\vso\mcvsftsn.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 C:\Program Files\Microsoft Office\Office10\msoffice.exe
 C:\WINDOWS\System32\svchost.exe
 C:\progra~1\mcafee\MCAFEE~1\MASCon.exe
 C:\PROGRA~1\mcafee.com\shared\mghtml.exe
 C:\HJT\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
 O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
 O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8d588edfc4be46d8a2396ae9a351e6bf
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
 O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
 O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcins...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x8...
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
 O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
 O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
 O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
 O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4744/mcfs...
 O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 
 I do thank you for all your help. By the way do you know what it was that I had?
 This message has been edited since posting. Last time this message was edited on 25. April 2006 @ 07:34 |  
					
					
				 |